{
    "generated_at": "2026-08-18T20:54:59+00:00",
    "count": 30,
    "articles": [
        {
            "id": 672,
            "title": "'CoSnitch' Attack Tricked Copilot into Mapping Out Architecture",
            "url": "https://www.darkreading.com/vulnerabilities-threats/cosnitch-attack-copilot-mapping-out-architecture",
            "author": "Alexander Culafi",
            "summary": "Researchers discovered a \"meta-hacking\" technique that can manipulate the AI service into revealing its own security weaknesses.",
            "published_at": "2026-08-18 20:17:24",
            "discovered_at": "2026-08-18 20:45:04",
            "updated_at": null,
            "priority_score": 0,
            "source": "Dark Reading",
            "source_group": "Security Journalism",
            "categories": [
                "Security Research"
            ],
            "cves": []
        },
        {
            "id": 670,
            "title": "Comcast turns your Xfinity WiFi into a home motion detector",
            "url": "https://www.bleepingcomputer.com/news/security/comcast-turns-your-xfinity-wifi-into-a-home-motion-detector/",
            "author": "Lawrence Abrams",
            "summary": "Comcast is promoting WiFi-based motion detection as a part of its new Xfinity Shield home protection platform, allowing routers and wireless devices to detect people moving through a home without cameras or motion sensors. [...]",
            "published_at": "2026-08-18 20:14:58",
            "discovered_at": "2026-08-18 20:25:03",
            "updated_at": null,
            "priority_score": 0,
            "source": "BleepingComputer",
            "source_group": "Security Journalism",
            "categories": [
                "Network Security"
            ],
            "cves": []
        },
        {
            "id": 668,
            "title": "CVE-2026-75935 and CVE-2026-75936 - Issue with Amazon ion-java - Memory-amplification denial of service",
            "url": "https://aws.amazon.com/security/security-bulletins/rss/2026-083-aws/",
            "author": "aws@amazon.com",
            "summary": "Bulletin ID: 2026-083-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/18/2026 12:30 PM PDT Description: ion-java is a Java library that implements the Amazon Ion data format specification. We identified CVE-2026-75935, memory-amplification denial of service via declared-length preallocation, and CVE-2026-75936, memory-amplification denial of service via highly compressed data expansion. Affected versions: < 1.12.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.",
            "published_at": "2026-08-18 19:44:37",
            "discovered_at": "2026-08-18 20:10:02",
            "updated_at": null,
            "priority_score": 5,
            "source": "AWS Security Bulletins",
            "source_group": "Vendor Research",
            "categories": [
                "Cloud Security",
                "Vulnerabilities"
            ],
            "cves": [
                "CVE-2026-75935",
                "CVE-2026-75936"
            ]
        },
        {
            "id": 671,
            "title": "Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)",
            "url": "https://unit42.paloaltonetworks.com/large-scale-credential-attacks/",
            "author": "Unit 42",
            "summary": "We provide guidance for preparing for and mitigating large-scale credential attacks, focusing on recent campaigns targeting security vendors' devices. The post Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18) appeared first on Unit 42.",
            "published_at": "2026-08-18 19:05:33",
            "discovered_at": "2026-08-18 20:45:02",
            "updated_at": null,
            "priority_score": 0,
            "source": "Palo Alto Networks Unit 42",
            "source_group": "Vendor Research",
            "categories": [],
            "cves": []
        },
        {
            "id": 669,
            "title": "CISOs Break Their Silence in 'Declassified' Docuseries",
            "url": "https://www.darkreading.com/cyber-risk/cisos-break-their-silence-in-declassified-docuseries",
            "author": "Arielle Waldman",
            "summary": "Million-dollar heists, divorce, and career-ending burnout are all stories told in the latest docuseries revealing a behind-the-scenes look at the cybersecurity community.",
            "published_at": "2026-08-18 18:32:01",
            "discovered_at": "2026-08-18 20:15:04",
            "updated_at": null,
            "priority_score": 0,
            "source": "Dark Reading",
            "source_group": "Security Journalism",
            "categories": [],
            "cves": []
        },
        {
            "id": 662,
            "title": "CVE-2026-75897 - Uncontrolled resource consumption in OpenSearch Dashboards capabilities route",
            "url": "https://aws.amazon.com/security/security-bulletins/rss/2026-082-aws/",
            "author": "aws@amazon.com",
            "summary": "Bulletin ID: 2026-082-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/18/2026 10:00 AM PDT Description: OpenSearch Dashboards is the open-source visualization and management UI for OpenSearch, and ships as part of Amazon OpenSearch Service. We identified CVE-2026-75897, an improper input validation in the capabilities route handler in OpenSearch Dashboards. The handler does not bound the size of the request payload, which might allow remote attackers to cause a denial of service via a crafted HTTP request. Affected Products and Versions: OpenSearch \"Plugin Type\" Plugin (open-source, self-managed): - Affected: All versions from 1.3.0 through 3.7.0 inclusive, including all 2.x releases up to and including 2.19.6. The issue is inherited from upstream Kibana and is also present in Kibana 7.7.1 through 7.10.2. - Fixed: 3.8.0 Amazon OpenSearch Service (AWS Managed): - Affected: Engine versions OpenSearch 1.3, 2.11, 2.13, 2.15, 2.17, 2.19, 3.1, 3.3, and 3.5, and Elasticsearch-compatibility versions using Kibana 7.9 and 7.10. - Fixed: A patched service software release is available for all affected versions. Apply the latest available service software update to your domain. Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.",
            "published_at": "2026-08-18 18:26:06",
            "discovered_at": "2026-08-18 18:30:03",
            "updated_at": null,
            "priority_score": 5,
            "source": "AWS Security Bulletins",
            "source_group": "Vendor Research",
            "categories": [
                "Cloud Security",
                "Vulnerabilities"
            ],
            "cves": [
                "CVE-2026-75897"
            ]
        },
        {
            "id": 661,
            "title": "More than 200 victims of Medusa ransomware identified over the last year, CISA says",
            "url": "https://therecord.media/more-than-200-medusa-ransomware-victims-in-last-year-cisa",
            "author": null,
            "summary": "The Cybersecurity and Infrastructure Security Agency (CISA) and FBI updated an advisory on the group initially released in March 2025 — writing that as of April 2026, Medusa actors have hit more than 500 victims. CISA previously said 300 victims, many of which are in critical infrastructure sectors, were attacked as of 2025.",
            "published_at": "2026-08-18 18:05:00",
            "discovered_at": "2026-08-18 18:15:05",
            "updated_at": null,
            "priority_score": 15,
            "source": "The Record",
            "source_group": "Security Journalism",
            "categories": [
                "Law Enforcement",
                "Ransomware"
            ],
            "cves": []
        },
        {
            "id": 667,
            "title": "Hackers Expose Data of 1.2 Million Heights Finance Customers",
            "url": "https://securityaffairs.com/197485/data-breach/hackers-expose-data-of-1-2-million-heights-finance-customers.html",
            "author": "Pierluigi Paganini",
            "summary": "A Heights Finance breach exposed personal and financial data of over 1.2 million people after hackers compromised a third-party cloud platform. Heights Finance is a U.S. consumer finance company that provides personal loans and related lending services, mainly to customers who may have limited access to traditional bank credit. It is part of Heights Finance […]",
            "published_at": "2026-08-18 17:55:18",
            "discovered_at": "2026-08-18 19:10:05",
            "updated_at": null,
            "priority_score": 0,
            "source": "Security Affairs",
            "source_group": "Other",
            "categories": [],
            "cves": []
        },
        {
            "id": 663,
            "title": "Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps",
            "url": "https://thehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html",
            "author": "info@thehackernews.com (The Hacker News)",
            "summary": "Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copilot session. The flaws, which the researchers collectively named CoSnitch, turn in part on an undocumented URL parameter that the assistant itself surfaced",
            "published_at": "2026-08-18 17:47:22",
            "discovered_at": "2026-08-18 18:35:03",
            "updated_at": null,
            "priority_score": 0,
            "source": "The Hacker News",
            "source_group": "Security Journalism",
            "categories": [
                "Cloud Security",
                "Microsoft"
            ],
            "cves": []
        },
        {
            "id": 664,
            "title": "Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets",
            "url": "https://thehackernews.com/2026/08/attackers-exploit-mlflow-ssrf-flaw-to.html",
            "author": "info@thehackernews.com (The Hacker News)",
            "summary": "Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation efforts. According to independent reports from watchTowr and VulnCheck, the vulnerabilities in question are as follows -",
            "published_at": "2026-08-18 17:44:05",
            "discovered_at": "2026-08-18 18:35:03",
            "updated_at": null,
            "priority_score": 0,
            "source": "The Hacker News",
            "source_group": "Security Journalism",
            "categories": [
                "AI Security",
                "ICS / OT"
            ],
            "cves": []
        },
        {
            "id": 659,
            "title": "Clop created custom web shell for Windchill data theft attacks",
            "url": "https://www.bleepingcomputer.com/news/security/clop-created-custom-web-shell-for-windchill-data-theft-attacks/",
            "author": "Lawrence Abrams",
            "summary": "A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. [...]",
            "published_at": "2026-08-18 17:29:51",
            "discovered_at": "2026-08-18 17:30:06",
            "updated_at": null,
            "priority_score": 15,
            "source": "BleepingComputer",
            "source_group": "Security Journalism",
            "categories": [
                "Ransomware"
            ],
            "cves": []
        },
        {
            "id": 666,
            "title": "Hunting MacSync Stealer infrastructure through behavioral pivots",
            "url": "https://www.microsoft.com/en-us/security/blog/2026/08/18/hunting-macsync-stealer-infrastructure-through-behavioral-pivots/",
            "author": "Microsoft Defender Experts and Microsoft Security Research",
            "summary": "MacSync Stealer rapidly rotates domains to evade detection, but its behavior remains consistent. Learn how Microsoft uncovered 30+ related domains using durable hunting pivots. The post Hunting MacSync Stealer infrastructure through behavioral pivots appeared first on Microsoft Security Blog.",
            "published_at": "2026-08-18 17:08:28",
            "discovered_at": "2026-08-18 18:40:04",
            "updated_at": null,
            "priority_score": 0,
            "source": "Microsoft Security Blog",
            "source_group": "Vendor Research",
            "categories": [
                "Malware",
                "Microsoft"
            ],
            "cves": []
        },
        {
            "id": 660,
            "title": "Project noRecognition: Teaching AI to Fool Surveillance Cameras",
            "url": "https://securityaffairs.com/197465/ai/project-norecognition-teaching-ai-to-fool-surveillance-cameras.html",
            "author": "Pierluigi Paganini",
            "summary": "Researchers tested 31 million patterns to disrupt surveillance AI, with promising results but significant gaps between simulation and real-world use. The Kansas City-based cybersecurity researcher Bill Swearingen spent the past year doing something that sounds almost too simple to work: printing patterns, watching cameras fail to detect them, and repeating. TechCrunch reports that after roughly […]",
            "published_at": "2026-08-18 17:05:06",
            "discovered_at": "2026-08-18 18:10:05",
            "updated_at": null,
            "priority_score": 0,
            "source": "Security Affairs",
            "source_group": "Other",
            "categories": [
                "Security Research"
            ],
            "cves": []
        },
        {
            "id": 658,
            "title": "Security Hub Extended adds Supply Chain Security as its tenth category",
            "url": "https://aws.amazon.com/blogs/security/security-hub-extended-adds-supply-chain-security-as-its-tenth-category/",
            "author": "Michael Fuller",
            "summary": "Since February, we’ve grown AWS Security Hub Extended from 14 curated partners across 9 categories to 23 partners across 10. At Black Hat this month, 14 of those partners were at the Amazon Web Services (AWS) booth demoing live. Four of those partners delivered theater talks and ten were featured on SecurityLive streaming. We hosted […]",
            "published_at": "2026-08-18 17:04:28",
            "discovered_at": "2026-08-18 17:30:03",
            "updated_at": null,
            "priority_score": 0,
            "source": "AWS Security Blog",
            "source_group": "Vendor Research",
            "categories": [
                "Cloud Security"
            ],
            "cves": []
        },
        {
            "id": 665,
            "title": "Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000",
            "url": "https://thehackernews.com/2026/08/ransom-busters-claims-it-hacked.html",
            "author": "info@thehackernews.com (The Hacker News)",
            "summary": "A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000. \"In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous,\" GuidePoint Research",
            "published_at": "2026-08-18 16:58:16",
            "discovered_at": "2026-08-18 18:35:03",
            "updated_at": null,
            "priority_score": 15,
            "source": "The Hacker News",
            "source_group": "Security Journalism",
            "categories": [
                "Data Breaches",
                "Microsoft",
                "Ransomware"
            ],
            "cves": []
        },
        {
            "id": 657,
            "title": "Berlin cuts two state ministries off government network after security breach",
            "url": "https://therecord.media/berlin-cuts-two-state-ministries-off-government-breach",
            "author": null,
            "summary": "The affected ministries — one responsible for urban development, construction and housing, and the other for mobility, transport, climate protection and the environment — have been isolated from government networks since Friday as a precaution.",
            "published_at": "2026-08-18 16:40:00",
            "discovered_at": "2026-08-18 17:00:06",
            "updated_at": null,
            "priority_score": 0,
            "source": "The Record",
            "source_group": "Security Journalism",
            "categories": [],
            "cves": []
        },
        {
            "id": 656,
            "title": "University of Texas forced to take systems offline in San Antonio after cyberattack",
            "url": "https://therecord.media/university-of-texas-forced-to-take-systems-offline-cyberattack-san-antonio",
            "author": null,
            "summary": "The University of Texas at San Antonio, which serves 40,000 students across six campuses, said its IT team identified threat activity on its academic campus over the weekend and took some systems, including phones, offline in response.",
            "published_at": "2026-08-18 16:20:00",
            "discovered_at": "2026-08-18 16:30:05",
            "updated_at": null,
            "priority_score": 0,
            "source": "The Record",
            "source_group": "Security Journalism",
            "categories": [],
            "cves": []
        },
        {
            "id": 652,
            "title": "Hackers target Ukrainian agency managing assets seized from sanctioned Russians",
            "url": "https://therecord.media/hackers-target-ukraine-agency-sanctioned-russians",
            "author": null,
            "summary": "The agency said the latest attack came amid preparations to select a manager for seized corporate rights in IDS Ukraine, one of the country’s largest producers of bottled mineral water and beverages.",
            "published_at": "2026-08-18 14:45:00",
            "discovered_at": "2026-08-18 15:05:01",
            "updated_at": null,
            "priority_score": 0,
            "source": "The Record",
            "source_group": "Security Journalism",
            "categories": [
                "Law Enforcement"
            ],
            "cves": []
        },
        {
            "id": 651,
            "title": "Your Controls Block Known Attacks. What About the Behavior?",
            "url": "https://www.bleepingcomputer.com/news/security/your-controls-block-known-attacks-what-about-the-behavior/",
            "author": "Sponsored by Picus Security",
            "summary": "Security controls can block a familiar attack method while missing quieter ways to achieve the same objective. Picus Security's Blue Report 2026 shows how prevention rates can vary dramatically by technique and why behavioral testing is needed to uncover those gaps. [...]",
            "published_at": "2026-08-18 14:01:11",
            "discovered_at": "2026-08-18 14:15:03",
            "updated_at": null,
            "priority_score": 0,
            "source": "BleepingComputer",
            "source_group": "Security Journalism",
            "categories": [],
            "cves": []
        },
        {
            "id": 655,
            "title": "Staying Ahead of Adversarial AI Through Agentic Source Code Review",
            "url": "https://cloud.google.com/blog/topics/threat-intelligence/staying-ahead-of-adversarial-ai-through-agentic-source-code-review/",
            "author": "Google Threat Intelligence Group",
            "summary": "Written by: Alex Tselevich, Michael Maturi Introduction Adversarial misuse of AI has increased the risk of data theft and extortion events, because when proprietary source code is exposed, defenders must scramble to identify and patch vulnerabilities while attackers deploy machine-speed AI tools against them. By structuring the analysis process, enforcing skeptical validation steps, and injecting domain-specific human expertise directly into the pipeline, we’ve achieved a leap in efficacy. Combining AI models with a deeply structured, human expert-driven orchestration layer to tip the scales so that defenders can beat adversaries to the punch. Today, we use the Agentic Vulnerability Discovery Harness (AVDH) to rapidly analyze code and find exploit paths during proactive reviews, penetration tests, red team operations, and incident response engagements. By combining multi-agent orchestration with our frontline subject-matter expertise, this framework helps to augment the discovery and validation of routine vulnerabilities, enabling humans to focus their impact. To help defenders implement similar approaches for their own environments, we are sharing the details of this internal, point-in-time architecture for the first time. AVDH can also be used alongside CodeMender’s ongoing scanning to create a two-layered defense strategy. Real-World Results In the 10 months that we’ve been using AVDH, we’ve seen it have a significant impact. During a recent incident response investigation involving stolen corporate repositories, the harness discovered over 100 true-positive critical vulnerabilities in just two days — achieving results in a fraction of the time required for manual review. This has greatly accelerated how Mandiant discovers vulnerabilities at scale. We have used it to analyze environments spanning tens of millions of lines of code, and execute thousands of pipelines to generate tens of thousands of findings. This rapid analysis has uncovered dozens of assignable flaws in widely used web extensions and open-source projects, resulting in 12 assigned CVEs, including CVE-2026-13242, CVE-2026-55803, and an additional dozen currently in active disclosure. While fast, broad, high-precision scanning has been one of the key benefits of AVDH, it has also acted as a force multiplier during our targeted adversary simulation engagements. We recently processed a client’s web application source code through the harness, and quickly found a remote code execution (RCE) vulnerability that enabled initial access. AVDH has repeatedly proven invaluable for navigating mature defenses and accelerating complex exploit chains. Architecting the Pipeline Harnesses have become a vital tool for cybersecurity uses of large language models (LLMs). They help mitigate much of the model’s unpredictability, driven by inherent, non-deterministic behavior, and dramatically improve their effectiveness at code analysis. The programmatic infrastructure of a harness orchestrates agents in a strictly deterministic manner toward objective completion. For AVDH, we used the Google Agent Development Kit (ADK), an LLM framework that implements the most common agent orchestration patterns, and provides flexibility for configuring custom and third-party integrations. This approach aligns with the agentic orchestration capabilities now available in Google Antigravity, which provides a centralized workspace for builders to steer and manage these agentic workflows. Our decades of frontline experience discovering and remediating vulnerabilities across every software domain helped us structure AVDH around the proven methodologies our consultants execute daily. AVDH chains specialized agents together in a sequential pipeline, much like the waterfall approach to software development: each phase is completed before the next begins. This pipeline yields a prioritized, risk-rated list of findings, primed for a human expert to review. Just as frontline security experts rely on organizational context, an agentic harness requires rich environmental inputs — such as asset inventories, software bills of materials (SBOMs), architecture documentation, and threat intelligence. When fed into a distilled human knowledge base, this contextual data allows agents to dynamically select relevant skills, language rules, and vulnerability patterns for deep analysis. Figure 1: Sequential vulnerability discovery methodology Threat Modeling A critical first step when using AI for code security analysis is to establish a threat model for the target codebase. Software architectures can vary wildly, and without a threat model, we can lose valuable context, such as attack vectors, business logic, and reachability. While traditional source code review engines rely on rigid pattern-matching rules, an LLM offers the distinct advantage of distinguishing code accessible to a standard user from code restricted to an administrator, or code that is never executed at all. Our pipeline begins by dispatching an Explorer agent to identify the core purpose of the target codebase. This agent determines the software domain (such as web or desktop application), reviews discovered documentation, flags directories to exclude from scanning (such as those containing unit tests), and dispatches Specialist Explorer subagents. These Specialist Explorers then delve into their respective focus areas, including authentication, authorization, routing, and other domain-specific categories. Their output is passed to a Threat Model Synthesis agent, which aggregates the findings into a cohesive threat model. Figure 2: Codebase reconnaissance workflow diagram Once this stage of analysis is complete, the consultant is presented with both textual and visual representations of the threat model for verification before analysis continues. This approval gate helps ensure that the rest of the pipeline has an accurate foundation to operate on. Figure 3 shows an example layout of a visual threat model generated by the harness, indicating which application components are exposed and how they connect. Figure 3: Visual representation of a threat model for a sample codebase Entry Point Discovery With the threat model established, we deploy parallelized Discovery agents to analyze every in-scope file. These agents use the lightweight Gemini Flash Lite model to process code at scale to extract critical application entry points, such as HTTP routes, inter-process communication (IPC) listeners, and other domain-specific attack vectors. Simultaneously, they isolate and extract all identifiable sources of user input nested in these identified entry points. Figure 4: Entry point discovery workflow diagram Context Enrichment Once entry points are selected for analysis, the harness assigns each to a dedicated Enrichment agent. In enterprise applications, analyzing an entry point in isolation is rarely sufficient — critical components like sanitizers, permissions, and routing conditions are often highly distributed. Furthermore, vulnerabilities frequently hide deep within nested function calls, multiple hops and files away from the initial source. To bridge this gap, the Enrichment agent navigates the codebase to aggregate contextually relevant code for its assigned entry point. It evaluates this aggregated data to determine whether the entry point requires further analysis by the Access Control agent, the Data Flow Analysis agent, or both. Figure 5: Context enrichment workflow diagram Hypothesis Generation Effective code analysis hinges on observing two primary properties: control flow and data flow. While control flow dictates the execution order of tasks and instructions, data flow traces how information moves and transforms throughout the application. Our AVDH delegates these critical tasks to the Access Control and Data Flow Analysis agents, respectively. At this stage, these agents perform minimal self-validation. Their primary objective is expansive brainstorming. To manage",
            "published_at": "2026-08-18 14:00:00",
            "discovered_at": "2026-08-18 15:55:03",
            "updated_at": null,
            "priority_score": 20,
            "source": "Google Threat Intelligence / Mandiant",
            "source_group": "Vendor Research",
            "categories": [
                "AI Security",
                "Cloud Security",
                "DFIR",
                "Microsoft",
                "Threat Intelligence",
                "Vulnerabilities"
            ],
            "cves": [
                "CVE-2026-13242",
                "CVE-2026-55803"
            ]
        },
        {
            "id": 650,
            "title": "Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud",
            "url": "https://www.darkreading.com/cloud-security/silent-twinloot-threat-operates-microsoft-cloud",
            "author": "Elizabeth Montalbano",
            "summary": "The Python-based malware framework takes living-off-the-land tactics to a new heights of stealth, with a modular implant that steals credentials and achieves persistence.",
            "published_at": "2026-08-18 13:00:00",
            "discovered_at": "2026-08-18 13:25:01",
            "updated_at": null,
            "priority_score": 0,
            "source": "Dark Reading",
            "source_group": "Security Journalism",
            "categories": [
                "Malware",
                "Microsoft"
            ],
            "cves": []
        },
        {
            "id": 649,
            "title": "'Ransom Busters': Ransomware Actor Poses as Incident-Recovery Service",
            "url": "https://www.darkreading.com/cyberattacks-data-breaches/ransom-busters-ransomware-actor-incident-recovery-service",
            "author": "Alexander Culafi",
            "summary": "A ransomware affiliate appears to be sidling up to victims with offers of aid, masking its true intention of diverting ransom payments.",
            "published_at": "2026-08-18 13:00:00",
            "discovered_at": "2026-08-18 13:10:03",
            "updated_at": null,
            "priority_score": 15,
            "source": "Dark Reading",
            "source_group": "Security Journalism",
            "categories": [
                "Ransomware"
            ],
            "cves": []
        },
        {
            "id": 653,
            "title": "New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles",
            "url": "https://www.rapid7.com/blog/post/tr-new-report-ai-threats-q2-2026-ends-traditional-patch-cycles",
            "author": "Rapid7 Labs",
            "summary": "You can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers.The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compress the time between disclosure and exploitation. The gap that patch cycles were built to fill is closing. Speed and volume are overwhelming security teams that have relied on traditional patch cycles and reactive programs. Success going forward can’t be about patching as much as possible - it has to be about understanding what matters most and reducing the exposures attackers can actually reach.Here are the four trends that defined Q2 2026, and what they mean for your security program as you define priorities for Q3 and beyond:The volume of disclosures hit another milestoneThere were 8,539 new high- and critical-severity CVEs (CVSS 7.0–10.0) this quarter- double the number reported in the same quarter last year (4,268). Meanwhile, the number of newly exploited vulnerabilities held roughly steady (40). The takeaway isn’t that exploitation exploded - it’s that disclosure volume is far outstripping what any team can triage.The report breaks down which of those disclosures are actually reachable and how to triage by exploitability instead of severity score alone.Initial access keeps getting easierNearly two-thirds of exploited vulnerabilities this quarter (62%) required no user interaction - no stolen credentials, no phishing victim, no click. Attackers reach and exploit them on their own, and that share is up nine points year over year (from 53% in Q2 2025). Reinforcing the trend, disclosures of missing-authentication flaws (CWE-306) surged 247% year over year - a fast-expanding pool of internet-facing systems that require no login at all.This is the quarter’s clearest signal - and the report details exactly which exposures to close first, and how, before the exploitation curve catches up.Nation-state activity remains persistentRapid7 observed continued activity from Iranian, North Korean, and Russian advanced persistent threat (APT) clusters targeting government, finance, healthcare, manufacturing, energy, and telecommunications. Russian campaigns targeted edge infrastructure; Iranian activity included sustained industrial control system (ICS) and operational technology (OT) targeting.The report maps the specific techniques and sectors each cluster focused on this quarter.Ransomware stays concentrated but keeps evolvingQilin led ransomware activity in Q2 with 263 listed victims, and the United States remained the most heavily targeted country - with business services and healthcare among the hardest-hit sectors. Rapid7’s Incident Response team also saw growing use of ClickFix and fake CAPTCHA campaigns, and social engineering through trusted collaboration platforms like Microsoft Teams - techniques that accounted for 31.8% of the incidents we worked.The report includes the full ransomware leaderboard, the sectors most at risk, and where affiliate activity is expanding next.Exposure is the real challenge, and the biggest opportunityThe volume is daunting, but the real challenge is keeping pace with attackers. As disclosures keep growing, the organizations that stay ahead won’t be the ones patching fastest — they’ll be the ones that know what they expose, which assets matter most, where attackers can realistically get in, and how to reduce reachable exposure before it becomes an incident. That’s what preemptive security means: not a slogan, but an operating model.The full Quarterly Threat Landscape Report shows where reachable exposure concentrates this quarter, the four actions Rapid7 Labs recommends, the sector-by-sector breakdown, and the dark-web signals shaping what’s next. Read it here before you pressure-test your Q3 prioritization.",
            "published_at": "2026-08-18 12:49:46",
            "discovered_at": "2026-08-18 15:35:03",
            "updated_at": null,
            "priority_score": 15,
            "source": "Rapid7",
            "source_group": "Vendor Research",
            "categories": [
                "APT / Nation-State",
                "Cloud Security",
                "Cybercrime",
                "DFIR",
                "ICS / OT",
                "Microsoft",
                "Phishing",
                "Ransomware",
                "Vulnerabilities"
            ],
            "cves": []
        },
        {
            "id": 647,
            "title": "AI \"Mind Viruses\" Can Spread Between Agents Through Persistent Prompt Files",
            "url": "https://thehackernews.com/2026/08/ai-mind-viruses-can-spread-between.html",
            "author": "info@thehackernews.com (The Hacker News)",
            "summary": "Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that autonomous agent harnesses use to carry state between sessions. The work, released as a preprint on August 10, 2026, tests the technique in a simulated six-agent coding",
            "published_at": "2026-08-18 12:38:36",
            "discovered_at": "2026-08-18 13:05:02",
            "updated_at": null,
            "priority_score": 0,
            "source": "The Hacker News",
            "source_group": "Security Journalism",
            "categories": [
                "AI Security",
                "Security Research"
            ],
            "cves": []
        },
        {
            "id": 648,
            "title": "TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks",
            "url": "https://thehackernews.com/2026/08/twinloot-abuses-sharepoint-and-teams-to.html",
            "author": "info@thehackernews.com (The Hacker News)",
            "summary": "Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. \"TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services,\" Ontinue said in a technical report shared with The Hacker News. \"Tasking flows through SharePoint Online file",
            "published_at": "2026-08-18 12:38:20",
            "discovered_at": "2026-08-18 13:05:02",
            "updated_at": null,
            "priority_score": 0,
            "source": "The Hacker News",
            "source_group": "Security Journalism",
            "categories": [
                "Microsoft",
                "Security Research"
            ],
            "cves": []
        },
        {
            "id": 646,
            "title": "One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025",
            "url": "https://thehackernews.com/2026/08/one-attacker-has-scraped-both.html",
            "author": "info@thehackernews.com (The Hacker News)",
            "summary": "A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco. The activity, which Reco has named the City Forum campaign after a domain tied to the attacker's IP address, traces back to one server: 158.220.87.79, hosted on a",
            "published_at": "2026-08-18 11:30:00",
            "discovered_at": "2026-08-18 11:55:02",
            "updated_at": null,
            "priority_score": 0,
            "source": "The Hacker News",
            "source_group": "Security Journalism",
            "categories": [],
            "cves": []
        },
        {
            "id": 645,
            "title": "16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets",
            "url": "https://thehackernews.com/2026/08/16-typosquatted-rubygems-packages-steal.html",
            "author": "info@thehackernews.com (The Hacker News)",
            "summary": "Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part of the campaign is below - ubnuler ubnlder ri18nr reaker rakier orakw joxn",
            "published_at": "2026-08-18 11:20:00",
            "discovered_at": "2026-08-18 11:55:02",
            "updated_at": "2026-08-18 13:05:02",
            "priority_score": 0,
            "source": "The Hacker News",
            "source_group": "Security Journalism",
            "categories": [
                "Malware",
                "Microsoft",
                "Security Research"
            ],
            "cves": []
        },
        {
            "id": 643,
            "title": "Microsoft tests faster Windows File Explorer, new context menu",
            "url": "https://www.bleepingcomputer.com/news/microsoft/microsoft-tests-faster-windows-explorer-customizable-context-menu/",
            "author": "Sergiu Gatlan",
            "summary": "Microsoft has started testing a faster File Explorer and a less cluttered and more customizable context menu in Windows 11 preview builds rolling out to Insiders this week. [...]",
            "published_at": "2026-08-18 11:14:28",
            "discovered_at": "2026-08-18 11:25:02",
            "updated_at": null,
            "priority_score": 0,
            "source": "BleepingComputer",
            "source_group": "Security Journalism",
            "categories": [
                "Microsoft"
            ],
            "cves": []
        },
        {
            "id": 642,
            "title": "CISA: Windows Task Host flaw now exploited by ransomware gangs",
            "url": "https://www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs/",
            "author": "Sergiu Gatlan",
            "summary": "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April. [...]",
            "published_at": "2026-08-18 10:32:16",
            "discovered_at": "2026-08-18 10:40:03",
            "updated_at": null,
            "priority_score": 40,
            "source": "BleepingComputer",
            "source_group": "Security Journalism",
            "categories": [
                "Microsoft",
                "Ransomware",
                "Vulnerabilities"
            ],
            "cves": []
        },
        {
            "id": 641,
            "title": "Microsoft confirms outage affecting search in Microsoft 365 apps",
            "url": "https://www.bleepingcomputer.com/news/microsoft/microsoft-working-to-fix-bug-behind-microsoft-365-search-issues/",
            "author": "Sergiu Gatlan",
            "summary": "Microsoft says some users are experiencing issues searching in Microsoft 365 apps, including Outlook on the web, Outlook desktop, SharePoint Online, and OneDrive. [...]",
            "published_at": "2026-08-18 09:24:49",
            "discovered_at": "2026-08-18 09:25:03",
            "updated_at": null,
            "priority_score": 0,
            "source": "BleepingComputer",
            "source_group": "Security Journalism",
            "categories": [
                "Microsoft"
            ],
            "cves": []
        }
    ]
}