{
  "schema_version": 2,
  "issue_date": "2026-08-17",
  "generated_at": "2026-08-17T21:30:26.098Z",
  "insight_context": {
    "schema_version": 2,
    "mode": "current",
    "checked_at": "2026-08-17T21:30:25.162Z",
    "report_date": "2026-08-17",
    "manifest_generated_at": "2026-08-17T18:50:12Z",
    "report_url": "https://ricomanifesto.github.io/SentryInsight/"
  },
  "articles": [
    {
      "id": "reporting-7ed54789e434",
      "title": "Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects",
      "link": "https://thehackernews.com/2026/08/critical-gitlab-graphql-flaw-could-let.html",
      "date": "2026-08-17T21:03:04.000Z",
      "source": "The Hacker News",
      "summary": "GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4. Released on…",
      "firstSeen": "2026-08-17T21:30:25.492Z"
    },
    {
      "id": "reporting-51cdb8f86fcc",
      "title": "Hacker claims 3.6 million Azure account records stolen from major companies",
      "link": "https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/",
      "date": "2026-08-17T19:35:01.000Z",
      "source": "Bleeping Computer",
      "summary": "A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials…",
      "firstSeen": "2026-08-17T21:30:25.492Z"
    },
    {
      "id": "reporting-0c65fb83c27f",
      "title": "Adam Shostack Talks Hugging Face & PHANTOM-B",
      "link": "https://www.darkreading.com/vulnerabilities-threats/adam-shostack-talks-hugging-face-phantom-b",
      "date": "2026-08-17T19:22:56.000Z",
      "source": "Dark Reading",
      "summary": "World-class threat modeler Adam Shostack shared he was \"blown away\" by OpenAI's revelations about the Hugging Face attack, and explains why his new threat model for LLMs is both \"lightweight yet still usable.\"",
      "firstSeen": "2026-08-17T21:30:25.492Z"
    },
    {
      "id": "reporting-e4644ae7413d",
      "title": "Pokémon Center data breach exposes customer info, cancels some orders",
      "link": "https://www.bleepingcomputer.com/news/security/pokemon-center-data-breach-exposes-customer-info-cancels-some-orders/",
      "date": "2026-08-17T19:12:39.000Z",
      "source": "Bleeping Computer",
      "summary": "Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics…",
      "firstSeen": "2026-08-17T21:30:25.492Z"
    },
    {
      "id": "reporting-499cd8c9d623",
      "title": "Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection",
      "link": "https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets_0330881554.html",
      "date": "2026-08-17T18:44:17.000Z",
      "source": "The Hacker News",
      "summary": "Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credentials. The issue was present in .github/workflows/jira_issue.yml, which ran when a…",
      "firstSeen": "2026-08-17T21:30:25.492Z"
    },
    {
      "id": "reporting-b83af1627135",
      "title": "Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads",
      "link": "https://thehackernews.com/2026/08/forminator-wordpress-flaw-can-enable.html",
      "date": "2026-08-17T18:22:09.000Z",
      "source": "The Hacker News",
      "summary": "A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites. The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out of 10.0 on the CVSS scoring system. It was discovered and reported by a security researcher who goes by the online alias \"…",
      "firstSeen": "2026-08-17T21:30:25.492Z"
    },
    {
      "id": "reporting-788b4d9b4fc1",
      "title": "Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic",
      "link": "https://thehackernews.com/2026/08/cavern-c2-uses-dns-and-google-apps.html",
      "date": "2026-08-17T17:41:06.000Z",
      "source": "The Hacker News",
      "summary": "Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian cybersecurity company Kaspersky said its ongoing monitoring of the threat activity cluster since December 2025 has led to the discovery of previously unreported components that expand the…",
      "firstSeen": "2026-08-17T21:30:25.492Z"
    },
    {
      "id": "reporting-31464e819e00",
      "title": "Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS",
      "link": "https://www.darkreading.com/cyber-risk/linux-botnet-evooo1bot-mirai-capabilities-beyond-ddos",
      "date": "2026-08-17T15:44:34.000Z",
      "source": "Dark Reading",
      "summary": "The botnet adds exploitation modules, credential theft, and reverse SOCKS relays to turn compromised devices into persistent attacker infrastructure.",
      "firstSeen": "2026-08-17T18:45:46.718Z"
    },
    {
      "id": "reporting-854ad5325b12",
      "title": "Microsoft confirms GitHub is down worldwide",
      "link": "https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-github-is-down-worldwide/",
      "date": "2026-08-17T14:47:08.000Z",
      "source": "Bleeping Computer",
      "summary": "GitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other services…",
      "firstSeen": "2026-08-17T18:45:46.718Z"
    },
    {
      "id": "reporting-c7510fc0ce5f",
      "title": "Certighost and the Privilege Hiding in Your Certificate Authority",
      "link": "https://www.bleepingcomputer.com/news/security/certighost-and-the-privilege-hiding-in-your-certificate-authority/",
      "date": "2026-08-17T14:00:10.000Z",
      "source": "Bleeping Computer",
      "summary": "CVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing privilege, implicit trust, and treating PKI as the Tier 0 identity infrastructure it has always been…",
      "firstSeen": "2026-08-17T18:45:46.718Z"
    },
    {
      "id": "reporting-74a4bb0aafac",
      "title": "⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More",
      "link": "https://thehackernews.com/2026/08/weekly-recap-vmware-exploits-windows-0.html",
      "date": "2026-08-17T13:23:51.000Z",
      "source": "The Hacker News",
      "summary": "The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than the original compromise. A lot of it came down to access that was already there and defenses that assumed nobody would look too closely. So, nothing magical. Just a…",
      "firstSeen": "2026-08-17T18:45:46.718Z"
    },
    {
      "id": "reporting-47cc0c0a3276",
      "title": "Windows Server 2022 reaches end of mainstream support in 60 days",
      "link": "https://www.bleepingcomputer.com/news/microsoft/windows-server-2022-reaches-end-of-mainstream-support-in-60-days/",
      "date": "2026-08-17T12:33:11.000Z",
      "source": "Bleeping Computer",
      "summary": "Microsoft has reminded IT administrators that Windows Server 2022 is rapidly approaching its mainstream end date of October 2026, when it will switch to extended support…",
      "firstSeen": "2026-08-17T12:53:03.224Z"
    },
    {
      "id": "reporting-5ab36643acff",
      "title": "How MCP Servers Can Expose Enterprise Secrets",
      "link": "https://thehackernews.com/2026/08/how-mcp-servers-can-expose-enterprise.html",
      "date": "2026-08-17T11:58:00.000Z",
      "source": "The Hacker News",
      "summary": "MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running. As more organizations adopt AI agents into their systems, that exposure can silently become a major gap in MCP server security. The Model Context Protocol (MCP) allows AI agents to reach the tools and data…",
      "firstSeen": "2026-08-17T12:53:03.224Z"
    },
    {
      "id": "reporting-1982bb8549d6",
      "title": "Philips and GE investigating Clop ransomware data theft claims",
      "link": "https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims/",
      "date": "2026-08-17T11:25:02.000Z",
      "source": "Bleeping Computer",
      "summary": "Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data…",
      "firstSeen": "2026-08-17T12:53:03.224Z"
    },
    {
      "id": "reporting-797946889533",
      "title": "Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access",
      "link": "https://thehackernews.com/2026/08/unisoc-volte-video-call-exploit-chain.html",
      "date": "2026-08-17T10:52:34.000Z",
      "source": "The Hacker News",
      "summary": "Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the chipset maker. The advisory, published August 17, 2026, is the second stage of a chain that began in March 2026, when SSD disclosed remote code execution in the…",
      "firstSeen": "2026-08-17T12:53:03.224Z"
    },
    {
      "id": "reporting-651dff2e0053",
      "title": "French tax authority data breach affects 678,000 individuals",
      "link": "https://www.bleepingcomputer.com/news/security/french-tax-authority-data-breach-affects-678-000-individuals/",
      "date": "2026-08-17T10:09:48.000Z",
      "source": "Bleeping Computer",
      "summary": "The French Ministry of the Economy and Finance has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems and stole data belonging to 678,000 individuals…",
      "firstSeen": "2026-08-17T12:53:03.224Z"
    },
    {
      "id": "reporting-7637e999c644",
      "title": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies",
      "link": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html",
      "date": "2026-08-17T09:29:55.000Z",
      "source": "The Hacker News",
      "summary": "Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies. \"While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including…",
      "firstSeen": "2026-08-17T12:53:03.224Z"
    },
    {
      "id": "reporting-9da7db7cc2a6",
      "title": "Microsoft working on Defender patch for ShieldBreak zero-day",
      "link": "https://www.bleepingcomputer.com/news/security/microsoft-working-on-defender-patch-for-shieldbreak-zero-day/",
      "date": "2026-08-17T09:05:33.000Z",
      "source": "Bleeping Computer",
      "summary": "Microsoft is working on a security patch for the \"ShieldBreak\" zero-day vulnerability disclosed last week by security researcher \"Nightmare Eclipse\" and now tracked as CVE-2026-69414…",
      "firstSeen": "2026-08-17T09:47:51.905Z"
    },
    {
      "id": "reporting-f632e57bed8c",
      "title": "Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware",
      "link": "https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html",
      "date": "2026-08-17T07:36:19.000Z",
      "source": "The Hacker News",
      "summary": "Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a malicious actor to execute arbitrary code…",
      "firstSeen": "2026-08-17T12:53:03.224Z"
    },
    {
      "id": "reporting-847da71208bc",
      "title": "SafePal data breach impacts 39,798 customers, stolen info for sale",
      "link": "https://www.bleepingcomputer.com/news/security/safepal-data-breach-impacts-39-798-customers-stolen-info-for-sale/",
      "date": "2026-08-16T23:47:06.000Z",
      "source": "Bleeping Computer",
      "summary": "Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data…",
      "firstSeen": "2026-08-17T01:37:21.686Z"
    },
    {
      "id": "reporting-0748ca510918",
      "title": "Anthropic confirms Claude is down in major outage affecting multiple services",
      "link": "https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-confirms-claude-is-down-in-major-outage-affecting-multiple-services/",
      "date": "2026-08-16T22:28:57.000Z",
      "source": "Bleeping Computer",
      "summary": "Claude is experiencing a major outage, with users reporting login problems and degraded performance across several Anthropic services…",
      "firstSeen": "2026-08-17T01:37:21.686Z"
    },
    {
      "id": "reporting-6565f6821662",
      "title": "Large-scale DDoS attacks disrupted Threema secure messaging service",
      "link": "https://www.bleepingcomputer.com/news/security/large-scale-ddos-attacks-disrupted-threema-secure-messaging-service/",
      "date": "2026-08-16T17:29:52.000Z",
      "source": "Bleeping Computer",
      "summary": "Multiple distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service earlier this week, causing severe disruptions to communications…",
      "firstSeen": "2026-08-16T18:35:07.143Z"
    },
    {
      "id": "reporting-0a6826eb0448",
      "title": "New AmnesiaStealer macOS malware hijacks browser sessions via remote control",
      "link": "https://www.bleepingcomputer.com/news/security/new-amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control/",
      "date": "2026-08-16T15:07:44.000Z",
      "source": "Bleeping Computer",
      "summary": "A new information-stealing malware called AmnesiaStealer, which targets macOS users via ClickFix attacks, includes a streaming module that allows the attacker to interactively control the victim's web browser…",
      "firstSeen": "2026-08-16T15:26:08.407Z"
    },
    {
      "id": "reporting-2ef1bbe49955",
      "title": "New Evooo1Bot Linux botnet turns routers into traffic relay nodes",
      "link": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/",
      "date": "2026-08-15T14:14:38.000Z",
      "source": "Bleeping Computer",
      "summary": "A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes…",
      "firstSeen": "2026-08-15T18:32:45.611Z"
    },
    {
      "id": "reporting-32f4f04d99f8",
      "title": "SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch",
      "link": "https://thehackernews.com/2026/08/sap-commerce-cloud-cve-2026-58231.html",
      "date": "2026-08-15T08:38:46.000Z",
      "source": "The Hacker News",
      "summary": "A maximum-severity security vulnerability impacting SAP Commerce Cloud is witnessing active exploitation efforts. The vulnerability, tracked as CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It relates to an instance of insufficient authorization checks and input validation. \"SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit…",
      "firstSeen": "2026-08-17T12:53:03.224Z"
    },
    {
      "id": "reporting-b90ffb4f7f9b",
      "title": "Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner",
      "link": "https://thehackernews.com/2026/08/apple-macos-screen-sharing-flaw.html",
      "date": "2026-08-15T07:24:04.000Z",
      "source": "The Hacker News",
      "summary": "A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC-NL) has warned. The vulnerability in question is CVE-2026-65400 (CVSS score: 9.8), a critical authentication issue impacting the Screen Sharing component that could allow an attacker already on the network to…",
      "firstSeen": "2026-08-17T12:53:03.224Z"
    },
    {
      "id": "reporting-adf27a5de8bb",
      "title": "How Anthropic plans to watermark Claude's AI-generated text",
      "link": "https://www.bleepingcomputer.com/news/artificial-intelligence/how-anthropic-plans-to-watermark-claudes-ai-generated-text/",
      "date": "2026-08-14T23:24:17.000Z",
      "source": "Bleeping Computer",
      "summary": "It could soon become easier to identify AI-generated content, even if it's not the usual \"It's Not X, it's Y\" type of post you'd come across on LinkedIn and other socials…",
      "firstSeen": "2026-08-15T01:29:05.754Z"
    },
    {
      "id": "reporting-4ae5bf990f47",
      "title": "Mission-Driven Security: Inside a Global Bank's Defense",
      "link": "https://www.darkreading.com/cybersecurity-operations/mission-driven-security-inside-global-bank-defense",
      "date": "2026-08-14T19:24:18.000Z",
      "source": "Dark Reading",
      "summary": "In this video interview, Standard Chartered's group CISO shares insights on transitioning from technical roles to strategic leadership, the importance of business-savvy security executives, and how AI is reshaping both defensive capabilities and adversarial tactics in banking.",
      "firstSeen": "2026-08-14T20:19:31.333Z"
    },
    {
      "id": "reporting-ffc565ec11c5",
      "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
      "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
      "date": "2026-08-14T18:48:46.000Z",
      "source": "The Hacker News",
      "summary": "Threat actors are acquiring expired domains to inherit website traffic and reputation to redirect victims to scams and malware on a large scale. DNS threat intelligence firm Infoblox has given the name dropcatch domains to those that get a second chance, where an expired domain becomes available for registration and is then snapped up by another party. During the first half of 2026, 50,400…",
      "firstSeen": "2026-08-17T12:53:03.224Z"
    },
    {
      "id": "reporting-f425d96c2c87",
      "title": "Hackers arrested over €30M bank fraud exploiting service provider flaw",
      "link": "https://www.bleepingcomputer.com/news/security/hackers-arrested-over-30m-bank-fraud-exploiting-service-provider-flaw/",
      "date": "2026-08-14T18:04:26.000Z",
      "source": "Bleeping Computer",
      "summary": "Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers' bank accounts…",
      "firstSeen": "2026-08-14T20:19:31.333Z"
    },
    {
      "id": "reporting-f9fa1931bdf6",
      "title": "Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI",
      "link": "https://www.darkreading.com/vulnerabilities-threats/ai-driven-bug-tsunami-nist-looks-to-ai",
      "date": "2026-08-14T17:32:46.000Z",
      "source": "Dark Reading",
      "summary": "Driven by AI-augmented research and scanning, vulnerability volumes continue to surge, driving the National Institute of Standards and Technology to ask whether AI could be the answer.",
      "firstSeen": "2026-08-14T20:19:31.333Z"
    },
    {
      "id": "reporting-9005f14ba897",
      "title": "IAM Compliance Requirements and Best Practices",
      "link": "https://thehackernews.com/2026/08/iam-compliance-requirements-and-best.html",
      "date": "2026-08-14T17:19:49.000Z",
      "source": "The Hacker News",
      "summary": "IAM compliance is the practice of demonstrating that identity and access controls are not only documented but actually enforced across users, applications, infrastructure, and non-human identities. This guide explains what IAM compliance requires, which regulations matter, and how organizations move from periodic access reviews toward continuous, evidence-backed verification that auditors can…",
      "firstSeen": "2026-08-17T12:53:03.224Z"
    },
    {
      "id": "reporting-9f7d0a43b985",
      "title": "Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office",
      "link": "https://www.darkreading.com/cyberattacks-data-breaches/scottish-govt-data-breach-prosecutors-office",
      "date": "2026-08-14T15:58:50.000Z",
      "source": "Dark Reading",
      "summary": "One Caledonian government agency reported a breach, thanks to a third party that may have serviced other agencies as well.",
      "firstSeen": "2026-08-14T20:19:31.333Z"
    },
    {
      "id": "reporting-f3d1727276b9",
      "title": "Hackers exploit macOS Screen Sharing flaw to deploy Monero miner",
      "link": "https://www.bleepingcomputer.com/news/security/hackers-exploit-macos-screen-sharing-flaw-to-deploy-monero-miner/",
      "date": "2026-08-14T14:59:55.000Z",
      "source": "Bleeping Computer",
      "summary": "The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged…",
      "firstSeen": "2026-08-14T20:19:31.333Z"
    },
    {
      "id": "reporting-4c9d6b022a5d",
      "title": "The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI",
      "link": "https://www.bleepingcomputer.com/news/security/the-modern-attack-chain-rethinking-google-workspace-security-in-the-age-of-ai/",
      "date": "2026-08-14T14:00:10.000Z",
      "source": "Bleeping Computer",
      "summary": "Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive, and connected systems. Material Security explains why organizations need defenses that cover the entire Workspace attack chain…",
      "firstSeen": "2026-08-14T20:19:31.333Z"
    },
    {
      "id": "reporting-f9f5eb360a33",
      "title": "What Boards Need to Know About Tech Risk",
      "link": "https://www.darkreading.com/cyber-risk/what-boards-must-know-tech-risk",
      "date": "2026-08-14T14:00:00.000Z",
      "source": "Dark Reading",
      "summary": "Why do so many boards underestimate technology risk until it becomes a crisis?",
      "firstSeen": "2026-08-14T20:19:31.333Z"
    },
    {
      "id": "reporting-99dadd313b8c",
      "title": "Max severity SAP Commerce Cloud flaw now targeted in attacks",
      "link": "https://www.bleepingcomputer.com/news/security/max-severity-sap-commerce-cloud-flaw-now-targeted-in-attacks/",
      "date": "2026-08-14T13:45:18.000Z",
      "source": "Bleeping Computer",
      "summary": "A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused…",
      "firstSeen": "2026-08-14T20:19:31.333Z"
    },
    {
      "id": "reporting-53b57e9b7662",
      "title": "Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth",
      "link": "https://thehackernews.com/2026/08/mustang-panda-adds-signed-windows.html",
      "date": "2026-08-14T13:08:56.000Z",
      "source": "The Hacker News",
      "summary": "The threat actor known as HoneyMyte (aka Mustang Panda) has been observed deploying an updated version of the CoolClient backdoor with a signed Windows kernel-mode rootkit that can hide and protect malicious processes, files, registry objects, and command-and-control (C2) network information. Russian cybersecurity vendor Kaspersky said it identified victims in Myanmar, Mongolia, Pakistan…",
      "firstSeen": "2026-08-17T12:53:03.224Z"
    },
    {
      "id": "reporting-5bfa349da239",
      "title": "Cyera's Oasis Security Buy Is All About AI Agent Control",
      "link": "https://www.darkreading.com/identity-access-management-security/cyera-oasis-security-acquisition-ai-agent-control",
      "date": "2026-08-14T12:17:21.000Z",
      "source": "Dark Reading",
      "summary": "The $1 billion deal aims to converge data security and identity into a single control plane for agents, with privileged access redefined around business context rather than static roles.",
      "firstSeen": "2026-08-14T20:19:31.333Z"
    },
    {
      "id": "reporting-ba32a4944ff6",
      "title": "Shell investigates 'potential incident' after Clop data theft claims",
      "link": "https://www.bleepingcomputer.com/news/security/shell-investigates-potential-incident-after-clop-data-theft-claims/",
      "date": "2026-08-14T11:55:45.000Z",
      "source": "Bleeping Computer",
      "summary": "Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data…",
      "firstSeen": "2026-08-14T20:19:31.333Z"
    },
    {
      "id": "reporting-669791ec854c",
      "title": "Who’s Tracking You? Use This New Service to Find Out",
      "link": "https://krebsonsecurity.com/2026/08/whos-tracking-you-use-this-new-service-to-find-out/",
      "date": "2026-08-14T11:24:35.000Z",
      "source": "Krebs on Security",
      "summary": "It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.",
      "firstSeen": "2026-08-14T20:19:31.333Z"
    },
    {
      "id": "reporting-815fb64a5a95",
      "title": "RingCentral data breach exposed info of 1.6 million accounts",
      "link": "https://www.bleepingcomputer.com/news/security/ringcentral-data-breach-exposed-info-of-16-million-accounts/",
      "date": "2026-08-14T10:52:05.000Z",
      "source": "Bleeping Computer",
      "summary": "The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned…",
      "firstSeen": "2026-08-14T20:19:31.333Z"
    },
    {
      "id": "reporting-de4f35c2e82c",
      "title": "Data analyst sent to prison for stealing data, extorting employer",
      "link": "https://www.bleepingcomputer.com/news/security/data-analyst-sent-to-prison-for-stealing-data-extorting-employer/",
      "date": "2026-08-14T08:27:18.000Z",
      "source": "Bleeping Computer",
      "summary": "A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme…",
      "firstSeen": "2026-08-14T10:07:49.994Z"
    },
    {
      "id": "reporting-df1d901c6dd9",
      "title": "Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks",
      "link": "https://www.bleepingcomputer.com/news/apple/apple-sends-new-threat-notification-alerts-over-mercenary-spyware-attacks/",
      "date": "2026-08-14T01:19:12.000Z",
      "source": "Bleeping Computer",
      "summary": "You're not alone if you just received an \"Apple Threat Notification\" saying it detected a \"mercenary spyware attack targeted at your iPhone.\"…",
      "firstSeen": "2026-08-14T02:20:20.962Z"
    },
    {
      "id": "reporting-2ef1deb56f00",
      "title": "Ukraine shuts down 94 fraudulent call centers, seize millions in cash",
      "link": "https://www.bleepingcomputer.com/news/security/ukraine-shuts-down-94-fraudulent-call-centers-seize-millions-in-cash/",
      "date": "2026-08-13T21:12:47.000Z",
      "source": "Bleeping Computer",
      "summary": "Authorities in Ukraine shut down 94 fraudulent call centers across the country that lured people into investment scams or tried to obtain access to bank accounts…",
      "firstSeen": "2026-08-13T21:51:18.396Z"
    },
    {
      "id": "reporting-7a20fee85e3d",
      "title": "Global Threat Campaign Hits Critical VMware vCenter Flaw",
      "link": "https://www.darkreading.com/vulnerabilities-threats/global-threat-campaign-critical-vmware-vcenter-flaw",
      "date": "2026-08-13T20:45:17.000Z",
      "source": "Dark Reading",
      "summary": "Exploitation against CVE-2026–59310 began earlier this month, and patching the vulnerability may not be enough to fully mitigate the threat.",
      "firstSeen": "2026-08-13T21:51:18.396Z"
    },
    {
      "id": "reporting-0d9304a57c79",
      "title": "'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft",
      "link": "https://www.darkreading.com/threat-intelligence/jewelbug-apt-state-espionage-cryptocurrency-theft",
      "date": "2026-08-13T10:00:00.000Z",
      "source": "Dark Reading",
      "summary": "Researchers discovered hackers-for-hire performing cyber espionage and financially motivated heists from the same Web panel.",
      "firstSeen": "2026-08-13T10:00:00.000Z"
    },
    {
      "id": "reporting-6ad3c57e750e",
      "title": "Belgium's eID Authentication Opens Citizen Accounts to RCE",
      "link": "https://www.darkreading.com/application-security/belgium-eid-authentication-citizen-accounts-rce",
      "date": "2026-08-13T07:00:00.000Z",
      "source": "Dark Reading",
      "summary": "The trust framework underlying Belgium's electronic ID system was fully compromised by severe vulnerabilities in a key browser extension, showcasing bigger problems with extensions in general.",
      "firstSeen": "2026-08-13T07:00:00.000Z"
    },
    {
      "id": "reporting-3c5ef5fa5324",
      "title": "Attackers Exploit SharePoint Authentication Bypass After Public PoC Release",
      "link": "https://thehackernews.com/2026/08/attackers-exploit-sharepoint.html",
      "date": "2026-08-13T06:09:48.000Z",
      "source": "The Hacker News",
      "summary": "Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from weak authentication. It was patched by Microsoft as part of its July 2026 Patch Tuesday updates. \"The authentication…",
      "firstSeen": "2026-08-13T06:09:48.000Z"
    },
    {
      "id": "reporting-5c0ecb74e8a5",
      "title": "Long-running Data Theft Campaign Targeting Salesforce, ServiceNow",
      "link": "https://www.darkreading.com/cyberattacks-data-breaches/long-running-data-theft-campaign-salesforce-servicenow",
      "date": "2026-08-12T21:08:54.000Z",
      "source": "Dark Reading",
      "summary": "The \"City-Forum\" campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling.",
      "firstSeen": "2026-08-12T21:08:54.000Z"
    },
    {
      "id": "reporting-3fd53cb513b8",
      "title": "Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor",
      "link": "https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html",
      "date": "2026-08-12T17:39:27.000Z",
      "source": "The Hacker News",
      "summary": "The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India. The activity, per Check Point Research, is part of Operation Dream Job, a long-running cyber espionage and…",
      "firstSeen": "2026-08-12T17:39:27.000Z"
    },
    {
      "id": "reporting-64f0c9a81850",
      "title": "Walmart Takes a 'Trusted Agent' Approach to Purple Teaming",
      "link": "https://www.darkreading.com/cybersecurity-operations/walmart-trusted-agent-approach-purple-teaming",
      "date": "2026-08-12T16:28:04.000Z",
      "source": "Dark Reading",
      "summary": "Walmart colocates red and blue teams to build trust and improve security through collaborative purple teaming exercises",
      "firstSeen": "2026-08-12T16:28:04.000Z"
    },
    {
      "id": "reporting-dc7fe6e1bf20",
      "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
      "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
      "date": "2026-08-12T14:09:50.000Z",
      "source": "The Hacker News",
      "summary": "A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure. The extensions, published across at least 40 Chrome Web Store developer accounts, racked up 75,486 installs. Of those identified, 274 have been found to impersonate 66…",
      "firstSeen": "2026-08-12T14:09:50.000Z"
    },
    {
      "id": "reporting-724af19cb2b3",
      "title": "Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition",
      "link": "https://www.darkreading.com/cyberattacks-data-breaches/ransomware-hits-colombian-justice-ministry-presidential-transition",
      "date": "2026-08-12T14:00:00.000Z",
      "source": "Dark Reading",
      "summary": "Attackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the increased activity across Latin America.",
      "firstSeen": "2026-08-12T14:00:00.000Z"
    }
  ]
}
