{
  "schema_version": 2,
  "issue_date": "2026-08-18",
  "generated_at": "2026-08-18T21:28:22.838Z",
  "insight_context": {
    "schema_version": 2,
    "mode": "current",
    "checked_at": "2026-08-18T21:28:21.389Z",
    "report_date": "2026-08-18",
    "manifest_generated_at": "2026-08-18T18:55:02Z",
    "report_url": "https://ricomanifesto.github.io/SentryInsight/"
  },
  "articles": [
    {
      "id": "reporting-cd21e9704a97",
      "title": "'CoSnitch' Attack Tricked Copilot into Mapping Out Architecture",
      "link": "https://www.darkreading.com/vulnerabilities-threats/cosnitch-attack-copilot-mapping-out-architecture",
      "date": "2026-08-18T20:17:24.000Z",
      "source": "Dark Reading",
      "summary": "Researchers discovered a \"meta-hacking\" technique that can manipulate the AI service into revealing its own security weaknesses.",
      "firstSeen": "2026-08-18T21:28:21.953Z"
    },
    {
      "id": "reporting-6ffb3f471f4f",
      "title": "Comcast turns your Xfinity WiFi into a home motion detector",
      "link": "https://www.bleepingcomputer.com/news/security/comcast-turns-your-xfinity-wifi-into-a-home-motion-detector/",
      "date": "2026-08-18T20:14:58.000Z",
      "source": "Bleeping Computer",
      "summary": "Comcast is promoting WiFi-based motion detection as a part of its new Xfinity Shield home protection platform, allowing routers and wireless devices to detect people moving through a home without cameras or motion sensors…",
      "firstSeen": "2026-08-18T21:28:21.953Z"
    },
    {
      "id": "reporting-2da9958060b2",
      "title": "CISOs Break Their Silence in 'Declassified' Docuseries",
      "link": "https://www.darkreading.com/cyber-risk/cisos-break-their-silence-in-declassified-docuseries",
      "date": "2026-08-18T18:32:01.000Z",
      "source": "Dark Reading",
      "summary": "Million-dollar heists, divorce, and career-ending burnout are all stories told in the latest docuseries revealing a behind-the-scenes look at the cybersecurity community.",
      "firstSeen": "2026-08-18T21:28:21.953Z"
    },
    {
      "id": "reporting-3db875d507ea",
      "title": "Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps",
      "link": "https://thehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html",
      "date": "2026-08-18T17:47:22.000Z",
      "source": "The Hacker News",
      "summary": "Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copilot session. The flaws, which the researchers collectively named CoSnitch, turn in part on an undocumented URL parameter that the assistant itself surfaced…",
      "firstSeen": "2026-08-18T18:45:42.782Z"
    },
    {
      "id": "reporting-c960f83a4e1f",
      "title": "Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets",
      "link": "https://thehackernews.com/2026/08/attackers-exploit-mlflow-ssrf-flaw-to.html",
      "date": "2026-08-18T17:44:05.000Z",
      "source": "The Hacker News",
      "summary": "Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation efforts. According to independent reports from watchTowr and VulnCheck, the vulnerabilities in question are as follows -…",
      "firstSeen": "2026-08-18T18:45:42.782Z"
    },
    {
      "id": "reporting-851d3dad3622",
      "title": "Clop created custom web shell for Windchill data theft attacks",
      "link": "https://www.bleepingcomputer.com/news/security/clop-created-custom-web-shell-for-windchill-data-theft-attacks/",
      "date": "2026-08-18T17:29:51.000Z",
      "source": "Bleeping Computer",
      "summary": "A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files…",
      "firstSeen": "2026-08-18T18:45:42.782Z"
    },
    {
      "id": "reporting-ee1a3760dd26",
      "title": "Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000",
      "link": "https://thehackernews.com/2026/08/ransom-busters-claims-it-hacked.html",
      "date": "2026-08-18T16:58:16.000Z",
      "source": "The Hacker News",
      "summary": "A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000. \"In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous,\" GuidePoint Research…",
      "firstSeen": "2026-08-18T18:45:42.782Z"
    },
    {
      "id": "reporting-a83ffd80f6bb",
      "title": "Your Controls Block Known Attacks. What About the Behavior?",
      "link": "https://www.bleepingcomputer.com/news/security/your-controls-block-known-attacks-what-about-the-behavior/",
      "date": "2026-08-18T14:01:11.000Z",
      "source": "Bleeping Computer",
      "summary": "Security controls can block a familiar attack method while missing quieter ways to achieve the same objective. Picus Security's Blue Report 2026 shows how prevention rates can vary dramatically by technique and why behavioral testing is needed to uncover those gaps…",
      "firstSeen": "2026-08-18T15:38:09.147Z"
    },
    {
      "id": "reporting-f626add06be0",
      "title": "Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud",
      "link": "https://www.darkreading.com/cloud-security/silent-twinloot-threat-operates-microsoft-cloud",
      "date": "2026-08-18T13:00:00.000Z",
      "source": "Dark Reading",
      "summary": "The Python-based malware framework takes living-off-the-land tactics to a new heights of stealth, with a modular implant that steals credentials and achieves persistence.",
      "firstSeen": "2026-08-18T15:38:09.147Z"
    },
    {
      "id": "reporting-1f616d071c66",
      "title": "'Ransom Busters': Ransomware Actor Poses as Incident-Recovery Service",
      "link": "https://www.darkreading.com/cyberattacks-data-breaches/ransom-busters-ransomware-actor-incident-recovery-service",
      "date": "2026-08-18T13:00:00.000Z",
      "source": "Dark Reading",
      "summary": "A ransomware affiliate appears to be sidling up to victims with offers of aid, masking its true intention of diverting ransom payments.",
      "firstSeen": "2026-08-18T15:38:09.147Z"
    },
    {
      "id": "reporting-31ec7c38c09a",
      "title": "AI \"Mind Viruses\" Can Spread Between Agents Through Persistent Prompt Files",
      "link": "https://thehackernews.com/2026/08/ai-mind-viruses-can-spread-between.html",
      "date": "2026-08-18T12:38:36.000Z",
      "source": "The Hacker News",
      "summary": "Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that autonomous agent harnesses use to carry state between sessions. The work, released as a preprint on August 10, 2026, tests the technique in a simulated six-agent coding…",
      "firstSeen": "2026-08-18T15:38:09.147Z"
    },
    {
      "id": "reporting-77045d80f7ad",
      "title": "TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks",
      "link": "https://thehackernews.com/2026/08/twinloot-abuses-sharepoint-and-teams-to.html",
      "date": "2026-08-18T12:38:20.000Z",
      "source": "The Hacker News",
      "summary": "Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. \"TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services,\" Ontinue said in a technical report shared with The Hacker News. \"Tasking flows through SharePoint Online file…",
      "firstSeen": "2026-08-18T15:38:09.147Z"
    },
    {
      "id": "reporting-6f9e97f4de86",
      "title": "One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025",
      "link": "https://thehackernews.com/2026/08/one-attacker-has-scraped-both.html",
      "date": "2026-08-18T11:30:00.000Z",
      "source": "The Hacker News",
      "summary": "A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco. The activity, which Reco has named the City Forum campaign after a domain tied to the attacker's IP address, traces back to one server: 158.220.87.79, hosted on a…",
      "firstSeen": "2026-08-18T12:55:11.783Z"
    },
    {
      "id": "reporting-baa27ed0fe16",
      "title": "16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets",
      "link": "https://thehackernews.com/2026/08/16-typosquatted-rubygems-packages-steal.html",
      "date": "2026-08-18T11:20:00.000Z",
      "source": "The Hacker News",
      "summary": "Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part of the campaign is below - ubnuler ubnlder ri18nr reaker rakier orakw joxn…",
      "firstSeen": "2026-08-18T12:55:11.783Z"
    },
    {
      "id": "reporting-d154f9dab0f4",
      "title": "Microsoft tests faster Windows File Explorer, new context menu",
      "link": "https://www.bleepingcomputer.com/news/microsoft/microsoft-tests-faster-windows-explorer-customizable-context-menu/",
      "date": "2026-08-18T11:14:28.000Z",
      "source": "Bleeping Computer",
      "summary": "Microsoft has started testing a faster File Explorer and a less cluttered and more customizable context menu in Windows 11 preview builds rolling out to Insiders this week…",
      "firstSeen": "2026-08-18T12:55:11.783Z"
    },
    {
      "id": "reporting-8d518de522f4",
      "title": "CISA: Windows Task Host flaw now exploited by ransomware gangs",
      "link": "https://www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs/",
      "date": "2026-08-18T10:32:16.000Z",
      "source": "Bleeping Computer",
      "summary": "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April…",
      "firstSeen": "2026-08-18T12:55:11.783Z"
    },
    {
      "id": "reporting-727e9dd4d812",
      "title": "Microsoft confirms outage affecting search in Microsoft 365 apps",
      "link": "https://www.bleepingcomputer.com/news/microsoft/microsoft-working-to-fix-bug-behind-microsoft-365-search-issues/",
      "date": "2026-08-18T09:24:49.000Z",
      "source": "Bleeping Computer",
      "summary": "Microsoft says some users are experiencing issues searching in Microsoft 365 apps, including Outlook on the web, Outlook desktop, SharePoint Online, and OneDrive…",
      "firstSeen": "2026-08-18T09:37:45.746Z"
    },
    {
      "id": "reporting-5e10185b7da2",
      "title": "SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers",
      "link": "https://thehackernews.com/2026/08/safepal-hardware-wallet-maker-says-flaw.html",
      "date": "2026-08-18T09:10:45.000Z",
      "source": "The Hacker News",
      "summary": "SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware wallet maker said all affected customers were notified individually by email on August 16 from security@safepal.com, with the subject line \"[Important] Your SafePal Order…",
      "firstSeen": "2026-08-18T09:37:45.746Z"
    },
    {
      "id": "reporting-25a892e0e074",
      "title": "Microsoft starts removing WMIC tool used by cybercriminals",
      "link": "https://www.bleepingcomputer.com/news/microsoft/microsoft-removes-wmic-lolbin-tool-in-windows-11-beta-builds/",
      "date": "2026-08-18T08:12:08.000Z",
      "source": "Bleeping Computer",
      "summary": "Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week…",
      "firstSeen": "2026-08-18T09:37:45.746Z"
    },
    {
      "id": "reporting-c8f5936ef6e3",
      "title": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE",
      "link": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html",
      "date": "2026-08-18T06:34:20.000Z",
      "source": "The Hacker News",
      "summary": "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Ray is an open-source, Python-native distributed computing framework designed to scale artificial intelligence and machine learning workloads. As of writing, the GitHub project has more than…",
      "firstSeen": "2026-08-18T09:37:45.746Z"
    },
    {
      "id": "reporting-41f91fb7fcb0",
      "title": "Video Call Exploit Chains Two Flaws in Unisoc Modems",
      "link": "https://www.darkreading.com/mobile-security/video-call-exploit-chains-two-flaws-unisoc-modems",
      "date": "2026-08-17T21:37:23.000Z",
      "source": "Dark Reading",
      "summary": "Researchers found that by combining two vulnerabilities, they could take over an Android device by delivering a payload and getting the victim to answer their phone.",
      "firstSeen": "2026-08-18T01:27:46.351Z"
    },
    {
      "id": "reporting-7ed54789e434",
      "title": "Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects",
      "link": "https://thehackernews.com/2026/08/critical-gitlab-graphql-flaw-could-let.html",
      "date": "2026-08-17T21:03:04.000Z",
      "source": "The Hacker News",
      "summary": "GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4. Released on…",
      "firstSeen": "2026-08-17T21:30:25.492Z"
    },
    {
      "id": "reporting-9b6a27ccd9dd",
      "title": "'Turf War' Between Claude Agents Leads to Self-Replicating Malware",
      "link": "https://www.darkreading.com/threat-intelligence/turf-war-claude-agents-self-replicating-malware",
      "date": "2026-08-17T20:26:34.000Z",
      "source": "Dark Reading",
      "summary": "Three testing models with the same goal but different directives engaged in \"increasingly aggressive\" territorial attacks on one another, according to Anthropic.",
      "firstSeen": "2026-08-18T01:27:46.351Z"
    },
    {
      "id": "reporting-51cdb8f86fcc",
      "title": "Hacker claims 3.6 million Azure account records stolen from major companies",
      "link": "https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/",
      "date": "2026-08-17T19:35:01.000Z",
      "source": "Bleeping Computer",
      "summary": "A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials…",
      "firstSeen": "2026-08-17T21:30:25.492Z"
    },
    {
      "id": "reporting-0c65fb83c27f",
      "title": "Hugging Face Breach Raises Big Questions About AI Security Controls",
      "link": "https://www.darkreading.com/vulnerabilities-threats/adam-shostack-talks-hugging-face-phantom-b",
      "date": "2026-08-17T19:22:56.000Z",
      "source": "Dark Reading",
      "summary": "Adam Shostack, president of Shostack & Associates and an affiliate professor at the University of Washington, talks with the Dark Reading News Desk about why he was \"blown away\" by OpenAI's revelations regarding the Hugging Face attack.",
      "firstSeen": "2026-08-17T21:30:25.492Z"
    },
    {
      "id": "reporting-e4644ae7413d",
      "title": "Pokémon Center data breach exposes customer info, cancels some orders",
      "link": "https://www.bleepingcomputer.com/news/security/pokemon-center-data-breach-exposes-customer-info-cancels-some-orders/",
      "date": "2026-08-17T19:12:39.000Z",
      "source": "Bleeping Computer",
      "summary": "Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics…",
      "firstSeen": "2026-08-17T21:30:25.492Z"
    },
    {
      "id": "reporting-499cd8c9d623",
      "title": "Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection",
      "link": "https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets_0330881554.html",
      "date": "2026-08-17T18:44:17.000Z",
      "source": "The Hacker News",
      "summary": "Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credentials. The issue was present in .github/workflows/jira_issue.yml, which ran when a…",
      "firstSeen": "2026-08-17T21:30:25.492Z"
    },
    {
      "id": "reporting-b83af1627135",
      "title": "Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads",
      "link": "https://thehackernews.com/2026/08/forminator-wordpress-flaw-can-enable.html",
      "date": "2026-08-17T18:22:09.000Z",
      "source": "The Hacker News",
      "summary": "A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites. The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out of 10.0 on the CVSS scoring system. It was discovered and reported by a security researcher who goes by the online alias \"…",
      "firstSeen": "2026-08-17T21:30:25.492Z"
    },
    {
      "id": "reporting-788b4d9b4fc1",
      "title": "Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic",
      "link": "https://thehackernews.com/2026/08/cavern-c2-uses-dns-and-google-apps.html",
      "date": "2026-08-17T17:41:06.000Z",
      "source": "The Hacker News",
      "summary": "Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian cybersecurity company Kaspersky said its ongoing monitoring of the threat activity cluster since December 2025 has led to the discovery of previously unreported components that expand the…",
      "firstSeen": "2026-08-17T21:30:25.492Z"
    },
    {
      "id": "reporting-31464e819e00",
      "title": "Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS",
      "link": "https://www.darkreading.com/cyber-risk/linux-botnet-evooo1bot-mirai-capabilities-beyond-ddos",
      "date": "2026-08-17T15:44:34.000Z",
      "source": "Dark Reading",
      "summary": "The botnet adds exploitation modules, credential theft, and reverse SOCKS relays to turn compromised devices into persistent attacker infrastructure.",
      "firstSeen": "2026-08-17T18:45:46.718Z"
    },
    {
      "id": "reporting-854ad5325b12",
      "title": "Microsoft confirms GitHub is down worldwide",
      "link": "https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-github-is-down-worldwide/",
      "date": "2026-08-17T14:47:08.000Z",
      "source": "Bleeping Computer",
      "summary": "GitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other services…",
      "firstSeen": "2026-08-17T18:45:46.718Z"
    },
    {
      "id": "reporting-c7510fc0ce5f",
      "title": "Certighost and the Privilege Hiding in Your Certificate Authority",
      "link": "https://www.bleepingcomputer.com/news/security/certighost-and-the-privilege-hiding-in-your-certificate-authority/",
      "date": "2026-08-17T14:00:10.000Z",
      "source": "Bleeping Computer",
      "summary": "CVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing privilege, implicit trust, and treating PKI as the Tier 0 identity infrastructure it has always been…",
      "firstSeen": "2026-08-17T18:45:46.718Z"
    },
    {
      "id": "reporting-74a4bb0aafac",
      "title": "⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More",
      "link": "https://thehackernews.com/2026/08/weekly-recap-vmware-exploits-windows-0.html",
      "date": "2026-08-17T13:23:51.000Z",
      "source": "The Hacker News",
      "summary": "The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than the original compromise. A lot of it came down to access that was already there and defenses that assumed nobody would look too closely. So, nothing magical. Just a…",
      "firstSeen": "2026-08-17T18:45:46.718Z"
    },
    {
      "id": "reporting-47cc0c0a3276",
      "title": "Windows Server 2022 reaches end of mainstream support in 60 days",
      "link": "https://www.bleepingcomputer.com/news/microsoft/windows-server-2022-reaches-end-of-mainstream-support-in-60-days/",
      "date": "2026-08-17T12:33:11.000Z",
      "source": "Bleeping Computer",
      "summary": "Microsoft has reminded IT administrators that Windows Server 2022 is rapidly approaching its mainstream end date of October 2026, when it will switch to extended support…",
      "firstSeen": "2026-08-17T12:53:03.224Z"
    },
    {
      "id": "reporting-5ab36643acff",
      "title": "How MCP Servers Can Expose Enterprise Secrets",
      "link": "https://thehackernews.com/2026/08/how-mcp-servers-can-expose-enterprise.html",
      "date": "2026-08-17T11:58:00.000Z",
      "source": "The Hacker News",
      "summary": "MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running. As more organizations adopt AI agents into their systems, that exposure can silently become a major gap in MCP server security. The Model Context Protocol (MCP) allows AI agents to reach the tools and data…",
      "firstSeen": "2026-08-17T12:53:03.224Z"
    },
    {
      "id": "reporting-1982bb8549d6",
      "title": "Philips and GE investigating Clop ransomware data theft claims",
      "link": "https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims/",
      "date": "2026-08-17T11:25:02.000Z",
      "source": "Bleeping Computer",
      "summary": "Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data…",
      "firstSeen": "2026-08-17T12:53:03.224Z"
    },
    {
      "id": "reporting-797946889533",
      "title": "Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access",
      "link": "https://thehackernews.com/2026/08/unisoc-volte-video-call-exploit-chain.html",
      "date": "2026-08-17T10:52:34.000Z",
      "source": "The Hacker News",
      "summary": "Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the chipset maker. The advisory, published August 17, 2026, is the second stage of a chain that began in March 2026, when SSD disclosed remote code execution in the…",
      "firstSeen": "2026-08-17T12:53:03.224Z"
    },
    {
      "id": "reporting-651dff2e0053",
      "title": "French tax authority data breach affects 678,000 individuals",
      "link": "https://www.bleepingcomputer.com/news/security/french-tax-authority-data-breach-affects-678-000-individuals/",
      "date": "2026-08-17T10:09:48.000Z",
      "source": "Bleeping Computer",
      "summary": "The French Ministry of the Economy and Finance has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems and stole data belonging to 678,000 individuals…",
      "firstSeen": "2026-08-17T12:53:03.224Z"
    },
    {
      "id": "reporting-7637e999c644",
      "title": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies",
      "link": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html",
      "date": "2026-08-17T09:29:55.000Z",
      "source": "The Hacker News",
      "summary": "Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies. \"While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including…",
      "firstSeen": "2026-08-17T12:53:03.224Z"
    },
    {
      "id": "reporting-9da7db7cc2a6",
      "title": "Microsoft working on Defender patch for ShieldBreak zero-day",
      "link": "https://www.bleepingcomputer.com/news/security/microsoft-working-on-defender-patch-for-shieldbreak-zero-day/",
      "date": "2026-08-17T09:05:33.000Z",
      "source": "Bleeping Computer",
      "summary": "Microsoft is working on a security patch for the \"ShieldBreak\" zero-day vulnerability disclosed last week by security researcher \"Nightmare Eclipse\" and now tracked as CVE-2026-69414…",
      "firstSeen": "2026-08-17T09:47:51.905Z"
    },
    {
      "id": "reporting-f632e57bed8c",
      "title": "Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware",
      "link": "https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html",
      "date": "2026-08-17T07:36:19.000Z",
      "source": "The Hacker News",
      "summary": "Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a malicious actor to execute arbitrary code…",
      "firstSeen": "2026-08-17T12:53:03.224Z"
    },
    {
      "id": "reporting-847da71208bc",
      "title": "SafePal data breach impacts 39,798 customers, stolen info for sale",
      "link": "https://www.bleepingcomputer.com/news/security/safepal-data-breach-impacts-39-798-customers-stolen-info-for-sale/",
      "date": "2026-08-16T23:47:06.000Z",
      "source": "Bleeping Computer",
      "summary": "Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data…",
      "firstSeen": "2026-08-17T01:37:21.686Z"
    },
    {
      "id": "reporting-0748ca510918",
      "title": "Anthropic confirms Claude is down in major outage affecting multiple services",
      "link": "https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-confirms-claude-is-down-in-major-outage-affecting-multiple-services/",
      "date": "2026-08-16T22:28:57.000Z",
      "source": "Bleeping Computer",
      "summary": "Claude is experiencing a major outage, with users reporting login problems and degraded performance across several Anthropic services…",
      "firstSeen": "2026-08-17T01:37:21.686Z"
    },
    {
      "id": "reporting-6565f6821662",
      "title": "Large-scale DDoS attacks disrupted Threema secure messaging service",
      "link": "https://www.bleepingcomputer.com/news/security/large-scale-ddos-attacks-disrupted-threema-secure-messaging-service/",
      "date": "2026-08-16T17:29:52.000Z",
      "source": "Bleeping Computer",
      "summary": "Multiple distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service earlier this week, causing severe disruptions to communications…",
      "firstSeen": "2026-08-16T18:35:07.143Z"
    },
    {
      "id": "reporting-0a6826eb0448",
      "title": "New AmnesiaStealer macOS malware hijacks browser sessions via remote control",
      "link": "https://www.bleepingcomputer.com/news/security/new-amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control/",
      "date": "2026-08-16T15:07:44.000Z",
      "source": "Bleeping Computer",
      "summary": "A new information-stealing malware called AmnesiaStealer, which targets macOS users via ClickFix attacks, includes a streaming module that allows the attacker to interactively control the victim's web browser…",
      "firstSeen": "2026-08-16T15:26:08.407Z"
    },
    {
      "id": "reporting-2ef1bbe49955",
      "title": "New Evooo1Bot Linux botnet turns routers into traffic relay nodes",
      "link": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/",
      "date": "2026-08-15T14:14:38.000Z",
      "source": "Bleeping Computer",
      "summary": "A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes…",
      "firstSeen": "2026-08-15T18:32:45.611Z"
    },
    {
      "id": "reporting-32f4f04d99f8",
      "title": "SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch",
      "link": "https://thehackernews.com/2026/08/sap-commerce-cloud-cve-2026-58231.html",
      "date": "2026-08-15T08:38:46.000Z",
      "source": "The Hacker News",
      "summary": "A maximum-severity security vulnerability impacting SAP Commerce Cloud is witnessing active exploitation efforts. The vulnerability, tracked as CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It relates to an instance of insufficient authorization checks and input validation. \"SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit…",
      "firstSeen": "2026-08-17T12:53:03.224Z"
    },
    {
      "id": "reporting-b90ffb4f7f9b",
      "title": "Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner",
      "link": "https://thehackernews.com/2026/08/apple-macos-screen-sharing-flaw.html",
      "date": "2026-08-15T07:24:04.000Z",
      "source": "The Hacker News",
      "summary": "A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC-NL) has warned. The vulnerability in question is CVE-2026-65400 (CVSS score: 9.8), a critical authentication issue impacting the Screen Sharing component that could allow an attacker already on the network to…",
      "firstSeen": "2026-08-17T12:53:03.224Z"
    },
    {
      "id": "reporting-adf27a5de8bb",
      "title": "How Anthropic plans to watermark Claude's AI-generated text",
      "link": "https://www.bleepingcomputer.com/news/artificial-intelligence/how-anthropic-plans-to-watermark-claudes-ai-generated-text/",
      "date": "2026-08-14T23:24:17.000Z",
      "source": "Bleeping Computer",
      "summary": "It could soon become easier to identify AI-generated content, even if it's not the usual \"It's Not X, it's Y\" type of post you'd come across on LinkedIn and other socials…",
      "firstSeen": "2026-08-15T01:29:05.754Z"
    },
    {
      "id": "reporting-4ae5bf990f47",
      "title": "Mission-Driven Security: Inside a Global Bank's Defense",
      "link": "https://www.darkreading.com/cybersecurity-operations/mission-driven-security-inside-global-bank-defense",
      "date": "2026-08-14T19:24:18.000Z",
      "source": "Dark Reading",
      "summary": "In this video interview, Standard Chartered's group CISO shares insights on transitioning from technical roles to strategic leadership, the importance of business-savvy security executives, and how AI is reshaping both defensive capabilities and adversarial tactics in banking.",
      "firstSeen": "2026-08-14T20:19:31.333Z"
    }
  ]
}
