ICYMI: 2026-08-21
Latest Headlines
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Microsoft Defender’s Own Driver Can Be Weaponized to Delete Security Software at Boot
Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution
Former NSA Director Paul Nakasone Launches National Security Advisory Firm
In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug
Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini
New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets
Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind
CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities
Claude Mythos 5 Now Available in Claude Security for Vulnerability Scanning
Microsoft Expands Mailbox Storage From 50 GB to 100 GB for Users
Scammers Use WhatsApp Groups to Coordinate Millions in Victim Trades and Pump Real Stocks
Chinese Hackers Use AI Agents to Exploit Web Servers and Automate Attacks
Hackers Hide Agent Tesla JScript Behind Unicode Emojis to Evade Detection
Claude Opus 5 Routes Around Obfuscated Binaries Instead of Defeating the Protection
Critical WordPress Plugin Vulnerability Exposes Sites to RCE Attacks
Critical GitLab Code Injection Vulnerability Actively Exploited in Attacks
US Bank Investigating Data Breach Following LockBit Ransomware Claim
Critical N-able Passportal Flaw Lets Malicious Websites Steal Entire Password Vault and 2FA Codes
New SynkLoader malware pushed in Microsoft Teams phishing campaign
Hundreds of leaked AWS keys give full control over corporate accounts
Microsoft blames Windows gaming issues on RGB lighting devices
Microsoft rolls out Classic Outlook theme for New Outlook users
CISA orders feds to patch actively exploited TrueConf Server flaws
Microsoft warns of max severity Entra ID flaw exploited in attacks
Hackers abuse FTP server banners to deliver new Windows malware
SickKids data breach exposes employee and job applicant info
– MTZ