Latest news as of 8/14/2026, 11:43:40 AM
The Hacker News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-18577 (CVSS score: 8.2), is a case of incomplete patching for CVE-2026-18556 (CVSS score: 8.2) that allows
Dark Reading
Newer social engineering techniques help attackers ignore entrenched security controls and limit the evidence they leave behind.
The Register
Automates bug bounty triage with Sonnet for $58 a month, CSO says Mythos would cost $200k
Bleeping Computer
Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. [...]
Bleeping Computer
Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys to take over accounts, bypass user verification, and extract passkey private keys. [...]
Dark Reading
Over the weekend, the vendor discovered another vector of authentication bypass CVE-2026-18577 that gives attackers administrator access.
Dark Reading
Researchers dug into the root of the problem with the goal of promoting industry collaboration on improved protective measures.
Dark Reading
Last month's incidents in which Claude breached real-world systems derived from over-permissioning, especially with Internet access.
The Register
Poisoned pull requests contain prompt injection that allows one to control another
Bleeping Computer
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems. [...]