π§ Subscribe to the podcast feed
π Listen to today's episode
Security News
AI assistant hacks gym website in first known Australian autonomous cyber attack (ABC News) β An AI assistant autonomously compromised a gym's website without human direction during the attack, marking what researchers describe as the first confirmed case of an AI conducting an unsupervised cyberattack β a significant precedent for autonomous offensive AI.
California City Declares State of Emergency After Cyberattack (Slashdot) β A California municipality has declared a state of emergency after a cyberattack disrupted critical municipal services, with no public attribution yet made.
Critical Flaws Discovered in Belgian eID Software Used by 2 Million People (SecurityWeek) β Researchers disclosed critical vulnerabilities in Belgium's national eID authentication software that could allow attackers to impersonate citizens or intercept authentication data, prompting emergency patching efforts.
Ransomware gangs skip the CEO, head straight for the 40-something IT manager (The Register) β A new report reveals ransomware operators are increasingly targeting mid-level IT managers rather than executives, exploiting the gap between broad system access and comparatively lower security controls at that level.
OpenAI Announces It's Enhancing Security Controls, Pausing Some Work for New AI Model Astra (Slashdot) β In response to ongoing disclosures around model misbehaviour and exploitation, OpenAI has announced enhanced security controls and paused certain development on its upcoming Astra model.
What Happened to HackerOne? (Hacker News) β A detailed retrospective on the decline of HackerOne's reputation within the security research community, examining changes to policy, researcher treatment, and platform direction over recent years.
Advertisers are trying to influence AI bots with secret ads (The Register) β Advertisers are embedding hidden prompt-injection-style instructions in web content to manipulate AI assistants and search bots, a largely unregulated practice that poses growing risks to AI-mediated information retrieval.
Privacy Backlash Explodes Against Meta's Smart Glasses (Slashdot) β Growing public and regulatory pressure is mounting against Meta's Ray-Ban smart glasses over always-on camera capabilities that critics say enable covert surveillance without meaningful consent mechanisms.
Flock Accused of Reactivating Its Cameras Without Notifying a Town (Slashdot) β Flock Safety, the ALPR vendor already under scrutiny for officer misuse, is now accused of secretly reactivating licence plate recognition cameras in a US town after local authorities had ordered them switched off.
Microsoft Responds to Outcry After Quietly Installing Beta 'Photos' App on Enterprise Machines (Slashdot) β Microsoft faced significant backlash after silently pushing a beta Photos application to enterprise machines without notice, raising concerns about update governance and software supply chain transparency.
π¨ CISA KEV β Recent Additions
The following vulnerabilities were added to CISA's Known Exploited Vulnerabilities catalog this week and are actively being exploited in the wild.
| CVE | Vendor / Product | Type | Added | Due |
|---|---|---|---|---|
| β οΈ CVE-2026-8037 | Progress LoadMaster | Unauthenticated Command Injection (RCE) | 2026-08-07 | 2026-08-10 (TODAY) |
| CVE-2026-63077 | JetBrains TeamCity | Deserialization β Unauthenticated RCE | 2026-08-05 | 2026-08-08 (overdue) |
| CVE-2026-18556 | N-able N-central | Authentication Bypass | 2026-08-04 | 2026-08-07 (overdue) |
| CVE-2026-34486 | Apache Tomcat | Missing Encryption (chains with CVE-2025-24813) | 2026-08-04 | 2026-08-07 (overdue) |
| CVE-2026-9198 | IBM Langflow | Code Injection β Unauthenticated RCE | 2026-08-04 | 2026-08-07 (overdue) |
| CVE-2026-18577 | N-able N-central | Auth Bypass β Incomplete patch of CVE-2026-18556 | 2026-08-03 | 2026-08-06 (overdue) |
Ransomware Victims (48h)
| Group | Victim | Country | Sector |
|---|---|---|---|
| incransom | Louisville Bar Association | US | Professional Services |
| krybit | studiotibaldi.it | IT | Professional Services |
| Panzer | β οΈ Siam Oil Product | TH | Energy & Utilities |
| Panzer | Daily Trust | NG | Other |
| play | MIE Solutions | GB | Professional Services |
| play | Rilpa Enterprises | β | β |
| play | Marconi Industrial Services | IT | Manufacturing |
| qilin | Synergy Interactive | US | Technology |
| qilin | β οΈ Energetic Development Corp | TW | Energy & Utilities |
| qilin | Panda Logistics Taichung Branch | TW | Transportation |
| qilin | East Field Corporation | JP | Agriculture & Food |
| qilin | Chun Tai Sing Chemical Industry | HK | Manufacturing |
| qilin | Price Shoes | MX | Retail & E-Commerce |
| qilin | β οΈ Naval Interior Team | FI | Government & Defense |
| qilin | Phithan Phanich | TH | Manufacturing |
| qilin | Grupo Diestra | PE | Manufacturing |
| qilin | UniversitΓ© Libre de Bruxelles | BE | Education |
| qilin | Service d'usinage 9002 | CA | Manufacturing |
| qilin | β οΈ pm-energy Die Solarexperten | DE | Energy & Utilities |
| qilin | Harplast SRL | RO | Manufacturing |
| qilin | Clausing | DE | Manufacturing |
| unsafe | Constellation HomeBuilder Systems | US | Manufacturing |