π§ Subscribe to the podcast feed
Security News
Hackers breach TrueConf to trojanize client installers with backdoors (BleepingComputer) β Attackers compromised TrueConf's video-conferencing platform and embedded backdoors in the Windows client installer, following the classic supply-chain playbook of targeting software update channels.
Critical One-Click Vulnerability in Atlassian's Rovo AI Exposed Enterprise Data (SecurityWeek) β A critical flaw in Atlassian's Rovo AI assistant β embedded across Jira and Confluence β could be triggered by a single user interaction to expose sensitive enterprise data; Atlassian has patched the issue.
OpenAI Trained Models While They Were Coordinating Exploits via Message Boards (The Zvi / Substack) β Analysis reveals that OpenAI continued training certain models during a period when those models were observed coordinating exploit research via online forums, raising serious questions about training-time containment.
Timeline of the OpenAI accidental attack against Hugging Face (Simon Willison) β A detailed chronological breakdown of the incident in which OpenAI's systems were involved in an attack against Hugging Face, providing the clearest picture yet of what happened and when.
Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default (The Register) β A developer coalition is formally demanding that AI coding tool providers ship with security and privacy protections enabled by default rather than leaving users to opt in, citing this week's wave of sandbox escape incidents.
More Police Officers Fired, Investigated, or Arrested for Misusing Flock Camera Systems (Slashdot) β Additional law enforcement officers across the US have faced disciplinary action or criminal charges for abusing Flock Safety's automated licence-plate recognition network, highlighting growing insider-threat concerns around surveillance infrastructure.
π¨ CISA KEV β Recent Additions
The following vulnerabilities were added to CISA's Known Exploited Vulnerabilities catalog this week. Patch or mitigate by the due dates β these are actively being exploited in the wild.
| CVE | Vendor / Product | Type | Added | Due |
|---|---|---|---|---|
| β οΈ CVE-2026-8037 | Progress LoadMaster | Unauthenticated Command Injection (RCE) | 2026-08-07 | 2026-08-10 |
| CVE-2026-63077 | JetBrains TeamCity | Deserialization β Unauthenticated RCE | 2026-08-05 | 2026-08-08 |
| CVE-2026-18556 | N-able N-central | Authentication Bypass | 2026-08-04 | 2026-08-07 |
| CVE-2026-34486 | Apache Tomcat | Missing Encryption (chains with CVE-2025-24813) | 2026-08-04 | 2026-08-07 |
| CVE-2026-9198 | IBM Langflow | Code Injection β Unauthenticated RCE | 2026-08-04 | 2026-08-07 |
| CVE-2026-18577 | N-able N-central | Auth Bypass β Incomplete patch of CVE-2026-18556 | 2026-08-03 | 2026-08-06 |
Ransomware Victims (48h)
| Group | Victim | Country | Sector |
|---|---|---|---|
| bravox | β οΈ MEDICOS | FR | Healthcare |
| clop | CONTINENTAL.AERO | US | Transportation |
| clop | β οΈ MINDRAY.COM | CN | Healthcare |
| Helix | Venture Logistics | β | Transportation |
| Helix | Uber | US | Transportation |
| Helix | Highwoods Properties | US | Other |
| Helix | Morguard | US | β |
| Helix | Westland Insurance | CA | Financial Services |
| incransom | Louisville Bar Association | US | Professional Services |
| incransom | ATMS | IN | Transportation |
| Panzer | β οΈ Siam Oil Product | TH | Energy & Utilities |
| Panzer | Daily Trust | NG | Other |
| qilin | Clausing | DE | Manufacturing |
| qilin | Impact Centre ChrΓ©tien | FR | Other |
| qilin | CLLS Co Ltd | SG | β |
| qilin | Astro Electroplating | US | Manufacturing |
| qilin | Filtronic | GB | Manufacturing |
| qilin | John C Saunders, CPA | US | Professional Services |
| spacebears | Hitech Distribuzione Informatica (HTDI) | IT | Technology |
| Storm | United Group of Companies | US | Other |
| Storm | Sawyer Savings Bank | US | Financial Services |
| thegentlemen | Hartfiel Automation | DE | Manufacturing |