The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience. “Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store… Read More "DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt"
CISA Details Incident Response to Exposed AWS GovCloud Keys
The US Cybersecurity and Infrastructure Security Agency (CISA) has detailed its response to internal CISA Amazon AWS GovCloud Keys and other information being made available in a public repository. The reaction came after KrebsOnSecurity detailed in May how a security researcher with GitGuardian… Read More "CISA Details Incident Response to Exposed AWS GovCloud Keys"
OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber
OpenAI on Monday announced a new cybersecurity-focused AI model named GPT-5.6-Cyber, as well as the expansion of its Daybreak Cyber Partner program. The AI giant says GPT-5.6-Cyber is designed for “advanced, authorized cybersecurity work”. Built on GPT-5.6-Sol, the new model… Read More "OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber"
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
Swati KhandelwalAug 11, 2026Vulnerability / Enterprise Security Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an… Read More "Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE"
Metabase SQLi exploit grants attackers total access
Metabase said that after it discovered the attack, it immediately blocked the exploited endpoints, patched the vulnerability, terminated relevant sessions, and revoked credentials used in the incident. Metabase Cloud customers have already been upgraded and patched against the vulnerability, but… Read More "Metabase SQLi exploit grants attackers total access"
Ransomware Groups Increasingly Deploy EDR Kill Techniques
Shutting down endpoint detection and response (EDR) tools before encryption begins has become standard operating procedure across the ransomware ecosystem, analysis of attacks by researchers at Halcyon has warned. The practice, sometimes called EDR-kill, was once considered a specialist capability.… Read More "Ransomware Groups Increasingly Deploy EDR Kill Techniques"
What is Vulnerability Remediation? | UpGuard
The “patch everything” model has become technically and operationally unsustainable for mid- to large-scale organizations. Today’s security teams navigate an environment where thousands of new CVEs are published monthly, necessitating a shift from reactive, point-in-time scanning to a disciplined remediation… Read More "What is Vulnerability Remediation? | UpGuard"
US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’
Federal lawmakers and cybersecurity leaders have launched parallel initiatives to protect US water infrastructure from growing cyber threats, combining new federal legislation with a grassroots defense project for local utilities. Senators Adam Schiff (D-Calif.) and Amy Klobuchar (D-Minn.) introduced the… Read More "US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’"
Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee’s Client
Swati KhandelwalAug 11, 2026Vulnerability / Software Security Anyone sharing their screen on a Zoom call could have taken over the computers of everyone watching, and anyone watching could have taken over the presenter’s. The flaw sat in the annotation tool,… Read More "Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee’s Client"
Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability
Advice for CSOs For CSOs, the primary strategic priority should be reducing the window of exposure around CVE-2026-68820, because exploitation is already occurring, Bicer said. CVE-2026-62832 should follow closely, because it is publicly disclosed and assessed as more likely to… Read More "Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability"