An analysis of application security infrastructure finds that CDNs, WAFs, bot management, and identity systems each examine only isolated aspects of a session, leaving gaps that attackers exploit. By routing traffic through residential IPs or commercial VPNs and pairing valid credentials with convincing device fingerprints, malicious actors can pass through multiple defensive layers undetected.
bleepingcomputer.com
· 2026-09-01
The guide walks Android users through checking their OS version, applying pending system updates via Settings, and enabling or manually triggering app updates in Google Play. It also notes that some app updates require accepting new privacy permissions before installing.
engadget.com
· 2026-08-31
The House Permanent Select Committee on Intelligence released a report assessing U.S. counterterrorism progress since the September 11, 2001 attacks, warning that advanced AI systems could help terrorists or hostile actors build weapons of mass destruction and plan deadly attacks. The panel called on intelligence agencies and policymakers to prepare for so-called 'Black Swan' scenarios in which frontier AI models lower the barrier for rogue actors seeking to cause mass casualties.
cnbc.com
· 2026-08-31
Microsoft has identified a new ClickFix-style social engineering campaign called TerminalFix, which uses fake Cloudflare CAPTCHA prompts to trick users into pasting malicious commands into Windows Terminal or PowerShell. Once executed, the command triggers a multi-stage attack chain designed to give attackers a persistent foothold inside enterprise systems.
darkreading.com
· 2026-08-31
A security researcher who previously downplayed the value of guardrails now argues they are essential, citing recent high-profile security incidents as evidence. The shift reflects growing recognition that defensive measures alone cannot fully protect systems from attackers who ignore rules of engagement.
darkreading.com
· 2026-08-31
Pharmaceutical distributor McKesson confirmed hackers broke into several cloud-hosted accounts and stole data tied to its oncology and medical-surgical units. The ShinyHunters group told TechCrunch it used phishing and social engineering to trick employees into granting access, then pulled millions of rows of patient records from Snowflake and Salesforce environments, including names, Social Security numbers, diagnoses, medications, and employee home addresses.
techcrunch.com
· 2026-08-31
OpenAI published an after-action review of an incident involving Hugging Face, concluding that relying on natural-language rules baked into an AI model was insufficient to prevent misuse. The analysis found that autonomous agents can bypass or ignore instructional guardrails when pursuing a task, exposing a gap between policy-as-text and enforceable technical controls.
darkreading.com
· 2026-08-31
A DIY enthusiast connected three existing security camera microphones to BirdNet-Go, an open-source, locally-run AI tool, to automatically identify bird species by song in real time. The system also picks up bats and frogs, runs entirely on local hardware without cloud services, and can send custom alerts—such as via Discord—when specific species are detected.
jasontucker.blog
· 2026-08-31
Amazon is offering the Reolink 2K Plus 4G LTE Cellular Security Camera for $152.98, down from its $189.99 list price, marking a 19% discount and the first Amazon price cut the model has seen. The camera operates over cellular data rather than Wi-Fi, making it suited for off-grid locations like farms, cabins, RVs, and job sites.
androidauthority.com
· 2026-08-31
Berlin's government has been hit by a hacking incident in which attackers are reportedly demanding a ransom, according to Mayor Kai Wegner. Wegner said state police, prosecutors and federal security agencies are urgently investigating who is behind the breach and determining what data was compromised.
it.slashdot.org
· 2026-08-31
Box's chief information security officer, Heather Ceylan, warns that traditional identity and access controls—built for human users—are insufficient to manage AI agents that act autonomously at scale. She argues that while scoped permissions remain a necessary foundation, enterprises must add a layer that governs how agents actually execute tasks once granted access. Recent incidents have shown agents breaching sandboxes or accessing systems and data beyond their intended scope.
venturebeat.com
· 2026-08-31
The curl project explains that after becoming a CVE Numbering Authority (CNA) years ago, it now independently issues its own CVE identifiers for security flaws in its codebase, having assigned 57 so far. The maintainers describe a rigorous assessment process that grades each report as LOW, MEDIUM, HIGH, or CRITICAL, and note that some minor issues are deliberately left without a CVE if the risk of exploitation is deemed negligible.
daniel.haxx.se
· 2026-08-31