Security News

Curated cybersecurity news and emerging threats relevant to startups, SMBs, and growing teams.

Industry news, vulnerability disclosures, compliance updates, and threat intelligence—handpicked for relevance to your environment.

Each item includes our perspective on why it matters to your security posture.

Cybersecurity News Digest — August 24, 2026

Iran-linked hackers force a UK power plant offline for four days, a critical CVSS 9.3 authentication bypass hits Citrix NetScaler ADC and Gateway, and a third-party software flaw exposes SickKids Hospital employee data back to 2016.

Read source →

Cybersecurity News Digest — August 23, 2026

Check Point weaponizes Microsoft Defender's own boot-time driver for kernel access, 9,300+ leaked AWS keys are still valid years later, Sakura Internet discloses a 1.36M-account breach, and a ransomware actor poses as a recovery firm.

Read source →

Cybersecurity News Digest — August 22, 2026

Five U.S. agencies warn of AI-generated exploit scripts hitting Siemens S7 PLCs, CISA adds an actively exploited MLflow SSRF flaw to its KEV catalog, and a Rust supply-chain attack poisoned three widely used crates with build-time malware.

Read source →

Cybersecurity News Digest — August 21, 2026

A CVSS 10.0 pre-auth flaw in Microsoft Entra ID was exploited before Microsoft's silent fix, CISA flags two actively exploited TrueConf Server bugs tied to trojanized installers, and a Copilot Personal flaw let one click exfiltrate connected accounts.

Read source →

Cybersecurity News Digest — August 20, 2026

CISA adds four actively exploited flaws in Apple macOS, SharePoint, VMware vCenter, and Windows IKE to its KEV catalog, a Heights Finance breach exposes Social Security numbers for 1.2 million loan customers, and a healthcare data breach at CareCloud grows to 3.7 million patient records.

Read source →

Cybersecurity News Digest — August 19, 2026

A cyberattack forces UT San Antonio to delay its fall semester for 42,000 students, a SafePal order-tracking flaw exposes nearly 40,000 crypto customers, and Questel confirms a vishing-driven Microsoft 365 breach ShinyHunters says yielded 21 million records.

Read source →

Cybersecurity News Digest — August 18, 2026

GitLab ships an emergency patch for an unauthenticated GraphQL flaw that could wipe public projects, a pre-auth RCE hits 600,000 Forminator WordPress sites, Pokémon Center notifies UK and German shoppers after a logistics-vendor breach, and an unfixed Unisoc modem flaw hands over Android kernel access through a video call.

Read source →

Cybersecurity News Digest — August 17, 2026

GeoServer finally ships a fix for its actively exploited SQL injection zero-day, a dark-web seller is auctioning Azure-tenant employee records from McDonald's and Vodafone, Clop names Shell among 43 new Windchill victims, and a hacktivist group trojanizes TrueConf installers with a custom backdoor.

Read source →

Cybersecurity News Digest — August 16, 2026

SAP Commerce Cloud's max-severity flaw and an unpatched GeoServer zero-day are both under active attack, a patched macOS Screen Sharing bug is already mining Monero, RingCentral's ShinyHunters data lands in HIBP, and Apple's spyware alerts hit 110 countries.

Read source →

Cybersecurity News Digest — August 15, 2026

A SharePoint JWT auth-bypass chain is under active exploitation with 8,500+ servers exposed, Beacon CRM's breach traces back to a leaked AWS key in public JS code, Claude watermark removers flood GitHub within days of rollout, and the EU's privacy watchdog pushes back on Europol's data-power expansion.

Read source →