DOJ Secures Indictment of 17 Iranians Accused of ‘Massive’ Cyber Theft Campaign
The U.S. Department of Justice (DOJ) has unsealed an indictment charging 17 Iranian nationals accused of conducting a large-scale cyber-theft campaign on behalf of Iran’s Islamic Revolutionary Guard Corps. Prosecutors allege the Iran-based Mabna Institute targeted at least 144 U.S. universities, 178 foreign universities, 42 U.S. companies, government agencies, and nonprofit organizations, stealing more than 31Tb of academic research and intellectual property.
[ » Read full article ]
The Hill; Max Rego (August 18, 2026)
At Black Hat, AI Helped Security Pros Find Threats—and Create New Ones
At the recent Black Hat cybersecurity conference in Las Vegas, AI helped security teams detect, assess, and respond to threats more efficiently. The event’s Network Operations Center used AI-powered agentic triage to analyze thousands of network issues, automatically resolving most while leaving complex cases for human review. AI also contributed to new security risks, particularly through vibe coding. Security staff found some applications transmit sensitive information without TLS encryption, including home camera footage and phone calls to banks.
[ » Read full article ]
Fast Company; Rob Pegoraro (August 14, 2026)
Passenger Returning from DEF CON 34 Spoofs Delta Wi-Fi Network In-Flight
A passenger returning from DEF CON 34 allegedly disrupted a Delta flight's Wi-Fi, creating a fake “Delta WiFi Fast” hotspot that directed users to a phishing site designed to capture Google credentials. Pilots alerted ground crews and corporate security after detecting the interference, reportedly involving a Wi-Fi penetration-testing device. Delta said flight safety was never threatened and aircraft operating systems were unaffected.
[ » Read full article ]
Tom's Hardware; Jowi Morales (August 12, 2026)
Tiny Device Hacks Boeing 737 Flight Systems
At the USENIX Security Symposium, University of California San Diego researchers demonstrated that brief physical access to a Boeing 737 could allow an attacker to manipulate data exchanged between critical flight computers. Their proof-of-concept device exploited a legacy ARINC 429 communications interface, potentially altering flight-route information and data related to aircraft weight, balance, and temperature. Boeing was notified of the vulnerability in 2020 and later validated the findings in its laboratory.
[ » Read full article ]
Interesting Engineering; Aamir Khollam (August 13, 2026)
SIM Card Can Run Attacker Code Inside Modems
Researchers at the U.K.'s University of Birmingham and security firm Fuzzware found that malicious SIM cards can exploit a standardized modem feature called RUN AT to execute attacker-controlled commands on certain cellular IoT devices and phones. Tests of 26 devices found the capability enabled on nine of them. Researchers demonstrated code execution on a commercial EV charger and showed that one affected phone could be forced onto insecure 2G networks, though no attacks have been reported.
[ » Read full article ]
The Hacker News; Swati Khandelwal (August 12, 2026)
Flock Adds Privacy Guardrails to Camera Systems amid Backlash
Flock Safety is introducing new privacy safeguards for its automated license plate surveillance network amid growing concerns about law enforcement misuse and mass surveillance. The company will reduce its recommended default data retention period from 30 days to seven, although local agencies can choose longer periods. Cities also will gain greater control over when other agencies can access their camera data.
[ » Read full article ]
The Hill; Miranda Nazzaro (August 13, 2026)
U.S. Courts to Publish How Often the Government Uses Spyware
U.S. courts will begin publicly reporting how often judges authorize government use of spyware and hacking tools to intercept real-time communications. The Administrative Office of the U.S. Courts will add a “spyware/hacking” category to its 2028 Wiretap Report, to be published in 2029, providing the first nationwide count of such surveillance orders. The data will cover spyware used to intercept communications, but not remote searches of stored phone data.
[ » Read full article ]
TechCrunch; Lorenzo Franceschi-Bicchierai (August 14, 2026)
Albania Ranked the Most Cyber Secure Country
Albania was ranked first in the National Cyber Security Index, scoring 98.33 out of 100. Estonia’s e-Governance Academy assessed 155 countries across 49 indicators covering strategic, preventive, and responsive cybersecurity capabilities. Albania’s strong performance followed a major 2022 cyberattack that prompted sweeping legal reforms, centralized cyber defenses, and closer cooperation with international partners. Czechia was second in the ranking with a score of 98.33, while Canada and Estonia tied at 96.67, followed by Finland ranked at 95.83.
[ » Read full article ]
euronews; Indrabati Lahiri (August 12, 2026)
Inside Higher Ed (8/20) reports the University of Texas at San Antonio postponed its fall semester by three days after an attempted cyberattack. On Tuesday, UTSA President Taylor Eighmy announced the delay to Monday, Aug. 24, to allow time to restore technological services. Officials proactively took systems offline over the weekend and said their investigation found no evidence that data was accessed.
Tech Companies Call for Action Against AI-Powered Threats
More than 100 technology and cybersecurity companies are calling for closer cooperation between AI developers and governments to prepare for increasingly sophisticated AI-enabled cyberattacks. In a joint letter led by OpenAI Thursday, the companies warned traditional cybersecurity defenses will be inadequate as advanced AI models become better at identifying and exploiting digital vulnerabilities. The letter urged governments to coordinate and fund cyber defense programs, improve threat-intelligence sharing, and provide critical infrastructure operators with AI-powered security tools.
[ » Read full article ]
Politico; Pieter Haeck (August 27, 2026)
Federal Reserve, NASA, DOJ Among Victims of Chinese State-Sponsored Hackers
A Chinese state-sponsored hacking group targeted the U.S. Federal Reserve, the National Aeronautics and Space Administration (NASA), the U.S. Department of Justice (DOJ), and other federal bodies, according to newly unsealed court documents. The group allegedly operated hacking platforms that targeted critical infrastructure and sensitive networks, including hospitals, telecommunications providers, power companies, financial institutions, and defense contractors. The DOJ and the Federal Bureau of Investigation seized domains associated with the platforms and disabled their malicious software.
[ » Read full article ]
CNBC; Dan Mangan (August 26, 2026)
Trump Signs Executive Order on Foreign Equipment in U.S. Energy Infrastructure
U.S. President Trump on Wednesday signed an executive order declaring a national emergency to protect the U.S. bulk-power system from cybersecurity and national security threats. The executive order targets foreign-produced equipment, software, and digital systems determined to pose a significant national security risk, potentially prohibiting their acquisition, importation, transfer, or installation in U.S. power facilities. The move is largely driven by concerns that Chinese-made power equipment could contain vulnerabilities or backdoors enabling remote access.
[ » Read full article ]
CyberScoop; Tim Starks (August 26, 2026)
Security Weaknesses Found in Leading Open AI Models
An international team led by researchers at Canada’s University of Waterloo and non-profit AI security research group FAR.AI found security weaknesses in 21 widely used open-weight AI models. The researchers discovered that built-in safety protections could be removed through relatively simple tampering and fine-tuning, potentially allowing models to generate harmful content, facilitate sophisticated scams, spread disinformation, or provide dangerous instructions. The team also developed TamperBench, an open-source tool for systematically testing these vulnerabilities.
[ » Read full article ]
Waterloo News (Canada) (August 25, 2026)
Japan Outlines Measures to Protect Infrastructure from Cyberattacks
Japan drafted cybersecurity guidelines outlining 150 measures for businesses operating critical infrastructure. Covering 15 sectors, including finance, railways, electricity, and postal services, the guidelines warn that even closed networks can be vulnerable to cyberattacks. The guidelines urge companies to strengthen their recovery capabilities, prepare for system failures, obtain cybersecurity insurance, and avoid paying ransomware demands. The draft also recommends using advanced AI tools to counter increasingly sophisticated AI-driven attacks.
[ » Read full article ]
The Japan Times (August 24, 2026)
Sweden Sets 2036 Deadline for National Quantum Technology Strategy
Sweden unveiled its first national quantum technology strategy, setting goals through 2036 in various areas. The plan seeks to better connect universities, industry, government, and investors, while expanding skilled talent and financing for quantum startups. Cybersecurity is a major priority, with the government urging early adoption of post-quantum cryptography to protect against future quantum attacks and “harvest now, decrypt later” threats. The strategy also emphasizes partnerships with the U.S., EU, Nordic countries, and NATO.
[ » Read full article ]
Quantum Insider; Matt Swayne (August 24, 2026)
Iran-linked Hackers Blamed for Cyberattack That Shut Down U.K. Power Plant
The U.K. government cast blame on Iran-linked hackers for causing a British energy generator to shut down for four days in August. The government said the affected facility was a small-scale generator and that the incident posed no risk to the wider electricity system. British officials have warned that hostile states, including Iran, increasingly are targeting critical infrastructure. U.S. agencies have also warned of Iran-linked cyber campaigns against infrastructure.
[ » Read full article ]
The Guardian (U.K.); Ben Quinn (August 23, 2026)
CISA Orders Feds to Patch Actively Exploited TrueConf Server Flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) gave U.S. federal agencies until Sept. 3 to patch two TrueConf Server vulnerabilities being actively exploited. CVE-2026-72529 allows unauthenticated attackers to remotely execute arbitrary scripts, while CVE-2026-72530 can enable code injection, sandbox escape, and command execution on the underlying operating system. Cybersecurity firm Kaspersky reported the Head Mare hacktivist group has exploited the vulnerabilities since at least July, targeting Russian organizations and using compromised TrueConf installers to distribute backdoor malware.
[ » Read full article ]
BleepingComputer; Sergiu Gatlan (August 21, 2026)
U.S. Agencies Warn Hackers are Actively Attacking Siemens S7 PLCs in Critical Facilities
Several U.S. agencies warned that hackers are actively targeting Siemens S7 programmable logic controllers used across critical infrastructure. The attackers scan Internet-exposed devices, then use AI-assisted tools and open-source libraries to access PLC memory, configurations, and programs. Officials say the activity appears focused on reconnaissance and developing capabilities that could enable future disruption. Industries at risk include energy, water, manufacturing, chemicals, agriculture, and defense. The warning came following a string of cyber incidents at U.S. water utilities.
[ » Read full article ]
Cyber Security News; Guru Baran (August 20, 2026)
NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
Security researchers at Israeli software company Cycode found critical flaws in NASA Jet Propulsion Laboratory’s AIT-GUI software that could allow unauthenticated attackers to issue arbitrary commands to spacecraft and instruments. The vulnerabilities involve missing authentication, cross-origin request handling, and path traversal. AIT-GUI version 2.5.2 addresses several exposure and browser-based attack paths, but the researchers say it still allows credential-free session creation and does not fully resolve the underlying authentication weakness.
[ » Read full article *May Require Paid Registration ]
The Hacker News; Swati Khandelwal (August 20, 2026)
G7 Tells Industry to Prep for Post-Quantum Encryption
A cybersecurity working group at the Group of Seven (G7) is urging governments and businesses to accelerate preparations for post-quantum cryptography, warning that organizations can no longer treat quantum threats as a distant concern. In a report prepared in June at the G7 Summit in France, the group said quantum computers eventually could break widely used public-key encryption, compromise authentication systems, and expose sensitive data that attackers collect today for future decryption.
[ » Read full article ]
CyberScoop; Derek B. Johnson (September 3, 2026)
OpenAI hails ‘New Era of AGI’ with Astra Model Release
OpenAI president Greg Brockman described Astra, the company’s latest AI model, as a potential milestone in the development of artificial general intelligence (AGI). The company says Astra can tackle advanced mathematics, scientific research, health tasks, computer programming, and everyday activities, while demonstrating significantly stronger cybersecurity capabilities than earlier models. According to OpenAI, Astra was designed to decline “advanced cybersecurity tasks” that could create openings for malicious hackers.
[ » Read full article ]
The Guardian (U.K.); Robert Booth (September 3, 2026)
First Quantum-Resistant Bitcoin Transaction Mined
A researcher at Israeli software and cryptography company StarkWare mined the first Bitcoin transaction designed to resist future quantum-computer attacks, using a hashing-based system that works within Bitcoin’s existing rules without requiring a protocol change. The experiment demonstrates a potential emergency “escape hatch” for protecting vulnerable cryptocoins, but the approach is expensive, computationally intensive, and could be risky if quantum computers become powerful enough before funds are moved.
[ » Read full article ]
Gizmodo; Kyle Torpey (August 30, 2026)
Hackers Leak ATF Data, Exposing Investigations
The Russian-speaking Qilin ransomware group published about 6.3GB of data allegedly stolen from the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF), potentially exposing sensitive criminal investigations, phone records, account information, and digital forensic evidence. The ATF confirmed a breach of a standalone CALEA (Communications Assistance for Law Enforcement Act) system used for federally authorized electronic surveillance, but said its main enterprise network and eForms system had not been affected.
[ » Read full article ]
cybernews; Stefanie Schappert (August 31, 2026)
Rhysida Ransomware Group Targets Berlin Government Ahead of Vote
The German state of Berlin is facing a ransomware extortion attempt by the Rhysida group following an August cyberattack on its administrative network. Rhysida claims to have stolen 5.79 TB of data, including personal information, personnel files, financial records, credentials, and sensitive government documents, though the claims have not been independently verified. Berlin has refused to pay the ransom and says the September 20 state election remains secure, with no election-related data known to be compromised.
[ » Read full article ]
Security Affairs; Pierluigi Paganini (August 29, 2026)
Rowhammer Breaks NVIDIA ECC: Root Shell in Under Two Minutes Before Code Goes Public
Researchers at Canada's University of Toronto disclosed an attack that defeats NVIDIA’s recommended error-correcting code (ECC) protection against Rowhammer attacks on four Ampere workstation GPUs. The GPUThor attack can generate hundreds of thousands of memory bit flips per gigabyte, reducing the time needed to exploit GPU page tables and obtain a root shell on the host from nearly 22 hours to about 1.1 minutes.
[ » Read full article ]
Tech Times; Clayton Lewis (August 27, 2026)
CISA Scraps Free Cybersecurity Assessments for Critical Infrastructure Operators
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is ending six free cybersecurity assessments for critical infrastructure operators, including reviews focused on cyber resilience, ransomware readiness, incident management, supply-chain dependencies, and security controls. The assessments provided hands-on guidance from regional advisers using CISA’s Cyber Security Evaluation Tool to identify vulnerabilities and recommend improvements. The agency says it is retiring the services because of redundancy and plans to direct organizations toward its broader Cybersecurity Performance Goals.
[ » Read full article ]
Cybersecurity Dive; Eric Geller (September 3, 2026)
U.S. Launches Program to Secure Water Systems
The Trump administration has launched a six-month pilot providing free cybersecurity and AI tools to under-resourced Texas water utilities. The Project Watershed 250 program aims to identify vulnerabilities and strengthen defenses against growing cyber threats, including suspected attacks linked to Iran. Major technology and cybersecurity companies are contributing services, while federal and state government agencies are supporting implementation.
[ » Read full article ]
Axios; Sam Sabin (August 31, 2026)
Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE
Security researcher Olivier Laflamme disclosed two vulnerabilities in Unitree’s G1 EDU humanoid robot that can enable remote code execution with root privileges. CVE-2026-76639 exploits a path-traversal flaw to reach bashrunner and execute code on the robot’s Locomotion PC, while CVE-2026-76640 begins through Bluetooth Low Energy and ultimately exploits a buffer overflow in Wi-Fi provisioning. A cloud authorization weakness previously allowed accounts to obtain key material associated with other robots, although Unitree patched that issue in July.
[ » Read full article ]
The Hacker News; Swati Khandelwal (August 28, 2026)
DeepSeek ‘AI of Choice’ for China-linked Hackers
China-linked hackers increasingly are using DeepSeek and other open-source AI models to automate and scale cyberattacks, according to Taiwanese cybersecurity firm TeamT5. Researchers say state-affiliated groups have more than doubled their attack activity by delegating routine tasks to AI and using it to develop malicious software. DeepSeek is particularly popular because of its relatively strong performance, low operating costs, customization options, and weaker cybersecurity guardrails compared to many Western models. Hackers have used AI for reconnaissance, vulnerability exploitation, and other attack stages.
[ » Read full article ]
The Business Times (Singapore) (August 25, 2026)
German Law Criminalizes Security Defenders’ Tools While Attackers Operate Freely
Germany’s cybersecurity community is urging comprehensive reform of criminal laws that can expose legitimate security researchers to prosecution for possessing or using hacking tools. The Gesellschaft für Informatik, Germany's principal professional organization for computer scientists, says Section 202c of the Criminal Code can criminalize tools such as network scanners and vulnerability-testing software, potentially discouraging researchers from identifying vulnerabilities before attackers exploit them.
[ » Read full article ]
Tech Times; Jerry Owens (August 25, 2026)
GPS Malfunctioning Across Poland
Poland is experiencing increasingly frequent GPS and satellite-navigation disruptions, with widespread interference recorded on most days during May, June, and August 2026. The National Institute of Telecommunications attributes the disruptions to electronic warfare activity in the Baltic Sea region, with experts identifying the neighboring Russia seaport of Kaliningrad as a likely major source of jamming and spoofing. The interference is affecting smartphones, transportation systems, drones, shipping, and aviation, creating inaccurate positioning or loss of navigation signals.
[ » Read full article ]
euronews; Aleksandra Galka Reczko (August 25, 2026)
AI Burnout Hits Those Defending Hospitals, Banks from Hackers
AI is intensifying burnout among cybersecurity professionals as increasingly sophisticated attacks, AI-generated vulnerabilities, and growing security alerts overwhelm teams defending hospitals, banks, and other critical infrastructure. More than 60% of cybersecurity workers say their jobs are more stressful than they were two years ago, according to a recent report by the SANS Institute, with nearly half considering leaving their positions.
[ » Read full article *May Require Paid Registration ]
Bloomberg; Issie Lapowsky (August 31, 2026)