Security Feed Digest (2026-08-20)
Hacker News: Best
- Aaron Swartz was prosecuted for scraping, while Meta does it without consequence — Thu, 20 Aug 2026 20:07:26 +0000
- Watching TikTok and Instagram deactivates the cognitive control network: Study — Thu, 20 Aug 2026 18:54:32 +0000
- Malicious Rust crate Arrayref runs a build-time payload — Thu, 20 Aug 2026 13:23:12 +0000
- Show HN: I trained a 125M model to autocomplete piano on-device — Thu, 20 Aug 2026 12:04:38 +0000
- AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint — Thu, 20 Aug 2026 10:08:52 +0000
- Don’t paste the AI, please — Thu, 20 Aug 2026 08:20:44 +0000
- Windows brings out the Rorschach test in everyone (2003) — Thu, 20 Aug 2026 06:16:40 +0000
- Turns are Better than Radians (2022) — Thu, 20 Aug 2026 01:29:12 +0000
- CIA funding helped keep NeXT afloat in the 80s — Thu, 20 Aug 2026 00:15:01 +0000
- Feature Request: Support AGENTS.md — Wed, 19 Aug 2026 21:19:50 +0000
- Unsloth Dynamic 3.0 GGUFs — Wed, 19 Aug 2026 18:36:45 +0000
- Google has stopped pushing Git tags for some Android source code — Wed, 19 Aug 2026 17:47:29 +0000
- Casio F-B100W-1A — Wed, 19 Aug 2026 15:28:01 +0000
- HTML Can Do That — Wed, 19 Aug 2026 15:11:36 +0000
- PostgreSQL for Everything — Wed, 19 Aug 2026 13:21:21 +0000
- Air Theremin – A browser theremin you play by waving at your webcam — Wed, 19 Aug 2026 10:15:00 +0000
- fx :Tiny, open, native coding agent. — Tue, 18 Aug 2026 22:00:21 +0000
BleepingComputer
- Hackers poison arrayref Rust crate to push infostealer malware — Thu, 20 Aug 2026 13:53:52 -0400
- Critical Elementor Pro bug exposes WordPress sites to RCE attacks — Thu, 20 Aug 2026 10:39:48 -0400
- How MSPs can catch phishing attacks email filters miss — Thu, 20 Aug 2026 10:01:11 -0400
- Citrix urges admins to patch new NetScaler flaws as soon as possible — Thu, 20 Aug 2026 08:14:38 -0400
- CISA warns of hackers exploiting critical MLflow vulnerability — Thu, 20 Aug 2026 07:06:14 -0400
- New Manic Android malware can exfiltrate data through nearby devices — Thu, 20 Aug 2026 06:02:02 -0400
- Critical Zimbra RCE flaw now actively exploited in attacks — Thu, 20 Aug 2026 05:46:54 -0400
- Microsoft says August Windows updates may cause gaming issues — Thu, 20 Aug 2026 02:51:03 -0400
- OpenAI confirms ChatGPT is down as logins and signups fail — Wed, 19 Aug 2026 20:20:55 -0400
Darkreading
- Calling on Cyber Pros to Help Defend City Hall — Fri, 21 Aug 2026 14:00:00 GMT
- New CUSTODY Framework Constrains AI Agents Inside the Network — Thu, 20 Aug 2026 20:42:18 GMT
- What We Missed: Delta Flight Disrupted With Wi-Fi Hack — Thu, 20 Aug 2026 19:11:15 GMT
- N-able Bug Exposes Password Vault Master Keys — Thu, 20 Aug 2026 17:39:24 GMT
- Money and Mindset: The Two Biggest Roadblocks to Cyber Policing — Thu, 20 Aug 2026 17:32:51 GMT
- Pakistan’s Transparent Tribe Refreshes Toolset for Afghan Cyberattacks — Thu, 20 Aug 2026 14:59:22 GMT
- ‘Grandoreiro’ Malware Resurfaces With Mexico Campaign — Thu, 20 Aug 2026 13:30:00 GMT
- Agentic AI Presents New Insider Threat Model for Orgs — Wed, 19 Aug 2026 19:54:43 GMT
The Hacker News
- Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads — Fri, 21 Aug 2026 01:52:35 +0530
- Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts — Fri, 21 Aug 2026 01:29:19 +0530
- ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More — Thu, 20 Aug 2026 22:53:48 +0530
- AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure — Thu, 20 Aug 2026 22:29:44 +0530
- New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data — Thu, 20 Aug 2026 20:06:27 +0530
- Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE — Thu, 20 Aug 2026 19:18:24 +0530
- Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers — Thu, 20 Aug 2026 19:05:13 +0530
- Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution — Thu, 20 Aug 2026 18:54:28 +0530
- Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments — Thu, 20 Aug 2026 17:31:24 +0530
- Why “Shady AI” is Security’s Next Big Governance Problem — Thu, 20 Aug 2026 17:15:00 +0530
- CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification — Thu, 20 Aug 2026 17:09:35 +0530
- Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices — Thu, 20 Aug 2026 16:56:08 +0530
- NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands — Thu, 20 Aug 2026 16:35:11 +0530
- ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud — Thu, 20 Aug 2026 16:08:28 +0530
- 40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets — Thu, 20 Aug 2026 14:12:03 +0530
- Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code — Thu, 20 Aug 2026 11:34:34 +0530
데일리시큐 - 최근인기기사
- 과기정통부·KISIA, 차세대 사이버보안 인재 발굴…정보보호 경진대회 성료 — 2026-08-20 07:20:32
- 오픈AI, 최신 AI 강화학습 2주간 중단…“사이버 공격 능력 커지자 안전장치 강화” — 2026-08-20 08:46:10
- [단독] 6월 드러난 ‘포티블리드’, 두 달 지난 지금도 위험…국내서도 1,167개 연관 IP 확인 — 2026-08-20 18:48:47
- [CISO 조찬] 김창훈 대구대 교수 “AI 시대 보안, 사람 중심 룰 관리로는 한계…지능형 통제로 전환해야” — 2026-08-20 19:26:16
- 김선희 전 국정원 3차장 “AI 시대 사이버안보…기술 아닌 국가 전략 차원 대응 필요” — 2026-08-20 18:27:33
- [인터뷰] 엄수창 데이터독 지사장 “AI 시대 보안 핵심은 에이전트 권한 통제와 가시성…운영·보안 통합해야” — 2026-08-20 17:47:39
- 인티큐브, 신한투자증권 IP 컨택센터(IPCC) 시스템 재구축 사업 착수 — 2026-08-20 15:16:10
- [CISO 조찬] 김호원 스마트엠투엠 대표 “외산 초거대 AI 의존 한계…폐쇄망용 특화 보안 AI 필요” — 2026-08-20 23:51:32
- [김승주 교수 칼럼] 정부의 보안내재화 정책이 공염불이 되지 않으려면 — 2026-08-20 23:56:36
- 안드로이드 뱅킹 악성코드 진화…스마트폰 안에서 송금까지 조작한다 — 2026-08-21 00:30:19