Security news

Latest security news

Mon, 31 Aug 2026

  1. Healthcare cyberattacks hit pacemakers and millions of patient records

    McKesson admits breach as ShinyHunters demands $55.2M

    The Register
  2. Anthropic Users Hit by Infostealer Attacks, Session Thefts

    A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.

    Dark Reading
  3. 'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks

    The ClickFix-style campaign features a sophisticated, multistage attack chain that includes reverse tunnels into victim organizations' networks.

    Dark Reading
  4. The Guardrails Debate: Security Researcher Changes His Mind

    While guardrails are critical, as evidenced by recent high-profile incidents, defenders need help staying ahead of attackers who do not play by the rules.

    Dark Reading
  5. The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary, (Mon, Aug 31st)

    One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide "free" LLM backends. It then received a real coding-agent session — history, filesystem output, working paths, and the agent's local tool manifest. The honeypot did not request or cause any tool execution; what the request exposed is what a malicious operator in that position could do.

    SANS Internet Storm Center
  6. OpenClaw 2.0 pours glitter on slow-burning security dumpster fire

    Making installation easier and putting a new wrapper on the interface while leaving most of the security to users is a recipe for more trouble with the popular agent harness

    The Register
  7. WatchGuard security advisory (AV26-865)

    Serial Number: AV26-865 Date: August 31, 2026 As of August 27, 2026, WatchGuard is affected by vulnerabilities in the following products: Dimension Prior to 2.3.1 Fireware OS Prior to 12.12.2 Prior to 12.5.20 Prior to 2026.2.2 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. WatchGuard Security Advisories

    Canadian Centre for Cyber Security
  8. Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines

    Next-level ClickFix wave sets off multi-stage attack chain

    The Register
  9. AI Model Rules Are Not Security Controls

    OpenAI's Hugging Face attack postmortem shows agents don't care about rules — they need strong controls.

    Dark Reading

About this news

1,383
Stories
78
Added in the last 24 hours
10
Critical in the last 7 days
4
Reported by several outlets