Cybersecurity news from across the internet
Cybersecurity news from across the internet

This week, EFF, along with Big Brother Watch, Defend Digital Me, Liberty, Open Rights Group, Race Equality First, Statewatch, and Stopwatch, wrote to Nottinghamshire Police Force in the UK raising concern about the propo…

More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. [...]




BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive
Identity Abuse Through Trusted Communication Channels
[0day-rubbish] VMS 6.48.809 Authenticated command injection to root RCE (8.8)
[0day-rubbish] ONE Reporter 13.1 Authenticated RCE / privilege escalation via CommandExecutor (8.8)
VU#756733: Calix GS7 XGS GS5239XG residential router contains missing authentication vulnerability
Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st)
ISC Stormcast For Friday, August 21st, 2026 https://isc.sans.edu/podcastdetail/10062, (Fri, Aug 21st)
Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays, (Fri, Aug 21st)
Zombie Card: An expired Visa credit card can be used for purchases
Report: Vishing and Device Code Phishing Are Surging
Medical records, SSNs, and bank details exposed in CareCloud data breach
Securing the Tip of the Spear: Guam’s Path to Human and AI Resilience