A detailed timeline of 108 cyber attacks from 1-15 August 2026, with charts on motivations, attack vectors, initial access, sectors, and target countries.
US charges Russian for infecting 80,000 freelancers with malware
A California federal grand jury has indicted a Russian national for his role in a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware.
I navigatori ottimizzano il viaggio del singolo, ma quando tutti seguono la stessa logica l’effetto si ribalta: il traffico si concentra, le emissioni aumentano e il costo dell’efficienza individuale ricade sulla città.
Infostealer contro Claude: le sessioni rubate consumano credito, Anthropic rimborsa
Un infostealer diffuso tramite software pirata ruba le sessioni attive del browser per accedere agli account Claude e consumarne il credito. Anthropic disattiva le sessioni compromesse, rimuove le carte salvate e rimborsa gli addebiti non autorizzati
Manchester Airports Group - 8,728,451 breached accounts
In August 2026, Manchester Airports Group (MAG) disclosed a data breach impacting their services. The incident was later claimed by the FulcrumSec hacking group, who subsequently published email addresses and phone numbers relating to 8.7M customers of Manchester, Stansted and East Midlands airports. The data contained personal information relating to airport services, including vehicle registrations and parking history, Fast Track purchases and lounge bookings. In their disclosure notice, MAG advised that "at no point has passenger safety or aviation security been compromised".
Sality botnet infrastructure dismantled in joint global takedown
International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet.
La geopolitica della fiducia tra alleati: cosa rende obsoleto lo spionaggio nell’era AI
Dall'arresto di Biwei Zhang alle manovre di contro-intelligence al quartier generale NATO a Mons: l'infiltrazione umana ad alta tecnologia smantella la blindatura burocratica dei nulla osta. Ecco perché threat intelligence, vertici aziendali e decisori politici devono ripensare la difesa degli asset strategici e le relazioni di fiducia tra alleati
Key Takeaways The DFIR Report Offerings Check out our Products here and our Services here. Want a demo, more information on our services, pricing or just want to chat? Get in Touch Contact us today for pricing or a demo! Case Summary In March 2026, our team identified an SEO poisoning campaign leading to malware deployment […]
Hackers abuse Faronics Deploy admin tool to install ScreenConnect
Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software.
Critical Langflow flaw exploited to steal OpenAI and AWS keys
Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys.
Claude supera i confini dei test: Anthropic rallenta e ripensa la sicurezza dell’AI
Dopo gli incidenti in cui alcuni modelli Claude hanno raggiunto sistemi reali durante test cyber, Anthropic ha sospeso parte delle valutazioni e rafforzato sandbox, monitoraggio e controlli. Il caso mostra perché la sicurezza dell'AI agentica non può dipendere da un'unica barriera
Hackers push malicious Virtualizor update in BGP hijacking attack
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers.
Novocure data breach affects more than 1,400 cancer patients
Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack.
Why Even the Best Edge Security Still Misses High-Risk Sessions
Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations identify risky sessions and make stronger enforcement decisions.
China-Linked Fire Ant Turned Cisco Routers, TACACS Servers Into Espionage Platforms
The China-nexus espionage group Fire Ant has moved from compromising virtualization platforms to implanting Cisco IOS XR routers and TACACS authentication servers.
Il tuo nuovo sviluppatore lavora per Pyongyang: i rischi dell’onboarding remoto
Un attaccante non deve violare la rete se può farsi assumere come sviluppatore, ricevere un laptop aziendale e ottenere credenziali valide. Le infiltrazioni di lavoratori IT nordcoreani mostrano il punto cieco dell’onboarding remoto: la cybersecurity autentica dispositivi e accessi, ma troppo spesso presume l’identità della persona