IT Security Newsletter

IT Security Newsletter - 8/14/2026

Written by Cadre | Fri, Aug 14, 2026

Private security firms will soon be allowed to hack overseas cybercriminals

The Trump administration is recruiting private security firms to conduct federal government-authorized operations, including cyberattacks, against overseas-based criminal organizations that commit hacks on US persons, organizations, or government entities. In a memorandum issued Thursday, US President Donald Trump directed the National Coordination Center (NCC) to develop a program for conducting specific cyber operations that combat foreign transnational criminal organizations (TCOs). READ MORE...

Crypto wallet maker Trezor confirms 13,000 customers' details exposed in logistics breach

Cryptocurrency hardware wallet maker Trezor has confirmed that a breach at one of its shipping partners exposed the personal data of more than 13,000 customers. The company's initial findings suggested the breach was limited to orders placed in certain countries during the previous 90 days. New information indicates that earlier orders may also be affected. The breach exposed the data of 11,742 customers who ordered Trezor products between May 10 and August 8. READ MORE...

RingCentral data breach exposed info of 1.6 million accounts

The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned. RingCentral is a cloud-based collaboration and communication platform used by over 600,000 businesses for services such as calling, messaging, and voicemail. The company disclosed the incident on July 28, revealing that its systems were compromised by a sophisticated social engineering campaign. READ MORE...

Over 1,000 Charities Hit by Beacon CRM Data Breach

UK-based customer relationship management (CRM) provider Beacon revealed this week the likely root cause of a recent data breach affecting many organizations. Beacon's CRM platform is designed for charities and other non-profit organizations to manage donors, supporters, volunteers, and related fundraising and service activities. The company revealed in early August that it had suffered a data breach in which hackers downloaded customer database backups. READ MORE...

Microsoft patches LegacyHive Windows zero-day vulnerability

Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday. The security flaw was disclosed by a security researcher who uses the "Nightmare Eclipse" handle in protest of Microsoft's bug bounty and vulnerability disclosure practices. Nightmare Eclipse published a LegacyHive proof-of-concept (PoC) exploit hours after the July 2026 Patch Tuesday security updates were released. READ MORE...

AI's 'middle class' has gotten dramatically better at hacking

As the White House and federal agencies grapple with frontier AI models and their hacking capabilities, researchers are warning that the industry's "middle class" of smaller models may end up posing a greater threat over the long term. Research from XBOW this week shows that a growing class of both proprietary and open-source models are becoming strategically important in the offensive security ecosystem. READ MORE...

AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

A multi-stage Rust-based macOS information stealer has been distributed through a counterfeit GitHub download page in recent ClickFix attacks. The fake download page lures victims into pasting a command into Terminal, which leads to the newly discovered AmnesiaStealer being installed. As part of a three-stage infection chain, a shell script runs to fetch and execute the payload, the infostealer harvests data, and a third module provides interactive control over the victims' browsers. READ MORE...

Who's Tracking You? Use This New Service to Find Out

It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and much of it has remained walled away in the hands of advertising platforms. Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you. READ MORE...

Ukrainian police raid 94 fraudulent call centers, seize $2 million

Ukrainian police have disrupted 94 fraudulent call centers during a nationwide operation that involved more than 400 searches and the seizure of thousands of computers, phones, and SIM cards. The call centers were linked to schemes involving callers impersonating bank employees, fraudulent investment services, cryptocurrency platforms, and attempts to gain remote access to victims' devices. Some groups collected personal information about prospective victims and shared or sold those records. READ MORE...

Global Threat Campaign Hits Critical VMware vCenter Flaw

A critical vulnerability in VMware vCenter came under heavy exploitation via a single threat actor just days after public disclosure. CVE-2026-59310 is a critical directory traversal flaw with a 9.8 CVSS score that VMware disclosed on July 29. According to VMware owner Broadcom, an attacker with network access to a vCenter instance can remotely exploit the vulnerability to execute arbitrary code in the target's virtual environment. READ MORE...

  • ...in 1935, President Franklin D. Roosevelt signs into law the Social Security Act.
  • ...in 1945, an official announcement of Japan's unconditional surrender to the Allies is made public to the Japanese people.
  • ...in 1994, terrorist Illich Ramirez Sanchez, long known as Carlos the Jackal, is captured in Sudan by French intelligence agents.
  • ...in 2003, a major outage knocked out power across the eastern United States and parts of Canada.