# internet of things (blogs) — RSS Amplifier

Recent posts from the 13 feeds in the RSS Amplifier directory that cover internet of things.

Page: <https://rssamplifier.com/topics/internet-of-thing/blogs>  
Feed: <https://rssamplifier.com/topics/internet-of-thing/blogs.md>

---

## [Australian Police Charge Two Over TeamPCP Credential Theft](https://securityaffairs.com/197929/security/two-arrests-one-supply-chain-attack-and-a-lot-of-stolen-credentials.html)

_2026-08-27 · Pierluigi Paganini · Security Affairs_

Australian police charged two men linked to TeamPCP over malware hidden in open-source code that stole 500,000+ credentials from 1,000+ organizations. Australian police have charged two men from Western Australia over a global cybercrime operation that allegedly hid malicious code in open-source software and used it to steal data from thousands of organisations. “Two West \[…\]

## [Meta to Pay Up to $18B Over Teen Social Media Use](https://securityaffairs.com/197914/laws-and-regulations/meta-to-pay-up-to-18b-over-teen-social-media-use.html)

_2026-08-27 · Pierluigi Paganini · Security Affairs_

Meta will pay up to $18B and cap teen Facebook and Instagram use at two hours daily after nearly all US states sued over child safety. Meta will pay up to $18 billion over the next decade and impose real usage limits on teenagers using Facebook and Instagram, settling claims that the company deliberately designed \[…\]

## [CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do](https://securityaffairs.com/197891/ics-scada/cisa-warns-water-utilities-find-your-exposed-plcs-before-attackers-do.html)

_2026-08-27 · Pierluigi Paganini · Security Affairs_

CISA urges water utilities to find and secure internet-exposed PLCs after July attacks showed how easily exposed industrial systems can be compromised. Over 100 internet-exposed systems in the US water and wastewater sector got hit by cyberattacks in July 2026, and CISA’s response wasn’t just an incident report, it was a how-to guide for making \[…\]

## [OpenAI banned Russian ChatGPT accounts backing covert influence operation](https://securityaffairs.com/197878/intelligence/openai-banned-russian-chatgpt-accounts-backing-covert-influence-operation.html)

_2026-08-27 · Pierluigi Paganini · Security Affairs_

OpenAI banned Russian ChatGPT accounts backing a fake think tank, IBI, that used AI posts and a fake “sovereignty” index to push pro‑Russia narratives. OpenAI says it has banned a cluster of ChatGPT accounts that likely originated in Russia and were used to support a covert influence operation. The campaign promoted an organisation called the \[…\]

## [CISA Red Team Fully Compromised Two Critical Infrastructure Orgs](https://securityaffairs.com/197901/hacking/cisa-red-team-fully-compromised-two-critical-infrastructure-orgs.html)

_2026-08-26 · Pierluigi Paganini · Security Affairs_

CISA red teams fully compromised two critical infrastructure orgs. One SOC isolated hosts in minutes; the other never detected the breach. CISA published an advisory (AA26-237A) documenting two simultaneous red team assessments at critical infrastructure organizations. Both organizations lost full domain control and had their cloud environments compromised. One of them didn’t know until CISA \[…\]

## [FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure](https://securityaffairs.com/197873/apt/fbi-seizes-china-linked-hacking-platforms-qscan-and-qtrouter-used-against-critical-infrastructure.html)

_2026-08-26 · Pierluigi Paganini · Security Affairs_

FBI seizes QScan and QTRouter, China-linked platforms used to hide intrusions and target U.S. critical infrastructure. The U.S. Department of Justice and the FBI have seized two platforms, QScan and QTRouter, used by a China-linked group to hide cyberattacks and target critical infrastructure. The operation matters because it shows how state-backed actors no longer need \[…\]

## [Estate planning of credentials](https://www.pentestpartners.com/security-blog/estate-planning-of-credentials/)

_2026-08-26 · Alex Wallace · Pen Test Partners_

A sad start Last year one of my colleagues, Ken, received the sad news that a father of a friend had passed away. He was a tech-savvy gentleman and had invested in smart tech to make his and his family’s life easier and, just as we recommend, he used strong and unique passwords everywhere. He stored all his passwords in an encrypted Excel spreadsheet… the \[…\] The post Estate planning of…

## [U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/197854/security/u-s-cisa-adds-gitea-flaw-to-its-known-exploited-vulnerabilities-catalog.html)

_2026-08-26 · Pierluigi Paganini · Security Affairs_

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Gitea flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-60004 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Gitea is an open-source platform…

## [88 ID Verification Breaches Show the Cost of Collecting Identity Data](https://securityaffairs.com/197855/reports/88-id-verification-breaches-show-the-cost-of-collecting-identity-data.html)

_2026-08-26 · Pierluigi Paganini · Security Affairs_

88 ID-verification breaches exposed billions of records, highlighting the growing risks of collecting sensitive identity and biometric data. A new report from Mysterium VPN compiles 88 documented incidents since 2011 where data collected specifically to verify someone’s identity or age got breached, exposed, or sold. The confirmed and researcher-verified total sits at 2.15 billion records, \[…\]

## [WhatsApp Adds Stronger Security as Passkeys Hit 1 Billion](https://securityaffairs.com/197837/security/whatsapp-adds-stronger-security-as-passkeys-hit-1-billion.html)

_2026-08-26 · Pierluigi Paganini · Security Affairs_

WhatsApp says 1 billion users now use passkeys, while stronger two-step verification and caller context add new layers of account protection. WhatsApp has reached a significant security milestone: more than one billion people now use passkeys to protect access to their accounts. At the same time, Meta is adding stronger two-step verification and more information \[…\]

## [AI QA That Opens Fix PRs (Sponsored)](https://crawlproof.com/a/6xIMQRK9NiPD)

_2026-08-26 · **Sponsored**_

Runs browser QA, files issues with repro evidence, and opens fix PRs.

## [Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams](https://securityaffairs.com/197843/cyber-crime/operation-jackal-58-arrests-expose-the-money-laundering-machine-behind-global-scams.html)

_2026-08-26 · Pierluigi Paganini · Security Affairs_

INTERPOL’s Operation Jackal IV made 58 arrests and exposed global networks laundering money from scams, fraud and sextortion. INTERPOL announced that Operation Jackal IV, running from November 2025 to June 2026, led to 58 arrests and identified 263 suspects tied to West African organized crime networks, groups like Black Axe that are responsible for a \[…\]

## [Water’s Song](https://vividcomm.com/2026/08/26/waters-song/)

_2026-08-26 · M.J. Martin · Vividcomm_

Reading Time: 5 minutes “A water leak is more than lost water. It is infrastructure making music beneath our feet. The quiet hiss, vibration and rhythm of escaping water become a song that, when we learn to listen, tells us exactly where the system needs our attention.” – MJ Martin The Hidden Music Beneath Canadian Streets A municipal water \[…\]

## [Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack](https://securityaffairs.com/197826/cyber-warfare-2/norway-s-digital-government-infrastructure-hit-by-a-new-ddos-attack.html)

_2026-08-25 · Pierluigi Paganini · Security Affairs_

Norway ’s shared government infrastructure suffered a third DDoS attack, disrupting digital services but showing no signs of data compromise. Norway ‘s shared digital government infrastructure has been hit by another distributed denial-of-service (DDoS) attack that disrupted services used by citizens, businesses and public agencies. The incident began at 03:38 CEST on Monday, August 24, \[…\]

## [When the Algorithm Fires You: Uber Faces €825M Fine](https://securityaffairs.com/197823/laws-and-regulations/when-the-algorithm-fires-you-uber-faces-e825m-fine.html)

_2026-08-25 · Pierluigi Paganini · Security Affairs_

Uber faces an €825M GDPR fine for automatically suspending drivers without human review, highlighting the risks of AI decisions affecting workers. The Dutch Data Protection Authority handed Uber its largest privacy fine yet, and this one isn’t about data transfers or cookie consent. The regulator imposed an 825 million euro penalty, roughly $964 million, over \[…\]

## [Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable](https://securityaffairs.com/197815/security/two-cvss-9-8-auth-bypasses-in-miniorange-saml-wordpress-plugin-were-exploited-before-any-database-even-listed-the-paid-editions-as-vulnerable.html)

_2026-08-25 · Pierluigi Paganini · Security Affairs_

Two CVSS 9.8 miniOrange SAML WordPress plugin auth bypasses were exploited while paid editions never appeared in any vulnerability database. Manual patch required. Two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On WordPress plugin, both rated CVSS 9.8, are under active exploitation. Both CVE-2026-61979 and CVE-2026-15981 allow an unauthenticated attacker…

## [U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/197801/security/u-s-cisa-adds-maximum-severity-oracle-flaw-to-its-known-exploited-vulnerabilities-catalog.html)

_2026-08-25 · Pierluigi Paganini · Security Affairs_

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Oracle flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-21962 (CVSS score of 10,0), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-21962 is a critical,…

## [Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown](https://securityaffairs.com/197784/malware/fake-minecraft-sites-are-still-spreading-weedhack-after-c2-takedown.html)

_2026-08-25 · Pierluigi Paganini · Security Affairs_

WeedHack Minecraft Malware Survives C2 Takedown: Fake Client Sites Still Active, SEO Poisoning Puts Malicious Downloads at the Top of Google McAfee Labs published a follow-up report on the WeedHack Malware-as-a-Service campaign this week, documenting ten active malicious sites and multiple file-hosting accounts that are still spreading the infostealer despite a disruption to its…

## [Modulation: How Radio Waves Carry Information](https://vividcomm.com/2026/08/25/modulation-how-radio-waves-carry-information/)

_2026-08-25 · M.J. Martin · Vividcomm_

Reading Time: 5 minutes “A radio wave carries energy. Modulation gives that energy meaning. The strength of the signal determines whether it arrives, but the intelligence encoded within it determines what it has to say.” – MJ Martin The Canadian RF Context In Canada, wireless systems from municipal AMI networks to Wi-Fi operate within spectrum and power rules administered \[…\]

## [Cybercriminals Turn GTA VI Leaks Into Malware Bait](https://securityaffairs.com/197772/malware/cybercriminals-turn-gta-vi-leaks-into-malware-bait.html)

_2026-08-24 · Pierluigi Paganini · Security Affairs_

A fake 113GB GTA VI build is packed with malware, using massive empty files to hide a tiny malicious payload. GTA VI hype has reached the point where people are volunteering to infect their own computers just to check if a leak is real. Someone on X asked their followers to “take one for the \[…\]

## [One SSID To Rule Them All](https://www.pentestpartners.com/security-blog/one-ssid-to-rule-them-all/)

_2026-08-24 · Alex Wallace · Pen Test Partners_

TL;DR How we ended up here My colleague Adam Bromiley and I recently tripped over one of those ‘What!?’ findings. We could completely break an IT-OT segmentation without having to do … anything. We were on an OT-focused engagement, working out of a control room. We use a risk-averse methodology for these engagements, so we began with passive monitoring and low-risk \[…\] The post One SSID To Rule…

## [CLI-first decentralized GPU compute (Sponsored)](https://crawlproof.com/a/JnsmTZPLoxUb)

_2026-08-24 · **Sponsored**_

Pay workers or run your GPU for FFmpeg transcode and AI inference.

## [Slovakia Warns of Cyber Risks in Road Speed Cameras](https://securityaffairs.com/197764/hacking/slovakia-warns-of-cyber-risks-in-road-speed-cameras.html)

_2026-08-24 · Pierluigi Paganini · Security Affairs_

Slovakia warns that vulnerable speed cameras could expose vehicle data, enable remote access and provide attackers with a foothold into public networks. Slovakia’s National Security Authority, NBÚ, recently issued a warning about several road speed cameras, calling them a significant cyber threat. The alert is not about someone deleting a speeding ticket. It is about \[…\]

## [TikTok Settles U.S. Child Privacy Case for $400 Million](https://securityaffairs.com/197713/laws-and-regulations/tiktok-settles-u-s-child-privacy-case-for-400-million.html)

_2026-08-24 · Pierluigi Paganini · Security Affairs_

TikTok will pay $400 million to settle U.S. claims that it violated child privacy laws by collecting data from users under 13. The U.S. Department of Justice announced that TikTok will pay $400 million to settle a 2024 lawsuit over children’s privacy. “Today, the Department of Justice announced a $400 million settlement with TikTok, ByteDance, \[…\]

## [iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset](https://securityaffairs.com/197748/cyber-crime/iauthflow-v2-the-10000-phishing-toolkit-that-survives-your-password-reset.html)

_2026-08-24 · Pierluigi Paganini · Security Affairs_

iAuthFlow v2 phishing toolkit uses a phished Google session to enroll an attacker-controlled passkey that survives password resets. Abnormal Security researchers have published an analysis of iAuthFlow v2, a phishing toolkit sold on a Russian-language cybercrime forum for $10,000 base price. The author also offers for sale additional capability modules separately. The headline feature is \[…\]

## [The Scientific Method: How a Canadian Emergency Department Solves a Medical Mystery and What Utility Operators can Learn](https://vividcomm.com/2026/08/24/the-scientific-method-how-a-canadian-emergency-department-solves-a-medical-mystery-and-what-utility-operators-can-learn/)

_2026-08-24 · M.J. Martin · Vividcomm_

Reading Time: 6 minutes “A symptom tells you where to look. Evidence tells you what to believe. Whether diagnosing a patient or a utility system, trust begins when assumptions end and disciplined investigation begins.” – MJ Martin Medicine Begins With a Question After spending a weekend in hospital and watching physicians, nurses, technicians and specialists work through the diagnostic \[…\]

## [SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 111](https://securityaffairs.com/197743/security/security-affairs-malware-newsletter-round-111.html)

_2026-08-23 · Pierluigi Paganini · Security Affairs_

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Akira Hits Safe Mode: Ransomware Rebooting Around EDR Multi-Functional Linux Botnet “Evooo1Bot” StubMaker RubyGems Campaign Delivers a Windows Infostealer Hunting MacSync Stealer infrastructure through behavioral pivots Manic: Blend between…

## [AI Is Everywhere](https://vividcomm.com/2026/08/23/ai-is-everywhere/)

_2026-08-23 · M.J. Martin · Vividcomm_

Reading Time: 4 minutes “We are often most afraid of technology when we can see the machinery behind the magic.” – MJ Martin The Invisible Intelligence Around Us Artificial intelligence has already become ordinary. Canadians encounter it when a bank flags a suspicious transaction, a smartphone improves a photograph, a navigation application reroutes around traffic, an email service catches \[…\]

## [ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries](https://securityaffairs.com/197681/breaking-news/toxicpanda-2-0-gets-a-major-upgrade.html)

_2026-08-22 · Pierluigi Paganini · Security Affairs_

ToxicPanda 2.0 targets 349 financial apps and abuses Android Wireless Debugging to gain deeper device access and steal banking credentials. ToxicPanda used to be a Europe-focused nuisance targeting a manageable list of banks. That version is gone. Zimperium’s zLabs team just documented ToxicPanda 2.0, and the numbers alone tell the story: 349 targeted financial institutions \[…\]

## [面向人机交互设计 Harness：构建以产物为中心的 Agent Loop](http://www.phodal.com/blog/artifact-centered-agent-harness/)

_2026-08-22 · Phodal Huang · Blog | Phodal - A Growth Engineer_

最近，我一直在 Better Harness 里思考编码智能体的工作闭环：用户究竟想完成什么，智能体读取了哪些上下文、执行了哪些操作，

## [Malware Hijacks Android Car Head Units](https://securityaffairs.com/197700/hacking/malware-hijacks-android-car-head-units.html)

_2026-08-22 · Pierluigi Paganini · Security Affairs_

Malware is abusing car infotainment updates to install proxy software, turning Android head units into nodes for the BADBOX network. Kaspersky researchers found something in June 2026 that made them stop and look twice: an Android app with no interface at all, installed like any ordinary app but making zero effort to disguise itself as \[…\]

## [Critical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command Execution](https://securityaffairs.com/197689/hacking/critical-flaw-in-nasa-jpl-open-source-spacecraft-command-software.html)

_2026-08-22 · Pierluigi Paganini · Security Affairs_

A critical flaw (CVSS 9.4) in NASA/JPL’s AIT-GUI let anyone send unauthenticated commands to spacecraft instruments. Cycode researchers found that AIT-GUI, the browser-based operator console in NASA/JPL open-source AMMOS Instrument Toolkit, shipped with no authentication, no session checks, and no CSRF protection on any of its state-changing endpoints. “AIT-GUI, the web front end of NASA/JPL’s \[…\]

## [Daily plans, scheduled by AI (Sponsored)](https://crawlproof.com/a/dVdbr4jT1qrd)

_2026-08-22 · **Sponsored**_

AI-made daily plans that schedule tasks and protect focus time.

## [Pulmonary Embolism](https://vividcomm.com/2026/08/22/pulmonary-embolism/)

_2026-08-22 · M.J. Martin · Vividcomm_

Reading Time: 4 minutes “We make plans as though tomorrow has signed a contract with us. Life reminds us that it never did.” – MJ Martin The Illusion of a Perfect Plan We make plans because plans give structure to uncertainty. We book flights, schedule meetings, organize vacations, coordinate work, and convince ourselves that next Tuesday is somehow waiting \[…\]

## [U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/197693/security/u-s-cisa-adds-zimbra-collaboration-suite-zcs-flaw-to-its-known-exploited-vulnerabilities-catalog.html)

_2026-08-22 · Pierluigi Paganini · Security Affairs_

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the Zimbra Collaboration Suite (ZCS) flaw CVE-2026-73570 to its Known Exploited Vulnerabilities (KEV) catalog. CERT Polska, Poland’s national computer emergency response team,…

## [Your Shredded Visa Card May Still Work at the Checkout](https://securityaffairs.com/197663/hacking/your-shredded-visa-card-may-still-work-at-the-checkout.html)

_2026-08-21 · Pierluigi Paganini · Security Affairs_

UMass Amherst researchers showed expired Visa contactless cards can make real purchases by exploiting an unsigned expiry field in Visa’s EMV kernel. Researchers at the University of Massachusetts Amherst demonstrated at USENIX Security 2026 in Baltimore that expired Visa contactless credit cards can complete real purchases, including transactions at live retail and grocery merchants, by \[…\]

## [Six Maximum-Severity Flaws Found in Cisco Products](https://securityaffairs.com/197640/security/six-maximum-severity-flaws-found-in-cisco-products.html)

_2026-08-21 · Pierluigi Paganini · Security Affairs_

Cisco patched nine critical flaws, including six rated CVSS 10.0, found during internal testing. None are known to be exploited. Cisco released another batch of security fixes for its Crosswork platforms and Secure Workload software, part of what it’s calling an ongoing internal security review, and the CVSS scores in this round are unusually severe. \[…\]

## [DEFCON 34: Planes, PLCs and 6am runs](https://www.pentestpartners.com/security-blog/planes-plcs-and-6am-runs-at-defcon-34/)

_2026-08-21 · Alex Wallace · Pen Test Partners_

TL;DR A perfectly normal amount of luggage On Tuesday 4th August, 5 brave souls set off to the faraway climes of Nevada, bound for DEF CON 34. We had 9 cases of tech with us, a motley assortment of flight simulators, industrial control CTFs and plenty more. We supported the ICS Village for the first time, reflecting our \[…\] The post DEFCON 34: Planes, PLCs and 6am runs appeared first on Pen Test…

## [Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics](https://securityaffairs.com/197630/apt/fake-conferences-oauth-and-whatsapp-inside-russias-new-espionage-tactics.html)

_2026-08-21 · Pierluigi Paganini · Security Affairs_

Google tracks three Russia-linked espionage clusters using phishing and legitimate authentication tools to target researchers, diplomats and defense staff. Google’s Threat Intelligence Group tracked three separate suspected Russia-linked cyber espionage clusters. All three focus on the same thing: abusing authentication features that are supposed to protect accounts to access them instead. Threat…

## [GitLab Warns of Active Exploitation of Critical GraphQL Flaw](https://securityaffairs.com/197622/uncategorized/gitlab-warns-of-active-exploitation-of-critical-graphql-flaw.html)

_2026-08-21 · Pierluigi Paganini · Security Affairs_

GitLab flaw CVE-2026-19478 is now under active exploitation, allowing unauthenticated attackers to modify or delete public projects. WatchTowr researchers warn of active exploitation of critical GitLab flaw CVE-2026-19478 (CVSS score of 9.4). This week, GitLab pushed out an emergency patch to address this flaw, which could let an attacker with zero credentials remotely modify or \[…\]

## [Poland&#8217;s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw](https://securityaffairs.com/197610/security/polands-cert-warns-of-active-exploitation-of-critical-zimbra-collaboration-suite-flaw.html)

_2026-08-21 · Pierluigi Paganini · Security Affairs_

CERT Polska confirmed active exploitation of CVE-2026-73570, a critical unauthenticated RCE in Zimbra Collaboration Suite patched on July 20. CERT Polska, Poland’s national computer emergency response team, confirmed this week that threat actors are actively exploiting a critical vulnerability in Zimbra Collaboration Suite tracked as CVE-2026-73570. The flaw allows unauthenticated remote code…

## [U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/197602/security/u-s-cisa-adds-trueconf-server-flaws-to-its-known-exploited-vulnerabilities-catalog.html)

_2026-08-21 · Pierluigi Paganini · Security Affairs_

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: TrueConf Server is an on-premises video conferencing and unified communications platform developed by…

## [Cl0p Targets 40+ Organizations Through PTC Windchill Flaw](https://securityaffairs.com/197587/cyber-crime/cl0p-targets-40-organizations-through-ptc-windchill-flaw.html)

_2026-08-21 · Pierluigi Paganini · Security Affairs_

Cl0p claims over 40 organizations fell victim to attacks exploiting a PTC Windchill and FlexPLM vulnerability. Cl0p is using a familiar strategy again: exploit one flaw in enterprise software to attack many companies, then publish the victims’ names if they refuse to pay. The group claims it has targeted more than 40 organizations through a \[…\]

## [Itron Temetra: Index Versus Interval Values](https://vividcomm.com/2026/08/21/itron-temetra-index-versus-interval-values/)

_2026-08-21 · M.J. Martin · Vividcomm_

Reading Time: 5 minutes Every once in a while, customers seem to ask common questions. Whenever this happens, I try to share a proper explanation or technical breakdown of the solution to share in the community. This is another example. Users are unclear as to when to export Index values versus Interval values. So, my hope is that this \[…\]

## [Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline](https://securityaffairs.com/197570/malware/manic-the-android-malware-that-exfiltrates-data-even-when-the-phone-is-offline.html)

_2026-08-20 · Pierluigi Paganini · Security Affairs_

Manic Android malware combines banking fraud and spyware, using a Bluetooth relay to steal data even when devices are offline. ThreatFabric’s Mobile Threat Intelligence team has identified a new Android malware, dubbed Manic, which has been active in the wild since at least February 2026. The researchers state that the malware is still under development \[…\]

## [NSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCs](https://securityaffairs.com/197566/ics-scada/nsa-cisa-fbi-doe-and-epa-warn-of-active-ai-assisted-attacks-on-siemens-s7-plcs.html)

_2026-08-20 · Pierluigi Paganini · Security Affairs_

NSA, CISA, FBI, DOE, and EPA warn of active AI-assisted attacks against Siemens S7 PLCs across US critical infrastructure sectors. Five U.S. federal agencies issued a joint advisory this week warning of an active hacking campaign against Siemens S7 Series programmable logic controllers. The advisory, CISA AA26-231A, is co-signed by NSA, FBI, DOE, and EPA \[…\]

## [GivEnergy enters administration, batteries expose home networks](https://www.pentestpartners.com/security-blog/givenergy-enters-administration-legacy-home-batteries-still-expose-customer-networks/)

_2026-08-20 · Alex Wallace · Pen Test Partners_

TL;DR Introduction In late 2024, we found multiple vulnerabilities in GivEnergy home battery systems that could allow attackers to access customers’ home networks, disrupt battery operation, and potentially violate UK product security regulations. While GivEnergy updated installer guidance for newer deployments, older installations may still be exposed, with no clear remediation plan communicated…

## [U.S. CISA adds an MLflow flaw to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/197558/hacking/u-s-cisa-adds-a-mlflow-flaw-to-its-known-exploited-vulnerabilities-catalog.html)

_2026-08-20 · Pierluigi Paganini · Security Affairs_

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds an MLflow vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2026-64849 (CVSS score of 9.3), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-64849 is a critical server-side request…

## [US Indicts 17 Iranians Over Years-Long Cyber Espionage Campaign](https://securityaffairs.com/197551/intelligence/us-indicts-17-iranians-over-years-long-cyber-espionage-campaign.html)

_2026-08-20 · Pierluigi Paganini · Security Affairs_

The US charged 17 Iranians over a years-long hacking campaign that stole 31TB from universities, companies and government agencies worldwide. Eight years after the original indictment first went public, US prosecutors just added eight more names to the list. The Justice Department unsealed a superseding indictment this week charging 17 members of the Mabna Institute, \[…\]

## [StopAndProtect Turns 2,000 Hacked WordPress Sites Into a Criminal Network](https://securityaffairs.com/197537/hacking/stopandprotect-turns-2000-hacked-wordpress-sites-into-a-criminal-network.html)

_2026-08-20 · Pierluigi Paganini · Security Affairs_

StopAndProtect turned nearly 2,000 hacked WordPress sites into a criminal network for malware delivery, data theft, surveillance and ransomware. Check Point Research uncovered a cybercrime operation, dubbed StopAndProtect, that has turned thousands of hacked WordPress websites into a shared platform for malware delivery, data theft, surveillance and ransomware. The operation is a good reminder…

## [A Municipal Streetlight Canopy for Integrated Utility Operations](https://vividcomm.com/2026/08/20/a-municipal-streetlight-canopy-for-integrated-utility-operations/)

_2026-08-20 · M.J. Martin · Vividcomm_

Reading Time: 4 minutes “A municipally owned streetlight canopy can become the digital backbone of Canadian utility operations, connecting essential services through shared infrastructure while keeping security, governance, and public accountability firmly in municipal hands.” – MJ Martin The Canadian Operating Case A municipally owned Itron streetlight canopy can provide Canadian utility…

## [Inside Operation CameraSwarm: How One Actor Took Over 14,000 Dahua Cameras](https://securityaffairs.com/197527/iot/inside-operation-cameraswarm-how-one-actor-took-over-14000-dahua-cameras.html)

_2026-08-19 · Pierluigi Paganini · Security Affairs_

An exposed operator directory reveals how one actor compromised 14,000+ Dahua cameras across Ukraine and Russia, no password needed for most. A researcher discovered an exposed directory containing the tools of an attacker who compromised more than 14,000 Dahua cameras between June 17 and July 22, 2026, mainly in Ukraine and Russia. Hunt.io reconstructed the \[…\]

## [Microsoft Tracks MacSync Stealer by Its Behavior, Not Its Domains](https://securityaffairs.com/197514/malware/microsoft-tracks-macsync-stealer-by-its-behavior-not-its-domains.html)

_2026-08-19 · Pierluigi Paganini · Security Affairs_

Microsoft tracked over 30 MacSync Stealer domains by focusing on behavioral patterns, revealing a campaign targeting passwords, keys, wallets and other data. Domain blocking is a losing game when the thing you’re blocking can register a new domain faster than you can add it to a list. That’s the exact problem Microsoft Defender Experts ran \[…\]

