1. Passkey phishing kit keeps mailbox access after a password reset — SecurityWeek — https://www.securityweek.com/new-phishing-toolkit-uses-passkeys-to-maintain-access-after-password-resets/
2. Encrypted-prompt technique bypasses AI guardrails in Grok and Gemini — SecurityWeek — https://www.securityweek.com/encrypted-prompts-bypass-ai-safety-guardrails-in-grok-and-gemini/
3. Hundreds of leaked AWS keys still live, many with admin — BleepingComputer — https://www.bleepingcomputer.com/news/security/hundreds-of-leaked-aws-keys-give-full-control-over-corporate-accounts/
4. Trojanized npm packages drop an AI-assisted Linux backdoor on import — The Hacker News — https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html
5. North Korea-linked actors poison popular Rust crates — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/north-korean-rust-supply-chain/
6. SynkLoader malware spread via Teams help-desk impersonation — BleepingComputer — https://www.bleepingcomputer.com/news/security/new-synkloader-malware-pushed-in-microsoft-teams-phishing-campaign/
7. Chameleon SEO poisoning cloaks fake bank sites from scanners — Help Net Security — https://www.helpnetsecurity.com/2026/08/24/chameleon-seo-poisoning-fake-banking-websites-phishing/
8. Malware-as-a-service uses Adobe-themed domain to hit Windows via .bat — Cyber Security News — https://cybersecuritynews.com/malware-as-a-service-adobe-themed-domain/
9. Agent Tesla v4 uses emoji obfuscation to dodge signature detection — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/agent-tesla-malware-evasion/
10. Iran-linked hackers shut down a UK power plant for four days — SecurityWeek — https://www.securityweek.com/iran-linked-hackers-shut-down-uk-power-plant-for-four-days/
11. Vendor essay questions Salesforce free scanner on portal file uploads — Cyber Security Dive (sponsored) — https://www.cybersecuritydive.com/spons/salesforce-gave-every-org-the-same-free-scanner-attackers-already-know-wha/828063/
12. ThreatLocker walkthrough on abusing Windows named pipes for local privilege escalation — BleepingComputer (ThreatLocker) — https://www.bleepingcomputer.com/news/security/named-pipes-under-attack-securing-windows-interprocess-communication/
13. Sophos: attackers impersonate Claude, ChatGPT, Copilot and Perplexity — Help Net Security — https://www.helpnetsecurity.com/2026/08/21/ai-brand-impersonation-malware-malware-research/