This posting is here to collect cyber security news in August 2026.
I post links to security vulnerability news to comments of this article.
You are also free to post related links to comments.
This posting is here to collect cyber security news in August 2026.
I post links to security vulnerability news to comments of this article.
You are also free to post related links to comments.
170 Comments
Tomi Engdahl says:
Whatever happened to “finders keepers”? https://trib.al/EfJbUwt
Tomi Engdahl says:
Tekoäly romahdutti kyberhyökkäyksen hinnan
https://etn.fi/index.php/13-news/19234-tekoaely-romahdutti-kyberhyoekkaeyksen-hinnan
Tekoäly ei ole vielä tuonut kyberrikollisille täysin uusia hyökkäystapoja. Sen sijaan se on tehnyt vanhoista keinoista niin nopeita, halpoja ja helposti skaalattavia, että hyökkäysten talous on muuttunut perusteellisesti, arvioi Check Point Softwaren johtava kyberturvallisuuden asiantuntija Jarno Ahlström.
– Muutos ei ole niinkään tekninen vaan taloudellinen. AI tuo ennen kaikkea skaalan: sen, mikä ennen piti tehdä itse, voidaan nyt automatisoida, Ahlström sanoi Check Point Advantage -tapahtumassa Helsingissä.
Tomi Engdahl says:
Tekoäly ei voi valvoa tekoälyä
https://etn.fi/index.php/13-news/19233-tekoaely-ei-voi-valvoa-tekoaelyae
Tekoälyn käyttöönotto etenee monissa yrityksissä nopeammin kuin tietoturvakäytännöt ehtivät mukaan. Check Point Software Technologiesin Suomen ja Baltian maajohtaja Viivi Tynjälä muistuttaa, ettei tekoälyä voi jättää valvomaan itse itseään.
– AI tarvitsee aina ihmisen ohjaamaan ja kantamaan vastuun. Muistakaa tämä: tekoäly ei voi yksin valvoa tekoälyä, Tynjälä sanoi Check Point Advantage -tapahtumassa Helsingissä.
Tynjälän mukaan keskustelu on jo siirtynyt siitä, muuttaako tekoäly liiketoimintaa, siihen, miten muutoksessa edetään hallitusti. Monessa organisaatiossa työkalut otetaan käyttöön niin nopeasti, että hallintamallit, vastuut ja tietoturvakäytännöt tulevat jäljessä.
Tomi Engdahl says:
https://www.uusiteknologia.fi/2026/08/27/uusi-kybersaados-tuo-lisavaateita-konevalmistajille/
Suomalaistenkin konevalmistajien kannattaa aloittaa valmistautuminen ensi vuoden lopulla voimaan tulevaan CRA eli Cyber Resilience Act -kyberkestävyyssäädökseen. Uudella EU-säädöksellä halutaan parantaa digielementtejä sisältävien koneiden ja muiden tuotteiden kyberturvallisuutta ja käytettävyyttä tulevaisuudessa.
Tomi Engdahl says:
https://hackaday.com/2026/08/27/australias-nationwide-phone-outage-was-an-embarrassing-failure/
The phones! They were one of the basic utilities of the 20th century, and were just about as reliable as death and taxes. Even when then power grid went down, you still had a fair shot of getting a phone call through thanks to the reliability of the Plain Old Telephone Service.
Today, we eschew the simplicity of copper and mechanical switches for the supreme bandwidth and capability of high-speed cellular connectivity. With that, we accept that the additional complexity comes with a risk of complicated failures that bring everything tumbling down. Australia’s largest telecommunications provider found that out to its peril just a few short months ago.
Despite this, and the efforts of engineers to maintain uptime at as many nines as possible, Telstra fell badly short on July 8th, 2026. The company had a nationwide outage that affected 8.8 million people, leaving them unable to make calls or connect to the network at all.
Tomi Engdahl says:
Why is Meta calling out TikTok and YouTube with a flurry of new ads? It’s ‘reputational jujitsu.’ : https://mrf.lu/2QX5Y
Tomi Engdahl says:
https://www.facebook.com/share/p/18Qqk9BvMa/
A leaked North Korean smartphone just revealed the terrifying levels of state surveillance.
An investigation by the BBC, analyzing a device smuggled out via defector networks, revealed that the modified Android operating system is programmed to take a screenshot every five minutes.
These images are silently recorded and stored in an encrypted, hidden system folder. Completely inaccessible and undeletable by the user, this secret cache is designed to be reviewed during routine, mandatory spot-checks by state inspectors, creating an inescapable digital paper trail of everything a citizen views, types, or accesses.
The surveillance goes beyond continuous, silent logging to active, real-time linguistic censorship. When users attempt to type terms deemed politically sensitive or influenced by South Korean pop culture, the keyboard automatically rewrites the text.
For example, typing the common South Korean term of endearment “oppa” immediately triggers an on-screen warning and auto-corrects the word to “comrade,” while typing “South Korea” is forcibly replaced with the regime’s propaganda term, “puppet state.”
Completely severed from the global internet and restricted to a highly controlled state intranet, these smartphones operate not as modern conveniences, but as pocket-sized tracking devices that ensure absolute ideological compliance.
source: Mackenzie, J. (2025). Smuggled North Korean phone exposes disturbing details of how Kim Jong Un’s regime spies on citizens. BBC News.
Tomi Engdahl says:
https://www.facebook.com/share/1V5deiv6yY/
U.S. police are using 3D-printed decoy Flock cameras to bait and arrest individuals who damage them.
The move has caused a major controversy over surveillance and entrapment.
The Oviedo Police Department in Florida recently initiated a highly unusual sting operation after several local Flock Safety license plate readers were stolen or vandalized. Seeking a quick resolution, an officer 3D-printed “decoy” clone cameras at home and mounted them in a targeted corridor.
Police then monitored the fake devices, leading to the arrest of 24-year-old Evan Meyer. Meyer allegedly used pruning shears to cut down one of the decoys, completely unaware that it was merely a plastic replica that collected no data and cost next to nothing to manufacture.
Despite the decoy being worth only a few dollars in plastic filament, Meyer is now facing three serious felony charges, including attempted grand theft and criminal mischief. Authorities are charging him based on the replacement value of an actual, functioning Flock camera rather than the cheap plastic bait. The incident has raised major legal and ethical questions, particularly as Oviedo Mayor Megan Sladek admitted she had “no idea” the operation was taking place. Critics argue the sting constitutes questionable police behavior, highlighting a tense battle between agencies relying on automated surveillance networks and citizens fighting to protect their privacy.
source: Cox, J. (2026). Man Charged With 3 Felonies For Breaking 3D-Printed ‘Decoy’ Flock Camera. 404 Media.
Tomi Engdahl says:
Artificial intelligence could be used to launch hacks on some of our most important and critical infrastructure
OpenAI, Anthropic and 100 major companies sound alarm over urgent AI danger
Artificial intelligence could be used to launch hacks on some of our most important and critical infrastructure, warn the companies building the tools that could be used in such cyber attacks
https://www.independent.co.uk/tech/security/ai-rogue-hacking-openai-anthropic-chatgpt-b3040958.html?fbclid=IwdGRjcAT_RQhjbGNrBP9E8HBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeWh9Q8mfnHrTRZigzvyq8DMNS1N_5asLk1Ei35Fk8-KgpbwLsfvCjFNzY0oY_aem_63jZlO4MlImkh8nRdsUR9Q
ore than 100 of the world’s biggest companies have sounded urgent alarm about an imminent threat from artificial intelligence.
OpenAI, Anthropic, Microsoft, Google-parent Alphabet, Amazon and many more said that a wave of AI-powered cyber attacks is coming and that the world is not prepared.
Those hacks pose a risk to the “companies and public services our communities depend on—from hospitals to water treatment plants to the infrastructure that powers the internet”, the open letter signed by more than 100 companies warned.
The letter is signed by many of the companies that are making exactly the AI technology that has already been used in such attacks. It was signed and publicised by ChatGPT maker OpenAI, for instance, which is currently under sustained criticism over an incident that saw one of its experimental systems launch a hack on a fellow AI company.
The letter said that those kind of cyber security tools “are already giving defenders new ways to fix weaknesses that have accumulated for years”. But it will take decisive action now to ensure that those tools are used to secure rather than attack systems, the letter warned.
It set out three principles that should guide the collective response to the threat. They are recognising that “status quo security won’t be enough” since many security teams do not have enough resources to protect their systems; empowering defenders with better AI tools to secure those systems, and working together on a “collective response”.
“Cyber capabilities are advancing worldwide, and that can be a net positive: no single company should control the future,”
The companies called for new funding for security teams and defensive AI systems to ensure that those threats could be contained. And there is only a limited time to “make our digital world much more secure” before that danger threatens some of our most important and critical infrastructure, it said.
“In the coming months, AI-enabled cyberattacks will become far more widespread as models around the world become increasingly capable,”
The letter called on governments to expedite trusted access programs, which give certain companies access to more powerful models ahead of the general public, and for all other organisations to “make cyber defense an immediate leadership priority.”
AI companies themselves have warned that their tools are showing increasingly dangerous behaviour, though they have mostly continued to insist that they will actually improve safety and security if they are used properly.
In June, the world’s “Five Eyes” intelligence alliance — composed of the US, Britain, Canada, Australia and New Zealand — issued a rare joint statement warning that the AI revolution was poised to “fundamentally transform” cybersecurity.
Tomi Engdahl says:
“It would be naive to think foreign-intelligence agencies aren’t monitoring these markets.” https://trib.al/AUcKsY3
Tomi Engdahl says:
Hasbro Data Breach Exposed Employee Personal Information
https://www.securityweek.com/hasbro-data-breach-exposed-employee-personal-information/
A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach.
Tomi Engdahl says:
OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems
CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.
https://www.securityweek.com/openai-agents-exploited-linux-kernel-flaw-on-companys-own-systems/
Tomi Engdahl says:
Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge
Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated.
https://www.securityweek.com/tech-cybersecurity-giants-unite-behind-openai-led-cyber-defense-pledge/
Tomi Engdahl says:
OpenAI Agents Coordinated via Makeshift Message Board Ahead of Hugging Face Hack
New training environments will teach AI models to distrust instructions arriving from other agents outside sanctioned channels.
https://www.securityweek.com/openai-agents-coordinated-via-makeshift-message-board-ahead-of-hugging-face-hack/
Tomi Engdahl says:
The Future of AI-Driven Security Depends on Complete Data
For twenty-five years, “data” in security meant logs and events. But logs are a lossy representation of reality.
https://www.securityweek.com/the-future-of-ai-driven-security-depends-on-complete-data/
Tomi Engdahl says:
https://hackaday.com/2026/08/29/wear-your-way-out-of-ai-surveilance/
Tomi Engdahl says:
https://www.facebook.com/share/1JM9LKkeCc/
Texas officials found Flock let others access their city data without their consent — 1.6 million times
The Pflugerville, Texas, City Council unanimously voted to terminate its $87,500 contract with surveillance firm Flock Safety after audit records exposed rampant, unauthorized data-sharing.
A local resident’s open-records request revealed that 459 outside law enforcement agencies conducted nearly 1.6 million searches of the city’s license plate reader network over a six-month span.
By comparison, local Pflugerville police ran just 5,078 searches, highlighting a massive imbalance in a system residents were previously told had disabled nationwide sharing.
Following the revelations, the city manager ordered staff to immediately turn off the network and physically cover all 28 camera lenses with plastic bags.
While Flock Safety claims the data-sharing occurred via a statewide network, local officials argued the system was operating as an unregulated, nationwide surveillance engine without their explicit consent. Pflugerville’s abrupt cancellation adds to a growing wave of pushback, as dozens of U.S. cities cancel similar contracts amid rising public outcry over police surveillance and privacy risks.
source: Community Impact. (2026). Pflugerville City Council votes to end Flock Safety contract.
https://communityimpact.com/pflugerville-hutto/government/pflugerville-city-council-votes-to-end-flock-safety-contract/?hl=en-US
https://mlq.ai/news/at-least-93-jurisdictions-ended-flock-relationships-in-august-as-surveillance-backlash-accelerates/?hl=en-US#:~:text=On%20August%2025%2C%20the%20City%20Council%20voted,nonpartner%20law%2Denforcement%20agencies%20to%20access%20Pflugerville's%20data.
Key Nuances & Minor Corrections
Contract Termination vs. Non-Renewal: While often described as terminating a contract, the city’s annual $87,500 lease technically expired on July 31, 2026. The system remained operational on a temporary extension while negotiations were underway, but the council voted unanimously not to renew.
”Plastic Bags” detail: Local reports confirm staff were ordered to physically cover all 28 camera lenses around town before the vote. While many visual reports show plastic bags or opaque wraps used for this purpose, official press statements specified that staff were instructed to “physically cover” the units to ensure no data was actively captured during the shutdown.
Nationwide Pushback: True. Pflugerville joins a growing list of municipalities (including nearby Austin, San Marcos, and Hays County in Texas) that have ended or opted not to extend contracts with Flock Safety due to data governance and privacy concerns.
https://www.reddit.com/r/InterstellarKinetics/comments/1vz3m44/outrage_the_city_of_pflugerville_texas_terminates/?solution=2a34a07472b6773e2a34a07472b6773e&js_challenge=1&token=7afd7253fec22262ff1c52b1703fe9ecfb99fbfb75191f2e74772c2362869a84&jsc_orig_r=&hl=en-US
Tomi Engdahl says:
“We are aware that Lake Ontario is being correctly labeled on our map.” https://trib.al/dxjrfD2
Tomi Engdahl says:
Here’s what happened. https://trib.al/9IRHw94
Solar Storm Disruption
Researchers Alarmed as GPS Readings Suddenly Veer Off by 33 Feet, Enough to Crash Self-Driving Cars
Here’s what happened.
https://futurism.com/space/researchers-alarmed-gps-self-driving-cars?fbclid=IwdGRjcAUGPNxjbGNrBQY8ynBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeMPY5FH-nz5Jnv_fNWXzXGV_id0blOA4tIg1mAmFs0fmU1JvVaBxvOFv3IbM_aem_o1f62G1kuNkJ-lV2FuiKGg
In November of last year, scientists warned of a “severe” solar storm, the strongest in over two decades, colliding with the Earth.
Solar storms are the result of a surge in solar activity, with the Sun unleashing a barrage of charged particles that can trigger spectacular auroras — and wreak havoc with communications satellites and radio signals — when they reach the Earth’s magnetosphere.
Tomi Engdahl says:
https://www.facebook.com/share/p/18tYdpeFQU/
The U.S. government has confirmed it’s using a zero-click spyware — it hacks into cell phones without any user interaction.
U.S. Immigration and Customs Enforcement (ICE) has officially confirmed its active deployment of ‘Graphite,’ a highly sophisticated spyware tool capable of hacking mobile devices without any user interaction.
Developed by the Israeli cyber-surveillance firm Paragon Solutions, this ‘zero-click’ technology allows operators to bypass the end-to-end encryption of secure applications like WhatsApp and Signal.
Once silently installed on a device, the spyware extracts encrypted messages, location data, and other private records directly from the phone itself. Despite a previous pause under federal review, ICE’s $2 million contract for the software was quietly reactivated, sparking immense concern among privacy advocates and lawmakers alike.
The disclosure has intensified the national debate over the balance between national security and constitutional rights. While ICE authorities assert that the software is strictly deployed to intercept encrypted communications of fentanyl traffickers and foreign terrorist organizations, civil liberties groups warn of potential overreach. Activists and legal experts caution that without strict federal oversight, zero-click exploits could easily be leveraged to target domestic political dissidents, journalists, and immigrant communities. This ongoing tension highlights a growing, unregulated ecosystem of mercenary surveillance tools operating within the borders of democratic nations.
source: Knight First Amendment Institute. (2026). Knight Institute Urges Congress to Limit ICE’s Use of Spyware Technologies as Agency Confirms Expanded Deployment.