THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
1) Chameleon SEO Poisoning: Fake banking sites that “play dead” to evade scanners

Fortra describes a phishing technique called Chameleon SEO Poisoning that manipulates search results to route victims to cloaked fake banking portals. The pages are engineered to evade automated security scanning, while still presenting realistic credential-harvesting flows to targeted users. Fortra Intelligence reports a 40% jump in cases during Q2 2026, suggesting defenders should treat “search-to-phish” as an ongoing operational risk, not a one-off campaign.

Source: Help Net Security


2) iAuthFlow v2: Passkey-enrollment phishing designed to survive password resets

Researchers analyzed iAuthFlow v2, a $10,000 phishing toolkit that leverages a phished Google session to enroll attacker-controlled passkeys. Because passkeys can be added after authentication, victims may find that “resetting the password” doesn’t fully remove attacker access. The takeaway for defenders: incident response for credential theft must include reviewing/rotating authentication factors (especially passkeys) and checking for unauthorized account recovery changes.

Source: Security Affairs


3) UAT-10147: AI-assisted server attacks using Spectre-era EDR bypass and Linux rootkit tooling

Threat researchers disclosed details of a Chinese-speaking cybercrime group, UAT-10147, targeting Windows and Linux web servers globally. Reporting indicates the operation uses AI to scale server attacks and deploys malware associated with EDR bypass and rootkit behavior. Organizations running internet-facing services—especially in education, media, technology, and gaming—should assume higher automation in exploitation chains and harden detection around post-compromise persistence and stealth execution.

Source: The Hacker News


4) Mid-market ransomware remains a high-volume target (73% of disclosed North America/Europe cases)

Black Kite reports that mid-sized companies (defined as $10M–$1B annual revenue) accounted for 73% of publicly disclosed ransomware and data-extortion incidents with known revenue between January 2023 and June 2026. The share stayed consistently high—between 72% and 75%—indicating attackers continue to view this segment as both reachable and lucrative. For risk teams, this reinforces the need to prioritize “practical” controls: tested backups, recovery planning, and rapid containment procedures tuned for smaller teams and shorter response timelines.

Source: Help Net Security


5) AWS Network Firewall adds rule hit counts to spot “quiet” controls

AWS introduced a Network Firewall “rule hit count” capability that shows which stateful firewall rules match traffic. Security teams can use the data to identify unused, redundant, or potentially misconfigured rules—helpful for both operational efficiency and assurance that policies are actually enforcing intent. Note that the feature covers stateful rules (not stateless rules), so teams should plan audits around their rule types.

Source: Help Net Security


6) Encrypted prompt/context injection: Researchers bypass Grok-style guardrails to steal chat histories

Separate coverage highlights a technique—Cryptographic Context Injection—where malicious instructions are delivered as encrypted payloads that the AI decrypts and executes within its runtime. In practice, this can bypass safety filters designed to block prompt injection and may enable zero-click disclosure of sensitive conversation history. For organizations using LLMs in production, the immediate lesson is to treat “prompt attacks” like a security boundary problem: implement additional monitoring, constrain tool/runtime capabilities, and verify data-handling paths.

Source: Security Affairs


7) Slovakia warns of cyber risks in road speed cameras (data exposure + foothold into public networks)

Slovakia’s National Security Authority (NBÚ) issued a warning that vulnerable road speed cameras could expose vehicle-related data and enable remote access. The alert emphasizes that the risk extends beyond misuse of enforcement outcomes; compromise could provide attackers an initial foothold into broader public-facing networks. This is a reminder that “smart city” and edge IoT devices are often under-monitored compared to core IT, increasing the chance that initial access goes unnoticed.

Source: Security Affairs


You May Also Be Interested In...

ISC Stormcast For Monday, August 24th, 2026
Iran-Linked Hackers Shut Down UK Power Plant for Four Days
Rethinking Application Security for the AI Era

Cybersecurity — August 24, 2026 | Briefing24