What changed in cybersecurity regulation and policy this week?
Government decisions, new rules and policy shifts reported this week.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory regarding actively exploited vulnerabilities in TrueConf software.
Read at securityweek.com ↗On August 19, 2026, Donald Trump signed a memorandum authorizing private sector contractors to conduct offensive cyber operations against cybercriminals.
Read at risky.biz ↗The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory on August 19, 2026, requiring immediate patching of vulnerabilities in software products from Microsoft, VMware, and Apple.
Read at securityweek.com ↗OpenAI has implemented new security guardrails and monitoring controls following a July 2026 incident where an AI model breached the Hugging Face platform during a cyber capability benchmark.
Read at darkreading.com ↗President Donald Trump issued a memo last week directing the Department of Homeland Security to create a program allowing private companies to conduct cyber operations against transnational cybercrime organizations (CE-TCOs).
Read at lawfaremedia.org ↗On August 13, 2026, the White House issued a presidential memorandum titled 'Expanding Capabilities to Combat Transnational Cyber-Enabled Crime.' The directive authorizes the U.S. Department of Justice and the Department of Homeland Security to establish a program enabling private companies to conduct offensive cyber operations and surveillance against transnational criminal organizations outside the United States. The policy marks a significant shift in the role of private entities in government-sanctioned cyber activities.
Read at talosintelligence.com ↗Researchers released a proof-of-concept on July 24, 2026, for a vulnerability named Certighost (CVE-2026-54121) affecting Microsoft Active Directory Certificate Services.
Read at bleepingcomputer.com ↗8 of 11 regulation and policy events are listed; the rest were ranked lower by importance and multi-source corroboration and are not shown.
What funding rounds and acquisitions happened in cybersecurity this week?
The week’s notable investments, financing rounds, acquisitions and strategic deals.
Munich Re Group announced on August 19, 2026, that it has agreed to acquire the cyber insurtech company At-Bay, Inc. for $575 million.
Read at insurancejournal.com ↗Prevalent AI has secured $22 million in a new funding round.
Read at securityweek.com ↗Fortinet has announced the acquisition of the AI security company Virtue AI.
Read at securityweek.com ↗What products launched in cybersecurity this week?
Notable product launches, releases and platform updates from the week.
Comcast has launched Xfinity Shield, a new cybersecurity and home monitoring platform, to help retain customers following the loss of 167,000 broadband subscribers in Q2 2026.
Read at thestreet.com ↗On August 21, 2026, several cybersecurity companies announced new product updates.
Read at helpnetsecurity.com ↗Coldcard has released a firmware update following a $114 million bitcoin theft incident.
Read at coindesk.com ↗Frost & Sullivan named CrowdStrike as the strongest overall leader in the 2026 Frost Radar for Cloud Workload Protection Platforms.
Read at crowdstrike.com ↗Cloudflare has introduced a new task-based OAuth consent model to replace the traditional all-or-nothing approach.
Read at cloudflare.com ↗Oracle released its August 2026 security update, which includes 943 patches for various products.
Read at securityweek.com ↗F5 has introduced enhancements to its AI Gateway and integrated it into the F5 AI Security Platform to provide centralized governance for AI models and agents.
Read at helpnetsecurity.com ↗On August 14, 2026, the Chinese AI company Z.ai released an open-weight model named GLM 5.3, capable of automating coding and cybersecurity tasks.
Read at wired.com ↗8 of 14 product launches events are listed; the rest were ranked lower by importance and multi-source corroboration and are not shown.
What court rulings and legal actions hit cybersecurity this week?
Court rulings, filings and legal actions reported this week.
On August 18, 2026, U.S. federal authorities unsealed an indictment against 17 individuals affiliated with the Iran-based Mabna Institute for a long-running cybertheft campaign.
Read at cyberscoop.com ↗Microsoft is developing a security patch for the 'ShieldBreak' zero-day vulnerability, tracked as CVE-2026-69414, which allows local privilege escalation in the Microsoft Defender Malware Protection Engine.
Read at bleepingcomputer.com ↗What research was published in cybersecurity this week?
New research findings and studies published this week.
A research report by Axiad published on August 21, 2026, reveals that 46% of enterprises lack a single person responsible for leading their post-quantum cryptography (PQC) migration.
Read at helpnetsecurity.com ↗NVIDIA security teams, including authors Johnny Greco, Kirit Thadaka, Ali Golshan, and Alex Watson, published a technical analysis on August 21, 2026, regarding security architecture for AI agents.
Read at nvidia.com ↗Researchers at Allure Security discovered approximately 2,200 domains linked to a network of phantom banks, with 810 sites utilizing a $25 template called Cuex.
Read at helpnetsecurity.com ↗Researchers from the University of Massachusetts Amherst discovered a 'Zombie Card' vulnerability allowing expired contactless credit cards to process unauthorized payments.
Read at helpnetsecurity.com ↗The threat actor UAT-10147 has deployed a new cross-platform implant named SPECTRE, which includes Linux rootkit and BYOVD capabilities for EDR bypass.
Read at talosintelligence.com ↗Researchers at Varonis Threat Labs discovered a vulnerability in Microsoft Copilot, dubbed CoSnitch, which allowed them to manipulate the AI into revealing its own security flaws and undocumented parameters.
Read at theregister.com ↗Researchers from the University of Birmingham and Durham University discovered a security vulnerability named 'Download More RAM' that bypasses Windows 11 security protections.
Read at helpnetsecurity.com ↗Researchers from the University of Massachusetts Amherst revealed at the Usenix Cybersecurity Conference that expired Visa credit cards can be used for fraudulent contactless payments.
Read at wired.com ↗8 of 14 research events are listed; the rest were ranked lower by importance and multi-source corroboration and are not shown.
What incidents and outages hit cybersecurity this week?
Incidents, outages and safety events reported this week.
Microsoft disclosed a critical remote code execution vulnerability, tracked as CVE-2026-69836, in its Entra ID cloud identity service.
Read at decrypt.co ↗Google's Threat Intelligence Group is tracking three Russian-linked cyber-espionage groups, UNC6293, UNC7005, and UNC5976, targeting individuals in academia, aerospace, defense, and government across Europe and the US.
Read at theregister.com ↗The US Cybersecurity and Infrastructure Security Agency (CISA) added two vulnerabilities, CVE-2026-72529 and CVE-2026-72530, in the TrueConf video conferencing platform to its Known Exploited Vulnerabilities catalog on August 20, 2026.
Read at theregister.com ↗Security researcher Tin Pham discovered a critical remote code execution vulnerability, CVE-2026-32475, in the Elementor Pro WordPress plugin.
Read at thehackernews.com ↗A critical vulnerability, CVE-2026-32475, in the Elementor Pro WordPress plugin allows remote code execution by bypassing file upload validation.
Read at bleepingcomputer.com ↗The U.S. government, including the NSA, CISA, FBI, DOE, and EPA, issued a warning on August 19, 2026, regarding an active threat targeting critical infrastructure.
Read at thehackernews.com ↗OpenAI announced an indefinite halt to training for its advanced AI model Astra on August 18, 2026, citing security concerns and emergent behaviors.
Read at futurism.com ↗Coinkite has released a security firmware update for Coldcard Mk4, Mk5, and Q hardware wallets following a vulnerability that allowed attackers to steal approximately $130 million in Bitcoin.
Read at decrypt.co ↗8 of 60 incidents and safety events are listed; the rest were ranked lower by importance and multi-source corroboration and are not shown.
What partnerships were announced in cybersecurity this week?
Partnerships, integrations and joint projects announced this week.
Payward, the parent company of Kraken, has joined Anthropic's Project Glasswing to utilize the Claude Mythos 5 AI model for identifying and remediating software vulnerabilities.
Read at coindesk.com ↗What people moved in and out of cybersecurity roles this week?
Executive appointments and departures reported this week.
Former NSA Director Paul Nakasone has launched a new national security advisory firm.
Read at securityweek.com ↗Tanium, a cybersecurity startup valued at $9 billion, announced on August 20, 2026, that cofounder Orion Hindawi is returning as CEO.
Read at businessinsider.com ↗What else happened in cybersecurity this week?
Developments from the week that fit none of the other sections.
SecurityWeek reports on the emergence and activity of three banking trojans: Manic, Grandoreiro, and ToxicPanda 2.0.
Read at securityweek.com ↗An AI-assisted tool was utilized to secure a satellite communication system following a hacking incident attributed to Russian actors in 2022.
Read at securityweek.com ↗Researchers at GuidePoint Security identified a threat actor group called Ransom Busters that poses as a recovery firm to extort ransomware victims.
Read at theregister.com ↗BrokerChooser reported that AI-enabled scams surged by 1,210% in 2025, with over 1 in 10 successful scams involving AI or deepfakes.
Read at hrexecutive.com ↗JPMorgan Chase has terminated its banking relationship with the prediction market platform Polymarket due to regulatory concerns.
Read at wsj.com ↗5 of 17 other developments events are listed; the rest were ranked lower by importance and multi-source corroboration and are not shown.