The University of Texas at San Antonio pushed back the start of its fall semester by three days after a cyberattack targeted its academic network over the weekend. Classes that were due to begin on Wednesday, August 19 will now start on Monday, August 24. UT San Antonio is one of the largest universities in Texas, serving more than 42,000 students. According to a statement issued by Andrea Marks,

The University of Texas at San Antonio (UTSA) has postponed the start of its fall semester by three days following a cyberattack that targeted its academic network over the weekend. Classes, originally scheduled to commence on Wednesday, August 19, will now begin on Monday, August 24. UTSA, one of Texas's largest universities, serves over 42,000 students.
According to a statement from Andrea Marks, Senior Executive Vice President of Enterprise Operations and Strategy and Chief Operating Officer, and Michael Schnabel, CTO, the attempted intrusion was detected at the network's perimeter, preventing it from reaching core systems. University Technology Solutions (UTS), collaborating with external incident response specialists, initiated containment measures.
As of their latest update, Marks and Schnabel stated that their investigation has not uncovered any evidence of university data exfiltration. They characterized their response as effective, though they did not elaborate on the nature of the attempted intrusion or identify potential perpetrators.
To facilitate a comprehensive network review and strengthen defenses, UTSA temporarily took certain systems and services offline. This precautionary measure led to disruptions for students, faculty, and staff, including outages of the university phone system and delays with the password reset tool.
University President Taylor Eighmy explained that the decision to delay the semester start was made to ensure all essential university systems, technology, and services are fully operational. He emphasized that the additional time allows teams to meticulously restore services and prepare the university community for a robust start to the semester. Eighmy reiterated that the university responded to attempted unauthorized activity and proactively took systems offline out of an abundance of caution to evaluate the technology environment and reinforce safeguards.

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.