130Articles
10Categories
2026-07-28Date
🚨 CISA KEV 2[−]
28 Jul KEVU.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Arista VeloCloud Orchestrator and Fort…SECURITYAFFAIRS.COM
28 Jul KEVAccelerating CISA BOD 26-04 Vulnerability and Triage Activities through WizWiz enables organizations to continuously assess environments against the CISA KEV catalog, automating risk prioritization, rapid remediation, and forensic triage workflows.WIZ.IO
🐛 COMMON VULNERABILITIES AND EXPOSURES 12[−]
28 JulAttackers Exploit Arista VeloCloud Orchestrator Command Injection FlawA maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave …THEHACKERNEWS.COM
28 JulCritical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging InJetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity …THEHACKERNEWS.COM
28 JulResearcher Says AI Helped Develop Linux Traffic-Control Race Into Root ExploitSTAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free race in the kernel's network traffic-control subsystem.Researcher Lee Ji…THEHACKERNEWS.COM
28 JulJetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)JetBrains has fixed a critical vulnerability (CVE-2026-63077) affecting TeamCity On-Premises and is urging admins to upgrade self-hosted servers as soon as possible. “For those who are unable to do so, we have released a security patch plugin,” noted Daniel Gallo, Sol…HELPNETSECURITY.COM
28 JulJetBrains Patches Critical TeamCity Flaw Allowing Server TakeoverJetBrains patched a critical TeamCity flaw (CVE-2026-63077) enabling unauthenticated code execution on affected on-premise servers. JetBrains has released security updates for TeamCity On-Premises after discovering a critical vulnerability, tracked as CVE-2026-63077 (CVSS score o…SECURITYAFFAIRS.COM
28 JulCritical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as RootOpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt's GitHub advisory, lets an unauth…THEHACKERNEWS.COM
28 JulVU#141367: AT&T's Arris BGW210-700 gateway contains authentication bypass vulnerability in LAN-side management interfaceOverview Firmware versions 2.7.7 and earlier of the Arris BGW210-700 residential gateway contain an authentication bypass vulnerability, tracked as CVE-2026-16771, that allows any unauthenticated LAN-side user to read sensitive configuration data and modify device settings throug…KB.CERT.ORG
28 JulCheck Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)Overview On July 22, 2026, Check Point published a security advisory for CVE-2026-16232 , an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server (MDS). By leveraging CVE-2026-16232, an unauthenti…RAPID7.COM
28 JulChromium: CVE-2026-13032 Use after free in WebGLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 JulChromium: CVE-2026-13028 Use after free in WebGLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 JulChromium: CVE-2026-13030 Uninitialized Use in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 JulChromium: CVE-2026-13037 Use after free in WebViewThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
⚠️ VULNERABILITY DISCLOSURE 36[−]
28 JulAI Agent Drives Espionage Attack on Thai Ministry of FinanceAttackers used Hermes, an autonomous open source tool, in unrestricted "YOLO mode" to conduct espionage against Thailand's Ministry of Finance.DARKREADING.COM
28 JulSamsung’s entry into AI-powered glasses forces CISOs to again consider corporate riskNow that Samsung has jumped into the crowded AI-powered glasses arena alongside Apple , Google , Meta , and others, CISOs and IT leaders are again having to think through whether it makes sense to establish enterprise restrictions on such devices, given the likely data leakage an…CSOONLINE.COM
28 JulHackers are compromising hotel Wi-Fi gateways to hijack Microsoft 365 accountsTraveling enterprise employees beware: Think twice before you log onto that oh-so-convenient public Wi-Fi. Since at least June, threat actors have been compromising “captive” Wi-Fi gateways and other portal appliances at hotels, conference centers, and similar shared venues to hi…CSOONLINE.COM
28 JulMicrosoft unveils multi-model agentic cyber stack for security operationsMicrosoft announced a new AI-powered service that enables enterprise security teams to continuously evaluate and update their organization’s security posture through a series of AI agents that can find vulnerabilities, simulate attacks, detect and triage potential threats, and de…CSOONLINE.COM
28 JulCybersecurity jobs available right now: July 28, 2026Cloud Security Engineer Toyota Automated Logistics | USA | On-site – View job details As a Cloud Security Engineer, you will design and enforce security controls across Azure and on-premises environments, strengthen identity and access management, and maintain clo…HELPNETSECURITY.COM
28 JulMicrosoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the CostMicrosoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% les…THEHACKERNEWS.COM
28 JulCritical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-DayImpacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality. The post Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
28 JulHugging Face breach shows why incident response needs a multi-model AI strategyThe recent breach of Hugging Face’s platform was the latest in a string of AI-assisted intrusions to come to light in recent weeks , showing that attackers can now use LLMs to automate entire attack chains. But it also exposed a limitation for defenders trying to use AI to respon…CSOONLINE.COM
28 JulUnpatched Fastjson Vulnerability Exploited in AttacksThe critical remote code execution bug can be exploited without authentication, under the library’s stock default configurations. The post Unpatched Fastjson Vulnerability Exploited in Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
28 JulRapid7 and Exclusive Networks expand partnership to modernize security operations and accelerate customer successClaudia Zoon is Senior Manager, Channel Sales at Rapid7. Across Belgium, the Netherlands, and Luxembourg, organizations are accelerating digital transformation through AI, cloud adoption, and increasingly connected business operations. These investments are creating new opportuni…RAPID7.COM
28 JulWhy your AI safety certificates are worthless at runtimeEvery week, another enterprise technology vendor issues a glossy press release announcing their new autonomous AI agent architecture, complete with a SOC 2 Type II report, an ISO 42001 certification, and an ironclad safety guarantee. On paper, the enterprise security battle looks…CSOONLINE.COM
28 JulInside the OWASP Agent Security Regression Harness Project - Mert Satilmaz - ASW #393Orgs need to be able to use agents, MCPs, and LLMs in ways that don't lead to unexpected actions and undesirable outcomes. The OWASP Agent Security Regression Harness project is an approach for defining customizable scenarios and testing whether those systems fail against known s…YOUTUBE.COM
28 JulData breach at medical billing firm MCBS affects 1.26 million peopleHealthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people. [...]BLEEPINGCOMPUTER.COM
28 Jul KEVHow we use /goal to find bugs in Patch the PlanetCodex’s /goal feature amplifies bug hunting, but getting good results requires the right prompt, the right scope, and the right number of outcomes per run. For Patch the Planet , our joint initiative with OpenAI to find and fix bugs in open-source software, we pointed Codex at so…TRAILOFBITS.COM
28 JulExposed BMCs hand out password hashes before loginAn attacker who reaches UDP port 623 on a server’s baseboard management controller can ask it for a password hash and receive one before logging in. The exchange is part of the IPMI 2.0 handshake, built on an authentication protocol introduced in 2004. That controller runs …HELPNETSECURITY.COM
28 JulInfoblox joins crowded EASM market with DNS-centric approachWith AI compressing reconnaissance and exploit development from weeks to hours, security vendors are racing to help enterprises identify exposures long before an incident happens. Infoblox is the latest to make that move, announcing its entry into the External Attack Surface Mana…CSOONLINE.COM
28 JulOver 24,000 exposed server BMCs leak password hash via decades-old flawMore than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface. [...]BLEEPINGCOMPUTER.COM
28 JulThe Next Evolution of MDR: Preemptive Defense and Agentic InvestigationFor years, security operations followed a familiar sequence: detect suspicious activity, investigate what happened, and respond before it caused significant harm. That model developed in a threat landscape where defenders had considerably more time to establish the facts and deci…RAPID7.COM
28 JulJFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face BreachJFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog's software repository manager. OpenAI says the models then escalated privileges and moved late…THEHACKERNEWS.COM
28 JulBugcrowd introduces Savant Pathseeker for agentic penetration testing with exploit validationBugcrowd unveils Savant Pathseeker, the first solution in its Agentic Offensive Testing line. Savant Pathseeker gives security teams the speed and scale to test every external web application and API continuously, not just the assets that make it onto the pentest schedule, while …HELPNETSECURITY.COM
28 JulMultiple water facilities in Minnesota attacked; Iranian hackers may be responsibleOn June 16, media reported that Iran-linked Handala had attacked Cal Water. There was no evidence that they tampered with the water supply, but the group warned it would be increasing attacks on U.S. critical infrastructure. On July 23, the Iran-linked WANA News reported: Followi…DATABREACHES.NET
28 JulSystem Prompts Can FailSystem prompts help guide an LLM's behavior, but they aren't a reliable security control. During testing, both open-source and some frontier models were observed ignoring system prompts and exposing information that should have remained protected. As organizations adopt AI agents…YOUTUBE.COM
28 JulAI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/schedAI-assisted research uncovered Linux kernel use-after-free allowing root escalationINFOSECURITY-MAGAZINE.COM
28 JulTengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its ProcessA new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process. If that happens, Tengu's other persistence mechanisms get another chance to relaunch it. Nozomi Networks Labs observed the drop…THEHACKERNEWS.COM
28 JulAI-assisted security tools are finding more bugs, but the threat level has not changedAnalysis from vulnerability intelligence firm VulnCheck shows AI-discovered flaws aren't being exploited any faster than traditional ones. The post AI-assisted security tools are finding more bugs, but the threat level has not changed appeared first on CyberScoop .CYBERSCOOP.COM
28 JulA senator looks to eliminate legacy VPNs from federal government.Decades-old vulnerability exposes 24,000 servers.THECYBERWIRE.COM
28 JulPrivacy-focused search engine NeoSearch open-sources code to promote decentralized web searchPrivacy-focused search engine NeoSearch has open-sourced its code under the Apache License 2.0, allowing users, developers, and researchers to inspect, modify, and run their own versions of the platform. The independent, ad-free search engine said the move is part of its broader …CYBERINSIDER.COM
28 JulFBI sees Anthropic’s Mythos as a law enforcement challengeThe post FBI sees Anthropic’s Mythos as a law enforcement challenge appeared first on CyberScoop .FEDSCOOP.COM
28 Jul'Certighost' Flaw Haunts Microsoft Active Directory CertificatesMicrosoft patched a high-severity vulnerability earlier this month that allows a threat actor to escalate privileges and compromise an AD environment.DARKREADING.COM
28 JulAI Security at Scale, CMMC phase II paused, and the Weekly Enterprise News - ESW #468Interview with Keith Hollender, CEO and Co-Founder of Arcova Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem As enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introduc…YOUTUBE.COM
28 JulvBulletin fixes critical pre-auth RCE flaw with public exploitA critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. [...]BLEEPINGCOMPUTER.COM
28 JulDysphoria Botnet Uses Blockchain Domains to Hide C2 InfrastructureResearchers uncovered the 200,000-device Dysphoria botnet, which uses Ethereum and Solana domains to hide its command servers. QiAnXin XLab, jointly with China’s CNCERT, disclosed Dysphoria, a botnet that has compromised roughly 200,000 devices worldwide and uses Ethereum a…SECURITYAFFAIRS.COM
28 JulOpenAI models used Artifactory zero-days to escape to the internetJFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging Face. [...]BLEEPINGCOMPUTER.COM
28 JulCubePilot drone software dev hit by DNS hijacking to intercept trafficCubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack. [...]BLEEPINGCOMPUTER.COM
28 JulGhost Credentials Expose Cloud Systems to Hidden Identity RisksSecurity researcher Aleksandr Krasnov reveals dormant non-human identities can create security blind spots and releases NHI Hound, an open source tool to sniff out trust paths.DARKREADING.COM
📋 SECURITY BULLETINS 1[−]
28 JulJuly Apple updates are especially important if you receive imagesApple issued a large July security update with several image processing related vulnerabilities that could compromise your device.MALWAREBYTES.COM
📢 SECURITY ADVISORIES 7[−]
28 JulRapid7 Cyber GRC is now available: Turn security action into compliance proofCompliance has become one of the biggest operational drains on modern security teams. CISOs are being asked to manage a growing sprawl of frameworks, prove control effectiveness more often, respond to more customer assurance requests, track risk across a growing web of third part…RAPID7.COM
28 JulCISA shares advice on isolating vital systems during cyberattacksThe U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions. [...]BLEEPINGCOMPUTER.COM
🔥 INCIDENT REPORTING 16[−]
28 JulFor Some, So-Called ‘Skynet Day’ Came too Close to Sci-Fi After a Rogue Agent Hacked Into a StartupDecades after it appeared in “The Terminator,” Skynet looks more like a forecast of the cyber incident in which a rogue AI system hacked into another AI company on its own. The post For Some, So-Called ‘Skynet Day’ Came too Close to Sci-Fi After a Rogue Agent Hacked Into a Startu…SECURITYWEEK.COM
28 JulOrigin Energy Data Breach Affects 900,000 AustraliansThe hacker claimed to have stolen the information of 2 million Origin Energy customers after breaching its systems. The post Origin Energy Data Breach Affects 900,000 Australians appeared first on SecurityWeek .SECURITYWEEK.COM
28 JulShadow AI incident response begins with logs that may already be goneIn this Help Net Security interview, Brandy Wityak, VP of Complex Matters at LevelBlue, explains what happens in the hours after a shadow AI incident. She describes how quickly logs roll over, why firewall records of outbound traffic to AI platforms are often gone before responde…HELPNETSECURITY.COM
28 JulHouston City College - 831,642 breached accountsIn June 2026, Houston City College was the target of a ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from the college was later published publicly and included 832k unique email addresses along with names, addresses, phone numbers, academic records, and …HAVEIBEENPWNED.COM
28 JulCoca-Cola confirms hackers stole data in Fairlife ransomware attackCoca-Cola has confirmed that the ransomware attack on its dairy subsidiary Fairlife involved the theft of company data, weeks after the incident temporarily halted production at its US facilities. Fairlife is a Coca-Cola-owned dairy brand that makes ultra-filtered milk and protei…HELPNETSECURITY.COM
28 JulCoca-Cola Reveals Subsidiary Fairlife Suffered Data BreachCoca Cola claims data was stolen from its Fairlife business after a recent ransomware attackINFOSECURITY-MAGAZINE.COM
28 JulVERITAS project could change the way scientists secure AIThe AI models, datasets, and automated systems researchers depend on can be compromised in ways conventional cybersecurity tools aren’t designed to detect. A new project called VERITAS (VERified Infrastructure for Trustworthy AI in Science) aims to close that gap by establi…HELPNETSECURITY.COM
28 JulTeam Cymru unveils Pure Signal Command for AI-powered threat intelligence and incident responseTeam Cymru has announced Pure Signal Command, the connected operating environment for analysts, security teams, applications, and AI agents to access and act on Team Cymru’s internet infrastructure intelligence. Command unlocks Team Cymru’s globally observed threat intelligence d…HELPNETSECURITY.COM
28 JulPhishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion TechniquesAnalysis of real-life incident response cases by Cisco Talos warns that phishing remains a powerful method of initial compromiseINFOSECURITY-MAGAZINE.COM
28 JulIs Your SSO Protected Against Modern Credential Attacks?A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening help secure modern SSO environments and the applications they protect. [...…BLEEPINGCOMPUTER.COM
28 JulIndia’s Bank of Baroda confirms cyber incident after hackers claim data theftAn employee's email account had been compromised, allowing unauthorized access to "certain data," Bank of Baroda reported.THERECORD.MEDIA
28 JulHugging Face breach reignites open-weights debate, raises liability questionsThe first publicly documented cyberattack run end-to-end by an autonomous AI was an OpenAI benchmark test that escaped its sandbox and breached Hugging Face. In an incident post-mortem compiled with the input from Hugging Face and several hundred members of Cloud Security Allianc…HELPNETSECURITY.COM
28 JulCoordinated cyberattack disrupts water utilities in 30+ Minnesota communitiesA cyberattack of undetermined origin disrupted water treatment plants in at least 30 communities in Minnesota, according to the state's technology bureau. The post Coordinated cyberattack disrupts water utilities in 30+ Minnesota communities appeared first on CyberScoop .STATESCOOP.COM
28 JulYou've been disconnected.A senator targets legacy VPNs. Minnesota water systems come under cyberattack. A 20-year-old flaw exposes 24,000 servers. Microsoft debuts its first cybersecurity AI model. A critical VeloCloud bug is under active attack. The Dysphoria botnet tops 200,000 devices. Apple faces a l…THECYBERWIRE.COM
28 JulStack Sports warns users after payment card data exposed through malicious codeSports technology provider Stack Sports is notifying users of a cybersecurity incident that may have exposed payment card information entered through its Sports Affinity web application platform. According to a data breach notification sent to affected individuals, Stack Sports d…CYBERINSIDER.COM
28 JulAuthorities investigating a coordinated cyberattack against Minnesota water systemsThe two-day attack comes days after federal officials warned of state-linked threat groups targeting a wider set of industrial devices.CYBERSECURITYDIVE.COM
🕵️ THREAT INTELLIGENCE 31[−]
28 JulISC Stormcast For Tuesday, July 28th, 2026 https://isc.sans.edu/podcastdetail/10026, (Tue, Jul 28th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
28 JulDownload: The High-Performance Team PlaybookGet practical insight from teams who’ve built, scaled and handed over engineering functions at enterprise level. Most engineering teams don’t fail because of bad engineers. They fail because performance is assumed. This playbook shows how high-performance teams are built intentio…HELPNETSECURITY.COM
28 JulCall of Duty Mobile scam uses fake free points giveaway to hijack players’ accountsCall of Duty Mobile players should watch out for a phishing campaign disguised as a free Call of Duty Points giveaway, Malwarebytes researchers have warned. Victims are asked to log in with their email address and password to claim free Call of Duty Points (CP), the game’s …HELPNETSECURITY.COM
28 JulAI took more than junior developer jobs and the bill comes laterA ticket comes in for a small bug fix. Hand it to the junior on your team and you wait a day, review something that half works, and sit down to explain what went wrong. Describe it to Claude and the patch merges before lunch. The second path wins on every number your team reports…HELPNETSECURITY.COM
28 JulAutoIT Payload Injector , (Tue, Jul 28th)For a long time, AutoIT[ 1 ] has been pretty common in the malware ecosystem. Threat actors still use it because it's easy to write and powerful. Indeed, it can perform all the required actions to inject a payload into a remote process as you'll see below. ISC.SANS.EDU
28 JulGoogle Adopts New Threat Actor Naming SystemThe new two-word naming convention uses a memorable term utilized in public reporting and a cluster-categorization word. The post Google Adopts New Threat Actor Naming System appeared first on SecurityWeek .SECURITYWEEK.COM
28 JulGrafana Assistant expands with AI agents for investigations, automation, and observabilityGrafana Labs has announced the general availability of six AI capabilities, extending Grafana Assistant into an agentic operations layer that detects, investigates, and remediates production issues. The releases include Grafana Assistant Investigations, Grafana Assistant Workspac…HELPNETSECURITY.COM
28 JulAWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027AWS Shield Advanced, a managed service that protects applications from external threats, is adding the Anti-DDoS managed rule group, designed for application-layer (L7) DDoS protection, to eligible web access control lists (ACLs) in Count mode. The addition preserves traffic flow…HELPNETSECURITY.COM
28 JulMurder in Mexico City: The Assassination of Leon TrotskyFor those of you who have visited the International Spy Museum, you may be familiar with one of our most prized artifacts, the ice ax used to assassinate Leon Trotsky in 1940. Trotsky was the operational mastermind of the Russian Revolution of 1917, and when Vladimir Lenin died, …THECYBERWIRE.COM
28 JulHacker Conversations: Tal Kollander’s Journey From Black Hat to Hack BlockerTal Kollander’s history divides neatly into two halves: first as an active hacker and then as the block that stops hacks. The post Hacker Conversations: Tal Kollander’s Journey From Black Hat to Hack Blocker appeared first on SecurityWeek .SECURITYWEEK.COM
28 JulAct Security Emerges from Stealth to Fight the Patch ProblemAct Security tackles the spiraling patch problem caused by AI’s ability to find new vulnerabilities in existing cloud environments. The post Act Security Emerges from Stealth to Fight the Patch Problem appeared first on SecurityWeek .SECURITYWEEK.COM
28 JulHush Security Raises $30 Million for AI Agent GovernanceThe startup will invest in expanding engineering and sales teams, accelerating ecosystem support, and expanding corporate partnerships. The post Hush Security Raises $30 Million for AI Agent Governance appeared first on SecurityWeek .SECURITYWEEK.COM
28 JulAxon Is Another License Plate Surveillance CompanyGovernments are switching, but I’m not sure it makes a difference : …some municipalities, including Denver, Colorado, are ditching their Flock arrays. But keep in mind that if they’re only switching from Flock to another brand of license-plate readers, like Axon…SCHNEIER.COM
28 JulMicrosoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI ModelThe company claims MAI-Cyber-1-Flash tops Anthropic’s Mythos and OpenAI’s GPT-5.6 Sol in CyberGym testing. The post Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model appeared first on SecurityWeek .SECURITYWEEK.COM
28 JulOT Security Startup Frenos Raises $1.52 MillionThe company will use the fresh investment to grow its customer success and AI R&D teams. The post OT Security Startup Frenos Raises $1.52 Million appeared first on SecurityWeek .SECURITYWEEK.COM
28 JulCyberhaven launches Flow to secure data across human and AI workflowsCyberhaven has introduced Cyberhaven Flow, an AI-native data security platform built to protect data across human and AI workflows. Flow connects lineage, identity, and behavior to protect data as it is created, copied, fragmented, and shared, marking a shift in how protection ad…HELPNETSECURITY.COM
28 JulIntel 471 expands Verity471 with AI agent and MCP support for threat intelligenceIntel 471 has announced two new AI capabilities in the Verity471 platform, MCP471 and Agent471. As attackers use AI to lower the barrier to scale, security teams must use their own AI capabilities to make intelligence more accessible, allowing them to pinpoint what is relevant to…HELPNETSECURITY.COM
28 JulSpecterOps brings AWS attack path management and AI to hybrid identity securitySpecterOps has announced new capabilities built to give defenders a dynamic understanding of how adversaries traverse their hybrid environment and the ability to proactively eliminate pathways before they can be abused. BloodHound Enterprise adds support for Amazon Web Services a…HELPNETSECURITY.COM
28 JulBlackCloak extends deepfake protection to the executive’s trusted circleDeepfakes have made one of our oldest assumptions unreliable: that you can trust a familiar face or voice. While the industry focuses mainly on building “in-line detection tools” that try to spot the fake, BlackCloak, the leader in Digital Executive Protection (DEP), built Impers…HELPNETSECURITY.COM
28 JulPrescient Security adds attack surface management to Cait, broadens AI-assisted pentestingPrescient Security has announced a series of capability expansions to Cait (Cacilian AI), its continuous AI-assisted penetration testing service. The updates which will roll out through summer 2026 add attack surface management (ASM), new asset testing types and expanded environm…HELPNETSECURITY.COM
28 JulCyera Acquiring Oasis Security in $1 Billion DealOasis Security recently raised $120 million in Series B funding for its agentic access management platform. The post Cyera Acquiring Oasis Security in $1 Billion Deal appeared first on SecurityWeek .SECURITYWEEK.COM
28 JulApple Patches 87 Vulnerabilities in iOS, 155 in macOS TahoeApple announced that dozens of vulnerabilities have been patched in each of its operating systems. The post Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe appeared first on SecurityWeek .SECURITYWEEK.COM
28 JulDisrupting supply chain attacks on npm and GitHub ActionsExplore the changes we've shipped across npm and GitHub Actions over the past few months to disrupt supply chain attack techniques and limit their impact. The post Disrupting supply chain attacks on npm and GitHub Actions appeared first on The GitHub Blog .GITHUB.BLOG
28 JulMicrosoft launches agentic security platform designed to combat AI-based attacksThe rollout comes amid growing concerns about the ability of hackers to launch campaigns using autonomous methods. CYBERSECURITYDIVE.COM
28 JulCompanies fear AI risks more than common cybersecurity threatsThat misprioritization could blind companies to the threats they should be focusing on, Arctic Wolf said in a new report.CYBERSECURITYDIVE.COM
28 JulItaly fines US data broker Lusha €2 million over unlawful data collectionItaly's data protection authority has fined US-based data broker Lusha Systems Inc. €2 million (approximately $2.3 million) for unlawfully collecting, enriching, and selling personal data belonging to a large number of individuals in Italy. Lusha operates a subscription-based pla…CYBERINSIDER.COM
28 JulCo-Founder of Controversial Spyware Firm Had Israeli Diplomatic PassportThe OCCRP found that the co-founder of NSO Group, which develops Pegasus spyware, travelled to Panama in 2013 on an Israeli diplomatic passport. The post Co-Founder of Controversial Spyware Firm Had Israeli Diplomatic Passport appeared first on The Citizen Lab .CITIZENLAB.CA
28 JulAI Is Flooding Bug BountiesGitHub is shifting more emphasis toward an invite-only bug bounty program, while other projects have reduced or ended public programs after receiving large volumes of low-quality reports. Many of these submissions are generated from AI tools or automated scanners without proper v…YOUTUBE.COM
28 JulHere’s what Anthropic found when it turned Mythos loose on encryption algorithmsClaude Mythos exposed mathematical weaknesses in a post-quantum candidate and a simplified version of AES, marking a major breakthrough for AI-driven cryptanalysis. The post Here’s what Anthropic found when it turned Mythos loose on encryption algorithms appeared first on C…CYBERSCOOP.COM
28 JulDeep Fakes, Molten Salt, PLCS, Checkpoint, Hugging Face, CENTOS, Josh Marpet and More - SWN #602Deep Fakes, Molten Salt, PLCS, Checkpoint, Hugging Face, CENTOS, Josh Marpet, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-602YOUTUBE.COM
28 JulIndustrial Controllers Are Under AttackU.S. cybersecurity agencies are warning that a campaign targeting programmable logic controllers (PLCs) has expanded from one major vendor to include multiple leading industrial automation manufacturers. PLCs are foundational components of industrial control systems (ICS) and ope…YOUTUBE.COM
🌐 CYBER THREAT LANDSCAPE 4[−]
28 JulMirage Kitten targets Middle East and Africa region with new malwareKaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.SECURELIST.COM
28 JulNew Crypter-as-a-Service Cruciferra Fuels Stealthy Malware Attacks WorldwideProofpoint uncovered Cruciferra, a crypter-as-a-service that helps hackers evade antivirus and deliver malware in multiple campaigns. Proofpoint’s research team traced a wave of income-tax-themed lures targeting Indian taxpayers, tax professionals, and corporate finance tea…SECURITYAFFAIRS.COM
28 JulNimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert RelaysThe Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia. The intrusions involve t…THEHACKERNEWS.COM
28 JulWe rebuilt Malwarebytes Mobile Security for the scams of todayYour phone needs more than a lock screen to stay safe. We've rebuilt Malwarebytes Mobile Security to put scam protection first and keep your phone secure.MALWAREBYTES.COM
🎙️ PODCASTS 2[−]
28 JulBetween Two Nerds: Cyber is peopleIn this edition of Between Two Nerds Tom Uren and The Grugq discuss how important people are to cyber power and whether the rise of AI is changing that. This episode is also available on YouTube.RISKY.BIZ
28 JulInside the Media Mind of Bree Fowler: Special Black Hat Episode!On this episode of #IMM, Christine and Madison sit down with freelance journalist Bree Fowler to discuss all things Black Hat Conference.THECYBERWIRE.COM
📡 INFOSEC NEWS 19[−]
28 JulHugging Face Has a Deepfake Nudes ProblemResearchers tested top image editing models on Hugging Face and found they could easily create explicit deepfakes—and 1,000 image editing prompts show how people use the software.WIRED.COM
28 JulNew CREST AI Standards to Deliver AI-Enabled Pentesting AccreditationCREST’s new AI standards are optional add-on requirements for cybersecurity service providers wishing to demonstrate responsible AI usageINFOSECURITY-MAGAZINE.COM
28 JulNVIDIA’s Open Secure AI Alliance Is Missing Some Big NamesNVIDIA has launched a new Open Secure AI Alliance to build an “open defense stack for agents”INFOSECURITY-MAGAZINE.COM
28 JulIR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chainsTalos IR's Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn how to sharpen your defenses.TALOSINTELLIGENCE.COM
28 JulVatican’s Click To Pray app exposed personal data from 700,000 usersAnyone could access other Click To Pray users' personal information. The flaw went unfixed for more than six months after it was reported.MALWAREBYTES.COM
28 JulShared Claude chats were searchable on GoogleReddit users found that by using a specific search query, they could find shared Claude conversations in search results.MALWAREBYTES.COM
28 JulMicrosoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled ThreatsMicrosoft has launched a new agentic security system for cyber defenders as well as its first cyber-focused AI modelINFOSECURITY-MAGAZINE.COM
28 JulFormer Citigroup CISO Blauner on What Makes A Great Security LeaderThe cybersecurity pioneer discusses the evolution of the CISO role, AI's impact on careers, and why operational resilience is the profession's next frontier.DARKREADING.COM
28 Jul24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before LoginCybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol to the public internet. Of the 36,872 internet-exposed server-management i…THEHACKERNEWS.COM
28 JulBugs in Hugging Face Diffusers Bypass Custom Code SafeguardThree CVEs in Hugging Face diffusers let a malicious model repo run code on any machine that loads itINFOSECURITY-MAGAZINE.COM
28 JulThe risk hiding behind exposed MCP serversHow unauthenticated Model Context Protocol (MCP) servers are opening doors to sensitive cloud data, IAM, and command execution.WIZ.IO
28 Jul2026 Phase 1a IRAP report is now available on AWS Artifact for Australian customersAmazon Web Services (AWS) is excited to announce that the latest version of Information Security Registered Assessors Program (IRAP) report (Phase 1a – full assessment) is now available through AWS Artifact. An independent Australian Signals Directorate (ASD) certified IRAP asses…AWS.AMAZON.COM
28 JulJoint guidance on isolating vital systemsThis joint guidance is intended to support senior decision-makers within CI organizations.CYBER.GC.CA
28 JulAWS KMS or AWS CloudHSM: Choose the right key management solutionChoosing the right cryptographic key management service on Amazon Web Services (AWS) starts with understanding the difference between AWS Key Management Service (AWS KMS) and AWS CloudHSM. Both provide key storage backed by a hardware security module (HSM) but serve very differen…AWS.AMAZON.COM
28 JulWhen AI Agents Escape Sandboxes, Old Security Rules ApplyOpenAI's recent AI agent sandbox escape proves traditional security principles matter more than ever: limit access, isolate execution, log everything.DARKREADING.COM
28 JulStronger AI Safety Requires Peeking Inside the 'Black Box'Researchers propose focusing on identification of certain cognitive elements in LLMs that indicate when AI systems may take an unwanted action.DARKREADING.COM
28 JulFlaw From 2002 Exposes Data Centers to Server TakeoverLots of Internet-exposed server management controllers are subject to offline password-cracking attacks — and adversaries have taken note.DARKREADING.COM
28 JulSenate confirms Clayton as intel chief after delaysA party-line vote in the Senate installed Jay Clayton as director of national intelligence, a job that has drawn increasing scrutiny during Donald Trump's second term as president.THERECORD.MEDIA
28 JulA Typo Landed an Innocent Gamer in Prison for 18 MonthsHow much could a single underscore in a username really matter? Just ask Brandon Klayme, who served 18 months in prison before realizing how authorities arrested, charged, and convicted the wrong man.WIRED.COM