🐛 COMMON VULNERABILITIES AND EXPOSURES 13[−]
29 JulA 13-year-old flaw is exposing tens of thousands of data center management systemsThe ‘no man’s land’ beneath the OS on enterprise servers is becoming the malicious actors’ next target. Attackers are gaining a foothold into broader data center environments by exploiting Baseboard Management Controllers (BMCs) that are largely unprotected, still running decades…CSOONLINE.COM
29 JulRansomware report: VPNs in the crosshairs, AI attacksRansomware attacks were up year over year in June for the fourth consecutive month, according to the NCC Group, though attacks increased just 3% in Q2 2026 versus the previous quarter. VPNs and other network edge devices continue to be prime initial access targets. And an autonom…CSOONLINE.COM
29 JulPublic PoC Released for Exploited Check Point SmartConsole Authentication BypassCybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild. The vulnerabi…THEHACKERNEWS.COM
29 JulNew Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell CommandsGitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account. Tracked as CVE-2026-6…THEHACKERNEWS.COM
29 JulContrast CVE Shield aims to protect applications while security teams deploy patchesContrast Security has announced Contrast CVE Shield, designed to help organisations defend against the growing number of exploits generated with advanced AI models such as Claude Mythos. Contrast CVE Shield runs inside the application, where it detects, monitors and blocks attemp…HELPNETSECURITY.COM
29 JulResearchers Show a Single Malicious Webpage Visit Can Compromise Tor BrowserNebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High…THEHACKERNEWS.COM
29 JulBroadcom Patches Critical VMware ESXi Vulnerability Enabling Host Code ExecutionBroadcom patched a critical VMware ESXi VM escape flaw (CVE-2026-47876) that could let attackers run code on the host from a compromised virtual machine. Broadcom has released patches to address five vulnerabilities affecting VMware ESXi, vCenter, Workstation, and Fusion, includi…SECURITYAFFAIRS.COM
29 JulRuflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI MemoryCybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10…THEHACKERNEWS.COM
29 JulThree Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM EscapeBroadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which ha…THEHACKERNEWS.COM
29 JulVU#305509: OPeNDAP Hyrax is vulnerable to SSRF and Credential DisclosureOverview A vulnerability has been discovered in the OPeNDAP Hyrax software solution. A remote attacker with the ability to submit crafted requests to an affected Hyrax instance could cause the application to communicate with unauthorized remote systems. Under certain conditions, …KB.CERT.ORG
29 JulCVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCityOverview On July 27, 2026, JetBrains published a security advisory for CVE-2026-63077 , a critical unauthenticated vulnerability affecting all versions of TeamCity On-Premises. The issue is classified as deserialization of untrusted data and has a CVSS score of 9.8 . An unauthent…RAPID7.COM
29 JulCritical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image UploadsRuby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process en…THEHACKERNEWS.COM
29 Jul KEVCisco warns of FMC static credential flaw exploited in zero-day attacksCisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. [...]BLEEPINGCOMPUTER.COM
⚠️ VULNERABILITY DISCLOSURE 44[−]
29 JulHow AI is Rewriting the Zero-Day Playbook for Preemptive SecurityThe scenario is all too familiar for any cybersecurity professional: It’s late in the day, and a critical zero-day vulnerability is disclosed. When this happens, CISOs from every industry immediately turn to their Security Operations Centers (SOC) with the single most important, …RAPID7.COM
29 JulClaude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES AttackAnthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic's…THEHACKERNEWS.COM
29 Jul KEVArista patches maximum severity vulnerability that is already being exploitedArista has patched a VeloCloud Orchestrator (VCO) security hole that has been actively leveraged in the wild, one that the vendor says “may allow a remote attacker to access privileged internal functionality and impact the VCO host.” The Arista security advisory added that the ho…CSOONLINE.COM
29 JulMeasuring LLMs’ Ability to Perform CryptanalysisThere’s new benchmark measuring AI’s ability to perform mathematical cryptanalysis. Anthropic’s frontier model actually found new attacks. The benchmark: “ CryptanalysisBench: Can LLMs do Cryptanalysis? ” The idea is to benchmark the ability of LLMs …SCHNEIER.COM
29 JulFortinet’s new FortiGate platform converges firewall, SASE technologiesFortinet has expanded its firewall family with new high-speed boxes that, when combined with the vendor’s FortiSASE Outpost software, extend cloud-based SASE (secure access service edge) capabilities and policy enforcement to on-premises environments. The new midrange FortiGate 1…CSOONLINE.COM
29 JulThe CSO’s blind spot: Why platform engineering 2.0 is now a security imperativeSecurity leaders have spent the last decade building controls around people and code. Shift-left practices caught vulnerabilities earlier in the development cycle. Zero trust reduced lateral blast radius. Developer tooling added guardrails at the IDE. The architecture was sound —…CSOONLINE.COM
29 JulWhat a CISO and Marketing Partnership Actually Looks Like with Jason Rebholz of Evoke SecurityJason Rebholz read a blog post about MCPs and saw the whole trajectory of AI security play out in front of him. Twenty years of incident response experience told him we were about to make the same mistakes…just faster. He started Evoke Security the same way he has approached ever…THECYBERWIRE.COM
29 JulSpecter: Open-source NFC reader bug sweep for Flipper ZeroSpecter is a Flipper Zero app that finds powered NFC readers by listening for the radio field they give off. The readers it hunts work at 13.56 MHz. The Flipper’s own chip does the sensing The onboard ST25R3916 carries a hardware external-field detector, the same circuit th…HELPNETSECURITY.COM
29 JulYour AI agents can reach data no one approvedA credential expired. An AI agent kept using it anyway, and a mid-sized company’s systems went down for a quarter’s worth of trouble before anyone traced the failure back to a non-human account no one had been logging. That agent could reach customer records, source c…HELPNETSECURITY.COM
29 JulFlying Eagle Android RAT Traces Found on 170 Servers as Source Code CirculatesSource code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced matching control panels and certificates to 170 internet servers. They linked the framework to a fa…THEHACKERNEWS.COM
29 JulAbnormal AI extends behavioral security to identities, AI systems, and insider threatsAbnormal AI has announced the expansion of its Behavioral Security Platform across the enterprise, introducing three new products: Identity Threat Protection, AI Governance, and Infiltration Prevention. Together, the launch extends the behavioral AI that already secures over 4,50…HELPNETSECURITY.COM
29 JulMend.io enhances application security with AI runtime protection and faster zero-day responseMend.io has announced new capabilities across Mend AI and Mend AppSec to help organizations respond faster to both application risk and the expanding attack surface created by AI. Mend.io’s latest enhancements help teams identify meaningful risk, reduce manual investigation…HELPNETSECURITY.COM
29 JulReco enhances AI Runtime with browser-based AI security and automated remediationReco has announced an expansion of AI Runtime, a core component of the Reco Platform. This update adds browser-based enforcement, real-time prompt analysis and blocking, and automated remediation to the Reco Platform. Every agent an enterprise runs carries a blast radius: the app…HELPNETSECURITY.COM
29 JulInfoblox enters EASM market with attack surface and supply chain risk toolsInfoblox has announced its entry into the external attack surface management (EASM) market. Together, with the introduction of Supply Chain Intelligence, the launch expands the Infoblox Exposure Management portfolio, helping organizations identify, prioritize and reduce exposures…HELPNETSECURITY.COM
29 Jul KEVRisk-based patching is the future. AI made it table stakesCISA’s new Binding Operational Directive (BOD) 26-04 marks one of the most important changes to federal vulnerability management in years. Rather than requiring agencies to patch every critical vulnerability on the same timetable, the directive prioritizes remediation based on ri…CSOONLINE.COM
29 JulJFrog Zero-Days Exploited in OpenAI-Hugging Face HackThe OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given. The post JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack appeared first on SecurityWeek .SECURITYWEEK.COM
29 JulFortiGate 1200G brings FortiSASE Outpost to customer-controlled environmentsFortinet has announced the FortiGate 1200G series, the newest addition to the FortiGate G series with FortiSASE Outpost, which brings cloud-delivered security services into customer-controlled environments. By combining high-performance threat protection, connectivity, hardware-r…HELPNETSECURITY.COM
29 JulWhatsApp brings end-to-end encrypted voice and video calls to the webWhatsApp has launched support for voice and video calls on the web, allowing users to make and receive calls directly from their browser without installing the desktop app. Web Calling (Source: WhatsApp) The new Web Calling feature is designed for people using shared or restricte…HELPNETSECURITY.COM
29 JulRoot Evidence puts real-world evidence at the center of vulnerability prioritizationRoot Evidence has launched the Evidence Platform, a vulnerability management platform that prioritizes vulnerabilities based on evidence of real-world exploitation and financial impact rather than severity scores alone. The platform is designed to help security teams focus on the…HELPNETSECURITY.COM
29 JulTransparency, The Key To Team Motivation For Remote Workers - Charles Gaudet - BSW #458Since the pandemic, managing remote teams have been challenging. How do you measure performance and motivate teams when they are remote? Charles Gaudet, CEO & Founder at Predictable Profits, joins Business Security Weekly to discuss why transparency is the key to team motivation …YOUTUBE.COM
29 JulLong-Lived Vulnerability in Microsoft Secure BootMicrosoft’s Secure Boot has had a serious vulnerability for most of its existence. An industry-wide standard Microsoft invented to protect Windows, and later Linux, devices from firmware infections has been trivial to bypass for 13 of its 14 years of existence. The discover…SCHNEIER.COM
29 JulIt’s easier to steal cargo than toothpasteOur cybersecurity world can get quite interesting and even close to science fiction sometimes. No, it’s not AI this time, but something movie-worthy nevertheless. Picture scenes from known heist-themed movies such as “Ocean’s Eleven” or “Mission: Impossible”. Real-world equivalen…CSOONLINE.COM
29 Jul KEVJust 1% of AI-Discovered Vulnerabilities Exploited in the Wild, Research ShowsFor now, the use of AI benefits vulnerability research more than vulnerability exploitation, a VulnCheck researcher saidINFOSECURITY-MAGAZINE.COM
29 JulExploiting Titan QuestTitan Quest is a hack-and-slash video game released in 2006. In 2016, THQ Nordic released an Anniversary Edition. In the version provided by GOG, several development tools are installed with the game. These allow for the creation of new maps, items, and effects. This article deta…SYNACKTIV.COM
29 JulCritical VM Escape Vulnerability Patched in VMware ESXiA total of five vulnerabilities have been patched in VMware ESXi, vCenter, Workstation, and Fusion. The post Critical VM Escape Vulnerability Patched in VMware ESXi appeared first on SecurityWeek .SECURITYWEEK.COM
29 JulOpenAI AI Model Used JFrog Artifactory Zero-Day Before Hugging Face BreachOpenAI confirmed its AI exploited an Artifactory zero-day to escape its test environment before breaching Hugging Face. Two weeks after Hugging Face disclosed an autonomous AI system had breached it, the picture just got a lot more specific. OpenAI has published an update confirm…SECURITYAFFAIRS.COM
29 JulMythos Asks the Right Question. It Doesn't Answer It.AI is compressing exploit timelines. The real question isn't whether your vulnerability management playbook needs to change, it's which part of it you've been getting wrong all along. The conversation happening in security circles right now goes something like this: Mythos is her…THEHACKERNEWS.COM
29 Jul KEVOpenAI rogue AI agent’s attack expanded beyond Hugging FaceThe autonomous AI agent that escaped during OpenAI testing exploited weaknesses across a customer workload, a third-party cloud platform, and Hugging Face’s production environment before being contained, according to new technical disclosures that provide the clearest picture yet…CSOONLINE.COM
29 JulShutterGap: Aryon Security finds 3.7M AWS cloud resources exposed beyond CSPM/CNAPP visibilityResearch from Aryon reveals that each year, 3,731,699 short-lived cloud resources containing highly sensitive information are publicly exposed. This impacts any organization using AWS services that support public sharing. These exposures often last only minutes or hours, too brie…HELPNETSECURITY.COM
29 JulTengu botnet reboots Linux devices to survive removalA new Mirai-derived IoT botnet can force an infected Linux device to reboot once its main process is killed, giving its persistence mechanisms another opportunity to relaunch it, Nozomi Networks Labs has found. The malware, dubbed Tengu, was discovered by a machine-learning syste…HELPNETSECURITY.COM
29 JulThe Wiz Red Agent is Now Generally AvailableContinuously uncover complex, exploitable risks to stay ahead in the AI Threat Era with the Red AgentWIZ.IO
29 JulNine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance PaymentsCybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years. According to Russian cybersecurity vendor F6, the t…THEHACKERNEWS.COM
29 JulLaundry Bear’s webmail hackers had more in store after February, report saysResearchers say the Russian state-linked hacking group tracked as Laundry Bear recently began exploiting a bug in Microsoft Outlook Web Access.THERECORD.MEDIA
29 JulShinyHunters Claims Ernst & Young Data Breach, Threatens to Leak Stolen DataShinyHunters claimed the Ernst & Young data breach, threatening to leak stolen tax records unless the firm contacts the group by July 31. The ShinyHunters cybercrime group has taken responsibility for the recently disclosed data breach involving professional services firm Ern…SECURITYAFFAIRS.COM
29 JulMythos takes its first shot at post-quantum cryptographyAnthropic’s Claude Mythos Preview model has helped researchers discover ways to speed up attacks against two widely studied cryptographic algorithms. One of the targets is Hawk, a candidate for post-quantum digital signature algorithms currently being evaluated by NIST, while the…CSOONLINE.COM
29 JulTame Dependabot: Group your updates, slow the cadence, keep security fastDependabot keeps your dependencies current, but its defaults can flood your repository with pull requests. Here's how grouping updates, slowing the cadence, and keeping security fixes fast cut the noise on a Microsoft open source project. The post Tame Dependabot: Group your upda…GITHUB.BLOG
29 JulRussian-Alligned TA488 Returns With Persistent Outlook Web Access AttackTA488 returned with OWA half-click exploit deploying OWAReaper implant that survived re-imagingINFOSECURITY-MAGAZINE.COM
29 JulPatch-Resistant 'RufRoot' Flaw Can Unleash Malicious AI Agent SwarmsThe vulnerability in the AI hosting platform Ruflo allows an unauthenticated attacker to take over the system and corrupt memory, so bad behavior can persist after patching.DARKREADING.COM
29 JulMeasuring the Tendency of AI Agents to Go RogueThis essay was written with Barath Raghavan, and originally appeared in The Guardian . In July, Hugging Face, a company that hosts much of the world’s AI software and open-source AI models, was hacked. A malicious dataset had been used to run code on one of its servers. Who…SCHNEIER.COM
29 JulVU#293714: Arbitrary File Overwrite in Develar app-builder (zipx.Unzip) via Symlink Following on macOS (APFS)Overview A vulnerability in the zipx.Unzip extraction routine of Develar’s app-builder allows an attacker to overwrite arbitrary files on macOS using Apple File System (APFS). The issue arises from a combination of Unicode normalization collisions and unsafe symlink-following beh…KB.CERT.ORG
29 JulAmazon identifies North Korean hacker group behind open-source supply chain attacksAmazon is sharing new findings about how a threat actor linked to the Democratic People’s Republic of Korea (DPRK) is targeting open source software libraries, the shared building blocks that companies around the world use to develop applications. Amazon Threat Intelligence has l…AWS.AMAZON.COM
29 JulOpenAI's Rogue Model Claims More Victims Beyond Hugging FaceOpenAI revealed rogue AI models compromised more services than initially disclosed, including a Modal customer environment and others.DARKREADING.COM
29 JulA little-known npm package was North Korea’s warm-up act for the axios hackAmazon's threat intelligence team traced domain records from the open-source software hack to a smaller, earlier compromise by the same North Korean group. The post A little-known npm package was North Korea’s warm-up act for the axios hack appeared first on CyberScoop .CYBERSCOOP.COM
29 JulRussian hackers exploit Exchange OWA zero-day for long-term mailbox accessThe Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper. [...]BLEEPINGCOMPUTER.COM
📢 SECURITY ADVISORIES 9[−]
29 JulAI agent hacks national finance ministry, Botnet uses blockchain, Healthcare chain reopensHospital ransomware fallout, blockchain botnet C2, and AI agent loose in Thailand's Finance Ministry. South Carolina's AnMed reopened some physician offices four days into a ransomware attack with phones, internet, and systems still offline, forcing manual processes and in-person…CYBERSECURITYTODAY.LIBSYN.COM
29 JulNCSC Publishes Guidance to Aid Incident Response and RecoveryThe National Cyber Security Centre has released a detailed framework to assist with incident response and recoveryINFOSECURITY-MAGAZINE.COM
29 JulAccuris uses AI to improve BOM decisions and supply chain resilienceAccuris has announced new AI capabilities for BOM Intelligence, part of its Supply Chain Intelligence suite. The launch gives engineering, procurement and supply chain teams a clearer way to move from spotting component risk to acting on it: catching obsolescence early, closing c…HELPNETSECURITY.COM
29 JulWyden calls for federal ban on legacy VPNs over security concernsUS Senator Ron Wyden is urging the Trump administration to phase out legacy virtual private network (VPN) technology across the federal government, arguing that outdated remote access systems have repeatedly enabled Chinese and Russian state-sponsored hackers to breach government…CYBERINSIDER.COM
29 JulJoint guidance on minimum elements for a software bill of materialsThis publication updates and replaces the 2021 Minimum Elements for a Software Bill of Materials published by the United States’ National Telecommunications and Information Administration.CYBER.GC.CA
29 JulCrypto Needs Rules to SurviveCryptocurrency continues to spark debate over how much regulation is appropriate. Some advocate for minimal oversight, while others argue that standards and regulatory frameworks are necessary for broader adoption and responsible business practices. Without consistent rules, mark…YOUTUBE.COM
29 JulMore than meets the AI.The Senate confirms Jay Clayton to lead ODNI. A new CISA framework highlights critical infrastructure isolation capabilities. OpenAI’s rogue agent breached more than just Hugging Face. The average cost of a data breach continues to rise. Indirect prompt injection proves irresisti…THECYBERWIRE.COM
29 JulClaude Mythos Shows AI Can Outpace Human Cryptography ResearchClaude Mythos found new flaws in HAWK and reduced AES, proving AI can autonomously advance cryptography research. Anthropic published two cryptographic research results achieved by Claude Mythos Preview working mostly autonomously: an improved attack on HAWK, a post-quantum digit…SECURITYAFFAIRS.COM
🔥 INCIDENT REPORTING 21[−]
29 JulOpenAI’s Rogue AI Agent Hacked More Than Just Hugging FaceIn a new disclosure, OpenAI says its agent used exposed logins to gain access to at least four “publicly available services” in its unhinged quest to solve a test.WIRED.COM
29 JulTwo Compromised joyfill npm Packages Run RAT When Imported Into Node.jsBeta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The list of affected packages is as follows - @joyfill/layouts@0.1.2-2773.beta.0 @joyfill/components@4.…THEHACKERNEWS.COM
29 JulThe energy sector’s OT cybersecurity talent is retiring faster than it can be replacedA ransomware hit lands a chemical plant in a safe state. Nobody is hurt, the site holds steady, and the operators begin the restart. The systems stay down. Every attempt to bring them online meets encrypted processes and altered configurations. The outage runs into weeks, and the…HELPNETSECURITY.COM
29 JulOpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face BreachOpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face's production environment, and also hacked multiple third-party accounts and services as part of the attack. The latest disclosure sho…THEHACKERNEWS.COM
29 JulRisky Business #846 -- OpenAI built a fireplace out of woodOn this week’s show special guest co-host Pete Ranks, the former director of the CIA’s Centre for Cyber Intelligence, joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover: Everyone signs the open weights open letter, except Anthropic… of course…RISKY.BIZ
29 JulRisky Bulletin: Cyberattack disrupts Minnesota water utilitiesA cyberattack has disrupted water utilities in more than 30 communities in Minnesota, Denmark tests a secondary banking system in case of a cyberattack, North Korea arrests bank hackers, and a new Chinese cyber contractor has been identified.RISKY.BIZ
29 JulVPN Breach Exposes 58 Million Connection Logs Despite “No-Logs” ClaimsA breached “no-logs” VPN exposed 58 million connection logs and millions of user, device, and payment records, contradicting its privacy claims. A threat actor on the Altenen cybercrime forum is distributing a 17 GB SQL database claimed to have been stolen from SplitV…SECURITYAFFAIRS.COM
29 JulOpenAI’s rogue AI agent shows why we need federal rules for autonomous systemsThe Hugging Face breach shows there is a gap in federal policy. The frameworks to govern autonomous AI already exist—there just needs to be the desire to apply them. The post OpenAI’s rogue AI agent shows why we need federal rules for autonomous systems appeared first on Cy…CYBERSCOOP.COM
29 JulOver 30 water systems in Minnesota hit by coordinated cyberattackMinnesota officials have activated a statewide cybersecurity response after a coordinated cyberattack targeted the operational technology (OT) of more than 30 community water systems across the state. Authorities say there is currently no indication that residents need to alter t…CYBERINSIDER.COM
29 JulOpenAI’s Rogue AI Agent Breached Second Company, Report SaysReuters says OpenAI’s rogue AI agent also breached a Modal customer, exposing a wider attack and raising fresh concerns over autonomous AI safety. Reuters reported that the OpenAI agent that hacked Hugging Face earlier this month also compromised a customer at a second comp…SECURITYAFFAIRS.COM
29 JulThe Average Cost of a Data Breach Rises to $5 MillionIBM Cost of a Data Breach Report warns that the global average cost of a data breach has reached a record high of $4.99m – and AI-backed attacks have played a roleINFOSECURITY-MAGAZINE.COM
29 Jul73% of Organizations Say They Are Not Fully Ready for a Major CyberattackMost organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the coordination, visibility, and executive alignment needed to withstand a serious cyberattack. According to The State of Incident Respon…THEHACKERNEWS.COM
29 JulCyberattack hits Angola’s largest telco hours before landmark stock debutAngola’s largest telecommunications operator, Unitel, was hit by a cyberattack that has left millions of people nationwide without voice services, mobile data, and internet access.THERECORD.MEDIA
29 JulStairwell launches Backstory, pioneering agentic investigation for malware blast radiusStairwell, the AI SOC that stops breaches no one else can, today announced the availability of Backstory, an agentic investigation platform that traces related malware variants, identifies affected systems, and maps the full blast radius of an incident in seconds, so enterprises …HELPNETSECURITY.COM
29 JulCoordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes OfflineA coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. Braham, Plymouth, South St. Paul and Maple Plain have publicly described a plant outage, communications fa…THEHACKERNEWS.COM
29 JulOpenAI explains how its AI agent breached Hugging FaceOpenAI has published an update on the incident in which one of its agents escaped its sandbox and accessed Hugging Face infrastructure.MALWAREBYTES.COM
29 JulAs data breaches grow costlier, ungoverned AI creates new risksMeanwhile, many companies still aren’t doing the basics to protect on-premises data, IBM found.CYBERSECURITYDIVE.COM
29 JulHackers target over 30 Minnesota water utilities in coordinated OT attackThe Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities across the entire state after hackers targeted more than 30 community water systems in "a coordinated cyberattack." [...]BLEEPINGCOMPUTER.COM
29 JulOpenAI agent used exposed credentials at 4 services in Hugging Face breachIn a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other organizations. [...]BLEEPINGCOMPUTER.COM
29 JulWho's Liable When AI Agents Escape? Hugging Face Breach Raises Hard QuestionsDark Reading walks through the many twists and turns in the bizarre story of how OpenAI's agent AI system broke out of its sandbox and decided to target Hugging Face, and what CISOs should be aware of.DARKREADING.COM
29 JulHackers Strike Minnesota Water Utilities, One Plant Briefly OfflineCoordinated OT cyberattacks hit 30+ Minnesota water utilities, briefly disrupting one plant. Backup procedures prevented major water service impacts. Minnesota just had its own live-fire lesson in what happens when someone targets water utilities at scale. Between Sunday and Mond…SECURITYAFFAIRS.COM
🕵️ THREAT INTELLIGENCE 29[−]
29 JulISC Stormcast For Wednesday, July 29th, 2026 https://isc.sans.edu/podcastdetail/10028, (Wed, Jul 29th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
29 JulAndroid malware detection collapses when the context stage comes outA phone backup app asks for storage, contacts, SMS, and call logs. A device-management tool asks for more than that. Run either one past a machine learning malware scanner and it comes back flagged. Six Android detectors in wide research use, including Drebin, MalScan, and MaskDr…HELPNETSECURITY.COM
29 JulAn AI agent can pass every safety check and still leak secretsA pull request lands with a tidy bug report in the description. A bot reads it before any person does, pulls a few shell commands out of it, gets them approved, and posts the output back on the thread. The maintainer reads the whole exchange the next morning. Elad Meged, a foundi…HELPNETSECURITY.COM
29 JulShinyHunters Claims Ernst & Young HackErnst & Young previously confirmed that personal and financial information was stolen from a third-party management platform. The post ShinyHunters Claims Ernst & Young Hack appeared first on SecurityWeek .SECURITYWEEK.COM
29 JulA Farewell from Sherrod: New Season Coming SoonAs we close out season three of the podcast, Sherrod offers her farewell message as she takes on a new threat intelligence leadership role outside of Microsoft. Our executive producer also joins to briefly share our plans for season four, with new faces and voices joining future …THECYBERWIRE.COM
29 JulDozens of Minnesota Water Utilities Targeted in Coordinated OT AttacksState and federal agencies respond after intrusions disrupt automated controls at municipal water and wastewater utilities. The post Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
29 JulRealm Security adds Detection Integrity and Data Haven Search to cut SIEM costsRealm Security has announced two new capabilities. Detection Integrity proves that reducing SIEM log volume never breaks a threat detection. New search inside Realm Data Haven, the platform’s searchable retention layer, makes the data you keep out of the SIEM directly query…HELPNETSECURITY.COM
29 JulTines introduces AI-native platform for secure enterprise workflow automationTines has launched Tines 3B, an AI-native platform for building, running and governing enterprise workflows, applications and agents securely at scale. AI has made it possible for every employee to build software in minutes. The result is an explosion of vibe-coded software sprea…HELPNETSECURITY.COM
29 JulZeroFox unveils HNTR and Executive Protection for AI-driven threat detectionZeroFox has launched HNTR, a new AI-first platform that brings digital risk protection and threat intelligence together to discover, validate, and disrupt threats, alongside the new platform’s first application, HNTR Executive Protection. HNTR is built on more than a decade of op…HELPNETSECURITY.COM
29 JulStolen Meta and Google ad accounts are worth more than the money they holdAd account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy complete with tiered pricing, escrow services, and money-back warranties for stolen accounts. Public reporting on this topic tends to …HELPNETSECURITY.COM
29 Jul1Password targets standing privileges with new access management capabilities1Password has launched 1Password Privileged Access, extending the 1Password Unified Access platform with privileged access management (PAM). It enables just-in-time, least-privilege access to critical infrastructure and is accompanied by the public preview of 1Password Credential…HELPNETSECURITY.COM
29 JulTorq makes AI SOC investigations continuously self-learningTorq has introduced Torq SOC Brain, a new layer of the Torq AI SOC Platform that continuously learns from historical investigations, analyst decisions, and organization-specific security operations to create a unified, self-learning AI SOC. While most autonomous investigation sys…HELPNETSECURITY.COM
29 JulSpur Raises $200 Million for IP Intelligence PlatformThe IP intelligence company will use the fresh investment to accelerate and scale its operations. The post Spur Raises $200 Million for IP Intelligence Platform appeared first on SecurityWeek .SECURITYWEEK.COM
29 JulWhatsApp Web gets end-to-end encrypted voice and video callsMeta has announced a series of new calling features for WhatsApp, including the ability to make and receive voice and video calls directly from WhatsApp Web without installing the desktop app. The update also introduces call transfers between devices, waiting rooms for group call…CYBERINSIDER.COM
29 JulUS, Australia Release OT Isolation Guidance for Critical InfrastructureThe guidance details steps organizations can take to isolate vital OT and supporting systems, and operate in isolation for an extended period. The post US, Australia Release OT Isolation Guidance for Critical Infrastructure appeared first on SecurityWeek .SECURITYWEEK.COM
29 JulOpenAI’s Rogue AI Ventured Beyond Hugging FaceHugging Face has published an anatomy of the attack and OpenAI has shared additional information from its investigation. The post OpenAI’s Rogue AI Ventured Beyond Hugging Face appeared first on SecurityWeek .SECURITYWEEK.COM
29 JulCloudflare reveals what’s behind major internet outagesStorms, earthquakes, and infrastructure failures disrupted internet access throughout the second quarter, while governments deliberately shut networks down, according to Cloudflare’s latest Internet Disruption Summary. Based on Cloudflare Radar traffic data, the report cove…HELPNETSECURITY.COM
29 JulMIND AI DLP Agents automate DLP classification, investigations and remediationMIND has announced MIND AI DLP Agents with capabilities focused on classification, investigation, policies, remediation and exception management. MIND also includes a Model Context Protocol (MCP) interface that enables security teams to direct data security work through any MCP-c…HELPNETSECURITY.COM
29 JulRussia accuses Telegram founder of aiding terrorism, seeks international arrestRussia is seeking to place Telegram founder Pavel Durov on an international wanted list, alleging that the app has been used by Ukrainian intelligence to organize terrorist attacks and conduct espionage inside Russia.THERECORD.MEDIA
29 JulMate Security Raises $35 Million for Agentic SOCThe startup will use the investment to expand its customer support, sales, and R&D teams. The post Mate Security Raises $35 Million for Agentic SOC appeared first on SecurityWeek .SECURITYWEEK.COM
29 JulThreatLocker Raises $190 Million in Series F FundingThe company was previously valued at $1.6 billion, and the latest raise has significantly increased that valuation. The post ThreatLocker Raises $190 Million in Series F Funding appeared first on SecurityWeek .SECURITYWEEK.COM
29 JulRussia charges Telegram founder Pavel Durov with facilitating terrorismRussia's Federal Security Service (FSB) claims that Ukrainian intelligence services used the popular Telegram dating chatbot “Daivinchik/Leo” to recruit Russian citizens, including minors, into sabotage and terrorist activities through deception and psychological mani…CYBERINSIDER.COM
29 JulUS Bans Foreign-Made Humanoid Robots, Targeting China Over National SecurityThe agency said imports of advanced robots pose cybersecurity and other national security risks. The post US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security appeared first on SecurityWeek .SECURITYWEEK.COM
29 JulAI Productivity Comes With a CostAI increases productivity, but productivity gains don't necessarily translate into more free time. As coding assistants and agentic AI become more capable, organizations can expect individual developers to oversee many more projects simultaneously. Higher output can quickly becom…YOUTUBE.COM
29 JulHuntress warns about attack spree that hit 30 SonicWall customers in 2 daysUnknown attackers broke into 92 unique SonicWall user accounts with legitimate credentials, researchers said. The post Huntress warns about attack spree that hit 30 SonicWall customers in 2 days appeared first on CyberScoop .CYBERSCOOP.COM
29 JulBetter security starts with better questionsLearn how better questions, trusted AI, and human judgment help security leaders make confident decisions and build resilient systems. The post Better security starts with better questions appeared first on Microsoft Security Blog .MICROSOFT.COM
29 JulSupply chain challenges loom large in quantum race, White House official saysBrad Blakestad, director of the National Quantum Coordination Office, also said encryption and measuring progress would pose challenges. The post Supply chain challenges loom large in quantum race, White House official says appeared first on CyberScoop .CYBERSCOOP.COM
29 JulThe AI Productivity Pay GapMany organizations expect AI to improve profit margins through higher productivity. But AI adoption still depends on people managing workflows, making decisions, and delivering results. As output increases, some employees feel their compensation hasn't kept pace. Productivity gai…YOUTUBE.COM
29 JulSmashing Security podcast #478: This job interview could destroy your companyYou've been headhunted for a great job in cryptocurrency. All you have to do is complete a short online assessment - with your webcam on, of course, so they can verify who you really are. Which is ironic, because the person recruiting you doesn't exist. And North Korean hackers u…GRAHAMCLULEY.COM
🌐 CYBER THREAT LANDSCAPE 2[−]
29 JulSecure your npm and pip package updates in Amazon LinuxIf you use and install packages from npm or PyPI, the first hours after a package is published are the riskiest because scanners can’t analyze packages before publication. Recent supply chain events affecting NodeJS and Python packages have been detected and removed within hours.…AWS.AMAZON.COM
29 JulWhen AppSec Scanners Become a Supply Chain Attack VectorNew research shows how security scanners embedded in the software supply chain can be attacked to serve as a foothold for downstream attacks.DARKREADING.COM
🎙️ PODCASTS 1[−]
29 JulHugging Face Hack Lessons for Cyber DefendersDark Reading Confidential Episode 20: Expert Rich Mogull reflects on lessons cyber teams should pull from the OpenAI agent's attack on Hugging Face.DARKREADING.COM
📡 INFOSEC NEWS 22[−]
29 JulWeekly Threat Bulletin – July 29th, 2026These are the top threats you should know about this week.F5.COM
29 JulCyera agrees to acquire Oasis Security for $1B to safeguard proliferating AI agentsThe deal is Cyera's third acquisition this year.TECHCRUNCH.COM
29 JulApple Patches Everything (July 2026), (Wed, Jul 29th)I am a bit late with this summary, but this week Apple released updates to all its operating systems and Safari. The Safari update, as usual, targets macOS prior to macOS 26. macOS updates covered the two older versions (14 and 15), while other operating system patches only cover…ISC.SANS.EDU
29 JulICE’s New Detention Center Contracts Declare State Laws ‘Shall Not Apply’One day after a federal judge ordered an ICE detention center opened to state health inspectors, the agency posted new contract terms that would void state oversight at four facilities.WIRED.COM
29 JulResearchers Warn of AI-Enhanced Phone Fraud EcosystemAI is dramatically reducing the barriers to entry for scam phone farm operators, Human Security warnsINFOSECURITY-MAGAZINE.COM
29 JulRussia Charges Telegram Founder Pavel Durov With Aiding Terrorist ActivityThe Federal Security Service of the Russian Federation (FSB) on Wednesday said it charged Telegram founder Pavel Durov for allegedly facilitating terrorist activities and for failing to remove prohibited information in violation of Russian law. The principal security agency said …THEHACKERNEWS.COM
29 JulWe found 120 fake Walmart stores trying to steal your credit cardFake Walmart stores are offering unbelievable bargains on liquor to lure shoppers into entering their credit card details.MALWAREBYTES.COM
29 JulThese near-mint ASUS Chromebook refurbs are only $145Buying a new computer in 2026 is a unique experience. Rather than deal with incredibly high tech prices, more shoppers are opting for high-quality refurbished tech. This ASUS Chromebook CM30 refurb is in near-mint condition with a grade "A" rating, but it still only costs $144.97…BLEEPINGCOMPUTER.COM
29 JulWindows 11 KB5101684 update released with 42 changes and fixesMicrosoft has released the KB5101684 preview cumulative update for Windows 11 24H2 and 25H2, which 42 bug fixes and additional feature improvements for the operating system. [...]BLEEPINGCOMPUTER.COM
29 JulWiz’s First 6 Months as Part of GoogleFast gets even faster: redefining security for the AI era and doubling down on our multicloud commitWIZ.IO
29 JulYour AI Agents Are Guessing at Scale: Permissions Decide the DamageAI agents are designed to improvise as they complete tasks, making broad permissions a growing security risk. Token Security explains why identity, intent-based access controls, and least privilege are becoming the foundation for securing agentic AI. [...]BLEEPINGCOMPUTER.COM
29 JulAI robocalls: Why caller ID is still lying to youAI is making robocall scams cheaper, more convincing, and harder to spot. Here's why caller ID still isn't enough.MALWAREBYTES.COM
29 JulSenate confirms Clayton to head ODNI.OpenAI's rogue agent targeted Model Lab's customer.THECYBERWIRE.COM
29 JulLogoKit Phishing Kit Screenshots Victim Sites in Real TimeLogoKit now builds per-victim phishing pages using live screenshots of the target's real websiteINFOSECURITY-MAGAZINE.COM
29 JulBuying TikTok views or followers? Here’s what you’re really gettingBehind TikTok's booming growth industry are fake engagements, stolen accounts, and a fast track to getting flagged.MALWAREBYTES.COM
29 JulUS government bans new foreign-made humanoids, robot dogs, and solar inverters, citing risks to national securityThe ban largely affects U.S. imports from China, which currently dominates the global market for making humanoid robots and solar inverters.TECHCRUNCH.COM
29 JulOpenAI says rogue agent behind Hugging Face hack broke into additional servicesThe four additional targeted organizations weren’t named. OpenAI said they were not affected as severely as Hugging Face.THERECORD.MEDIA
29 JulHealth-ISAC warns of rising ShinyHunters data theft attacks on healthcareHealth-ISAC, a cybersecurity information-sharing organization for the health sector, is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters. [...]BLEEPINGCOMPUTER.COM
29 JulThreatLocker secures $190 million in a Series F round led by ElephantAct Security emerged from stealth with $60 million in total fundraising to create an action-centric cloud security platform. Cyera acquires Oasis Security in a $1 billion deal.THECYBERWIRE.COM
29 JulRed Agents vs. Blue Agents: How to Make AI Better At DefenseThe agentic AI playing field was heavily tilted toward offense, so researchers began using red team agents to help teach their blue counterparts.DARKREADING.COM
29 JulApple accused of letting fake crypto app steal $1.8 millionThe case raises fresh questions about how effectively Apple polices apps that impersonate legitimate developers.MALWAREBYTES.COM