🚨 CISA KEV 80[−]
23 Sep KEVCVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APMOverview On September 22, 2026, F5 published a security advisory for CVE-2026-94127 , a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8. An unauthenticated attacker with network acce…RAPID7.COM
23 Sep KEVU.S. CISA adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerab…SECURITYAFFAIRS.COM
22 Sep KEVU.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zyxel flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Zyxel GS1900 Series Switches flaw, tracked as CVE-2026-7273 (CVSS score of 8.8), t…SECURITYAFFAIRS.COM
20 Sep KEVU.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities …SECURITYAFFAIRS.COM
18 Sep KEVCISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-39964 Linux Kernel Race Condition Vulnerability CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability These types of vulnerabil…CISA.GOV
17 Sep KEVU.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilitie…SECURITYAFFAIRS.COM
16 Sep KEVCISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-58704 Google Pixel Improper Authorization Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors…CISA.GOV
15 Sep KEVA maximum severity GitLab flaw could turn your CI/CD server into an attacker’s treasure troveYet another security vulnerability has been discovered in GitLab infrastructure, this one a perfect 10 in severity. CVE-2026-85706 , the second flaw GitLab has disclosed in just a month, is a maximum-severity vulnerability that allows attackers to read arbitrary files in a single…CSOONLINE.COM
15 Sep KEVCritical Cisco Secure Email Gateway zero-day gives attackers root accessCisco released emergency patches for a critical vulnerability in its Secure Email Gateway appliance that could allow attackers to take over the device by simply sending malicious crafted emails to users. The flaw was already being exploited in the wild when the fixes were release…CSOONLINE.COM
15 Sep KEVU.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (C…SECURITYAFFAIRS.COM
14 Sep KEVU.S. CISA adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabili…SECURITYAFFAIRS.COM
12 Sep KEVCISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEVThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.…THEHACKERNEWS.COM
11 Sep KEVMetasploit Wrap Up: This One Goes to Sixteen!This One Goes to Sixteen! Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner…RAPID7.COM
10 Sep KEVU.S. CISA adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known…SECURITYAFFAIRS.COM
10 Sep KEVU.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities t…SECURITYAFFAIRS.COM
8 Sep KEVStyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-dayA critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a vendor patch became available. Key takeaways CVE-2026-75650 is …TENABLE.COM
4 Sep KEVU.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, tracked as CVE-2026-85046 (CVSS score of 8,8…SECURITYAFFAIRS.COM
3 Sep KEVCISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto MinersThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers' crosshairs. The vulnerabilities are as follows - CVE-2026-83548 (CVSS score: 10.0) - A ser…THEHACKERNEWS.COM
1 Sep KEVPaperCut Exploitation Escalates to Active IntrusionsCISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog. The post PaperCut Exploitation Escalates to Active Intrusions appeared first on SecurityWeek .SECURITYWEEK.COM
1 Sep KEVU.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulner…SECURITYAFFAIRS.COM
31 Aug KEVCISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability CVE-2026-82078 PaperCut NG/MF Unsafe Refle…CISA.GOV
28 Aug KEVPaperCut NG/MF Critical Zero-Day Exploited in the WildOverview On August 27, 2026, PaperCut Software published an urgent security advisory stating that it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. PaperCut has confirmed customer incidents and is treating the issue as a security em…RAPID7.COM
27 Aug KEVCISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server BugsThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exp…THEHACKERNEWS.COM
27 Aug KEVCISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix ProductsCISA added six new bugs to its Known Exploited Vulnerabilities catalog on August 26, showing signs of active exploitation in the wildINFOSECURITY-MAGAZINE.COM
26 Aug KEVU.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Gitea flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-…SECURITYAFFAIRS.COM
26 Aug KEVEdge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeterA joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to t…TENABLE.COM
25 Aug KEVU.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Oracle flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE…SECURITYAFFAIRS.COM
22 Aug KEVU.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the Zimbra Collaboration Suite (ZCS) flaw CVE-2026-73570 …SECURITYAFFAIRS.COM
21 Aug KEVU.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV…SECURITYAFFAIRS.COM
20 Aug KEVU.S. CISA adds an MLflow flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds an MLflow vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2026-64849 (CVSS sc…SECURITYAFFAIRS.COM
19 Aug KEVU.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the followi…SECURITYAFFAIRS.COM
19 Aug KEVCritical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active ExploitationThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below - CVE-202…THEHACKERNEWS.COM
18 Aug KEVU.S. CISA adds a Ray-Project Ray flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Ray-Project Ray vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2025-62593 …SECURITYAFFAIRS.COM
14 Aug KEVThe cybersecurity backlog is not a security problemCybersecurity teams should be responsible for risk oversight, rather than for executing every corrective action. Assigning security teams the tasks of finding, prioritizing, assigning, implementing, tracking and validating every remediation does not foster accountability. Instead…CSOONLINE.COM
13 Aug KEVCisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)A high-severity vulnerability (CVE-2026-20349) is being leveraged by attackers to temporarily interrupt the operation of Cisco firewalls, the company has confirmed. The flaw has been added to CISA’s Known Exploited Vulnerabilities catalog and needs to be remediated by US ci…HELPNETSECURITY.COM
13 Aug KEVU.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known E…SECURITYAFFAIRS.COM
11 Aug KEVPatch Tuesday - August 2026Microsoft is publishing 421 vulnerabilities on August 2026 Patch Tuesday , including 236 vulnerabilities in Windows. This is lower volume than last month’s record-breaking behemoth, but still one of the largest Patch Tuesday totals ever. There is no reason to suppose that Patch T…RAPID7.COM
8 Aug KEVProgress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit AttemptsThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tra…THEHACKERNEWS.COM
8 Aug KEVU.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2026-80…SECURITYAFFAIRS.COM
6 Aug KEVU.S. CISA adds a JetBrains TeamCity flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a JetBrains TeamCity vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a JetBrains TeamCity vulnerability, tracked as CVE-2026-6307…SECURITYAFFAIRS.COM
6 Aug KEVThe exploit window is shrinking. Most security workflows are notAI is accelerating vulnerability discovery, exploit development, and attacker weaponization faster than most organizations can adapt. Security teams are inundated with vulnerability disclosures, threat intelligence feeds, exploit chatter, and vendor advisories, all demanding imme…CSOONLINE.COM
5 Aug KEVU.S. CISA adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known …SECURITYAFFAIRS.COM
4 Aug KEVCISA Adds Exploited N-able N-central Flaw to KEV After Customer CompromisesThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2…THEHACKERNEWS.COM
4 Aug KEVCVE-2026-18577: N-able N-central Authentication Bypass Exploited in the WildOverview On August 2, 2026, N-able published a security advisory for CVE-2026-18577 , an authentication bypass vulnerability affecting N-central that was discovered being exploited in-the-wild after an incomplete fix for an earlier authentication bypass issue, CVE-2026-18556 was …RAPID7.COM
4 Aug KEVU.S. CISA adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a N-able N-central flaw, tracked as CVE-2026-18577 (CVSS score of 8.2),…SECURITYAFFAIRS.COM
30 Jul KEVU.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Firewall Management Center …SECURITYAFFAIRS.COM
28 Jul KEVU.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Arista VeloCloud Orchestrator and Fort…SECURITYAFFAIRS.COM
28 Jul KEVAccelerating CISA BOD 26-04 Vulnerability and Triage Activities through WizWiz enables organizations to continuously assess environments against the CISA KEV catalog, automating risk prioritization, rapid remediation, and forensic triage workflows.WIZ.IO
28 Jul KEVCoordinated “cyberattack” on Minnesota water utilities: What you need to knowA coordinated cyber attack disrupted water systems across more than 30 Minnesota communities. Here is what defenders need to know about the attack so far. This FAQ also details recent cyberactivity targeting internet-exposed PLCs, and how to protect exposed infrastructure. Key Ta…TENABLE.COM
23 Jul KEVMicrosoft’s 3-day patching directive comes with added operational riskMicrosoft 365 Director Jeremy Chapman this month took to video to tell Windows admins that the days of delaying security patches are over. Complex enterprise systems and historic incidents involving patch problems have caused many admins to hold fire on immediately applying secur…CSOONLINE.COM
23 Jul KEVCVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the WildOverview On July 22, 2026, Check Point published a security advisory for multiple vulnerabilities affecting Security Management, Multi-Domain Management, and firewall products. The most urgent of these is CVE-2026-16232 , an authentication bypass in the SmartConsole login process…RAPID7.COM
23 Jul KEVU.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SharePoint and Check Point flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added DD-WRT, Langflow, and WordPress flaws to its Known Exploi…SECURITYAFFAIRS.COM
22 Jul KEVU.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds DD-WRT, Langflow, and WordPress flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added DD-WRT, Langflow, and WordPress flaws to its Known Exploi…SECURITYAFFAIRS.COM
20 Jul KEVwp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress CoreAn unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public dis…TENABLE.COM
18 Jul KEVU.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Fortinet FortiSandbox and Microsoft ShareP…SECURITYAFFAIRS.COM
17 Jul KEVCISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEVThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fi…THEHACKERNEWS.COM
17 Jul KEVU.S. CISA adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SonicWall and M…SECURITYAFFAIRS.COM
16 Jul KEVCISA urges immediate SharePoint hardening as exploits mountThe US Cybersecurity and Infrastructure Security Agency (CISA) has urged organizations to immediately secure Microsoft SharePoint deployments after warning that three vulnerabilities affecting the on-premises collaboration platform are being actively exploited. A recent advisory …CSOONLINE.COM
16 Jul KEVCVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server VulnerabilitiesFour Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments. Key Takeaways CISA confirmed active exploi…TENABLE.COM
15 Jul KEVU.S. CISA adds SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SonicWall and Microsoft flaws to its Known Exploited Vulnerabilit…SECURITYAFFAIRS.COM
15 Jul KEVPatch These Joomla Vulnerabilities NowCISA added vulnerabilities affecting the iCagenda and Babioon Forms Joomla extensions to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The flaws can enable remote code execution through arbitrary file uploads. When CISA gives a vulnerability i…YOUTUBE.COM
14 Jul KEVPatch Tuesday - July 2026Microsoft is publishing 622 vulnerabilities on July 2026 Patch Tuesday , including a record-breaking 416 Windows vulnerabilities. Microsoft is aware of exploitation in the wild for two of the vulnerabilities published today, both of which are listed on CISA KEV, as well as public…RAPID7.COM
13 Jul KEVU.S. CISA adds a Cisco IOS flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Cisco IOS flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco IOS flaw, tracked as CVE-2008-4128, to its Known Exploited Vulnerabili…SECURITYAFFAIRS.COM
12 Jul KEVSecurity Affairs newsletter Round 585 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. U.S. CISA adds iCagenda and B…SECURITYAFFAIRS.COM
11 Jul KEVU.S. CISA adds iCagenda and Balbooa Forms flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds iCagenda and Balbooa Forms flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added iCagenda and Balbooa Forms flaws to its Known Exploited Vulner…SECURITYAFFAIRS.COM
9 Jul KEVAI Is Annoying & IoT Devices Still Get Hacked - PSW #934In the security news: - Son of Anton strikes again! - HalluSquatting and using Claude to defend itself - CISA KEV’s Revolving Door - LLM's hallucinate and companies get sued - Additionally - GitLost - Yet even more Linux vulnerabilities - Citrix just keeps bleeding - Old hardware…YOUTUBE.COM
8 Jul KEVCISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEVThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-48282 (CVSS score: 10.0) - A path tr…THEHACKERNEWS.COM
8 Jul KEVU.S. CISA adds Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] …SECURITYAFFAIRS.COM
8 Jul KEVCISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla FlawsTwo newly disclosed critical vulnerabilities in Adobe ColdFusion and Langflow join two Joomla extension flaws in CISA's Known Exploited Vulnerabilities catalog, with federal agencies given until July 10 to patch. The post CISA Urges Immediate Patching of Exploited ColdFusion, Lan…SECURITYWEEK.COM
8 Jul KEVAttackers using Langflow flaw for credential harvesting (CVE-2026-55255)The US Cybersecurity and Infrastructure Security Agency (CISA) is warning about yet another Langflow vulnerability (CVE-2026-55255) leveraged by attackers in the wild. The flaw was added to the agency’s Known Exploited Vulnerabilities catalog on Tuesday, July 7, nearly two …HELPNETSECURITY.COM
2 Jul KEVSharePoint RCE CVE-2026-45659 Added to CISA KEV After Active ExploitationThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-4565…THEHACKERNEWS.COM
2 Jul KEVU.S. CISA adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Microsoft SharePoint Server flaw, tracked as CVE-2026-4565…SECURITYAFFAIRS.COM
30 Jun KEVHow CISA BOD 26-04 redefines vulnerability management metrics for security leadersCISA’s BOD 26-04 changes how federal agencies patch and how security leaders must measure, justify, and communicate cyber risk to executives and boards. Key takeaways BOD 26-04 requires agencies to make and defend risk-based vulnerability prioritization decisions, including decis…TENABLE.COM
30 Jun KEVU.S. CISA adds SimpleHelp flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a SimpleHelp flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a SimpleHelp flaw, tracked as CVE-2026-48558 (CVSS score v3.1 …SECURITYAFFAIRS.COM
29 Jun KEVModernizing Global Vulnerability Standards For The Age Of AIAs AI-driven vulnerability discovery accelerates, the cybersecurity ecosystem is being forced to examine whether the standards, disclosure processes, and prioritization frameworks defenders rely on can still keep pace. Many of those systems were built around human-speed discovery…RAPID7.COM
29 Jun KEVJSP webshells being dropped on unpatched PTC Windchill instancesThe US Cybersecurity and Infrastructure Security Agency (CISA) added a vulnerability (CVE-2026-12569) in Windchill and FlexPLM, two product lifecycle management software platforms developed by PTC, to its Known Exploited Vulnerabilities (KEV) catalog. Entries in the KEV catalog d…HELPNETSECURITY.COM
26 Jun KEVFirst-Ever Exploitation of PTC Windchill Vulnerability Discovered in the WildCISA has added the remote code execution flaw CVE-2026-12569 to its Known Exploited Vulnerabilities catalog. The post First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild appeared first on SecurityWeek .SECURITYWEEK.COM
26 Jun KEVCISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks ContinueThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical remote code execution vulnerability impacting PTC Windchill PDMlink and PTC FlexPLM enterprise Product Data Management (PDM) and Product Lifecycle Management (PLM) software to its Known …THEHACKERNEWS.COM
26 Jun KEVWeekly Metasploit Update: Modules for Audiobookshelf, LiteLLM, Next.js, Dalfox and moreHelp shape the future of Metasploit Framework We are planning future work in relation to the evasion capabilities present in Metasploit Framework, and how they function/are presented to users. We are currently accepting responses to our feedback form, which means that you can sha…RAPID7.COM
25 Jun KEVCISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-12569 PTC Windchill and FlexPLM Improper Input Validation Vulnerability CVE-2026-20230 Cisco Unified Communications Manager Serv…CISA.GOV
🐛 COMMON VULNERABILITIES AND EXPOSURES 2386[−]
23 SepF5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth ServersAttackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access token…THEHACKERNEWS.COM
23 SepChinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP MalwareA Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome …THEHACKERNEWS.COM
23 SepCVE-2026-87902: how close is your WordPress to remote code execution?WordPress 7.1.2 fixes an unauthenticated file inclusion bug active since version 4.7, patchable but exploitable into remote code execution. WordPress 7.1.2 shipped on September 22 address an unauthenticated local file inclusion, tracked as CVE-2026-87902 (CVSS score of 9.2), whic…SECURITYAFFAIRS.COM
23 SepWordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)WordPress released version 7.1.2 to fix a critical flaw that lets an unauthenticated attacker make the software load a PHP file of the attacker’s choosing from outside the site’s active theme folders. On sites where the server and the active theme meet certain conditi…HELPNETSECURITY.COM
23 SepAttackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instancesCheck Point Software has released emergency fixes for a critical Check Point Management Server vulnerability (CVE-2026-93616) that has been exploited as far back as July 23, 2026. The company also confirmed that a pre-authentication remote code execution (RCE) vulnerability (CVE-…HELPNETSECURITY.COM
23 SepExploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container EscapeA use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The flaw, tracked as CVE-2026-80521 (CVSS score: 7.8), was fixed upstream …THEHACKERNEWS.COM
23 SepMikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH KeyTwo MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2…THEHACKERNEWS.COM
23 SepVU#754548: Cinnamon's kotaemon contains improper authorization checks in Kotaemon multi‑user chat handlersOverview Cinnamon's Kotaemon (all versions up to v0.12.0) multi‑user chat interface does not verify conversation ownership when loading a conversation. Any authenticated user can read, delete, rename, or overwrite another user’s conversation data by supplying the correct ID. This…KB.CERT.ORG
23 SepVU#273940: Enterprise Access Management EAM does not rotate RSA keysOverview Imprivata Enterprise Access Management (EAM), an authentication and single sign-on platform for enterprise and clinical environments, contains a vulnerability in versions 26.2.6 and below. The product provides no supported mechanism to rotate its RSA key pair after deplo…KB.CERT.ORG
23 SepHackers start exploiting critical WordPress flaw for code executionThreat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. [...]BLEEPINGCOMPUTER.COM
23 SepF5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE AttacksF5 warns of a critical BIG-IP APM zero-day, CVE-2026-94127, allowing remote code execution. Attackers are already exploiting it. F5 has released emergency security updates for a critical vulnerability, tracked as CVE-2026-94127 (CVSS score of 9.8), in BIG-IP Access Policy Manager…SECURITYAFFAIRS.COM
23 SepCheck Point warns of hackers exploiting Security Gateway VPN RCE flawCybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product. [...]BLEEPINGCOMPUTER.COM
23 Sep KEVF5 fixes actively exploited zero-day flaw in BIG-IP APMTechnology company F5 fixed a critical remote code execution vulnerability in its BIG-IP Access Policy Manager (APM) platform on Tuesday. The flaw impacts deployments configured as OAuth authorization servers and was already under active exploitation in the wild before the patch …CSOONLINE.COM
22 SepWordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin SessionA new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site's server. WordPress fixed the flaw, tracked as CVE-2026-93485 and d…THEHACKERNEWS.COM
22 Sep KEVZyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM AccessThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026…THEHACKERNEWS.COM
22 SepAttacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)A Chinese-speaking threat actor has exploited a vulnerability (CVE-2026-7273) in unpatched ZyXEL GS1900 Smart Managed Switches and has exfiltrated sensitive data from 996 devices across 48 countries, GreyNoise reported on Monday. The affected switches are predominantly located in…HELPNETSECURITY.COM
22 SepNew Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host MemoryA new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled. The bug, tracked as CVE-2026-89775, allows a guest to read and write host kern…THEHACKERNEWS.COM
22 SepSharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCEA SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh K…THEHACKERNEWS.COM
22 SepD-Link warns of max severity zero-day bug in DIR-822A routersD-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers. [...]BLEEPINGCOMPUTER.COM
22 Sep KEVNew CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based SetupsAttackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege interna…THEHACKERNEWS.COM
22 SepCritical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without CredentialsA critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CV…THEHACKERNEWS.COM
22 SepAL26-022 - Vulnerability impacting F5 BIG-IP Access Policy Manager (APM) – CVE-2026-94127CYBER.GC.CA
22 SepCheck Point Warns of Management Server Zero-Day Exploited in Targeted AttacksAttackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging …THEHACKERNEWS.COM
22 Sep KEVCheck Point Fixes a New Actively Exploited Critical Security FlawCheck Point fixes an actively exploited flaw that lets unauthenticated attackers upload and run scripts on vulnerable Security Management Servers. Check Point has released emergency hotfixes for CVE-2026-93616, a critical path traversal flaw in its Security Management Server. The…SECURITYAFFAIRS.COM
21 SepCVE-2026-68825 Windows Bind Filter Driver Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 SepCVE-2026-77901 Microsoft Office Word Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 SepCVE-2026-78524 Microsoft Office Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 SepCVE-2026-78526 Microsoft Office Word Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 SepCVE-2026-83498 Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 SepCVE-2026-63516 Microsoft SharePoint Server Spoofing VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 SepCVE-2026-63532 Microsoft Office Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 SepCVE-2026-68798 Microsoft Excel Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 SepCVE-2026-68804 Microsoft Excel Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 SepCVE-2026-55123 Microsoft PowerPoint Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 SepMind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day ExploitsOn September 9, 2026, Volexity published a blog post detailing the simultaneous use of multiple chained zero-day exploits in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Microsoft Windows (CVE-2026-85880) by two different […] The post Mind the (Patch) Gap, Part 2: Fak…VOLEXITY.COM
19 SepSolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCESolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on…THEHACKERNEWS.COM
19 Sep KEVCritical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the WildA critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution. "Orkes C…THEHACKERNEWS.COM
19 Sep KEVCISA Flags Three Linux Kernel Vulnerabilities Exploited in the WildThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2025-39682 (CV…THEHACKERNEWS.COM
18 SepCritical Orkes Conductor Vulnerability Exploited in AttacksCVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions. The post Critical Orkes Conductor Vulnerability Exploited in Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
18 SepCheck Point Fixes Critical CVE-2026-91843 Allowing Root Code ExecutionCheck Point fixed CVE-2026-91843, a critical flaw that could let attackers run code as root on Security Management and Log Servers with no login needed. Check Point addressed CVE-2026-91843 (CVSS score of 9.8), a critical vulnerability in its Security Management and Log Servers. …SECURITYAFFAIRS.COM
18 SepMicrosoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege EscalationMicrosoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0. "Missing authentication for c…THEHACKERNEWS.COM
18 Sep KEVCISA is ending its monthly vulnerability bulletinThe rise in AI-generated security threats may just have generated one casualty: the death of the weekly bulletin of security threats from the US Cybersecurity Infrastructure and Security Agency (CISA). The agency will discontinue its weekly bulletin of known vulnerabilities from …CSOONLINE.COM
18 SepCisco Zero-Day Highlights API Endpoint Authentication IssuesThe authentication bypass flaw CVE-2026-76460 impacts Cisco's Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score.DARKREADING.COM
17 Sep KEVUnauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)Two days after it warned customers about an actively exploited email gateway zero-day, Cisco confirmed one more flaw is being targeted: CVE-2026-76460, an authentication bypass bug in an API of Cisco Identity Services Engine (ISE). About CVE-2026-76460 Cisco ISE is an identity-ba…HELPNETSECURITY.COM
17 SepCritical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS ZoneEvery release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling rem…THEHACKERNEWS.COM
17 SepCVE-2026-50311 Windows Server Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
17 SepCVE-2026-55039 Microsoft Excel Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
17 SepCVE-2026-66809 Microsoft Office Graphics Component Information Disclosure VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
17 SepCVE-2026-62819 Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
17 SepCVE-2026-68794 Microsoft Excel Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
17 SepCVE-2026-69724 Microsoft Office SharePoint Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
17 SepCVE-2026-81957 Microsoft Excel Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
17 Sep KEVCisco patches max-severity ISE flaw, the second critical zero-day this weekCisco released patches for an actively exploited authentication bypass vulnerability in its Cisco Identity Services Engine (ISE) platform, which is used for enterprise network access control and policy enforcement. This is the second zero-day flaw Cisco has been forced to release…CSOONLINE.COM
17 Sep KEVCisco alerts customers to second actively exploited zero-day in as many daysThe latest zero-day has a maximum-severity rating and affects Cisco Identity Services Engine, a product hit with three actively exploited vulnerabilities since June 2025. The post Cisco alerts customers to second actively exploited zero-day in as many days appeared first on Cyber…CYBERSCOOP.COM
16 SepAttackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionA critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauth…THEHACKERNEWS.COM
16 SepGoogle Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationGoogle has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw. "In Cellular Modem, there is a possible permission bypass d…THEHACKERNEWS.COM
16 Sep KEVAcronis cPanel Backup Plugin Vulnerability Exploited in Targeted AttacksAcronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild. The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7.8), is described as a case of local privilege escalation due to…THEHACKERNEWS.COM
16 SepActive Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin TokensA critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result…THEHACKERNEWS.COM
16 Sep KEVOracle’s September patches put Fusion Middleware back in the hot seatOracle’s September 2026 Critical Security Patch Update has arrived with 673 new security patches spanning 17 Oracle product families, with Oracle E-Business Suite accounting for the largest share at 159 patches, followed by Fusion Middleware with 153. Of these, 19 E-Business Suit…CSOONLINE.COM
16 SepZDI-26-707: (0Day) MindsDB OpenBBtable Code Injection Remote Code Execution VulnerabilityThis vulnerability allows remote attackers to execute arbitrary code on affected installations of MindsDB. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-92207.ZERODAYINITIATIVE.COM
16 SepZDI-26-706: (0Day) CrewAI crewAI Framework Agent Loading Unsafe Reflection Remote Code Execution VulnerabilityThis vulnerability allows remote attackers to execute arbitrary code on affected installations of CrewAI crewAI. User interaction is required to exploit this vulnerability in that the target must load a malicious agent configuration from the repository. The ZDI has assigned a CVS…ZERODAYINITIATIVE.COM
16 SepZDI-26-705: (0Day) BusyBox libarchive Symlink Directory Traversal Arbitrary File Creation VulnerabilityThis vulnerability allows remote attackers to create arbitrary files on affected installations of BusyBox. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.1…ZERODAYINITIATIVE.COM
16 SepZDI-26-704: (0Day) Airbyte OneDrive Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure VulnerabilityThis vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Airbyte. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.7. The following CVEs are assigned: CVE-2026-92204.ZERODAYINITIATIVE.COM
16 SepZDI-26-703: (0Day) Airbyte SharePoint Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure VulnerabilityThis vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Airbyte. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.7. The following CVEs are assigned: CVE-2026-92203.ZERODAYINITIATIVE.COM
16 SepVU#212479: Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environmentOverview A vulnerability exists in Sentry Seer when the system is configured to automatically hand issues to a coding agent for remediation. Successful exploitation results in arbitrary code execution within the coding‑agent environment and access to connected source repositories…KB.CERT.ORG
16 SepGoogle patches Pixel modem zero-day exploited in targeted attacksGoogle has fixed a high-severity Pixel modem vulnerability that may already have been exploited in limited, targeted attacks. Tracked as CVE-2026-58704, the flaw was fixed as part of the September 2026 Pixel security update, which brings supported devices to the 2026-09-05 securi…CYBERINSIDER.COM
16 SepPixel Modem Zero-Day Exploited in Targeted AttacksGoogle announced patches for the exploited privilege escalation vulnerability (CVE-2026-58704) on September 15. The post Pixel Modem Zero-Day Exploited in Targeted Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
16 SepParallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)A newly disclosed vulnerability in Parallels Desktop, tracked as CVE-2026-90894 and dubbed “ParaShells,” can allow any local user on a Mac to gain root privileges on the host system. ParaShells PoC in action (Source: JFrog) The danger is highest on developer laptops, …HELPNETSECURITY.COM
16 SepAcronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886)A Linux privilege escalation vulnerability (CVE-2026-87886) affecting Acronis’ backup extensions for cPanel, WebHost Manager (WHM), and Plesk, is being leveraged by attackers, the backup and recovery company warns. “Exploitation of this vulnerability has been detected…HELPNETSECURITY.COM
16 SepGoogle Patches Pixel Modem Zero-Day Exploited in Targeted AttacksGoogle has patched a high-severity zero-day in the Pixel cellular modem after finding evidence that the vulnerability was exploited in limited, targeted attacks. Google has released its September 2026 Pixel security update, addressing a large set of vulnerabilities, including a h…SECURITYAFFAIRS.COM
15 SepRoot RCE Zero-Day in Cisco Secure Email Gateway Under Active ExploitationAn unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges. The post Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation appeared first on SecurityWeek .SECURITYWEEK.COM
15 Sep KEVCisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command ExecutionCisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described a…THEHACKERNEWS.COM
15 Sep KEVCisco patches actively exploited email gateway zero-day (CVE-2026-76461)Attackers have leveraged a zero-day SQL injection vulnerability (CVE-2026-76461) to compromise Cisco Secure Email Gateway appliances, Cisco confirmed on Monday. The vendor’s Product Security Incident Response Team became aware of active exploitation of this vulnerability in…HELPNETSECURITY.COM
15 SepCVE-2026-68824 Connected User Experiences and Telemetry Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-68841 Windows NTFS Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-68847 Connected User Experiences and Telemetry Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-69406 Windows Kernel Information Disclosure VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-69608 Microsoft Windows Search Component Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-69605 Microsoft Install Service Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-78517 Microsoft Office Word Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-80075 Windows Work Folders Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-80097 Microsoft Authenticator Elevation of Privilege VulnerabilityCorrected fix build number. Informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-81355 Virtual Hard Disk (VHD) Miniport Driver Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-69486 Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityHeap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.MSRC.MICROSOFT.COM
15 SepCVE-2026-69286 Windows USB Audio Class Driver Information Disclosure VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-69314 Windows Device Association Broker Service Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-69321 Windows Power Dependency Coordinator Tampering VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-69416 Windows DHCP Server Denial of Service VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-69619 Windows exFAT File System Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-69714 Windows Device Association Service Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-69559 Microsoft Teams for Android Information Disclosure VulnerabilityCorrected fix build number. Informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-65812 Microsoft Teams for Android Information Disclosure VulnerabilityCorrected fix build number. Informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-73006 DirectWrite Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-81963 Windows Update Stack Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-85893 Microsoft Edge (Chromium-based) Elevation of Privilege VulnerabilityUse after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.MSRC.MICROSOFT.COM
15 SepCVE-2026-61923 Windows Display Enhancement Service Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-62753 Windows HTTP.sys Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-62772 Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-61363 Remote Desktop Client Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-62717 Windows Message Queuing Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-68812 Microsoft Excel Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-63508 Microsoft Planetary Computer Pro Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-49805 Win32k Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-50688 Windows Win32k Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-50683 Windows DHCP Client Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-55053 Microsoft Excel Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 SepCVE-2026-55121 Microsoft Office Information Disclosure VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
15 Sep KEVExposed Vite servers are being probed for AWS and Azure credentialsAttackers have opened a new front in their war on software developers: Vite servers, which they are probing for sensitive data including cloud credentials, infrastructure configuration and environment files. Vite was created as a build tool for Vue , a JavaScript framework for bu…CSOONLINE.COM
15 Sep KEVCVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the WildOverview On September 14, 2026, Cisco published a security advisory for CVE-2026-76461 , a critical SQL injection vulnerability affecting Cisco AsyncOS Software for Cisco Secure Email Gateway. The vulnerability has a reported CVSS v3.1 base score of 9.8 and could allow an unauthe…RAPID7.COM
15 Sep KEVCisco Warns of Ongoing Exploitation of Critical Email Gateway Zero-DayCisco warns of a critical zero-day in Secure Email Gateway, exploited in the wild to gain root access through malicious emails. Cisco disclosed a critical zero-day, tracked as CVE-2026-76461 (CVSS score of 9.8), affecting Secure Email Gateway appliances. The flaw can be exploited…SECURITYAFFAIRS.COM
14 Sep KEVCVE-2026-85706: Critical GitLab Path Traversal Exploited in the WildOverview On September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706 , a critical path traversal vulnerability ( CWE-22 ) in the repository commits API with a CVSSv3.1 score o…RAPID7.COM
14 SepNintendo warns of Switch code execution flaw via on-screen QR codesNintendo has patched a high-severity Nintendo Switch vulnerability that could allow a nearby attacker to execute unauthorized code or access information stored on the console. The flaw, tracked as CVE-2026-82079, affects Switch systems running firmware versions earlier than 23.0.…CYBERINSIDER.COM
14 SepLogitech Options+ flaw lets attackers gain Windows SYSTEM privilegesA vulnerability in Logitech Options+ allows a standard Windows user to gain SYSTEM-level privileges by exploiting a weakness in the software’s updater service. Tracked as CVE-2026-12518, the issue requires no administrator rights, network access, or additional user interact…CYBERINSIDER.COM
14 SepMaximum Severity GitLab Flaw Puts Supply Chains at RiskCVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.DARKREADING.COM
14 SepChromium CVE-2026-87454: Information leak in EnterpriseThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87455: Use after free in AuraThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87456: Uninitialized resource in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87457: Race condition in UpdaterThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87458: UI misrepresentation in GeometryThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87480: Use after free in PrintingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87484: UI misrepresentation in GeometryThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87485: Incorrect authorization in CORSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87487: Missing authorization in FileSystemThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87489: Memory corruption in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87490: Information leak in Transactions PlatformThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87492: Incorrect authorization in DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87493: Missing authorization in FileSystemThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87494: Use after free in BrowserThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87495: Information leak in ScrollThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87496: UI misrepresentation in BrowserThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87497: Uninitialized resource in CodecsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87498: Missing authorization in WebUIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87499: Incorrect authorization in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87500: Improper validation of array index in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87501: UI misrepresentation in PasswordsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87502: Confused deputy in FullscreenThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87504: Use after free in CoreThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87505: Incorrect authorization in FileSystemThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87506: Privilege elevation in WebUIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87507: UI misrepresentation in DownloadsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87508: Incorrect authorization in LoaderThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87509: Incorrect authorization in UpdaterThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87510: Improper input validation in FileAPIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87511: Missing authorization in DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87512: Use after free in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87513: Missing authorization in ControlledFrameThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87514: Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87515: Incorrect authorization in FileAPIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87516: Observable discrepancy in NavigationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87519: Incorrect authorization in SafebrowsingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87521: Information leak in WebMCPThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87523: Race condition in DataTransferThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87524: Use after free in CoreThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87525: Out of bounds read in ChromotingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87526: Use after free in PasswordsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87527: Buffer overflow in WebGLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87528: Type confusion in RustThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87529: Numeric truncation error in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87530: Uncontrolled search path element in CredentialProviderThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87531: Information leak in CORSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87532: Improper state validation in SafebrowsingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87533: Use after free in DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87535: Information loss or omission in SafebrowsingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87537: Missing authorization in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87538: Clickjacking in InputThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87539: Observable discrepancy in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87540: Incorrect authorization in IsolatedThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87541: Information leak in NavigationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87542: Use after free in InputThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87543: Missing authorization in CoreThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87544: Incorrect authorization in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87546: Incorrect type conversion or cast in SafebrowsingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87547: Incorrect reference resolution in FileSystemThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87548: Improper state validation in InstallerThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87549: Incomplete cleanup in DownloadsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87550: Improper encoding or escaping of output in CSSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87551: Improper certificate validation in CORSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87553: Improper input validation in SiteIsolationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87554: Race condition in ChromotingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87556: Missing authorization in BrowserThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87557: Missing authorization in LocalNetworkAccessThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87558: Use after free in PaymentsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87559: UI misrepresentation in UIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87560: Missing authorization in BrowserThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87561: Incorrect authorization in Web AuthenticationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87562: Incorrect reference resolution in AccessibilityThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87563: Origin validation error in PaintThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87564: Type confusion in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87565: Information leak in PasswordsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87566: Observable discrepancy in LayoutThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87567: UI misrepresentation in UrlFormattingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87568: Improper input validation in ChromiumThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87569: Missing authorization in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87598: Incorrect authorization in ServiceWorkerThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87599: Improper input validation in InterstitialsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87600: Improper input validation in SafebrowsingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87601: Race condition in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87602: Out of bounds read in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87603: Missing authorization in FileSystemThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87604: Out of bounds read in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87605: Missing authorization in ContactsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87606: Missing authorization in SiteIsolationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87608: Improper certificate validation in FedCMThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87609: Use after free in SharingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87610: Incorrect authorization in OmniboxThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87611: Missing authorization in FileSystemThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87612: Type confusion in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87613: Incorrect reference resolution in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87614: Incorrect authorization in ServiceWorkerThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87615: Race condition in PaymentsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87616: Improper initialization in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87617: Use after free in DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87618: Incorrect reference resolution in StorageThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87619: Observable discrepancy in PrefetchThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87620: Observable discrepancy in SVGThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87621: Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87622: Missing authorization in FedCMThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87623: Observable discrepancy in DOMThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87624: UI misrepresentation in PasswordsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87625: Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87626: Incorrect authorization in DeviceBoundSessionCredentialsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87627: Interpretation conflict in SafebrowsingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87628: Use after free in CastThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87629: Incorrect authorization in SourcesThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87630: Integer overflow in WebRTCThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87631: Missing authorization in DOMThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87632: Cross-site scripting in SanitizerAPIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87633: Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87634: Use after free in WebPackagingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87635: UI misrepresentation in PaymentsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87636: Type confusion in XMLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87637: Use after free in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87638: Out of bounds write in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87639: Use after free in WebPackagingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87641: Race condition in BrowserThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87642: Uninitialized resource in WebGLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87644: Incorrect authorization in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87645: Improper state validation in SafebrowsingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87646: Use after free in Web AuthenticationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87647: Uninitialized resource in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87648: Use after free in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87649: UI misrepresentation in DownloadsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87650: Out of bounds read in WebGLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87651: Incorrect authorization in PaintThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87652: Incorrect authorization in PushAPIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87653: UI misrepresentation in FullScreenThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87654: Buffer overflow in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87655: Clickjacking in DownloadsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87656: Improper state validation in SafebrowsingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87657: Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87658: Information leak in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87429: Missing authorization in ServiceWorkerThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87430: Buffer overflow in WebRTCThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87431: Missing authorization in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87432: Incorrect authorization in NavigationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87433: Race condition in FileAPIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87434: Missing authorization in CORSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87435: Information leak in ControlledFrameThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87436: Incomplete cleanup in BrowserThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87437: Information leak in FramesThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87439: Information leak in ServiceWorkerThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87440: Out of bounds read in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87441: Missing authorization in DownloadsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87442: Confused deputy in PrerenderThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87443: Missing authorization in ActorThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87444: Memory corruption in CodecsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87445: UI misrepresentation in SessionThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87446: Incomplete cleanup in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87447: Incorrect authorization in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87448: Use after free in DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87449: Cross-site request forgery in DeviceBoundSessionCredentialsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87450: Incorrect authorization in PermissionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87451: Information leak in DownloadsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87452: Incorrect authorization in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87453: Confused deputy in BackgroundFetchThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87459: Observable discrepancy in SelectThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87460: Use after free in PlatformThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87461: Information leak in CoreThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87462: UI misrepresentation in FedCMThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87463: Incorrect authorization in CertificateThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87465: Incorrect authorization in DownloadsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87466: Incorrect authorization in WorkersThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87467: Race condition in UpdaterThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87468: Incorrect authorization in IsolatedThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87469: Improper input validation in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87470: Improper quantity validation in TintThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87471: Incorrect authorization in ServiceWorkerThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87472: Improper input validation in FedCMThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87473: Incorrect authorization in FileHandlingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87474: Use after free in PaymentsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87475: Missing authorization in OmniboxThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87476: Incorrect authorization in LoaderThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87477: Information leak in CoreThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87478: Observable discrepancy in AutofillThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87479: Insufficient policy enforcement in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87570: Incorrect authorization in SiteIsolationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87571: Improper certificate validation in LoaderThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87572: Injection in DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87573: Improper input validation in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87574: Information leak in ServiceWorkerThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87575: Incorrect authorization in LoaderThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87577: Incorrect authorization in IsolatedThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87578: Use after free in ReceiverThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87579: Buffer overflow in WebRTCThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87580: Incorrect authorization in WebAppInstallsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87581: Use after free in PaymentsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87582: Confused deputy in DataTransferThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87583: UI misrepresentation in PasswordsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87584: Incorrect authorization in WebUIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87585: Double free in PDFiumThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87586: Out of bounds read in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87587: Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87588: Use after free in ChromecastThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87589: Incorrect authorization in SiteIsolationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87590: Improper input validation in PasswordsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87591: Incorrect authorization in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87592: Out of bounds read in TintThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87593: Information leak in EditingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87594: Incorrect authorization in DataTransferThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
14 SepChromium CVE-2026-87596: Out of bounds read in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
13 SepGitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 HoursCVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure. GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path traversal vulnerability in its repository commits API. CVE-2026-85706 affects GitLab’…SECURITYAFFAIRS.COM
13 SepHackers exploit Tencent app flaw to deploy GrayRabbit malwareThreat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. [...]BLEEPINGCOMPUTER.COM
12 SepDutch NCSC: Critical Check Point VPN flaws exploitation is imminentThe Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. [...]BLEEPINGCOMPUTER.COM
11 SepAL26-020 - Vulnerabilities Impacting MikroTik RouterOS - CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060CYBER.GC.CA
11 SepCisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin RansomwareCisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication byp…THEHACKERNEWS.COM
11 SepAttackers are weaponizing the gap between Chromium fixes and Chrome patchesA new exploit kit is revealing the perils of the “patch later” mentality. According to the Proofpoint Threat Research team , espionage-motivated threat actors are using a new malicious toolkit to chain together four separate Chrome browser and Microsoft Windows vulnerabilities to…CSOONLINE.COM
11 Sep[remote] CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCECVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCEEXPLOIT-DB.COM
11 SepGitLab urges users to patch max severity path traversal flawGitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. [...]BLEEPINGCOMPUTER.COM
11 SepCheck Point Patches Critical VPN VulnerabilitiesTracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. The post Check Point Patches Critical VPN Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
11 SepAttackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomwareThree threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware. Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (FMC) flaws. The main target is CVE-2026-…SECURITYAFFAIRS.COM
11 SepCVE-2026-70334 Visual Studio Code Security Feature Bypass VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
11 SepConnectWise patches critical ScreenConnect authentication failure after five daysConnectWise has issued a security update for ScreenConnect, five days after warning customers the product could allow files to be transferred and executed through active remote sessions without authorization or confirmation. The company warned customers on Sept. 3 of the problem …CSOONLINE.COM
11 SepCloud Takeover: Mass Scanning for Exposed Vite Endpoints (CVE-2026-39364)Sensor Intel Series: September 2026 CVE TrendsF5.COM
11 SepGitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After DisclosureGitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the re…THEHACKERNEWS.COM
11 SepChromium CVE-2026-85042: Use after free in DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-85043: Incomplete cleanup in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-85045: Race condition in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-85048: Use after free in CompositingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-85049: Use after free in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-85051: Type confusion in CompositingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-85052: Out of bounds read in CrashReportingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-85053: Improper resource exposure in CacheStorageThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-76017: Use after free in ChromotingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-76018: Privilege elevation in ImportThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-76019: Incorrect authorization in WorkersThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-76021: Use after free in DOMThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-76022: Buffer overflow in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-76023: Improper resource control in Linux Toolkit ThemingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-76036: Buffer overflow in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-76039: Incorrect reference resolution in CoreThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepVU#369611: ExLlamaV3 contains Denial of Service vulnerability via insufficient bounds checking on kernel dispatch indexOverview An out-of-bounds (OOB) memory access vulnerability involving unchecked array indexing has been identified in the exllamav3_ext compute unified device architecture ( CUDA ) extension. Successful exploitation can lead to an immediate denial of service or application instab…KB.CERT.ORG
11 SepChromium CVE-2026-87491: Out of bounds write in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Google is aware that an exploit for CVE-2026-87491 exists i…MSRC.MICROSOFT.COM
10 SepFortinet Code Execution Flaw Exploited in PivotC2 RAT AttacksThe high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026. The post Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
10 SepOrganizations Warned of Cisco Secure FMC ExploitationCisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026. The post Organizations Warned of Cisco Secure FMC Exploitation appeared first on SecurityWeek .SECURITYWEEK.COM
10 Sep KEVCISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch DeadlineThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by S…THEHACKERNEWS.COM
10 SepStealth rootkit targeting F5 BIG-IP could expose enterprise identity gatewaysA newly analyzed Linux rootkit is believed to have given attackers a way to hide shells inside recently compromised F5 BIG-IP Access Policy Management (APM) environments, without leaving the malicious PHP code on disk. Sophos said the malware, found in compromised BIG-IP APM envi…CSOONLINE.COM
10 SepCisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)State-sponsored and financially-motivated attackers are actively exploiting CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC), which is used for centrally managing multiple Cisco Secure Firewall devices across a networ…HELPNETSECURITY.COM
10 Sep KEVCritical NetScaler Vulnerability Exploited in AttacksTracked as CVE-2026-19490, the authentication bypass flaw has been exploited in the wild since at least September 3. The post Critical NetScaler Vulnerability Exploited in Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
10 SepVU#687587: AOMEI Backupper amwrtdrv.sys local privilege escalation vulnerability allows arbitrary writes to physical disksOverview An incorrect permissions assignment vulnerability in the amwrtdrv.sys kernel driver, included with AOMEI Backupper 8.4.0, allows an unprivileged local user to perform arbitrary writes to the physical disk. When Secure Boot is disabled, this can be leveraged to execute ar…KB.CERT.ORG
10 SepArtifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329Wiz Research has identified active, in-the-wild exploitation of three critical and high-severity vulnerabilities impacting JFrog Artifactory (CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329). Attackers are chaining these vulnerabilities to bypass authentication and gain administr…WIZ.IO
9 Sep KEVCisco bundles fixes for multiple vulnerabilities, some critical, into one patchCisco is looking to get ahead of attackers with a new set of more than a half-dozen fixes, some of them critical, for its IOS XR Linux-based network operating system (OS). As part of its regular testing, Cisco’s software engineering team flagged “multiple internally-discovered vu…CSOONLINE.COM
9 Sep KEVSeptember 2026 Patch Tuesday roundup: Plugs for two zero day holes among almost 1,000 fixes in WindowsPossibly wormable bugs and two zero-day holes highlight the almost 1,000 fixes issued today by Microsoft in its September Patch Tuesday release . The 964 vulnerabilities, another record since Microsoft began using AI in the middle of the year to find holes, require customer actio…CSOONLINE.COM
9 Sep KEVN-able N-central Pre-Auth RCE Flaw Exploited in the WildThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by Se…THEHACKERNEWS.COM
9 Sep KEVGoogle fixes second actively exploited Chrome zero-day in under five daysGoogle has released Chrome 153 to the stable channel with fixes for 230 security vulnerabilities, including a V8 memory corruption flaw that Google says is already being exploited in attacks. The actively exploited vulnerability is tracked as CVE-2026-87491 and is described as an…CYBERINSIDER.COM
9 Sep KEVGoogle fixes yet another actively exploited Chrome zero-day (CVE-2026-87491)Google has fixed 230 vulnerabilities in Chrome, including a zero-day flaw, CVE-2026-87491, with an in-the-wild exploit. “Google is aware that an exploit for CVE-2026-87491 exists in the wild,” the company said in a Tuesday security advisory. The fix has been shipped i…HELPNETSECURITY.COM
9 Sep KEVChrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside SandboxGoogle on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bu…THEHACKERNEWS.COM
9 SepResearcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be BypassedThe security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which th…THEHACKERNEWS.COM
9 SepSAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code ExecutionSAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as …THEHACKERNEWS.COM
9 SepSeptember 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successorSeptember 2026 Patch Tuesday is here, with Microsoft delivering another record-breaking number of patches, including those for two vulnerabilities that have been exploited as zero-days. Another “new normal” is the anonymous security researcher Nightmare Eclipse publis…HELPNETSECURITY.COM
9 Sep KEVGoogle fixes the seventh actively exploited Chrome zero-day of 2026Google patched 230 Chrome flaws, including an actively exploited V8 bug that could let attackers run arbitrary code through a crafted HTML page. Google released a Chrome update fixing 230 security vulnerabilities, including one already exploited in the wild tracked as CVE-2026-87…SECURITYAFFAIRS.COM
9 SepChromium: CVE-2026-85046 Type confusion in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Google is aware that an exploit for CVE-2026-85046 exists i…MSRC.MICROSOFT.COM
9 SepMikroTik patches flaws currently being exploited to take over routersNetworking gear manufacturer MikroTik has released patches for six vulnerabilities in its RouterOS firmware, two of which can be chained together to take over devices without authentication over SSH. The exploit chain, dubbed MikroTrick, is already being used by attackers in the …CSOONLINE.COM
9 Sep KEVCisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacksCisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. [...]BLEEPINGCOMPUTER.COM
8 SepAdobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web ShellAdobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler…THEHACKERNEWS.COM
8 SepAdobe Commerce max-severity bug comes under active attackOnline stores running Adobe Commerce and Magento Open Source have been hit by a max-severity, zero-day bug that lets unauthenticated attackers execute code on vulnerable servers. Security firm Sansec is calling the flaw StyleSmuggler because of the way attackers abused Magento’s …CSOONLINE.COM
8 SepCVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)Overview While conducting research into a recent N-able N-central authentication bypass vulnerability ( CVE-2026-18577 ), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-central. When chained together, these two vulnerabilities allow a remote unau…RAPID7.COM
8 Sep KEVAdobe fixes critical Magento zero-day exploited to backdoor serversAdobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. [...]BLEEPINGCOMPUTER.COM
8 SepVU#859658: Skullcandy Dime 3 wireless earbuds contain an unauthenticated Bluetooth pairing vulnerabilityOverview Skullcandy Dime 3 wireless earbuds, running firmware version 1.0.0.28, accept a new Bluetooth Classic (BR/EDR) pairing request from an unpaired device without requiring the earbuds to be placed into pairing mode or requiring any physical confirmation or interaction from …KB.CERT.ORG
8 SepVU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerabilityOverview A Server-Side Request Forgery (SSRF) vulnerability exists in Ascensio System SIA's ONLYOFFICE ownCloud integration plugin (version 9.12). The plugin’s backend endpoint does not adequately validate the user‑supplied document server URL before initiating outbound connectio…KB.CERT.ORG
8 SepCVE-2026-50696 Internet Key Exchange (IKE) Protocol Denial of Service VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
8 Sep KEVMicrosoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)104 Critical 860 Important 0 Moderate 0 Low Microsoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the wild. Microsoft patched a record 964 CVEs in its September 202…TENABLE.COM
8 SepAdobe Patches Over 170 Vulnerabilities, Including Commerce Zero-DayTracked as CVE-2026-75650, the exploited defect allows unauthenticated attackers to execute arbitrary code. The post Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
8 Sep KEVMicrosoft releases Windows security update addressing 723 flawsMicrosoft has released its September 2026 security updates, fixing two Windows elevation-of-privilege vulnerabilities that attackers are already exploiting in the wild. The company’s broader Patch Tuesday release addresses 974 CVEs across its products, including 723 affecting Win…CYBERINSIDER.COM
8 Sep KEVPatch Tuesday - September 2026Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday , including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to 999. Whether this is the…RAPID7.COM
7 Sep KEVBack-to-back N-able bugs send admins on a patching spreeA max-severity zero-day bug could be affecting cybersecurity firm N-able’s N-central remote monitoring and management platform, the company said, even as administrators were applying a hotfix for two vulnerabilities disclosed just a day earlier. The latest flaw, tracked as CVE-20…CSOONLINE.COM
7 Sep KEVN-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)N-able released an emergency hotfix for CVE-2026-86218, a remote code execution (RCE) flaw affecting N-central, its remote monitoring and management (RMM) solution popular with managed service providers (MSPs). In its release notes, N-able described CVE-2026-86218 as a “cri…HELPNETSECURITY.COM
7 SepN-able Releases Hotfix for Critical Remote Code Execution VulnerabilityThe vulnerability, CVE-2026-86218, was allocated a maximum-severity rating by the software provider itselfINFOSECURITY-MAGAZINE.COM
5 SepAttackers Exploit PaperCut Flaws to Steal Credentials From Schools and UniversitiesThreat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an au…THEHACKERNEWS.COM
5 SepElementor Pro WordPress Plugin Vulnerability Exploited to Hack SitesTracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first on SecurityWeek .SECURITYWEEK.COM
5 SepCritical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host CodeBroadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-…THEHACKERNEWS.COM
5 SepPaperCut Flaws Exploited in Attacks on U.S. and European SchoolsAttackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools a…SECURITYAFFAIRS.COM
4 SepOver 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE FlawsThreat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms …THEHACKERNEWS.COM
4 Sep KEVGoogle Releases Chrome Update to Patch Actively Exploited V8 Zero-DayGoogle on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's Ja…THEHACKERNEWS.COM
4 Sep KEVGoogle fixes actively exploited Chrome V8 zero-day vulnerabilityGoogle has released a Chrome security update addressing 12 vulnerabilities, including a high-severity V8 flaw that is being actively exploited in attacks. The fixes are included in Chrome 152.0.7977.82/.83 for Windows and macOS and version 152.0.7977.82 for Linux, with deployment…CYBERINSIDER.COM
4 Sep KEVSangoma Switchvox Vulnerabilities Exploited in the WildTracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution. The post Sangoma Switchvox Vulnerabilities Exploited in the Wild appeared first on SecurityWeek .SECURITYWEEK.COM
4 Sep12-Year-Old PostgreSQL Vulnerability Enables Database, Server TakeoverDubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database backdoor. The post 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover appeared first on SecurityWeek .SECURITYWEEK.COM
4 Sep KEVGoogle patches actively exploited Chrome zero-day (CVE-2026-85046)Google has patched 12 vulnerabilities affecting its popular Chrome browser, among them CVE-2026-85046, which has been exploited in the wild. “Google is aware that an exploit for CVE-2026-85046 exists in the wild,” the company said in a Thursday security advisory. The …HELPNETSECURITY.COM
4 SepPostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server TakeoverPostGREShell (CVE-2026-6471) is a 12-year-old PostgreSQL flaw that lets low-privileged attackers execute code and take over servers. Cyera researchers found a severe PostgreSQL vulnerability, dubbed PostGREShell and tracked as CVE-2026-6471 (CVSS score of 7.2). Present in release…SECURITYAFFAIRS.COM
4 Sep KEVGoogle fixes the sixth actively exploited Chrome zero-day of 2026Google patched 12 Chrome flaws, including an actively exploited V8 zero-day that could enable remote code execution through a crafted webpage. Google released a Chrome security update fixing 12 vulnerabilities, including CVE-2026-85046 (CVSS score of 8.8), an actively exploited V…SECURITYAFFAIRS.COM
4 SepCritical Citrix NetScaler auth bypass now leveraged in attacksAttackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. [...]BLEEPINGCOMPUTER.COM
4 SepPostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code ExecutionPostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical de…THEHACKERNEWS.COM
4 SepHPE Patches Critical RCE Vulnerabilities in AOS-CXNearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates. The post HPE Patches Critical RCE Vulnerabilities in AOS-CX appeared first on SecurityWeek .SECURITYWEEK.COM
4 SepAL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489CYBER.GC.CA
3 SepOver 3 Million WordPress Sites Affected by Migration Plugin VulnerabilityThe high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution. The post Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
3 SepDecade-old PostgreSQL flaw turns backup account into a backdoorA critical vulnerability in PostgreSQL had remained hidden for more than a decade, potentially turning a routine backup account into a path to full database and server compromise. The issue, dubbed PostGREShell by Cyera Research, exists in the database’s replication functionality…CSOONLINE.COM
3 SepCritical Elementor Pro flaw exploited to take over WordPress sitesA recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server. [...]BLEEPINGCOMPUTER.COM
3 SepCVE-2026-58641 .NET Elevation of Privilege VulnerabilityAdded SkiaSharp 4.151.2 to the affected software table.MSRC.MICROSOFT.COM
3 SepCritical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as RootCisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8…THEHACKERNEWS.COM
3 SepVU#889462: Casdoor authentication server is vulnerable to authorization bypassOverview Casdoor is an open-source Access Management (IAM) platform used to manage web applications. An authorization bypass vulnerability affects Casdoor versions 3.115.0 and earlier. The vulnerability allows a non-global organization administrator to perform unauthorized admini…KB.CERT.ORG
3 SepCisco Fixed Critical RCE in Nexus 9000 Series SwitchesCisco patched a critical Nexus 9000 vulnerability, CVE-2026-20212, allowing unauthenticated remote root code execution. Cisco has released patches for a critical flaw, tracked as tracked as CVE-2026-20212 (CVSS score of 9.8) in 10 Silicon One-based Nexus 9000 switches. The vulner…SECURITYAFFAIRS.COM
3 SepChromium: CVE-2026-84323 Missing authorization in FileSystemThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
3 SepChromium: CVE-2026-84325 Improper input validation in DataTransferThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
3 SepChromium: CVE-2026-84326 Uninitialized resource in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
3 SepChromium: CVE-2026-84327 Incorrect authorization in AutofillThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
3 SepChromium: CVE-2026-84329 Confused deputy in CredentialProviderThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
3 SepChromium: CVE-2026-84332 Incorrect authorization in SiteSettingsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
3 SepChromium: CVE-2026-84354 Incorrect authorization in FileSystemThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
3 SepChromium: CVE-2026-84358 Improper privilege management in DownloadsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
3 SepChromium: CVE-2026-84324 Use after free in ProxyThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
3 SepChromium: CVE-2026-84328 Missing authorization in FileSystemThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
3 SepChromium: CVE-2026-84331 Incorrect authorization in ActorThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
3 SepChromium: CVE-2026-84334 Incorrect authorization in ChromotingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
3 SepChromium: CVE-2026-84335 Incorrect authorization in TabStripThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
3 SepChromium: CVE-2026-84347 Use after free in WebRTCThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
3 SepChromium: CVE-2026-84348 Information leak in MediaCaptureThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
3 SepChromium: CVE-2026-84349 Use after free in BrowserThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
3 SepChromium: CVE-2026-84350 Use after free in TabStripThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
3 SepChromium: CVE-2026-84351 Buffer overflow in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
3 SepChromium: CVE-2026-84353 Use after free in Shared Tab GroupsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
3 SepChromium: CVE-2026-84355 Incorrect authorization in NavigationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
3 SepChromium: CVE-2026-84356 UI misrepresentation in FullScreenThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
3 SepChromium: CVE-2026-84357 Improper input validation in OmniboxThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
3 SepChromium: CVE-2026-84359 Information leak in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
2 Sep22,000 Exchange servers open to hijack, 700 rogue AI agents swarmed Hugging Face, AI threatens global finance22,000 Exchange Servers Exposed, 700 AI Agents Swarm Hugging Face, and FSB Warns Frontier AI Is Top Financial Risk Cybersecurity Today with host David Shipley reports nearly 21,899 Microsoft Exchange servers still exposed and unpatched for high-severity auth-bypass CVE-2026-62911…CYBERSECURITYTODAY.LIBSYN.COM
2 SepSonicWall Warns of Two SMA1000 Zero-Days Exploited in AttacksThe vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution. The post SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
2 SepResearchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to AnotherForescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware. The exploit targets&…THEHACKERNEWS.COM
2 SepAttackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without CredentialsThreat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulne…THEHACKERNEWS.COM
2 SepHackers Target Langflow in CVE-2026-0768 AttacksHackers are exploiting a critical Langflow flaw that lets unauthenticated attackers remotely execute Python code on vulnerable systems. Hackers have started exploiting a critical vulnerability, tracked as CVE-2026-0768 (CVSS score of 9.8), in the AI-focused low-code platform Lang…SECURITYAFFAIRS.COM
2 SepAttackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack ChainSonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks. The vulnerabilities, discovered internally by SonicWall's William Perry and Adam Babis, are list…THEHACKERNEWS.COM
2 SepSonicWall SMA 1000 appliances under attack via zero-day flawsAttackers are exploiting two previously undisclosed vulnerabilities (CVE-2026-83548, CVE-2026-83549) in SonicWall SMA 1000 appliances, the vendor confirmed on Tuesday. The vulnerabilities (CVE-2026-83548, CVE-2026-83549) The SonicWall SMA 1000 series is a line of secure remote ac…HELPNETSECURITY.COM
2 Sep KEVExploited JFrog Artifactory bug puts software supply chain on alertA critical authentication bypass in JFrog Artifactory is now being exploited in the wild, with attackers observed generating administrator tokens and probing the software supply-chain platform’s sensitive data. The flaw, tracked as CVE-2026-82329 , was disclosed by JFrog on Augus…CSOONLINE.COM
2 SepExploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)A threat actor is actively targeting internet-exposed Sangoma Switchvox instance through a recently patched SQL injection flaw (CVE-2026-9586), and organizations running them should check for signs of compromise immediately. How CVE-2026-9586 works Switchvox is a VoIP-based unifi…HELPNETSECURITY.COM
2 SepNearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability, according to daily scans from the Shadowserver Foundation. The United States and Germany top the list with 6,200 and 5,100 unpatched servers. CVE-2026…HELPNETSECURITY.COM
2 SepHackers exploit critical JFrog Artifactory flaw to forge admin tokensA critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access. [...]BLEEPINGCOMPUTER.COM
2 SepCVE-2026-47285 Visual Studio Code Information Disclosure VulnerabilityAffected software updated with new package information.MSRC.MICROSOFT.COM
2 SepCVE-2026-58650 Visual Studio Code Security Feature Bypass VulnerabilityAffected software updated with new package information.MSRC.MICROSOFT.COM
2 SepCVE-2026-59113 Visual Studio Code Remote Code Execution VulnerabilityAffected software updated with new package information.MSRC.MICROSOFT.COM
2 Sep KEVCritical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the WildOverview On September 1, 2026, SonicWall disclosed two vulnerabilities affecting SonicWall SMA1000 appliances that the vendor says are being actively exploited in the wild. The vulnerabilities, CVE-2026-83548 and CVE-2026-83549 , can be chained to achieve unauthenticated remote c…RAPID7.COM
2 SepHackers exploit Sangoma Switchvox flaw to deploy reverse shellsAttackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. [...]BLEEPINGCOMPUTER.COM
2 Sep KEVSonicWall reports two major security holes under active exploitSonicWall on Monday reported two major security holes in its Secure Mobile Access 1000 series appliances, both of which it said are being actively exploited, and published patches for each. Consultants called the holes, one of which permits remote attacks that bypass authenticati…CSOONLINE.COM
1 SepAttackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 ActivityThreat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability …THEHACKERNEWS.COM
1 Sep KEVCritical JFrog Artifactory Vulnerability Reportedly Exploited in the WildExploitation of the authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure. The post Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild appeared first on SecurityWeek .SECURITYWEEK.COM
1 SepHackers Start Exploiting Critical Langflow VulnerabilityTracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely. The post Hackers Start Exploiting Critical Langflow Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
1 SepCritical Langflow flaw exploited to steal OpenAI and AWS keysThreat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. [...]BLEEPINGCOMPUTER.COM
1 SepAttackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After DisclosureThreat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to admin…THEHACKERNEWS.COM
1 SepCritical Langflow Flaw Exploited as Attacks on AI Platform RiseThe attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year.DARKREADING.COM
1 SepAttackers Pounce on Critical Artifactory Flaw Following DisclosureCVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected systems.DARKREADING.COM
1 SepWhat happens when AI models take aim at ICS exploitsLLMs have shown great improvement in vulnerability research and exploit development capabilities over the past six months. But it’s one thing to find vulnerabilities in well documented open-source projects and an entirely different skillset to decrypt file systems and reverse-eng…CSOONLINE.COM
31 AugCVE-2026-49177 Windows TCP/IP Information Disclosure VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
31 AugCVE-2026-50344 Windows OLE Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
31 AugCVE-2026-65775 Windows Win32k Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
31 AugCVE-2026-65776 Windows Win32k Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
31 AugCVE-2026-62823 Windows DHCP Server Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
31 AugCVE-2026-62889 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
31 AugSimulating legitimate Active Directory services on the network: the case of GPO exploitationSimulating legitimate Active Directory services on an internal network is a powerful and versatile capability that can be leveraged in various contexts. Many examples of exploits relying on the ability to simulate working LDAP and/or SMB services can be cited, such as Group Polic…SYNACKTIV.COM
29 AugFive Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCEMultiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to…THEHACKERNEWS.COM
28 Aug KEVownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research BodyThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nucl…THEHACKERNEWS.COM
28 AugTwo Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over BluetoothSecurity researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low Energy (BLE) path that can reach root on the robot's Locomotion PC. The flaws are tracked as CVE-2026-76639 …THEHACKERNEWS.COM
28 AugChina-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root AccessVulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices. The implants, named SPEAKING…THEHACKERNEWS.COM
28 AugCritical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole ServercPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user. The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported ver…THEHACKERNEWS.COM
28 AugCVE-2026-70331 Microsoft Edge for iOS Spoofing VulnerabilityImproper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.MSRC.MICROSOFT.COM
28 AugCVE-2026-58616 Copilot Chat (Microsoft Edge) Information Disclosure VulnerabilityConcurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network.MSRC.MICROSOFT.COM
28 AugCVE-2026-62904 Microsoft Edge (Chromium-based) Information Disclosure VulnerabilityIncorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.MSRC.MICROSOFT.COM
28 AugCVE-2026-66323 Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityImproper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.MSRC.MICROSOFT.COM
28 AugCVE-2026-66324 Microsoft Edge (Chromium-based) Spoofing VulnerabilityExternal control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.MSRC.MICROSOFT.COM
28 AugCVE-2026-66798 Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityUse after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.MSRC.MICROSOFT.COM
28 AugCVE-2026-70341 Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityUse after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.MSRC.MICROSOFT.COM
28 AugCVE-2026-72984 Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityAccess of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78891 Buffer overflow in WebRTCThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78892 Incorrect authorization in ChromotingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78893 Information leak in QUICThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78894 Race condition in PaymentsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78895 Information leak in PaintThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78896 Information leak in StorageAccessAPIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78897 Missing authorization in BrowserTagThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78898 Incorrect authorization in DownloadsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78899 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78900 Improper input validation in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78901 Race condition in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78903 Incomplete cleanup in SiteIsolationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78904 Type confusion in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78905 Type confusion in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78906 Race condition in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78907 Incorrect authorization in WebProtectThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78908 Information leak in CanvasThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78909 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78910 Buffer overflow in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78911 Incorrect authorization in USBThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78912 UI misrepresentation in BrowserThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78913 Use after free in ChromotingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78914 Uninitialized resource in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78915 Race condition in EnterpriseThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78934 Race condition in ReadAloudThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78938 Type confusion in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78939 Use after free in ChromecastThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78940 Improper initialization in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78941 Information leak in CoreThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78942 Incorrect reference resolution in LoaderThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78943 Improper input validation in EditingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78944 Use after free in DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78945 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78946 Incorrect authorization in SelectThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78947 Incomplete cleanup in ChromiumThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78948 Buffer overflow in WebGLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78950 Integer overflow in WebRTCThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78951 Use after free in ServiceWorkerThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78952 Out of bounds write in CrashpadThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78953 Missing authorization in SiteIsolationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78954 Incorrect authorization in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78955 Observable discrepancy in PerformanceAPIsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78956 Type confusion in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78958 Uninitialized resource in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78959 Improper handling of case sensitivity in FileSystemThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78960 Information leak in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78961 Incorrect authorization in CoreThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78962 Uninitialized resource in WebXRThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78963 Improper input validation in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78964 Use after free in SyncThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78965 Uninitialized resource in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78966 Externally controlled reference in QUICThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78967 Missing authorization in BFCacheThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78968 Missing authorization in CoreThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78969 Uninitialized resource in VideoThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78974 UI misrepresentation in Linux Toolkit ThemingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78975 Incorrect authorization in DOMThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78976 Improper input validation in StorageAccessAPIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78977 Uninitialized resource in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78978 Out of bounds read in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78979 Race condition in CoreThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78980 Improper input validation in ReaderModeThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78983 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78984 Uninitialized resource in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78985 Incorrect reference resolution in FileSystemThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78986 Uninitialized resource in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78987 Information leak in CanvasThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78989 Out of bounds read in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78990 Use after free in CompositingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78991 Race condition in WebProtectThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78999 Improper privilege management in NavigationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79000 Improper input validation in DeviceBoundSessionCredentialsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79001 Information leak in BluetoothThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79002 Incorrect authorization in SiteIsolationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79003 Incorrect authorization in DeviceThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79004 Out of bounds read in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79005 Incorrect authorization in StorageAccessAPIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79006 Protection mechanism failure in HttpsUpgradesThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79007 Uninitialized resource in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79009 UI misrepresentation in UIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79010 Operation on a resource after expiration or release in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79011 UI misrepresentation in BrowserThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79012 Use after free in SafebrowsingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79013 Improper input validation in SyncThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79014 Race condition in AutofillThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79015 Improper input validation in ServiceWorkerThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79016 Observable discrepancy in SVGThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79017 Race condition in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79018 Information leak in FoldableAPIsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79019 Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79020 Out of bounds read in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79021 Missing authorization in InterestGroupsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79022 UI misrepresentation in Transactions PlatformThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79023 Incorrect authorization in EditingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79024 Information leak in ServiceWorkerThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79025 Improper input validation in WorkersThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79026 Use after free in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79027 Use after free in WebRTCThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79028 Observable discrepancy in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79030 Observable discrepancy in AutofillThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79031 Improper resource exposure in PreloadThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79032 Improper input validation in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79033 Insufficient control flow management in DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79034 Information leak in CORSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79038 Incorrect authorization in WebProtectThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79040 Uninitialized resource in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79041 Missing authorization in BrowserThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79042 Missing authorization in PaymentsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79043 Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79045 Type confusion in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79047 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79048 Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79049 Incorrect reference resolution in PasswordsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79050 Incorrect authorization in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79051 Incorrect authorization in LoaderThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79052 Use after free in AuraThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79053 Missing authorization in LighthouseThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79054 Use after free in ChromecastThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79055 Information leak in SharingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79056 Use after free in ServiceWorkerThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79058 Missing authorization in PasswordsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79059 Information leak in BFCacheThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79060 Incorrect authorization in StorageAccessAPIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79064 Use after free in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79065 Improper input validation in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79066 Improper input validation in NavigationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79067 Missing authorization in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79068 Improper resource exposure in StreamsAPIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79069 Memory corruption in TintThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79070 Incorrect reference resolution in CacheThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79071 Race condition in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79072 Improper state validation in PerformanceThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79073 Improper state validation in ParserThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79074 Information leak in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79075 Information leak in GeolocationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79076 Improper input validation in SyncThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79077 Incorrect authorization in WebProtectThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79078 Use after free in FedCMThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79082 Incorrect authorization in Transactions PlatformThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79083 Improper enforcement of behavioral workflow in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79084 Inadequate encryption strength in NotificationsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79085 Missing authorization in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79087 Injection in Chrome TabsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79088 Incorrect authorization in FileSystemThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79089 Race condition in Transactions PlatformThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79090 Improper privilege management in ActorThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79091 Use after free in BluetoothThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79093 Incorrect authorization in PaintThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79094 Race condition in WorkersThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79095 Information leak in PaymentsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79097 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79098 UI misrepresentation in PermissionElementThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79099 Missing authorization in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79103 Incorrect reference resolution in SpeechThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79104 Missing authorization in SensorThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79106 Improper input validation in InputThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79107 Incorrect authorization in TabGroupsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79108 UI misrepresentation in Web Authentication (Passkeys & Security Keys)This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79109 Improper input validation in PrintingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79110 Missing authorization in PreloadThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79111 Improper input validation in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79112 Out of bounds read in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79116 Missing authorization in VizThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79118 Uninitialized resource in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79119 Use after free in PDFThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79120 Uninitialized resource in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79121 Improper input validation in ChromecastThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79122 Information leak in SignInThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79123 Improper input validation in NTP FooterThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79124 Information leak in IntentsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79125 Information leak in XRThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79126 Incorrect provision of specified functionality in ProxyThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79127 Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79128 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79130 Buffer overflow in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79131 Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79133 Incorrect authorization in FormsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79134 Incorrect authorization in GetUserMediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79136 Incorrect authorization in ServiceWorkerThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79137 Incorrect authorization in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79138 Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79139 Improper input validation in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79140 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79141 Incorrect authorization in BrowserThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79142 Buffer overflow in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79143 Incorrect authorization in FileSystemThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79144 Information leak in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79147 Information leak in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79148 Off-by-one error in DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79149 Use after free in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79150 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79151 Improper input validation in SafebrowsingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79154 Missing authorization in DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79155 Race condition in FileSystemThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79173 UI misrepresentation in WebAppInstallsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79174 Incorrect authorization in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79175 Type confusion in AccessibilityThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79176 UI misrepresentation in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79177 Incorrect authorization in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79178 Incorrect authorization in Web Authentication (Passkeys & Security Keys)This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79179 Incorrect authorization in DOMThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79181 Observable discrepancy in GlicThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79182 Improper input validation in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79183 Use after free in AccessibilityThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79184 Missing authorization in PreloadThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79185 Information leak in DOMThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79186 Incorrect authorization in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79187 Use after free in WebRTCThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79188 Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79189 Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79190 Incorrect authorization in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79191 Incorrect authorization in SiteIsolationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79192 Improper input validation in VariationsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79193 Information leak in CanvasThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79194 Use after free in ChromotingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79195 Use after free in ScriptThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79196 Race condition in EditingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79197 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79198 Use after free in PlatformThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79199 Incorrect authorization in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79200 Use after free in AuraThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79201 Improper access control in WorkersThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79202 Use after free in ChromecastThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79203 Improper input validation in DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79204 UI misrepresentation in InputThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79205 Incorrect authorization in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79206 Out of bounds read in FileSystemThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79208 Missing authorization in HTTP2This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79209 Type confusion in AnimationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79211 Incorrect authorization in USBThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79212 Missing authorization in PasswordsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79214 Improper input validation in PreloadThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79215 Integer overflow in WebGLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79216 Buffer overflow in BlinkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79218 Incorrect authorization in SandboxThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79219 Use after free in BluetoothThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79220 Information leak in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79221 Uninitialized resource in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79223 Integer overflow in ChromiumThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79224 Use after free in ChromecastThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79225 Incorrect authorization in BrowserThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79226 Improper privilege management in Regional CapabilitiesThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79227 Type confusion in DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79228 Incorrect authorization in SiteIsolationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79229 Uninitialized resource in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79230 Improper input validation in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79231 Buffer overflow in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79232 Use after free in AuraThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79234 Injection in CSSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79235 Use after free in WebGLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79236 Type confusion in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79237 Incorrect authorization in NavigationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79238 Incorrect authorization in ServiceWorkerThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79239 Out of bounds read in TintThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79240 Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79242 Observable discrepancy in HTMLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79243 Improper input validation in ReadingListThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79244 Use after free in AnimationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79245 Use after free in UIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79246 Information leak in DataTransferThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79247 Use after free in ChromotingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79248 Incorrect authorization in InputThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79249 Code injection in BisectionThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79250 UI misrepresentation in NavigationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79251 Improper input validation in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79252 Information leak in ServiceWorkerThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79253 Improper input validation in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79255 Improper input validation in WebRTCThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79257 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79258 Incorrect authorization in WebXRThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79259 Improper input validation in SafebrowsingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79260 Improper input validation in CookiesThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79261 Incorrect authorization in ControlsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79262 Incorrect authorization in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79263 Race condition in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79264 Incorrect reference resolution in PreloadThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79265 Incomplete cleanup in GetUserMediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79266 Use after free in DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79267 Race condition in WorkersThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79269 Uninitialized resource in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79270 Uninitialized resource in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79271 Information leak in DOMThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79272 Improper input validation in FindInPageThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79274 Information leak in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79275 Use after free in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79276 Improper privilege management in FileSystemThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79283 UI misrepresentation in GeometryThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79284 UI misrepresentation in CoreThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79285 Uninitialized resource in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79287 Observable discrepancy in FormsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79289 Improper control of a resource through its lifetime in WorkersThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79290 Use after free in AuraThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79291 Information leak in CSSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79292 Integer overflow in ChromecastThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79293 Information leak in AnimationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugCVE-2026-70309 Microsoft Edge (Chromium-based) Security Feature Bypass VulnerabilityOrigin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.MSRC.MICROSOFT.COM
28 AugCVE-2026-65813 Microsoft Exchange Server Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
28 AugServiceNow patches three maximum severity flaws that could put enterprise data at riskCode injection and SQL injection attacks have been around for decades, and they are still tried-and-true ways for attackers to compromise systems. ServiceNow’s latest trio of maximum severity flaws shows that even AI-era platforms remain vulnerable to these techniques: The softwa…CSOONLINE.COM
28 AugThe first 24 hours of an AI agent security incidentMost of what I read on AI agent security follows the same shape: a taxonomy of risks, a list of governance principles and a call to “adopt responsible AI practices.” That’s useful for a board deck. It’s nearly useless at 2 a.m. when an autonomous agent with live credentials has j…CSOONLINE.COM
28 AugCTEM can give your security team a contextual edgeTraditional vulnerability management is accelerating toward a reset, with many security organizations considering continuous threat exposure management (CTEM) to better align their operations with the pace of change — and attacks — today. Whereas traditional vulnerability managem…CSOONLINE.COM
27 Aug KEVRecent Citrix NetScaler Vulnerability Exploited in the WildCISA is urging government agencies to immediately patch the Citrix NetScaler vulnerability tracked as CVE-2026-8452. The post Recent Citrix NetScaler Vulnerability Exploited in the Wild appeared first on SecurityWeek .SECURITYWEEK.COM
27 Aug KEVPreviously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452)CISA added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a previously patched Citrix NetScaler ADC and Gateway flaw, tracked as CVE-2026-8452, that is being exploited in the wild. The agency published the alert on August 26 and gave feder…HELPNETSECURITY.COM
27 AugCVE-2026-69550 Windows App for Mac Information Disclosure VulnerabilityUpdated CWE value. This is an informational change only.MSRC.MICROSOFT.COM
27 AugCVE-2026-50435 Windows Overlay Filter Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
27 AugCVE-2026-50351 Windows Audio Compression Manager (ACM) Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
27 AugCVE-2026-65779 Windows Autopilot Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
27 AugCVE-2026-68817 Microsoft Excel Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
27 AugCVE-2026-42993 Remote Desktop Client Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
27 AugNext.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCECredit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traver…THEHACKERNEWS.COM
26 AugCISA Warns of Exploited Gitea VulnerabilityCVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1.27.1. The post CISA Warns of Exploited Gitea Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
26 Aug KEVCritical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like PayloadThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code executio…THEHACKERNEWS.COM
26 Aug KEVCritical Gitea vulnerability now exploited in the wild (CVE-2026-60004)Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. The KEV entry does not contain or point to details about …HELPNETSECURITY.COM
26 AugNemoClaw’s AI can be poisoned through a browser tabA vulnerability affecting Nvidia’s NemoClaw could let an attacker gain control of the local Ollama model server through a single malicious website visit on the victim’s machine. According to a Cyera research , the flaw could give attackers unauthenticated access to the server, al…CSOONLINE.COM
26 AugVMs won't contain cyber-capable agentsAs part of Patch the Planet , we received preview access to GPT 5.6-Cyber with a simple task: evaluate its cyber capabilities. Recent events inspired me to give it a challenge to work through: escape the VM I’d normally use for sandboxing. The target was a QEMU/KVM VM on my Linux…TRAILOFBITS.COM
26 AugUnpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run CodeThe CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The flaws, tracked as CVE-2026-19913 and CVE-2026…THEHACKERNEWS.COM
26 AugCVE-2026-62890 Windows GDI+ Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
25 AugAttackers Target miniOrange SAML Flaws That Can Grant WordPress Admin AccessBad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators. The vulnerabilities, as disclosed by…THEHACKERNEWS.COM
25 Aug KEVActively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilit…THEHACKERNEWS.COM
25 AugCISA Warns of Exploited Oracle WebLogic VulnerabilityThe vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers. The post CISA Warns of Exploited Oracle WebLogic Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
25 AugUnpatched Zimbra servers are falling to CVE-2026-73570 attacksAt least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. About CVE-2026-73570 Zimbra Collaboration Suite (ZCS) is a communication and collaboration platform popular with organization…HELPNETSECURITY.COM
25 AugNucleus wants to get ahead of scanners on new vulnerabilitiesThere usually is a crucial time lapse from when a vulnerability is newly disclosed to when security scanners are finally updated to scan for it. Nucleus Security says it wants to close that gap. The cybersecurity outfit focused on unified exposure management is expanding its plat…CSOONLINE.COM
25 AugCVE-2026-55137 Microsoft Excel Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
25 AugCVE-2026-50448 Windows NTFS Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
25 AugCVE-2026-61939 Winlogon Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
25 AugWordPress Websites Targeted via MiniOrange Plugin VulnerabilitiesCVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin. The post WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
25 AugCVE-2026-62728 Windows Common Log File System Driver Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
25 AugCVE-2026-70337 Microsoft PowerShell Remote Code Execution VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
25 AugCVE-2026-59127 Windows Installer Elevation of Privilege VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
25 AugVU#308749: Remote Code Execution and Arbitrary File Read Vulnerabilities in Kaltura ServersOverview The Kaltura HTML5 Player Library (mwEmbed / html5lib) contains two vulnerabilities, both involving the same insecure deserialization flaw, that enable arbitrary file read and remote code execution. Affected versions include html5lib v2.45, v2.103 and earlier, and other v…KB.CERT.ORG
25 AugTwo CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as VulnerableTwo CVSS 9.8 miniOrange SAML WordPress plugin auth bypasses were exploited while paid editions never appeared in any vulnerability database. Manual patch required. Two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On WordPress plugin, both …SECURITYAFFAIRS.COM
24 Aug KEVMicrosoft patches perfect-ten Entra ID flaw, Defender driver deletes Defender at boot, Malware turns cars into proxy botnetEntra ID Perfect 10 Patch, Defender Driver Weaponized, SickKids Breach, Live Leaked AWS Keys, and Car Head Unit Malware Microsoft patched a maximum-severity Entra ID deserialization RCE (CVE-2026-69836) after briefly indicating it was exploited in the wild before correcting that …CYBERSECURITYTODAY.LIBSYN.COM
24 AugCritical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any AccountRed Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset. The vulnerability, as…THEHACKERNEWS.COM
24 AugCVE-2026-65787 Desktop Window Manager Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
24 AugCVE-2026-47292 Visual Studio Code MSSQL Extension Remote Code Execution VulnerabilityAffected software updated with new package information.MSRC.MICROSOFT.COM
24 AugMetal Gear Online 3 flaw allowed code execution on players’ PCsA vulnerability in Konami’s Metal Gear Online 3 allowed malicious multiplayer lobby hosts to remotely execute arbitrary code on the computers of players joining their sessions. The flaw, tracked as CVE-2026-19874, was silently fixed earlier this month in game version 1.1.2.9. The…CYBERINSIDER.COM
24 AugExploited Zimbra Flaw Highlights Shrinking Window to PatchCISA has issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications.DARKREADING.COM
21 Aug KEVMicrosoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code ExecutionMicrosoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer action is required. The vulnerability, tracked as CVE-2026-69836 (CVSS score: 10.0), is a case of remote code execution impacting t…THEHACKERNEWS.COM
21 AugGitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of DisclosureA newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an unauthenticated attacker to modify or …THEHACKERNEWS.COM
21 AugCitrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)Citrix has patched two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw tracked as CVE-2026-19490, and is urging customers to upgrade affected appliances as soon as possible. “We strongly recommend that customers review…HELPNETSECURITY.COM
21 AugGitLab Warns of Active Exploitation of Critical GraphQL FlawGitLab flaw CVE-2026-19478 is now under active exploitation, allowing unauthenticated attackers to modify or delete public projects. WatchTowr researchers warn of active exploitation of critical GitLab flaw CVE-2026-19478 (CVSS score of 9.4). This week, GitLab pushed out an emerg…SECURITYAFFAIRS.COM
21 AugPoland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite FlawCERT Polska confirmed active exploitation of CVE-2026-73570, a critical unauthenticated RCE in Zimbra Collaboration Suite patched on July 20. CERT Polska, Poland’s national computer emergency response team, confirmed this week that threat actors are actively exploiting a cr…SECURITYAFFAIRS.COM
21 AugCVE-2026-58547 Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 AugCVE-2026-49183 Windows Clipboard Server Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 AugCVE-2026-55134 Microsoft Word Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 AugCVE-2026-68801 Microsoft Excel Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 AugCVE-2026-64903 Microsoft Office Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 AugCVE-2026-64899 Microsoft Office Information Disclosure VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 AugCVE-2026-70335 GitHub Copilot and Visual Studio Code Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 Aug KEVCritical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)Microsoft has patched a critical remote code execution vulnerability (CVE-2026-69836) in Entra ID, reportedly exploited in the wild. Entra ID is Microsoft’s cloud identity service, formerly Azure Active Directory, that verifies logins and controls access to Microsoft 365, A…HELPNETSECURITY.COM
21 AugCVE-2026-50466 Microsoft Brokering File System Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 AugVU#756733: Calix GS7 XGS GS5239XG residential router contains missing authentication vulnerabilityOverview The Calix GS7 XGS GS5239XG router running firmware EXOS/6.6.47 contains a missing authentication vulnerability that exposes its UPnP (Universal Plug and Play) WANIPConnection service on the public WAN interface. Description Calix GS7 XGS GS5239XG is a residential gateway…KB.CERT.ORG
21 Aug KEVCVE-2026-69836 Microsoft Entra ID Remote Code Execution VulnerabilityCorrected **Exploited** to **No**. This vulnerability was not exploited in the wild. This is an informational change only.MSRC.MICROSOFT.COM
20 AugElementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute CodeCybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been descr…THEHACKERNEWS.COM
20 AugCritical GitLab Flaw Exploited Shortly After DisclosureCVE-2026-19478 can be exploited without authentication to modify or delete public projects and user data. The post Critical GitLab Flaw Exploited Shortly After Disclosure appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugCVE-2026-66802 Windows Device Health Attestation (DHA) Remote Code Execution VulnerabilityCorrected the Executive Summary to clarify that the vulnerability affects Windows Device Health Attestation (DHA), not Microsoft Azure Attestation. This is an informational change only.MSRC.MICROSOFT.COM
20 AugCVE-2026-71331 Windows Device Health Attestation (DHA) Remote Code Execution VulnerabilityCorrected the Executive Summary to clarify that the vulnerability affects Windows Device Health Attestation (DHA), not Microsoft Azure Attestation. This is an informational change only.MSRC.MICROSOFT.COM
20 AugAttackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code ExecutionA now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska). The vulnerability in question is CVE-2026-73570 (CVSS score: 8.9), which refers to a case of co…THEHACKERNEWS.COM
20 AugCVE-2026-62754 Windows Kerberos Elevation of Privilege VulnerabilityUpdated links to security updates. This is an informational change only.MSRC.MICROSOFT.COM
20 AugHackers Target Zimbra Servers in Active Exploitation CampaignExploitation of the Zimbra Collaboration vulnerability CVE-2026-73570 has been observed by Poland’s CERT Polska. The post Hackers Target Zimbra Servers in Active Exploitation Campaign appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugCVE-2026-54118 Microsoft SQL Server Remote Code Execution VulnerabilityThe CVSS vector string was update to reflect that an attacker does not require any privileges to successfully exploit this vulnerability (PR:N). This is an informational change only.MSRC.MICROSOFT.COM
20 AugCVE-2026-54117 Microsoft SQL Server Remote Code Execution VulnerabilityThe CVSS vector string was update to reflect that an attacker does not require any privileges to successfully exploit this vulnerability (PR:N). This is an informational change only.MSRC.MICROSOFT.COM
20 AugCitrix issues critical security updates for its NetScaler devicesCitrix is urging its NetScaler ADC and NetScaler Gateway customers to quickly patch two critical security holes, one involving a memory overflow vulnerability leading to unpredictable behavior or denial of service, and the other allowing authentication bypass. Citrix said in an a…CSOONLINE.COM
20 AugRejoice In The Nostalgia - PSW #940In the security news this week: - Cursor opens your repo, the repo opens you - If you want the good model I'm going to need to see your ID - Flock's a Flocking mess - Defender was supposed to be the chosen one - Side stepping Secure boot - twice - SonicWall: a LAMP stack in a fan…YOUTUBE.COM
19 AugMicrosoft finally patches critical one-click Copilot vulnerability, almost eight months after learning of itAlmost eight months after confirming a critical security vulnerability within the personal version of its AI assistant, Copilot, Microsoft on Tuesday issued a patch to close the hole, which relies on an LLM’s inability to distinguish the data in a query from an instruction. The C…CSOONLINE.COM
19 Aug KEVCVE-2026-20349: Someone Is Crashing Cisco Firewalls. We Need to Talk About Why.An unauthenticated attacker can crash any Cisco ASA or FTD with SSL VPN exposed; it’s been confirmed exploited in the wild, and Cisco hasn’t told us who or why. Attackers Can Force Your Firewall To Reboot If you run a Cisco Adaptive Security Appliance or a Firepower T…ECLYPSIUM.COM
19 AugCVE-2026-70338 Microsoft PowerShell Security Feature Bypass VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
19 AugCVE-2026-62705 Microsoft Brokering File System Elevation of Privilege VulnerabilityCorrected the CVE title from **Windows Bind Filter Driver Elevation of Privilege Vulnerability** to **Microsoft Brokering File System Elevation of Privilege Vulnerability** and updated the acknowledgement. These are informational changes only.MSRC.MICROSOFT.COM
19 AugCVE-2026-42912 Windows Telephony Service Elevation of Privilege VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
19 AugCVE-2026-69414 Microsoft Defender Elevation of Privilege VulnerabilityCWE added. Informational change only.MSRC.MICROSOFT.COM
19 AugCVE-2020-1173 Microsoft Power BI Report Server Spoofing VulnerabilityCorrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.MSRC.MICROSOFT.COM
19 AugCVE-2021-26859 Microsoft Power BI Information Disclosure VulnerabilityCorrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.MSRC.MICROSOFT.COM
19 AugCVE-2021-41372 Power BI Report Server Spoofing VulnerabilityCorrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.MSRC.MICROSOFT.COM
19 AugCVE-2023-21806 Power BI Report Server Spoofing VulnerabilityCorrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.MSRC.MICROSOFT.COM
19 AugCVE-2026-58647 Microsoft PowerBI Report Server Spoofing VulnerabilityCorrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.MSRC.MICROSOFT.COM
19 AugCVE-2026-65811 Power BI Remote Code Execution VulnerabilityCorrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.MSRC.MICROSOFT.COM
19 Aug KEVCVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler GatewayOverview On August 19, 2026, a security advisory was published for CVE-2026-19490 , a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3 and can be exploited remotely by an una…RAPID7.COM
19 AugVU#874418: RDK-B WebUI contains multiple vulnerabilitiesOverview RDK Central RDK-B WebUI version, rdkb-2025q4-kirkstone, contains multiple vulnerabilities involving memory corruption, improper authentication, race conditions, and insufficient input validation. An attacker with network access to an affected WebUI may be able to bypass …KB.CERT.ORG
18 AugCritical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public ProjectsGitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. T…THEHACKERNEWS.COM
18 AugGitLab Patches Critical Unauthenticated GraphQL VulnerabilityGitLab patched a critical GraphQL flaw that let unauthenticated attackers remotely modify or delete public projects on self-managed servers. GitLab pushed out an emergency patch this week to address a critical flaw, tracked as CVE-2026-19478 (CVSS score of 9.4), that could let an…SECURITYAFFAIRS.COM
18 Aug300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin FlawTracked as CVE-2026-15748, the arbitrary file upload bug allows unauthenticated attackers to upload executable files. The post 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw appeared first on SecurityWeek .SECURITYWEEK.COM
18 AugCritical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.2 before 18.11.11, 19.0 befor…HELPNETSECURITY.COM
18 AugCVE-2026-24301 Microsoft Copilot Information Disclosure VulnerabilityImproper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.MSRC.MICROSOFT.COM
18 AugCVE-2026-47632 Azure Connected Machine Agent Elevation of Privilege VulnerabilityCorrected the affected product from **Azure Monitor Agent Metrics Extension** to **Azure Connected Machine Agent** and updated the Security Updates table. This is an informational change only.MSRC.MICROSOFT.COM
18 AugCritical GitLab flaw allows attackers to delete and modify public reposGitLab has fixed a critical vulnerability that could allow unauthenticated attackers to perform unauthorized modifications inside code repositories or to completely delete them with a single HTTP request. The patched releases also address a second high-risk cross-site request for…CSOONLINE.COM
18 AugCritical GitLab Zero-Click Flaw Poses Mitigation ChallengesA lack of technical details could make it hard for organizations running self-managed GitLab versions to detect potential exploitation of CVE-2026-19478.DARKREADING.COM
17 AugHackers exploit SharePoint bypass, Snowflake hacker's threats to researcher backfire, CISA warns schoolsCISA's Back-to-School Cyber Playbook, SharePoint Auth Bypass Exploited, and Major Ransomware & Cybercrime Arrests As students return to class, CISA released two free cybersecurity guides for K–12 leaders with limited budgets, emphasizing MFA, device protection, tested backups, an…CYBERSECURITYTODAY.LIBSYN.COM
17 AugCritical SAP Commerce Cloud Vulnerability Exploited 3 Days After DisclosureThe vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components. The post Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure appeared first on SecurityWeek .SECURITYWEEK.COM
17 AugMicrosoft working on Defender patch for ShieldBreak zero-dayMicrosoft is working on a security patch for the "ShieldBreak" zero-day vulnerability disclosed last week by security researcher "Nightmare Eclipse" and now tracked as CVE-2026-69414. [...]BLEEPINGCOMPUTER.COM
17 AugSuspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived RansomwareCybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-travers…THEHACKERNEWS.COM
17 Aug KEVAttackers exploit patched macOS Screen Sharing flaw to deploy cryptominerA recently patched security flaw in Apple macOS is being actively exploited by hackers to bypass authentication, gain root access, and install a cryptominer, the Netherlands’ National Cyber Security Centre (NCSC) warns. The vulnerability, tracked as CVE-2026-65400, , let attacker…HELPNETSECURITY.COM
17 AugCertighost and the Privilege Hiding in Your Certificate AuthorityCVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing privilege, implicit trust, and treating PKI as the Tier 0 identity infrastructure it has always been. [...]BLEEPINGCOMPUTER.COM
17 AugCVE-2026-62722 Microsoft Brokering File System Elevation of Privilege VulnerabilityCorrected the CVE description and title. This is an informational change only.MSRC.MICROSOFT.COM
17 AugForminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP UploadsA critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites. The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out of 10.…THEHACKERNEWS.COM
16 AugSecurity Affairs newsletter Round 590 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Crooks Are Buying Your Expired Do…SECURITYAFFAIRS.COM
16 AugCVE-2026-65769 Microsoft Teams iOS Information Disclosure VulnerabilityCorrected build number for the security update. This in an informational change only.MSRC.MICROSOFT.COM
15 AugmacOS Screen Sharing Flaw Exploited to Deploy Monero MinersHackers are exploiting a macOS Screen Sharing flaw to gain root access and install Monero miners on Macs with port 5900 exposed online. The Dutch National Cyber Security Centre confirmed active exploitation of a critical macOS authentication flaw, tracked as CVE-2026-65400 (CVSS …SECURITYAFFAIRS.COM
15 Aug KEVSAP Commerce Cloud CVE-2026-58231 Exploited in the WildAttackers are actively exploiting a maximum severity SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231, just days after SAP released a patch. A critical SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231 (CVSS score of 10.0), is under active exploitation just d…SECURITYAFFAIRS.COM
14 AugYou’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))Suddenly, you’re in a room. You look around - oh, you’re surrounded by other new starters at your new job. Yes, it’s Monday, and you’re being onboarded. You know the drill - it’s the typical enterprise “please don’t beLABS.WATCHTOWR.COM
14 AugCVE-2026-62777 Windows License Manager Elevation of Privilege VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
14 AugCVE-2026-68821 Windows Package Manager Elevation of Privilege VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
14 AugCVE-2026-65671 Remote Access API Elevation of Privilege VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
14 AugCVE-2026-61347 Windows Event Logging Service Information Disclosure VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
14 AugCVE-2026-59126 Windows Event Logging Service Elevation of Privilege VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
14 AugCVE-2026-62746 Win32k Information Disclosure VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
14 AugCVE-2026-40400 Windows PowerShell Remote Code Execution VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
14 AugCVE-2026-48566 Windows DWM Core Library Information Disclosure VulnerabilityThis CVE has been discovered to be an Elevation of Privilege and not an Information Disclosure. The CVE's Impact has been updated.MSRC.MICROSOFT.COM
14 AugChromium: CVE-2026-19560 Use after free in BlinkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
14 AugChromium: CVE-2026-19559 Use after free in HTMLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
14 AugChromium: CVE-2026-19558 Use after free in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
14 AugChromium: CVE-2026-19557 Use after free in TabStripThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
14 AugChromium: CVE-2026-19556 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
14 AugMetasploit Wrap Up: Lot of summer shells and fit http profilesThis wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their e…RAPID7.COM
14 Aug KEVThe Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposureTenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous offensive AI has crossed from theoretical risk to…TENABLE.COM
13 AugAttackers Exploit SharePoint Authentication Bypass After Public PoC ReleaseThreat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from w…THEHACKERNEWS.COM
13 AugSharePoint CVE-2026-55040 Comes Under Attack Following Public ExploitAttackers are exploiting SharePoint flaw CVE-2026-55040 after a public PoC was released, allowing unauthenticated users to impersonate administrators. Attackers started exploiting CVE-2026-55040 (CVSS score of 9.1), a critical SharePoint authentication bypass patched in July, wit…SECURITYAFFAIRS.COM
13 AugCritical VMware vCenter Vulnerability in Attackers’ CrosshairsTracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code. The post Critical VMware vCenter Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek .SECURITYWEEK.COM
13 AugIt took $58 to break Microsoft’s SCCM, but a patch made it harderResearchers at XM Cyber found that a standard domain user with no Microsoft SCCM privileges can chain multiple flaws to reach remote code execution, although the attack does require network access to the SCCM environment. Enterprises use Microsoft System Center Configuration Mana…CSOONLINE.COM
13 AugAttackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)Threat actors have begun exploiting a critical Microsoft SharePoint flaw following the release of proof-of-concept (PoC) exploit code by Rapid7. About CVE-2026-55040 Tracked as CVE-2026-55040, the vulnerability was patched by Microsoft as part of its July 2026 Patch Tuesday updat…HELPNETSECURITY.COM
13 AugCVE-2026-49162 Microsoft Brokering File System Elevation of Privilege VulnerabilityAdded acknowledgements. This is an informational change only.MSRC.MICROSOFT.COM
13 AugCVE-2026-61346 Windows Graphics Kernel Elevation of Privilege VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
13 AugCVE-2026-62695 Windows Storage Elevation of Privilege VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
13 AugCVE-2026-61359 Windows Storage Elevation of Privilege VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
13 AugCVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
13 AugCVE-2026-65796 Windows iSCSI Target Service Denial of Service VulnerabilityCorrected severity entries in the Affected Products table. This is an informational change only. Customers who have successfully installed the update do not need to take any further action.MSRC.MICROSOFT.COM
13 AugCVE-2026-44814 Windows DWM Core Library Information Disclosure VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
13 AugCVE-2026-45597 Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
13 AugCVE-2026-45593 Windows SDK Elevation of Privilege VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
13 AugCVE-2026-45592 Windows Internet (wininet.dll) Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
13 AugCVE-2026-50298 Windows Spaceport.sys Elevation of Privilege VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
13 AugCVE-2026-50342 Windows MIDI Service Module Elevation of Privileges VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
13 AugCVE-2026-50461 Windows NTFS Remote Code Execution VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
13 AugCVE-2026-49798 Windows Kernel Elevation of Privilege VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
13 AugCVE-2026-50383 Windows Print Spooler Information Disclosure VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
13 AugCVE-2026-50387 Windows GDI Elevation of Privilege VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
13 AugAdobe Commerce Bug Targeted Immediately After DisclosureThe first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches. The post Adobe Commerce Bug Targeted Immediately After Disclosure appeared first on SecurityWeek .SECURITYWEEK.COM
13 AugAL26-018 - Vulnerability affecting Cisco ASA and Secure Firewall Threat Defense Software Remote Access SSL VPN - CVE-2026-20349CYBER.GC.CA
13 AugCVE-2026-62688 Windows MIDI Service Module Elevation of Privileges VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
13 AugCVE-2026-62897 .NET Framework Remote Code Execution VulnerabilityRemoved Linux and macOS products from the Affected Software table. This is an informational change only.MSRC.MICROSOFT.COM
13 AugCVE-2026-62902 .NET Information Disclosure VulnerabilityRemoved Linux and macOS products from the Affected Software table. This is an informational change only.MSRC.MICROSOFT.COM
13 AugCVE-2026-70354 .NET Core Remote Code Execution VulnerabilityRemoved Linux and macOS products from the Affected Software table. This is an informational change only.MSRC.MICROSOFT.COM
13 AugCVE-2026-62871 .NET Elevation of Privilege VulnerabilityRemoved Linux and macOS products from the Affected Software table. This is an informational change only.MSRC.MICROSOFT.COM
13 AugCVE-2026-62886 .NET Elevation of Privilege VulnerabilityRemoved Linux and macOS products from the Affected Software table. This is an informational change only.MSRC.MICROSOFT.COM
13 AugCVE-2026-62898 Microsoft QUIC Information Disclosure VulnerabilityRemoved Linux and macOS products from the Affected Software table. This is an informational change only.MSRC.MICROSOFT.COM
13 AugCritical VMware vCenter RCE flaw exploited for reverse SSH accessA recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. [...]BLEEPINGCOMPUTER.COM
13 AugAdobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public DisclosureHackers began targeting a critical Adobe Commerce flaw that could let unauthenticated attackers hijack customer accounts and access private data. Hackers began targeting CVE-2026-71362 (CVSS score of 9.1), a critical Adobe Commerce flaw, shortly after its public disclosure. The v…SECURITYAFFAIRS.COM
13 AugGlobal Threat Campaign Hits Critical VMware vCenter FlawExploitation against CVE-2026–59310 began earlier this month, and patching the vulnerability may not be enough to fully mitigate the threat.DARKREADING.COM
12 AugMicrosoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active AttackMicrosoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escal…THEHACKERNEWS.COM
12 AugDefCon airplane Wi-Fi drama. GhostJacking leads to agent hijacks, AI agent hacks gymDEF CON In-Flight Wi‑Fi Hack, 400 Microsoft Patches, and AI Agent 'Ghostjacking' Delta Air Lines is investigating a brief appearance of an unauthorized Wi‑Fi network on a Las Vegas–Atlanta flight carrying DEF CON attendees after reports of a deauthentication attack, a rogue SSID …CYBERSECURITYTODAY.LIBSYN.COM
12 Aug KEVPatch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerabilityA currently exploited zero-day elevation of privilege vulnerability that needs to be patched in a Windows driver for WinSock is the highlight of the 398 fixes issued today in Microsoft’s August Patch Tuesday releases. The hole is in Windows’ Ancillary Function Driver for WinSock …CSOONLINE.COM
12 AugMetabase SQLi exploit grants attackers total accessBusiness intelligence (BI) platform provider Metabase has disclosed a zero-day SQL Injection vulnerability, warning that customers’ sensitive credentials, tokens, API keys, and other data may have been exposed. The Metabase vulnerability revealed on August 6, designated CVE-2026-…CSOONLINE.COM
12 AugCisco Patches Firewall Zero-Day Exploited for DoS AttacksCVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices. The post Cisco Patches Firewall Zero-Day Exploited for DoS Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugSAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary CodeSAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution. The vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It has been des…THEHACKERNEWS.COM
12 AugShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM AccessThe security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak. The vulnerability, rooted in Microsoft Defender for Windows, demonstrates …THEHACKERNEWS.COM
12 Aug KEVCisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoSCisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild. The high-severity flaw, tracked as CVE-2026-20349 (CVSS score: 8.6), is a case of insuf…THEHACKERNEWS.COM
12 Aug17 old software bugs that took way too long to squashIn 2021, a vulnerability was revealed in a system that lay at the foundation of modern computing. An attacker could force the system to execute arbitrary code. Shockingly, the vulnerable code was almost 54 years old — and there was no patch available, and no expectation that one …CSOONLINE.COM
12 AugShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet PatchChaotic Eclipse released a PoC for ShieldBreak, a Microsoft Defender zero-day that bypasses the CVE-2026-50656 patch and could enable SYSTEM-level code execution. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a …SECURITYAFFAIRS.COM
12 AugAttackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote AccessThreat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter s…THEHACKERNEWS.COM
12 AugMicrosoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)Microsoft’s August 2026 Patch Tuesday delivered security fixes for 400+ vulnerabilities, including one that has been exploited in zero-day attacks (CVE-2026-68820) and three that were publicly disclosed prior to the release of the patches. Vulnerabilities of note CVE-2026-6…HELPNETSECURITY.COM
12 AugAdobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic FlawsAdobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The most severe of the flaws are listed below -…THEHACKERNEWS.COM
12 AugNIST Seeks Public Input on AI-Ready NVD ModernizationThe US National Institute for Standards and Technology wants to modernize its National Vulnerability Database to embrace AI-powered vulnerability researchINFOSECURITY-MAGAZINE.COM
12 AugCVE-2026-62696 Windows Program Compatibility Assistant Service Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
12 AugCVE-2026-62747 Windows Device Association Service Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
12 AugCVE-2026-70348 Windows Management Services Denial of Service VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
12 AugCVE-2026-68815 Microsoft Excel Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
12 AugCVE-2026-50687 Windows Win32k Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
12 AugCVE-2026-58538 Windows Bluetooth Service Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
12 AugCVE-2026-50655 Microsoft Windows Media Foundation Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
12 AugCVE-2026-62913 Microsoft Exchange Server Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
12 AugCVE-2026-58643 Windows Admin Center Spoofing VulnerabilityCorrected Build Number in the Security Updates table. This is an informational change only.MSRC.MICROSOFT.COM
12 AugCVE-2026-50476 Windows Network Connections Service Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
12 AugLazarus hackers exploited Windows zero-day to target defense firmsNorth Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. [...]BLEEPINGCOMPUTER.COM
12 AugHackers exploit critical Adobe Commerce flaw to hijack customer accountsAttempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts. [...]BLEEPINGCOMPUTER.COM
12 Aug KEVResearcher creates workaround for Microsoft Defender security patchJust weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent workaround that provides system-level control to attackers once they gain any level of access. The researcher, who goes by the name Nightmare Eclipse, has b…CSOONLINE.COM
11 AugCVE-2026-64581 xfrm: fix sk_dst_cache double-free in xfrm_user_policy()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68258 drm/amdkfd: Check bounds on CRIU restore queue type and mqd sizeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68203 media: vivid: fix cleanup bugs in vivid_init()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-64653 GitHub CLI: Unescaped variable components in request URLs could allow path traversalInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68186 binfmt_misc: set have_execfd only once the interpreter is openedInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68114 drm/amdgpu/gfx12.1: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68183 firmware: stratix10-svc: fix memory leaks and list corruption bugsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68190 staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-64652 GitHub CLI: Partial token disclosure in `gh auth status` outputInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68273 drm/amdgpu: Fix context pstate override handlingInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68097 ksmbd: validate ACE size against SID sub-authoritiesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68412 wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-71497 jsoup: Cleaner may expose markup with custom raw-text elementsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-61477 Libvirt: libvirt: newline injection in network xml dns txt/srv fields allows dnsmasq config directive injectionInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68235 drm/amd/display: dce100: skip non-DP stream encoders for DP MSTInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68407 wifi: nl80211: free RNR data on MBSSID mismatchInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-71556 go-git: Worktree operations may follow symlinksInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68323 tipc: serialize udp bearer replicast list updatesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-71557 go-git: Malicious reference names may modify files outside the reference storageInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68363 wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware requestInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-65819 gopacket: Multiple layer decoders panic on crafted packets (out-of-bounds/underflow) enabling unauthenticated remote DoS via DecodingLayerParserInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68388 smb/client: handle overlapping allocated ranges in fallocateInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68288 net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOADInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68256 drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink referenceInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68242 drm/i915/gt: Fix NULL deref on sched_engine alloc failureInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68252 drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68374 usb: core: sysfs: add lock to bos_descriptors_read()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68353 wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handlerInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68187 exec: fix unsigned loop counter wrap in transfer_args_to_stack()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68411 wifi: mac80211_hwsim: clamp virtio RX length before skb_putInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68152 amt: fix use-after-free in AMT delayed worksInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68189 Bluetooth: hci_sync: Protect UUID list traversalInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68351 wifi: carl9170: bound memcpy length in cmd callback to prevent OOB readInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68136 net: gro: fix double aggregation of flush-marked skbsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68083 ksmbd: fix path resolution in ksmbd_vfs_kern_path_createInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68352 wifi: ath6kl: fix OOB read from firmware IE lengths in connect eventInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68254 drm/i915/vrr: require valid min/max vfreq for VRRInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68238 drm/amdgpu: Release VFCT ACPI table referenceInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68241 drm/i915/mst: limit DP MST ESI service loopInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68362 wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_beginInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68315 sctp: validate stream count in sctp_process_strreset_inreq()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-15534 Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatchInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68272 drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68197 wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-operInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68148 fscrypt: Add missing superblock check in find_or_insert_direct_key()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68249 drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68155 libceph: Reject monmaps advertising zero monitorsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68397 net/iucv: take a reference on the socket found in afiucv_hs_rcv()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68312 cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain pathsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-72522 libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68130 ksmbd: defer destroy_previous_session() until after NTLM authenticationInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68350 wifi: carl9170: fix OOB read from off-by-two in TX status handlerInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68337 bpf: Reject redirect helpers without a bpf_net_contextInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68395 ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registeredInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68297 tipc: fix u16 MTU truncation in media and bearer MTU validationInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68141 net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68371 usb: musb: omap2430: Do not put borrowed of_node in probeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68110 drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68206 media: v4l2-ctrls: validate HEVC active reference countsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68195 wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio busesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68143 net: slip: serialize receive against buffer reallocationInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68111 drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68355 wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68125 mac802154: llsec: reject frames shorter than the authentication tagInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68176 tracing: Fix mmiotrace possible NULL dereferencing of hiter->devInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68234 drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reservedInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68366 usb: gadget: uvc: clamp SEND_RESPONSE length to the response bufferInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68145 iomap: fix out-of-bounds bitmap_set() with zero-length rangeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68278 drm/dp/mst: fix buffer overflows in sideband chunk accumulationInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68405 wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lockInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68255 drm/virtio: bound EDID block reads to the response bufferInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68100 ksmbd: validate num_subauth when copying ACE in set_ntacl_daclInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68277 drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsersInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68115 drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68414 wifi: cfg80211: cancel sched scan results work on unregisterInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68158 libceph: Fix multiplication overflow in decode_new_up_state_weight()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68318 pds_core: fix use-after-free on workqueue during removeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68222 media: msi2500: Return queued buffers on start_streaming() failureInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68413 wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68182 comedi: comedi_parport: deal with premature interruptInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68280 drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68428 KVM: x86/mmu: Fix use-after-free on vendor module reloadInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68331 dpaa2-eth: put MAC endpoint device on disconnectInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68231 media: airspy: Return queued buffers on start_streaming() failureInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68131 rbd: Reset positive result codes to zero in object map update pathInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68118 tcp: challenge ACK for non-exact RST in SYN-RECEIVEDInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68129 gve: fix Rx queue stall on alloc failureInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68112 drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68175 tracing: Fix resource leak on mmiotrace trace_pipe closeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68156 libceph: refresh auth->authorizer_buf{,_len} after authorizer updateInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68217 media: pwc: Drain fill_buf on start_streaming() failureInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68123 openvswitch: fix GSO userspace truncation underflowInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68218 media: pci: dm1105: Free allocated workqueueInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68250 drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68422 btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68404 wifi: cfg80211: use wiphy work for socket owner autodisconnectInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68284 bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68408 wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlockInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68165 mm/damon/core: validate ranges in damon_set_regions()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68369 usb: gadget: printer: fix infinite loop in printer_read()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68137 net/x25: fix use-after-free in x25_kill_by_neigh()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68406 wifi: cfg80211: validate PMSR FTM preamble rangeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68364 drm/amd/display: Fix ISM dc_lock deadlock during suspendInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68317 pds_core: fix auxiliary device add/del racesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68202 ALSA: seq: close a re-opened queue timer in the destructorInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68154 libceph: reject zero bucket types in crush_decodeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68417 RDMA/siw: publish QP after initializationInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68223 media: meson: vdec: Fix memory leak in error path of vdec_openInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68303 drm/vc4: hvs/v3d: Fix null dereference in unbindInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68199 wifi: ath6kl: fix OOB access from firmware ADDBA window sizeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68320 sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkidInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68109 drm/amdgpu/sdma7.1: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68336 bonding: fix devconf_all NULL dereference when IPv6 is disabledInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68300 sctp: auth: verify auth requirement when auth_chunk is NULLInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68192 wifi: brcmfmac: make release_scratchbuffers idempotentInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68116 vxlan: mdb: Fix source list corruption on a failed replaceInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68257 drm/amdkfd: fix 32-bit overflow in CWSR total size calculationInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68419 RDMA/irdma: Prevent rereg_mr for non-mem regionsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68099 ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACLInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68426 xfrm: fix stale skb->prev after async crypto steals a GSO segmentInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68157 libceph: guard missing CRUSH type name lookupInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68425 IB/mad: Drop unmatched RMPP responses before reassemblyInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68354 firewire: net: Fix fragmented datagram reassemblyInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68180 intel_th: fix MSC output device reference leakInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68392 Bluetooth: mgmt: fix locking in unpair_device/disconnect_syncInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68409 wifi: mac80211: defer link RX stats percpu free to RCUInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68279 drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsersInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68357 watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68113 drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68309 wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68368 usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68402 wifi: cfg80211: bound element ID read when checking non-inheritanceInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68310 wifi: mt76: mt7915: guard HE capability lookupsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68367 usb: gadget: f_tcm: synchronize delayed set_alt with teardownInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68386 bpf, sockmap: Reject unhashed UDP sockets on sockmap updateInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68140 net/iucv: fix use-after-free of a severed iucv_pathInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68219 media: nxp: imx8-isi: Fix potential out-of-bounds issuesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68329 iommu/amd: Wait for completion instead of returning early in iommu_completion_wait()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68396 scsi: core: wake eh reliably when using scsi_schedule_ehInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68248 drm/i915: Return NULL on error in active_instanceInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68246 drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68376 sctp: fix auth_hmacs array size in struct sctp_cookieInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68269 drm/i915/gem: Add missing nospec on parallel submit slotInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68349 wifi: carl9170: fix buffer overflow in rx_stream failover pathInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68301 net: hsr: fix memory leak on slave unregistration by removing synced VLANsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68135 net: hip04: fix RX buffer leak on build_skb failureInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68326 wifi: mwifiex: bound uAP association event IEs to the event bufferInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68117 tipc: clear sock->sk on the failed-insert path in tipc_sk_create()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68106 drm/amdgpu: fix division by zero with invalid uvd dimensionsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68294 net: qrtr: restrict socket creation to the initial network namespaceInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68293 net/mlx5: Fix MCIA register buffer overflow on 32 dword readsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68149 fs: preserve ACL_DONT_CACHE state in forget_cached_acl()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68151 binfmt_elf_fdpic: only honour the first PT_INTERPInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68335 rds: drop incoming messages that cross network namespace boundariesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68410 wifi: libertas: fix memory leak in helper_firmware_cb()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68212 media: saa7134: Fix a possible memory leak in saa7134_video_init1Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68418 RDMA/irdma: Prevent user-triggered null deref on QP createInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68361 hwmon: (corsair-psu) Stop device IO before calling hid_hw_stopInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68090 debugobjects: Plug race against a concurrent OOM disableInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68126 mac802154: hold an interface reference across the scan workerInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68416 mtd: fix double free and WARN_ON in add_mtd_device() error pathsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68247 drm/i915/bios: range check LFP Data Block panel_type2Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68245 drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68377 net/sched: act_tunnel_key: Defer dst_release to RCU callbackInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68103 drm/amdgpu: reject mapping a reserved doorbell to a new queueInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68147 fscrypt: Avoid dynamic allocation in fscrypt_get_devices()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68381 ksmbd: pin conn during async oplock break notificationInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68343 smb: client: validate DFS referral PathConsumedInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68184 cdrom: fix stack out-of-bounds read in CDROMVOLCTRLInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68124 mctp: serial: handle zero-length frames to prevent rx buffer overflowInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68146 ftrace: Add global mutex to serialize trace_parser accessInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68401 firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68322 rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabledInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68373 wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68214 media: rtl2832: fix use-after-free in rtl2832_remove()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68327 wan: wanxl: Only reset hardware after BAR mappingInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68188 Bluetooth: RFCOMM: Fix session UAF in set_termiosInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68360 hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stopInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68271 drm/nouveau: fix reversed error cleanup order in ucopy functionsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68162 sctp: avoid auth_enable sysctl UAF during netns teardownInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68229 media: cedrus: skip invalid H.264 reference list entriesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68359 hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stopInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68313 tipc: fix infinite loop in __tipc_nl_compat_dumpitInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68324 iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68121 pppoe: reload header pointer after dev_hard_header()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68132 super: fix emergency thaw deadlock on frozen block devicesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68209 media: sun4i-csi: Return queued buffers on start_streaming() failureInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-20348 ClamAV XAR File Format Processing Memory Corruption VulnerabilityInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68325 iommu/amd: Bound the early ACPI HID mapInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68085 Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceledInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68196 wifi: wilc1000: validate assoc response length before subtracting headerInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68370 usb: gadget: dummy_hcd: prevent fifo_req reuse during givebackInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68233 drm/vc4: Shut down BO cache timer before teardownInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-64654 GitHub CLI: Terminal escape sequence injection in multiple `gh` commandsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68304 wifi: brcmfmac: fix 802.1X-SHA256 call trace warningInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68243 drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEUInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-20339 ClamAV PESpin File Format Processing Integer Overflow VulnerabilityInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-20338 ClamAV ZIP File Format Processing Memory Corruption VulnerabilityInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-20347 ClamAV Mach-O File Format Processing Memory Corruption VulnerabilityInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-20337 ClamAV ZIP File Format Processing Memory Corruption VulnerabilityInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-20346 ClamAV PDF File Format Processing Memory Corruption VulnerabilityInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-64563 rhashtable: clear stale iter->p on table restartInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-64655 GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacters in SAN MatchingInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68098 ksmbd: bound DACL dedup walk to copied ACEsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68104 drm/amdgpu: invoke pm_genpd_remove() before freeing genpdInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68210 media: stm32: dcmi: unregister notifier on probe failureInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68399 bpf: Fix UAF in sock clone early bailoutsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68127 ila: reload IPv6 header after pskb_may_pull in checksum adjustInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68244 drm/i915/gem: Do not leak siblings[] on proto context errorInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68171 arm64: syscall: Ensure saved x0 is kept in-sync with tracer updatesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68289 tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68181 mei: bus: access mei_device under device_lock on cleanupInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68348 ASoC: tas2781: bound firmware description string parsingInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68308 wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68365 USB: serial: io_edgeport: cap received transmit creditsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68391 Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmdsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68302 amt: re-read skb header pointers after every pullInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68286 drop_monitor: perform u64_stats updates under IRQ-disabled sectionInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68333 dpaa2-switch: put MAC endpoint device on disconnectInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68427 gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappingsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-66485 Uncontrolled Memory Allocation in GNU cpioInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68161 sctp: close UDP tunnel sockets during netns teardownInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68306 wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68338 net/packet: avoid fanout hook re-registration after unregisterInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68185 LoongArch: Move jump_label_init() before parse_early_param()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68096 audit: fix recursive locking deadlock in audit_dupe_exe()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68287 drop_monitor: fix size calculations for 64-bit attributesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68403 wifi: brcmfmac: initialize SDIO data work before cleanupInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68220 media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68389 Bluetooth: hci_qca: Clear memdump state on invalid dump sizeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68166 userfaultfd: prevent registration of special VMAsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68198 wifi: ath6kl: fix use-after-free in aggr_reset_state()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68398 ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAFInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68194 wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio busesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68215 media: radio-si476x: Unregister v4l2_device on probe failureInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68091 HID: wacom: stop hardware after post-start probe failuresInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68159 libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZEInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68138 net/sched: serialize qdisc_rtab_list against concurrent get/putInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68299 vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packetsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68205 media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68259 drm/amdkfd: Check bounds in allocate_event_notification_slotInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68207 media: ti: vpe: unwind v4l2 device registration on probe errorInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68088 usb: gadget: function: rndis: add length check to response queryInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68108 drm/amdgpu/vce: fix integer overflow in image sizeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68226 media: cx23885: add ioremap return check and cleanupInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68142 geneve: require CAP_NET_ADMIN in the device netns for changelinkInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68086 mm/khugepaged: write all dirty file folios when collapsingInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68160 ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68144 phonet: pep: fix use-after-free in pep_get_sb()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68164 mm/damon/core: disallow overlapping input ranges for damon_set_regions()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68107 drm/amdgpu/vcn4: avoid rereading IB param lengthInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68204 media: vivid: check for vb2_is_busy() when toggling capsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68236 drm/amd/display: set new_stream to NULL after releaseInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68340 hwmon: occ: validate poll response sensor blocksInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68253 drm/i915/hdcp: check streams[] bounds before overflowInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68339 Bluetooth: btusb: validate Realtek vendor event lengthInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68169 mptcp: pm: userspace: fix use-after-free in get_local_idInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68093 KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplugInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68153 libceph: remove debugfs files before client teardownInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68084 staging: vme_user: fix location monitor leak in tsi148 bridgeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-20345 ClamAV GPT File Format Processing Memory Corruption VulnerabilityInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-72568 Redis - Heap Out-of-Bounds Read in Cluster Bus PING Message HandlerInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68105 drm/amdgpu: Fix kernel panic during driver load failureInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68216 media: pwc: Return queued buffers on start_streaming() failureInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68251 drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-64523 net/handshake: Take a long-lived file reference at submitInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-64525 xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exitInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-64513 KVM: x86: Unconditionally recompute CR8 intercept on PPR updateInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-43871 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limitInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-64377 cpufreq: qcom-cpufreq-hw: Fix possible double freeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-64388 smb/client: fix chown/chgrp with SMB3 POSIX ExtensionsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-64539 Bluetooth: eir: Fix stack OOB write when prepending the Flags ADInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-54332 GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoSInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-55969 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2024-57895 ksmbd: set ATTR_CTIME flags when setting mtimeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2024-57893 ALSA: seq: oss: Fix races at processing SysEx messagesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2024-57888 workqueue: Do not warn when cancelling WQ_MEM_RECLAIM work from !WQ_MEM_RECLAIM workerInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2024-57795 RDMA/rxe: Remove the direct link to net_deviceInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2024-52005 The sideband payload is passed unfiltered to the terminal in gitInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2025-21629 net: reenable NETIF_F_IPV6_CSUM offload for BIG TCP packetsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2024-57899 wifi: mac80211: fix mbss changed flags corruption on 32 bit systemsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2025-37853 drm/amdkfd: debugfs hang_hws skip GPU with MESInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2025-37842 spi: fsl-qspi: use devm function instead of driver removeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2025-37849 KVM: arm64: Tear down vGIC on failed vCPU creationInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2025-37852 drm/amdgpu: handle amdgpu_cgs_create_device() errors in amd_powerplay_create()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2025-37879 9p/net: fix improper handling of bogus negative read/write repliesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2025-37903 drm/amd/display: Fix slab-use-after-free in hdcpInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2025-37980 block: fix resource leak in blk_register_queue() error pathInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)Overview Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapi…RAPID7.COM
11 AugRapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)Overview On July 14, 2026, Rapid7 and Microsoft disclosed CVE-2026-55040, an authentication bypass vulnerability affecting Microsoft SharePoint. Today we are publishing a technical analysis of the vulnerability along with an accompanying proof-of-concept (PoC) script . Figure 1: …RAPID7.COM
11 AugVU#431093: TCG TPM 2.0 reference code found vulnerable to information leakage and timing side-channel attacksOverview Two vulnerabilities have been identified in the Trusted Platform Module (TPM) 2.0 reference implementation: CVE-2026-6726 – Information leakage via falsified TPM keys. CVE-2026-6727 – A timing side-channel vulnerability in RSA OAEP decryption. An attacker with privileged…KB.CERT.ORG
11 AugNIST wants to overhaul its vulnerability database for the AI ageNIST is seeking public input to modernize the National Vulnerability Database to keep pace with AI-driven cyber threats and machine-scale security data. The post NIST wants to overhaul its vulnerability database for the AI age appeared first on CyberScoop .CYBERSCOOP.COM
11 AugZoom zero-click flaw allowed RCE attacks during meetingsMultiple vulnerabilities in Zoom’s annotation engine could allow a malicious meeting participant to compromise another attendee’s device by sending specially crafted meeting data. The most serious issue, tracked as CVE-2026-53413, is a buffer overwrite that Zoom says could lead t…CYBERINSIDER.COM
11 AugResearchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCESecurity researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects Shar…THEHACKERNEWS.COM
11 Aug KEVMicrosoft's August 2026 Patch Tuesday Addresses 398 CVEs (CVE-2026-68820)42 Critical 355 Important 1 Moderate 0 Low Microsoft addresses 398 CVEs in the eighth Patch Tuesday of 2026, with three zero-days, including one that was exploited in the wild. Microsoft patched 398 CVEs in its August 2026 Patch Tuesday release, with 42 rated critical, 355 rated …TENABLE.COM
11 AugZoom Patches “Zoomsday” Zero-Click Flaw Enabling Remote Code ExecutionZoom patches a zero-click flaw that could let a meeting participant execute code on another user’s computer through the annotation feature. Zoom has patched four vulnerabilities, including a critical zero-click flaw, tracked as CVE-2026-53413, in its annotation feature. CVE-2026-…SECURITYAFFAIRS.COM
11 AugCVE-2026-19137 Use after free in WebGLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19140 Use after free in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19138 Heap buffer overflow in CrashReportingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19139 Race in CredentialProviderThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19145 Use after free in TranslateThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19142 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19144 Use after free in HTMLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19146 Uninitialized Use in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19147 Use after free in AuraThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19149 Use after free in AuraThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19148 Out of bounds write in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19151 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19153 Insufficient validation of untrusted input in WorkersThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19152 Inappropriate implementation in NavigationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19155 Use after free in PaymentsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19158 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19157 Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19156 Heap buffer overflow in BaseThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19150 Inappropriate implementation in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19161 Uninitialized Use in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19162 Out of bounds write in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19160 Uninitialized Use in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19163 Use after free in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19159 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19164 Insufficient validation of untrusted input in CodecsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19165 Use after free in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19167 Integer overflow in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19166 Use after free in Web AuthenticationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19170 Use after free in WebGLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19169 Insufficient validation of untrusted input in Contextual TasksThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19173 Out of bounds write in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19172 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19168 Inappropriate implementation in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19174 Integer overflow in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19176 Use after free in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19171 Use after free in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19175 Use after free in PaymentsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19177 Insufficient validation of untrusted input in UIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugZoom zero-click RCE flaws allow attackers to compromise meeting participantsZoom has fixed four vulnerabilities across its applications, including two that could allow attackers who join a meeting to execute malicious code on the systems of all other meeting participants with no interaction required from them. Three of the vulnerabilities affect all Zoom…CSOONLINE.COM
10 AugAI writes patches that don't work, WordPress login takeover, Researchers hijack 36 million kids' GPS trackersAI Patch Development Fails, WordPress Login XSS Hits All Versions, and DEF CON's Biggest Security Lessons David Shipley covers new research from 1Password's Off By One Labs showing AI-generated vulnerability patches often fail: across 6,080 scored patches for six CVEs, only 26% f…CYBERSECURITYTODAY.LIBSYN.COM
10 AugN-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577To help customers fend off ongoing attacks, N-able released a second security hotfix for N‑central, its monitoring and management (RMM) solution popular with managed service providers (MSPs). “Hotfix 2 is required, even if you already applied the earlier hotfix. Hotfix 2 su…HELPNETSECURITY.COM
10 AugCVE-2021-34474 Microsoft Dynamics 365 Business Central Remote Code Execution VulnerabilityUpdated the build numbers. This is an informational update only.MSRC.MICROSOFT.COM
10 AugCVE-2026-50309 Windows NTFS Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
10 AugVU#614868: Opencart ecommerce platform contains directory traversal vulnerabilityOverview The OpenCart v4.2.0.0 extension installer contains a directory traversal vulnerability. The extension installation process extracts uploaded .zip files then uses the zip entry filenames as filesystem paths, without validating that the resolved path stays inside the inten…KB.CERT.ORG
10 AugCVE-2021-40440 Microsoft Dynamics Business Central Cross-site Scripting VulnerabilityUpdated the build numbers. This is an informational update only.MSRC.MICROSOFT.COM
10 AugCVE-2021-36946 Microsoft Dynamics Business Central Cross-site Scripting VulnerabilityUpdated the build numbers. This is an informational update only.MSRC.MICROSOFT.COM
10 AugNATO and an AI startup can now name and track software vulnerabilitiesNATO’s cyber defense arm and a startup that uses artificial intelligence to find software flaws can now issue the ID numbers the industry uses to track those flaws, the European Union Agency for Cybersecurity announced last week. The NATO Cyber Security Centre, part o…CYBERSCOOP.COM
9 AugCVE-2026-64572 ipv4: fib: free fib_alias with kfree_rcu() on insert error pathInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64569 mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=nInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64567 btrfs: reject free space cache with more entries than pagesInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64577 gtp: check skb_pull_data() return in gtp1u_send_echo_resp()Information published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64561 KVM: x86: Check for invalid/obsolete root *after* making MMU pages availableInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64564 sctp: don't free the ASCONF's own transport in DEL-IP processingInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64562 KVM: nVMX: Hide shadow VMCS right after VMCLEARInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-18839 Popt-devel: popt-static: size_t underflow in singleoptionhelpInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64590 dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warningInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64583 usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardownInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64584 usb: gadget: f_midi: cancel pending IN work before freeing the midi objectInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64571 wifi: p54: validate RX frame length in p54_rx_eeprom_readback()Information published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64576 nexthop: initialize extack in nh_res_bucket_migrate()Information published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64676 Kata Containers: Unauthorized mem-agent ttRPC methods let an untrusted host tamper with confidential-guest memoryInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-47243 Kata guest escape: runtime-rs guest-root to host-root escape via virtiofsInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2025-49506 Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attackInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-34191 Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracleInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-34501 Apache Portable Runtime Utility: Heap buffer overflow in APR redis clientInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-34502 Apache Portable Runtime Utility: Heap buffer overflow in APR memcached clientInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-68081 KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest stateInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-68082 libceph: fix two unsafe bare decodes in decode_lockers()Information published.MSRC.MICROSOFT.COM
9 AugCVE-2026-54876 Client-Side Memory Leak in OCSP Response CheckingInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-71225 Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundariesInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-71226 Libkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot aio pathInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-71227 Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout returnInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-44605 Rpm: heap buffer overflow in ndb slot table parsingInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64574 wifi: mac80211: tear down new links on vif update error pathInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64573 Bluetooth: qca: fix NVM tag length underflow in TLV parserInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64565 Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()Information published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64604 KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest modeInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64578 ksmbd: validate compound request size before reading StructureSize2Information published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64579 xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsertInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64580 xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()Information published.MSRC.MICROSOFT.COM
9 AugCVE-2026-50540 Kata Containers: Config Path Annotation Arbitrary File LoadingInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64560 posix-cpu-timers: Prevent UAF caused by non-leader exec() raceInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64542 ipv6: ndisc: fix NULL deref in accept_untracked_na()Information published.MSRC.MICROSOFT.COM
8 AugCVE-2026-63030 and CVE-2026-60137: 'wp2shell' Captured Exploit PayloadSensor Intel Series: August 2026 CVE TrendsF5.COM
8 AugCVE-2025-62725 Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer AnnotationsInformation published.MSRC.MICROSOFT.COM
8 AugCVE-2026-68480 x86/bugs: Make Safe-RET robust against interrupt injectionInformation published.MSRC.MICROSOFT.COM
8 AugCVE-2026-55995 Double-free in the iSNS attribute decoder in open-iscsiInformation published.MSRC.MICROSOFT.COM
8 AugCVE-2026-44943 remote limited file-write as root via discovery in open-iscsiInformation published.MSRC.MICROSOFT.COM
8 AugCVE-2026-44944 iscsiuio control-socket authentication bypass in open-iscsiInformation published.MSRC.MICROSOFT.COM
8 AugCVE-2026-6879 Quadratic Behavior in xml.etree.ElementPath Index PredicatesInformation published.MSRC.MICROSOFT.COM
8 AugCVE-2026-32597 PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)Information published.MSRC.MICROSOFT.COM
8 AugCVE-2026-48524 PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)Information published.MSRC.MICROSOFT.COM
7 AugHuman oversight is still critical as AI patching tools miss security risksAI-generated vulnerability patches still heavily depend on human review, particularly the ones involving security-sensitive code, according to a research. Researchers from 1Password have disclosed an internal evaluation that found AI-generated fixes frequently overlook broader co…CSOONLINE.COM
7 AugNew WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAPWordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server. Tracked as CVE-2026-…THEHACKERNEWS.COM
7 AugVU#987105: The nothings stb TrueType library, up to version 1.26, contains a heap buffer overflow vulnerabilityOverview A heap buffer overflow vulnerability exists in the stb TrueType library created by nothings. Exploitation of this vulnerability can occur when handling malformed font data and may lead to both Denial of Service (DoS) and Information Disclosure. Description The nothings s…KB.CERT.ORG
7 Aug KEVRapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)Overview On July 27, 2026, JetBrains published a security advisory for CVE-2026-63077 , a critical unsafe deserialization vulnerability affecting JetBrains TeamCity . An attacker who can reach a TeamCity server over HTTP or HTTPS can exploit the agent polling protocol without cre…RAPID7.COM
6 AugHackers Start Exploiting Recent JetBrains TeamCity VulnerabilityTracked as CVE-2026-63077, the critical bug can be exploited without authentication for remote code execution. The post Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
6 AugCISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the WildA newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The vulnerability in question is CVE-2026-63077 (CVSS score: 9.8), a ca…THEHACKERNEWS.COM
6 AugCritical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200)Cisco has fixed a critical vulnerability (CVE-2026-20200) in its Integrated Management Controller (IMC), which allows an attacker to run commands as root through the controller’s web interface. The fix was part of Cisco’s August 5 advisory batch, and unlike the bugs s…HELPNETSECURITY.COM
6 AugAutonomy is earned, not claimedAfter more than 300,000 production penetration tests (pentests), our company has learned something that may surprise people watching the recent wave of autonomous security announcements. The hardest problem in autonomous security isn’t teaching a machine how to attack. It’s teach…CSOONLINE.COM
6 AugChinese Zbtlink WiFi routers ship with ENDLESSDOORS malwareAt least 20 Zbtlink router models contain a preinstalled remote-access implant that connects to external command-and-control servers and can execute arbitrary commands with root privileges. The issue, tracked as CVE-2026-66747, does not require attackers to compromise the router …CYBERINSIDER.COM
6 AugTails emergency update fixes flaws that could deanonymize usersThe Tails Project has released Tails 7.10.1 as an emergency security update addressing critical vulnerabilities that could allow attackers to obtain administrator privileges, take control of the operating system, and potentially deanonymize users. Released on August 5, 2026, the …CYBERINSIDER.COM
6 AugNew Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux HostsZapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked…THEHACKERNEWS.COM
6 AugNatJack exploits put NAT security assumptions to the test at Black HatFor decades, Network Address Translation (NAT) has been the default way IP addresses are provided inside larger networks, as a means to deal with the challenges of IPv4 address availability. The basic premise behind NAT is that private addresses stay private, but that assumption …CSOONLINE.COM
6 Aug KEVVU#487613: Alinto SOGo v5.12.7 vulnerable to cross-site scripting via malformed ICS calendar invitationsOverview A cross-site scripting (XSS) vulnerability in Alinto SOGo v5.12.7 allows attackers to achieve remote code execution by embedding malicious SVG (Scalable Vector Graphics) objects in ICS (iCalendar) invitations. The vulnerability has been actively exploited in the wild, as…KB.CERT.ORG
5 AugRuby on Rails critical bug puts every image upload under scrutinyA new critical vulnerability in the Ruby on Rails (“Rails”) web application framework, CVE-2026-66066 , could turn a seemingly innocuous image into a front door to your secrets. Disclosed July 30, the high severity CVE (scored 9.5 out of 10) poses a significant risk to enterprise…CSOONLINE.COM
5 Aug KEVCISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively ExploitedThe U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The list of vulnerabilities is as follows - CVE-2026-9198 (CVSS score: …THEHACKERNEWS.COM
5 AugCritical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode MarkupAn unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Org-mode markup are enough. The flaw is fixed in Gitea 1.2…THEHACKERNEWS.COM
5 AugCritical Paperclip bugs expose AI agent trust failuresSecurity researchers are warning against trust assumptions in AI security with newly detailed flaws affecting the open-source AI agent platform Paperclip that could be chained into remote code execution (RCE), data exposure, and developer-machine compromise. An Oasis Security res…CSOONLINE.COM
5 AugNew OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitchA memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel builds. The vulnerability, tracked as CVE-20…THEHACKERNEWS.COM
5 AugOVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become RootOVSwrap is a 13-year-old Linux kernel flaw that lets local users gain root privileges on most distributions using Open vSwitch. Security researcher Asim Manizada disclosed OVSwrap (CVE-2026-64531, CVSS score of 7.8), a local privilege escalation vulnerability in the Linux kernel&…SECURITYAFFAIRS.COM
5 AugPre-auth RCE in enterprise Java hits Bonita and OFBiz serversAn attacker sends a single web request to a Bonita server and lands inside an internal API that assumed nobody could reach it. The request arrives unauthenticated. From there the attacker runs code on the host. Bonita BPM handles loan approvals, insurance claims, and employee onb…HELPNETSECURITY.COM
4 AugNew cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database RootcPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity. It shipped in a targeted security release that closes two o…THEHACKERNEWS.COM
4 AugCVE-2026-58048: cPanel Bug Enables Full Database Administrator AccessA critical cPanel flaw (CVE-2026-58048) lets authenticated users execute SQL as root. Users should update to fixed versions immediately. If you run a shared hosting box, this one’s worth reading before your morning coffee gets cold. cPanel just patched a flaw, tracked as CV…SECURITYAFFAIRS.COM
3 AugRuby on Rails Patches Critical Active Storage Vulnerability Affecting Image ProcessingRuby on Rails fixed a critical vulnerability that could let unauthenticated attackers read files and achieve remote code execution. Ruby on Rails has patched CVE-2026-66066, a critical vulnerability (CVSS score of 9.5) that could allow unauthenticated attackers to read arbitrary …SECURITYAFFAIRS.COM
3 AugN-able Says Attackers Take Over N-central Servers After Initial Fix Proves IncompleteN-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers. Its first fix was incomplete. CVE-2026-18577 affects N-central builds prior to 2026.3.1.7. N-able shipped build…THEHACKERNEWS.COM
3 AugThermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly UndetectableThermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them. The vendor's July 31 security bulletin says nearly undetectable changes to .fsa and .hid outputs c…THEHACKERNEWS.COM
3 AugKindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)A critical security vulnerability (CVE-2026-66066) in Ruby on Rails (aka Rails), one of the most widely used frameworks for building websites and web apps, may allow attackers to read sensitive files off a server and, in some cases, take full control of it. Nicknamed “Kinda…HELPNETSECURITY.COM
3 Aug KEVN‑able Patches Vulnerability Exploited to Hack N-central ServersThe N‑central vulnerability CVE-2026-18577 has been exploited in the wild after threat actors found a patch bypass. The post N‑able Patches Vulnerability Exploited to Hack N-central Servers appeared first on SecurityWeek .SECURITYWEEK.COM
3 AugAttackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577)Attackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) in N-able N-central, a remote monitoring and management (RMM) solution widely used by managed service providers, to gain access to managed endpoints. How the flaw was discovered “On July 31, 20…HELPNETSECURITY.COM
3 AugN-able warns of N-central auth bypass flaw exploited in attacksN-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers. [...]BLEEPINGCOMPUTER.COM
3 AugRapid7 Analysis: KindaRails2Shell (CVE-2026-66066)Overview On July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066 , an arbitrary file read in Active Storage applications that use the Vips image processor with untrusted uploads. The affected Active Storage ranges are < 7.2.3.2 , >= 8.0,…RAPID7.COM
3 AugAttackers Exploit N-able Patch Bypass Flaw on RMM ServersOver the weekend, the vendor discovered another vector of authentication bypass CVE-2026-18577 that gives attackers administrator access.DARKREADING.COM
1 AugAdobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User InteractionAdobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score o…THEHACKERNEWS.COM
1 AugAdobe fixed a maximum-severity vulnerability flaw in Campaign ClassicAdobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enter…SECURITYAFFAIRS.COM
31 JulOpenAI's rogue agent hit more victims, attackers hit 30 Minnesota water systems, Russian crew delivers weaponized e-mails in ExchangeOpenAI 'Rogue Agent' Fallout, Minnesota Water Systems Hit, Exchange OWA Zero-Click Mailbox Takeover David Shipley covers multiple security stories: the OpenAI "rogue agent" incident expands as Modal Labs says a customer's exposed endpoint was used as a launchpad in attacks on Hug…CYBERSECURITYTODAY.LIBSYN.COM
31 JulCritical Code Execution Vulnerability Patched in TeamCityTracked as CVE-2026-63077, the security defect can be exploited without authentication via the agent polling protocol. The post Critical Code Execution Vulnerability Patched in TeamCity appeared first on SecurityWeek .SECURITYWEEK.COM
31 JulJetBrains says a crafted HTTP request could break TeamCityJetBrains is warning of a critical security vulnerability in its TeamCity DevOps platform that could allow unauthenticated attackers to execute arbitrary operating system commands on vulnerable servers. “If exploited, this vulnerability may allow an unauthenticated attacker with …CSOONLINE.COM
31 JulBroadcom patches vulnerabilities all over VMwareBroadcom has addresses five vulnerabilities in its VMware product range, three of which have been accorded a “critical” rating. The affected products are: VMware ESX, VMware vCenter, VMware Workstation, VMware Fusion, VMware Cloud Foundation, VMware vSphere Foundation, VMware Tel…CSOONLINE.COM
31 JulVU#243636: VPS.org one-click deployment templates contain multiple vulnerabilitiesOverview VPS.org's one-click deployment templates provision services with default passwords and predefined network bindings instead of generating randomized secrets or applying per-deployment hardening measures. Description VPS.org is a cloud and virtual private server hosting pr…KB.CERT.ORG
30 Jul KEVCisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive DataThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation. T…THEHACKERNEWS.COM
30 Jul KEVCisco Secure FMC Zero-Day Exploited in the WildThe vulnerability tracked as CVE-2026-20316 can be exploited by a remote, unauthenticated attacker to log into affected devices. The post Cisco Secure FMC Zero-Day Exploited in the Wild appeared first on SecurityWeek .SECURITYWEEK.COM
30 JulRussian hackers turn Exchange flaw into ‘half-click’ mailbox takeoverA Russia-aligned threat group used a “half-click” exploit against Microsoft Exchange’s Outlook Web Access to install a browser-based backdoor when recipients opened specially crafted emails. The campaign began on July 22 and was conducted by TA488, which is also tracked as Void B…CSOONLINE.COM
30 JulCisco FMC static credentials exploited by attackers (CVE-2026-20316)A static credentials vulnerability (CVE-2026-20316) in Cisco Secure Firewall Management Center (FMC), a platform for centrally managing multiple Cisco Secure Firewall devices across a network, is being leveraged by attackers, CISA warned. Two FMC flaws, one indicator of compromis…HELPNETSECURITY.COM
30 Jul KEVCritical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)Overview On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-20…RAPID7.COM
30 JulCVE-2026-56197 Windows Admin Center (WAC) Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
30 JulCVE-2026-54128 Windows DHCP Client Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
30 JulCritical Ruflo flaw lets attackers hijack AI agents through exposed MCP bridgeA critical vulnerability in the open-source AI agent platform Ruflo could allow unauthenticated attackers to take control of enterprise AI environments by exploiting an exposed Model Context Protocol (MCP) bridge, according to research published by Noma Security. The flaw, tracke…CSOONLINE.COM
30 JulLaundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)Russia-affiliated cyber espionage group Laundry Bear (aka Void Blizzard, aka TA488) is exploiting CVE-2026-42897, a cross-site scripting vulnerability in Microsoft Exchange, to target US and European government entities and a variety of private sector organizations via email. The…HELPNETSECURITY.COM
30 JulVU#790363: foreUP golf management platform's web API contains multiple vulnerabilitiesOverview Two vulnerabilities in the REST API were found in Golf Compete foreUP. The first exposes the merchant, Finix, API credentials directly in customer record responses, allowing any user to obtain and use the payment processor account. The second is a missing object-level au…KB.CERT.ORG
30 JulKindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on RailsOverview On July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066 , a critical vulnerability affecting Active Storage image processing when used in conjunction with the libvips image processing library. The vulnerability has a CVSSv4 score of 9…RAPID7.COM
30 JulVU#281278: SGLang contains six different vulnerabilities including RCE, data exfiltration, and credential disclosureOverview Six vulnerabilities have been discovered within the SGLang project, including remote code execution (RCE), server-side request forgery (SSRF), local file read, credential leakage, and model weight exfiltration on a target server. Exploitation does not require authenticat…KB.CERT.ORG
29 JulA 13-year-old flaw is exposing tens of thousands of data center management systemsThe ‘no man’s land’ beneath the OS on enterprise servers is becoming the malicious actors’ next target. Attackers are gaining a foothold into broader data center environments by exploiting Baseboard Management Controllers (BMCs) that are largely unprotected, still running decades…CSOONLINE.COM
29 JulRansomware report: VPNs in the crosshairs, AI attacksRansomware attacks were up year over year in June for the fourth consecutive month, according to the NCC Group, though attacks increased just 3% in Q2 2026 versus the previous quarter. VPNs and other network edge devices continue to be prime initial access targets. And an autonom…CSOONLINE.COM
29 JulPublic PoC Released for Exploited Check Point SmartConsole Authentication BypassCybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild. The vulnerabi…THEHACKERNEWS.COM
29 JulNew Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell CommandsGitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account. Tracked as CVE-2026-6…THEHACKERNEWS.COM
29 JulContrast CVE Shield aims to protect applications while security teams deploy patchesContrast Security has announced Contrast CVE Shield, designed to help organisations defend against the growing number of exploits generated with advanced AI models such as Claude Mythos. Contrast CVE Shield runs inside the application, where it detects, monitors and blocks attemp…HELPNETSECURITY.COM
29 JulResearchers Show a Single Malicious Webpage Visit Can Compromise Tor BrowserNebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High…THEHACKERNEWS.COM
29 JulBroadcom Patches Critical VMware ESXi Vulnerability Enabling Host Code ExecutionBroadcom patched a critical VMware ESXi VM escape flaw (CVE-2026-47876) that could let attackers run code on the host from a compromised virtual machine. Broadcom has released patches to address five vulnerabilities affecting VMware ESXi, vCenter, Workstation, and Fusion, includi…SECURITYAFFAIRS.COM
29 JulRuflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI MemoryCybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10…THEHACKERNEWS.COM
29 JulThree Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM EscapeBroadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which ha…THEHACKERNEWS.COM
29 JulVU#305509: OPeNDAP Hyrax is vulnerable to SSRF and Credential DisclosureOverview A vulnerability has been discovered in the OPeNDAP Hyrax software solution. A remote attacker with the ability to submit crafted requests to an affected Hyrax instance could cause the application to communicate with unauthorized remote systems. Under certain conditions, …KB.CERT.ORG
29 JulCVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCityOverview On July 27, 2026, JetBrains published a security advisory for CVE-2026-63077 , a critical unauthenticated vulnerability affecting all versions of TeamCity On-Premises. The issue is classified as deserialization of untrusted data and has a CVSS score of 9.8 . An unauthent…RAPID7.COM
29 JulCritical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image UploadsRuby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process en…THEHACKERNEWS.COM
29 Jul KEVCisco warns of FMC static credential flaw exploited in zero-day attacksCisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. [...]BLEEPINGCOMPUTER.COM
28 JulAttackers Exploit Arista VeloCloud Orchestrator Command Injection FlawA maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave …THEHACKERNEWS.COM
28 JulCritical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging InJetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity …THEHACKERNEWS.COM
28 JulResearcher Says AI Helped Develop Linux Traffic-Control Race Into Root ExploitSTAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free race in the kernel's network traffic-control subsystem.Researcher Lee Ji…THEHACKERNEWS.COM
28 JulJetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)JetBrains has fixed a critical vulnerability (CVE-2026-63077) affecting TeamCity On-Premises and is urging admins to upgrade self-hosted servers as soon as possible. “For those who are unable to do so, we have released a security patch plugin,” noted Daniel Gallo, Sol…HELPNETSECURITY.COM
28 JulJetBrains Patches Critical TeamCity Flaw Allowing Server TakeoverJetBrains patched a critical TeamCity flaw (CVE-2026-63077) enabling unauthenticated code execution on affected on-premise servers. JetBrains has released security updates for TeamCity On-Premises after discovering a critical vulnerability, tracked as CVE-2026-63077 (CVSS score o…SECURITYAFFAIRS.COM
28 JulCritical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as RootOpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt's GitHub advisory, lets an unauth…THEHACKERNEWS.COM
28 JulVU#141367: AT&T's Arris BGW210-700 gateway contains authentication bypass vulnerability in LAN-side management interfaceOverview Firmware versions 2.7.7 and earlier of the Arris BGW210-700 residential gateway contain an authentication bypass vulnerability, tracked as CVE-2026-16771, that allows any unauthenticated LAN-side user to read sensitive configuration data and modify device settings throug…KB.CERT.ORG
28 JulCheck Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)Overview On July 22, 2026, Check Point published a security advisory for CVE-2026-16232 , an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server (MDS). By leveraging CVE-2026-16232, an unauthenti…RAPID7.COM
28 JulChromium: CVE-2026-13032 Use after free in WebGLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 JulChromium: CVE-2026-13028 Use after free in WebGLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 JulChromium: CVE-2026-13030 Uninitialized Use in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 JulChromium: CVE-2026-13037 Use after free in WebViewThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
27 JulCVE-2026-64530 net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handleInformation published.MSRC.MICROSOFT.COM
27 JulCVE-2026-16461 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formattingInformation published.MSRC.MICROSOFT.COM
27 JulCVE-2026-8450 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()Information published.MSRC.MICROSOFT.COM
27 JulPoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)Security researchers who discovered and reported CVE-2026-54121 (aka “Certighost”), a critical privilege elevation vulnerability in Active Directory Certificate Services (AD CS), have released a proof-of-concept (PoC) exploit for and technical details related to the f…HELPNETSECURITY.COM
27 Juln8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Processn8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while probing n8n's February fix for CVE-2026-27577 for another …THEHACKERNEWS.COM
27 JulCVE-2026-50333 Windows Spaceport.sys Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
25 JulChromium: CVE-2026-16804 Use after free in InputThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
25 JulChromium: CVE-2026-16805 Use after free in BlinkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
25 JulChromium: CVE-2026-16806 Use after free in WebMCPThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
25 JulChromium: CVE-2026-16807 Out of bounds write in CodecsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
25 JulFastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched AvailableSecurity firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process. Tracked…THEHACKERNEWS.COM
24 Jul KEVRansomware groups are hammering your vulnerable VPNsCybercriminals are actively exploiting a recently discovered vulnerability in Palo Alto Networks firewall and VPN appliances to deploy the Qilin ransomware strain. A critical authentication bypass flaw ( CVE-2026-0257 ) in Palo Alto GlobalProtect portal and gateway was the common…CSOONLINE.COM
24 JulCVE-2026-59676 Local File Deletion Attack Vector in rm_rf() in seunshareInformation published.MSRC.MICROSOFT.COM
24 JulCVE-2026-59677 Process Kill Attack Vector in killall() in seunshareInformation published.MSRC.MICROSOFT.COM
24 JulCVE-2026-64600 xfs: resample the data fork mapping after cycling ILOCKInformation published.MSRC.MICROSOFT.COM
24 JulBing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's ServersA crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's testing got the same result on workers across different hosts and network ranges, so …THEHACKERNEWS.COM
24 JulRussian hackers exploit unpatched Zimbra servers to steal emailsRussian state-backed hacker group Laundry Bear has been breaking into government and commercial networks for at least a year by exploiting a vulnerability in the Zimbra Collaboration Suite (ZCS) webmail platform. Laundry Bear (also known as Void Blizzard, CL-STA-1114, and TA488) …HELPNETSECURITY.COM
24 JulClop gang targets Windchill, FlexPLM in data theft attacksSergiu Gatlan reports: The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. Clop has reportedly been exploiting a critical improper input validation vulnerability tracked as CVE-2…DATABREACHES.NET
23 JulCheck Point Patches Exploited SmartConsole Flaw Allowing Full Admin AccessCheck Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild. The security flaw, tracked as CVE-2026-16232 (CV…THEHACKERNEWS.COM
23 JulCVE-2026-56145 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-63140 Reachable Assertion in Elasticsearch Leading to Denial of ServiceInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-63136 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-53910 Heap-based Buffer Overflow in GNU diffutilsInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-55973 'dns-error-reporting: yes' leads to stack buffer overflowInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-44687 Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAINInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-50248 BOGUS configured primary hostname accepted for XFR in auth/rpz zonesInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-55708 Privacy/configuration issue when adding local data in views through 'unbound-control'Information published.MSRC.MICROSOFT.COM
23 JulCVE-2026-44621 Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminatedInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-55717 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crashInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-32665 Remote DNS-over-QUIC denial of service due to `quic-size` budget bypassInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-46582 A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply pathInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-42955 Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue recordsInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-50046 Possible heap use-after-free in an error path when a DoT forwarded query is jostled outInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-55990 Packet of death for a DNSCrypt misconfigured UnboundInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-55991 Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2Information published.MSRC.MICROSOFT.COM
23 JulCVE-2026-50251 Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flushInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-50252 Possible cache poisoning attack by mapping source port population per threadInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-50243 'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAILInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-63308 Helm Files.Lines Denial of Service via Empty Chart FilesInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-15588 Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line bufferingInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-26080 HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.Information published.MSRC.MICROSOFT.COM
23 JulCVE-2026-26081 HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.Information published.MSRC.MICROSOFT.COM
23 JulCVE-2026-15788 WCOW cache mount source selector resolves NTFS junctions outside of cache rootInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-12080 Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keysInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-16277 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist()Information published.MSRC.MICROSOFT.COM
23 JulCVE-2026-44509 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a duplicate of CVE-2026-43619. Notes: All CVE users should reference CVE-2026-43619 instead of this candidate.Information published.MSRC.MICROSOFT.COM
23 JulCVE-2026-44508 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a duplicate of CVE-2026-43618. Notes: All CVE users should reference CVE-2026-43618 instead of this candidate.Information published.MSRC.MICROSOFT.COM
23 JulCVE-2026-54171 Excon: redact additional sensitive/risky headers when following redirectsInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-63263 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-62994 CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` pluginInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-50045 'max-global-quota' reset by DNSSEC validation restartsInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-44690 Cross-zone wildcard cache poisoning via RRSIG.labels manipulationInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-52863 Memory corruption could lead to crash and denial of serviceInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-56416 Possible heap buffer overflow when validator canonicalizes RDATA that contains domain nameInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-56444 Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configurationInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-54478 DNS Cookie bypass when combined with proxy-protocol useInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-14586 Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environmentsInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-41637 Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queriesInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-44510 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a duplicate of CVE-2026-43620. Notes: All CVE users should reference CVE-2026-43620 instead of this candidate.Information published.MSRC.MICROSOFT.COM
23 JulNine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL InstallsRefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access. Qualys said default installations of Red Hat Enterprise Linux and its derivatives…THEHACKERNEWS.COM
23 Jul KEVNew Check Point Zero-Day Vulnerability Exploited in the WildThe vulnerability tracked as CVE-2026-16232 has been exploited against customers with certain configurations. The post New Check Point Zero-Day Vulnerability Exploited in the Wild appeared first on SecurityWeek .SECURITYWEEK.COM
23 Jul KEVCheck Point patches actively exploited SmartConsole authentication bypass flawCheck Point addressed a critical authentication bypass flaw, tracked as CVE-2026-16232, in SmartConsole that is being actively exploited. Check Point has released security updates to fix multiple vulnerabilities, including CVE-2026-16232 (CVSS score of 9.3), a critical authentica…SECURITYAFFAIRS.COM
23 JulAttackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)Attackers are exploiting a critical authentication bypass vulnerability (CVE-2026-16232) that affects Check Point Security Management and Multi-Domain Security Management, the management servers that push policy to Check Point security gateways (i.e., firewalls). “An unauth…HELPNETSECURITY.COM
23 JulNew RefluXFS Linux flaw lets attackers gain root privilegesA nine-year-old race condition vulnerability in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges. [...]BLEEPINGCOMPUTER.COM
23 JulLinux XFS has a decade-old race condition allowing full root accessLinux systems using the XFS filesystem suffer from a race condition that could enable an unprivileged local user to gain full root access. The flaw affects systems with Linux kernel 4.11 or later that have enabled the XFS feature reflink, which permits the creation of copies of a…CSOONLINE.COM
23 JulVU#492466: Logto Identity Platform has authentication and authorization failures in core protocol handlingOverview The Logto platform contains multiple vulnerabilities affecting the identity‑processing pipeline. These flaws reduce the reliability of authentication and authorization decisions and may allow attackers to bypass account‑ownership checks, skip MFA, replay externally issue…KB.CERT.ORG
23 Jul KEVCheck Point hole grants unauthenticated attackers full SmartConsole admin privilegesCheck Point has confirmed that a critical security hole in its SmartConsole management tool, one that allows unauthenticated attackers to assume full admin privileges, is now being exploited in the wild. The vulnerability, CVE-2026-16232 , was given a CVSS score of 9.3. In its se…CSOONLINE.COM
22 JulWordPress Feeding Frenzy, Another Healthcare Supply Chain Breach, Qillin Targets Palo Alto BugWP2Shell WordPress RCE feeding frenzy, AI agent breaches Hugging Face, Killin hits Palo Alto VPN flaw This episode covers five major incidents: a chained WordPress exploit dubbed WP2Shell (CVE-2026-6330 and CVE-2026-6137) enabling anonymous remote code execution on stock installs…CYBERSECURITYTODAY.LIBSYN.COM
22 JulCVE-2026-42533 NGINX Map directive and Regex matching vulnerabilityInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-56434 NGINX ngx_http_ssi_module vulnerabilityInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-26197 Array full size, element count, and element size are not checked to make sure they match in H5Odtype.cInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-64192 bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitializedInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-64189 netfilter: ipset: fix race between dump and ip_set_list resizeInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-64188 net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()Information published.MSRC.MICROSOFT.COM
22 JulCVE-2026-26199 Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zeroInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-64187 xfs: fail recovery on a committed log item with no regionsInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-64205 i2c: i801: fix hardware state machine corruption in error pathInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-64190 net: team: fix NULL pointer dereference in team_xmit during mode changeInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-64206 Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lockInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-64191 i2c: stub: Reject I2C block transfers with invalid lengthInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-39879 SQL injection in syslog-ng SQL destionation driverInformation published.MSRC.MICROSOFT.COM
22 JulFourth SharePoint Vulnerability Exploited in Past Month’s Wave of AttacksCVE-2026-50522 is being exploited by threat actors to steal machine keys and retain long-term access. The post Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulAnother SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)Attackers are exploiting a critical SharePoint remote code execution (RCE) vulnerability (CVE-2026-50522) to extract the servers’ IIS machine keys. “WatchTowr is observing active exploitation of CVE-2026-50522 against on-premise Microsoft SharePoint deployments follow…HELPNETSECURITY.COM
22 JulHackers Exploit Windmill Flaw to Read Arbitrary Server Files Without AuthenticationA high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill's "get_log…THEHACKERNEWS.COM
22 JulCVE-2026-50441 Windows Resilient File System (ReFS) Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
22 JulCVE-2026-50458 Microsoft Brokering File System Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
22 JulVU#360868: Analog Way Picturall Quad Compact Mark II contains a local privilege escalation vulnerabilityOverview Version 3.5.8 of Analog Way's Picturall Quad Compact Mark II server contains a local privilege escalation vulnerability, tracked as CVE-2026-14985, due to improper privilege delegation and insufficient input validation in a maintenance script. Description The Picturall Q…KB.CERT.ORG
22 JulWhat’s New in Rapid7 Products and Services: Q2 2026 in ReviewIf Q1 set the pace for Rapid7's tools, Q2 accelerated it. This quarter brought a steady stream of product enhancements, platform investments, and customer-driven innovation across Rapid7’s portfolio. Each release was designed with a clear goal in mind: helping security teams redu…RAPID7.COM
22 JulAdobe fixes Chrome extension flaw that could expose WhatsApp chatsA chain of vulnerabilities in the Adobe Acrobat Chrome extension could have allowed attackers to steal content from a victim's WhatsApp Web session simply by luring them to a malicious website. Adobe fixed the flaws within days of the report and assigned the issue CVE-2026-48294.…CYBERINSIDER.COM
22 JulVU#847406: Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission assignment vulnerabilityOverview Duplicati v2.3.0.1 is vulnerable to arbitrary code execution when installed outside the default C:\Program Files\Duplicati 2\ directory. An attacker with local user privileges who can write files to the Duplicati installation directory can execute arbitrary code by placi…KB.CERT.ORG
22 JulUbuntu snap-confine Flaw Could Give Local Users Root on Default Desktop InstallsCybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment. The high-severity flaw, tracked as CVE-2026-8933…THEHACKERNEWS.COM
22 JulOracle’s July update fixes ten 10.0 vulnerabilities in Fusion MiddlewareOracle’s July 2026 Critical Patch Update, its largest ever, contains 1,449 new security patches spanning 32 product families, from Oracle Database and E-Business Suite to PeopleSoft, GoldenGate, Java SE, and Fusion Middleware. Fusion Middleware was particularly hard hit, with new…CSOONLINE.COM
22 JulCritical Zimbra security update fixes 9 vulnerabilitiesBusiness email and collaboration suite Zimbra has received a major security update that fixes several critical issues that could allow attackers to execute malicious code on the server or in users’ browsers. Available in commercial and open-source editions, Zimbra Collaboration S…CSOONLINE.COM
22 JulAdobe Acrobat Chrome extension bug enabled silent WhatsApp data theftAdobe patched CVE-2026-48294, a flaw in Adobe Acrobat Chrome extension that could let attackers steal WhatsApp Web chats by luring users to a webpage. Guardio Labs researcher Shaked Biner disclosed HermeticReader, a vulnerability chain in the Adobe Acrobat Chrome extension that a…SECURITYAFFAIRS.COM
22 JulCVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protectionsQualys disclosed CVE-2026-8933, a high-severity Ubuntu flaw that lets local attackers gain root privileges through a race condition in snap-confine. Qualys has disclosed a high-severity local privilege escalation vulnerability, tracked as CVE-2026-8933 (CVSS score of 7.8), affect…SECURITYAFFAIRS.COM
21 Jul KEVWhite hat hacker Park Chan-am zeros in on the AI era’s key security challengesDubbed the “Genius Hacker,” Park Chan-am began his white hat hacker journey at the precocious age of 11, winning awards at domestic and international hacking competitions since his teenage years. He has since served as a cybersecurity advisor for various Korean government agencie…CSOONLINE.COM
21 JulAttackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875Attackers are exploiting critical ServiceNow flaw CVE-2026-6875, allowing unauthenticated remote code execution on self-hosted instances. Searchlight Cyber researchers disclosed a critical pre-authentication remote code execution vulnerability, tracked as CVE-2026-6875, in the Se…SECURITYAFFAIRS.COM
21 JulCritical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code ExecutionThreat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said it's observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbo…THEHACKERNEWS.COM
21 JulCVE-2026-38754 A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-3842 Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob writeInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64133 ALSA: asihpi: Fix potential OOB array access at reading cacheInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64097 drm/amd/display: Validate GPIO pin LUT table size before iteratingInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63940 KVM: SEV: Ignore Port I/O requests of length '0'Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64077 netfilter: ebtables: move to two-stage removal schemeInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63879 drm/amdgpu: fix amdgpu_hmm_range_get_pagesInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63882 drm/amdkfd: fix NULL pointer bug in svm_range_set_attrInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64017 blk-mq: pop cached request if it is usableInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64146 erofs: fix metabuf leak in inode xattr initializationInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-38755 A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64038 hwmon: (lm90) Stop work before releasing hwmon deviceInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64036 cgroup/rstat: validate cpu before css_rstat_cpu() accessInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64079 netfilter: x_tables: allocate hook ops while under mutexInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64001 ALSA: pcm: oss: Fix setup list UAF on proc write errorInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64160 netfs: Fix potential for tearing in ->remote_i_size and ->zero_pointInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64138 ksmbd: validate SID in parent security descriptor during ACL inheritanceInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63959 usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNTInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64070 powerpc/hv-gpci: fix preempt count leak in sysfs show pathsInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64015 security/keys: fix missed RCU read section on lookupInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63962 usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes()Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63958 usb: typec: ucsi: validate connector number in ucsi_connector_change()Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64117 wifi: mac80211: capture fast-RX rate before mesh reuses skb->cbInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63954 hpfs: fix a crash if hpfs_map_dnode_bitmap failsInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64078 netfilter: x_tables: add and use xtables_unregister_table_exitInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63983 net/sched: fix packet loop on netem when duplicate is onInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63964 usb: typec: ucsi: ccg: reject firmware images without a ':' record headerInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63960 usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer()Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63881 drm/amdkfd: fix a vulnerability of integer overflow in kfd debuggerInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63961 usb: typec: altmodes/displayport: validate count before reading Status Update VDOInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63963 usb: typec: tcpm: validate VDO count in Discover Identity ACK handlersInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64111 lsm: hold cred_guard_mutex for lsm_set_self_attr()Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64154 drm/msm/adreno: Fix a reference leak in a6xx_gpu_init()Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64112 rbd: eliminate a race in lock_dwork draining on unmapInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64076 netfilter: bridge: eb_tables: close module init raceInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64060 netfs: Fix leak of request in netfs_write_begin() error handlingInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63979 net/handshake: hand off the pinned file reference to accept_doitInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63999 ethtool: rss: fix indir_table and hkey leak on get_rxfh failureInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63978 net/handshake: Drain pending requests at net namespace exitInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63974 Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device closeInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64082 riscv: Fix register corruption from uninitialized cregs on errorInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-38753 A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-38752 A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-42770 FFC-DH Peer Validation Uses Attacker-Supplied qInformation published.MSRC.MICROSOFT.COM
21 JulWordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass ScanningAttackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have be…THEHACKERNEWS.COM
21 JulExploitation of ServiceNow Vulnerability Seen Days After DisclosureThe ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution. The post Exploitation of ServiceNow Vulnerability Seen Days After Disclosure appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulSonicWall SMA zero-days were exploited weeks before disclosureTwo recently disclosed SonicWall SMA 1000 vulnerabilities – CVE-2026-15409 and CVE-2026-15410 – were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances, Volexity researchers revealed. The intrusions b…HELPNETSECURITY.COM
21 JulQilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial AccessThreat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with…THEHACKERNEWS.COM
21 JulCritical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoCA third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Of…THEHACKERNEWS.COM
21 JulCVE-2026-58640 Windows NTFS Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 JulCVE-2026-50462 Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 JulVU#762226: Plane contains multi-tenant authorization bypass vulnerabilityOverview The project management tool Plane, versions 1.3.0 and earlier, contains a multi-tenant authorization bypass vulnerability in its asset-management API that allows unauthorized users to access, delete, or duplicate assets that belong to other workspaces. Description Plane …KB.CERT.ORG
21 JulCritical wp2shell WordPress flaws exploited to install webshellsHackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers. [...]BLEEPINGCOMPUTER.COM
21 JulQilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN AccessQilin ransomware exploits the PAN-OS GlobalProtect flaw CVE-2026-0257 to gain unauthorized VPN access to unpatched networks. Arctic Wolf researchers warn that the Qilin ransomware gang is exploiting the critical PAN-OS GlobalProtect vulnerability CVE-2026-0257 to compromise corpo…SECURITYAFFAIRS.COM
21 JulCritical SharePoint RCE flaw exploited to steal machine keysHackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. [...]BLEEPINGCOMPUTER.COM
21 Jul KEVPublic PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522Critical SharePoint RCE vulnerability CVE-2026-50522 is under active exploitation after the release of a PoC exploit code. A critical Microsoft SharePoint vulnerability, tracked as CVE-2026-50522 (CVSS score of 9.8), is being actively exploited following the release of a public p…SECURITYAFFAIRS.COM
20 JulCritical NGINX Vulnerability Can Crash Workers and May Allow Remote Code ExecutionF5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in NGINX Plus 37.…THEHACKERNEWS.COM
20 Jul KEVWP2Shell WordPress Vulnerabilities Exploited in the WildExploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure. The post WP2Shell WordPress Vulnerabilities Exploited in the Wild appeared first on SecurityWeek .SECURITYWEEK.COM
20 JulCVE-2026-63815 f2fs: bound i_inline_xattr_size for non-inline-xattr inodesInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53386 iio: adc: ti-ads1298: add bounds check to pga_settings indexInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63810 block: Avoid mounting the bdev pseudo-filesystem in userspaceInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53392 NFSv4/flexfiles: reject zero filehandle version countInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53374 drm/amdgpu: zero-initialize GART table on allocationInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53376 drm/amdkfd: Add upper bound check for num_of_nodesInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63806 KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned()Information published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63833 ntfs3: reject direct userspace writes to reserved $LX* xattrsInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63826 fbdev: fix use-after-free in store_modes()Information published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63829 net: ip_gre: require CAP_NET_ADMIN in the device netns for changelinkInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53375 drm/amdgpu/vce: Prevent partial address patchesInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53393 nfsd: reset write verifier on deferred writeback errorsInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63809 bpf: use kvfree() for replaced sysctl write bufferInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63803 hdlc_ppp: sync per-proto timers before freeing hdlc stateInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63834 batman-adv: tp_meter: restrict number of unacked list entriesInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53391 NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addrInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63822 wifi: ath11k: fix warning when unbindingInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53397 nfsd: fix posix_acl leak on SETACL decode failureInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63836 batman-adv: tp_meter: avoid divide-by-zero for dec_cwndInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63796 ocfs2: reject oversized group bitmap descriptorsInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63812 f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()Information published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63801 tipc: fix slab-use-after-free Read in tipc_aead_decrypt_doneInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63828 apparmor: mediate the implicit connect of TCP fast open sendmsgInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53382 media: vidtv: fix NULL pointer dereference in vidtv_mux_push_siInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63795 9p: avoid putting oldfid in p9_client_walk() error pathInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63808 exfat: fix potential use-after-free in exfat_find_dir_entry()Information published.MSRC.MICROSOFT.COM
20 JulCVE-2026-45784 rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphersInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-62389 ws < 8.21.1 Default maxFragments Allows Memory Exhaustion DoSInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63805 crypto: nx - fix nx_crypto_ctx_exit argumentInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63816 f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inodeInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63825 gcov: use atomic counter updates to fix concurrent access crashesInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63853 drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ringInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53402 fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()Information published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63819 f2fs: fix to do sanity check on f2fs_get_node_folio_ra()Information published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53401 fbdev: omap2: fix use-after-free in omapfb_mmapInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63811 f2fs: read COW data with the original inode during atomic writeInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53403 fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_varInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53368 f2fs: fix fsck inconsistency caused by incorrect nat_entry flag usageInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53400 i2c: core: fix adapter registration raceInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63871 Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route callsInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63872 esp: fix page frag reference leak on skb_to_sgvec failureInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53399 nfsd: release layout stid on setlease failureInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63858 netfilter: nf_tables: add hook transactions for device deletionsInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63818 f2fs: validate orphan inode entry countInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63832 wifi: mt76: add wcid publish check in mt76_sta_addInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53387 iio: light: veml6075: add bounds check to veml6075_it_ms indexInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63835 batman-adv: v: prevent OGM aggregation on disabled hardifInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63807 KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping levelInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53384 serial: 8250_dw: unregister 8250 port if clk_notifier_register() failsInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63830 net: skmsg: preserve sg.copy across SG transformsInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53388 fuse: re-lock request before replacing page cache folioInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63794 KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT pathInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63821 wifi: rtw88: usb: fix memory leaks on USB write failuresInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63824 KEYS: fix overflow in keyctl_pkey_params_get_2()Information published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63798 irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on removeInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63823 keys: Pin request_key_auth payload in instantiate pathsInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63800 pNFS: Fix use-after-free in pnfs_update_layout()Information published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63797 rpmsg: char: Fix use-after-free on probe error pathInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63817 f2fs: validate compress cache inode only when enabledInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63804 gfs2: fix use-after-free in gfs2_qd_deallocInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63831 mac802154: llsec: add skb_cow_data() before in-place cryptoInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63802 blk-cgroup: fix UAF in __blkcg_rstat_flush()Information published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53385 vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_writeInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53390 ksmbd: fix out-of-bounds read in smb_check_perm_dacl()Information published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63814 f2fs: validate ACL entry sizes in f2fs_acl_from_disk()Information published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53383 ksmbd: reject non-VALID session in compound request branchInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53398 NFSD: Fix SECINFO_NO_NAME decode error cleanupInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63827 apparmor: fix use-after-free in rawdata dedup loopInformation published.MSRC.MICROSOFT.COM
20 JulNew 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During ExtractionOpening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro's Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June …THEHACKERNEWS.COM
20 JulCritical ServiceNow code execution flaw now exploited in attacksAttackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. [...]BLEEPINGCOMPUTER.COM
20 JulCVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server TakeoversF5 fixes critical nginx flaw CVE-2026-42533 that can crash servers and, in some cases, allow remote code execution through crafted HTTP requests. F5 released patches for a critical nginx vulnerability, tracked as CVE-2026-42533 (CVSS score of 9.2), that can allow an unauthenticat…SECURITYAFFAIRS.COM
20 JulFrom a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery LabExecutive summary An MDR alert recently led our team to an exposed server that was doing more than hosting payloads. It was functioning as a fully operational malware delivery lab. Containing over 1,000 artifacts, the infrastructure served as a QA hub where attackers systematical…RAPID7.COM
20 JulSonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before PatchThe zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533. The post SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch appeared first on SecurityWeek .SECURITYWEEK.COM
20 Jul KEVServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About the vulnerability ServiceNow AI is a Platform-as-a-Service that lets organizations build and automate dig…HELPNETSECURITY.COM
20 JulCVE-2026-50650 .NET Framework Elevation of Privilege VulnerabilityUpdated product information in the Software Update table. This is an informational change only.MSRC.MICROSOFT.COM
20 JulExploitation in the Wild of wp2shellWiz Research has identified exploitation of "wp2shell", a critical pre-auth RCE vulnerability chain impacting WordPress Core (CVE-2026-63030 & CVE-2026-60137). Attackers are deploying persistent webshells on vulnerable servers. Organizations should prioritize patching or applying…WIZ.IO
20 JulWordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)Last week, Searchlight Cyber released details about a vulnerability they are calling "wp2shell". The vulnerability was initially announced without a CVE number. But now has been assigned CVE-2026-63030. Many WordPress plugin vulnerabilities are never assigned CVE numbers. But wp2…ISC.SANS.EDU
20 JulCVE-2024-44000 (LiteSpeed Cache Account Takeover) Ranks in June’s Top ThreatsSensor Intel Series: July 2026 CVE TrendsF5.COM
20 Jul KEVServiceNow’s sandbox escape RCE hole now exploited in the wildA sandbox security hole that could lead to remote code execution (RCE), patched last week by ServiceNow, is being actively exploited in the wild, according to a report from threat intel firm Defused . The report, posted on X, said the firm is “observing in-the-wild exploitation o…CSOONLINE.COM
20 Jul'WP2Shell' Opens Millions of WordPress Sites to Remote TakeoverBarely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.DARKREADING.COM
19 JulAttackers Can Take Over WordPress Sites Using Newly Released wp2shell ExploitsPublic exploits are now available for two critical WordPress flaws that attackers can chain to gain remote code execution without authentication. Public proof-of-concept exploits are now available for the critical wp2shell vulnerabilities affecting WordPress Core. The flaws, trac…SECURITYAFFAIRS.COM
18 JulCVE-2026-62309 CoreDNS: proxyproto plugin panics on PPv2 datagram with non-UDP transport — single 28-byte packet remote DoSInformation published.MSRC.MICROSOFT.COM
18 JulCVE-2026-62299 CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downstream plugin returns a response with no OPT recordInformation published.MSRC.MICROSOFT.COM
18 JulCVE-2026-47729 Squid: Memory disclosure in FTP gatewayInformation published.MSRC.MICROSOFT.COM
18 JulCVE-2026-50012 Squid: Memory corruption in cache_digest reply handlingInformation published.MSRC.MICROSOFT.COM
18 JulTwo new high severity WordPress vulnerabilities, patch immediately!The 7.0.2 WordPress security release addresses one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: CVE-2026-60137 – A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo CVE-2026-60…HELPNETSECURITY.COM
17 JulCVE-2026-48863 Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of serviceInformation published.MSRC.MICROSOFT.COM
17 JulCVE-2026-53366 ipv4: account for fraggap on the paged allocation pathInformation published.MSRC.MICROSOFT.COM
17 JulCVE-2026-15713 Libsoup: soupcache: libsoup: http/2 frame window exhaustion remote denial of service via memory leakInformation published.MSRC.MICROSOFT.COM
17 JulCVE-2026-15714 Libsoup: soupmultipartinputstream: libsoup: out-of-bounds read in soup_multipart_input_stream_read_headers via an oversized multipart boundary stringInformation published.MSRC.MICROSOFT.COM
17 JulCVE-2026-15712 Soupclientmessageiohttp2: libsoup3: libsoup: http/2 goaway frame parsing heap buffer over-read via invalid nul-termination assumptionInformation published.MSRC.MICROSOFT.COM
17 JulCVE-2026-60082 DBI versions before 1.651 for Perl do not enforce statement handle consistency with the rowInformation published.MSRC.MICROSOFT.COM
17 JulCVE-2026-60081 DBI::ProfileData versions before 1.651 for Perl do not limit the path indexInformation published.MSRC.MICROSOFT.COM
17 JulCVE-2026-59884 pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDsInformation published.MSRC.MICROSOFT.COM
17 JulCVE-2026-59886 pyasn1: Uncontrolled resource consumption when converting decoded REAL valuesInformation published.MSRC.MICROSOFT.COM
17 JulCVE-2026-15711 Libsoup: soupwebsocketconnection: libsoup: websocket remote denial of service via oversized control frame protocol violationInformation published.MSRC.MICROSOFT.COM
17 JulCVE-2026-15709 Soupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate unbounded decompression remote denial of serviceInformation published.MSRC.MICROSOFT.COM
17 JulCVE-2026-57433 Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK recordInformation published.MSRC.MICROSOFT.COM
17 JulCVE-2026-15043 DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on textInformation published.MSRC.MICROSOFT.COM
17 JulCVE-2026-15392 DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted locationInformation published.MSRC.MICROSOFT.COM
17 JulCVE-2026-59885 pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of serviceInformation published.MSRC.MICROSOFT.COM
17 Jul KEVCVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the WildOverview On July 14, 2026, Microsoft published a security advisory addressing CVE-2026-58644 , a critical remote code execution (RCE) vulnerability affecting on-premises Microsoft SharePoint Server deployments. The vulnerability, which carries a CVSS v3.1 score of 9.8 (Critical),…RAPID7.COM
17 JulChromium: CVE-2026-15904 Use after free in OzoneThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
17 JulChromium: CVE-2026-15903 Out of bounds read and write in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
17 JulChromium: CVE-2026-15899 Use after free in CameraCaptureThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
17 JulChromium: CVE-2026-15900 Use after free in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
17 JulChromium: CVE-2026-15901 Use after free in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
17 JulChromium: CVE-2026-15902 Use after free in CastThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
17 JulChromium: CVE-2026-15905 Use after free in AuraThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
17 JulCVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress CoreOverview On July 17, 2026, a GitHub Security Advisory was published for CVE-2026-63030 , a critical unauthenticated remote code execution vulnerability affecting WordPress Core . WordPress Core. While the official GitHub security advisory classifies the severity as Critical, the …RAPID7.COM
16 JulZoom Patches Critical Windows Flaw That Could Enable Account TakeoverZoom has released security updates for a critical security flaw impacting Zoom Workplace for Windows that could facilitate account takeover. The vulnerability, tracked as CVE-2026-53412 (CVSS score: 9.8), affects Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Z…THEHACKERNEWS.COM
16 JulZoom Fixes CVE-2026-53412, a Critical Account Takeover BugZoom warns of a critical Windows flaw, tracked as CVE-2026-53412, that could let attackers take over accounts without authentication. Zoom has fixed a critical Windows vulnerability, tracked as CVE-2026-53412 (CVSS score of 9.8) that could allow unauthenticated attackers to hijac…SECURITYAFFAIRS.COM
16 JulAge of Empires II patch fixes RCE bug exploitable through multiplayer lobbiesA recent update for Age of Empires II: Definitive Edition fixed a remote code execution (RCE) vulnerability that could have allowed attackers to compromise other players' systems through multiplayer. The flaw, tracked as CVE-2026-50663, stemmed from a relative path traversal bug …CYBERINSIDER.COM
16 JulVU#326070: SGLang contains a vulnerable pickle deserialization vulnerability through the expert-parallel subsystemOverview A Pickle deserialization vulnerability has been discovered within the SGLang project , enabling an attacker to perform remote code execution (RCE) on the target vulnerable server. In order for an attacker to exploit this vulnerability, the expert-parallel backup subsyste…KB.CERT.ORG
15 Jul KEVPatch Tuesday roundup: Microsoft fixes a monthly record 569 holes; SAP patches a critical memory corruption bugEarlier this month Microsoft warned that, because the latest AI models can now help discover vulnerabilities, CSOs will see a higher volume of security updates every month. It wasn’t kidding. Today the company issued a record number of patches , with 59 rated as critical. And Mic…CSOONLINE.COM
15 JulSonicWall Issues Urgent SMA Patch Warning for Two Zero-Day ExploitsSonicWall SMA1000 zero-day vulnerabilities CVE-2026-15409 and CVE-2026-15410 can be exploited for remote code execution. The post SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits appeared first on SecurityWeek .SECURITYWEEK.COM
15 JulTwo SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin CommandsSonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution. The vulnerabilities are listed below - CVE-2026-15409 (CVSS score: 10.0…THEHACKERNEWS.COM
15 JulCVE-2026-57432 Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpackInformation published.MSRC.MICROSOFT.COM
15 JulCVE-2026-39822 Root escape via symlink plus trailing slash in osInformation published.MSRC.MICROSOFT.COM
15 JulCVE-2026-42505 Invoking Encrypted Client Hello privacy leak in crypto/tlsInformation published.MSRC.MICROSOFT.COM
15 JulCVE-2026-15028 Libarchive: heap overflow oob read while parsing a tar archive contains a pax extended headerInformation published.MSRC.MICROSOFT.COM
15 JulCVE-2026-57219 RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurationsInformation published.MSRC.MICROSOFT.COM
15 JulCVE-2026-13221 Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunkInformation published.MSRC.MICROSOFT.COM
15 JulCVE-2026-59875 node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath recordsInformation published.MSRC.MICROSOFT.COM
15 JulCVE-2026-59831 GitHub CLI `gh codespace jupyter` could allow remote code execution when connecting to a malicious CodespaceInformation published.MSRC.MICROSOFT.COM
15 JulCVE-2026-57220 RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoSInformation published.MSRC.MICROSOFT.COM
15 JulCVE-2026-57217 RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypassInformation published.MSRC.MICROSOFT.COM
15 JulCVE-2026-57213 RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag renderingInformation published.MSRC.MICROSOFT.COM
15 JulCVE-2026-57216 RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checksInformation published.MSRC.MICROSOFT.COM
15 JulCVE-2026-57211 RabbitMQ: UNC SSRF affecting the management UI on WindowsInformation published.MSRC.MICROSOFT.COM
15 JulCVE-2026-57215 RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantomInformation published.MSRC.MICROSOFT.COM
15 JulAI-driven bug hunting fuels record Microsoft Patch TuesdayMicrosoft has released patches for 570+ vulnerabilities on July 2026 Patch Tuesday, including two that are being leveraged by attackers (CVE-2026-56155 and CVE-2026-56164), and one that was previouly disclosed (CVE-2026-50661). The release was once again followed by Nightmare Ecl…HELPNETSECURITY.COM
15 JulFirefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security FlawsMozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published. The vulnerabilities are listed below - CVE-2026-15718, an invalid pointer in the JavaScript: WebAssembly component CVE-2026-15719, a site isolation in t…THEHACKERNEWS.COM
15 JulVU#725167: node-forge Signature Forgery Vulnerabilities in RSA-PKCS and ED25519 ImplementationsOverview Two distinct cryptographic signature verification vulnerabilities exist in Digital Bazaar node-forge, a widely used JavaScript library implementing cryptographic primitives for Node.js and browser environments. These vulnerabilities allow attackers to forge RSA (PKCS#1 v…KB.CERT.ORG
15 Jul KEVRapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)Overview On July 14, 2026, SonicWall published a security advisory addressing two vulnerabilities affecting SMA1000 Series remote access appliances, including the critical server-side request forgery (SSRF) vulnerability CVE-2026-15409 (CVSS 10.0) and the high-severity code injec…RAPID7.COM
15 Jul KEVCVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wildSonicWall patched two recently exploited zero-day vulnerabilities in its SMA 1000 Series secure remote access appliances which may have been chained for unauthenticated remote code execution. Key takeaways CVE-2026-15409 and CVE-2026-15410 are a pair of exploited vulnerabilities …TENABLE.COM
15 JulVU#529388: Privilege escalation vulnerability via unprotected IOCTL interface in Pegatron Tdelo64.sysOverview A privilege escalation vulnerability exists in the tdeio64.sys driver due to an unprotected input/output control (IOCTL) dispatch routine that fails to validate the origin and permissions of user-supplied requests. An unprivileged local attacker can abuse exposed IOCTL d…KB.CERT.ORG
15 JulAL26-017 - Critical vulnerabilities impacting Microsoft SharePoint Server – CVE-2026-56164, CVE-2026-55040 and CVE-2026-58644CYBER.GC.CA
14 JulGovernments to enterprises: Improve your router security hygieneGlobal security agencies say enterprises must clean up their act as Russian government-sponsored attackers exploit weaknesses in routers. According to a new multinational cybersecurity advisory , cyberattackers continue to exploit inadequately-protected and/or poorly-configured n…CSOONLINE.COM
14 JulAI-powered breaches provide wake-up call for incident responseEnterprises have worked for years to improve detection and response times in the face of increasingly sophisticated attacks that relied on manual hacking and living-of-the-land techniques. AI is now threatening to undo those efforts. An increasing number of threat actors are auto…CSOONLINE.COM
14 JulCVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)Overview Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapi…RAPID7.COM
14 Jul KEVSonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410)SonicWall has fixed two actively exploited vulnerabilities (CVE-2026-15409, CVE-2026-15410) affecting its Secure Mobile Access (SMA) 1000 Series appliances, and is urging customer organizations to upgrade to a fixed firmare version and search for evidence of potential compromise.…HELPNETSECURITY.COM
14 Jul KEVMicrosoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)56 Critical 510 Important 3 Moderate 0 Low Microsoft addresses 569 CVEs in the largest Patch Tuesday release yet. This month’s release includes three zero-days, two of which were exploited in the wild. Microsoft patched 569 CVEs in its July 2026 Patch Tuesday release, with 56 rat…TENABLE.COM
14 JulSAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify DataSAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP. The vulnerability in question is CVE-2026-44747 (CVSS score: 9.9), an out-of-bounds write flaw that allows…THEHACKERNEWS.COM
14 Jul KEVMicrosoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilitiesMicrosoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products, including 57 that Microsoft marked as "critical". Microsoft notes that two of the vulnerabilities disclosed this month have been exploited…TALOSINTELLIGENCE.COM
14 JulSonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch nowSonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates. [...]BLEEPINGCOMPUTER.COM
13 Jul KEViCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-DaysThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation in the wild. The vu…THEHACKERNEWS.COM
13 JulRabbitMQ flaws expose OAuth secrets, risk complete takeover of the brokerRabbitMQ has patched two access control vulnerabilities affecting the widely used open-source message broker that could expose enterprise application data and, in some deployments, allow attackers to gain complete control over the messaging infrastructure. The flaws, discovered b…CSOONLINE.COM
12 JulCVE-2026-15308 Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarationsInformation published.MSRC.MICROSOFT.COM
12 JulCVE-2026-59871 node-tar: Process crash via PAX numeric path type confusionInformation published.MSRC.MICROSOFT.COM
12 JulCVE-2026-59873 node-tar: Decompression/parse DoS via unlimited inputInformation published.MSRC.MICROSOFT.COM
12 JulCVE-2026-59874 node-tar: Negative tar entry size causes infinite loop in archive replaceInformation published.MSRC.MICROSOFT.COM
11 JulWeekly Metasploit Update: Exploits for FlowiseAI CSV Agent and MacOS Package KitMore AI, more software, more bugs! AI, it's all you hear about nowadays and everyone's got an opinion on it. Here at Metasploit, we care less about those opinions and more about the growing attack surface all this new software brings with it (yeehaw exploits!). Take for example t…RAPID7.COM
11 JulCVE-2026-59856 Vim: Arbitrary Code Execution via PHP Omni-CompletionInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-20214 ClamAV FSG File Format Processing Out-of-Bounds Memory Corruption VulnerabilityInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-20215 ClamAV 7Zip File Format Processing Out-of-Bounds Memory Corruption VulnerabilityInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-20216 ClamAV InstallShield File Format Processing Resource Exhaustion VulnerabilityInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-20217 ClamAV PESpin File Format Processing Out-of-Bounds Memory Corruption VulnerabilityInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-20244 ClamAV DMG File Processing Denial of Service VulnerabilityInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-59998 sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.Information published.MSRC.MICROSOFT.COM
11 JulCVE-2026-14380 DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced ProfileInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-14740 DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL commentInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-59926 Mistune: XSS via unescaped class option in Admonition directiveInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-59925 inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairsInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-59930 Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` contentInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-59890 setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+Information published.MSRC.MICROSOFT.COM
11 JulCVE-2026-58207 NATS Server: Remote crash via integer overflow in Connz paginationInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-58251 NATS Server: Queue Subscribe Authz BypassInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-58208 NATS Server: MQTT-over-WebSocket Path Can Crash WebSocket-Only JetStream Servers Before MQTT Is EnabledInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-58252 NATS Server: Subscribe Authz Bypass via Wildcard-OverlapInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-58209 NATS Server: MQTT retained and QoS replay bypass subscribe deny filtersInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-20213 ClamAV PE File Format Processing Out-of-Bounds Memory Corruption VulnerabilityInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-20243 ClamAV ALZ Archive Processing Denial of Service VulnerabilityInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-14739 DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholdersInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-59928 Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitionsInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-59922 Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)Information published.MSRC.MICROSOFT.COM
11 JulCVE-2026-59869 js-yaml: YAML merge-key chains can force quadratic CPU consumptionInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-58250 NATS Server: Pre-auth server crash via double INFO in leafnode handshakeInformation published.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14428 Insufficient validation of untrusted input in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13777 Insufficient validation of untrusted input in iOSWebThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13778 Use after free in WebUSBThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14394 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14396 Out of bounds read in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14395 Out of bounds write in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14397 Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14398 Use after free in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14399 Uninitialized Use in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14400 Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14401 Insufficient validation of untrusted input in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14402 Uninitialized Use in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14403 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14405 Uninitialized Use in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14404 Inappropriate implementation in PDFiumThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14406 Out of bounds read in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14410 Inappropriate implementation in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14407 Inappropriate implementation in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14409 Inappropriate implementation in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14412 Insufficient validation of untrusted input in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14408 Uninitialized Use in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14411 Insufficient validation of untrusted input in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14413 Uninitialized Use in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14415 Inappropriate implementation in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14418 Uninitialized Use in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14417 Use after free in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14416 Out of bounds read in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14419 Use after free in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14420 Out of bounds read and write in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14421 Uninitialized Use in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14422 Out of bounds read and write in TintThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14423 Type Confusion in TintThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14425 Use after free in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14426 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14427 Heap buffer overflow in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14424 Use after free in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14429 Insufficient validation of untrusted input in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14430 Integer overflow in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14432 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14431 Type Confusion in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14414 Insufficient validation of untrusted input in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13785 Use after free in BluetoothThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13788 Use after free in FullscreenThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13791 Insufficient validation of untrusted input in DownloadsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13807 Use after free in ImportThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13795 Insufficient policy enforcement in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13792 Use after free in TouchbarThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13805 Use after free in GFXThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13808 Insufficient data validation in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13812 Insufficient validation of untrusted input in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13809 Side-channel information leakage in Safe BrowsingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13813 Insufficient validation of untrusted input in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13816 Insufficient validation of untrusted input in File InputThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13822 Inappropriate implementation in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13819 Out of bounds read in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13825 Uninitialized Use in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13826 Inappropriate implementation in AutofillThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13827 Use after free in UpdaterThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13842 Incorrect security UI in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13843 Insufficient validation of untrusted input in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13833 Uninitialized Use in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13846 Use after free in USBThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13847 Insufficient validation of untrusted input in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13850 Insufficient validation of untrusted input in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13851 Insufficient validation of untrusted input in WebAppInstallsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13856 Insufficient validation of untrusted input in SpeechThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13852 Insufficient validation of untrusted input in WebAppInstallsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13863 Insufficient validation of untrusted input in CustomTabsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13866 Insufficient validation of untrusted input in InputThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13872 Insufficient validation of untrusted input in WebAppInstallsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13868 Inappropriate implementation in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13870 Use after free in WebViewThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13878 Use after free in BluetoothThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13885 Use after free in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13880 Use after free in USBThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13889 Insufficient validation of untrusted input in WebAuthenticationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13892 Inappropriate implementation in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13887 Insufficient policy enforcement in NFCThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13902 Inappropriate implementation in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13904 Incorrect security UI in Safe BrowsingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13905 Incorrect security UI in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13907 Inappropriate implementation in iOSWebThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13908 Insufficient validation of untrusted input in OmniboxThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13910 Insufficient policy enforcement in WebXRThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13912 Incorrect security UI in Safe BrowsingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13914 Inappropriate implementation in PasswordsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13913 Insufficient policy enforcement in AutofillThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13915 Use after free in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13916 Inappropriate implementation in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13917 Insufficient validation of untrusted input in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13918 Use after free in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13924 Insufficient validation of untrusted input in WebViewThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13923 Uninitialized Use in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13926 Insufficient validation of untrusted input in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13927 Insufficient validation of untrusted input in UIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13932 Inappropriate implementation in SharingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13929 Insufficient validation of untrusted input in DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13936 Inappropriate implementation in PasswordsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13939 Insufficient validation of untrusted input in WebShareThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13944 Inappropriate implementation in DataTransferThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13943 Uninitialized Use in CSSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13949 Insufficient policy enforcement in PaymentsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13946 Inappropriate implementation in ScriptInjectionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13955 Insufficient validation of untrusted input in CustomTabsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13964 Insufficient policy enforcement in WebViewThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13969 Uninitialized Use in UIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13974 Integer overflow in Safe BrowsingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13975 Out of bounds read in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13980 Incorrect security UI in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13994 Inappropriate implementation in Credential ManagementThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13983 Incorrect security UI in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13981 Inappropriate implementation in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13991 Insufficient validation of untrusted input in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13992 Inappropriate implementation in UIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13987 Incorrect security UI in MobileThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13997 Incorrect security UI in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13998 Incorrect security UI in File InputThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14028 Incorrect security UI in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13995 Insufficient validation of untrusted input in AutofillThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14005 Use after free in OmniboxThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14066 Insufficient validation of untrusted input in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14067 Use after free in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14075 Policy bypass in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14099 Use after free in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14096 Object lifecycle issue in InputThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14101 Insufficient policy enforcement in SandboxThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14114 Inappropriate implementation in WebAppInstallsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14126 Incorrect security UI in UIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14123 Incorrect security UI in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14128 Insufficient data validation in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14382 Insufficient validation of untrusted input in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14136 Incorrect security UI in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14137 Insufficient validation of untrusted input in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14386 Out of bounds read in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14385 Heap buffer overflow in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14388 Out of bounds read in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14390 Use after free in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14393 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14391 Integer overflow in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14392 Out of bounds write in TintThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
10 JulCVE-2026-59818 etcd: gRPC client listener does not enforce `--client-crl-file` certificate revocationInformation published.MSRC.MICROSOFT.COM
10 JulCVE-2026-56289 Loop with Unreachable Exit Condition in GNU patchInformation published.MSRC.MICROSOFT.COM
10 JulThe business case for burning down security debt: A practical approach for CISOsSecurity leaders have made strong progress in visibility. Most organizations can now identify vulnerabilities across their applications, dependencies and development pipelines with far more consistency than in the past. Yet a fundamental imbalance remains: Vulnerabilities are bei…CSOONLINE.COM
10 Jul“GhostLock” flaw survived in the Linux kernel code for 15 yearsA Linux kernel vulnerability remained hidden in virtually every major Linux distribution for more than 15 years before being fixed earlier this year. The flaw, tracked as CVE-2026-43499 and dubbed GhostLock, can be exploited by an unprivileged local attacker to gain root privileg…CYBERINSIDER.COM
10 JulVU#564823: GNU Wget enables SSRF via unvalidated FTP PASV IPsOverview GNU Wget, versions 1.25.0 and earlier, contains a server-side request forgery (SSRF) vulnerability in its implementation of FTP passive mode. Because Wget does not properly validate IP addresses obtained from PASV responses, an attacker-controlled FTP endpoint can redire…KB.CERT.ORG
9 JulUnpatched Backdoor in Tenda Firmware Grants Admin Access to DevicesTracked as CVE-2026-11405, the vulnerability allows unauthenticated attackers to access a device's web management interface. The post Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulCVE-2026-53359 KVM: x86: Fix shadow paging use-after-free due to unexpected roleInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-14355 ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PADInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-59997 internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.Information published.MSRC.MICROSOFT.COM
9 JulCVE-2026-59996 scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.Information published.MSRC.MICROSOFT.COM
9 JulCVE-2026-59995 sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.Information published.MSRC.MICROSOFT.COM
9 JulCVE-2026-60001 sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.Information published.MSRC.MICROSOFT.COM
9 JulCVE-2026-60000 sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.Information published.MSRC.MICROSOFT.COM
9 JulCVE-2026-59999 In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.Information published.MSRC.MICROSOFT.COM
9 JulCVE-2026-60002 ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)Information published.MSRC.MICROSOFT.COM
9 JulCVE-2026-56002 libXfont2 PCF Font Parsing Heap Buffer OverflowInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-56000 xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent()Information published.MSRC.MICROSOFT.COM
9 JulCVE-2026-38968 ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.Information published.MSRC.MICROSOFT.COM
9 JulCVE-2026-38969 ruby webrick through v1.9.2 WEBrick reparses trailer Content-Length into canonical request state, enabling request smuggling.Information published.MSRC.MICROSOFT.COM
9 JulCVE-2026-54908 Pion DTLS: Denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange messageInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-53354 arm64: errata: Mitigate TLBI errata on various Arm CPUsInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-53345 KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dyingInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-53332 slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngdInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-53336 nvmem: layouts: onie-tlv: fix hang on unknown typesInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-53327 debugobjects: Do not fill_pool() if pi_blocked_onInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-53339 i2c: qcom-cci: Fix NULL pointer dereference in cci_remove()Information published.MSRC.MICROSOFT.COM
9 JulCVE-2026-8927 env-set cross-proxy Digest auth state leakInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-56001 libXfont2 BitmapScaleBitmaps Integer Overflow Heap Buffer OverflowInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-56003 libXfont2 computeProps Property Buffer Heap Buffer OverflowInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-55999 xorg-server / xwayland glamor font atlas Heap Buffer OverflowInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-14191 WinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeaderInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-53269 netfilter: synproxy: add mutex to guard hook reference countingInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-47241 Net::IMAP: Denial of Service via incomplete raw argument validationInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-53167 fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate foliosInformation published.MSRC.MICROSOFT.COM
9 JulMicrosoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM PrivilegesMicrosoft has released security updates for a Defender vulnerability known as RoguePlanet, nearly a month after details of the flaw became public. The vulnerability, tracked as CVE-2026-50656 (CVSS score: 7.8), is a privilege escalation issue in the Microsoft Malware Protection E…THEHACKERNEWS.COM
9 JulMicrosoft Patches Defender ‘RoguePlanet’ VulnerabilityThe privilege escalation vulnerability tracked as CVE-2026-50656 has been patched with a Microsoft Malware Protection Engine update. The post Microsoft Patches Defender ‘RoguePlanet’ Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulMicrosoft fixed Defender flaw RoguePlanet (CVE-2026-50656)Microsoft fixed RoguePlanet (CVE-2026-50656), a Defender flaw allowing local attackers to gain higher privileges through the Malware Protection Engine. Microsoft released security updates for RoguePlanet, a vulnerability tracked as CVE-2026-50656 (CVSS score of 7.8) affecting the…SECURITYAFFAIRS.COM
9 JulVU#734812: Xerte Online Toolkit contains an authentication bypass that allows for RCEOverview Two vulnerabilities have been discovered in Xerte Online Toolkits, an open-source e-learning authoring toolsuite intended for the creation of learning materials within a web browser. CVE-2026-14261 tracks the persistence of the /setup/ directory after installation, which…KB.CERT.ORG
9 JulMicrosoft releases fix for RoguePlanet Defender flaw (CVE-2026-50656)Microsoft has finally released a security update for its Microsoft Malware Protection Engine, which fixes CVE-2026-50656, the Windows Defender local privilege escalation vulnerability triggered by the RoguePlanet exploit. The vulnerability and the fix CVE-2026-50656 is due to imp…HELPNETSECURITY.COM
9 JulVU#152953: PayRange Android app version 7.0.7 contains multiple vulnerabilitiesOverview PayRange is a mobile payment app that allows users to pay for vending machines, laundromats, and other unattended machines using a smartphone with Bluetooth. Two vulnerabilities were discovered in version 7.0.7 of the PayRange app that is available in the Google Play sto…KB.CERT.ORG
8 JulScattered Spider squashed, Rogue Agent AI flaw, 16 year-old Linux bug and new phish hunts marketersCybersecurity Today host David Shipley covers how a newly unsealed U.S. complaint tied an alleged Scattered Spider member to a luxury retailer intrusion using a persistent Windows device ID, with prosecutors alleging help-desk social engineering, admin account takeover, data exfi…CYBERSECURITYTODAY.LIBSYN.COM
8 Jul15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux DistrosResearchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a machine that has not been patched. The vulnerable code has shipped by default in essentially ever…THEHACKERNEWS.COM
8 JulUbiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OSUbiquiti has shipped updates to address multiple critical security flaws impacting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS that could result in privilege escalation and arbitrary command execution. The list of vulnerabilities is as follows - CVE-2026-…THEHACKERNEWS.COM
8 JulVU#849433: Adalo Database API Enables Cross-App User Data Extraction via Over-Fetching and Missing Authorization ControlsOverview Adalo’s no‑code application platform exposes complete user records through its database API for all applications built on both V1 and V2. Due to a platform-level flaw, authenticated users can retrieve full user data belonging to any Adalo application, regardless of confi…KB.CERT.ORG
8 JulUbiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege EscalationUbiquiti patched seven UniFi OS flaws, including critical CVE-2026-50746, which allows command injection in UniFi Connect Application. Ubiquiti released security updates for seven critical UniFi OS vulnerabilities, including a maximum-severity flaw, tracked as CVE-2026-50746 (CVS…SECURITYAFFAIRS.COM
7 JulInsignary Closes SBOM Accuracy Gap With Binary-Level Clarity for Regulatory RiskMost software composition analysis tools read what developers declare. Insignary Clarity’s patented binary-first platform analyzes what is actually built, shipped, and deployed — including the open-source components that never appear in any manifest. Insignary, Inc. , whose paten…CSOONLINE.COM
7 JulBeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRABeyondTrust has released updates to address two critical security flaws affecting Remote Support (RS) and Privileged Remote Access (PRA) products that, if successfully exploited, could allow unauthenticated attackers to take control of susceptible devices. The vulnerabilities are…THEHACKERNEWS.COM
7 JulCERT/CC Warns of Hidden Admin Backdoor in Tenda Router FirmwareSeveral versions of firmware released by Chinese network device manufacturer Tenda have been found to embed an undocumented authentication backdoor that enables administrative access to the devices' web management interfaces, the CERT Coordination Center (CERT/CC) warned Monday. …THEHACKERNEWS.COM
7 JulCVE-2026-8932 incomplete mTLS config matching in conn reuseInformation published.MSRC.MICROSOFT.COM
7 JulCVE-2026-55952 TLS 1.3 server denial of service via malformed ClientHello pre-shared key extensionInformation published.MSRC.MICROSOFT.COM
7 JulCVE-2026-54886 SSH SFTP server denial of service via extended channel data infinite loopInformation published.MSRC.MICROSOFT.COM
7 JulCVE-2026-12480 Arbitrary HDF5 File Read via Virtual Dataset Bypass in keras-team/kerasInformation published.MSRC.MICROSOFT.COM
7 JulCVE-2026-14647 onnx onnxruntime old.cc convPoolShapeInference_opset19 out-of-boundsInformation published.MSRC.MICROSOFT.COM
7 JulCVE-2026-54891 Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in sslInformation published.MSRC.MICROSOFT.COM
7 JulSuspected China-Aligned Hackers Exploit Roundcube Flaws Against UniversitiesA suspected China-aligned threat activity cluster has been observed exploiting Roundcube webmail software belonging to physics and engineering departments of U.S. and Canadian universities as part of a new campaign. The activity involves the exploitation of now-patched, critical …THEHACKERNEWS.COM
7 JulHP DeskJet 2800 printer zero-day flaw leaks Wi-Fi credentialsHP DeskJet 2800 series printers are affected by a newly disclosed vulnerability that allows anyone on the same network to access sensitive configuration data without authentication. The flaw, tracked as CVE-2026-13753, affects devices running firmware version TBP1CN2612AR or earl…CYBERINSIDER.COM
7 JulHidden Tenda Router Backdoor Grants Admin Access, No Patch AvailableCERT/CC warns an unpatched backdoor in several Tenda routers lets attackers bypass login and gain full admin access with a hidden password. CERT/CC published an alert documenting an undocumented authentication backdoor in multiple Tenda firmware versions, tracked as CVE-2026-1140…SECURITYAFFAIRS.COM
7 JulCritical Adobe ColdFusion Vulnerability Exploited in AttacksHackers are exploiting a recently patched critical vulnerability (CVE-2026-48282) in Adobe ColdFusion that carries a CVSS score of 10/10. The post Critical Adobe ColdFusion Vulnerability Exploited in Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
7 Jul KEVAttackers exploit critical Adobe ColdFusion vulnerability (CVE-2026-48282)CVE-2026-48282, one of the maximum severity vulnerabilities patched in Adobe ColdFusion on June 30, 2026, has been targeted by attackers in the wild. Exploitation attempts were detected on July 2, through the honeypot sensors of cybersecurity threat-intelligence service KEVIntel,…HELPNETSECURITY.COM
7 JulPicus Autonomous Exposure Validation Platform validates real-world CVE exploitabilityPicus Security has launched the Picus Autonomous Exposure Validation Platform, built for a world where frontier AI has collapsed the time between disclosure and attack. Adversaries now weaponize new CVEs in hours, against a backdrop of around 132 published every day. A CVE drops;…HELPNETSECURITY.COM
7 JulCVE-2026-45638 Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
7 JulCritical Gitea Flaw Under Active Exploitation, Researchers WarnAttackers are exploiting the critical Gitea vulnerability CVE-2026-20896 to bypass authentication with a single HTTP header and access vulnerable repositories and secrets. The post Critical Gitea Flaw Under Active Exploitation, Researchers Warn appeared first on SecurityWeek .SECURITYWEEK.COM
7 Jul16-year-old KVM flaw allows attackers to escape VMs and take over Linux serversA critical vulnerability in the Kernel-based Virtual Machine (KVM) module of the Linux kernel allows attackers with root access in a guest VM to execute arbitrary code on the host system. This violates the most important security boundary that cloud providers and enterprises rely…CSOONLINE.COM
7 JulCritical Gitea Docker Bug Under Active Exploitation Exposes Repositories and SecretsAttackers are exploiting a critical Gitea flaw (CVE-2026-20896) that bypasses authentication with a single HTTP header, exposing repositories and sensitive data. Sysdig researchers warn that attackers are actively exploiting a critical authentication bypass flaw, tracked as CVE-2…SECURITYAFFAIRS.COM
6 JulAI-Run Ransomware, New Oracle Critical Flaw, NetNut bustedAI-Run Ransomware, New Oracle 9.8 Flaw Exploited, NetNut Proxy Network Busted, and Pegasus Hits EU Spyware Investigator This episode covers researchers' report of "Jade Puffer," the first ransomware attack run end-to-end by an autonomous AI agent, which exploited a patched Langfl…CYBERSECURITYTODAY.LIBSYN.COM
6 JulBad Epoll Flaw Gives Attackers Root Access on Linux and AndroidBad Epoll (CVE-2026-46242) lets local attackers gain root on Linux and Android. The flaw was missed by AI but found by a security researcher. A newly disclosed Linux kernel vulnerability, named Bad Epoll (CVE-2026-46242), allows a local attacker with no special privileg…SECURITYAFFAIRS.COM
6 JulThis AI agent autonomously hacked a network, adapted on the fly, and demanded a ransomA fully autonomous AI agent conducted an end-to-end cyber intrusion and extortion campaign after exploiting a vulnerable Langflow server, demonstrating how large language models could accelerate ransomware operations, according to research published by Sysdig. Sysdig detailed the…CSOONLINE.COM
6 JulMax severity Adobe ColdFusion flaw now exploited in attacksAttackers are now exploiting a maximum-severity Adobe ColdFusion vulnerability tracked as CVE-2026-48282, the Canadian Center for Cyber Security (CCCS) warned on Thursday. [...]BLEEPINGCOMPUTER.COM
6 JulThreat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After DisclosureThreat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig. The vulnerability in question is CVE-2026-20896 (CVSS score: 9.8), a vulnerability that stems from the DevOps platform trusting the "X-WEB…THEHACKERNEWS.COM
6 JulVU#828543: HP Deskjet 2800 Printer Series Webservers contain Missing Authorization VulnerabilityOverview HP Printers in the Deskjet 2800 Series running firmware version <=TBP1CN2612AR contain a missing authorization vulnerability tracked as CVE-2026-13753. This vulnerability allows unauthenticated access to the printer's webserver API endpoints, exposing Wi-Fi credential…KB.CERT.ORG
6 Jul16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 SystemsA use-after-free bug in Linux's KVM hypervisor can be triggered from a guest virtual machine to corrupt the shadow-page state of the host kernel that runs it. Dubbed 'Januscape' and tracked as CVE-2026-53359, the flaw sits in the shadow MMU code that KVM shares across both I…THEHACKERNEWS.COM
6 JulVU#213560: Tenda firmware (multiple versions) contains hidden authentication backdoorOverview Several versions of Tenda firmware contain an undocumented authentication backdoor that grants administrative access to the devices' web management interfaces. An attacker can expoit this vulnerability, tracked as CVE-2026-11405, to bypass the password verification proce…KB.CERT.ORG
6 Jul KEVAdobe ColdFusion flaw CVE-2026-48282 now exploited in the wildAttackers are exploiting the critical Adobe ColdFusion flaw CVE-2026-48282, which allows remote code execution on unpatched servers. Attackers have started exploiting CVE-2026-48282, a maximum-severity vulnerability in Adobe ColdFusion. The flaw is a path traversal issue that cou…SECURITYAFFAIRS.COM
4 JulNew "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits AndroidA newly disclosed Linux kernel flaw called Bad Epoll (CVE-2026-46242) lets an ordinary user with no special access take full control of a machine as root. It affects Linux desktops, servers, and Android, and a fix is out. Bad Epoll sits in the same small stretch of kernel code wh…THEHACKERNEWS.COM
4 JulCVE-2026-53223 net: guard timestamp cmsgs to real error queue skbsInformation published.MSRC.MICROSOFT.COM
3 JulRansomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain CredentialsThreat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access. "Although tactics differ between affiliates, common patterns emerged in tradecraft through use of legitimate Remo…THEHACKERNEWS.COM
3 JulCVE-2026-56149 Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of ServiceInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-14258 Dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd option in router advertisement handlingInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-49090 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-53357 Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del()Information published.MSRC.MICROSOFT.COM
3 JulCVE-2026-53043 ocfs2/dlm: validate qr_numregions in dlm_match_regions()Information published.MSRC.MICROSOFT.COM
3 JulCVE-2026-52911 ksmbd: scope conn->binding slowpath to bound sessions onlyInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-53045 memory: tegra124-emc: Fix dll_change checkInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-53039 ocfs2: validate group add input before cachingInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-53046 ksmbd: fix use-after-free from async crypto on Qualcomm crypto engineInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-53048 gfs2: prevent NULL pointer dereference during unmountInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-12912 Libtiff: libtiff: heap-based buffer overflow via crafted pixarlog-compressed tiff imageInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-14164 Libarchive: double-free vulnerability in rar5 decompression logic via dangling filtered_buf pointer in init_unpack()Information published.MSRC.MICROSOFT.COM
3 JulCVE-2026-53195 USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr()Information published.MSRC.MICROSOFT.COM
3 JulCVE-2026-53052 ASoC: qcom: qdsp6: topology: check widget type before accessing dataInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-53098 wifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work()Information published.MSRC.MICROSOFT.COM
3 JulCVE-2026-52992 fs/adfs: validate nzones in adfs_validate_bblk()Information published.MSRC.MICROSOFT.COM
3 JulCVE-2026-53130 fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_STARTInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-53016 crypto: ccp - copy IV using skcipher ivsizeInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-52935 xfrm: espintcp: do not reuse an in-progress partial sendInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-52944 ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSEInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-4360 Tarfile.extract() doesn't fully respect filter parameterInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-13757 P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsingInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-57585 MessagePack: Out-of-bounds read/crash on Unpacker reuse after caught errorInformation published.MSRC.MICROSOFT.COM
3 Jul KEVNew CitrixBleed-like NetScaler flaw sees exploit attempts in the wildCitrix NetScaler appliances have been a constant target for attackers in recent years, most recently through an information leak vulnerability dubbed CitrixBleed 3, the latest in a series of NetScaler memory overreads going back to 2023. This week, Citrix patched yet another Citr…CSOONLINE.COM
3 JulAI helps find flaws in FatFs library used in millions of devicesResearchers at runZero have disclosed seven security vulnerabilities in the widely used FatFs filesystem library, warning that the flaws could expose millions of embedded devices to attacks through malicious USB drives, SD cards, and, in some cases, firmware update mechanisms. Th…CYBERINSIDER.COM
2 JulSandbox bypass flaws in Cursor IDE highlight prompt injection as an RCE vectorResearchers have discovered two vulnerabilities in the widely used Cursor AI-enabled integrated development environment (IDE) that can be exploited through prompt injection to achieve remote code execution (RCE). The two flaws, tracked as CVE-2026-50548 and CVE-2026-50549 , allow…CSOONLINE.COM
2 Jul KEVCISA Warns of Actively Exploited Microsoft SharePoint VulnerabilityCISA says threat actors are exploiting a recently patched SharePoint remote code execution vulnerability (CVE-2026-45659). The post CISA Warns of Actively Exploited Microsoft SharePoint Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
2 JulVU#639124: Multiple local privilege escalation vulnerabilities in Little Orbits GameFirst Anti-CheatOverview The GamersFirst Anti-Cheat (GFAC) driver GFAC.sys contains multiple local privilege escalations and denial-of-service vulnerabilities stemming from insecure handling of user-controlled input through a minifilter communication port. A local attacker can abuse these flaws …KB.CERT.ORG
2 JulAL26-015 - Critical vulnerability impacting Microsoft SharePoint Server – CVE-2026-45659CYBER.GC.CA
1 JulCitrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-ServiceCitrix on Tuesday released security updates to address multiple flaws in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) that could be exploited by an attacker to facilitate arbitrary file reads or trigger a denial-of-service (DoS) condition. T…THEHACKERNEWS.COM
1 JulCVE-2026-57062 CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.Information published.MSRC.MICROSOFT.COM
1 JulCVE-2026-42055 NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerabilityInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-48779 ws: Memory exhaustion DoS from tiny fragments and data chunksInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-58010 Glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal()Information published.MSRC.MICROSOFT.COM
1 JulCVE-2026-58015 Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receiveInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-58016 Glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"Information published.MSRC.MICROSOFT.COM
1 JulCVE-2026-58012 Glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char()Information published.MSRC.MICROSOFT.COM
1 JulCVE-2026-58011 Glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid gdatetimeInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-58013 Glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend"Information published.MSRC.MICROSOFT.COM
1 JulCVE-2026-58014 Glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list"Information published.MSRC.MICROSOFT.COM
1 JulCVE-2026-13322 Kubevirt: virt-handler-rhel9: kubevirt: unbounded virtio-serial readline in virt-handler causes oom denial of serviceInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-13208 Kubevirt: virt-handler-rhel9: kubevirt: virt-handler notify server trusts vmi identity from unauthenticated grpc request bodyInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-13218 Kubevirt: kubevirt: symlink following in writetocachedfile allows host file overwrite from virt-launcherInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-13325 Virt-handler-rhel9: kubevirt: kubevirt: disabletls migration setting removes authentication, exposing unauthenticated virtqemud proxy on all interfacesInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-57918 libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the xid/record-marker.Information published.MSRC.MICROSOFT.COM
1 JulCVE-2026-6291 Bleichenbacher padding oracle in PKCS#7 KTRI RSA PKCS#1 v1.5 decryptionInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-7532 iPAddress name constraints not enforced when WOLFSSL_IP_ALT_NAME is undefinedInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-6450 CRL critical extension bypass in ParseCRL_ExtensionsInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-55960 Un-negotiated Raw Public Key (RFC 7250) accepted in place of X.509, bypassing chain validationInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-55964 Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA (temporary CA exemption)Information published.MSRC.MICROSOFT.COM
1 JulCVE-2026-6329 PKCS#12 MAC verification uses attacker-controlled comparison lengthInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-55961 wolfSSL_PKCS7_verify() reports success for degenerate (certs-only) PKCS#7 with no signerInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-6678 Integer underflow in wc_PKCS7_DecryptOri handling crafted Other Recipient InfoInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-6094 Heap buffer overread in wc_PKCS7_DecodeEnvelopedData parsing crafted PKCS7 EnvelopedDataInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-6331 HMAC zero-length tag forgery in EVP_DigestVerifyFinalInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-6330 ML-KEM ARM64 NEON ciphertext comparison only compares half of the inputInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-6731 X.509 name constraint bypass via Subject CN treated as a DNS nameInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-55958 Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessageInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-6325 Out-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms listInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-10592 Wildcard DNS SAN bypasses CA name-constraint checksInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-10512 X25519 x86_64 assembly final reduction leaves non-canonical field elementInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-8720 HMAC-BLAKE2 final discards message when key length exceeds block sizeInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-10098 OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_statusInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-10097 ML-KEM-1024 x64 AVX2 incomplete cipher text comparison enables IND-CCA2 break and static private-key recoveryInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-11310 X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoringInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-13595 Util-linux: util-linux: heap use-after-free in libblkid nested partition probingInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-13318 Virt-api-rhel9: kubevirt: kubevirt: ssrf in virt-api port-forward via unvalidated guest-agent-reported ipInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-57231 Podman: Malformed Image can trick podman run into leaking host environment variables into the containerInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-11703 Missing SNI/ALPN binding on stateful (session-ID) TLS session resumptionInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-55967 AES-GCM streaming APIs do not reject >64 GiB cumulative single messages, enabling counter wrap and keystream reuseInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-55962 TLS 1.3 post-handshake authentication: server accepts Finished without client Certificate/CertificateVerifyInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-11999 X.509 trust-chain bypass via path-depth exhaustion in wolfSSL_X509_verify_cert()Information published.MSRC.MICROSOFT.COM
1 JulCVE-2026-7511 PKCS7_verify signer confusion allows forged signatures to be acceptedInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-6091 Partial-chain verification accepts untrusted intermediate as trust anchorInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-12340 Out-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computationInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-6092 Encrypt-then-MAC could fall back to MAC-then-Encrypt when HAVE_ENCRYPT_THEN_MAC is configuredInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-6412 Continued acceptance of SHA-1/MD5 digests in certificate processingInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-7531 Use-after-free in PQC hybrid key-share handlingInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-11625 Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processesInformation published.MSRC.MICROSOFT.COM
1 JulCISA Warns BlueHammer Flaw Is Now Exploited in Ransomware AttacksCISA confirms BlueHammer (CVE-2026-33825) is now used in ransomware attacks to gain SYSTEM privileges through Microsoft Defender. BlueHammer, tracked as CVE-2026-33825, has moved from proof-of-concept noise to real ransomware attacks in the wild, the US CISA confirms. BlueHammer …SECURITYAFFAIRS.COM
1 JulProgress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation AttemptsA recently disclosed critical security flaw impacting Progress Kemp LoadMaster is seeing active exploitation attempts, according to an advisory from eSentire's Threat Response Unit (TRU). The Canadian cybersecurity company said it identified exploitation attempts targeting CVE-20…THEHACKERNEWS.COM
1 JulCritical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run CommandsTwo flaws in Cursor, an AI code editor, could let a single, ordinary-looking prompt break out of the editor's safety sandbox and run any command on a developer's computer. There is no click to fall for and no approval box to ignore. Cato AI Labs found the pair and named them…THEHACKERNEWS.COM
1 Jul KEVOracle E-Business Suite Flaw Under Active Attack, 950 Systems ExposedOracle E-Business Suite flaw CVE-2026-46817 is under active attack, with about 950 vulnerable internet-facing instances still exposed. This week, Defused Cyber researchers warned that a critical vulnerability in Oracle E-Business Suite, tracked as CVE-2026-46817, is being activel…SECURITYAFFAIRS.COM
30 Jun KEVOracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the WildA critical security flaw impacting Oracle E-Business Suite has come under active exploitation in the wild, according to Defused Cyber. The vulnerability, tracked as CVE-2026-46817 (CVSS score: 9.8), refers to an improper privilege management and authentication flaw in Oracle Paym…THEHACKERNEWS.COM
30 JunApple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit BugsApple on Monday released security updates for iOS, macOS, and the Safari web browser to address over three dozen flaws, including four vulnerabilities in WebKit that were discovered using artificial intelligence (AI) tools like Anthropic Claude and OpenAI Codex Security. The WebK…THEHACKERNEWS.COM
30 JunCVE-2026-54369 acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl FunctionsInformation published.MSRC.MICROSOFT.COM
30 JunCVE-2026-54371 attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattrInformation published.MSRC.MICROSOFT.COM
30 JunCVE-2026-53325 agp/amd64: Fix broken error propagation in agp_amd64_probe()Information published.MSRC.MICROSOFT.COM
30 JunProgress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-AuthA critical vulnerability in Progress Kemp LoadMaster can let an unauthenticated attacker execute arbitrary commands as root on the appliance by sending a crafted request to its API. The flaw, tracked as CVE-2026-8037, carries a CVSS score of 9.8 according to ZDI. A patc…THEHACKERNEWS.COM
30 Jun KEVAttackers actively exploit the Oracle E-Business Suite flaw CVE-2026-46817Attackers are exploiting a critical flaw in Oracle E-Business Suite, CVE-2026-46817, that allows remote, unauthenticated attackers to take over Oracle Payments. A critical vulnerability in Oracle E-Business Suite, tracked as CVE-2026-46817, is being actively exploited in the wild…SECURITYAFFAIRS.COM
30 JunSimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558)Attackers are exploiting CVE-2026-48558, a recently patched authentication bypass vulnerability in SimpleHelp RMM, to drop the novel Djinn Stealer malware on victim computers. The malware is capable of targeting Windows, macOS, and Linux systems, and “collects credentials a…HELPNETSECURITY.COM
30 JunAttackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn StealerAn unknown threat actor has been observed exploiting a recently disclosed maximum-severity security flaw in SimpleHelp to deliver two previously unreported malware families, TaskWeaver and Djinn Stealer. The intrusion involves the exploitation of CVE-2026-48558 (CVSS score: 10.0)…THEHACKERNEWS.COM
30 Jun KEVBlueHammer Vulnerability Exploited in Ransomware AttacksThe Microsoft Defender vulnerability CVE-2026-33825 was exploited in the wild as a zero-day before patches were released. The post BlueHammer Vulnerability Exploited in Ransomware Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunOracle E-Business Suite Payments flaw under attack (CVE-2026-46817)Exploitation attempts targeting a critical vulnerability (CVE-2026-46817) in Oracle Payments, the payment-processing module within Oracle’s E-Business Suite (EBS), have been spotted over the weekend, threat intelligence company Defused warned on Monday. The detected exploit…HELPNETSECURITY.COM
30 JunCVE-2026-42910 Windows Hotpatch Monitoring Service Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
30 JunLangflow RCE Exploited to Deploy Monero Miner on Exposed AI App EndpointsThreat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner. The activity has been found to weaponize CVE-2026-33017 (CVSS score: 9.3), an unauthenticated remote code execution (RCE) vulnerab…THEHACKERNEWS.COM
30 JunCitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)Well, well, well - once again, the cat has dragged us in and spat us out. Today, we find ourselves questioning the reality we sit within. Must it be so predictable, and why us? “But watchTowr, what do you mean?” Well, if you’re here, you likely fitLABS.WATCHTOWR.COM
30 Jun KEVCitrix patches a new NetScaler flaw with echoes of CitrixBleedThe bulletin includes six NetScaler issues, but attention is centered on a high-severity flaw with similarities to earlier actively exploited bugs. The post Citrix patches a new NetScaler flaw with echoes of CitrixBleed appeared first on CyberScoop .CYBERSCOOP.COM
29 JunPublic PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH FlawA public proof-of-concept is now out for CVE-2026-55200, a critical flaw in libssh2 that lets a malicious or compromised SSH server trigger memory corruption on a connecting client, with possible code execution. No credentials, no user interaction. The bug affects every release u…THEHACKERNEWS.COM
29 JunCVE-2026-52910 bpf: Free reuseport cBPF prog after RCU grace period.Information published.MSRC.MICROSOFT.COM
29 JunCVE-2026-52908 RDMA: During rereg_mr ensure that REREG_ACCESS is compatibleInformation published.MSRC.MICROSOFT.COM
29 JunCVE-2026-58050 libssh2 - Integer Overflow in publickey Subsystem Attribute AllocationInformation published.MSRC.MICROSOFT.COM
29 JunCVE-2026-58051 libssh2 - Free of Uninitialized Pointer in publickey List CleanupInformation published.MSRC.MICROSOFT.COM
29 JunCVE-2026-58058 Nmap - Integer Underflow in IPv6 Extension Header ParsingInformation published.MSRC.MICROSOFT.COM
29 JunCVE-2026-52909 ip6_vti: set netns_immutable on the fallback device.Information published.MSRC.MICROSOFT.COM
29 JunCVE-2026-58055 nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-LengthInformation published.MSRC.MICROSOFT.COM
29 JunHackers now exploit critical Oracle E-Business flaw in attacksAttackers have begun exploiting a critical vulnerability (CVE-2026-46817) in the Oracle E-Business Suite (EBS) financial application, according to threat intelligence company Defused. [...]BLEEPINGCOMPUTER.COM
29 JunCritical SimpleHelp flaw exploited to deploy new stealer malwareHackers are exploiting a recently disclosed critical vulnerability (CVE-2026-48558) in SimpleHelp to deploy Djinn Stealer, a previously undocumented cross-platform information stealer targeting Windows, macOS, and Linux. [...]BLEEPINGCOMPUTER.COM
29 JunEnterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037)Welcome back to another watchTowr Labs blog post. This time, we're looking at Progress Kemp LoadMaster, a load balancer that sits at the edge of a lot of enterprise networks. Edge appliances have a habit of becoming the way in rather than the thing keeping people out, andLABS.WATCHTOWR.COM
29 Jun'Djinn' Stealer Targets Cloud, AI CredentialsThe infostealer was delivered via CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp, targeting credentials linking development and admin environments to wider enterprise systems.DARKREADING.COM
28 JunCVE-2026-46245 drm/amd/display: Fix dc_link NULL handling in HPD initInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-46252 regulator: core: fix locking in regulator_resolve_supply() error pathInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-46244 netfilter: nft_inner: Fix IPv6 inner_thoff desyncInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-12003 CPython >3.11 Insecure Input Validation resulting in privilege escalationInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52953 iommu/vt-d: Fix oops due to out of scope accessInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-56405 libexpat before 2.8.2 has an integer overflow in getAttributeId.Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53005 af_unix: Drop all SCM attributes for SOCKMAP.Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53239 xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52912 netfilter: nf_queue: hold bridge skb->dev while queuedInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-55653 Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of serviceInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-56406 libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52931 batman-adv: tp_meter: avoid use of uninit sender varsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-55655 Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client versionsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53147 thunderbolt: Validate XDomain request packet size before type castInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-9675 undici WebSocket client vulnerable to denial of service via cumulative fragment bypassInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53159 misc: fastrpc: fix DMA address corruption due to find_vma misuseInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-56131 libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53274 net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoSInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52915 netfilter: ip6t_hbh: reject oversized option listsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-9697 undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgentInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53230 net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_listInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52956 libceph: Fix potential out-of-bounds access in __ceph_x_decrypt()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53194 USB: serial: kl5kusb105: fix bulk-out buffer overflowInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53115 bus: fsl-mc: use generic driver_override infrastructureInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53161 misc: fastrpc: fix use-after-free of fastrpc_user in workqueue contextInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53163 locking/rtmutex: Skip remove_waiter() when waiter is not enqueuedInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53254 Bluetooth: RFCOMM: validate skb length in MCC handlersInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52916 batman-adv: frag: disallow unicast fragment in fragmentInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53017 f2fs: fix data loss caused by incorrect use of nat_entry flagInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53089 bpf: Fix use-after-free in offloaded map/prog info fillInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53158 misc: fastrpc: Fix NULL pointer dereference in rpmsg callbackInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53120 PCI: use generic driver_override infrastructureInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53151 rxrpc: Fix the ACK parser to extract the SACK table for parsingInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52934 batman-adv: tvlv: reject oversized TVLV packetsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53267 netfilter: nft_ct: bail out on template ct in get evalInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53249 ipv4: restrict IPOPT_SSRR and IPOPT_LSRR optionsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52943 net: skbuff: fix missing zerocopy reference in pskb_carve helpersInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53139 drm/v3d: Skip CSD when it has zeroed workgroupsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52942 netfilter: nf_log: validate MAC header was set before dumping itInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52957 libceph: Fix potential null-ptr-deref in decode_choose_args()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53131 netfilter: require Ethernet MAC header before using eth_hdr()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53198 ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCELInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53214 ipv6: Fix a potential NPD in cleanup_prefix_route()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53218 netfilter: nft_exthdr: fix register tracking for F_PRESENT flagInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53097 wifi: mt76: mt7996: fix use-after-free bugs in mt7996_mac_dump_work()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53107 wifi: libertas: don't kill URBs in interrupt contextInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53166 futex/requeue: Prevent NULL pointer dereference in remove_waiter() on self-deadlockInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53179 staging: rtl8723bs: fix buffer over-read in rtw_update_protectionInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53228 ipv6: sit: reload inner IPv6 header after GSO offloadsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53132 vsock/virtio: fix potential unbounded skb queueInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52961 ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob sizeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53208 Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsigInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53010 ksmbd: fix use-after-free in smb2_open during durable reconnectInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52937 tap: fix stack info leak in tap_ioctl() SIOCGIFHWADDRInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53109 powerpc/pgtable-frag: Fix bad page state in pte_frag_destroyInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53106 bpf: Do not allow deleting local storage in NMIInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53217 net: mvpp2: sync RX data at the hardware packet offsetInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53186 RDMA/srp: bound SRP_RSP sense copy by the received lengthInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53268 netfilter: conntrack_irc: fix possible out-of-bounds readInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53053 iommu/amd: Fix clone_alias() to use the original device's devidInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52926 batman-adv: clear current gateway during teardownInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52927 netfilter: ebtables: fix OOB read in compat_mtw_from_userInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53219 netfilter: x_tables: avoid leaking percpu counter pointersInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53157 net: phonet: free phonet_device after RCU grace periodInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53102 wifi: mt76: Fix memory leak after mt76_connac_mcu_alloc_sta_req()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53247 net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardownInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-57452 Vim: Out-of-bounds Read with libsodium-encrypted FilesInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-55895 Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filenameInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53221 ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-55693 Vim: Out-of-bounds Write in Spell File Word CountInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53253 Bluetooth: bnep: reject short frames before parsingInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53196 USB: serial: io_ti: fix heap overflow in get_manuf_info()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-57455 Vim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length `soundfold()` argumentInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53025 greybus: raw: fix use-after-free on cdev closeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-57456 Vim: Arbitrary Code Execution via Python Omni-Completion DocstringsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-57453 Vim: PowerShell Command Injection via Unescaped Filename in zip.vim ExtractionInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53215 net: mvpp2: refill RX buffers before XDP or skb useInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-55892 Vim: Out-of-bounds Write in Spell File Prefix DumpInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53154 mm/hugetlb: restore reservation on error in hugetlb folio copy pathsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52941 net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepointInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53263 6lowpan: fix off-by-one in multicast context address compressionInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52947 net: qrtr: fix refcount saturation and potential UAF in qrtr_port_removeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52991 sched/psi: fix race between file release and pressure writeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52988 netfilter: nf_tables: join hook list via splice_list_rcu() in commit phaseInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-57454 Vim: Out-of-bounds Read with Text PropertiesInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-46243 smb: client: reject userspace cifs.spnego descriptionsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-46254 AppArmor: Allow apparmor to handle unaligned dfa tablesInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2025-71313 PCI: endpoint: Add missing NULL check for alloc_workqueue()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-43973 gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustionInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52948 i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctlInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53136 drm/amd/display: Clamp VBIOS HDMI retimer register count to array sizeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53227 net: openvswitch: fix possible kfree_skb of ERR_PTRInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-56407 libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-56404 libexpat before 2.8.2 has an integer overflow in addBinding.Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53207 mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoisonInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52913 batman-adv: v: stop OGMv2 on disabled interfaceInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53027 fs/ntfs3: fix missing run load for vcn0 in attr_data_get_block_locked()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-56403 libexpat before 2.8.2 has an integer overflow in storeAtts.Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53238 netlabel: validate unlabeled address and mask attribute lengthsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52921 netfilter: ipset: stop hash:* range iteration at endInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53024 greybus: raw: fix use-after-free if write is called after disconnectInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53270 ipvs: clear the svc scheduler ptr early on editInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-11525 undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matchingInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-56132 In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53129 fs/mbcache: cancel shrink work before destroying the cacheInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-48142 NGINX ngx_http_charset_module vulnerabilityInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53242 ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streamsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53236 tcp: restrict SO_ATTACH_FILTER to priv usersInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53118 vdpa: use generic driver_override infrastructureInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-56412 libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53266 netfilter: bridge: make ebt_snat ARP rewrite writableInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53138 drm/amd/display: Bound VBIOS record-chain walk loopsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53146 thunderbolt: Limit XDomain response copy to actual frame sizeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53264 net/sched: act_api: use RCU with deferred freeing for action lifecycleInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-3195 Qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb (incomplete fix for cve-2024-7730)Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-3196 Qemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocationInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53182 wifi: nl80211: reject oversized EMA RNR listsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-11972 tarfile opened in streaming mode mishandles EOFInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52924 sctp: purge outqueue on stale COOKIE-ECHO handlingInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-0864 Configuration Injection via Carriage Return (\r) in write() methodInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-55199 libssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO HandlerInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-55200 libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.cInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53246 sctp: validate cached peer INIT chunk length in COOKIE_ECHO processingInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53150 thunderbolt: Reject zero-length property entries in validatorInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53149 thunderbolt: Bound root directory content to block sizeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53181 vsock/vmci: fix sk_ack_backlog leak on failed handshakeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53018 f2fs: avoid reading already updated pages during GCInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2025-15661 libssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.cInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53184 udp: clear skb->dev before running a sockmap verdictInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52923 ipc: limit next_id allocation to the valid ID rangeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53178 staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtractionInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53143 drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53209 Bluetooth: hci_sync: reject oversized Broadcast Announcement prependInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53275 ipv6: mcast: Fix use-after-free when processing MLD queriesInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53192 ALSA: timer: Fix UAF at snd_timer_user_params()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52960 ceph: put folios not suitable for writebackInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53133 RDMA/umem: Fix truncation for block sizes >= 4GInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52919 batman-adv: fix tp_meter counter underflow during shutdownInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53078 bpf: Fix same-register dst/src OOB read and pointer leak in sock_opsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52946 fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signalingInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53255 Bluetooth: MGMT: validate advertising TLV before type checksInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53113 wifi: ath11k: fix memory leaks in beacon template setupInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53015 erofs: unify lcn as u64 for 32-bit platformsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53265 dm cache policy smq: check allocation under invalidate lockInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52922 batman-adv: dat: handle forward allocation errorInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53237 gpio: mvebu: fix NULL pointer dereference in suspend/resumeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52954 libceph: handle rbtree insertion error in decode_choose_args()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53148 thunderbolt: Clamp XDomain response data copy to allocation sizeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53000 netfilter: nat: use kfree_rcu to release opsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53225 sctp: fix uninit-value in __sctp_rcv_asconf_lookup()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53262 l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53245 net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattrInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53199 hv_netvsc: use kmap_local_page in netvsc_copy_to_send_bufInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53258 wifi: fix leak if split 6 GHz scanning failsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53160 misc: fastrpc: fix use-after-free race in fastrpc_map_createInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53226 gpio: rockchip: fix generic IRQ chip leak on removeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52930 ipc/shm: serialize orphan cleanup with shm_nattch updatesInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53135 drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53080 net/sched: cls_fw: fix NULL dereference of "old" filters before change()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53108 powerpc/64s: Fix unmap race with PMD migration entriesInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53091 net: pull headers in qdisc_pkt_len_segs_init()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53232 net: phy: clean the sfp upstream if phy probing failsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52962 ceph: fix a buffer leak in __ceph_setxattr()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53176 IB/isert: Reject login PDUs shorter than ISER_HEADERS_LENInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53070 sctp: disable BH before calling udp_tunnel_xmit_skb()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53156 nvmem: core: fix use-after-free bugs in error pathsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-57451 Vim: Out-of-bounds Read in Text Property CountInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53252 Bluetooth: fix memory leak in error path of hci_alloc_dev()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53320 nilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53296 mailbox: mailbox-test: free channels on probe errorInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53292 net: phonet: do not BUG_ON() in pn_socket_autobind() on failed bindInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53284 btrfs: only release the dirty pages io tree after successful writesInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53309 ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparisonInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53304 scsi: sg: Resolve soft lockup issue when opening /dev/sgXInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53313 drm/amd/display: Avoid NULL dereference in dc_dmub_srv error pathsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53306 tty: hvc_iucv: fix off-by-one in number of supported devicesInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53291 ALSA: hda/conexant: Fix missing error check for jack detectionInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53297 net: mana: Guard mana_remove against double invocationInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53293 drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REGInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53294 mailbox: mailbox-test: don't free the reused channelInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53289 ice: fix NULL pointer dereference in ice_reset_all_vfs()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53287 audit: fix incorrect inheritable capability in CAPSET recordsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53303 f2fs: protect extension_list reading with sb_lock in f2fs_sbi_show()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53314 padata: Put CPU offline callback in ONLINE section to allow failureInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-44889 WebOb: Location header normalization during redirect leads to open redirectInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53295 mailbox: add sanity check for channel arrayInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53279 drm/gma500/oaktrail_lvds: fix hang on init failureInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53655 node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)Information published.MSRC.MICROSOFT.COM
28 JunCVE-2024-42123 drm/amdgpu: fix double free err_addr pointer warningsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-42155 s390/pkey: Wipe copies of protected- and secure-keysInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-42227 drm/amd/display: Fix overlapping copy within dml_core_mode_programmingInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-41085 cxl/mem: Fix no cxl_nvd during pmem region auto-assemblingInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-42158 s390/pkey: Use kfree_sensitive() to fix Coccinelle warningsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-58012 ASoC: SOF: Intel: hda-dai: Ensure DAI widget is valid during paramsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-50225 btrfs: fix error propagation of split biosInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-53056 drm/mediatek: Fix potential NULL dereference in mtk_crtc_destroy()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2024-53084 drm/imagination: Break an object reference loopInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-50091 dm vdo: don't refer to dedupe_context after releasing itInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-50090 drm/xe/oa: Fix overflow in oa batch bufferInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-50102 x86: fix user address masking non-canonical speculation issueInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-50178 cpufreq: loongson3: Use raw_smp_processor_id() in do_service_request()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2024-53051 drm/i915/hdcp: Add encoder check in intel_hdcp_get_capabilityInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-27010 net/sched: Fix mirred deadlock on device recursionInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-26962 dm-raid456, md/raid456: fix a deadlock for dm-raid456 while io concurrent with reshapeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-27079 iommu/vt-d: Fix NULL domain on device releaseInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-53187 io_uring: check for overflows in io_pin_pagesInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-56544 udmabuf: change folios array from kmalloc to kvmallocInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-56702 bpf: Mark raw_tp arguments with PTR_MAYBE_NULLInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-56742 vfio/mlx5: Fix an unwind issue in mlx5vf_add_migration_pages()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2024-49908 drm/amd/display: Add null check for 'afb' in amdgpu_dm_update_cursor (v2)Information published.MSRC.MICROSOFT.COM
28 JunCVE-2024-49918 drm/amd/display: Add null check for head_pipe in dcn32_acquire_idle_pipe_for_head_pipe_in_layerInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-49990 drm/xe/hdcp: Check GSC structure validityInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-47703 bpf, lsm: Add check for BPF LSM return valueInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-49910 drm/amd/display: Add NULL check for function pointer in dcn401_set_output_transfer_funcInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-49916 drm/amd/display: Add NULL check for clk_mgr and clk_mgr->funcs in dcn401_init_hwInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-49970 drm/amd/display: Implement bounds check for stream encoder creation in DCN401Information published.MSRC.MICROSOFT.COM
28 JunCVE-2024-50004 drm/amd/display: update DML2 policy EnhancedPrefetchScheduleAccelerationFinal DCN35Information published.MSRC.MICROSOFT.COM
28 JunCVE-2024-46681 pktgen: use cpus_read_lock() in pg_net_init()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2024-46701 libfs: fix infinite directory reads for offset dirInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-46775 drm/amd/display: Validate function returnsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-44956 drm/xe/preempt_fence: enlarge the fence critical sectionInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-46698 video/aperture: optionally match the device in sysfb_disable()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2024-46778 drm/amd/display: Check UnboundedRequestEnabled's valueInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-46808 drm/amd/display: Add missing NULL pointer check within dpcd_extend_address_rangeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-46842 scsi: lpfc: Handle mailbox timeouts in lpfc_get_sfp_infoInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2025-4035 Libsoup: cookie domain validation bypass via uppercase characters in libsoupInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-43886 drm/amd/display: Add null check in resource_log_pipe_topology_updateInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-43824 PCI: endpoint: pci-epf-test: Make use of cached 'epc_features' in pci_epf_test_core_init()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2023-6606 Kernel: out-of-bounds read vulnerability in smbcalcsizeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2025-21833 iommu/vt-d: Avoid use of NULL after WARN_ON_ONCEInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2025-40213 Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_completeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-0989 Libxml2: unbounded relaxng include recursion leading to stack overflowInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2025-68304 Bluetooth: hci_core: lookup hci_conn on RX path on protocol sideInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-24864 Race condition vulnerability in Linux kernel media/dvb-core in dvbdmx_write()Information published.MSRC.MICROSOFT.COM
27 JunBypassing Windows authentication reflection mitigations for SYSTEM shells - Part ②In part 1 of this blogpost series, we proved our initial theory that the patch for CVE-2025-33073 was insufficient, by disclosing a trivial NTLM reflection vulnerability leading to LPE. In this second part, we turn to Kerberos and explain how we achieved a full-blown RCE primitiv…SYNACKTIV.COM
27 JunBypassing Windows authentication reflection mitigations for SYSTEM shells - Part 1A year ago, authentication reflection vulnerabilities resurfaced as a powerful attack vector through the discovery of CVE-2025-33073 by several security researchers, including us. This logical vulnerability allowed taking over almost any Windows machine without any user interacti…SYNACKTIV.COM
27 JunPaint it blue: Attacking the bluetooth stackBluetooth has always been an attractive target to attackers since it is present almost everywhere (TV, automotive charger, connected fridge, etc.). This is especially true on mobile devices, as it runs as a privileged process with a potential access to microphone, address book, e…SYNACKTIV.COM
27 JunSniffing Authentication References on macOSCVE-2017-7170 was a local priv-esc vulnerability that affected OSX/macOS for over a decade! Here (for the first time!), we dive into the technical details of finding the bug, the core flaw, and exploitation.OBJECTIVE-SEE.ORG
27 JunRootpipe Reborn (Part II)@CodeColorist continues writing about bugs, such as CVE-2019-8521 and CVE-2019-8565 that provide a mechanism to elevate privileges to root on macOS.OBJECTIVE-SEE.ORG
27 JunFrom the Top to the Bottom; Tracking down CVE-2017-7149High Sierra suffered from a nasty bug (CVE-2017-7149) that afforded local attackers access to the contents of encrypted APFS volumes.OBJECTIVE-SEE.ORG
27 JunCVE-2015-3673: Goodbye Rootpipe...(for now?)Details on bypassing Apple's original rootpipe patchOBJECTIVE-SEE.ORG
27 JunDirtyClone: Fourth Linux Kernel Flaw in Six Weeks Escalates to RootDirtyClone: a Linux kernel privilege escalation that silently rewrites executables in memory, leaving no disk trace. Patch now. JFrog Security Research published a working exploit walkthrough on June 25 for CVE-2026-43503 (CVSS score of 8.8), a Linux kernel privilege escalation t…SECURITYAFFAIRS.COM
26 JunCVE-2026-4367 Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsingInformation published.MSRC.MICROSOFT.COM
26 JunSynology issues critical fix for MailPlus Server vulnerabilitiesSynology has has fixed critical vulnerabilities in MailPlus Server, a software package used to run private email infrastructure on Synology NAS devices. The security update fixes three flaws: CVE-2026-13136, stemming from faulty authorization checks, may allow remote attackers to…HELPNETSECURITY.COM
26 JunNew DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned PacketsDirtyClone is a new Linux kernel privilege escalation in the DirtyFrag family. JFrog Security Research published a working exploit walkthrough for the flaw on June 25, the first public demonstration for this variant. Tracked as CVE-2026-43503 (CVSS 8.8), it le…THEHACKERNEWS.COM
26 JunNew Linux pedit COW Exploit Enables Root Access by Poisoning Cached BinariesA flaw in the Linux kernel's traffic-control subsystem can let a local unprivileged user gain root on affected systems. CVE-2026-46331, nicknamed "pedit COW," is an out-of-bounds write in the packet-editing action (act_pedit) that corrupts shared page-cache memory. A public,…THEHACKERNEWS.COM
26 JunAmazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP ConfigsA high-severity flaw in Amazon Q Developer let a malicious repository run commands and steal a developer's cloud credentials. The path was short: a developer opens the repo, trusts the workspace, and Amazon Q does the rest. Amazon has patched it. Tracked as CVE-2026-12957&nb…THEHACKERNEWS.COM
26 JunChromium: CVE-2026-13027 Use after free in FileSystemThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13026 Use after free in Digital CredentialsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13025 Insufficient validation of untrusted input in DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13024 Insufficient validation of untrusted input in NavigationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13023 Uninitialized Use in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13022 Inappropriate implementation in AutofillThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13021 Inappropriate implementation in DeviceBoundSessionCredentialsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13036 Use after free in BlinkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13035 Use after free in BluetoothThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13034 Inappropriate implementation in PasswordsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13033 Out of bounds read in Blink>InterestGroupsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13031 Use after free in BlinkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13029 Use after free in Web AuthenticationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13038 Use after free in AutofillThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 Jun KEVHackers exploit critical PTC Windchill PLM software flawHackers are exploiting a critical vulnerability recently patched in PTC Windchill and FlexPLM, two product lifecycle management solutions used by organizations across a range of industries, including defense, aerospace, automotive, medical, electronics, industrial machinery, and …CSOONLINE.COM
25 JunCisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root AccessAn unknown threat actor exploited a recently disclosed high-severity security flaw impacting Cisco Catalyst SD-WAN as a zero-day at least two months before it was publicly disclosed, according to new findings from Google-owned Mandiant. The vulnerability, tracked as CVE-2026-2024…THEHACKERNEWS.COM
25 JunCVE-2026-45637 Microsoft DWM Core Library Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
25 JunCVE-2026-46140 Bluetooth: btmtk: validate WMT event SKB length before struct accessInformation published.MSRC.MICROSOFT.COM
25 JunWhy patch directives only go so farSix weeks of undetected access through a compromised VPN exposes why patching isn't a solution for the organizations already breached. The post Why patch directives only go so far appeared first on CyberScoop .CYBERSCOOP.COM
25 JunLantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat WarningThe exploited flaw, CVE-2025-67038, is one of the vulnerabilities disclosed in April as part of the BRIDGE:BREAK research project. The post Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning appeared first on SecurityWeek .SECURITYWEEK.COM
⚠️ VULNERABILITY DISCLOSURE 2506[−]
23 SepAI malware just removed the human from the attack loopAttackers using AI have greatly benefited when it comes to speed and scale, and now, says Cisco Talos, the technology has evolved to execute large portions of the attack chain entirely without human involvement. Researchers at the threat intelligence group have identified what th…CSOONLINE.COM
23 SepPrismor: Open-source runtime control plane for AI agentsPrismor is a free, open-source security layer for AI coding agents. It sits between an agent such as Claude Code, Codex, or Cursor and the actions that agent wants to take, and it checks each tool call against a policy before the call runs. Every call gets one of three verdicts: …HELPNETSECURITY.COM
23 SepWeekly Update 522: Live From Oslo with Scott HelmePresently sponsored by: SACR's Endpoint Control and Prevention report, live Oct 1 with its author and Origin's founder, deep on endpoint AI observability. Register. Heads up: the first 7 mins is a bit quiet until we worked out the external mic was misbehaving - sorry! But get thr…TROYHUNT.COM
23 SepCheck Point Patches Exploited Management Server Zero-DayThe critical-severity flaw could allow unauthenticated attackers to upload and execute arbitrary scripts. The post Check Point Patches Exploited Management Server Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
23 SepCritical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG InputA new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The risk applies when an app puts values an attacker controls, such as text read from …THEHACKERNEWS.COM
23 SepF5 patches BIG-IP APM zero-day flaw exploited in RCE attacksF5 has released security updates to address a critical BIG-IP APM zero-day vulnerability being exploited in remote code execution attacks. [...]BLEEPINGCOMPUTER.COM
23 SepCritical F5 BIG-IP Vulnerability Exploited as Zero-DayUnauthenticated attackers could send malicious traffic to BIG-IP to achieve remote code execution. The post Critical F5 BIG-IP Vulnerability Exploited as Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
23 SepOkta bets on identity to control AI agents, but is identity enough?Concerns over agentic risks are rising, and identity and access management (IAM) giant Okta believes it’s making the moves of a would-be leader in this emerging cyber market. “Identity is the primary control plane for securing AI,” said Okta CEO and co-founder Todd McKinnon in an…CSOONLINE.COM
23 SepArista Urges Immediate Patching of Exploited VCO Zero-DayRemote attackers could trigger the critical-severity flaw to access privileged internal functionality. The post Arista Urges Immediate Patching of Exploited VCO Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
23 SepMicrosoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxesThe EvilTokens phishing service, which compromised more than 12,000 inboxes at over 10,000 organizations, has been disrupted by a coalition of law enforcement and private-sector partners led by Microsoft. With authorization from the US District Court for the Eastern District of V…HELPNETSECURITY.COM
23 SepShinyHunters Claims FBI Hack Via PeopleSoft Zero DayInfamous threat group ShinyHunters claims to have personal information on thousands of FBI employeesINFOSECURITY-MAGAZINE.COM
23 SepResearch on Models Engaging in Genie-Like BehaviorNew paper: “ Self-Jailbreaking: Language Models Can Reason Themselves Out of Safety Alignment After Benign Reasoning Training .” Abstract: We discover a novel and surprising phenomenon of unintentional misalignment in reasoning language models (RLMs), which we call se…SCHNEIER.COM
23 SepAdobe Patches Critical Flaws in Connect, AEM FormsThe nine critical security defects could be exploited for arbitrary code execution and privilege escalation. The post Adobe Patches Critical Flaws in Connect, AEM Forms appeared first on SecurityWeek .SECURITYWEEK.COM
23 SepEvilTokens made phishing-as-a-service look easy. Then it got taken downMicrosoft, Coinbase and law enforcement took down EvilTokens, a phishing kit that compromised 12,000 inboxes through device-code phishing and AI. EvilTokens showed up in February 2026 and moved fast. Within months it had compromised more than 12,000 inboxes across over 10,000 org…SECURITYAFFAIRS.COM
23 SepMeta’s Muse AI Assistant Rolled Out With a Serious Security FlawMeta says it issued a fix for the Muse zero-day vulnerability that would have let attackers do “whatever” they wanted on a victim’s Mac, highlighting the inherent dangers of AI helpers.WIRED.COM
23 Sep KEVArista patches actively exploited VeloCloud Orchestrator zero-dayArista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments. [...]BLEEPINGCOMPUTER.COM
23 SepPortnox detects and removes unauthorized AI applications from managed devicesPortnox has announced new capabilities to detect unauthorized AI applications and agents on managed devices and automatically enforce security policy, restricting, quarantining, or removing unapproved or risky applications the moment they’re detected. The capability address…HELPNETSECURITY.COM
23 SepNetwork Solutions Dark Web Monitoring alerts small businesses to domain-linked data exposureNetwork Solutions has launched Dark Web Monitoring, a new security capability that alerts small businesses when information associated with their domain appears in known breach data and provides steps they can take to reduce risk. Stolen credentials and other information exposed …HELPNETSECURITY.COM
23 SepDarkMe RAT trades zero-days for plain phishing emailsDarkMe, a remote access trojan and info-stealer that has previously been associated with a threat group that targeted financial market traders and cryptocurrency users, has been spotted again. This time around, its distribution has been simplified: instead of leveraging zero-day …HELPNETSECURITY.COM
23 SepBarracuda brings AI security and governance within reach of smaller organizationsBarracuda Networks has launched Barracuda AI Data Security, the AI security and governance solution purpose-built for resource-constrained organizations and managed service providers (MSPs). The solution enables businesses to accelerate AI adoption by protecting sensitive data, e…HELPNETSECURITY.COM
23 Sep KEVInfraTrust report warns network management systems under attackAttackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them. [...]BLEEPINGCOMPUTER.COM
23 SepHow One Kubernetes YAML Can Hand Over a GCP OrganizationA Kubernetes user with limited permissions can potentially gain control of an entire Google Cloud organization by exploiting the authority granted to Google Kubernetes Config Connector. Varonis explains how this confused deputy problem can turn a single Kubernetes YAML file into …BLEEPINGCOMPUTER.COM
23 SepHow dynamic application security testing validates risk at runtimeSecurity teams already have long queues of potential application vulnerabilities. The useful question is what happens next: can they see how a weakness behaves in a running application, reproduce the attack, and give developers enough evidence to fix it? Dynamic application secur…RAPID7.COM
23 SepThe EU spent billions on a cyberattack shield — nobody checked if it workedThe EU built an early-warning system to catch the next major cyberattack before it spreads. Roughly 20 months later, auditors have found it still is not fully switched on. Jonathan Bent reports: Brussels has allocated €1.4 billion to defending Europe from cyberattacks. Its own au…DATABREACHES.NET
23 SepShinyHunters claims FBI breach after alleged PeopleSoft zero-day attackShinyHunters claims FBI breach via PeopleSoft zero-day, steals staff data; FBI investigating, no confirmation yet. The popular cybercrime group ShinyHunters is claiming that it breached the U.S. Federal Bureau of Investigation (FBI) and stole sensitive information belonging to FB…SECURITYAFFAIRS.COM
23 SepRyuk Ransomware Operator Sentenced to 24 Months in PrisonAbinaya reports: An Armenian national extradited from Ukraine to the United States has been sentenced to federal prison for his role in Ryuk ransomware attacks that targeted organizations worldwide, including a company in Oregon. Karen Vardanyan, 35, received a 24-month federal p…DATABREACHES.NET
23 SepLatvia arrests suspected hacker for electronics repair company breachDaryna Antoniuk reports: Latvian police arrested a 23-year-old man suspected of hacking at least two companies, stealing personal information and attempting to extort money from the victims, authorities said Wednesday. The first attack was detected in February, while a second — u…DATABREACHES.NET
23 SepMalicious AI agents steal 600K credit cards, infect 100+ sites with skimmersA financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records. [...]BLEEPINGCOMPUTER.COM
23 SepThe AI Vulnerability That Isn’t AIPlugin4Shell affected plugin installation mechanisms in several AI coding tools. Air Security says the flaw could allow an attacker to bypass the expected plugin version and install something else. The incident is a reminder that AI products still depend on ordinary software comp…YOUTUBE.COM
23 SepPentagon cyber chief: The demand far exceeds supplyAt DefenseTalks on Tuesday, Katie Sutton said the Pentagon now receives far more requests to use cyber operations than its forces can fulfill, eight years after gaining that authority. The post Pentagon cyber chief: The demand far exceeds supply appeared first on CyberScoop .CYBERSCOOP.COM
23 SepAttackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp RegistryCybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads. According to Aikido…THEHACKERNEWS.COM
23 SepNo evidence of successful foreign meddling in 2024 election, spy agencies foundU.S. intelligence officials found no evidence that any foreign adversary successfully interfered in the 2024 presidential election, according to sources familiar with the findings of a classified assessment.THERECORD.MEDIA
23 SepThe hunters go after the bureau.ShinyHunters claims to have breached FBI systems. CLOSEDQUORUM malware delegates command-and-control decisions to commercial LLMs. An IT error erases 11 years of hospital maternity data. F5 patches a critical BIG-IP APM zero-day. Ransomware activity remains high. Microsoft disrup…THECYBERWIRE.COM
23 SepCanva hacked via vendor’s Salesforce instance; Other customers affected as wellA new dedicated leak site by threat actors calling themselves “The Seven Deadly Sins” lists Canva Pty Ltd among the sites that haven’t paid them. DataBreaches obtained additional details on the incident and this new group. Attack on Canva A spokesperson for The …DATABREACHES.NET
22 SepGemini broke into 3 companies, but Google kept it quiet because ‘no damage was done’A Google Gemini AI agent broke into three companies in July, guessing the credentials for one and discovering the credentials for the second two in a public repository, Google confirmed on Monday. But the more interesting background to the story, which was broken by The Wall Stre…CSOONLINE.COM
22 SepOne Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a BackdoorMalware already running on a Mac can quietly take over Meta's Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21. It works by changing a hidden setting so that wh…THEHACKERNEWS.COM
22 SepThe cyber AI parity window now has a deadlineIn April, I wrote about what I called the Cyber AI Parity Window . This is the rare period in which defenders and adversaries gained access to the same transformative technology at roughly the same moment. For most of cybersecurity history, advanced offensive capability reached a…CSOONLINE.COM
22 SepCISOs can no longer ignore the nation-state threatFlare-ups between US intelligence agencies and private-sector defenders have long been a characteristic of the cybersecurity landscape, with the balance swinging between deep collaboration and friction. The goal of CISOs has typically been to get adversaries out of networks as qu…CSOONLINE.COM
22 SepCISA orders feds to patch Zyxel flaw exploited for data theftAttackers are now actively exploiting a high-severity vulnerability in Zyxel GS1900 series switches, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...]BLEEPINGCOMPUTER.COM
22 SepUnderstanding Prompt Injection In Order to Contain It - Julie Brunias - ASW #401Prompt injection demonstrates one of the major challenges in securing LLMs and agents -- how do you ensure an agent ignores attackers and only does what you instructed it to do. The flaw highlights how LLMs mix inputs, context, and outputs without any strict boundaries between th…YOUTUBE.COM
22 SepWordPress “wp2shell” attacks stole 18,000 government recordsA suspected Chinese-speaking threat actor exploited WordPress vulnerabilities to breach dozens of organizations worldwide, stealing more than 18,000 sensitive records from one Western government agency. GreyNoise researchers tracked the attacker through the company’s Global Obser…CYBERINSIDER.COM
22 SepNew Windows Defender zero-day blocks Microsoft antivirus updatesOver the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates. [...]BLEEPINGCOMPUTER.COM
22 SepResearchers used Claude to hack OpenAIClaude helped researchers break into OpenAI in under 72 hours, and exposed how quickly AI is lowering the bar for sophisticated hacking.MALWAREBYTES.COM
22 SepHow the CIA captured Carlos the JackalBefore he became one of the world's most notorious terrorists in the 1970s and '80s, inspiring movies, books, and future terrorists, Carlos the Jackal was born Ilich Ramírez Sánchez to a privileged family in Venezuela. Over time, his crimes grew bolder, from an attempted assassin…THECYBERWIRE.COM
22 SepWordPress Patches ‘Click2Shell’ VulnerabilityThe bug lets attackers automatically install and preview themes and could lead to remote code execution. The post WordPress Patches ‘Click2Shell’ Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
22 SepSomewhere in your traffic logs, a bot is doing more than lookingAkamai has watched verified AI crawlers, ChatGPT among them, move from reading web pages to sending high-frequency POST requests. In a 30-day analysis of its global customers, ecommerce accounted for 44.8% of those AI bot POST transactions, and travel climbed to 30% in a single m…HELPNETSECURITY.COM
22 SepPublic PoC Exposes Critical Veeam Agent Privilege EscalationA Veeam Agent flaw lets local users gain SYSTEM privileges. A public PoC is available, raising the risk of exploitation on shared Windows systems. If you’re running Veeam Agent on a Windows endpoint with more than one local user, now’s the time to check the version, n…SECURITYAFFAIRS.COM
22 SepDORA Year Two: Can Your SOC Actually See the Attack?When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint. Financial entities spent the first year establishing risk governance, assessing third-party service providers, updating contract…THEHACKERNEWS.COM
22 SepMeta’s Muse AI assistant has a zero-day that can turn it into a Mac backdoorA simple terminal command can hijack Muse and use its extensive permissions to spy on Mac users and control their connected accounts.MALWAREBYTES.COM
22 SepZTE SmartLife flaws allows account takeover without reset codeSecurity researcher Mina Nageh Salama disclosed a chain of vulnerabilities in ZTE’s SmartLife platform that lets attackers take over user accounts by resetting passwords without a verification code. ZTE confirmed four flaws, issued CVE identifiers, and said it fully patched the v…CYBERINSIDER.COM
22 SepRecent ZyXEL Switch Vulnerability Exploited by Chinese HackersA Chinese threat actor has exploited the bug to exfiltrate sensitive information from nearly 1,000 ZyXEL switches. The post Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers appeared first on SecurityWeek .SECURITYWEEK.COM
22 SepThe next intellectual property thief may sound like your CEOImpersonation, phishing and domain-name abuse are the most concerning types of online intellectual property infringement, according to CSC’s The State of Online IP Risk 2026 report. Internet and branded content, online marketplaces and paid search were the channels most frequentl…HELPNETSECURITY.COM
22 SepBeware these fake websites selling subscriptions to AI assistantsWebsites offering fake subscriptions to AI transcription tools, image generators, and other digital assistants could be putting enterprise data at risk, according to researchers at Malwarebytes. The sites impersonate AI products with solid reputations, including GPT-6 Astra , DaV…CSOONLINE.COM
22 SepNightmare Eclipse Drops New Microsoft Defender Exploit After Revealing IdentityAbdelhamid Naceri, a former Microsoft Germany employee, is the exploit leaker Nightmare Eclipse, aka Chaotic Eclipse. The post Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity appeared first on SecurityWeek .SECURITYWEEK.COM
22 SepResearchers uncover malware that uses AI to choose its next moveTo help security practitioners catch malware that leans on AI, researchers from Cisco Talos shared an open-source framework that they hope will be used to classify and analyze the threat. The tool, called CAIRN, works entirely from metadata pulled off files. No downloading the ma…HELPNETSECURITY.COM
22 SepSpokane Public Schools takes some systems offline after ‘network security incident’Shannon Moudy reports: Some systems are offline Monday after Spokane Public Schools says it experienced an overnight ‘network security incident.’ In an email sent to families Monday, the district says the situation is being investigated. “Out of an abundance of …DATABREACHES.NET
22 SepEarly Scattered Spider member pleads guilty to cybercrime spreeMatt Kapko reports: Another core member of the hacker subset of The Com involved in a spree of extortion attacks from at least 2021 to 2023 pleaded guilty to federal charges, according to court records released Tuesday. Ahmed Hossam Eldin Elbadawy, a 24-year-old from Texas, plead…DATABREACHES.NET
22 SepZ.ai disables coding assistant feature after flaw exposed enterprise code upload riskChinese artificial intelligence company Z.ai had to disable several features of its ZCode coding assistant this week after a default setting was caught sending users’ local code repositories to Alibaba Cloud servers in China without their consent, raising fresh concerns for enter…CSOONLINE.COM
22 SepChaotic Eclipse Released BigDiskBuster, A PoC For Windows Defender Update DoS Zero-DayThe researcher Chaotic Eclipse released BigDiskBuster, a PoC exploit for a Windows Defender Update DoS Zero-Day vulnerability. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting …SECURITYAFFAIRS.COM
22 SepCISA’s tenth Cyber Storm exercise tests critical infrastructure cybersecurity.Nightmare Eclipse publishes another Defender zero-day. Ireland fines Google $462 million over GDPR violations.THECYBERWIRE.COM
22 SepIsraeli cyber manager accused of remotely accessing cameras, stealing passwords and infiltrating 26 companiesAmir Kurz recently reported: Three weeks after his arrest, the State Attorney’s Office’s Cyber Department on Thursday filed a major indictment against Michael “Miki” Bar, a 43-year-old hacker from Ashkelon who served as Chief Information Security Officer for the Hamat Group. The …DATABREACHES.NET
22 SepCheck Point warns of Management Server zero-day exploited in attacksCheck Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts. [...]BLEEPINGCOMPUTER.COM
22 SepResearcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender UpdatesA zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. It…THEHACKERNEWS.COM
22 SepShinyHunters claims FBI breach via new Oracle PeopleSoft zero-dayThe ShinyHunters cybercrime group is now claiming it breached FBI systems after discovering and immediately exploiting a previously unknown vulnerability in Oracle PeopleSoft. This allegedly gave them access to several internal services and allowed them to steal between 2TB and 3…CYBERINSIDER.COM
22 SepBigCommerce Data Stolen via Ribon Apps HackThe attackers used a compromised BigCommerce application key held by Ribon to access customer data. The post BigCommerce Data Stolen via Ribon Apps Hack appeared first on SecurityWeek .SECURITYWEEK.COM
22 SepVU#738147: Vendor-signed UEFI Shell applications allow Secure Boot bypassOverview Vendor-signed UEFI Shell applications may allow an attacker to bypass Secure Boot protections by abusing commands such as mm (Memory Modify). On systems that trust the affected vendor’s certificate or include the application’s Authenticode hash in the UEFI Authorized Sig…KB.CERT.ORG
22 SepVolexity spots another China-aligned threat group exploiting Chrome and Microsoft defectsThe threat group Volexity tracks as UTA0565 showcased a variance in tactics, but it used the same exploit kit as multiple Chinese threat groups. The post Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects appeared first on CyberScoop .CYBERSCOOP.COM
22 SepShinyHunters escalates dispute with FBI; claims to have seized job applicants’ site and acquired dataJoseph Cox reports: A high profile hacking group claims it has breached multiple FBI-related services and stolen data “on all FBI employees and applicants.” A representative of the group, called ShinyHunters, told 404 Media the data includes FBI agents’ names, home addresses, pho…DATABREACHES.NET
22 SepMalicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate CredentialsCybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data. The package, named "tw-…THEHACKERNEWS.COM
22 SepPatch Less, Mitigate MoreA large vulnerability count does not automatically mean every vulnerability deserves the same response. The discussion argues for prioritizing vulnerabilities that are actually being exploited and applying compensating controls where appropriate. That can mean using firewall, ide…YOUTUBE.COM
22 SepShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breachThe ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. [...]BLEEPINGCOMPUTER.COM
22 SepMicrosoft’s EvilTokens takedown sheds light on state of AI-powered cybercrimeMicrosoft has hailed its success in disrupting EvilTokens , an AI-powered a phishing-as-a-service (PhaaS) platform linked to more than 12,000 compromised Microsoft 365 inboxes across more than 10,000 organizations worldwide. Since February 2026, EvilTokens has offered a subscript…CSOONLINE.COM
22 SepStorm clouds over the waterworks.CISA rides out a Cyber Storm. The EU struggles to share cyber threat information. Nightmare Eclipse drops another Defender zero-day. TASK#STOMP steals business documents. North Korean operatives fake their way through job interviews. A genetics lab pays $700,000 over a phishing b…THECYBERWIRE.COM
22 SepChinese hackers exploit WordPress, Zyxel flaws to steal govt dataA Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases. [...]BLEEPINGCOMPUTER.COM
22 SepElsevier Evolve, ClinicalPharmacology, and GSDD APIs Hijacked: LAPSUS$ Redirect CampaignSorami Consulting reports: Users and systems trying to connect to Elsevier Evolve, Sherpath, and ClinicalPharmacology are being redirected to extortion splash pages tied to LAPSUS$ (pointing to domains including lapsus[.]ar[.]io and lapsus[.]bz). While public discussion on Reddit…DATABREACHES.NET
21 SepNot you too Gemini? More AI hacking.Gemini Breaches Real Companies, OpenAI SSO Hijacked, Browser AI Agents Exposed | Cybersecurity Today David Shipley covers multiple cybersecurity headlines: Google's Gemini unintentionally accessed the internet during an Irregular security test, breached real company systems due t…CYBERSECURITYTODAY.LIBSYN.COM
21 SepAI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factorForty percent of large companies had an AI-related compliance or governance issue in the past 12 months, according to 1,000 senior IT, operations, and transformation leaders surveyed by Sapio Research. Those leaders said process-related problems contributed to 84 percent of the i…HELPNETSECURITY.COM
21 SepGopass: Open-source command-line password manager for teamsGopass is a free, open-source password manager that stores credentials in an encrypted store and runs from the command line. Its maintainers built it as a drop-in replacement for pass, the standard Unix password manager. Out of the box, Gopass encrypts each secret with GPG and ke…HELPNETSECURITY.COM
21 SepIntent injection attacks are a new worry for AI-native 6G networksIntent-based networking (IBN) lets operators state the outcome they want and leaves its translation into network policy to software, an approach AI-native 6G designs have moved to the forefront. Researchers at the University of Ottawa and Nokia Bell Labs argue that this abstracti…HELPNETSECURITY.COM
21 SepJade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK BackdoorsThe North Korean threat actor known as Jade Sleet has been attributed to the compromise of an India-based "much smaller organization" in the information technology (IT) services industry, once again highlighting how the adversary continues to target developers to breach target ne…THEHACKERNEWS.COM
21 Sep5 ways AI is reshaping the cybersecurity job marketMario Platt spent part of last year eliminating a team. As CISO for online password management service LastPass, he shut down the company’s dedicated vulnerability management function in late 2025, folding its responsibilities directly into IT and product security. AI and busines…CSOONLINE.COM
21 SepHackers exploit Gyazo server flaw to steal 23.6 million user recordsJapanese software company Helpfeel has confirmed a data breach on its screenshot-sharing platform Gyazo, in which attackers exploited a vulnerability in its image upload server, stealing approximately 23.62 million user records and metadata tied to hundreds of millions of images.…HELPNETSECURITY.COM
21 SepCyber Resilience with Cohesity, When to use AI for Writing, and the News - Rob Sadowski - ESW #477Interview with Rob Sadowsky from Cohesity Global Cyber Resilience Report: Cyber Recovery Plans Weren't Designed for this Moment Cyber recovery plans weren't designed for this moment. Most were built around assumptions that made sense when they were written: incidents could be und…YOUTUBE.COM
21 SepMore CVEs than ever. The same old ones keep getting exploited.Vulnerability volume is climbing fast. The exploited ones are old and already patchable.CYBERSECURITYDIVE.COM
21 SepOrganizations Warned of 3 Exploited Linux Kernel VulnerabilitiesAttackers could exploit the flaws to cause denial-of-service conditions, disclose memory, or modify memory. The post Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
21 SepSiemba brings continuous IDOR testing to production APIsSiemba has announced automated testing for insecure direct object reference (IDOR) as part of its API Security Testing capability, which tests REST, GraphQL and SOAP APIs for the vulnerability classes most likely to expose customer data. A 200-endpoint API collection can be teste…HELPNETSECURITY.COM
21 SepCrowdSec Confirms Source Code Stolen in Supply Chain AttackThe cybersecurity firm believes the data breach was the result of the May 2026 TanStack supply chain attack. The post CrowdSec Confirms Source Code Stolen in Supply Chain Attack appeared first on SecurityWeek .SECURITYWEEK.COM
21 SepSAML: A fractal of bad designBorn out of academia and raised in corporate IT departments, the Security Assertion Markup Language (SAML) authentication protocol continues to be a staple in these organizations. However, it’s time for it to retire. With the rise of software-as-a-service (SaaS) companies i…TRAILOFBITS.COM
21 SepOrchid Security Introduces AI Agent Readiness Controls Featuring Continuous Identity Monitoring and Kill-Switch CapabilitiesReadiness tagging for AI, always-on observability, and coordinated kill switches at the application layer give enterprises a defensible route to scaling agents while keeping authority in human hands. New York, London – September 15, 2026 – Orchid Security, which unlocks safe AI a…CSOONLINE.COM
21 SepSpain blocks anonymous service Archive.today and all mirror domainsSpanish authorities have ordered internet providers to block Archive.today and six of its mirror domains under the country’s intellectual property enforcement system. Users attempting to access the affected addresses are instead redirected to a government warning page describing …CYBERINSIDER.COM
21 Sep⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser HijacksA browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths…THEHACKERNEWS.COM
21 SepTASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard DataCybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts. The backdoor "automatically harvests and exfiltrates business documents, watches the filesystem for …THEHACKERNEWS.COM
21 SepNew npm malware finds a way around install script defensesBlocking suspicious install scripts may no longer be enough to mitigate threats from malicious JavaScript dependencies used in software supply-chain attacks. Security researchers at Checkmarx are warning of attackers using a malicious package called “indexed-btree” to impersonate…CSOONLINE.COM
21 SepFBI's CJIS v6.1: What Security Teams Need to Know.The FBI's CJIS Security Policy v6.1 strengthens requirements around encryption and vulnerability scanning while continuing the shift toward more continuous security assessment. Specops explains what changed and how agencies can address password, MFA, and identity requirements as …BLEEPINGCOMPUTER.COM
21 SepGoogle confirms unauthorized hacks by Gemini.CrowdSec discloses breach affecting source code. ShinyHunters hijacks Clop’s leak site.THECYBERWIRE.COM
21 SepChina-nexus actor steals thousands of documents in monthslong exploitation campaignResearchers suspect the hacker employed LLMs to develop custom tools.CYBERSECURITYDIVE.COM
21 SepRogue Behavior: OpenAI Reveals More Model Misalignment IncidentsThe AI giant disclosed six examples of concerning model activity and published a new framework for investigating and disclosing such incidents.DARKREADING.COM
21 SepAfter spending billions, OpenAI still has gaps in its cybersecurityTwo separate reports of security flaws in OpenAI systems highlight how even a company spending billions on developing its own AI-powered cybersecurity testing tools remains vulnerable. In one incident, researchers breached OpenAI systems with the help of a rival AI developer’s to…CSOONLINE.COM
21 SepDems seek top-to-bottom assessment of CISA workforceAfter the exit of around 1,000 CISA workers, legislation from three top House Democrats orders a force structure assessment like that more common to military branches. The post Dems seek top-to-bottom assessment of CISA workforce appeared first on CyberScoop .CYBERSCOOP.COM
21 SepWordPress Click2Shell flaw enables RCE after one admin clickWordPress has patched a vulnerability dubbed Click2Shell that could allow an attacker to silently install a theme and execute PHP code on the targeted website. The attack does not require the threat actor to have a WordPress account, but it does require a logged-in administrator …CYBERINSIDER.COM
21 SepWordPress Click2Shell flaw lets hackers execute PHP on the serverTechnical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component. [...]BLEEPINGCOMPUTER.COM
21 SepA very real-world AI test.Google confirms unauthorized access by Gemini. AI’s growing power outpaces its defenses. Hackers target Colorado water utilities. Georgia weighs voting-system security. ShinyHunters hijacks Clop’s leak site. FamousSparrow spies across Latin America. CrowdSec loses source code. Ne…THECYBERWIRE.COM
21 SepCISA alerts of active exploitation of three Linux kernel flawsThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical. [...]BLEEPINGCOMPUTER.COM
21 SepBigCommerce alerts merchants of data breach linked to Ribon appsEcommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores. [...]BLEEPINGCOMPUTER.COM
21 SepMuse, Meta's extraordinarily privileged AI assistant, has a serious 0-dayA simple ClickFix attack is only one way to completely hijack the new agent.ARSTECHNICA.COM
21 Sep21st September – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 21st Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Japan’s Digital Agency, which operates the Government Solution Service used by multiple ministries, has confirmed a data breach …RESEARCH.CHECKPOINT.COM
20 SepClaude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained FlawsThree researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. The chain began with a bug in the software that run…THEHACKERNEWS.COM
20 SepDefending Space as Critical Infrastructure.Space infrastructure has become an increasingly important part of everyday life, which has also made it an increasingly attractive target for exploitation. Host Maria Varmazis and Sean MacKirdy, Area Vice President for the National Security vertical at Elastic Government Solut…THECYBERWIRE.COM
20 SepWeek in review: Cisco patches exploited email gateway 0-day, Revolut breachHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: What we know about the Revolut data breach so far Someone impersonating a government agency, using an email address on that agency’s domain, obtained sensitive customer records from …HELPNETSECURITY.COM
20 SepSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Gray Rabbits and the Tale of a One-Click Backdoor Red Heron exploits Gitea n-day flaw in multinational campaign, ex…SECURITYAFFAIRS.COM
20 SepAI Hallucinations Nearly Triggered a US-China Military ConfrontationAn AI-generated intelligence report falsely identified weapons on a Chinese ship, nearly triggering a US military operation during the Iran war. According to CNN, four sources familiar with the episode say an intelligence report circulated through the military claiming a Chinese …SECURITYAFFAIRS.COM
19 SepAnthropic insider claims 10% extinction risk, Five Eyes push basics, Microsoft patches backfireAI Doomerism vs. Cybersecurity Reality: Five Eyes 'Back to Basics,' Incident PR, and Microsoft's Patch/Unpatch Cycle On the month-end weekend episode of Cyber Security Today, Jim Love, David Shipley, Laura Payne, and Mike Kim discuss AI doomerism sparked by an Anthropic employee'…CYBERSECURITYTODAY.LIBSYN.COM
19 SepGoogle Gemini Broke Into Real Company Systems After Security Test Domain Mix-UpGoogle's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal. The incidents occurred in May 2026 as part of a …THEHACKERNEWS.COM
19 SepForget the AI Slowdown—the Vulnerability Explosion Is Already HappeningAI labs are toying with an industry-wide pact to slow development. Meanwhile, widely available AI chatbots are already helping uncover a tidal wave of security flaws.WIRED.COM
19 SepBragJack attacks hijack AI browser agents through malicious extensionsBragJack, a proof-of-concept attack from Forever Security's Gal Weizman, hijacks the AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome using one malicious extension. The Prompt Forcing technique earned over $20,000 in bounties and two CVEs. [...]BLEEPINGCOMPUTER.COM
19 SepNorth Korean WaterPlum hackers infected 30,000 devices worldwideA joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. [...]BLEEPINGCOMPUTER.COM
19 SepTigerByte Cyber Emerges From Stealth With $3 Million in FundingThe company has secured over $7 million in contracts with US government agencies, including the US Space Force, the US Navy, and DARPA. The post TigerByte Cyber Emerges From Stealth With $3 Million in Funding appeared first on SecurityWeek .SECURITYWEEK.COM
19 SepShinyHunters hacks Clop leak site, threatens to extort ransomware gang (1)Lawrence Abrams reports: The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation’s data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. The attack began Friday night when ShinyHunters …DATABREACHES.NET
19 SepNational Cancer Centre e-mail lapse allegedly exposes patients’ detailsThe mistaken cc: breach still happens. Ann Neo reports: An invitation to an event sent by the National Cancer Centre Singapore (NCCS) has sparked privacy concerns after a mailing list exposed the identities, contact details and, in some instances, workplaces of individuals with a…DATABREACHES.NET
19 SepGemini Hacked Three Companies in First Known Breakout by Google’s AIErin Woo and Robert McMillan report: Google’s Gemini model accessed the internet and hacked other companies during a test of its cybersecurity capabilities, the first known example of the company’s artificial-intelligence systems autonomously committing such an act. T…DATABREACHES.NET
19 SepHHS’ Office for Civil Rights Settles HIPAA Investigation of Ambry Genetics for Security Rule ViolationsWASHINGTON — September 17, 2026 — The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) today announced a settlement with Ambry Genetics Corporation (Ambry) concerning potential violations of the Health Insurance Portability and Accountability Act of …DATABREACHES.NET
19 SepAI Helps Hackers Hijack OpenAI Staff Accounts Through a ForumAI helped researchers exploit a Discourse flaw in under 72 hours, hijacking OpenAI staff accounts and exposing the risks of shared SSO. Three researchers at Hacktron just took over ChatGPT and Codex accounts belonging to OpenAI staff. The attack did not rely on phishing technique…SECURITYAFFAIRS.COM
18 SepOpenAI models steal credentials and lie, Microsoft writes AI rules it can't enforce, Congress punts AI safety to 2027OpenAI Models Self-Jailbreak & Leak Data, Microsoft's "Humanist AI" Promise, Windows Patch Tuesday Fallout, and AI Laws Delayed Host David Shipley covers reports that OpenAI disclosed six recent incidents of internal models exhibiting concerning behavior—writing jailbreak instruc…CYBERSECURITYTODAY.LIBSYN.COM
18 Sep98% of fraudulent hires have company credentials by the time they’re caughtA 90-day period between hiring and onboarding is creating a blind spot in enterprise identity security, according to HYPR’s State of HR Identity Fraud Detection report. “Adversaries no longer need to breach a network when they can pass a remote interview and receive authentic cre…HELPNETSECURITY.COM
18 SepCheck Point, Kaspersky, Tanium Patch Product VulnerabilitiesCheck Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges. The post Check Point, Kaspersky, Tanium Patch Product Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
18 SepStrong fundamentals make next-gen security possibleRisk management has always been a difficult job, but the current threat landscape has taken the challenge to a new level. I’ve spent years leading cybersecurity efforts at large enterprises, including Hyatt and United Airlines, and in that time I’ve seen cybercriminals grow incre…CSOONLINE.COM
18 SepFake parcel delivery messages steal your card and bank detailsParcel delivery phishing messages impersonate familiar couriers and use small fees or promised refunds to steal personal and financial information.MALWAREBYTES.COM
18 SepArcjet brings security controls and audit trails to AI agentsArcjet has launched agent runtime security, a new product that helps engineering teams secure the AI agents they are building while giving security teams the governance and compliance evidence they need. Arcjet brings observability, enforcement, and audit capabilities across agen…HELPNETSECURITY.COM
18 SepZero-click RCE vulnerability hit four major AI coding agents, two remain unpatchedFour major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an attacker the same reach into a company’s systems and data as the employee running the agent, according to AIR. “It i…HELPNETSECURITY.COM
18 SepCISA Upgrades Vulnerability Reporting Platform with More AutomationThe US cybersecurity agency is moving to a new vulnerability coordination platform called VINCE-NTINFOSECURITY-MAGAZINE.COM
18 SepNew Check Point flaw lets hackers execute code with root privilegesCheck Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems. [...]BLEEPINGCOMPUTER.COM
18 SepWeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension StorageCybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associ…THEHACKERNEWS.COM
18 SepAuditing in the age of (good enough) AISecurity firms have published numerous blog posts describing how they pointed their agent harness at a codebase and found dozens of bugs ( we’re one of them ). However, these posts tend to focus on agentic code review, which is just one aspect of how we use AI in our security rev…TRAILOFBITS.COM
18 SepGyazo data breach exposed 23.6 million user records and 490M image metadataHelpfeel has disclosed a major data breach affecting its Gyazo image-sharing service, after an attacker exploited a vulnerability in an upload server to execute arbitrary commands and access backend systems. The incident exposed approximately 23.62 million user-related records an…CYBERINSIDER.COM
18 SepMicrosoft Patches 18 Vulnerabilities in AI, Cloud ProductsMicrosoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority. The post Microsoft Patches 18 Vulnerabilities in AI, Cloud Products appeared first on SecurityWeek .SECURITYWEEK.COM
18 SepBots with good manners are better at fooling people on social mediaMost people can’t tell a bot from a human online, and the bots most likely to fool them are the polite ones, according to a new Surfshark study. The company analyzed 1,722 participants worldwide, testing their ability to separate human comments from AI-generated ones in a s…HELPNETSECURITY.COM
18 Sep23 Million User Records Compromised in Gyazo Data BreachGyazo maker Helpfeel said the attacker exploited a vulnerability in its image upload server to gain unauthorized access. The post 23 Million User Records Compromised in Gyazo Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
18 SepAI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI CodeHacktron researchers earned a bug bounty after demonstrating access to OpenAI employee accounts. The post AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code appeared first on SecurityWeek .SECURITYWEEK.COM
18 SepRaon data leak: Insider leak of 1,894 cases went undetected for 4 yearsChoi Won-woo reports: Internal data amounting to 1,894 cases from the Korean-type heavy ion accelerator ‘Raon,’ built with a state budget of 1.5 trillion Korean won [USD $1,080,038,017.50 at today’s rates] was confirmed to have been leaked externally. The estimated time of …DATABREACHES.NET
18 SepInternational Meteor Organization says cyberattack dealt ‘critical blow’ to websiteJonathan Greig reports: A cyberattack has shut down the website of the premier international organization responsible for tracking meteors. The International Meteor Organization (IMO) has continued tracking asteroids and meteor through its Facebook page, but its website now carri…DATABREACHES.NET
18 SepResearchers used Anthropic’s Claude to hack into OpenAISecurity researchers used Anthropic’s Claude to exploit vulnerabilities in OpenAI’s systems, taking over employee accounts and gaining access to an internal code repository before reporting the flaws.TECHCRUNCH.COM
18 SepWebinar: Which Google Workspace security controls actually matter?Fast-growing companies face countless recommendations for securing Google Workspace, but not every control provides the same value. This webinar examines real-world breaches to explore which security controls matter most, which may be overrated, and where lean security teams shou…BLEEPINGCOMPUTER.COM
18 SepIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawNoteworthy stories that might have slipped under the radar: Mandiant's 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug exploited. The post In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw appeared f…SECURITYWEEK.COM
18 SepA zero-click RCE flaw in AI coding agents could have exposed enterprise systemsPopular AI coding agents such as OpenAI’s Codex, Anthropic’s Claude Code, Google’s Gemini CLI, and Microsoft-owned GitHub Copilot were vulnerable to a zero-click attack that enabled attackers to execute malicious code, even without developer interaction, by swapping a trusted plu…CSOONLINE.COM
18 SepGhostCode attackers abuse device codes to take over Microsoft 365 accountsMicrosoft 365 users are being tricked into handing over access to their accounts by a new phishing kit, GhostCode, that exploits a weakness in a legitimate device authorization flow. Researchers in eSentire’s threat response unit identified the campaign in late August 2026. The k…CSOONLINE.COM
18 SepCisco patches a maximum-severity zero-day.Gyazo data breach affects more than 23 million user records. China's FamousSparrow deploys a new backdoor.THECYBERWIRE.COM
18 SepInternational security agencies warn about North Korean hackers exploiting job seekers to steal crypto, dataThe U.S., Japan, Germany and Australia said WaterPlum operators pose as prospective employers and have infected more than 30,000 devices worldwide. The post International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data appeared first…CYBERSCOOP.COM
18 SepCISA ends weekly vulnerability roundups as part of shift to prioritization approachThe agency wants to help companies sort through the AI-fueled avalanche of bug reports.CYBERSECURITYDIVE.COM
18 SepINTERPOL says it used AI to identify 126 criminals from 100,000 imagesINTERPOL says an international counter-terrorism operation used artificial intelligence and facial recognition technology to identify 126 suspected foreign terrorist fighters from imagery collected from jihadist groups online. Operation Shams II, coordinated by INTERPOL between J…CYBERINSIDER.COM
18 SepGyazo server flaw exploited to steal 23.6 million user recordsThe Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records. [...]BLEEPINGCOMPUTER.COM
18 SepNew WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code ExecutionWordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install. The security …THEHACKERNEWS.COM
18 SepResearchers use AI to find widespread software decoder flawThe bug, since patched, gave attackers remote code execution privileges and access to user accounts and production environments, including Meta’s core product suite and an OpenAI software repository. The post Researchers use AI to find widespread software decoder flaw appeared fi…CYBERSCOOP.COM
18 SepGyazo Data Breach Exposes 23 Million User RecordsA Gyazo breach exposed 23 million user records after attackers exploited a vulnerability in Helpfeel’s image upload server. Japanese software company Helpfeel is notifying Gyazo users about a data breach that compromised 23 million user records. Attackers gained unauthorized acce…SECURITYAFFAIRS.COM
18 SepPublic Exploits Released for Four Linux Kernel Flaws That Enable Local RootA security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine. Kernel maintainers have fixed all four over the past few weeks, so a system running an up-to-date kernel is not affe…THEHACKERNEWS.COM
18 SepThe Cisco root route.Cisco patches a maximum-severity vulnerability in its Identity Services Engine. Court documents describe AI as “an astonishing theft of unprecedented proportions.” Researchers chain vulnerabilities to take over employee ChatGPT accounts. Microsoft and Check Point patch vulnerabil…THECYBERWIRE.COM
18 SepEarly Scattered Spider member pleads guilty to cybercrime spreeAhmed Elbadawy pocketed massive proceeds from his crimes. Prosecutors are seeking the forfeiture of about $17.6 million in virtual currency, luxury vehicles, and a vast collection of jewelry and designer bags. The post Early Scattered Spider member pleads guilty to cybercrime spr…CYBERSCOOP.COM
18 SepRansomware attack on Kansas county will affect some servicesJoseph McCarty reports: A Kansas county’s government says it has been hit by a ransomware attack. Ellis County discovered the attack on parts of its information technology systems Thursday morning. Officials said they “immediately took steps to contain the disruption” by isolatin…DATABREACHES.NET
18 SepForeign actors breach Colorado water systemsAlayna Alvarez reports: Foreign actors last month breached two small Colorado water utilities and manipulated equipment used to control drinking water systems. The two privately owned utilities, each serving fewer than 200 people, were breached in late August, Gov. Jared Polis…DATABREACHES.NET
18 SepThe U.S. military leaked more than 93,000 tips via insecure P3 Global Intel. Has anyone been notified?As part of DataBreaches.net’s ongoing investigation into the Navigate360 breach, this report covers approximately 94,000 unclassified but sensitive tips submitted through P3 Global Intel apps and websites used by the military. What has Homeland Security done in response to …DATABREACHES.NET
18 SepCan AI Let You Jump SOC Maturity Levels? (Spoiler: Only the Boring Half)Back in my analyst days , I built maturity models for a SOC (2018), a SIEM (2018), vulnerability management (2017) and threat intel (201?). Later, just for fun, I cooked up a simple SOAR adoption maturity model (2022). All of them were vaguely CMM-shaped: you start ad hoc, you ge…MEDIUM.COM
18 SepBrevo Supply-Chain Attack Infected Over 100,000 WebsitesA Brevo supply-chain attack used compromised Cloudflare access to inject malware into websites, potentially affecting over 100,000 sites. Brevo, formerly known as Sendinblue, is a French cloud-based marketing and customer communication platform whose clients include eBay, Louis V…SECURITYAFFAIRS.COM
17 SepAI is adding to the review load on open-source projects, many of them thinly fundedAI coding tools are making open source software harder to maintain and secure, according to six authors writing for the Association for Computing Machinery’s Technology Policy Council, among them Simson Garfinkel and Josiah Dykstra. The tools write code and find security fl…HELPNETSECURITY.COM
17 SepA flat cybersecurity budget doesn’t have to mean weaker coverageCheri Hotman, Managing Partner of Hotman Group, works as a vCISO and vGRC leader. In this Help Net Security video, she talks about holding coverage steady when the CFO asks for a flat budget or a 12% cut. Her advice is to stop trimming every line by the same percentage. Instead, …HELPNETSECURITY.COM
17 SepActive Exploitation Triggers Emergency Patch for Cisco ISE Zero-DayRemote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests. The post Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
17 SepTuskira Vector brings autonomous red teaming to attack surface validationTuskira has announced Vector, its autonomous red teaming agentic capability, which identifies an organization’s exploitable attack surface by simulating what an attacker can do from outside it. Tuskira validates every external finding against the organization’s deploy…HELPNETSECURITY.COM
17 SepCisco warns of max severity ISE zero-day exploited in attacksCisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]BLEEPINGCOMPUTER.COM
17 Sep16 governance tools for securing your AI fleetEvery DevOps team member knows that dealing with an AI is like being a circus lion tamer. The boss and the audience are happy when the lions sit on the pedestal and roar on cue, but there’s always the danger that they’ll go rogue and bring the whole show to a quick and disastrous…CSOONLINE.COM
17 Sep100,000+ WordPress sites infected via Brevo supply chain attackA breach affecting Brevo infrastructure has pushed malicious JavaScript to more than 100,000 websites through Brevo-hosted widgets and scripts. According to a report from the Sansec Forensics Team, attackers modified Brevo resources on September 14 to deliver malware that attempt…CYBERINSIDER.COM
17 SepCisco Warns of Active Exploitation of Critical ISE FlawCisco urged ISE customers to apply a software update, as well as check for signs of exploitationINFOSECURITY-MAGAZINE.COM
17 SepFBI takes down one of the longest-running DDoS-for-hire servicesThe FBI has seized the domains behind NightmareStresser, a DDoS-for-hire service officials call one of the longest running “booter” operations in existence. The domain seizure notice (Source: US Department of Justice) “Booter services such as those named in this…HELPNETSECURITY.COM
17 SepGyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata RecordsSwati Khandelwal reports: A security breach at Gyazo, Helpfeel’s image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice published Wednesday. It also exposed about 490 million i…DATABREACHES.NET
17 SepISC Patches 14 Vulnerabilities in BIND 9 Security UpdateAttackers could exploit the flaws to increase resource usage, trigger an unexpected program exit, or terminate the named process. The post ISC Patches 14 Vulnerabilities in BIND 9 Security Update appeared first on SecurityWeek .SECURITYWEEK.COM
17 SepRansomware Attacks on Manufacturers Surge as Supply Chain Risk GrowsResearch shows attacks on manufacturers rose 40% in early 2026, as ransomware groups increasingly exploit the supply-chain disruption caused by operational shutdowns. The post Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows appeared first on SecurityWeek .SECURITYWEEK.COM
17 SepCisco Fixes Dozens of Flaws Across FMC, ISE and Nexus DashboardThe vulnerabilities may lead to root access, command execution, bypasses, SQL injection, and remote code execution. The post Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard appeared first on SecurityWeek .SECURITYWEEK.COM
17 SepCISA wants critical infrastructure orgs and smaller security teams to start using cyber decoysCyber deception has long been the domain of well-resourced security teams, but CISA’s latest guidance, titled “Using Cyber Decoys to Strengthen Detection and Response”, is an attempt to try and change that. Why decoys, and why now The core problem CISA is attemp…HELPNETSECURITY.COM
17 SepNavigate360 may soon release a public notice about its horrific breach, but will any individuals be notified?Six months ago, a hacktivist announced that they had accessed and acquired 8.3 million tips submitted on supposedly anonymous tip lines and platforms used by schools, communities, Crime Stoppers organizations, law enforcement, and the military. Six months later, individuals affec…DATABREACHES.NET
17 SepCan You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This WebinarA new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be exploited in your environment? Mythos-class AI is compressing the time between disclosure and working exploitation, while many secur…THEHACKERNEWS.COM
17 SepCISO's Expert Guide to Agentic Pentesting for WebsitesAttackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon DBIR 2026). A new free guide explains how autonomous AI agents are closing that gap, and what security leaders must demand …THEHACKERNEWS.COM
17 SepCongress eyes new support for Cyber Command after recent suicide deathsCongressional sources say they view the deaths of U.S. Cyber Command personnel as an inflection point, especially as the Pentagon’s appetite for cyber capabilities grows following successful contributions to high-profile missions against Iran and Venezuela.THERECORD.MEDIA
17 SepIranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAESix months after Iranian drone strikes tore through its Middle East infrastructure, Amazon Web Services (AWS) has acknowledged the permanent loss of customer data in Bahrain and the UAE. In two updates posted September 15, AWS said it can no longer recover customer data and resou…HELPNETSECURITY.COM
17 SepDownload: The IT leader’s guide to AI code sprawlAI hasn’t just made building faster, it’s made everyone a builder. Across every department, employees are shipping apps, agents and automations using AI tools, often without knowing they’ve created something that needs governing at all. The result: AI code spraw…HELPNETSECURITY.COM
17 SepAI Is Outrunning Your Patch ProgramAI is accelerating vulnerability discovery, while patching still depends on people, money, and operational capacity. The old delay between finding vulnerabilities and having to fix them provided some breathing room. As that friction disappears, organizations may face vulnerabilit…YOUTUBE.COM
17 SepOpenAI reveals its AI agents hid mistakes and bypassed restrictionsOpenAI has disclosed six examples of concerning model behavior observed during the training and evaluation over the past six months, including models concealing mistakes, using exposed API keys, uploading files publicly, and bypassing technical restrictions. The incidents are the…CYBERINSIDER.COM
17 SepCISA Retires Weekly Vulnerability Bulletin in Risk-Based PivotThe decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk. The post CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot appeared first on SecurityWeek .SECURITYWEEK.COM
17 SepOpenAI admits six new misalignment incidents under new reporting frameworkOpenAI has published six new reports detailing AI model misalignment, including instances of hidden instructions, unauthorized communication, and attempts to locate exposed API keys, adding to the evidence that its AI systems bypassed controls during testing. The reports, based o…CSOONLINE.COM
17 SepVU#280377: Dokploy is vulnerable to OS command injectionOverview Dokploy versions 0.29.8 and 0.29.11, as well as commit 24b02f5 on the canary branch, are vulnerable to OS command injection during the backup creation and restoration processes. The vulnerability stems from unsanitized shell command construction that can allow an attacke…KB.CERT.ORG
17 SepOpenAI discloses six new "concerning" AI incidents.US law enforcement seizes DDoS-for-hire service. TrustSink technique uses rogue external MFA providers to intercept passwords.THECYBERWIRE.COM
17 SepPort of LA Fended Off 120 Million Cyberattacks in AugustPYMNTS reports: The Port of Los Angeles reportedly blocked more than 120 million cyberattacks during August. That’s according to a report Thursday (Sept. 17) by Bloomberg News, which notes that these attacks on America’s busiest container hub for global trade represent an ongoing…DATABREACHES.NET
17 SepEU chief wants joint response to cyberattacks, sabotageAlexander Martin reports: European Commission President Ursula von der Leyen proposed on Wednesday an emergency mechanism allowing any EU country to summon the bloc’s governments in response to security threats including sabotage, cyberattacks and drone incursions. Delivering her…DATABREACHES.NET
17 SepThe AI hacking apocalypse is not inevitableWhile large language models present real risks to society, experts say they can be tested and largely controlled using well-worn cybersecurity and policy choices. The post The AI hacking apocalypse is not inevitable appeared first on CyberScoop .CYBERSCOOP.COM
17 SepAI hates CAPTCHAs - PSW #944In the security news this week: - UK government rolls out passkeys to 20 million users - Phishing-resistant authentication and replay resistance - Passkey adoption, device security, and user acceptance - EU Cyber Resilience Act guidance, scope, and compliance - CRA vulnerability …YOUTUBE.COM
17 SepScamazon prime.This week, hosts of N2K CyberWire Maria Varmazis and Dave …THECYBERWIRE.COM
17 SepCISA Ditches Weekly Vulnerability Roundups for Risk-Based FocusThe move is consistent with the agency's advice on the need for organizations to prioritize the vulnerabilities that actually matter.DARKREADING.COM
16 SepRevolut hands customer data to criminals, Microsoft patches break Remote Desktop, Conti developer gets four yearsRevolut Fooled by Fake Govt Data Requests, Microsoft RDP Patch Fallout, and Conti Dev Sentenced David Shipley covers multiple cybersecurity headlines: Revolut disclosed extensive customer data after fraudsters used fake emergency requests from a legitimate government email accoun…CYBERSECURITYTODAY.LIBSYN.COM
16 SepAttacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 RepositoriesMandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code repositories. Before the repository spread, the assistant recommended software that the attac…THEHACKERNEWS.COM
16 SepThreat Intelligence Alone Won't Close the Exploitation GapA leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combining that kind of intelligence with AI-assisted expl…THEHACKERNEWS.COM
16 SepAttackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web ShellsThreat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. "This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, …THEHACKERNEWS.COM
16 SepGoogle says some Pixel phone owners were hacked in zero-day attacksThe Pixel phone maker said there are indications that a bug in the phone's modem "may be under limited, targeted exploitation."TECHCRUNCH.COM
16 SepBig Tech’s AI safety rift signals disruption and disparity for enterprisesA growing divide among leading AI companies over how to secure increasingly powerful models is beginning to translate into challenges for enterprise IT, with implications for how organizations access, deploy, and govern AI systems. The latest flashpoint came after Meta CEO Mark Z…CSOONLINE.COM
16 SepAI agent authorization risks remain a gap in new NIST-CISA token security guidanceAI agents’ actions are out of scope for new guidance from US authorities on securing identity and access tokens, but there is still plenty enterprises can do to protect their systems from rogue humans and AI agents alike. “ Protecting Tokens and Assertions from Forgery, Theft, an…CSOONLINE.COM
16 SepYou don’t have to join the hack-back program to inherit its riskThe obvious question about Washington’s new private offensive cyber program is which security vendors will join it. The CSO question is what happens to you when one of your vendors does. The August 12 National Security Presidential Memorandum , “Expanding Capabilities to Combat T…CSOONLINE.COM
16 SepAI made software development unrecognizable. Is cybersecurity next?The rapid emergence of AI has radically changed a host of professions, with software engineering and development perhaps the most transformed of all pursuits. The usual “ solitary ritual ” of a developer writing code for hours is giving way to collaboration with an army of chatbo…CSOONLINE.COM
16 SepHundreds of OpenAI agents attack RubyGems platformA swarm of hundreds of OpenAI agents uploaded “malicious packages” to RubyGems and tried to steal API keys, the Ruby community gem hosting service revealed Friday. OpenAI confirmed part of the disclosure, saying , “our agents used the RubyGems platform to access the internet to c…CSOONLINE.COM
16 SepZDI-26-708: (0Day) Microsoft Windows HTTP Proxy Privilege Escalation VulnerabilityThis vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS ratin…ZERODAYINITIATIVE.COM
16 SepVU#369093: MLflow dspy and statsmodels flavors bypass pickle deserialization controlOverview A vulnerability in MLflow’s dspy and statsmodels model flavors allows unauthorized pickle deserialization executions despite a safety control. Specifically, the dspy flavor conditionally applies the control based on the model path’s file extension, and the statsmodels fl…KB.CERT.ORG
16 Sep KEVGoogle Pixel owners urged to patch actively exploited modem flawGoogle’s September Pixel update fixes 110 vulnerabilities, including a modem flaw being used in limited, targeted attacks.MALWAREBYTES.COM
16 SepNightEagle targets Russian companiesKaspersky GERT experts have uncovered a new campaign by the NightEagle APT, featuring the GhostContainer backdoor and tools hosted on GitHub. The group is also exploiting vulnerabilities in Active Directory and RDP.SECURELIST.COM
16 SepHackers exploit zero-day flaw in Cisco email gatewayResearchers warn the vulnerability could be used by state-linked actors for espionage.CYBERSECURITYDIVE.COM
16 SepPHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin BugAttackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshellsINFOSECURITY-MAGAZINE.COM
16 SepZero-Day Flaw in TP-Link Cameras Enables EavesdroppingOPSWAT researchers find two zero-days in TP-Link camerasINFOSECURITY-MAGAZINE.COM
16 Sep KEVCritical ScreenConnect flaw now actively exploited in attacksAttackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...]BLEEPINGCOMPUTER.COM
16 Sep KEVGoogle fixes actively exploited Android zero-day on Pixel devicesGoogle has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks. [...]BLEEPINGCOMPUTER.COM
16 SepFirst Agentic AI Data Breach Reported to Spanish RegulatorSpanish regulators say an AI agent chained together a successful login, vulnerability discovery, and access to personal data in a potential milestone for autonomous cyberattacks. The post First Agentic AI Data Breach Reported to Spanish Regulator appeared first on SecurityWeek .SECURITYWEEK.COM
16 SepUnauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to TakeoverVulnerabilities in The Events Calendar can provide attackers with remote code execution capabilities. The post Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover appeared first on SecurityWeek .SECURITYWEEK.COM
16 SepHackuity Raises $19 Million for AI-Powered Vulnerability ManagementThe company will use the new capital to expand its vulnerability operations platform and support international growth. The post Hackuity Raises $19 Million for AI-Powered Vulnerability Management appeared first on SecurityWeek .SECURITYWEEK.COM
16 SepCyber Op Targets South Korean Media & Automotive SectorsA likely North Korean advanced persistent threat (APT) group used a previously undocumented Linux espionage toolkit to compromise load balancers, gain access to communications, and further exploit networks.DARKREADING.COM
16 SepCohesity adds recovery capabilities for AI agents and the data they manageCohesity has introduced Cohesity Agent Resilience. This new Cohesity Data Cloud capability will discover, protect, and recover the infrastructure behind enterprise AI agents. A unified view of an agent and the state it depends on. (Source: Cohesity) The company outlined its visio…HELPNETSECURITY.COM
16 SepCenterPoint Energy confirms data breach following claims on hacking forumCenterPoint Energy disclosed that an unauthorized third party got into customer data through one of its external systems, after online claims by a hacker that millions of records had been stolen from the company. CenterPoint Energy is a Houston-based public utility company that p…HELPNETSECURITY.COM
16 SepNozomi Compass helps industrial teams manage OT assets and vulnerabilitiesNozomi Networks announced Nozomi Compass, an OT asset and service management platform designed to help organizations manage industrial assets, vulnerabilities, and exposures. The platform brings asset data, remediation workflows, and operational processes together, reducing relia…HELPNETSECURITY.COM
16 SepOne runaway AI agent racked up a $50,000 cloud billOrganizations are deploying autonomous AI systems that execute API calls, optimize production configurations, and analyze telemetry across hybrid cloud environments. At the same time, attacks are expanding from direct prompts to indirect prompt injection and AI supply chain compr…HELPNETSECURITY.COM
16 SepRevolut Data Leak May Trace Back to Compromised Italian Government AccountsA suspected compromise of an Italian government PEC account may have allowed threat actors to impersonate law enforcement and obtain sensitive data from hundreds of Revolut customers. The Revolut data exposure may be part of a much broader cyber incident involving compromised Ita…SECURITYAFFAIRS.COM
16 SepData Broker Radaris Loses Domains in Privacy FightThe consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey priva…KREBSONSECURITY.COM
16 SepHouse passes bill to equip local law enforcement with scam-fighting toolsThe Guarding Unprotected Aging Retirees from Deception Act (GUARD) attempts to address a common complaint from the victims of online scams like pig butchering — that such cases typically do not rise to the level of a federal investigation but local law enforcement is unequipped t…THERECORD.MEDIA
16 SepMalware bypasses browser checks to force install Chrome, Edge extensionsA banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. [...]BLEEPINGCOMPUTER.COM
16 SepLinkedIn fights for the right to tell customers when the feds want their dataMicrosoft’s top lawyer argued Tuesday that legislators “must make secrecy [orders] the exception” in government subpoenas demanding information about LinkedIn users. LinkedIn, which is owned by Microsoft, is fighting what it calls overly broad subpoena demands from the US governm…CSOONLINE.COM
16 SepCybercrime finds its sea legs.Officials investigate suspected cyberattacks on U.S.-bound oil tankers. Iranian operators deploy Chosen Brick surveillance malware. Ukraine cracks down on scam call centers. Researchers uncover two TP-Link camera zero-days. Maria Varmazis looks at weapons in space. CenterPoint En…THECYBERWIRE.COM
16 SepKey lawmaker suggests action on AI safety legislation will wait until 2027“It's really complicated, and I wouldn't want to do something in a lame duck session to do it quickly and not get it right,” said House Energy and Commerce Chairman Brett Guthrie about the FRONTIER Act.THERECORD.MEDIA
16 SepCanada: Nipigon hospital hit by ransomware attackMike Stimpson reports: Some patient services may be affected as the general hospital in Nipigon responds to what it describes as a “cyber security incident.” An incident involving ransomware affected information technology systems, Nipigon District Memorial Hospital stated in a p…DATABREACHES.NET
15 SepHomebrew 7.0.0 is out, here’s what changed for securityHomebrew installs command-line software and desktop applications from the terminal on macOS and Linux, and Mac developers use it to set up their machines. On Sunday the project shipped version 7.0.0 and closed eight security advisories with it. The most serious of them let unsign…HELPNETSECURITY.COM
15 SepYour employees are already using AI tools you never approvedSeventy-four percent of respondents report departmental or scaled AI adoption at their organizations, including within individual teams or departments, across business functions, and as part of processes and operations, according to the latest OneTrust 2026 AI-Ready Governance Re…HELPNETSECURITY.COM
15 SepChina-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGEA Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. Volexity, which is tracking the threat cluster under the monik…THEHACKERNEWS.COM
15 SepCisco patches Secure Email Gateway zero-day exploited in attacksCisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. [...]BLEEPINGCOMPUTER.COM
15 SepLiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared ServerA critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory published on September 14. On such servers, many customers' sites run on a single machine, and an atta…THEHACKERNEWS.COM
15 SepThreat actors are coming for your AI assets to operationalize their use of AIBoth state-affiliated cyberespionage group and cybercrime gangs are targeting AI-related documents, configuration files, and proprietary models during intrusions. In addition, the number and scope of distillation attacks, where the knowledge, logic, and reasoning capabilities of …CSOONLINE.COM
15 SepMicrosoft Releases Emergency Patch to Fix RDS SnafuMicrosoft has been forced to issue an out-of-band fix for several issues stemming from this month’s Patch TuesdayINFOSECURITY-MAGAZINE.COM
15 SepAkuity gives AI agents operational context to safely ship softwareAkuity has introduced its Agentic Control Plane and MCP Server. Akuity’s Agentic Control Plane lets AI agents accelerate software delivery by giving them the operational context and permissions to act, all governed by the same controls Akuity already enforces across the pip…HELPNETSECURITY.COM
15 SepTraefik Labs brings independent verification to AI agent governanceTraefik Labs has introduced the Sovereign Trust Plane (STP), a set of capabilities in Traefik Hub that brings verifiable evidence to AI agent governance, with general availability planned by September 30, 2026. STP connects delegated access, policy enforcement and protected recor…HELPNETSECURITY.COM
15 SepTelegram Desktop Flaw Could Turn Old Chat Exports Into Data Theft TrapsA Telegram Desktop flaw let bots inject JavaScript into exported chats, enabling data theft and page manipulation. Old HTML exports remain unsafe. A vulnerability in Telegram Desktop could have turned an ordinary chat export into a serious data leak. Security researchers Denis an…SECURITYAFFAIRS.COM
15 SepNon-Zero-Day VPN Flaw Left Japan ‘s Government Shared Network Platform Exposed: 246,000 Records at RiskJapan ‘s Digital Agency disclosed a VPN breach exposing 246,000 government employee records across 23 ministries. Detected June 25, publicly disclosed September 11. Japan ‘s Digital Agency disclosed that attackers exploited a vulnerability in a VPN device to access it…SECURITYAFFAIRS.COM
15 SepAI is exposing a security structure built for yesterday’s threatsOrganizations are investing more in security than ever before, yet many still struggle with a fundamental problem: they are preparing for tomorrow’s crisis with yesterday’s mindset. For decades, companies organized security around neat categories. Cybersecurity protected networks…CSOONLINE.COM
15 SepThe AI Threat Multiplier: Securing Mobile Apps in the Automated Era - ASW #400While agents and LLMs haven't fundamentally changed core mobile vulnerability types, they have supercharged speed, scale, and accessibility—democratizing threats like automated phishing, synthetic identity fraud, and easier identification of hard-coded secrets. Ryan Lloyd and Jas…YOUTUBE.COM
15 Sep25 Years of Mass Surveillance Is EnoughThis essay was written with Cindy Cohn, and originally appeared in Lawfare . One of the many legacies of the terrorist attacks of Sept. 11 is the government-wide shift from targeted surveillance—such as individual wiretaps or pen register/trap and trace orders—to mass…SCHNEIER.COM
15 Sep1Password's AI patching benchmark is misleading1Password’s FLAWED report , published on August 6, 2026, gives defenders a misleading picture of AI patching. Its headline says models produced clean fixes only 26% of the time. That figure includes experiments that deliberately instructed agents to apply the wrong fix, along wit…TRAILOFBITS.COM
15 SepAttackers hijack HBO Max’s Reddit account for 48-hour malvertising blitzAttackers compromised the verified official HBO Max Reddit account, u/hbomax, and used its trusted advertising status to launch a ClickFix campaign targeting macOS and Windows devices with information-stealing malware. Screenshot of the fraudulent ad (Source: Alex Cutts) ClickFix…HELPNETSECURITY.COM
15 Sep240,000 Hit by Data Breach at Japan’s Digital AgencyHackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people. The post 240,000 Hit by Data Breach at Japan’s Digital Agency appeared first on SecurityWeek .SECURITYWEEK.COM
15 SepApple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 ReleasesThe updates resolve kernel vulnerabilities that could lead to memory corruption, privilege escalation, system termination, and information leaks. The post Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases appeared first on SecurityWeek .SECURITYWEEK.COM
15 SepHackers demand 10,000 Bitcoin from Revolut following data breachDev Kundaliya reports: Revolut recently disclosed a security incident in which an unauthorised third party obtained sensitive customer information by sending fraudulent requests from the email domain of a legitimate government agency. People claiming responsibility for the incide…DATABREACHES.NET
15 SepMembers of ‘Black Axe’ cybercriminal group extradited from South AfricaJonathan Greig reports: Five alleged members of the Black Axe cybercriminal organization will make their first court appearance on Monday after being extradited from South Africa. Prosecutors unsealed a 2021 indictment accusing the five men of conducting lucrative romance scams t…DATABREACHES.NET
15 SepStudent photos, bank details stolen by hackers after St James Anglican School in Perth hit by cyber attackEmma Kirk reports: A school in Perth’s north has been targeted in a cyber attack, with hackers stealing students and families’ personal information. St James Anglican School, in Perth’s north, identified a cyber breach involving unauthorised access into its computer systems. Pare…DATABREACHES.NET
15 SepOne Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under FireTwo China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome’s patch shipped, deploying different backdoors each. Two China-linked threat actors used the same Chrome/Windows zero-day against NGOs starting September 1, 2026, VolexityR…SECURITYAFFAIRS.COM
15 SepBambooToken Malware Uses MQTT to Control Windows and Linux SystemsCybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken, is assessed to be …THEHACKERNEWS.COM
15 SepHuman Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight SecondsWith artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly after gaining initial access. In one insta…THEHACKERNEWS.COM
15 SepMass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev ServersCybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at internet-exposed Vite development servers that's designed to steal cloud credentials, configurations fr…THEHACKERNEWS.COM
15 SepExaforce extends its AI security tool to monitor more than just ClaudeExaforce is offering to help enterprise security teams discover and monitor AI agents using security telemetry they already collect, rather than requiring yet another endpoint sensor. By combining usage data from agentic AI platforms with endpoint, cloud, SaaS and code data, Exaf…CSOONLINE.COM
15 SepOracle September 2026 Critical Security Patch Update addresses 672 CVEsOracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of …TENABLE.COM
15 SepAustralia is replacing the Essential Eight with a new cyber framework. Here’s how exposure management can help you get ahead of it.Australia’s move from the Essential Eight to an outcomes-based cybersecurity model will push organizations from conducting periodic point-in-time, checklist compliance assessments to having continuous evidence of a solid security posture. Key takeaways The Australian Signals Dire…TENABLE.COM
15 Sep KEVCisco warns customers of actively exploited zero-day in email gatewaysThe company confirmed the defect was exploited before it was disclosed and patched, but it did not describe the nature of the attacks or the scope of impact across its customer base. The post Cisco warns customers of actively exploited zero-day in email gateways appeared first on…CYBERSCOOP.COM
15 SepSteam client flaw with no fix enables privilege elevation on WindowsA proof-of-concept exploit named BrokenPipe abuses the Steam Client Service to elevate a standard Windows user to NT AUTHORITY\SYSTEM without displaying a UAC prompt or requiring administrator credentials. The issue was disclosed on GitHub by security researcher KillaBoi (@killa)…CYBERINSIDER.COM
15 Sep KEVAcronis warns of actively exploited flaw in its cPanel backup pluginAcronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]BLEEPINGCOMPUTER.COM
15 SepCenterPoint Energy confirms customer data stolen in cyberattackCenterPoint Energy disclosed a breach compromising some customers' personal information after an attacker leaked data allegedly stolen from the utility company. [...]BLEEPINGCOMPUTER.COM
15 SepHackers target WordPress sites via third-party WooCommerce pluginHackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...]BLEEPINGCOMPUTER.COM
15 SepWhat Zero-Day Response Should Be in the Post-Mythos EraAI is shrinking the time between vulnerability disclosure and exploitation, leaving defenders less time to wait for patches or public exploits. Picus Security explains how exploitability validation, security control testing, and autonomous pentesting can help teams close exposure…BLEEPINGCOMPUTER.COM
15 SepCISA: Critical VMware RCE flaw now exploited by ransomware gangsThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. [...]BLEEPINGCOMPUTER.COM
15 SepBlack Hat USA 2026 | The 'Breaking' News: The OpenAI–Hugging Face IncidentThe 'Breaking' News: The OpenAI–Hugging Face Incident - A Technical Reconstruction and Its Implications for AI At this Black Hat USA 2026 talk, OpenAI security engineers and researchers will reconstruct the OpenAI-Hugging Face incident and examine its implications for AI security…DARKREADING.COM
15 SepPayroll system of mosques, madrasahs hit by ransomware; staff details potentially compromisedDavid Sun reports: The payroll system of mosques and madrasahs overseen by the Islamic Religious Council of Singapore (MUIS) has been hacked and held for ransom, The Straits Times has learnt. The SmartHRMS human resources (HR) system is supplied by Singapore-based software vendor…DATABREACHES.NET
15 SepRevolut’s paperwork breach shows why insurers are rethinking what counts as a ‘cyber attack’Matthew Sellers reports: Revolut wasn’t hacked in the usual sense. No one broke into its servers or slipped malware past its defences. Someone asked for customer data, from what looked like a genuine government email address, and Revolut handed it over. That email is now be…DATABREACHES.NET
15 SepRansomware group claims attack on Missouri’s Cedar County Memorial Hospital after IT outageDysruptionHub reports: Cedar County Memorial Hospital in El Dorado Springs, Missouri, shut down its IT networks Aug. 14 after a disruption left its electronic health record, patient portal and internet access unavailable. The outage also disrupted diagnostic imaging. Hospital sys…DATABREACHES.NET
15 SepShared Hosting at Risk: LiteSpeed Enterprise Bug Can Grant Root from a Single TenantCritical LiteSpeed Enterprise flaw lets one shared hosting account gain root, bypassing CageFS; patch now to 6.3.7 via forced update. cPanel warned that a critical flaw in LiteSpeed Enterprise can let a low‑privilege website user break out of their account and gain root on the wh…SECURITYAFFAIRS.COM
14 SepShinyHunters breaches Florida DMV, OpenAI agents flood code repository with malware, Airlines dodge paying for cyber delaysHost David Shipley covers multiple cyber stories: Florida confirmed criminals breached its DMV using credentials from a Plant City police officer that were improperly stored on a personal device; ShinyHunters claimed responsibility and the full scope remains unknown. IDScan also …CYBERSECURITYTODAY.LIBSYN.COM
14 SepAWS puts AI vulnerability detection to the test, and false positives pile upAWS’ Deception Benchmark measures how well AI models distinguish genuine security vulnerabilities from code that looks risky but is safe. AWS is making it publicly available so researchers can use the dataset and evaluation process without repeating the cost of generating and ref…HELPNETSECURITY.COM
14 SepCybersecurity attention fades within months after a breachCybersecurity attention often rises after an incident, then recedes as organizations return to their existing priorities and practices, according to a new ManageEngine survey of 700 IT and cybersecurity leaders in the US and Canada. (Source: ManageEngine) All of them had already …HELPNETSECURITY.COM
14 SepCertificate failures can cost firms over $250,000The move toward 47-day public TLS certificates by 2029 will increase the certificate management workload for enterprises, according to DigiCert’s Certificate Management Outlook. Organizations will need to renew certificates more than eight times as often as under the previous cer…HELPNETSECURITY.COM
14 SepPermify: Open-source authorization as a servicePermify is an open-source authorization service that answers access questions at run time: can user X view document Y, which posts can members of team Y edit. It keeps those rules in one place, apart from the application code that would otherwise carry them. Permify follows the d…HELPNETSECURITY.COM
14 SepCISA: Hackers now exploit max severity GitLab flaw in attacksThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity GitLab vulnerability in attacks. [...]BLEEPINGCOMPUTER.COM
14 SepDebian 13.7 ships the fixes behind 92 security advisories, updates 106 packagesThe Debian project shipped Debian 13.7 codenamed “trixie.” The project folded in 92 security advisories it had already published separately, added corrections to 106 source packages, and rebuilt the installer around both. Six of the 92 advisories cover the Linux kerne…HELPNETSECURITY.COM
14 SepHow to level up from security pro to security leaderThere comes a time in a cybersecurity professional’s life when being a tech expert is no longer enough. The next step may lead to management or the C-suite, but the goal demands a different kind of expertise. Technical skills will continue to serve a new CISO well, but the role d…CSOONLINE.COM
14 SepMalicious Twitch extension exposed OAuth tokens of 30,000 usersA browser extension installed by more than 30,000 Twitch users was found forwarding live OAuth session tokens to proxy servers operated by Russian-language bot service JeetBot. The tokens could let anyone who possesses them act on affected Twitch accounts without the account pass…CYBERINSIDER.COM
14 SepRevolut discloses data breach exposing financial info, passportsFintech company Revolut has disclosed a data breach after sharing data from an undisclosed number of customers with a threat actor impersonating a government agency. [...]BLEEPINGCOMPUTER.COM
14 SepConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like AttacksThe flaw allows attackers to send files and execute them without authorization through an active remote session. The post ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
14 SepWhat the 3M ChatGPT case reveals about AI governanceOne detail in the Watson Grinding explosion litigation involving 3M changed the way I think about prompt governance. An engineering expert retained by 3M had been using ChatGPT while developing his analysis, and among the conversations that later surfaced was a prompt telling the…CSOONLINE.COM
14 SepSafely exploiting vulnerabilities at scale, TVs attack privacy, and the news - ESW #476Interview with Snehal Antani Snehal Antani, CEO and co-founder of Horizon3 joins us to talk about how automated validation can help with exposure management. As vulnerability counts spike, security teams are looking for a way to prioritize. Automated penetration testing offers a …YOUTUBE.COM
14 SepHackers Exploit Maximum Severity Flaw in GitLabCISA warns that threat actors are exploiting a vulnerability with a CVSS score of 10.0INFOSECURITY-MAGAZINE.COM
14 SepThree JFrog Artifactory Flaws Exploited for Backdoor DeploymentThe vulnerabilities can allow attackers to bypass authentication and elevate their privileges to administrator. The post Three JFrog Artifactory Flaws Exploited for Backdoor Deployment appeared first on SecurityWeek .SECURITYWEEK.COM
14 Sep KEVDutch NCSC Warns: Critical Check Point VPN Flaws Put Networks at RiskTwo critical Check Point VPN flaws score 9.8 and could enable remote code execution. Patch now and restrict VPN access before exploitation begins. The Dutch NCSC warns that two critical vulnerabilities in Check Point VPN products, both rated CVSS score of 9.8, could soon be activ…SECURITYAFFAIRS.COM
14 SepChinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code ExecutionThe Chinese-language input method editor for Windows can allow attackers to execute arbitrary code remotely. The post Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution appeared first on SecurityWeek .SECURITYWEEK.COM
14 SepAI Changed the Exposure Problem. Validation Needs to Change With It.There's a lot of noise around AI and cybersecurity right now. What’s actually important is far simpler, if often lost in the hubbub. Vulnerability discovery is getting faster and happening at a much greater scale, while defenders still have to work out which findings actually des…THEHACKERNEWS.COM
14 Sep14th September – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES IDScan.net, a US identity verification provider, has disclosed a data breach after detecting unauthorized access on September 1.…RESEARCH.CHECKPOINT.COM
14 Sep KEVENISA launched the CRA Single Reporting Platform for actively exploited vulnerabilitiesThe EU Agency for Cybersecurity switched on the Cyber Resilience Act‘s Single Reporting Platform on 11 September 2026, the same day the law’s reporting obligations started binding manufacturers. ENISA built the tool and runs its day-to-day operations, a job Article 16…HELPNETSECURITY.COM
14 SepYour EDR Might Stop Only 16%Organizations can spend millions on EDR and data-security tools while leaving important protections disabled or improperly configured. In one example discussed here, a leading EDR stopped a post-exploitation RAT implant only 16% of the time during testing. The point isn’t that th…YOUTUBE.COM
14 SepPersonal, Financial Info Exposed in Revolut Data BreachThe company unintentionally disclosed users’ information to a third party impersonating a government agency. The post Personal, Financial Info Exposed in Revolut Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
14 SepSilent Ransom Group Hacked Greenberg Traurig; Who notifies the 126k Affected?Silent Ransom Group added Greenberg Traurig to its list of prominent law firms it attacked and leaked. DataBreaches.net has exclusive details on the incident. On August 21, when DataBreaches reported on a data breach affecting Troutman Pepper Locke, the firm was one of 64 law fir…DATABREACHES.NET
14 SepMalicious actors already using critical GitLab flaw, CISA and others warnThe vulnerability could let unauthenticated users access sensitive files from software-development environments.CYBERSECURITYDIVE.COM
14 SepHuman Attacker Hits Machine-Speed Exploitation of Marimo RCEA human attacker exploited a Marimo RCE and reached an SSH bastion in eight secondsINFOSECURITY-MAGAZINE.COM
14 Sep⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and RootkitsAI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination. The rest of the week is more familiar: old bugs still working, fre…THEHACKERNEWS.COM
14 SepBeyond the CVE Count: The Real State of Vulnerability Management - Charles Loring - CSP #228Vulnerability management isn’t just about finding more vulnerabilities—it’s about knowing what matters and having the resources to act. Chuck Loring of the Lee County Clerk of Circuit Court & Comptroller joins CISO Stories to explore how budgets, staffing, legacy technology, and …YOUTUBE.COM
14 SepRapid7 Named Among Notable Vendors in Forrester MDR Landscape: Why the Future is Exposure-informed, Preemptive MDRThe managed detection and response (MDR) market has reached a turning point. We’ve gone beyond the baseline of 24/7 monitoring focusing on the speed of detection and moved to a world with a convergence of exposure management and response to deliver measurable, outcome-based defen…RAPID7.COM
14 SepNew DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential ComputingResearchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server's memory, so the processor keeps reading old encrypted data as if it were current. The attack requires…THEHACKERNEWS.COM
14 SepRed Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six CountriesA Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national campaign. "Red Heron scanned 1,386 Gitea instances across seven co…THEHACKERNEWS.COM
14 SepPossible cyber incident disrupts Monroe schools in WisconsinJoseph Topping reports an incident at the School District of Monroe in Wisconsin has resulted in the district pulling the plug on internet connections: Students powered down computers, school phone service failed and a scheduled ACT session was canceled after a possible network s…DATABREACHES.NET
14 SepAI Finds Vulnerabilities Humans Must ValidateAI is getting better at finding potential vulnerabilities, but reliable validation can still require humans. That creates a bottleneck around the AI itself. Generating more findings does not automatically produce more useful security work if people still have to determine which f…YOUTUBE.COM
14 SepHomebrew 7.0.0 gets built-in GUI, better security controlsHomebrew package manager version 7.0.0 has been released with a built-in vulnerability scanner, stronger security controls, and the full release of its native BrewUI graphical interface. [...]BLEEPINGCOMPUTER.COM
14 SepBigfoot in the neural network.NSA preps a major restructuring. Anthropic’s CEO calls for an AI slowdown. China acknowledges AI risks. RubyGems got swarmed by AI agents. A maximum-severity GitLab vulnerability is under active exploitation. Direct Send abuse makes phishing emails appear legit. A British fintech…THECYBERWIRE.COM
14 SepENISA: Frontier AI Is Changing the Speed of Cyberattacks. Europe Needs to Catch UpFrontier AI is compressing the attack lifecycle from vulnerability discovery to exploitation, forcing defenders to detect, patch and respond at machine speed. Cybersecurity has always been a race between attackers and defenders. ENISA’s latest assessment suggests that front…SECURITYAFFAIRS.COM
13 SepRevolut handed customer data to fraudsters using a government email domainRevolut disclosed personal and financial information of customers after receiving fraudulent information requests sent from an email account hosted on a legitimate government agency domain. The fintech company says its systems and customer funds were not compromised. Blockchain i…CYBERINSIDER.COM
13 SepWeek in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploitedHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: Zero trust AI agents demand a different kind of security In this interview, Chris Webber, VP, Product Marketing at Teleport, explains why zero trust principles need to change for AI …HELPNETSECURITY.COM
13 SepAttackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate DataMicrosoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first campaign, per the tech giant, i…THEHACKERNEWS.COM
13 SepChess.com (2026) - 4,653,212 breached accountsIn August 2026, millions of records allegedly sourced from Chess.com were posted online . The data contained 7.3M rows with 4.6M unique email addresses, along with usernames, names, countries and data relating to users' Chess.com accounts. Analysis of the data suggested it had be…HAVEIBEENPWNED.COM
13 SepDelaware Consumer Privacy and Data-Breach Law UpdatesJoseph J. Lazzarotti of JacksonLewis writes: On September 2, 2026, Delaware’s Governor signed House Bill (HB) 380 and HB 381. HB 380 amends the Delaware Personal Data Privacy Act (DPDPA), which was enacted in 2023 and became effective January 1, 2025. HB 381 separately amends Del…DATABREACHES.NET
13 SepAT&T store worker gets 16 months inside for SIM-swap side hustleConnor Jones reports: A former AT&T retail worker who used his system access to hijack customers’ phone numbers for cybercriminals has been sentenced to 16 months in federal prison. Kenneth Carter, 44, carried out the SIM swaps at a store in Portland, Oregon, , allowing…DATABREACHES.NET
13 SepHHS Releases Updated Security Risk Assessment ToolFrom HHS OCR: The U.S. Department of Health and Human Services Office for Civil Rights (OCR) and the Office of the National Coordinator for Health IT (ONC) are pleased to announce the release of version 3.7 of the Security Risk Assessment (SRA) Tool. To help you make the most of …DATABREACHES.NET
13 SepSix in 10 Cyberattacks in Colombia Target HospitalsJoseph Freixes reports: Six in 10 cyberattacks recorded in Colombia target health sector institutions, a figure that highlights the growing exposure of hospitals and clinics to digital threats. The figure, included in a Biofile report based on a measurement analyzed from IBM’s X-…DATABREACHES.NET
12 SepOpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc ServersThe "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software supply ch…THEHACKERNEWS.COM
12 SepBlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-DaysMultiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments. The post BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days appeared first on SecurityWeek .SECURITYWEEK.COM
12 SepTelegram Desktop bug lets poisoned messages steal exported chat historiesA vulnerability in Telegram Desktop could allow specially crafted bot messages to execute JavaScript inside HTML chat exports, potentially exposing the messages and metadata contained in those files. The flaw was fixed in July, roughly two months before its public disclosure, but…CYBERINSIDER.COM
12 SepRevolut confirms customer data breach through fake government requestsRevolut said it notified affected customers and alerted the relevant government agency, law enforcement, and financial regulators.TECHCRUNCH.COM
12 SepAnthropic: AI Misuse Is Entering a New Phase: From Cybercrime to Surveillance, Propaganda and WeaponsAI is becoming an operational force for cybercrime, surveillance, propaganda, fraud and weapons development, lowering the cost and scale of attacks. Artificial intelligence (AI) is becoming more than a tool for people who want to do something malicious. It is increasingly becomin…SECURITYAFFAIRS.COM
12 SepRevolut Exposed KYC Data After Fraudulent Government Email Passed Security ChecksRevolut handed over KYC documents, selfies, and Bitcoin transaction histories after a fake government email with valid domain credentials passed its checks. Revolut confirmed on September 12, 2026, that it disclosed sensitive customer data to an unauthorized third party after rec…SECURITYAFFAIRS.COM
12 SepNot just Korea: Google leaked identifying info for sex crime victims across the worldShin Da-eun and Park Kang-su report: Korea was not the only country where victims who sent Google removal requests about illegally obtained sexual images ended up having their private information posted online, the Hankyoreh has confirmed. “Photos of me from when I was a minor we…DATABREACHES.NET
12 SepNYS DFS Issues New Cybersecurity Guidance on Risk Assessments for Financial Services EntitiesNew York State Department of Financial Services (DFS): September 10, 2026 New York State Department of Financial Services (DFS) Acting Superintendent Kaitlin Asrow today issued new cybersecurity guidance outlining the Department’s expectations for DFS-regulated entities’ on condu…DATABREACHES.NET
11 SepShieldCrash zero-day breaks Microsoft's newest patch, AI agents compromise 440 school print servers, Fortinet's 92-day streak endsDefender Patch Broken in 24 Hours, AI Agents Hit Papercut Servers, FTC Rolls Back Health App Breach Rules Microsoft patched a Defender zero day, but a day later researcher Nightmare Eclipse released "ShieldCrash," a new exploit that bypasses the ShieldBreak fix, itself a bypass o…CYBERSECURITYTODAY.LIBSYN.COM
11 SepChina-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT BackdoorA China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in research published Thursday. The attack started …THEHACKERNEWS.COM
11 Sep KEVPaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited FlawsPaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said PaperCut NG/MF versions 26.0.5,…THEHACKERNEWS.COM
11 SepHow AI and cybersecurity are reshaping ServiceNowThe once stable era of IT service management (ITSM) has entered a period of disruption and uncertainty. At least if you’re an investor or enterprise customer with an interest in ITSM giant ServiceNow, the signals over recent months have been hard to ignore. Last year, the categor…CSOONLINE.COM
11 SepAttackers use passkey-themed scams to hijack Microsoft 365 accountsAttackers are using passkey-themed social engineering to trick employees into giving them access to their Microsoft accounts. Microsoft Security Research said it has been tracking active cloud intrusions since May in which attackers impersonated IT helpdesk staff, told employees …CSOONLINE.COM
11 SepGoogle’s Early Access is creating a blind spot for malicious appsGoogle’s Early Access program is meant to give developers a place to release unfinished apps, gather feedback and handle bugs before a full launch. But new research from Bitdefender Labs suggests the feature may also be giving potentially deceptive applications an unusual advanta…CSOONLINE.COM
11 SepKiteworks Acquires Bonfy.AI to Fill the AI Gap in Data GovernanceFinancials have not been disclosed, but the estimated cost is in the tens of millions of dollars. The post Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance appeared first on SecurityWeek .SECURITYWEEK.COM
11 SepPaperCut Flaws Exploited in AI-Powered AttacksA Russian threat actor used AI to build, test, and deploy exploits against hundreds of organizations worldwide. The post PaperCut Flaws Exploited in AI-Powered Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
11 SepIndonesia Hit by Android Banking App-Cloning CampaignThe GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.DARKREADING.COM
11 SepAI agents exploited PaperCut flaws to breach 395 organizationsA threat actor built a working exploit for PaperCut print management software, then handed the job of breaking into hundreds of organizations to AI agents that did most of the work on their own, according to GreyNoise. The result was at least 440 compromised PaperCut instances ac…HELPNETSECURITY.COM
11 SepAutomox Mitigation Worklets cut endpoint exposure to unpatchable flawsAutomox has announced its AI-speed Mitigation Worklet Pipeline, which automates mitigation to reduce risk from the increased volume and velocity of frontier-model AI vulnerabilities. Now the time from vulnerability disclosure to exposure mitigation is shortened from days or weeks…HELPNETSECURITY.COM
11 SepCompanies may be measuring phishing resilience the wrong wayCompanies that judge phishing simulation programs by how often employees click simulated attack emails may be overlooking more important indicators of cyber resilience, according to Pistachio’s Phishing Behaviour Report 2026. Examples of difficult simulations (Source: Pistachio) …HELPNETSECURITY.COM
11 SepAI is changing what Salesforce security needs to governExisting security and governance practices have largely focused on identities, permissions, access, configurations and controls. WithSecure’s Navigating Trust in the Modern Salesforce Ecosystem paper says Salesforce environments also require organizations to understand what infor…HELPNETSECURITY.COM
11 SepNew infosec products of the week: September 11, 2026Here’s a look at the most interesting products from the past week, featuring releases from Akeyless, Orchid Security, Scytale, and Securin. Securin Platform helps security teams prove when attack paths are closed Securin has announced the general availability of the Securin Platf…HELPNETSECURITY.COM
11 SepRisky Bulletin: Anthropic agents went hacking againAnthropic agents went hacking again, South Korea increases its data breach fines, Apple notifies three Turkish ministers of mercenary spyware attacks, and CISA is ready to hire 250 staff.RISKY.BIZ
11 SepUK Council Attack Linked to Mass Exploitation of SonicWall FlawA critical SonicWall flaw was rapidly weaponized, with a UK Council attack linked to a campaign that exposed credentials and enabled Active Directory theft. On July 17, 2026, the Borough Council of King’s Lynn and West Norfolk announced it had detected a cyberattack affecti…SECURITYAFFAIRS.COM
11 SepYour Critical Vulnerabilities Might Not Be Your Biggest RiskSecurity teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise. A critical vulnerability may look alarming on a scanne…THEHACKERNEWS.COM
11 SepAnthropic finds evidence of a fourth AI escaping from containmentAnthropic has owned up to a fourth security incident involving its AI model, Claude, escaping onto the open internet and attacking other organizations during a test of cybersecurity abilities on what was believed to be a closed system. The company revealed three such incidents in…CSOONLINE.COM
11 SepThe Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented EnvironmentIntroduction The surge in emerging threat actors directly correlates with the rapid escalation of victim counts and stolen financial resources. Simultaneously, this growth has spurred the proliferation of specialized supply storefronts across social media platforms, dark web chan…RAPID7.COM
11 SepClaude Used to Automate Exploitation and Data Theft Across Multiple VictimsAnthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026. The threat actors, which the artificial intelligence (AI) company has…THEHACKERNEWS.COM
11 SepIndia’s STPI serves TerminalFix-style attack via fake Cloudflare checkA website linked to India’s Software Technology Parks of India (STPI) is serving a spoofed Cloudflare verification page that silently copies a malicious string to visitors’ clipboards and prompts them to execute it via Windows Terminal, in a technique consistent with emerging Ter…CSOONLINE.COM
11 SepState authorities warn they lack resources to address cyber threat to critical sectorsA report shows that state CIOs and CISOs need additional funding, personnel and training to protect water, energy and healthcare.CYBERSECURITYDIVE.COM
11 SepArtifactory flaws chained in attacks deploying backdoor malwareThreat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. [...]BLEEPINGCOMPUTER.COM
11 SepGitLab Vulnerability Exploited One Day After DisclosureThe critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server. The post GitLab Vulnerability Exploited One Day After Disclosure appeared first on SecurityWeek .SECURITYWEEK.COM
11 SepUkrainian National Sentenced to Four Years in Prison for Wire Fraud Conspiracy in Connection with Conti RansomwareThere’s an update to a previously reported case. From the Department of Justice, this press release: Oleksii Oleksiyovych Lytvynenko, 44, a Ukrainian national, was sentenced today to four years in prison for conspiracy to commit wire fraud in connection with a conspiracy to…DATABREACHES.NET
11 SepPersonal Info Possibly Compromised at Japan’s Digital AgencyJiJi Press reports: Japan’s Digital Agency said Friday that about 246,000 sets of personal information, including the names and email addresses of government employees, may have been compromised through the unauthorized access of a network system operated by the agency. So …DATABREACHES.NET
11 SepTX: Two Lamesa ISD employees arrested over security breachUrijah Jaushlin reports: Two Lamesa ISD employees were arrested in connection with a law enforcement investigation involving allegations of a breach of computer security, according to a press release by the Lamesa Independent School District Friday morning. The Lamesa Police Depa…DATABREACHES.NET
11 Sep9/11 at 25, OfferLoader, Gemini CLI, Liquid, 10% Doom, Josh Marpet, and More - SWN #615Twenty-five years since 9/11, and we open by marking it properly — the people who didn't come home, and the survivors and responders still carrying it, physically and mentally, a quarter of a century on. Then we get to work. Shift-left didn't fail. The starting line moved. AI cod…YOUTUBE.COM
11 SepWeekly Update 521: Breach Perception v. RealityPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite I think what really resonates with me this week is being able to completely turn the tables on perceptions around things like AI being …TROYHUNT.COM
11 SepWhy AI raises the stakes for exposure validationAI dominated the conversation at Fal.Con 2026, but one of the most important takeaways wasn’t simply how AI is changing cyber defense. It was how AI is changing the speed and scale of a problem defenders already face. Security teams already have more vulnerabilities and security …CSOONLINE.COM
10 SepLove, lies, and a fake 49er.This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittn…THECYBERWIRE.COM
10 SepAI adoption brings new security headaches for already stretched CISOsCISOs are taking on AI governance without a matching increase in resources or expertise, adding to an already broad remit spanning data protection, identity, resilience and compliance, according to Proofpoint’s 2026 Voice of the CISO report. The Al mandate expands faster than res…HELPNETSECURITY.COM
10 SepEU Cyber Resilience Act to Enforce New Reporting RequirementsStarting Friday, businesses operating in the EU will have just 24 hours to notify the government any time they discover serious product security incidents.DARKREADING.COM
10 SepFour Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 DaysFour espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days. Researchers suspect AI development. Proofpoint published a detailed analysis of a Chrome-and-Windows exploit kit it tracks as BlueMoon that four nation-state actors adopted within roughly two weeks…SECURITYAFFAIRS.COM
10 SepMcKesson - 6,404,340 breached accountsIn August 2026, healthcare and pharmaceutical company McKesson was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published a substantial corpus of data they alleged was sourced from the company, which included 6.4M unique email addresses amo…HAVEIBEENPWNED.COM
10 SepNew ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft DefenderThe exploit provides full System privileges on Windows machines running the September 2026 patches. The post New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender appeared first on SecurityWeek .SECURITYWEEK.COM
10 SepNearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin KeyNearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM's own setup guide. LiteLLM is an open-source AI gateway, the software a company puts between its applications and the m…THEHACKERNEWS.COM
10 SepAnthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a growing list of cases that have raised concerns about the security risks posed by autonomous AI agents. The AI company s…THEHACKERNEWS.COM
10 SepGetting ahead of ‘harvest-now-decrypt-later’: Post-quantum cryptography planningI’ve sat in enough boardroom conversations about quantum computing to notice a pattern. Someone raises it, someone else says “that’s ten years out,” and the topic gets tabled until next year’s budget cycle. The clock that matters isn’t the one measuring when a quantum computer ar…CSOONLINE.COM
10 Sep KEVCISA: WatchGuard RCE flaw now exploited in ransomware attacksThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. [...]BLEEPINGCOMPUTER.COM
10 SepApple is building photo verification for the people who need it mostApple has introduced Apple Reference Image, an opt-in feature designed to verify the authenticity of photos taken with iPhone 18 Pro models. Apple Reference Image provides users with an unalterable reference photo, visually confirming what the sensor saw at the moment of capture.…HELPNETSECURITY.COM
10 SepAIs Compress Exploit TimelineGive an AI agent a mere rumor of an exploit, and it’s enough for them to find it. What’s worse, I found I could use my own agents to find the exploit just by knowing roughly what it was about and so could have been exploiting it well before the public patch was availa…SCHNEIER.COM
10 SepThe Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRELearn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities. The post The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
10 SepSurfshark says hackers accessed internal engineering serverSurfshark has disclosed a security incident in which an improperly configured internal test server was exposed to the internet and accessed by an unauthorized third party. The VPN provider says the breach did not affect customer data, VPN traffic, production systems, apps, or bro…CYBERINSIDER.COM
10 SepScytale expands vendor risk management with AI-powered TPRM toolsScytale has announced the launch of their latest AI-powered third-party risk management (TPRM) capabilities within its Vendors module. The release further extends vendor risk management from a periodic review exercise into a continuously updated vendor risk intelligence engine, g…HELPNETSECURITY.COM
10 SepWordPress adds automated security checks to block risky plugin releasesWordPress’ automated security review will now assess every plugin release before it is distributed through the WordPress.org update API. Releases considered a potential security risk will be blocked automatically. “A plugin can be secure today and introduce a vulnerability, or ma…HELPNETSECURITY.COM
10 Sep KEVUpdate Chrome now to protect against an actively exploited vulnerabilityChrome issues another monster update, fixing an actively exploited V8 vulnerability and 229 other flaws.MALWAREBYTES.COM
10 SepBlueMoon exploit kit lets hackers compromise fully updated Chrome usersMultiple state-aligned hacking groups have adopted a new exploit kit that can compromise Google Chrome users even when they run the latest stable browser version available at the time of the attack. The campaign, independently documented by Proofpoint and Volexity, uses a shared …CYBERINSIDER.COM
10 SepAI workflows may be creating a dangerous new authorization blind spotA newly identified AI attack technique can let unauthenticated users trigger privileged workflows and access enterprise systems, highlighting a gap in how identity and access controls apply to AI agents, according to research from Noma Labs. The report , authored by Noma Labs lea…CSOONLINE.COM
10 Sep KEVThe agentic harness for Tenable Hexa AI: How Tenable prevents AI agents from going off the railsLearn why Tenable treats agentic LLMs as untrusted insiders, and how we’ve made sure you can control and monitor the AI agents making changes in your production security environment Key takeaways AI models can quickly understand data, but not your business. While modern AI models…TENABLE.COM
10 SepUK appoints new commander of National Cyber ForceThe individual has not yet been avowed — the formal process in Britain by which an intelligence or security figure’s identity is publicly acknowledged — as routine security considerations are still being worked through.THERECORD.MEDIA
10 SepCheck Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCECheck Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not described. One flaw…THEHACKERNEWS.COM
10 SepPaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ InstancesA suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from Blackpoin…THEHACKERNEWS.COM
10 SepRussian e-commerce giant Wildberries says DDoS attack delayed payments to sellersWildberries told several Russian media outlets earlier this week that payments to some sellers were delayed by security measures introduced after a distributed denial-of-service (DDoS) attack targeted systems used to track and withdraw their earnings.THERECORD.MEDIA
10 SepDeceptive Android Apps Exploit Google Play Early Access to Evade ReviewsDeceptive apps in Early Access are being used by dishonest developers for their own benefit. The post Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews appeared first on SecurityWeek .SECURITYWEEK.COM
10 SepAttackers call employees’ personal phones to break into Microsoft 365 accountsAttackers are calling or texting employees on their personal phones, posing as internal IT staff, in a social engineering campaign that tricks them into handing over access to corporate cloud accounts. Once inside, they pull files and email from Microsoft 365 apps, SharePoint, On…HELPNETSECURITY.COM
10 SepFTC Withdraws Obsolete Policy StatementFrom the Federal Trade Commission: The Federal Trade Commission rescinded the 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices. This controversial policy statement purported to apply the FTC’s Health Breach Notification Rule to health apps and connecte…DATABREACHES.NET
10 SepKorea raises data breach fines to 10% of revenueKorea JoongAng Daily reports: Korea’s privacy regulator is sharply raising the cost of data breaches, aiming to push companies to treat data protection as a preventive investment rather than a routine cost of doing business. Starting Friday, companies found to have leaked t…DATABREACHES.NET
10 SepShinyHunters expose 6.4M in attack on medical supplier McKessonConnor Jones reports: McKesson’s cyberattack last month affected roughly 6.4 million individuals, according to Have I Been Pwned (HIBP). The breach notification service added data leaked by serial extortionists ShinyHunters, revealing the scale of the attack for the first t…DATABREACHES.NET
10 SepNew 'BlueMoon' kit exploited Windows and Chrome zero-day flawsMultiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. [...]BLEEPINGCOMPUTER.COM
10 SepBlueMoon exploit kit turns Chrome and Windows flaws into attacksFour different espionage groups used the same exploit kit to target recently fixed flaws, showing why “patch later” is a dangerous gamble.MALWAREBYTES.COM
10 SepFBI releases its first public cyber strategy.Anthropic discloses another instance of unauthorized AI access. Chinese espionage actors deploy new exploit kit.THECYBERWIRE.COM
10 SepCisco FMC flaws exploited by ransomware gang, state-sponsored hackersCisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. [...]BLEEPINGCOMPUTER.COM
10 SepNightmare-Eclipse Strikes Again with 'ShieldCrash' Windows ExploitThe disgruntled researcher continued their vendetta against Microsoft by publishing yet another zero-day exploit for Windows Defender.DARKREADING.COM
10 SepAI-powered attack exploited PaperCut flaws to hack 395 organizationsA threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers. [...]BLEEPINGCOMPUTER.COM
10 Sep KEVWhat 972 Microsoft Patches SignalMicrosoft's September security release addressed roughly 972 vulnerabilities, including 112 rated critical. Two exploited zero-days were among the issues, alongside vulnerabilities affecting Exchange Server, SharePoint, SQL Server, Remote Desktop Services, and Microsoft Authentic…YOUTUBE.COM
10 SepIt's More Secure When It's Disabled - PSW #943In the security news this week: - Microsoft patches all the things - Commissary freezers enter cyberwar - Fake AV, real Defender nap - Rowhammer comes for the GPU - BIOS updates are no longer optional - CVSS is not a crystal ball - Kworker, but make it malware - FortiGate gets a …YOUTUBE.COM
10 SepWe've got one word for it, and it's usually the wrong oneIn this week's Threat Source newsletter, Joe explores why the word "burnout" often fails to capture the true toll of working in the cybersecurity industry and why we need better language to address it.TALOSINTELLIGENCE.COM
10 SepMaking cybercrime more difficult.The FBI lays out its new Cyber Strategy. CISA plans a federal cyber overhaul. Anthropic discloses another unauthorized AI intrusion. Treasury sanctions a Chinese-language cybercrime marketplace. Another Microsoft Defender zero-day emerges. Gigabud banking malware gets stealthier.…THECYBERWIRE.COM
10 SepAI lets small actors run state-level hacking campaigns, Anthropic report findsThe report details a Russian-aligned espionage campaign against more than 20 organizations, an exploit foundry run by Chinese undergraduates and ShinyHunters-affiliated breaches, among other disrupted operations. The post AI lets small actors run state-level hacking campaigns, An…CYBERSCOOP.COM
10 SepSurfshark VPN says hackers breached internal testing, proxy serversSurfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet. [...]BLEEPINGCOMPUTER.COM
10 SepVoice Callers Exploit BYOD to Reach Microsoft 365, Corporate DataThreat actors are leveraging Microsoft's Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters.DARKREADING.COM
9 Sep KEVMicrosoft patches record 966 flaws, Cybercriminals return $265 million in BitcoinMicrosoft's Record 966-Fix Patch Tuesday, Liquid Network Bitcoin Returned (Mostly), and Five Eyes' Back-to-Basics Warning Cybersecurity Today host David Shipley reports Microsoft's largest Patch Tuesday ever with 966 vulnerability fixes (plus 204 earlier cloud-service fixes), inc…CYBERSECURITYTODAY.LIBSYN.COM
9 SepBleachBit 6.0.4 fixes secure wiping that skipped clusters on WindowsThe open source cleaner BleachBit reached version 6.0.4 this week, erasing caches, browser traces, and files on Windows, Linux, and now macOS. If you shredded a sensitive file on Windows with an earlier build, parts of it may still sit on the disk where the wipe missed. Fragmenta…HELPNETSECURITY.COM
9 SepAI-Infra-Guard: Open-source security scanner for AI systemsTencent’s Zhuque Lab built AI-Infra-Guard, an open-source security scanner for AI systems. It fingerprints running services such as Ollama, vLLM and ComfyUI and checks them against more than 1,600 known CVEs, inspects MCP servers and agent skills across 14 categories of ris…HELPNETSECURITY.COM
9 Sep KEVMicrosoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-DaysMicrosoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62…THEHACKERNEWS.COM
9 Sep KEVGoogle warns of new Chrome zero-day bug exploited in attacksGoogle has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. [...]BLEEPINGCOMPUTER.COM
9 SepNew Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM accessAn anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. [...]BLEEPINGCOMPUTER.COM
9 SepMicrosoft’s Biggest Patch Tuesday: 974 CVEs, 2 Zero-Days and 20 Wormable BugsSeptember 2026 Patch Tuesday fixes a record 974 CVEs including 2 exploited zero-days, 20 wormable bugs, and a critical Exchange RCE via Visio email. Microsoft’s September 2026 Patch Tuesday set a new record. Depending on how researchers count external and Chromium bugs, Microsoft…SECURITYAFFAIRS.COM
9 Sep50% of CISOs see Mythos as a sign to exit the professionCISOs already have it tough, but the straw that breaks the back of many IT security executives may be the rapidly advancing capabilities of frontier AI models, enterprise insistence on rapid and widespread AI experimentation, and the compounding risk responsibilities and personal…CSOONLINE.COM
9 SepSAP Patches Maximum Severity “Overpass” FlawOnapsis urges SAP customers to patch “Overpass” vulnerability, which has a CVSS score of 10.0INFOSECURITY-MAGAZINE.COM
9 SepChaotic Eclipse Released ShieldCrash, A PoC For Microsoft Defender Zero-DayThe researcher Chaotic Eclipse released ShieldCrash, a PoC exploit for a Microsoft Defender Zero-Day vulnerability. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Microsoft Defend…SECURITYAFFAIRS.COM
9 SepWhen the prompt becomes the payload: A practical pen-testing guide for GenAI, LLM and RAG applicationsGenerative AI has moved well beyond the stand-alone chatbot. It now drafts code, searches internal knowledge, reviews contracts, opens support cases and, in some deployments, takes action through connected tools. That broader role changes the security question. A tester is no lon…CSOONLINE.COM
9 SepPost-quantum cryptography adoption and the national security implicationsQuantum computers have advanced significantly in capability and compute power in the last several years and are turning theoretical vulnerabilities in modern cryptography into real-world threats. The shift to post-quantum cryptography (PQC) needs to start now, but several challen…CSOONLINE.COM
9 SepMicrosoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026The update contained 119 critical flaws and two zero days, with security teams needing to prioritize updatesINFOSECURITY-MAGAZINE.COM
9 SepChrome 153 Patches Seventh Zero-Day of 2026The Chrome update includes 230 security fixes, and users are advised to update their browsers as soon as possible. The post Chrome 153 Patches Seventh Zero-Day of 2026 appeared first on SecurityWeek .SECURITYWEEK.COM
9 SepPoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server MemoryPoisonedRefresh rootkit injects PHP web shells into F5 BIG-IP APM Apache memory, leaving no disk artifacts. SophosLabs published a detailed technical analysis on September 8, 2026, of a Linux implant, dubbed PoisonedRefresh by ESET, they found in compromised F5 BIG-IP Access Poli…SECURITYAFFAIRS.COM
9 Sep KEVMicrosoft fixes record 964 flaws, including 2 exploited zero-daysMicrosoft’s September 2026 Patch Tuesday fixes a record 964 vulnerabilities, including two actively exploited zero-days.MALWAREBYTES.COM
9 SepOver 36,000 exposed Plex servers vulnerable to recent flawsOver 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks. [...]BLEEPINGCOMPUTER.COM
9 SepIvanti Patches Critical Flaws Across Enterprise Security ProductsSix critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches for authentication bypass flaws. The post Ivanti Patches Critical Flaws Across Enterprise Security Products appeared first on SecurityWeek .SECURITYWEEK.COM
9 SepSecurin Platform helps security teams prove when attack paths are closedSecurin has announced the general availability of the Securin Platform, an AI-native Preemptive Exposure Management platform designed to answer three questions security teams struggle with every day: What can attackers actually exploit? What should we fix first? And did the fix a…HELPNETSECURITY.COM
9 SepDeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without ApprovalA flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command. The tool runs an agent's commands inside an operating-system sandbox, so that an agent working on u…THEHACKERNEWS.COM
9 SepSpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the EnterpriseNinety-five percent of organizations believe they have visibility into their AI and machine identity exposures, yet only 36% are actually monitoring them. SpyCloud , the leader in identity threat protection, today released its annual SpyCloud Identity Threat Report , a survey-bas…CSOONLINE.COM
9 SepChatGPT flaw lets attackers pull Gmail data across accounts via a hidden channelA flaw in OpenAI’s ChatGPT allowed attackers to extract data from a victim’s connected Gmail account by passing hidden instructions between separate user sessions, according to research from Check Point. In a proof-of-concept, Check Point demonstrated that a victim’s ChatGPT sess…CSOONLINE.COM
9 SepShinyHunters claims Florida DMV breach, puts data on the clockShinyHunters is claiming to have broken into a Florida government database containing sensitive information on the state’s drivers. The notorious extortion group said it has breached the Florida Department of Highway Safety and Motor Vehicles’ Driver and Vehicle Information Datab…CSOONLINE.COM
9 SepA “proof” of Fermat’s Last Theorem that fits the marginFermat famously claimed to have a “truly marvelous proof” of his Last Theorem , but he never wrote it down, insisting the margin of his page was too narrow to contain it. A few centuries later, Anthropic announced a complete formalization of Fermat’s Last Theorem using 13 m…TRAILOFBITS.COM
9 SepHackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memoryA rootkit found on hacked F5 BIG-IP APM devices skips the usual step of writing a web shell to disk, hiding it in memory instead, according to Sophos. F5 BIG-IP APM provides access policy enforcement to secure access to apps, APIs, and data. It’s primarily used by enterprises, fi…HELPNETSECURITY.COM
9 SepWebinar: Learn How to Answer “Are We Exposed?” Faster After a New CVEA major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application …THEHACKERNEWS.COM
9 SepIntroducing the CyberAgents Exchange AI Inspector: Rigorous review for community-built AIOpen-source registries for AI agents are only effective when they include a rigorous, transparent security review process for community submissions. That’s why for its new CyberAgents Exchange registry, Tenable paired its exposure management expertise with OpenAI GPT Cyber models…TENABLE.COM
9 SepUkraine prosecutor general steps down amid scam call center bribery probeUkraine’s prosecutor general, Ruslan Kravchenko, resigned this week over allegations that officials in his office took bribes to shield scam call centers from law enforcement.THERECORD.MEDIA
9 SepSkullcandy earbuds flaw lets nearby attackers access the microphoneSkullcandy Dime 3 wireless earbuds have a Bluetooth vulnerability that lets a nearby attacker pair with the device without putting it into pairing mode or getting the owner’s approval. Successful exploitation can let an attacker disrupt audio playback and potentially captur…CYBERINSIDER.COM
9 Sep“Network outage” disrupts Westfield Public Schools in New Jersey as ransomware group posts samplesJoseph Topping reports: Westfield Public Schools in New Jersey kept classrooms open during a districtwide network outage that disrupted communications and digital instruction throughout the first week of school. The district initially attributed the outage to equipment failure. “…DATABREACHES.NET
9 SepRussian suspect in bank account takeovers is extradited to USJoe Warminsky reports: A Russian web developer who played a role in a multimillion-dollar bank account takeover scheme has been extradited to the U.S. to face an indictment in the case, federal authorities said Tuesday. Sergei Anatolyevich Filimonov, 36, appeared in an Atlanta fe…DATABREACHES.NET
9 SepAkeyless adds real-time enforcement for AI agents in productionAkeyless has announced the general availability of Akeyless Agentic Runtime Authority, the real-time identity control layer for AI agent actions. It works on top of Akeyless SecretlessAI, a credential protection layer that keeps credentials out of AI agents and brokers access to …HELPNETSECURITY.COM
9 SepPassing the bucks $$$: Passback attacks explainedTL;DR Introduction Default printer configurations are common to find in internal infrastructure engagements. These configurations are usually insecure, exposing outdated protocols like SNMPv1 and web interfaces without requiring authentication. For an unauthenticated, internal at…PENTESTPARTNERS.COM
9 SepVeradigm warns of patient data breach after ransomware gang claims attackHealthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data. [...]BLEEPINGCOMPUTER.COM
9 SepCredentialed Pre-Port Discovery: Don't Probe the Host, Ask itIf your scan engine already holds credentials for a host, it can ask that host which ports are open instead of probing for them. Every scan begins with the same question: which ports on this host are open? Everything after it, from identifying services to checking for vulnerabili…RAPID7.COM
9 SepMultiple Chinese hacking groups seen using identical Chrome zero-day exploitA Google Chrome bug identified in August was exploited by at least four China-linked cyber-espionage groups, according to researchers.THERECORD.MEDIA
9 SepAI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google WarnsCriminal and state-sponsored adversaries are increasingly using AI to automate and scale their attacks, according to GTIG. The post AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns appeared first on SecurityWeek .SECURITYWEEK.COM
9 SepOff Guard: Breaking LiteLLM from authentication bypass to cloud compromiseHow default keys, unauthenticated MCP sessions, and custom code guardrails expose cloud AI infrastructure to root-level remote code execution and IAM theft.WIZ.IO
9 SepScans for Proxmox Servers, (Wed, Sep 9th)About a week ago, Proxmox published an advisory revealing a vulnerability in older versions of Proxmox VE, its flagship Virtual Environment product. The vulnerability only affects version 7, which has not been supported for a couple of years now.
ISC.SANS.EDU
9 SepMind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & WindowsOn September 1, 2026, Volexity’s Network Security Monitoring (NSM) service detected a spear-phishing campaign from a Chinese threat actor it tracks as UTA0560 targeting customers at multiple non-governmental organizations (NGOs). […] The post Mind the (Patch) Gap: Multiple …VOLEXITY.COM
9 SepU.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in CryptoThe U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and depl…THEHACKERNEWS.COM
9 SepFour Spy Groups Used the Same Chrome and Windows Exploit Kit Within a WeekMultiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to…THEHACKERNEWS.COM
9 SepThe state of AI for security: Measuring what matters most for building trustSecurity teams are starting to actively use AI for security work, including vulnerability triage, penetration testing, threat modeling, incident response, and code review. The promise is speed, but a security tool that moves fast and raises too many false alarms doesn’t save time…AWS.AMAZON.COM
9 SepFTC rescinds policy requiring health apps to notify customers after a breachThe policy, passed under the Biden administration, forced health apps to disclose when users’ personal health records were exposed in a breach or shared without authorization. The post FTC rescinds policy requiring health apps to notify customers after a breach appeared first on …CYBERSCOOP.COM
9 SepChinese espionage groups swarm to exploit triple-link chain of zero-daysMultiple China-aligned threat groups exploited the defects quickly to target various organizations. Proofpoint said the activity is ongoing and expects it to widen. The post Chinese espionage groups swarm to exploit triple-link chain of zero-days appeared first on CyberScoop .CYBERSCOOP.COM
9 SepMythos Vulnerability Firehose Hits a Human BottleneckAn analysis of Project Glasswing findings shows only a fraction have reached disclosure, and an even smaller number have been fixed.DARKREADING.COM
9 SepCO: Cyberattack damages files at Salida School District in ColoradoDysruptionHub reports: A cyberattack forced Salida School District in Colorado to shut down its network June 29, damaging locally stored files and disrupting administrative operations, the district said. The attack began about 6:30 a.m. and was detected two hours later, according…DATABREACHES.NET
8 SepProduct showcase: Doppler secures secrets for humans, pipelines, and AI agentsEvery engineering team has spent years trying to keep credentials out of source code. Then AI agents moved the problem. Coding agents review code, agents run workflows, and MCP servers broker access to databases, cloud providers, and internal APIs on a developer’s behalf. For eve…HELPNETSECURITY.COM
8 SepSecurity leaders must prepare for likely threats, not sensationalized agentic attacksA malicious dataset exploits code-execution paths in a remote-code dataset loader and a dataset configuration before compromising access credentials to move laterally through the target network. A frontier AI model publishes a malicious Python package to a public PyPI registry af…CSOONLINE.COM
8 SepSecuring AI agents: Key controls and best practicesEnterprises increasingly give AI agents the credentials, tools, and network access of privileged employees, but security experts warn that existing security controls designed to govern human access are insufficient. An AI agent operates at inhuman speed, can chain allowed actions…CSOONLINE.COM
8 SepMathspace breach exposes data on over a million students and parentsMathspace has confirmed that attackers broke into its internal reporting system through an unpatched Metabase vulnerability and stole data belonging to more than a million students, parents, and school staff. The Sydney-based maths education company wrote in a blog post that the …HELPNETSECURITY.COM
8 SepBengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support ScamsCybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has op…THEHACKERNEWS.COM
8 SepSecurity Conversations on AI, Agents, and Emerging Threats from Black Hat 2026 - ASW #399We showcase recordings from this year's Black Hat. The Hidden Risks of the AI Supply Chain - Black Hat interview with Michael Leland, VP and Field CTO of Island Agents can independently discover and install tools, but the emerging ecosystem of Skills and MCP servers lacks many of…YOUTUBE.COM
8 SepStealing AI Reasoning TracesInteresting research: “ Stealing Reasoning Traces from Proprietary LLM APIs “: Abstract: Leading large language model providers now conceal their models’ step-by-step reasoning, or chain-of-thought, to protect intellectual property and limit information leakage.…SCHNEIER.COM
8 SepBigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFAA phishing-as-a-service operation targeting Microsoft 365 users has harvested thousands of session cookies that could be used to hijack authenticated sessions after victims complete multifactor authentication, CloudSEK said. The cybersecurity firm said in a report that it uncover…CSOONLINE.COM
8 SepMikroTik router flaws allow takeover without a passwordAttackers are exploiting critical RouterOS flaws to take control of routers with SSH exposed to the internet.MALWAREBYTES.COM
8 Sep25 Years After 9/11: The CIA's First Moments Behind Enemy Lines in AfghanistanRetired Colonel Justin Sapp was a Green Beret detailed to the CIA after the September 11th terrorist attacks. He was part of Team Alpha, the first eight Americans to drop behind enemy lines into the mountains of Afghanistan. At 29, Justin was its youngest member. There was no tim…THECYBERWIRE.COM
8 SepN-able Patches Critical Zero-Day in N-centralAdministrators are advised to check their deployments for newly created user accounts they don’t recognize. The post N-able Patches Critical Zero-Day in N-central appeared first on SecurityWeek .SECURITYWEEK.COM
8 SepNorth Korea-linked Hackers Hide a Backdoor Inside HAProxyNorth Korea-linked hackers hid a backdoor inside HAProxy, masking C2 traffic and stealing data while keeping the load balancer working normally. North Korean-linked hackers found a genuinely clever hiding spot for their malware: inside the actual source code of HAProxy, the load …SECURITYAFFAIRS.COM
8 SepParty’s over for scammers who went on spending spree after $240M bitcoin theftMichael Kunzelman of the AP reports: They pulled off one of the largest cryptocurrency thefts in U.S. history, duping a stranger out of bitcoin worth over $240 million. They tried to hide their digital fingerprints, carrying out a sophisticated scheme to launder the proceeds. And…DATABREACHES.NET
8 SepThreat actors are giving AI agents a bigger role in cyberattacksAI agents are automating parts of cyberattacks with less human involvement, including vulnerability scanning, credential harvesting, and troubleshooting, according to Google Threat Intelligence Group’s Q3 2026 AI Threat Tracker. (Source: Google) The report draws on Mandiant incid…HELPNETSECURITY.COM
8 SepMars Security brings threat intelligence to detection in real timeMars Security has announced Real-Time Intel-Based Detection, a capability that turns newly published threat intelligence into validated, ready-to-deploy detection rules within minutes of release. Built by former offensive operators, the new capability converts advisories from CIS…HELPNETSECURITY.COM
8 Sep“Zero-click” WeChat worm could hijack accounts and spread via a single callResearchers with security company Calif have discovered, weaponized, and privately reported to Tencent a critical vulnerability that allowed them to create “WeWorm”, a worm that spreads via WeChat calls without any user interaction. During its rampage, the WeWorm comp…HELPNETSECURITY.COM
8 SepEverett, Massachusetts, closes City Hall after cybersecurity incidentDysruptionHub reports: Everett, Massachusetts, closed City Hall to the public Tuesday after a cybersecurity incident affected its internal network and technology systems, shifting most essential employees to another municipal building. The city said in a Monday announcement that …DATABREACHES.NET
8 SepSAP warns of maximum severity 'OVERPASS' kernel vulnerabilitySAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code. [...]BLEEPINGCOMPUTER.COM
8 SepOpenAI says GPT-6 Astra can find zero-days, but is also harder to monitorOpenAI confirmed that GPT-6 Astra is the first model it has broadly deployed to reach the "Critical level" for cybersecurity capabilities. [...]BLEEPINGCOMPUTER.COM
8 SepSAP Patches Critical Extended Passport Processing VulnerabilityAffecting the SAP kernel code, the flaw allows unauthenticated, remote attackers to run arbitrary commands, recover secrets, and modify data. The post SAP Patches Critical Extended Passport Processing Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
8 SepThe US military just turned off ad tracking on its phones. Maybe you should tooLocation data sold by the ad industry has reportedly helped adversaries target US troops. The Pentagon has responded by switching off ad tracking on its devices - and you can do the same on yours. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
8 SepMars Security Debuts Automated Threat Engine Processing Live Cyber Intelligence Into Validated Rules Within MinutesMars Security , an autonomous threat hunting and detection engineering platform founded by offensive cybersecurity veterans, today announced Real-Time Intel-Based Detection. The milestone expansion equips enterprise security operations centers (SOCs) to convert newly published th…CSOONLINE.COM
8 SepVU#718077: UEFI Shell module embedded in SPI Flash can be used to bypass Secure BootOverview The UEFI Shell program may expose raw memory access capabilities that, if present in platform firmware for debugging or advanced support use cases, could be abused to undermine UEFI Secure Boot protections. When the UEFI Shell is included in SPI flash, an attacker with t…KB.CERT.ORG
8 SepN-able issues patch for zero-day flawSecurity researchers warned the company of unusual threat activity in a recently patched N-able environment.CYBERSECURITYDIVE.COM
8 SepZero-click worm spreads on iPhones and Android via WeChat callsA zero-click worm can spread between iPhones and Android devices through WeChat calls, allowing attackers to hijack accounts even without victims answering. Dubbed WeWorm, the proof-of-concept attack exploits a memory corruption vulnerability in WeChat’s Voice-over-IP (VoIP) stac…CYBERINSIDER.COM
8 SepCISA tells operators to harden Siemens S7 PLCs. Here’s how to do it without disrupting productionOn a conventional server, disabling an unused service is usually a routine hardening task. On a Siemens S7 controller, the supposedly unused service may carry remote I/O traffic, supply process values to an HMI or provide the maintenance team’s only path to diagnostics. Close it …CSOONLINE.COM
8 SepClaude Mythos 5 is coming to Tenable One, powering the new “Adversary View”Tenable is bringing Anthropic’s Claude Mythos 5 into our enterprise security offerings. Adding frontier adversarial reasoning to the Tenable One Exposure Management Platform will help customers better anticipate how attackers could breach their environments and stay ahead of AI-f…TENABLE.COM
8 Sep KEVMicrosoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-daysToday is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. [...]BLEEPINGCOMPUTER.COM
8 SepSingaporean Ringleader of $245 Million Cryptocurrency Racketeering Enterprise Pleads Guilty in Washington D.C.WASHINGTON – Malone Lam, 22, a citizen of Singapore and recent resident of Miami, pleaded guilty today in U.S. District Court in Washington D.C. in connection with his role as ringleader of an international cybercrime conspiracy that used social engineering to steal and launder c…DATABREACHES.NET
8 Sep KEVSeptember 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while …ISC.SANS.EDU
8 SepMicrosoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-DaysThe record-breaking September security update fixes two exploited privilege-escalation zero-days and 20 potentially wormable vulnerabilities. The post Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days appeared first on SecurityWeek .SECURITYWEEK.COM
8 SepWeChat Worm Can Hijack Accounts Without Victims Answering CallsResearchers built a WeChat worm that spreads through incoming calls without user action. Tencent has blocked the exploit. Researchers at Calif created a WeChat worm that can take over an account through an incoming call, even if the victim never answers or touches the phone. The …SECURITYAFFAIRS.COM
8 SepWorming its way through WeChat.Researchers build a self-propagating attack against WeChat. Threat actors move toward multi-agent AI frameworks. N-able issues an emergency patch for a maximum-severity bug under active exploitation. MikroTik patches multiple RouterOS vulnerabilities. China accesses restricted Am…THECYBERWIRE.COM
8 SepScammer behind $245 million crypto heist pleads guilty to RICO chargesMalone Lam was indicted on scamming charges in September 2024 after drawing law enforcement scrutiny for parlaying stolen crypto into lavish Hamptons vacations, cars and private jets.THERECORD.MEDIA
8 Sep KEVThe EU CRA's Real Question: What Shipped, and When Did You Know?The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly what shipped and when vulnerabilities were discovered will be cr…BLEEPINGCOMPUTER.COM
8 SepHackers breach F5 BIG-IP APM devices to deploy Linux rootkitA Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk. [...]BLEEPINGCOMPUTER.COM
8 SepSurvival of the Basics: Which Security Fundamentals Were Secretly Relying on Lazy Attackers?A few weeks ago I asked on X and LinkedIn a deceptively simple question: which “security basics” matter more against AI-armed attackers, and which ones don’t matter anymore? What Gemini think of this blog [before you freak out about ‘…but Anton, we don’t even have a consensus def…MEDIUM.COM
8 SepPatch Tuesday Sets Another Record With 974 CVEsAttackers are actively exploiting two of the vulnerabilities and another 58 are more likely to be exploited, according to Microsoft.DARKREADING.COM
8 SepHow Fast Can You Repair AI?A vulnerability in an AI-powered system can turn from a technical problem into an operational problem once the system controls real-world actions. Patching matters, but resilience also means being able to respond quickly when automated systems behave unexpectedly. The consequence…YOUTUBE.COM
8 SepMicrosoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploitedThe new record total for Patch Tuesday is 973 vulnerabilities.THERECORD.MEDIA
8 Sep KEVMicrosoft discloses two actively exploited zero-days among 974 vulnerabilitiesWhile the vendor hit another monthly record, it hasn’t resulted in a flood of active exploits. Researchers encourage customers to focus on their specific areas of risk and exposure. The post Microsoft discloses two actively exploited zero-days among 974 vulnerabilities appeared f…CYBERSCOOP.COM
7 SepIDScan sued over 153 million licence breach, FalconFlank zero-day hijacks CrowdStrike, Magento stores backdoored with no patchIdentity verification firm IDScan faces multiple lawsuits and investigations after hackers allegedly breached it. The criminals offered over 153 million U.S. and Canadian driver's license scans for sale. Nightmare Eclipse releases FalconFlank, a zero-day privilege escalation that…CYBERSECURITYTODAY.LIBSYN.COM
7 SepToolHive: The open-source way to run any MCP server securelyToolHive is an open-source platform that runs Model Context Protocol servers inside containers. An MCP server is the connector that lets an AI client like Cursor or Claude Code reach an outside tool, and Stacklok ships ToolHive under Apache 2.0, so the runtime, the Kubernetes ope…HELPNETSECURITY.COM
7 SepN-able patches max severity N-central flaw amid ongoing attacksN-able has released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw affecting its N-central remote monitoring and management (RMM) platform. [...]BLEEPINGCOMPUTER.COM
7 SepJSCeal Malware Can Bypass Google Authentication Using Stolen Session CookiesCybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. "The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-pr…THEHACKERNEWS.COM
7 SepWhat do CISOs need to rest easy about future AI risks?Security leaders’ confidence in their ability to navigate the security risks AI will pose over the next two years rests on several clear factors, according to IANS analysis of its AI Security Survey, fielded earlier this year. Of the 113 CISOs IANS surveyed in April and May, 41% …CSOONLINE.COM
7 SepResearcher Publishes CrowdStrike Privilege Escalation Zero DayA security researcher has posted a zero-day exploit in CrowdStrike which could allow hackers to escalate privilegesINFOSECURITY-MAGAZINE.COM
7 Sep KEVMikroTik RouterOS bugs actively exploited in device takeover attacksCERT Polska is warning MikroTik customers to urgently update RouterOS after confirming that attackers are exploiting two critical SSH vulnerabilities to gain full administrative access to internet-exposed devices. The Polish national cybersecurity team disclosed six RouterOS vuln…CYBERINSIDER.COM
7 Sep KEVN-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE FlawEvery on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able's incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. N-able has released its fourth hotfix…THEHACKERNEWS.COM
7 SepShadow AI Epidemic: Uncovering Agents on the Endpoint, British Library Breach, & News ... - ESW #475Interview - Amit Assaraf As employees rapidly adopt local AI models, autonomous agents, and browser extensions to boost productivity, enterprise endpoints are quietly accumulating unchecked security risks. This episode explores how traditional EDR solutions miss non-binary softwa…YOUTUBE.COM
7 SepOpenAI just hit a milestone on the road to self-improving AIOpenAI has announced that it has reached a goal set last fall of having an automated research intern by September 2026. The milestone means a system can carry out well-defined research tasks under human direction, including work that would take a skilled researcher several days. …HELPNETSECURITY.COM
7 SepHackers exploit new MikroTik RouterOS flaws to hijack routersHackers are exploiting a chain of two recently disclosed vulnerabilities in MikroTik routers to take control of devices with SSH services exposed to the internet. [...]BLEEPINGCOMPUTER.COM
7 SepConnectWise warns of new ScreenConnect flaw without patchConnectWise has shared temporary mitigation measures for a new ScreenConnect Remote Access vulnerability that it plans to patch later this week. [...]BLEEPINGCOMPUTER.COM
7 SepBimbo Bakeries confirms data stolen in Oracle EBS zero-day attackBimbo Bakeries USA has disclosed a data breach caused by the exploitation of an Oracle E-Business Suite (EBS) zero-day that allowed attackers to steal files containing names and Social Security numbers. The company says it determined on December 6, 2025, that unauthorized parties…CYBERINSIDER.COM
7 SepAdobe Commerce Zero-Day Exploited to Backdoor Online StoresThe StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores. The post Adobe Commerce Zero-Day Exploited to Backdoor Online Stores appeared first on SecurityWeek .SECURITYWEEK.COM
7 SepRogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected HostsCybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress, three unrelated incidents have been found to use divers…THEHACKERNEWS.COM
7 SepTelerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit ReleasedA TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports …THEHACKERNEWS.COM
7 SepSam Altman calls GPT-6 Astra rollout ‘messy’ as enterprise users wait for accessOpenAI’s rollout of its GPT-6 Astra model ran into early access issues after paying ChatGPT users were unable to use the system shortly after launch, prompting CEO Sam Altman to apologize and say the release had been “messy.” “First, sorry for the messy rollout,” OpenAI CEO Sam A…CSOONLINE.COM
7 SepNightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day ExploitsThe proof-of-concept (PoC) exploits lead to privilege escalation, spawning a shell with System privileges. The post Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits appeared first on SecurityWeek .SECURITYWEEK.COM
7 SepJapan’s Health Ministry to Strengthen Cybersecurity Measures at HospitalsThe Yomiuri Shimbun reports: The Health, Labor and Welfare Ministry is set to strengthen cybersecurity measures at hospitals to counter a surging number of cyberattacks on medical institutions. The ministry has included ¥13.7 billion in its budget request for fiscal 2027 to imple…DATABREACHES.NET
7 SepPersonal Data of Approximately 220,000 Domestic and International Gangnam Unni Users LeakedLee Seunghyeong reports: Personal information of approximately 220,000 domestic and international users has been leaked from Gangnam Unni, a beauty medical platform operated by Healing Paper. On September 7, Healing Paper announced through a public notice that on September 4, the…DATABREACHES.NET
7 SepWeverse Data Leak Affects More Than 422,000 K-Pop Fan Accountskbizoom reports: Weverse, the fan platform operated by HYBE-affiliated Weverse Company, has confirmed a security incident that affected 422,584 user accounts. The company said the exposed information consisted mainly of internal identifiers that cannot be used outside the platfor…DATABREACHES.NET
7 SepMathspace Breach Impacts More Than 1 Million Users in Australia, NZAshish Khaitan reports: The Mathspace data breach has affected 1,079,819 people in Australia and New Zealand after unauthorized parties accessed an internal reporting system and downloaded user information. Mathspace confirmed the security incident on September 3, 2026, and said …DATABREACHES.NET
7 SepMathspace discloses data breach affecting over 1 million peopleOnline maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system. [...]BLEEPINGCOMPUTER.COM
7 SepHackers exploit RouterOS flaws to hijack MikroTik devices without authenticationAttackers are exploiting a chain of RouterOS vulnerabilities to hijack MikroTik devices with SSH open to the internet, CERT Polska found. CERT Polska, Poland’s national CSIRT team, have discovered six vulnerabilities in RouterOS and coordinated their disclosure with MikroTi…HELPNETSECURITY.COM
7 SepChaotic Eclipse Released A PoC For NVIDIA GreenSection Memory Corruption Zero-DayChaotic Eclipse released GreenSection, a PoC exploit for an Nvidia GreenSection Memory Corruption Zero-Day Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Nvidia. The researcher na…SECURITYAFFAIRS.COM
7 SepFake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion AttacksThreat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and res…THEHACKERNEWS.COM
7 Sep⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and MoreTurning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a tr…THEHACKERNEWS.COM
7 Sep7th September – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 7th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Thomson Reuters, a global information and technology company, has disclosed a breach of its C-Track court case-management platfor…RESEARCH.CHECKPOINT.COM
7 SepMagento StyleSmuggler zero-day exploited to deploy Linux backdoorA zero-day vulnerability dubbed "StyleSmuggler" affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. [...]BLEEPINGCOMPUTER.COM
7 SepHackers drain $320M in Bitcoin from Liquid Network, claim they’re the good guysCarly Page reports: Hackers have drained roughly $320 million in Bitcoin from the federation wallet backing the Liquid Network, while claiming to be the good guys. Liquid, a Bitcoin sidechain developed by Blockstream and used by exchanges and other financial institutions, said in…DATABREACHES.NET
7 SepBigBear Microsoft 365 phishing service bypassed MFA at 258 organizationsBill Toulas reports: A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. Researchers at cybersecurity company CloudSEK gained administrator access to the…DATABREACHES.NET
7 SepPEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command ExecutionCybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. "Requiring prior administrative or code execution access, its installer injects the extension directly…THEHACKERNEWS.COM
7 SepStyleSmuggler: The Magento Zero-Day Behind New Store AttacksStyleSmuggler Magento zero-day is under active attack, letting unauthenticated attackers execute code and install backdoors on stores that may already be patched. A new zero-day flaw, dubbed StyleSmuggler, in Magento and Adobe Commerce is under active attack, giving unauthenticat…SECURITYAFFAIRS.COM
7 SepAI Found Vulnerabilities Just By AskingAn AI assistant was casually asked whether it could find vulnerabilities in devices connected to a computer. The result was reportedly significant vulnerabilities across consumer and prosumer products, although the findings were described as largely local and not necessarily rele…YOUTUBE.COM
7 SepMA: Springfield Public Schools will be closed Tuesday after a cyber incidentCarolyn Rodriguez reports: Springfield Public Schools will be closed Tuesday after a cyber incident disrupted systems necessary for essential school operations, Superintendent Dr. Sonia Dinnall announced Monday. According to the district, the closure will help the district contin…DATABREACHES.NET
6 SepUnpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online StoresAttackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, w…THEHACKERNEWS.COM
6 SepWhen hackers control the clock.The accurate timing data from spacecraft has become an invaluable tool for nearly every critical infrastructure sector and a greater target for malicious actors. Host Maria Varmazis and Andy Davis, Global Research Director at the NCC Group, discuss the importance of timin…THECYBERWIRE.COM
6 SepThe vulnerable clock in space.This week on T-Minus: Space-Cyber Briefing: we explore the role of timing in space and how vital these systems are for everyday functionality. Given their importance, attackers have become increasingly aware of how to exploit these systems.THECYBERWIRE.COM
6 SepWeek in review: Claude accounts compromised through infostealer, Patch Tuesday forecastHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: Anthropic locks out Claude users after infostealers hijack login sessions Anthropic has started locking users out of their Claude accounts due to their login sessions having been com…HELPNETSECURITY.COM
6 SepSecurity Affairs newsletter Round 593 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. PaperCut Flaws Exploited in Attac…SECURITYAFFAIRS.COM
6 SepAttackers Hijack MikroTik Routers Through Internet-Exposed SSH Without AuthenticationAttackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska's attack warning, published on September 5. Successful at…THEHACKERNEWS.COM
6 SepNYS Comptroller DiNapoli releases more municipal cybersecurity auditsNew York State Comptroller DiNapoli recently released some municipal audits, three of which concerned cybersecurity. The following are excerpts from the public versions of the audits. Town of Wilton – Cybersecurity (2026M-48) Audit Period January 1, 2024 – August 8, 2025 Understa…DATABREACHES.NET
6 SepNatural Resources Wales confirms data breach due to human errorNation.Cymru reports: Sensitive personal information relating to current and former Natural Resources Wales employees has been exposed in a data breach. The public body said a spreadsheet containing employee information had been inadvertently published on its website, potentially…DATABREACHES.NET
6 SepUS offers $10 million for info on Iranian allegedly behind cyberattacks on critical infrastructureJonathan Greig reports: A $10 million reward has been posted by the State Department for information on the whereabouts of senior Iranian official Amir Yaryab. Yaryab allegedly leads the Islamic Revolutionary Guard Corps’ (IRGC) Cyber-Electronic Command (CEC). U.S. officials accu…DATABREACHES.NET
6 SepYour MikroTik Router May Already Be Compromised: Look for SSH User “-2”MikroTik RouterOS SSH zero-day (MikroTrick chain) under active exploitation since Sept 2. Patch to 7.24.2, 7.23.5, or 6.49.21 immediately and check logs. Anyone running a MikroTik router with SSH exposed to the internet should treat it as compromised until proven otherwise. The p…SECURITYAFFAIRS.COM
6 SepCritical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this point, assume compromise. Attackers have been adding new accounts to affected devices to maintain access …ISC.SANS.EDU
5 SepSurviving and thriving in the AI VulnpocalypseKatie Moussouris on AI's Vulnerability Deluge, Bug Bounties, and Smart Regulation In this Cybersecurity Today on the Weekend feature interview, host David Shipley interviews cybersecurity entrepreneur and long-time hacker Katie Moussouris about today's surge in AI-driven vulnerab…CYBERSECURITYTODAY.LIBSYN.COM
5 SepNew darknet marketplace peddles millions of driver's licenses.Healthcare companies disclose breaches. Law enforcement and industry partners shutter the Sality botnet.THECYBERWIRE.COM
5 SepRMM-ber this ransomware.Ismael Valenzuela, Vice President of Labs, Threat Research and Intelligence at Arctic Wolf, sits down with Dave to discuss their work tracking Anubis. Arctic Wolf Labs details a series of 2026 Anubis ransomware intrusions, revealing affiliates using stolen VPN credentials and…THECYBERWIRE.COM
5 SepBroadcom Patches Critical VMware Workstation and Fusion VM-Escape VulnerabilitiesBroadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to …SECURITYAFFAIRS.COM
5 SepTrezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was DeletedHardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order num…THEHACKERNEWS.COM
5 SepFalconFlank Zero-Day Hits CrowdStrike Falcon SensorCyberKendra reports: A security researcher known as Chaotic Eclipse has released FalconFlank, a proof-of-concept zero-day that escalates privileges on fully patched Windows machines running CrowdStrike Falcon. The researcher — who also uses the aliases Nightmare-Eclipse, MSNightm…DATABREACHES.NET
5 SepAttackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS CredentialsJetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately r…THEHACKERNEWS.COM
5 SepFrench Police Arrest Suspected ZeroBytes Hacker Over Tax Data TheftWaqas reports: French authorities have detained an 18-year-old man suspected of belonging to ZeroBytes, a hacking group that claimed responsibility for several attacks targeting French government services and companies. The Paris prosecutor’s office disclosed the case on Septembe…DATABREACHES.NET
5 SepOpenAI Announced $1B in Defensive Tools for Water UtilitiesOpenAI pledges $1B in subsidized Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. OpenAI announced Daybreak for Frontline Defenders on September 3, 2026, committing $1 billion in subsidized access to its Daybreak cyber models, training, and t…SECURITYAFFAIRS.COM
4 SepSecurity Vulnerability in a Voting SystemIt’s a vulnerability that allows someone to recover the order of ballots cast, newly exploited with AI tools. Nearly four years since the original vulnerability was disclosed, I was still able to use it to analyze voter behavior in Georgia (one of the 21 states that uses af…SCHNEIER.COM
4 SepFBI probes 153 million driver's licence leak, Health data breach hits 9.5 million, Cyberattack closes Slovenian casinos153M Driver's Licenses for Sale, 9.5M-Patient Breach, and CISA Drops Key Security Assessments The episode reports the FBI investigating Nexus, a dark web service selling scans of over 153 million U.S. and Canadian driver's licenses and other identity documents, with evidence sugg…CYBERSECURITYTODAY.LIBSYN.COM
4 SepPlex Urges Immediate Updates After Patching Multiple Undisclosed Security FlawsPlex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws. The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what those …THEHACKERNEWS.COM
4 SepGPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit RequestsOpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the "world's most intelligent and aligned model." The development comes days after the artificial intelligence (AI) company said the model had reached the "Critical" cybersecurity capability threshold under…THEHACKERNEWS.COM
4 SepFBI investigates breach of 153 million driving license records at IDscan.netDrivers in North America received a nasty shock this week when it was revealed that digital scans of 153 million drivers’ licenses were for sale on the dark web. Among the victims were US Defense Secretary Pete Hegseth – and investigative reporter Brian Krebs, who has dug deep in…CSOONLINE.COM
4 SepOpenAI launches GPT-6 Astra, its first model to cross a critical cybersecurity thresholdOpenAI launched GPT-6 Astra on Thursday, disclosing that the new flagship model has crossed the “Critical” threshold for cybersecurity risk under its Preparedness Framework, a classification the company said triggers additional deployment restrictions. “GPT‑6 Astra is rolling out…CSOONLINE.COM
4 SepThe democratization of cyber warfare — and what it means for CISOsFor most of modern history, sophisticated and costly warfare had a high barrier to entry. In order to maintain a significant tactical advantage, you needed money, infrastructure and highly trained human resources. In the physical realm, you needed trained and capable warfighters …CSOONLINE.COM
4 SepRecorded Future Announces Automated Signature Creation, Accelerating Vulnerability PrioritizationRecorded Future's Automated Signature Creation turns new vulnerabilities into detection signatures in under an hour, matching the pace of AI-driven exploits.RECORDEDFUTURE.COM
4 SepTrezor says data of another 67,000 US customers exposed in breachTrezor says a recent breach at logistics provider ShipMonk exposed the personal and shipping information of another approximately 67,000 customers, dramatically expanding the scope of an incident first disclosed in August. The newly identified records belong to US customers who o…CYBERINSIDER.COM
4 SepNew CrowdStrike 'FalconFlank' zero-day grants SYSTEM privilegesAn anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems. [...]BLEEPINGCOMPUTER.COM
4 Sep KEVGoogle warns of new Chrome zero-day flaw exploited in attacksGoogle has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. [...]BLEEPINGCOMPUTER.COM
4 SepVMware Workstation and Fusion Updates Patch Critical VulnerabilityThe flaws could allow attackers with administrative access to a virtual machine to execute code on the host system. The post VMware Workstation and Fusion Updates Patch Critical Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
4 SepGoogle Patches 6th Chrome Zero-Day of 2026Google’s Chrome 152 security update resolves 12 vulnerabilities, including a high-severity type confusion flaw in the V8 engine. The post Google Patches 6th Chrome Zero-Day of 2026 appeared first on SecurityWeek .SECURITYWEEK.COM
4 SepNvidia Is Buying AI Platform Hugging Face for $13 BillionThe deal highlights Nvidia’s push to champion increasingly popular open-source AI models. The post Nvidia Is Buying AI Platform Hugging Face for $13 Billion appeared first on SecurityWeek .SECURITYWEEK.COM
4 Sep KEVSeptember 2026 Patch Tuesday forecast: All we need is more timeThe Patch Apocalypse is continuing unabated. We are seeing record numbers of patches being released and reported CVEs continue to grow as well. August 2026 Patch Tuesday was the second biggest in history with 398 resolved CVEs: 42 rated Critical, 355 rated Important, and 1 rated …HELPNETSECURITY.COM
4 SepScammers have figured out the best time to text youThe suspicious calls, texts, and DMs you got recently aren’t a coincidence, according to Malwarebytes. Scammers have worked out which platform gets them the best results for each type of con, and they stick to that formula. (Source: Malwarebytes) The company looked at its o…HELPNETSECURITY.COM
4 SepOpenAI is putting $1 billion behind Daybreak for defenders working without enterprise budgetsOpenAI committed $1 billion to subsidize access to its Daybreak cyber models, along with training and technical support, for organizations defending water and wastewater systems, the electric grid, state and local government, community and regional banks, nonprofits, and open-sou…HELPNETSECURITY.COM
4 SepMost of the bugs Claude Mythos found have never been checked by a humanAnthropic pointed Claude Mythos Preview at 281 open-source projects and collected 23,019 candidate vulnerabilities. External security firms reviewed 1,900 of them. Maintainers received 1,596 reports and acknowledged 1,451; 97 fixes landed upstream, and 88 findings became publishe…HELPNETSECURITY.COM
4 SepDPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectorsOverview A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty,…RAPID7.COM
4 SepHoneywell Aerospace Inc. Agrees to Pay Over $2M to Settle False Claims Act Allegations of Failing to Comply with Cybersecurity Requirements in a U.S. Department of Defense ContractA DOJ press release on September 1: The Justice Department announced today that Honeywell Aerospace Inc. has agreed to pay $2,042,518 to resolve allegations that it is liable under the False Claims Act for failing to comply with cybersecurity requirements in a contract with the U…DATABREACHES.NET
4 SepDaVita settles ransomware attack lawsuit for $15MChad Van Alstin reports an update on a ransomware attack previously reported on DataBreaches.net: Nationwide kidney dialysis chain DaVita has agreed to pay $15 million to settle a class action lawsuit stemming from a 2025 ransomware attack that exposed sensitive patient data to h…DATABREACHES.NET
4 SepLedger faces $500 million class action over data breachesPavlo Kot reports: Hardware crypto wallet maker Ledger is facing a class action seeking at least $500 million over a series of customer data breaches. The plaintiff claims the company failed to adequately protect customers’ personal information and did not take sufficient …DATABREACHES.NET
4 SepFBI probes suspected breach at IDScan.net after dark web service Nexus offered 153M+ US and Canadian driver’s license scansPierluigi Paganini reports: A dark web identity theft service called Nexus appeared on September 1, 2026, offering searchable access to more than 153 million scanned driver’s licenses belonging to people in the United States and Canada. The FBI’s New Orleans field office opened a…DATABREACHES.NET
4 SepTR: Fine for famous kebab chain that allowed theft of 500 thousand customers’ dataThe Turkish Data Protection Authority (KVKK) investigation into the data breach at the famous restaurant chain Baydöner, where the full names, phone numbers, emails, and city information of 505,337 customers were compromised, has been completed. The investigation found that there…DATABREACHES.NET
4 SepNew Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web TrafficA previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug stri…THEHACKERNEWS.COM
4 SepNightmare Eclipse drops a CrowdStrike zero-day.Extortion group leaks alleged Manchester Airports Group data. France's CNIL fines hospital over 2025 data breach.THECYBERWIRE.COM
4 SepNvidia’s $12.9B Hugging Face deal could benefit enterprisesThe chipmaker’s acquisition could eventually bring additional security resources and model evaluation tools to the platform, according to experts.CYBERSECURITYDIVE.COM
4 SepOpenAI pledges $1 billion to provide resources, training for frontline cyber defendersAmid heightened scrutiny, the company will use frontier AI to help water, power and local government providers fight malicious actors.CYBERSECURITYDIVE.COM
4 SepUsing a VM to Contain an AI AgentIt won’t work : My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt. We have to reassess sandboxing quality for capable AI agents, and in general the software stack with which they interact. An off-the-shelf VM is…SCHNEIER.COM
4 SepOpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure DefendersThe Daybreak initiative will provide subsidized AI cyber capabilities, training and technical assistance, though OpenAI has disclosed few details about costs and eligibility. The post OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders appeared fir…SECURITYWEEK.COM
4 SepOSPAR 2026 report now available with 167 services in scopeWe’re pleased to confirm the successful completion of our annual Amazon Web Services (AWS) Outsourced Service Provider’s Audit Report (OSPAR) assessment on July 29, 2026, in line with the OSPAR version 2.0 framework. The Association of Banks in Singapore (ABS) established the Gui…AWS.AMAZON.COM
4 Sep KEVWhat the Flock?The G7 and CISA prepare for the quantum threat. Nightmare Eclipse drops a CrowdStrike zero-day. The White House’s offensive hacking plan raises legal questions. CISA offers a playbook for communicating through cyber incidents. OpenAI puts a billion dollars behind AI-powered defen…THECYBERWIRE.COM
4 SepLegitimate RMM Tools Became the TrapA phishing campaign operating across 46 countries used familiar lures such as tax documents, invoices, Social Security notices, VAT notices, and shipping communications. Victims were directed toward legitimate remote management and monitoring software, including ScreenConnect, Co…YOUTUBE.COM
3 SepFlipping AI’s kill switch.This week, Dave and Ben look at two major AI stories. The first involves Anthropic winning one of its legal challenges regarding the Pentagon designating the company as a supply chain risk. The second story looks at a recent law introduced in Congress that seeks to give CISA the …THECYBERWIRE.COM
3 SepI just want to give you $25 million!This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner…THECYBERWIRE.COM
3 SepSrsly Risky Biz: China's botnets are worth disruptingTom Uren and James Wilson talk about China’s long-term shift to getting private companies to build botnets for cyberespionage. A disruption effort from the US this week is good news, but China has been using these networks for a surprisingly long time and will rebuild. They also …RISKY.BIZ
3 SepResearcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike FalconThe security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting Crowdstrike Falcon. "FalconFlank is a 0day privilege escalation that abuses the offic…THEHACKERNEWS.COM
3 SepSeemplicity Response Options accelerates vulnerability mitigationSeemplicity announced Response Options for vulnerability management and exposure management workflows. This new capability gives security teams multiple, actionable paths to closing a vulnerability finding based on context. The problem Response Options addresses is straightforwar…HELPNETSECURITY.COM
3 SepZero trust has a big AI agent problem aheadDespite singing the praises of zero trust for many years, many CISOs have struggled to implement the framework in full . And now comes what could be the final nail: agentic AI. Can zero trust coexist with autonomous agents in typical enterprise environments? Technically, yes. In …CSOONLINE.COM
3 SepPegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhoneThe iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, according to new findings from the Citizen Lab in collaboration with the SHARE Foundation. "Our analysis confirmed that an iMessage zero-click exploit was used to …THEHACKERNEWS.COM
3 SepAI agents help compress ransomware intrusion to under 10 hours, raising stakes for CISOsA ransomware attacker used AI agents to move through an enterprise network in less than 10 hours, according to Palo Alto Networks researchers, who estimated that similar work could have taken human operators about two weeks. The incident involved more than 50 techniques mapped to…CSOONLINE.COM
3 SepStop playing with the CISO role. Fix cybersecurity leadershipWe have spent years telling chief information security officers (CISOs) that they need to become better aligned with the business. They need to understand strategy. They need to speak the language of the board. They need to build relationships with business leaders. They need to …CSOONLINE.COM
3 SepYour phone or computer may soon ask how old you areCalifornia and Colorado will require operating systems to collect users’ ages, but open-source software like Linux may be exempt.MALWAREBYTES.COM
3 SepChaotic Eclipse Releases Crowdstrike Falcon ZeroDay FalconFlankChaotic Eclipse released FalconFlank, a PoC exploit for a Crowdstrike Falcon ZeroDay Elevation of Privileges Vulnerability Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Crowdstri…SECURITYAFFAIRS.COM
3 SepCisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch VulnerabilitiesPublicly disclosed S/MIME flaws could expose encrypted email content, while critical IOS XR and Nexus bugs could enable remote code execution and authentication bypass. The post Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities appeared first on…SECURITYWEEK.COM
3 SepCounterfeit installers turn routine software downloads into enterprise breachesMicrosoft has warned that attackers are breaching enterprise systems via counterfeit download sites impersonating software including Microsoft Edge, Kaspersky and Razer, delivering trojanized installers for persistent access. “Once executed, the malicious installers deploy malwar…CSOONLINE.COM
3 SepUS and Canadian Court Records Breached Following Thomson Reuters IncidentThomson Reuters has disclosed a cyber incident affecting its C-Track court management software, potentially exposing court records in Canada and the USINFOSECURITY-MAGAZINE.COM
3 SepPegasus zero-click attack infects Serbian activist’s iPhoneA member of Serbia’s pro-democracy student movement was infected with NSO Group’s Pegasus spyware through a zero-click iMessage exploit. The case is part of a broader surveillance wave that has targeted at least 14 students, activists and opposition politicians since the beginnin…CYBERINSIDER.COM
3 SepWhatsApp rolls out emergency fix for locked Android photo access bugWhatsApp announced it has begun rolling out a fix for an Android privacy issue that could allow someone with physical access to a locked phone to view the owner’s photos after initiating a WhatsApp video call. Security researcher Jose Rodriguez publicly disclosed the behavior on …CYBERINSIDER.COM
3 Sep'Breeze Comet' Tears Into Brazilian & Global Financial SystemsBrazil's most sophisticated threat group is making light work of the country's financial systems, putting money directly into its own pocket.DARKREADING.COM
3 SepRussian National Indicted For Exploiting Online Platform Used For Freelance Employment And Distributing Malware To Thousands Of VictimsSAN FRANCISCO – A federal grand jury has indicted Searzhudin Tamirlanovich Aktulaev on charges of Conspiracy, Transmission of a Program, Information, Code, and Command to Cause Damage to a Protected Computer, and Aggravated Identity Theft, among other offenses. Defendant was arre…DATABREACHES.NET
3 SepNorth Dakota Supreme Court impacted by third-party data breach that has affected dozens of statesJoe Kurzewski reports: A criminal investigation is underway after data associated with the North Dakota Supreme Court was affected by a breach of a third-party vendor used by the court. According to a news release, the North Dakota Court System was informed in late July that C-Tr…DATABREACHES.NET
3 SepThomson Reuters reveals breach that exposed U.S. and Canadian court recordsThomson Reuters has disclosed a data breach affecting C-Track, a court case management platform operated by its subsidiaries, exposing court records and sensitive personal information across courts in at least 12 US states, the US Virgin Islands, and Canada. The company published…HELPNETSECURITY.COM
3 SepMap Your AWS Network FirstA strong AWS audit starts with understanding the environment. Mapping network routes and security groups shows which systems are able—or supposed—to communicate. IAM roles then show what those systems are authorized to do. These two views reveal different parts of the attack surf…YOUTUBE.COM
3 SepSonicWall urges immediate patching of chained vulnerabilitiesJust weeks after a wave of ransomware attacks, new flaws in SMA1000 series appliances are being exploited.CYBERSECURITYDIVE.COM
3 SepPegasus Zero-Click Exploit Infects Serbian Student Activist's iPhonePegasus infected a Serbian student activist's iPhone through an iMessage zero-click exploitINFOSECURITY-MAGAZINE.COM
3 SepBraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace InventoryCybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. "Unlike the standard infostealer model, BraZetsu is a comprehensive master…THEHACKERNEWS.COM
3 SepThomson Reuters Court Software Breach May Have Exposed SSNs and Sealed DataThomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. West Pu…THEHACKERNEWS.COM
3 SepBTS #81 - Infratrust Pulse, AI's Role in SecurityIn this episode of Below the Surface, host Paul Asadoorian is joined by Eclypsium’s Vlad Babkin for a wide-ranging discussion on the latest infrastructure security risks, beginning with the August InfraTrust Pulse and expanding into management plane exploitation, BMC persistence,…ECLYPSIUM.COM
3 SepAgentic Ransomware Took Down Enterprise in Ten Hours: AI Left 80-Page AuditRoger Satterfield reports: An attacker handed an unknown corporate victim a comprehensive, 80-page security audit on Wednesday — not as a service, but as a postscript to the ransomware attack that had just consumed the victim’s enterprise. According to Palo Alto Networks…DATABREACHES.NET
3 SepHPE patches critical ArubaOS-CX remote code execution flawHewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. [...]BLEEPINGCOMPUTER.COM
3 SepOpenAI targets small utilities with $1 billion cyber defense initiativeIn a keynote speech during a summit at OpenAI’s headquarters attended by 300 enterprise security leaders and CISOs from Fortune 1000 companies, OpenAI President Greg Brockman announced Daybreak for Frontline Defenders, a new global initiative to help frontline defenders use front…CSOONLINE.COM
3 SepYour Vendor Might Be Your Blind SpotVendor trust changes dramatically with security maturity. Organizations with mature security programs tend to scrutinize everything their vendors provide. Organizations closer to the security poverty line may have to trust vendors simply because they lack the resources to verify …YOUTUBE.COM
3 SepLinux Threat Hunting - PSW #942First up: a technical segment on Linux threat hunting. We'll start this series by covering the best places to look for IoCs on Linux systems and devices, starting with startup services and scheduled tasks. Then, in the security news this week: - SonicWall zero-days, again - AI fi…YOUTUBE.COM
3 SepIntroducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak modelsUse production traffic and security signals to prioritize findings, prepare edge mitigations when safe, and propose code patches. By combining WAF data with OpenAI Daybreak models, Vulnerability Discovery and Remediation helps teams identify and patch the most critical threats fi…CLOUDFLARE.COM
3 SepWho’s watching the AI watchers?A watchdog challenges the Trump administration’s secret frontier AI reviews. METR discloses two cyberattacks. Leaked documents reveal a Russian cyber training pipeline. Rogue ScreenConnect clients spread malware like a worm. A breach exposes appellate court records across the U.S…THECYBERWIRE.COM
3 Sep KEVAttackers exploit zero-days in consistently besieged SonicWall productSonicWall customers have confronted a barrage of attacks for years, including five actively exploited vulnerabilities in SMA 1000 appliances since late 2025. The post Attackers exploit zero-days in consistently besieged SonicWall product appeared first on CyberScoop .CYBERSCOOP.COM
3 SepCNIL: Health data breach: €500,000 fine imposed on the Loire Private HospitalOn September 3, 2026, the CNIL issued a €500,000 fine against the Loire Private Hospital, for not having taken appropriate measures to ensure the security of the data of its patients and some of their relatives. During the summer of 2025, an attacker managed to connect to the ele…DATABREACHES.NET
3 SepTwo “Nephrology Associates” suffered cyberattacks. Only one of them has disclosed it.Sometimes, first impressions are wrong. And in the case of “Nephrology Associates,” DataBreaches mistakenly thought one victim was attacked by two different groups. But no, there are actually two unrelated entities with the same name that suffered attacks this year. A…DATABREACHES.NET
3 SepThe New School Safety Perimeter: Where Cybersecurity Meets Physical SecurityKumar Sokka reports: At many institutions, the student ID number exposed in a data breach is the same number that unlocks dorm doors, sits behind classroom badge readers, controls laboratory access, and authenticates into building automation systems. The badge in a student’…DATABREACHES.NET
2 SepOld, Unpatched Flaws Give Attackers Access to Philippines Nuclear AgencyThreat actors exploited commodity in ownCloud to gain initial access, resulting in stolen reactor databases, personnel records, and credential stores.DARKREADING.COM
2 SepAnthropic makes changes to stop AI agents running amok againLearning from the OpenAI-Hugging Face fiasco, as well as from recent revelations about its own model, Anthropic is revamping its security and alignment practices. The company has established controls that flag when a model attempts to break out of a sandbox or successfully access…CSOONLINE.COM
2 SepOpen-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and JiraSift is a free, open-source command line tool that searches for passwords, API keys, and other sensitive data across the places a company keeps its work: local disks, Windows file shares, an entire Active Directory domain, SharePoint, OneDrive, Teams channel files, Slack messages…HELPNETSECURITY.COM
2 Sep KEVSonicWall warns of actively exploited SMA1000 zero-day flawsSonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. [...]BLEEPINGCOMPUTER.COM
2 SepDuckDB stays open source while the team behind it goes to work for AmazonHannes Mühleisen and Mark Raasveldt started as AWS employees. The two built DuckDB, an analytical database that runs inside your process instead of on a server somebody has to administer. If you ship anything on top of DuckDB, your license does not change. Amazon did not buy the …HELPNETSECURITY.COM
2 SepAuthorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware PayloadsThe U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operation. The effort was undertaken on August 31, 2026, by authorities from the U.S., Bulgaria, Hungary, a…THEHACKERNEWS.COM
2 SepSality botnet infrastructure dismantled in joint global takedownInternational law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet. [...]BLEEPINGCOMPUTER.COM
2 SepHow China industrialized the infrastructure behind state hackingLast week, the US Justice Department and FBI announced court-authorized seizures of domains hard-coded into two complementary hacking platforms known as “QScan” and “QTRouter,” used by Chinese state-sponsored hackers to target US critical infrastructure and other sensitive networ…CSOONLINE.COM
2 Sep KEVHackers Chain Two New SonicWall Zero-Day VulnerabilitiesSonicWall has urged customers to patch two new zero-day vulnerabilities being exploited in the wildINFOSECURITY-MAGAZINE.COM
2 SepGlobal sinkhole operation ends Sality botnet’s 23-year runSality, a peer-to-peer (P2P) botnet that had been running for 23 years and infecting more than 15,000 machines worldwide, has been taken down in a joint operation by international law enforcement agencies, working with CrowdStrike and the Shadowserver Foundation. The operation cu…HELPNETSECURITY.COM
2 SepKeepnet launches free SMS/Call Reporter for iOSKeepnet, an Extended Human Risk Management (xHRM) and Secure Behavior Management platform, today launched the Keepnet SMS/Call Reporter. It is a free app that turns a suspicious SMS or phone call into a one-tap report. Anyone can download it for personal protection. Organizations…HELPNETSECURITY.COM
2 SepGeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal BackendsTwo vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026…THEHACKERNEWS.COM
2 SepManchester Airports Group - 8,728,451 breached accountsIn August 2026, Manchester Airports Group (MAG) disclosed a data breach impacting their services . The incident was later claimed by the FulcrumSec hacking group , who subsequently published email addresses and phone numbers relating to 8.7M customers of Manchester, Stansted and …HAVEIBEENPWNED.COM
2 Sep KEVWhen the patch tsunami meets the maintenance windowIn April 2026, the balance between finding software flaws and fixing them broke. Frontier AI models released by Anthropic and OpenAI can now autonomously identify exploitable vulnerabilities in production software — work that used to take experienced human researchers roughly six…CSOONLINE.COM
2 SepChrome and Firefox Updates Patch Dozens of VulnerabilitiesThe browser refreshes fix multiple use-after-free, sandbox escape, and privilege escalation bugs. The post Chrome and Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
2 SepUS and European authorities disrupt Sality botnet after 23 yearsUS and European law enforcement agencies have disrupted the long-running Sality malware operation, cutting its operators off from more than 15,000 infected computers worldwide. The coordinated action, carried out on August 31, involved the US Department of Justice, FBI, Defense C…CYBERINSIDER.COM
2 SepOpenAI’s Astra Becomes First Model to Cross Critical Cybersecurity ThresholdThe designation applies when a model can independently find and exploit zero-day vulnerabilities across many well-defended systems. The post OpenAI’s Astra Becomes First Model to Cross Critical Cybersecurity Threshold appeared first on SecurityWeek .SECURITYWEEK.COM
2 SepAnthropic introduces zero-retention AI safety monitoring for enterprisesAnthropic is introducing a new framework aimed at helping enterprises monitor AI misuse without ceding control over sensitive data, as organizations struggle to balance security visibility with strict compliance requirements. The company announced a new solution called Enterprise…CSOONLINE.COM
2 SepDropbox accounts breached through Lenovo email verification flawDropbox is warning some users that an unauthorized party accessed their accounts by exploiting a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs. [...]BLEEPINGCOMPUTER.COM
2 SepExploit Published for Fresh Cleo Harmony VulnerabilityThe security defect allows remote attackers to bypass authentication through argument bearer manipulation. The post Exploit Published for Fresh Cleo Harmony Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
2 Sep$536 and 8 Hours: AI Learns to Attack a Different PLCExperts got Claude to port a PLC exploit, but it cost $536 and 8 hours, and a later AI-generated payload accidentally destroyed the hardware. Forescout researchers just answered a question that’s been hanging over industrial security for a while: can AI actually port a work…SECURITYAFFAIRS.COM
2 SepMeta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device ControlCybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta and can give operators near-complete control of infected devices. ThreatFabric said t…THEHACKERNEWS.COM
2 SepMalicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker CodeManifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication. The command executes as the u…THEHACKERNEWS.COM
2 Sep KEVSonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNsSonicWall patched two zero-days in SMA 1000 VPNs, including a CVSS 10 pre-auth SSRF flaw, after confirming active exploitation. SonicWall has released security updates for two vulnerabilities in its SMA 1000 VPN appliances that are actively exploited in attacks in the wild. Sonic…SECURITYAFFAIRS.COM
2 SepNew darknet marketplace peddles millions of driver's licenses.Law enforcement and industry partners shutter the Sality botnet. Business news: Socure raises $156 million and acquires Fravity.THECYBERWIRE.COM
2 SepAI Security Findings Aren’t ProofAI can generate remarkably polished security findings, complete with severity ratings, CWE classifications, explanations, and proposed patches. But a convincing output is not proof that a vulnerability exists—or that a proposed fix actually resolves it. AI can still be valuable w…YOUTUBE.COM
2 SepWordPress backup plugin flaw exposes millions of sites to takeover attacksAn SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites. [...]BLEEPINGCOMPUTER.COM
2 SepOpenLeash Adds a Human Check to Risky AI Agent ActionsThe security tool intercepts potentially dangerous agent actions, blocking clear threats and requesting human approval when intent is uncertain. The post OpenLeash Adds a Human Check to Risky AI Agent Actions appeared first on SecurityWeek .SECURITYWEEK.COM
2 SepManaging identity source transition for AWS IAM Identity CenterSeptember 2, 2026: This post was republished to include Active Directory migration strategies and automation for permission sets. AWS IAM Identity Center manages user access to Amazon Web Services (AWS) resources, including both AWS accounts and applications. You can use IAM Iden…AWS.AMAZON.COM
2 SepDrive-by data theft.Nexus sells driver’s license scans on the dark web. OpenAI says its models have reached a “Critical” capability threshold. International law enforcement disrupts a decades-old botnet. AI hallucinations fuel “slop squatting.” Plus, urgent patches for Cleo Harmony and Virtualizor, …THECYBERWIRE.COM
2 SepSonicWall SMA 1000 Zero-Days Enable Unauthenticated RCEThe exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.DARKREADING.COM
2 SepDoD confirms ‘refrigeration disruption’ at military commissariesDysruptionHub raised the suspicion flag yesterday, but couldn’t get a straight answer from DOD as to whether refrigeration outages at 14 commissaries represented a cyberattack. The Military Times fared no better: With more than a half-dozen commissaries on military bases in…DATABREACHES.NET
2 SepHackers expose donor data from Russian fundraisers for Ukrainians, political prisonersDaryna Antoniuk reports: Hackers reportedly gained access to payment accounts used by two Russian fundraising projects supporting Ukrainians and political prisoners, exposing donor email addresses and limited payment card information. The unknown threat actor targeted Davayte, wh…DATABREACHES.NET
2 SepLuminis Health facilities dealing with a cyberattackBridget Byrne reports: Luminis Health is experiencing a cybersecurity incident affecting certain systems across its organization, according to a Facebook post Tuesday. “Our priority remains providing safe, high-quality care to our patients,” the health system said in the post tha…DATABREACHES.NET
2 SepJail time for Maine child in 764 marks turning point in federal law enforcementResearcher tracking 764 said the first-of-its-kind case has a wider impact that will cause ripples across the landscape of violent extremist crime. The post Jail time for Maine child in 764 marks turning point in federal law enforcement appeared first on CyberScoop .CYBERSCOOP.COM
2 SepAI’s Vulnerability Surge May Be More Manageable Than First FearedNew research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have the right strategies.DARKREADING.COM
2 SepOpenAI Astra Brings Autonomous Zero-Day Exploitation to AIOpenAI says Astra can autonomously find zero-days and build exploits, marking its first model to reach the “Critical” cyber risk level. Astra is now officially OpenAI’s highest-risk cybersecurity model. In August, OpenAI said it “couldn’t rule out” that its upcoming model had rea…SECURITYAFFAIRS.COM
2 SepSmashing Security podcast #483: This AI helps thieves steal your iPhoneYou've had your iPhone stolen. A day later, you get a text from Apple saying they've found it, and a very helpful woman called Alice from Apple Support calls to walk you through recovering it. She's polite. She's professional. But she is not from Apple. She's not even human. And …GRAHAMCLULEY.COM
1 SepBot detection arrives in CrowdSec 1.8.0, along with two DoS fixesFailed SSH logins pile up in an auth log, and a scanner walks a website looking for exposed admin paths. CrowdSec reads log sources and HTTP requests, works out which addresses are misbehaving, and hands the block to a separate remediation component sitting in front of the servic…HELPNETSECURITY.COM
1 SepNIS2 compliance: Fixing IAM and access control before the 2026 auditThe NIS2 Directive places direct obligations on organizations across supply chain risk management, incident reporting, and board-level accountability. October brings a new wave of legally binding deadlines across the EU, as member states move from transposition into enforcement. …HELPNETSECURITY.COM
1 Sep179: The Courthouse - RevisitedIn this episode we follow up with Gabby and Justin from Episode 59 - two seasoned penetration testers who tell us a story about the time when they tried to break into a courthouse but it went all wrong, and what happened in the aftermath. Sponsors This show is brought to you by D…DARKNETDIARIES.COM
1 SepRecently patched PaperCut zero-days used in data theft attacksTwo security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks. [...]BLEEPINGCOMPUTER.COM
1 SepRussia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI AnalysisCybersecurity researchers have disclosed a new technique dubbed GuardBreaker that's been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligence (AI)-assisted analysis. The idea, ESET said in …THEHACKERNEWS.COM
1 SepChina-linked hackers turn Cisco routers into covert attack infrastructureA China-linked cyber espionage group has expanded beyond VMware environments to target network and authentication infrastructure that enterprises rely on to manage access and administer critical systems, according to new findings from incident response firm Sygnia . The threat ac…CSOONLINE.COM
1 SepFixing Software Weaknesses Rather Than Just Finding More Flaws - ASW #398AppSec has always emphasized techniques and tools for discovering vulns, along with taxonomies and lists for describing them. But just piling up more CVEs into a prioritized patching queue has never been an effective strategy. Nidhi Aggarwal talks about some of the economics and …YOUTUBE.COM
1 SepChaotic Eclipse Releases Kaspersky Zero-Day HardBreacherChaotic Eclipse released HardBreacher, a PoC exploit for a Kaspersky Endpoint Security privilege escalation flaw, adding another zero-day to his list. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day…SECURITYAFFAIRS.COM
1 SepAttackers Steal METR API Key and Consume AI Credits Worth About $600,000METR (short for Model Evaluation and Threat Research and pronounced "Meter"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered "two notable security incidents" …THEHACKERNEWS.COM
1 SepAesto healthcare data breach impacts 9.5 million peopleHealthcare data migration and archiving provider Aesto has disclosed to the US Department of Health and Human Services (HHS) that a data breach announced earlier this year affected 9,540,683 individuals. The incident involved unauthorized access to part of Aesto’s Amazon Web Serv…CYBERINSIDER.COM
1 SepIntroducing Continuous Vulnerability Assessment: Real-Time Defense for the AI Threat EraDetect exposure to new vulnerabilities the moment they are published with Wiz CVAWIZ.IO
1 SepFake Cloudflare CAPTCHA tricks victims into opening a tunnel for attackersAttackers are using fake CAPTCHA prompts to trick victims into running malicious PowerShell commands as part of a multi-stage intrusion campaign that can establish persistence, conduct network reconnaissance and potentially give operators a path to deeper access within an organiz…CSOONLINE.COM
1 SepFive Venezuelans Plead Guilty in US Court to ATM JackpottingThe defendants unsuccessfully attempted to physically install malware on ATMs to force them to dispense cash. The post Five Venezuelans Plead Guilty in US Court to ATM Jackpotting appeared first on SecurityWeek .SECURITYWEEK.COM
1 SepOpenClaw rolls out system-wide overhaul, updates security controls across agent platformOpenClaw has released what it describes as the largest update in its history, introducing a system-wide overhaul spanning runtime behavior, plugins, and security controls, as enterprises increasingly evaluate how such agent-based systems operate across connected environments. “Th…CSOONLINE.COM
1 SepWhite House Launches Pilot Program in Texas to Protect Water InfrastructureProject Watershed 250 will see water providers in Texas provided with federal and private sector cybersecurity resources amid rising nation-state threatsINFOSECURITY-MAGAZINE.COM
1 SepNearly 22,000 Microsoft Exchange servers vulnerable to hijack attacksNearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. [...]BLEEPINGCOMPUTER.COM
1 SepExperiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of DollarsForescout researchers used Claude AI to port a remote code execution exploit between WAGO PLC models. The post Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars appeared first on SecurityWeek .SECURITYWEEK.COM
1 SepFake Claude Opus 5 app delivers malware and wipes its own tracksA malicious GitHub repository impersonating Anthropic and claiming to offer free access to “Claude Opus 5” is delivering RevStealer, Windows information-stealing malware that targets passwords, cryptocurrency wallet data and login credentials, according to Morphisec. Repository R…HELPNETSECURITY.COM
1 SepIE: HSE fined €645,000 over data breach affecting Westmeath hospitalAdrian Cusack reports: The Data Protection Commission has fined the HSE [Health, Safety, and Environment] more than €600,000 over the mismanagement of historical records held at St Loman’s hospital, Mullingar, and St Conal’s Hospital, Letterkenny. The fine was issued …DATABREACHES.NET
1 SepSanta Fe Schools Move Forward With New Cybersecurity PolicyAndré Salkin reports: The Santa Fe school board approved a new cybersecurity policy this week but delayed a vote on a separate policy governing student data privacy, with most board members calling it too broad and too important to rush through. The delayed measure, Draft Policy …DATABREACHES.NET
1 SepWhat AI Researchers See Beyond AIAI models can identify vulnerabilities and sometimes conclude that there is nothing further to exploit. Researchers with deep domain expertise can challenge that conclusion. Knowing the specifics of an asset, environment, and deployment can allow researchers to take an AI-generat…YOUTUBE.COM
1 SepVU#456290: Hugging Face Transformers library writes remote code to disk prior to consent checkOverview A vulnerability in the Hugging Face Transformers library (versions 4.49.0 through 5.8.1) allows remote, attacker‑controlled Python files to be written to the local disk without user authorization. The library performs a remote module fetch and local cache write before ev…KB.CERT.ORG
1 Sep13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet SeedsCybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS d…THEHACKERNEWS.COM
1 SepNovocure data breach affects more than 1,400 cancer patientsHealthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack. [...]BLEEPINGCOMPUTER.COM
1 SepWhy Even the Best Edge Security Still Misses High-Risk SessionsAttackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations identify risky sessions and make stronge…BLEEPINGCOMPUTER.COM
1 SepChaotic Eclipse Releases GenDigital Avast Antivirus ZeroDay PrettyPragueChaotic Eclipse released PrettyPrague, a PoC exploit for a GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting …SECURITYAFFAIRS.COM
1 SepNightmare Eclipse releases PoC exploit for Kaspersky Endpoint Security.Healthcare companies disclose breaches. Attackers exploit recently patched JFrog Artifactory flaw.THECYBERWIRE.COM
1 SepCISA review makes the case for eliminating vulnerability classesFor years, the security industry has treated vulnerabilities as an endless queue of individual fixes. A recent CISA review argues that this is precisely why attackers keep winning. The solution to this problem, they believe, is eliminating entire categories of weaknesses at the s…HELPNETSECURITY.COM
1 SepAttackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million RecordsAesto Health suffered a breach exposing personal and health data of more than 9.5 million people after attackers accessed its AWS infrastructure. Aesto Health, a U.S. healthcare technology company, disclosed a data breach that exposed personal and health information belonging to …SECURITYAFFAIRS.COM
1 SepLeaked Russian Cyber-Operations Training MaterialsThis is interesting: The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security. […] …SCHNEIER.COM
1 SepFrontier AI used to help exploit flaws in tests using key industrial devicesA report showed that Claude could help hackers develop attack strategies targeting PLCs used by water utilities and other industries.CYBERSECURITYDIVE.COM
1 SepBreeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment SystemsBrazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024. Google Threat Intelligence Group (GTIG) and Mandiant teams described the threat actor as "specializ…THEHACKERNEWS.COM
1 SepMalicious website themes infect outdated iPhones with spywareMalicious website themes infect unpatched iPhones with spyware when users visit a compromised site, allowing attackers to steal messages, photos, passwords, location data, and cryptocurrency wallet recovery phrases. Socket’s Threat Research Team uncovered the packages on Packagis…CYBERINSIDER.COM
1 SepAesto Health says data breach affects over 9.5 million patientsAesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. [...]BLEEPINGCOMPUTER.COM
1 SepNightmare on Windows 11.Nightmare Eclipse drops a Kaspersky zero-day. The Financial Stability Board warns frontier AI could threaten the global financial system. Anthropic says it has tightened security. CISA adopts a risk-based approach to patching. A new Windows infostealer hides in fake AI models. A …THECYBERWIRE.COM
1 SepFBI Probes Service Selling 153M+ Drivers LicensesA new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appea…KREBSONSECURITY.COM
1 SepThe CAPTCHA Is Actually the Attack“Click-fix” attacks use social engineering to convince victims to execute malicious commands themselves. One technique disguises the instructions behind a fake Cloudflare CAPTCHA and tells the user to open PowerShell or Terminal and paste a command. The attacker doesn't necessari…YOUTUBE.COM
1 SepSN 1094: AI Patching Shortcomings - Should You Trust AI-Generated Code?AI-generated code is flooding the industry, but researchers reveal that almost half of it contains critical vulnerabilities. This week, we unpack what happens when the race for automation outpaces security best practices. A possible means for preventing prompt injection abuse. Cl…TWIT.TV
31 Aug KEVShinyHunters claims another health giant breach, PaperCut rushes second emergency patch, US bans foreign grid techShiny Hunters Claims 284M McKesson Records Stolen, PaperCut Patch Bypassed Again, and White House Bans Foreign Power Grid Tech Host David Shipley covers multiple cybersecurity headlines: Shiny Hunters claims it breached healthcare giant McKesson via voice phishing, compromised Ok…CYBERSECURITYTODAY.LIBSYN.COM
31 AugHow AI could make it harder for governments to use hacking toolsAI is proving effective at finding and exploiting vulnerabilities. Some say this will make it harder for governments to use hacking tools and spyware and could reignite calls to backdoor devices.TECHCRUNCH.COM
31 AugOpenAI-led coalition warns AI will compress cyberattack timelines, expose enterprise weaknessesA coalition led by OpenAI is warning that AI will sharply accelerate the speed and scale of cyberattacks, leaving enterprises with a narrowing window to fix long-standing security weaknesses before they are exploited. “In the coming months, AI-enabled cyber attacks will become fa…CSOONLINE.COM
31 AugIs your cloud security strategy ready for AI’s looming threat?Cloud architectures designed to withstand human attackers are facing a new threat: AI agents that rewrite the rules on the pace and scope of attacks. The recent OpenAI incident involving Hugging Face offers an early example of what an autonomous AI attack can look like, with an a…CSOONLINE.COM
31 AugLife as a CISO in Hollywood: Keeping New Films Leak-Free & 4 Black Hat Interviews - ESW #474Interview with Dan Meacham, CISO at Legendary Entertainment Dan Meacham joined us to share a preview of his leadership panel at InfoSec World. At this CRA event in October, Dan will be discussing *The Augmented Defender - What AI Actually Changes on the Front Line* with Daniel Bo…YOUTUBE.COM
31 Aug[webapps] Langflow 1.8.4 - Path Traversal to Remote Code ExecutionLangflow 1.8.4 - Path Traversal to Remote Code ExecutionEXPLOIT-DB.COM
31 AugAttackers begin exploiting critical Ruby on Rails flaw.PaperCut issues emergency patch for a second zero-day. Two Nigerians extradited to US over sextortion schemes.THECYBERWIRE.COM
31 AugSlovenian casinos reopen after cyberattack knocked gaming systems offlineOne of Slovenia’s largest gambling and tourism groups has begun reopening its casinos after a cyberattack forced them to shut down for several days.THERECORD.MEDIA
31 Aug31th August – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 31st August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Manchester Airports Group, the UK operator of Manchester, London Stansted, and East Midlands airports, has disclosed a cyberattack …RESEARCH.CHECKPOINT.COM
31 AugCalifornia moves to exempt Linux from new age-verification lawCalifornia lawmakers have passed AB 1856, a bill that would exclude qualifying open-source software distributors from being treated as operating system providers under the state’s upcoming Digital Age Assurance Act (DAAA). The measure passed the Senate 39–0 on August 26, and the …CYBERINSIDER.COM
31 AugGrapheneOS may skip Pixel 11 over missing hardware security featureGrapheneOS says it may abandon support for Google’s Pixel 11 series after discovering that the new devices appear to lack usable support for ARM Memory Tagging Extension (MTE). MTE is a hardware security feature the privacy-focused Android project relies on extensively to mitigat…CYBERINSIDER.COM
31 AugNightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product ExploitKaspersky told SecurityWeek that it patched the vulnerability affecting its Endpoint Security product. The post Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit appeared first on SecurityWeek .SECURITYWEEK.COM
31 AugServiceNow Patches 3 Critical Code Injection VulnerabilitiesAttackers could exploit the security defects to execute arbitrary code and access or tamper with data. The post ServiceNow Patches 3 Critical Code Injection Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
31 AugCritical Ruby on Rails Vulnerability in Attackers’ CrosshairsNamed KindaRails2Shell, the arbitrary file read flaw allows attackers to extract secrets and execute arbitrary code remotely. The post Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek .SECURITYWEEK.COM
31 AugThreat actors are posing as AI crawlers to hunt for exposed credentialsAttackers are disguising automated scanning as traffic from AI crawlers operated by OpenAI, Anthropic, Google, Perplexity and other companies while searching websites for exposed credentials and configuration files, according to GreyNoise. (Source: GreyNoise) “Every program that …HELPNETSECURITY.COM
31 AugAttackers plant remote access tools on compromised PaperCut serversThe threat actor targeting internet-facing PaperCut Application Servers is covertly installing legitimate remote access software on them, PaperCut Software shared in the most recent update on the ongoing attack campaign. PaperCut zero-days exploited to deploy remote access tools …HELPNETSECURITY.COM
31 AugShinyHunters claims it stole 284 million patient records from McKessonHealthcare company McKesson disclosed a cybersecurity incident in which hackers got into third-party applications and stole data. McKesson is a major U.S. healthcare company that distributes pharmaceuticals, medical supplies and other healthcare products to pharmacies, hospitals …HELPNETSECURITY.COM
31 AugRussian hackers plant nuclear weapon prompt in malware to trip AI safety guardrailsRussian state hackers are trying to interfere with AI-assisted malware analysis in Ukraine by deliberately setting off AI safety mechanisms, ESET has found. The technique, named GuardBreaker by ESET, appeared in a malicious VBS script tied to UAC-0099, a Russia-aligned group prev…HELPNETSECURITY.COM
31 AugThe OpenClaw 2.0 release moves your sessions into SQLiteOpenClaw is open source software that hands an AI model small standing jobs across your accounts, the kind of chore where it watches a mailbox for vendor advisories and pings you on Telegram when one names a product you run. OpenClaw 2.0 is the largest update in the project’…HELPNETSECURITY.COM
31 Aug KEVWhat vulnerability prioritization looks like when KEV, EPSS, and CVSS disagreeIn this Help Net Security interview, Dr. Joye Purser, Global Field CISO at Cohesity, explains how to rank vulnerabilities when KEV, EPSS, and CVSS point in different directions. Active exploitation comes first, then exploit likelihood, then technical severity, with adjustments fo…HELPNETSECURITY.COM
31 AugHalo-record: Open-source audit trails for AI agentsBrian Kuan wrote halo-record, a small Python package that sits inside an AI agent and writes down the moves it makes: tool calls, model calls, data access, approvals. Each action becomes one line in a file that only ever gets appended to, and every line carries a hash of the line…HELPNETSECURITY.COM
31 AugA rough day at the extortion office and a botched attack on Blossom Health.A tip about Click2Mail was not the only interesting tip DataBreaches received on Thursday. We also received an email from someone who identified themself as a patient at Blossom Health, a US-based telehealth and psychiatry platform. “An extortionist appears to have compromi…DATABREACHES.NET
31 AugTime’s Up: Ransomware Group Claims 150,000+ Cardiology Patient Records. We’ve Seen the Data.On August 6, DataBreaches reported that Cardiology Associates of Port Huron (CAPH), a Michigan medical practice with 9 locations, appeared to have been breached by a group called Orova. As reported at the time, the listing included screenshots with personally identifiable and pro…DATABREACHES.NET
31 AugCritical GiveWP Flaw Lets Attackers Run Commands on WordPress ServersA critical GiveWP flaw lets unauthenticated attackers execute server commands. Version 4.16.7.2 fixes the PHP object injection chain. A critical vulnerability in GiveWP, one of the most widely used WordPress plugins for online donations and fundraising, can let an unauthenticated…SECURITYAFFAIRS.COM
31 AugAutomate IAM Identity Center governance with continuous discovery and reportingAWS IAM Identity Center integrates with external identity provider (IdP) to provide customers with a centralized authentication and authorization solution for AWS resources across AWS Organizations. AWS continues to invest into IAM Identity Center with a growing number of AWS ser…AWS.AMAZON.COM
31 AugIs Someone Hacking DoD Refrigerators?It sure seems like it. The stores confirmed to be affected include Fort Irwin , Calif.; F.E. Warren Air Force Base , Wyo.; Fort Huachuca , Ariz.; Naval Station Newport , R.I.; Columbus Air Force Base , Miss.; and Travis Air Force Base , Calif., according to announcements made onl…SCHNEIER.COM
31 AugWindows bug incorrectly tells users that Microsoft Defender Antivirus is turned offMicrosoft on Friday reported that a glitch is causing Windows to tell users that Microsoft Defender Antivirus is turned off when it is in fact fully functional, a bug that the vendor says it is working to fix. Consultants say that this advisory raises a major concern in that it w…CSOONLINE.COM
31 AugFive plead guilty in latest federal ATM jackpotting caseFederal law enforcement continued to warn about ATM jackpotting gangs as it announced guilty pleas from five Venezuelan nationals.THERECORD.MEDIA
31 AugCronos blockchain restarts after $74 million Tectonic exploitThe Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million. [...]BLEEPINGCOMPUTER.COM
30 AugTerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel BackdoorMicrosoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell. "While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply …THEHACKERNEWS.COM
30 AugClosing the space-cyber workforce gap.Despite the space sector's consistent growth and greater importance as a critical infrastructure sector, finding cybersecurity talent is still proving to be a challenge. Host Maria Varmazis and Nick Cohen, Principal Engineer at the Aerospace Corporation, sat down to discuss t…THECYBERWIRE.COM
30 AugFulcrumSec claims Manchester Airports hack, theft of 86 GB of dataFulcrumSec claims it stole 86 GB of data from Manchester Airports Group. BleepingComputer validated one traveller's record, while samples revealed detailed customer, booking, and travel information beyond what MAG initially disclosed. [...]BLEEPINGCOMPUTER.COM
30 AugUS government snitch-finder pleads guilty to leaking state secrets to foreign spiesConnor Jones reports: The former Defense Intelligence Agency (DIA) IT specialist previously accused of trying to pass secret and top-secret information to foreign spies has pleaded guilty following a successful FBI sting. Nathan Vilas Laatsch, then 28, and now 29, was arrested in…DATABREACHES.NET
30 AugA massive cache of Valve data has reportedly leaked online, appearing to include Portal 2’s elusive beta build and a potential weapon from Half-Life 2: Episode 3Rick Lane reports: A massive cache of internal builds from Valve has reportedly leaked online, including beta builds of several classic Valve titles and possible weapons from Half-Life 2’s cancelled third episode. The leak, which began circulating on Saturday and comes from…DATABREACHES.NET
30 AugCybercriminals build fake school websites as education attacks hit record highJoy Agwunobi reports: Cybercriminals are ramping up preparations for the new academic year by creating thousands of education-themed websites and phishing campaigns designed to steal personal and financial information from students, parents and educators, as the education sector …DATABREACHES.NET
30 AugVT: Local VA warns of possible data breachAbigail Ham reports: The U.S. Department of Veteran’s Affairs says some veterans getting services through the White River Junction, Vt. healthcare system may have had their personal information exposed in an unintentional data breach. Earlier this summer, several unencrypte…DATABREACHES.NET
30 AugExtortion Group FulcrumSec Claims 86GB Manchester Airports Group Data TheftExtortion group FulcrumSec claims they stole 86GB of Manchester Airports Group data after finding API credentials exposed in client-side JavaScript. Manchester Airports Group (MAG) disclosed a data breach on August 27 affecting customers of Manchester, London Stansted, and East M…SECURITYAFFAIRS.COM
30 Aug KEVHackers Are Probing PaperCut Servers, and 47% Still Have No PatchPaperCut servers are under active attack, while 47% of tracked installations still run unpatched versions vulnerable to remote code execution. PaperCut, the print management software running in schools, hospitals, and offices worldwide, confirmed on August 27 that a pre-authentic…SECURITYAFFAIRS.COM
29 AugHow Varonis hacks AIs into snitching on themselvesVaronis AI Threat Lead on Copilot Exploits, Prompt Injection, and the AI Hacking Trifecta The host interviews Mark Vaitsman, AI threat research lead at Varonis, about Varonis Threat Labs' research into AI vulnerabilities, including a chain of single-click exploits in Microsoft Co…CYBERSECURITYTODAY.LIBSYN.COM
29 AugBerlin Refuses to Pay Hackers Who Stole Data From the City's State NetworkBerlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortionists' demands. The same statement disclosed that forensic work had found furthe…THEHACKERNEWS.COM
29 AugCosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was VulnerableCosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was publis…THEHACKERNEWS.COM
29 AugAI Agents Escaped the Evaluation EnvironmentHugging Face reported vulnerabilities exploited by AI agents in its dataset processing pipeline. The agents were able to execute code, access credentials, and move laterally across production infrastructure. The agents also escaped their evaluation environment and used a zero-day…YOUTUBE.COM
29 AugWho let the AI hack?Today we are joined by Crystal Morin, Senior Cybersecurity Strategist, and Michael Clark, Senior Director of Threat Research, at Sysdig, sharing their work on "LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools." The Sysdig Threat Res…THECYBERWIRE.COM
29 AugThe Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants WarnPlus: Hackers target over 100 US water systems, ICE puts in an order for robot dogs, and you’ll never guess what “MrChildPorn” was arrested for.WIRED.COM
29 AugDe: Hackers demand 30 bitcoin from Berlin as sensitive data breach widensDPA reports: The Berlin state government has declined to comment on the demands made by hackers who targeted the city’s administrative data network two weeks ago, a spokeswoman said on Saturday. The government is also withholding information about which data the attackers a…DATABREACHES.NET
29 AugUS officials backpedal on claims that government agencies were hacked by ChineseAJ Vicens and Raphael Satter report: U.S. officials are backpedaling on claims that several government agencies were hacked by Chinese spies, now saying that the organizations were among the hackers’ targets. In a freshly edited statement, the Justice Department said Friday…DATABREACHES.NET
29 AugPEAR leaks data allegedly exfiltrated from South Plains Rural Health Services while SPRHS remains silentSuspectFile reports: A cyberattack against a Texas healthcare organization allegedly resulted in the exfiltration of approximately 1.4 TB of data, according to claims made by the ransomware group PEAR. The alleged victim is South Plains Rural Health Services, Inc. (SPRHS), a nonp…DATABREACHES.NET
29 AugSCOOP: Some Click2Mail customers will soon be receiving notification of a data security incidentOn August 27, DataBreaches woke up to a message request on Signal that read, “Click2mail.com checkout with a debit card, website is actively hijacked. Card gets sold to fraudsters. It’s happened twice.” DataBreaches accepted the request, and learned that the customer …DATABREACHES.NET
29 AugPhilippine Nuclear and Naval Targets Hit by Suspected Chinese OperatorAn alleged Chinese-speaking actor breached Philippine nuclear and naval targets by exploiting known flaws, stealing sensitive data. A suspected Chinese-speaking operator targeted a Philippine nuclear research body and a marine engineering company that supports the Philippine Navy…SECURITYAFFAIRS.COM
28 AugOpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging FaceOpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May. The incident, the company said, took place during cybersec…THEHACKERNEWS.COM
28 AugAlleged TeamPCP hackers arrested, Cyberattack halts medical shipments, FBI dismantles Chinese hacking platformsTeam PCP Arrests, Boston Scientific Shipping Halt, FBI Disrupts Chinese Hacking, CISA Cuts Scrutinized, and AI Email Summarizers Poisoned Host David Shipley covers five cybersecurity stories: Australian police, working with the FBI, arrested and charged two alleged core members o…CYBERSECURITYTODAY.LIBSYN.COM
28 AugNew infosec products of the month: August 2026Here’s a look at the most interesting products from the past week, featuring releases from A10 Networks, Abnormal AI, F5 Networks, Intezer, Netscout, ScienceLogic, Searchlight Cyber, SelectHub, ServiceNow, Snyk, Tanium, and Tufin. ServiceNow organizes autonomous security around s…HELPNETSECURITY.COM
28 AugFriday Squid Blogging: Truckload of Squid Spills in Rhode IslandUgh : A tractor-trailer rollover sent a truckload of squid spilling into a Rhode Island roadway, leaving a stench as they sat in the road for hours in the summer heat. Local authorities have dubbed it the “Squidpocalypse of ’26.” That would be twenty tons of squ…SCHNEIER.COM
28 AugAttackers Chain Two PaperCut Flaws to Execute Code Without AuthenticationMalicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. "This vulnerability gives an unauthenticated attacker remote control ov…THEHACKERNEWS.COM
28 AugThree CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQLServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker. The company said it deployed a security update to hosted in…THEHACKERNEWS.COM
28 AugPaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF VersionsPaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company has released an emergency patch for v25 and v26 to address the issue. It sai…THEHACKERNEWS.COM
28 AugGPUThor hardware attack can root Nvidia GPU systemsHardware security researchers from University of Toronto have developed a new memory bit flipping technique that significantly improves on previously known attacks against GPU memory. The new method can defeat the error-correcting codes (ECC) defense used on enterprise Nvidia GPU…CSOONLINE.COM
28 AugBeyond compliance: Designing systems that earn customer trustOver the years, I have learned that customer trust is not built by compliance alone. It comes from how systems actually handle data every day. In practice, I think five areas matter most Making customer intent consistent across systems Treating privacy as a distributed-systems pr…CSOONLINE.COM
28 AugSecurity Teams Become Their ToolsSecurity organizations rely on specialized teams for vulnerability management, patching, threat hunting, and other security functions. Yet much of the time and career investment can go toward learning the tools used to perform those jobs. That expertise can become so deeply embed…YOUTUBE.COM
28 AugMythos Writes the Exploit. Atlas Writes the Response. - Harman Kaur - SWN #611Most enterprise AI today is a conversation — it summarizes, suggests, recommends. Harman unpacks what changes when AI actually executes across endpoints, and the governance problem that creates. Where does the human stay in the loop, and where do they get out of the way? This seg…YOUTUBE.COM
28 AugWhen The Protocol Is The VulnerabilitySome security flaws aren't simply bugs in an application. They can be embedded in the underlying protocol or architecture, making a conventional patch impossible. IPMI is presented as an example where the weakness is fundamental enough that the recommended remediation is to stop …YOUTUBE.COM
28 AugWhy a cryptographic inventory is key for addressing the quantum computing threatWhen quantum computers become generally available, they’ll be able to crack current public-key cryptographic algorithms, putting digitally stored and transmitted data at risk. But the threat already exists, as attackers use the "harvest now, decrypt later" tactic. Discover why bu…TENABLE.COM
28 AugThe blacklist boomerang.A judge rules the Trump administration illegally labeled Anthropic a national security risk. The White House moves to keep foreign technology out of U.S. power systems. OpenAI rallies a global cyber defense push as its own AI agents exploit a Linux vulnerability. Researchers unco…THECYBERWIRE.COM
28 AugPaperCut warns of hackers using printer management software flaw in attacksPaperCut released an emergency advisory on Thursday evening saying vulnerabilities in their print management software, PaperCut NG and MF, are under active exploitation.THERECORD.MEDIA
28 AugMicrosoft Teams Has Become a Haven for Scammers in ChinaFraudsters are exploiting enterprise chat apps like Teams and Webex to trick Chinese victims into transferring large sums of money, fueling a wave of complaints.WIRED.COM
28 AugThreat Actors Abuse Cursor Agent AI to Assist Ransomware OperationsAurora ransomware operators are abusing SpaceX’s Cursor Agent AI tool to conduct tasks such as reconnaissance and exploitation activitiesINFOSECURITY-MAGAZINE.COM
28 AugExperiment shows AI agents can escape secure VMs using zero-daysA cyber-capable AI agent could repeatedly escape a QEMU/KVM virtual machine, first using known vulnerabilities and later chaining previously unknown flaws. The results challenge the assumption that conventional VMs are sufficient containment for advanced autonomous agents. Trail …CYBERINSIDER.COM
28 AugMcKesson discloses breach after ShinyHunters claims patient data theftHealthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. [...]BLEEPINGCOMPUTER.COM
28 Aug KEVPaperCut releases second emergency patch for exploited flawsPaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. [...]BLEEPINGCOMPUTER.COM
28 AugThe Vulnpocalypse Is Repricing the Bug Bounty EconomyThe surge in AI-powered vulnerability reports is driving down bug bounty prices, and that could spell trouble for independent researchers.DARKREADING.COM
27 Aug400 episodes and we still have trust issues.This week, we’re celebrating a pretty big milestone: 400 episodes of Hacking Humans! Along the way, we’ve shared hundreds of stories, scams, lessons, and plenty of memorable Catch of the Days—and we couldn’t have made it this far without you. To everyone who has listened, written…THECYBERWIRE.COM
27 AugAI will not fix a governance problem in your camera estateCamera systems often outlive the companies that install them. In this Help Net Security interview, Rob Janssens, EMEA Cyber Security Director at Hikvision Europe, discusses what happens when the integrator is gone, the documentation is lost, and nobody holds the admin credentials…HELPNETSECURITY.COM
27 AugNew GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root AccessAcademic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-service (DoS) and privilege escalation to a root she…THEHACKERNEWS.COM
27 AugCritical infrastructure’s long, undefended tail exposed by UK energy attackA cyberattack that forced a small British electricity generator offline for four days caused no power outage, threatened no part of the national grid, and may not even have been carried out by the Iran-linked hackers initially blamed. But the incident illustrates a consequential …CSOONLINE.COM
27 AugOpenAI says AI agents formed a ‘swarm’ before breaching Hugging FaceOpenAI has published a detailed post-mortem of July’s Hugging Face breach, revealing that its AI agents did far more than escape a cybersecurity sandbox. The models created an unauthorized communication network, shared exploits and credentials, coordinated attacks across separate…CYBERINSIDER.COM
27 AugATF confirms “major incident” after recent Qilin breach claimsATF, the regulatory agency that enforces federal laws governing firearms and explosives in the United States, has confirmed that one of its systems was compromised after breach claims made by the Qilin ransomware gang. [...]BLEEPINGCOMPUTER.COM
27 AugLLM-Based Social Engineering ScamsOpenAI disrupted a social engineering group from Cambodia that used ChatGPT. Its scope is impressive: The network simultaneously conducted multiple types of scams, often blending elements from different schemes. For instance, operators used dating personas to build trust before i…SCHNEIER.COM
27 Aug KEVCISA orders feds to patch Citrix NetScaler RCE flaw by SaturdayCISA has ordered U.S. government agencies to patch their Citrix NetScaler appliances against an actively exploited remote code execution vulnerability by Saturday. [...]BLEEPINGCOMPUTER.COM
27 AugUS Navy tells sailors and their families: scrub your social media, enemies are watchingThe US Navy has told its entire workforce of 340,000 active-duty personnel, 58,000 reservists, and 210,000 civilian employees to clean up their social media profiles, because adversaries might be using them to determine who they are, where they live, and when they may not be at h…BITDEFENDER.COM
27 AugSignal flaws allowed rogue servers to decrypt users’ contact queriesSecurity researchers at V12 discovered two critical vulnerabilities in Signal’s Contact Discovery Service that could allow a malicious server operator to escape the protections of its Intel SGX enclave. The flaws enabled arbitrary reading of protected enclave memory and, in the m…CYBERINSIDER.COM
27 AugTwo Alleged ‘TeamPCP’ Hackers Arrested in AustraliaAuthorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (…KREBSONSECURITY.COM
27 AugSpark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security ToolsIndividuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT. "The samples employ diverse lure themes, suggesting an effort to appeal to a broad range of potential victims. These in…THEHACKERNEWS.COM
27 AugAI can be made to read an email much differently than you doSecurity researchers are claiming it is possible for users to see one email in their inbox while their AI assistant reads another. Forcepoint X-Labs has demonstrated how a few lines of invisible HTML can be planted into an email that an AI email summarizer picks up and runs as in…CSOONLINE.COM
27 AugChinese Hacker Group QTFY Uses Custom-Built Platforms to Target US Infrastructure, FBI WarnsThe FBI advisory set out QTFY’s distributed hacking ecosystem, allowing it to exploit vulnerabilities at scale and obfuscate its activitiesINFOSECURITY-MAGAZINE.COM
27 AugUnknown PaperCut NG/MF vulnerability is under active attackA yet unspecified vulnerability affecting print management solutions PaperCut NG and PaperCut MF is being exploited by attackers, PaperCut Software warned today. “We are aware of confirmed customer incidents and are treating this matter with the highest priority,” the…HELPNETSECURITY.COM
27 AugLearn How to Build Security Operations Ready for AI-Powered AttacksSecurity teams have spent years trying to detect threats faster. AI is changing the harder part: how much time defenders have left to act. Advanced AI models can now help attackers discover vulnerabilities, generate exploit code, and move through weaknesses faster than traditiona…THEHACKERNEWS.COM
27 AugAlleged TeamPCP Hackers Charged in Australia Over Major Supply Chain AttacksThe Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged role in TeamPCP, the cybercrime group behind the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS and the AI gatew…THEHACKERNEWS.COM
27 AugWebinar: How Google Workspace breaches happen and what to do nextGoogle Workspace breaches can begin with social engineering or forgotten third-party integrations rather than sophisticated exploits. This webinar examines real-world breaches, what happens during the critical first hours, and the security controls that can make the greatest diff…BLEEPINGCOMPUTER.COM
27 AugTwo Alleged ‘TeamPCP’ Hackers Arrested in AustraliaBrian Krebs reports: Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Austra…DATABREACHES.NET
27 AugManchester Airports Group suffers data breach exposing customer dataManchester Airports Group (MAG) has disclosed a cybersecurity incident in which an unauthorized third party obtained customer information linked to airport parking, lounge, Fast Track, and Wi-Fi services. The company says payment information was not exposed and airport operations…CYBERINSIDER.COM
27 AugAmazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro PowersCybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers. The security flaw, which do…THEHACKERNEWS.COM
27 AugAustralian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and othersThe arrests come after a wave of cyberattacks earlier this year targeting tech companies that rely on high-profile and widely used open source software.TECHCRUNCH.COM
27 AugHow to build an exposure management program the business trusts: Lessons from Tenable’s CSODiscover how Tenable’s shift to an AI-driven exposure management program helped Tenable’s CSO, Robert Huber, overcome tool sprawl, unify data silos, mitigate the risk of rapid AI adoption, and shift from presenting granular, technical metrics to communicating business risk that t…TENABLE.COM
27 AugTwo alleged TeamPCP hackers arrested over global supply chain attacksTwo men from Western Australia have been charged after police allege they were part of TeamPCP, a cybercrime group that planted malicious code in open-source software, then used it to break into organizations around the world. The Australian Federal Police (AFP), working with the…HELPNETSECURITY.COM
27 AugIdentity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNsIntroduction Despite modern verification controls, identity theft remains one of the most pervasive threats to both individuals and enterprise organizations. U.S. Federal Trade Commission statistics show over 1 million identity theft reports annually, with related fraud and impos…RAPID7.COM
27 AugAustralian Police Charge Two Over TeamPCP Credential TheftAustralian police charged two men linked to TeamPCP over malware hidden in open-source code that stole 500,000+ credentials from 1,000+ organizations. Australian police have charged two men from Western Australia over a global cybercrime operation that allegedly hid malicious cod…SECURITYAFFAIRS.COM
27 AugOpenClaw went viral. Meet the maintainers building and securing it.OpenClaw is the fastest-growing project in GitHub history. Peter Steinberger and several maintainers share what they learned in the project's first six months. The post OpenClaw went viral. Meet the maintainers building and securing it. appeared first on The GitHub Blog .GITHUB.BLOG
27 AugManchester Airports Group confirms cyber attack exposed customer emails, phone numbers and vehicle detailsGabriel Higgins reports: Manchester Airports Group (MAG) has confirmed that it has been the target of a cybersecurity incident carried out by an unauthorised third party, resulting in the exposure of a quantity of customer data. The group operates Manchester, London Stansted and …DATABREACHES.NET
27 AugThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New StoriesA fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting…THEHACKERNEWS.COM
27 AugPaperCut warns of NG, MF flaw exploited in zero-day attacksPaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. [...]BLEEPINGCOMPUTER.COM
27 AugManchester Airports Group says hackers stole travelers' dataThe Manchester Airports Group (MAG) disclosed that hackers breached its systems and stole customer data, including Wi-Fi sign-ups from Manchester, Stansted, and East Midlands airports. [...]BLEEPINGCOMPUTER.COM
27 AugQilin claimed they attacked the ATF. Here’s what the ATF says.As many people have heard by now, the Qilin ransomware group claimed to have attacked the ATF. As is their regular practice, they provided no proof of their claims. Today, the ATF has issued a statement that sheds light on the incident and what ATF has found so far: WASHINGTON …DATABREACHES.NET
27 AugSwarm of 700 AI bots went rogue in hacking attackJames Titcomb reports: A swarm of 700 OpenAI bots conspired in a cyber attack last month, an investigation has revealed, in what the AI giant called a “warning shot” to the world. Independent researchers found that hundreds of AI bots worked together to attack the technology comp…DATABREACHES.NET
27 AugInside 90 days of attacks on AI infrastructureWiz honeypots uncover active campaigns targeting LiteLLM, MCP servers, and AI frameworks through RCE, blind prompt injection, and memory credential theft.WIZ.IO
27 Aug“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friendIn his first Threat Source newsletter, David Bianco explores the critical need for operational sovereignty in customizing AI guardrails to maintain the defender’s advantage.TALOSINTELLIGENCE.COM
27 AugAgentic AI Risks, CVE Program Concerns Permeate Black Hat USA 2026This installment of the Reporters' Notebook video series discusses the topics that dominated the cybersecurity conference, such as AI's effects on vulnerability reporting and security research.DARKREADING.COM
27 AugWhite House bans foreign-made equipment for power generation over cyber backdoor concernsThe Trump administration is banning the acquisition of foreign-made components used to manage electricity and power, alleging that “certain foreign actors are increasingly creating and exploiting vulnerabilities” in the technology.THERECORD.MEDIA
27 AugHacking All The Devices, with AI? - Rob Allen - PSW #941Rob Allen from ThreatLocker joins us to discuss securing agentic AI with zero-trust controls, least privilege, and access controls to limit what agents can access and do. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about …YOUTUBE.COM
27 AugSIEM: Centralize Like You Mean It, Federate Like You Have To(by Anton Chuvakin & Usman Chaudhary) Prologue: Three Years After “The End Is Nigh” Back in 2023, one of us wrote “Log Centralization: The End Is Nigh?” — an admittedly incomplete-thought blog with a scary premise: after 20+ years of yelling “centralize your logs!” (the earli…MEDIUM.COM
26 AugAI vulnerability discovery scores the highest impact of 20 emerging risksRisk managers, auditors and senior executives at 316 companies spent April and May ranking 20 threats they have not yet felt. AI discovery of cyber vulnerabilities came back first, according to Gartner. Three months earlier the same quarterly survey put information integrity risk…HELPNETSECURITY.COM
26 AugHottest cybersecurity open-source tools of the month: August 2026Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across diverse settings. SkillSpector: NVIDIA’s open-source security scanner for AI agent skills SkillSpector is an o…HELPNETSECURITY.COM
26 AugFake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA CodesCybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode. SOCRadar Threat…THEHACKERNEWS.COM
26 AugMeta adds three new features to keep WhatsApp accounts secureMeta has added new security enhancements to WhatsApp, this time in the form of stronger two-step verification, additional information about calls from unknown numbers, and the ability to add multiple passkeys to the same account. New account security features (Source: Meta) ̶…HELPNETSECURITY.COM
26 AugWho is accountable when your AI agent goes rogue?AI agents can go to great lengths to complete the tasks their operators assign, and as a series of recent incidents showed, this can include exploiting third-party systems, manipulating people, and distributing malicious code. But AI agents are not people who can be fired, sued, …CSOONLINE.COM
26 AugInterpol's Jackal IV Disrupts West African Crime InfrastructureThe international law enforcement operation focused on disrupting crime-as-a-service networks and supporting infrastructure behind groups like Black Axe.DARKREADING.COM
26 AugConnecting Cyber Risks to Board Outcomes & BHUSA interviews from Mimecast & Zscaler - BSW #462The threat landscape has become more interconnected, disruptive, and complex. Ransomware is now as much about extortion and data theft as it is about encryption. Supply chain events can create outages that ripple far beyond the initial target, and business interruption increasing…YOUTUBE.COM
26 AugExploits and vulnerabilities in Q2 2026This report covers statistics on vulnerabilities, exploits, and C2 frameworks in Q2 2026. For the first time ever, we aggregate data on vulnerabilities in open-source AI agents and AI frameworks.SECURELIST.COM
26 AugClaude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in TestsAikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the OpenClaw agent harness, exploited a client-side-only booking restriction in 9 of 10 runs. The original incident was f…THEHACKERNEWS.COM
26 AugGPUThor Rowhammer attack beats ECC on NVIDIA workstation GPUsUniversity of Toronto researchers have developed a new Rowhammer technique named GPUThor that can overwhelm error-correcting memory on several NVIDIA workstation GPUs, enabling crashes and even privilege escalation to root. The attack produces up to 23,500 times more bit flips th…CYBERINSIDER.COM
26 Aug KEVMicrosoft warns patch window is collapsing, urges shift to network-level containmentMicrosoft is warning that the window for patching vulnerabilities is rapidly shrinking, as attackers move from disclosure to exploitation faster than enterprises can safely deploy fixes, and is urging organizations to adopt network-level controls to limit exposure during that gap…CSOONLINE.COM
26 AugHackers now exploit critical Gitea flaw in code injection attacksAttackers are now exploiting a critical-severity vulnerability in the Gitea self-hosted Git service, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...]BLEEPINGCOMPUTER.COM
26 AugFour in Five AI Tools Run with No IT Oversight, New Research FindsReco report reveals growing shadow AI problem and surge in vulnerability disclosuresINFOSECURITY-MAGAZINE.COM
26 AugA recommendation from the Saskatchewan Information and Privacy Commissioner caught our eyeHere’s one we missed last week. Hannah Spray reports: The personal information of more than 2,000 people was stolen from Autism Services of Saskatoon during a data breach last year. In the aftermath, the organization properly notified the affected individuals and enhanced i…DATABREACHES.NET
26 AugUpdate Chrome before you browse againChrome’s latest update fixes 327 security vulnerabilities, including some that malicious websites could exploit as soon as you visit them.MALWAREBYTES.COM
26 AugUbiquiti patches three max severity security vulnerabilitiesUbiquiti has released security patches for three new maximum-severity vulnerabilities that threat actors can exploit remotely without privileges. [...]BLEEPINGCOMPUTER.COM
26 AugNational Kidney Registry allegedly hacked by DireWolf ransomware groupSince its emergence in May 2025, DireWolf has attacked several U.S. healthcare entities, as listed among its more than 100 targets on its dedicated leak site. As early analysts reporting on the group have noted, DireWolf encrypts victims’ files as part of their double-extor…DATABREACHES.NET
26 AugNovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 SessionsCybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that's used as a proxy to redirect Microsoft 365 sign-ins, while capturing authenticated sessions in the process. In a report shared with The Hacker News a…THEHACKERNEWS.COM
26 AugGTA 6 leak hype abused to distribute Vidar infostealer malwareMalicious websites impersonating Rockstar Games are exploiting interest in Grand Theft Auto VI leaks and an upcoming official preview to distribute the Vidar information stealer. The campaign uses fake “Play Now” and “Official Download” prompts that deliver a 1.1 MB executable na…CYBERINSIDER.COM
26 AugHackers target Microsoft SharePoint RCE chain with PoC exploitAttackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused. [...]BLEEPINGCOMPUTER.COM
26 AugStop Building a 2003 SOC with AI: Local Context, Failure Modes and Your Path (Part 3)In Part 1 of this series , we dumped a pile of uncomfortable questions on you and promised answers. In Part 2 of the series , we talked about why 1990s-2000s alert triage must die. The core thesis, if you recall: if you add AI agents into a legacy, swivel-chair SOC structure, you…MEDIUM.COM
26 AugUS takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and SenateThe DOJ said it disrupted Chinese state-backed tools used to scan, infect and exploit IoT devices for attacks on federal agencies and multiple industries.THERECORD.MEDIA
26 AugDoes Exploitation Status Actually Matter?Phishing-resistant authentication can significantly reduce credential theft, but attackers can target the authentication session itself. An adversary-in-the-middle attack can relay authentication and obtain a live session. Once inside, attackers may access Microsoft 365 or Okta r…YOUTUBE.COM
26 AugDetecting multi-stage attacks on AWS: A guide to cross-service signal correlationA single alert from one security service tells you something happened. Read that signal alongside activity from other services and your own business context, and you will know whether what happened is part of a multi-stage attack. Consider a short sequence. An identity calls GetC…AWS.AMAZON.COM
26 AugUS takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and SenateJonathan Greig reports; Chinese government hackers used tools known as “QScan” and “QTRouter” to breach multiple federal agencies since 2018, the Department of Justice said in announcing the takedown of the platforms on Wednesday. The tools were run by China-based Nanjing Xinjiuw…DATABREACHES.NET
26 AugThree 10.0 security flaws fixed across Ubiquiti’s UniFi lineThe communications product company disclosed 22 total Wednesday, all but one of which was rated “critical” at 9.0 or higher. The post Three 10.0 security flaws fixed across Ubiquiti’s UniFi line appeared first on CyberScoop .CYBERSCOOP.COM
26 AugNew GPUThor attack defeats NVIDIA ECC protection for root accessA newly disclosed Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service (DoS) and root-level privilege escalation. [...]BLEEPINGCOMPUTER.COM
26 AugWhen AI infrastructure becomes the target: Securing gateways and control pointsMicrosoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining activity. The post When AI infrastructure becomes the target: Securing gateways and control points appeared first o…MICROSOFT.COM
26 AugThe feds flip the script.The U.S. disrupts a Chinese hacking operation blamed for intrusions at several sensitive government agencies. CISA says more than 100 water systems were targeted in July. Attackers exploit a critical Gitea flaw, while malicious pages masquerade as Cloudflare verification screens.…THECYBERWIRE.COM
26 AugCritical Avada WordPress theme flaw enables zero-click RCEA critical vulnerability chain in the popular Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the server. [...]BLEEPINGCOMPUTER.COM
26 AugNSA to host a hacker reunion in bid to rebuild secretive unitMartin Matishak reports: A top U.S. spy agency will resemble a college for a while on Friday, as it hosts a first-of-its-kind reunion for alumni of its most secretive hacking unit. The National Security Agency will welcome back to campus potentially hundreds of former members of …DATABREACHES.NET
25 AugHow Equifax is using AI to elevate its cybersecurityFor nearly a decade, Equifax has been dealing with the aftermath of one of the worst cybersecurity breaches in US history, racking up $1.4 billion on cleanup costs. Among the mistakes that led to the breach were a mismanaged patching process, an expired public-key certificate, an…CSOONLINE.COM
25 AugApplying Zero Trust Principles to Agents - Kieran Human - ASW #397Sandboxing, least privilege, and monitoring are well-established controls in terms of the defenses they provide against unexpected and unauthorized actions. But being well-established in theory doesn't always translate to successful in practice. Kieran Human talks about some of t…YOUTUBE.COM
25 AugSilent Patches Don’t Stop Attackers—They Blind DefendersSilent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. The post Silent Patches Don’t Stop Attackers—They Blind Defenders appeared first on SecurityWeek .SECURITYWEEK.COM
25 AugAI supply chain risk is showing up in developer workflows firstIn this Help Net Security interview, Dr. Jaushin Lee, CEO of Zentera Systems, discusses where AI supply chain risk shows up. He says most incidents still hit developer workflows and open-source package repositories, while poisoned model weights and compromised MCP servers stay mo…HELPNETSECURITY.COM
25 AugHOL Guard: Open-source antivirus for AI agentsHOL Guard is a free, open-source tool that sits between an AI assistant and the computer it runs on. When the assistant tries something risky, the tool pauses it and asks you first. It installs in about a minute, runs on your own machine, and a typical check takes under 50 millis…HELPNETSECURITY.COM
25 AugCybersecurity jobs available right now: August 25, 2026Specialist Compliance Security AT&T | USA | On-site – View job details As a Specialist Compliance Security, you will serve as AT&T’s liaison for law enforcement, first responders, and emergency personnel nationwide. Respond 24×7 to emergency r…HELPNETSECURITY.COM
25 AugPeter Ortiz: The WWII Marine Who Foreshadowed Modern-Day Special ForcesIn 2017, journalist Katie Sanders discovered an episode of a radio program called This Is Your Life. It was a scratchy recording from 1949, and she heard the voice of 2nd Lt. Murray Simon, her grandfather, for the first time. In the episode, Murray was reunited with a man named P…THECYBERWIRE.COM
25 Aug KEVAustralia Warns of Active Exploitation of Critical TeamCity Server FlawAustralian officials are urging TeamCity customers to patch an actively exploited critical flaw, which follows a similar warning from the US governmentINFOSECURITY-MAGAZINE.COM
25 AugPolice arrests dozens of suspects in global cybercrime crackdownLaw enforcement agencies from 22 countries helped identify 263 suspects and arrested 58 individuals linked to cybercrime networks coordinated by African crime groups. [...]BLEEPINGCOMPUTER.COM
25 AugNew attack lets hackers plant hidden instructions in AI memory with a single promptA newly demonstrated attack technique allows hackers to plant hidden instructions inside an AI agent’s memory with a single prompt, enabling them to influence how the system responds to future queries. The technique, called InjecMEM, is described in a research paper as a “targete…CSOONLINE.COM
25 AugAI helps Chinese-speaking hackers speed up attacks on exposed serversA Chinese-speaking cybercrime group is using AI-driven tools to help compromise internet-facing Windows and Linux web servers, according to Cisco Talos, Cisco’s threat intelligence research unit. Talos said the activity points to increasingly automated offensive operations. Talos…CSOONLINE.COM
25 AugState divergence enables unauthorized accessWe found and reported a bug in Provenance Blockchain, a public proof-of-stake chain built on Cosmos SDK , that lets any user grant themselves admin control over marker accounts without holding a single token. Provenance covers a range of financial services, including on-chain tok…TRAILOFBITS.COM
25 Aug24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA PagesCybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. "While the malware is simply a single HTML page inside the npm package, and while downlo…THEHACKERNEWS.COM
25 AugFrontier AI: Vulnerability Management's Systemic RevolutionVulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline. The symbiotic relationship between vulnerability and patch management teams has also existed for that time and has gone through waves of contention and thankfulness. Wh…THEHACKERNEWS.COM
25 AugAnonyMousKIT service uses AI calls to unlock stolen Apple devicesA Phishing-as-a-Service (PhaaS) ecosystem dubbed AnonyMousKIT helps criminals steal Apple credentials and disable Activation Lock on stolen devices. The platform combines phishing emails, SMS, WhatsApp messages, recorded calls, and AI-powered voice agents in a credit-based servic…CYBERINSIDER.COM
25 AugHackers breached over 270 Zimbra servers in ongoing attacksThreat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability. [...]BLEEPINGCOMPUTER.COM
25 AugMarimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit ModeMarimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck's CVE Numbering Authority (CNA) record. The CNA record…THEHACKERNEWS.COM
25 AugINTERPOL crackdown on West African crime rings uncovers troubling new trendPolice across 22 countries arrested 58 people and identified 263 suspects during an eight-month INTERPOL operation targeting West African organized crime groups. Suspects detained in an operation targeting West African crime groups (Source: INTERPOL) Operation Jackal IV ran from …HELPNETSECURITY.COM
25 AugSeoul National University Hospital skips cybersecurity disclosure for years despite breach affecting 830,000This is one of those headlines where our first thought was “Uh oh!” but then we read more and thought “Hmmm…” Ko Jae-woo reports: Seoul National University Hospital has not filed a mandatory cybersecurity disclosure for years, an investigation has fo…DATABREACHES.NET
25 AugA Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClawOasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself. The findings were shared with The Hacker N…THEHACKERNEWS.COM
25 AugCISA orders agencies to fix exploited Zimbra vulnerabilityThe collaboration software’s developer took almost a full month to patch the flaw after disclosing it.CYBERSECURITYDIVE.COM
25 AugInside a Syrian Interrogation Room: The Detainee Files an Infostealer Stole From a Military Police UnitHudson Rock’s InfoStealers has an interesting story. From their Executive Summary: In May 2023, an infostealer infected a computer belonging to the Military Police Investigation Section in Suluk, northern Syria – a unit of the Turkish-backed Syrian National Army (SNA). The …DATABREACHES.NET
25 AugHealth systems warn of coordinated phishing targeting Epic’s patient portalChad Van Alstin reports: Numerous health systems across the country have issued alerts, warning patients to ignore scam messages that are attempting to phish passwords from patients, allowing hackers to gain access to Epic Systems’ MyChart patient portal. The effort appears to be…DATABREACHES.NET
25 AugResearchers warn about chained SharePoint sequenceAn authentication bypass flaw is already under exploitation, the latest in a series of recent SharePoint attacks. CYBERSECURITYDIVE.COM
25 AugNew Utah law protects student privacy after BYU research found K-12 apps were collecting and sharing dataSharman Gill reports: … BYU research finds that EdTech vendors don’t always meet their student privacy obligations; that research has led to new Utah legislation that tightens up the privacy issues. In an August 2025 investigation report prepared for the Utah State Board of…DATABREACHES.NET
25 AugFinding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClawAttackers can exploit a security bug in NVIDIA's tool to gain unauthenticated access to the local model server through the Ollama API, paving the way for persistent AI agent corruption.DARKREADING.COM
25 Aug2 weeks after JPS Health Network outage, patients still dealing with falloutGiles Bruce reports: Patients at Fort Worth, Texas-based JPS Health Network are facing lasting consequences from a network outage that stretched nearly two weeks, the Fort Worth Star-Telegram reported. JPS Health Network operated under a “controlled network downtime” starting Aug…DATABREACHES.NET
25 Aug‘Close Enough’ Data Breach Notifications Create ExposureVaughn Stupart, Matthew W. Van Hise, and Craig A. Hoffman of BakerHostetler write: One ruling is not a trend. And there can be unique factors at play in regulatory investigations related to large incidents. But a summary judgment ruling in favor of a state in a lawsuit against a …DATABREACHES.NET
25 AugWhat If Nobody Has Exploited It Yet?A vulnerability's current exploitation status can provide an important urgency signal, but it doesn't necessarily determine the risk it poses to an organization. Attack complexity may also be becoming a less reliable measure of practical risk as AI and nation-state capabilities b…YOUTUBE.COM
25 AugSN 1093: Tokens in the Stream - Why LLMs are inherently insecure and prompt injection will persistTurns out, every chatbot conversation runs on a messy hack at the heart of language models, making prompt injection an unsolved—and possibly unsolvable—security threat. Steve and Leo unravel the research that explains why "roles" in AI aren't what you think they are. Understandin…TWIT.TV
24 AugRansomware attackers are zeroing in on mid-market companiesMid-sized companies accounted for 73% of publicly disclosed ransomware and data-extortion incidents with known revenue in North America and Europe between January 2023 and June 2026, according to Black Kite. The analysis covered 13,336 incidents with known revenue and defined mid…HELPNETSECURITY.COM
24 AugAnthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source FundClaude Security, currently in public beta for Claude Enterprise customers, now runs codebase scans on Mythos 5. The post Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund appeared first on SecurityWeek .SECURITYWEEK.COM
24 AugUAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux RootkitCybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast majority of the targets are located in Brazil, Bo…THEHACKERNEWS.COM
24 Aug7 ways AI can be used to enhance security operationsAI has an almost unlimited number of applications, yet none may be more important than its ability to strengthen enterprise security. AI marks a new era of business transformation in which AI autonomy and innovation converge to redefine how people, processes, and technology inter…CSOONLINE.COM
24 AugSalesforce gave every org the same free scanner. Attackers already know what it misses.A defense every attacker can rehearse against isn't a defense. It's a false sense of security.CYBERSECURITYDIVE.COM
24 AugRethinking Application Security for the AI EraAs AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. The post Rethinking Application Security for the AI Era appeared first on SecurityWeek .SECURITYWEEK.COM
24 AugCriminal Deception in Silicon ValleyInteresting paper : Abstract: With entrepreneurial fraud cases on the rise, we investigate how entrepreneurs carry out criminal deception , employing deceptive means to defraud audiences. Analyzing court data from Silicon Valley ventures and their founders prosecuted for fraud be…SCHNEIER.COM
24 Aug KEVCISA orders urgent patching of actively exploited Zimbra flawThe Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. [...]BLEEPINGCOMPUTER.COM
24 AugWindows Defender’s own driver can leave systems defenselessA Microsoft-signed Windows Defender remediation driver can be repurposed into a kernel-level “operation engine” capable of deleting files, modifying the registry and neutralizing security controls, according to new research from Check Point Research (CPR). The technique does not …CSOONLINE.COM
24 AugCybersecurity job ads demanding AI skills double in a yearJob postings asking for AI skills in cybersecurity have doubled in a single year in G7 countries according to new research from the Cisco-founded AI Workforce Consortium. Analysis from recruitment firms Cornerstone and Indeed covering 24 months, from April 2024 to March 2026, spa…HELPNETSECURITY.COM
24 AugShinyHunters provided no real proof they hacked ReliaQuest– because they didn’t get anywhere: ReliaQuestYesterday, DataBreaches reported that ShinyHunters had added ReliaQuest to its dedicated leak site, but without any substantive proof — only a few screenshots showing access to a user account on reliaquest.okta[.]com/enduser/settings. ReliaQuest did not reply to DataBreaches’ ema…DATABREACHES.NET
24 AugShipping More AI Code Than You Can Secure? Watch How to Control Remediation DebtIf your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work. The harder part is what comes after. AI can also introduce open-source packages at a pace your security team was never bui…THEHACKERNEWS.COM
24 AugPersonal Information Exposed in Apollo Global Data BreachEduard Kovacs reports: Private equity giant Apollo Global Management has disclosed a data breach that exposed sensitive personal information. According to a data breach notice sent to affected individuals, a social engineering attack enabled threat actors to access some of the co…DATABREACHES.NET
24 AugGunra ransomware: what you need to knowThe ransomware gang Gunra has been creating havoc - exploiting unpatched VPNs and firewalls to steal data, encrypt systems, and extort victims across healthcare, finance, manufacturing, and more. Read more in my article on the Fortra blog.FORTRA.COM
24 AugSuspected Iran-linked attack knocked UK power plant offline for daysNews that suspected Iranian hackers caused the shutdown of a British power plant broke over the weekend, raising the question of whether UK’s power grid and, indeed, the country’s critical infrastructure can fend off destructive cyber attacks. According to sources of …HELPNETSECURITY.COM
24 AugVU#728712: Konami's Metal Gear Online 3 contains a heap-based buffer overflowOverview Konami's Metal Gear Online 3 video game contains a heap-based buffer overflow that can be triggered by an input‑validation vulnerability that allows match hosts to remotely execute arbitrary code on lobby members' machines through specially crafted data. Description Meta…KB.CERT.ORG
24 Aug⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and MoreA package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks th…THEHACKERNEWS.COM
24 AugHouse Democrats ask GAO to study CISA workforce cutsFive lawmakers serving on the Homeland Security Committee said Congress didn’t know enough about the Trump administration’s changes to the cybersecurity agency.CYBERSECURITYDIVE.COM
24 AugThe Vulnerability Gap: Why Discovery Is Outrunning RepairAI is discovering more vulnerabilities, faster, and under a tightening regulatory environment, making this an all-hands-on-deck moment for the cybersecurity community.DARKREADING.COM
24 AugFake GTA 6 Extended Look and demo sites deliver an infostealerBogus “Play Now” sites are exploiting the GTA 6 leak hype to spread malware that steals passwords stored in browsers.MALWAREBYTES.COM
24 AugIndian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderlyA Jersey City resident is facing charges for his alleged role as a money mule for overseas cyberscammers who stole millions from elderly New Yorkers.THERECORD.MEDIA
24 Aug“Cognizable damage” required for data breach claims, MA appeals court says in a firstChristopher R. Deubert of Constangy, Brooks, Smith & Prophete, LLP writes: Helpful guidance for businesses, and for Massachusetts state courts. In 2021, the U.S. Supreme Court held in TransUnion, LLC v. Ramirez that in a suit for damages, “the mere risk of future harm, withou…DATABREACHES.NET
24 AugAlabama launches investigation into OpenAI’s hack of Hugging FaceWeeks after OpenAI disclosed that one of its cybersecurity models had gone rogue and hacked AI dataset company Hugging Face, Alabama’s Attorney General announced an investigation into the incident.TECHCRUNCH.COM
24 AugAI Found Its Own VulnerabilityThe discussion covers a vulnerability created by AI that was later exploited by AI. After Wiz identified the issue and notified Snowflake’s security team, a patch was released the same day, followed by a JIRA token rotation. AI could accelerate both sides of the security equation…YOUTUBE.COM
24 AugHackers target WordPress sites in miniOrange auth bypass attacksHackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]BLEEPINGCOMPUTER.COM
24 AugAscent Skilled Nursing Facilities Assure Breach Victims of “Credible Evidence” Stolen Data Was DeletedA DataBreaches.net Commentary On July 31, Asheville Beaverdam NC Opco LLC d/b/a Bear Mountain Health and Rehabilitation, Asheville Victoria NC Opco LLC d/b/a Elevate Health & Rehabilitation, and Asheville US Seventy NC Opco LLC d/b/a Swannanoa Valley Health and Rehabilitation…DATABREACHES.NET
24 Aug KEVThe odds were classified.Polymarket traders win big on U.S. military insider information. Slovakia deactivates speed cameras with Russian backdoors. TikTok pays $400 million to settle kids' privacy allegations. Hackers infect Android-based car systems with botnet malware. CISA orders quick patching of an…THECYBERWIRE.COM
24 AugUnpatched Calix flaw lets hackers bypass NAT to expose internal devicesAn unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet. [...]BLEEPINGCOMPUTER.COM
23 AugShinyHunters claims hack of ReliaQuest but provides no proofCybersecurity firm ReliaQuest has reported its research findings about ShinyHunters multiple times recently. On August 17, @ReliaQuestTR tweeted that they were tracking yet another ShinyHunters campaign. But after another forum user replied on August 23 with some screenshots and …DATABREACHES.NET
22 AugAI attacks now move in minutes, not weeks: N-Able's Robert Johnston on the SOC's AI reckoningHow AI Is Reshaping MDR, SIEM, and the SOC: Robert Johnston on Faster Attacks, MSP Security, and What's Next In this Weekend episode of Cybersecurity Today, host David chats with Robert Johnston—former U.S. Marine with experience at Cyber Command, NSA, and the intelligence commun…CYBERSECURITYTODAY.LIBSYN.COM
22 AugCitrix urges immediate patching of two newly disclosed vulnerabilities.Supply chain attack compromises popular Rust library. US states sue Meta over claims that it deliberately addicts young users.THECYBERWIRE.COM
22 AugGolf Canada - 568,972 breached accountsIn mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram. The data included 569k unique email addresses along with names, usernames, dates of birth, genders and approximate geographic locations (city, province and postco…HAVEIBEENPWNED.COM
22 AugCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionA critical flaw (CVSS 9.4) in NASA/JPL’s AIT-GUI let anyone send unauthenticated commands to spacecraft instruments. Cycode researchers found that AIT-GUI, the browser-based operator console in NASA/JPL open-source AMMOS Instrument Toolkit, shipped with no authentication, n…SECURITYAFFAIRS.COM
22 AugYour Expired Visa Card Could Be ‘Zombified’ to Make Contactless PaymentsPlus: Apple sends out an “unprecedented” number of spyware warnings, Ukraine hits a Russian ecommerce giant with cyber and drone attacks, and more.WIRED.COM
22 AugConnecticut says data from 41,000 Medicaid members exposed in portal breach; the second portal incident this yearWSFB reports: State officials say a data breach involving the Connecticut Medicaid program’s provider portal exposed payment and claims information tied to roughly 41,000 HUSKY Health members. The Connecticut Department of Social Services said Gainwell Technologies, which serves …DATABREACHES.NET
21 Aug KEVNSA warns AI exploits target power and water, Android malware leaks data via nearby phones, ransomware's sweet spotNSA Warns AI-Generated Exploits Target US Critical Infrastructure + New Android Malware "Manic" + Ransomware's Mid-Market Focus In this episode of Cybersecurity Today, sponsored by NordLayer, the NSA and FBI warn of an active campaign using AI-generated exploit tools to probe US …CYBERSECURITYTODAY.LIBSYN.COM
21 AugRisky Bulletin: US warns of AI-assisted attacks against Siemens PLCsThe US warns of AI-aided attacks against Siemens PLCs, hackers breach Latvia’s road traffic agency, a new hacking tool enrolls an attacker’s passkey to your account, and academics find source code overlaps between Geedge devices and China’s Great FirewallRISKY.BIZ
21 AugNew infosec products of the week: August 21, 2026Here’s a look at the most interesting products from the past week, featuring releases from F5 Networks, Intezer, Netscout, and Tufin. NETSCOUT expands Adaptive DDoS Protection with outbound attack mitigation NETSCOUT has announced an extension of its Adaptive DDoS Protection (ADP…HELPNETSECURITY.COM
21 AugA $25 template helped scammers build hundreds of phantom bank domainsA phrase on a suspicious website turned into an investigation of phantom banks built to support scams, according to new research from Allure Security. Molly DeQuattro, the company’s VP of Operations, was reviewing a domain that resembled the brand of one of its financial se…HELPNETSECURITY.COM
21 AugNearly half of enterprises have no one leading PQC migrationEnterprises believe they are prepared for the security challenges posed by quantum computing, but gaps in ownership, testing and visibility could complicate their transition to post-quantum cryptography (PQC), according to new research from Axiad. Who owns PQC migration? (Source:…HELPNETSECURITY.COM
21 AugCybersecurity Job Ads Requiring AI Skills DoubleAn analysis by the AI Workforce Consortium found that technical cybersecurity jobs are becoming more strategic due to the influence of AIINFOSECURITY-MAGAZINE.COM
21 AugCISA Urges Immediate Patching of Exploited TrueConf VulnerabilitiesThe Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware. The post CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
21 AugCl0p Targets 40+ Organizations Through PTC Windchill FlawCl0p claims over 40 organizations fell victim to attacks exploiting a PTC Windchill and FlexPLM vulnerability. Cl0p is using a familiar strategy again: exploit one flaw in enterprise software to attack many companies, then publish the victims’ names if they refuse to pay. The gro…SECURITYAFFAIRS.COM
21 AugAI threats are everywhere. A risk-first CISO decides what to prioritizeThe good news? AI gives cyber defenders some of the best discovery tooling they’ve ever had. The bad news? It gives attackers the same capability. This duality has left CISOs managing AI on two simultaneous fronts. Outside the organization, attackers are using AI to make phishing…CSOONLINE.COM
21 AugRansomware takes aim at enterprise resilienceRansomware remains one of the most disruptive cyber threats organizations face. Companies have strengthened their cyber defenses over the years, but attackers in 2026 have become faster, more targeted, and increasingly reliant on AI , forcing the need for a change in how organiza…CSOONLINE.COM
21 AugMicrosoft Rolls Out 22 Fresh Security PatchesMost of the fixes resolve code execution, privilege escalation, and information disclosure vulnerabilities. The post Microsoft Rolls Out 22 Fresh Security Patches appeared first on SecurityWeek .SECURITYWEEK.COM
21 AugMore Incidents of AIs Going Rogue in Cybersecurity ChallengesThe AI Security Institute has a new report of AI systems engaging in “unsanctioned behavior”—what I have been calling “ genie behavior —while being tested on their cybersecurity capabilities. The incident stemmed from a single evaluation where agents…SCHNEIER.COM
21 AugBackdoored Rust packages hit crates.io, exposing developers to malware at build timeMalicious versions of three Rust packages, including the widely used arrayref, were published to the crates.io registry on August 20, carrying a backdoor that executed automatically when affected projects were compiled. Security researchers at Wiz said the attack also shares infr…CSOONLINE.COM
21 AugMicrosoft warns of max severity Entra ID flaw exploited in attacksMicrosoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited in attacks. [...]BLEEPINGCOMPUTER.COM
21 AugAttackers impersonate popular AI brands to spread malwareAttackers are impersonating popular AI brands like Perplexity, Claude, ChatGPT, and Copilot to spread information stealers, backdoors, malicious browser extensions, and other malware, according to Sophos. Overview of MDR cases with AI involvement (Source: Sophos) Sophos X-Ops rev…HELPNETSECURITY.COM
21 Aug KEVCISA orders feds to patch actively exploited TrueConf Server flawsThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform. [...]BLEEPINGCOMPUTER.COM
21 AugCritical Isolated-vm Vulnerability Leads to RCE on HostThe type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process. The post Critical Isolated-vm Vulnerability Leads to RCE on Host appeared first on SecurityWeek .SECURITYWEEK.COM
21 AugScammers Pose as NYPD Officers in “Well-Done” Video-Call Impersonation ScamThe phone rang, and when “Eddie” (not his real name) picked up, the caller identified herself as being from American Express. Even though Eddie didn’t have any American Express account, he wasn’t initially suspicious. According to the caller, Eddie’s…DATABREACHES.NET
21 AugAI, Data Breaches, and an Old Lesson from the Law of BailmentSo I didn’t know what the doctrine of bailment is. If you don’t either, you may want to read this post by Jake L. Ramsey of Offit Kurman. It starts by noting the presentation at BlackHat by two OpenAI engineers about the Hugging Face incident and notes two of their st…DATABREACHES.NET
21 AugSix Maximum-Severity Flaws Found in Cisco ProductsCisco patched nine critical flaws, including six rated CVSS 10.0, found during internal testing. None are known to be exploited. Cisco released another batch of security fixes for its Crosswork platforms and Secure Workload software, part of what it’s calling an ongoing int…SECURITYAFFAIRS.COM
21 AugAWS EKS forensics: data sources and investigation toolingInvestigating a compromise in Amazon EKS means piecing together evidence spread across three layers: the managed Kubernetes control plane, the worker nodes, and the surrounding AWS services. This article maps the data sources an EKS cluster exposes for digital forensics and threa…SYNACKTIV.COM
21 Aug KEVCISA warns of actively exploited TrueConf vulnerabilities.Supply chain attack compromises popular Rust library. Data giant Alation discloses a cyberattack.THECYBERWIRE.COM
21 AugMicrosoft confirms maximum severity flaw in Entra ID targeted for exploitationThe company said the remote-code execution vulnerability has been fully mitigated and no further action is necessary.CYBERSECURITYDIVE.COM
21 AugMicrosoft Defender's Own Driver Can Be Weaponized to Delete Security Software at BootCheck Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software fl…THEHACKERNEWS.COM
21 AugTroutman Pepper Locke Silent as Threat Actors Leak Client Data, Tens of Thousands of SSNsIn April, Silent Ransom Group’s (SRG)* leak site listed 38 law firms that had not paid them and whose data was leaked. By June 29, there were 48 law firms. Now there are 64, and, in somewhat surprising claims, SRG says a recent attack was actually its second on one law firm…DATABREACHES.NET
21 AugYour Shredded Visa Card May Still Work at the CheckoutUMass Amherst researchers showed expired Visa contactless cards can make real purchases by exploiting an unsigned expiry field in Visa’s EMV kernel. Researchers at the University of Massachusetts Amherst demonstrated at USENIX Security 2026 in Baltimore that expired Visa co…SECURITYAFFAIRS.COM
21 AugThe guest nobody invited.CISA orders patching of TrueConf Server vulnerabilities. LockBit threatens release of stolen banking data. Researchers disclose a critical type confusion vulnerability in a Node.js library. A new Agent Tesla v4 campaign introduces enhanced evasion techniques. A novel malware deli…THECYBERWIRE.COM
20 AugCloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/SecondCybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second, 360 times the rate of an earlier attack demonstr…THEHACKERNEWS.COM
20 AugOpenAI ‘temporarily slows’ scaling efforts, also promises zero data retention for select frontier model customersOpenAI this week announced multiple moves designed to counter negative perceptions of its security and privacy, saying it had slowed its pace of scaling, implemented a two-week pause in reinforcement learning, and will be offering zero data retention for “eligible API customers.”…CSOONLINE.COM
20 Aug8,539 reasons to rethink how vulnerabilities get patchedThe window for responding to newly disclosed security flaws is getting shorter. Exploit code can appear quickly, exploitability can be tested soon after disclosure, and organizations have a growing number of weaknesses to sort through. Rapid7’s Q2 2026 Threat Landscape Report cou…HELPNETSECURITY.COM
20 AugAirlock Digital Completes Independent IRAP Assessment at the PROTECTED LevelAirlock Digital, a global provider of application control and allowlisting solutions, today announced that it has completed an independent Information Security Registered Assessors Program (IRAP) assessment at the PROTECTED classification level. The assessment was conducted by an…CSOONLINE.COM
20 AugObjection! That's a scam.This week, while Dave is out, hosts Maria Varmazis and Joe Carrigan are discussing the latest in social engine…THECYBERWIRE.COM
20 AugAI is making fraud harder to spot and identity harder to proveOnline fraud has become a routine concern for consumers and businesses that rely on digital accounts, payments and customer service. Experian’s 2026 U.S. Identity & Fraud Report describes a market where scams extend across messages, websites, documents, voices, images and ac…HELPNETSECURITY.COM
20 AugSrsly Risky Biz: Trump's private hacker memo is the right ideaTom Uren and James Wilson talk about President Donald Trump’s memo enlisting the US private sector to tackle cybercriminals. The initiative gets the big idea right: traditional law enforcement approaches have not worked against cybercriminals so the government has turned to disru…RISKY.BIZ
20 AugExploitation Expected for Critical Authentication Bypass Patched in Citrix NetScalerRemote, unauthenticated attackers could exploit the critical-severity flaw without user interaction. The post Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugIdentity Abuse Through Trusted Communication ChannelsUnit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The post Identity Abuse Through Trusted Communication Channels appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
20 Aug KEVCritical Zimbra RCE flaw now actively exploited in attacksCERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS). [...]BLEEPINGCOMPUTER.COM
20 AugUS agencies warn of AI-powered attacks on Siemens industrial controllersThreat actors are using AI to write exploit scripts targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs) used across water, energy, manufacturing, and other critical infrastructure sectors, according to US federal agencies. PLCs are the small industr…HELPNETSECURITY.COM
20 AugICS Operators Warned of AI-Driven Attacks on Siemens PLCsA US government advisory warned that attackers are deploying AI-generated exploitation scripts against exposed Siemens S7 Series PLCsINFOSECURITY-MAGAZINE.COM
20 AugNASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft CommandsSecurity researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, that allow an unauthenticated attacker to issue arbitrary commands to the software's spacecraft and instrument comman…THEHACKERNEWS.COM
20 Aug40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet SecretsA set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products. According to the Socket Threat Research team, the extensions are part of a broader set of 77 browser add-ons tha…THEHACKERNEWS.COM
20 AugKriminal breaks out of Grok, Claude guardrails at $12.99Security researchers are warning of a criminal AI service built on Grok and Claude, among other models, that promises uncensored access to powerful AI capabilities for as little as $12.99 a month. ThreatDown researchers say “Kriminal” is largely a storefront wrapped around legiti…CSOONLINE.COM
20 AugLargest Applebee’s franchisee says hackers stole sensitive dataApple American Group LLC, a major Applebee’s franchise operator in the United States, has disclosed a data breach incident. The event has reportedly exposed sensitive personal information, including Social Security numbers, financial data, health records, and biometric informatio…CYBERINSIDER.COM
20 AugAI-powered cyberattacks are targeting critical infrastructure in the USUS agencies are warning that threat actors are actively using AI-generated exploitation scripts to target Siemens S7 programmable logic controllers (PLCs) deployed across critical infrastructure. The activity focuses on Internet-exposed and poorly secured industrial systems, with…CYBERINSIDER.COM
20 AugCISA warns of hackers exploiting critical MLflow vulnerabilityThe Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical vulnerability in the MLflow open-source AI engineering platform. [...]BLEEPINGCOMPUTER.COM
20 AugCisco Patches Critical Crosswork, Secure Workload VulnerabilitiesThe flaws could lead to remote code execution, authentication bypasses, and path traversal attacks. The post Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugAI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian HackingAtalanta's Argo product is now being used to prove the resilience of Viasat’s satellite communications network. The post AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugAWS limits AI agents’ data access, even when manipulatedAWS has detailed an approach for propagating user authorization context through AI agents, allowing access controls to be enforced by infrastructure and downstream services rather than relying on the agent itself. Customers using Amazon Bedrock AgentCore can build AI agents that …HELPNETSECURITY.COM
20 AugAtlassian, Splunk Patch Dozens of Critical, High-Severity VulnerabilitiesThe flaws could be exploited to execute arbitrary code, access sensitive information, and elevate privileges. The post Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugMLflow Vulnerability Exploited for Cloud Credential TheftThe critical-severity flaw allows attackers to send HTTP requests to internal endpoints and extract sensitive information. The post MLflow Vulnerability Exploited for Cloud Credential Theft appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugCDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS AmplificationCybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to the websites they front, amplifying a low-bandwidth request stream by up to 350x aga…THEHACKERNEWS.COM
20 AugThe push to designate AI as the next critical infrastructure sectorThe designation would unlock a range of federal services, tools and resources for an industry that policymakers view as increasingly tied to national and economic security. The post The push to designate AI as the next critical infrastructure sector appeared first on CyberScoop .CYBERSCOOP.COM
20 AugBTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation PrimitiveResearch by: Jiří Vinopal (@vinopaljiri) Abstract What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from Ring 0…RESEARCH.CHECKPOINT.COM
20 Aug'Grandoreiro' Malware Resurfaces With Mexico CampaignThe banking Trojan, post-law enforcement takedown, is sprucing itself up with features that make detection and analysis harder.DARKREADING.COM
20 AugLargest Applebee’s franchisee says hackers stole sensitive dataAmar Ćemanović reports: Apple American Group LLC, a major Applebee’s franchise operator in the United States, has disclosed a data breach incident. The event has reportedly exposed sensitive personal information, including Social Security numbers, financial data, health records, …DATABREACHES.NET
20 AugIsolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCECybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the isolated environment. The vulnerability ("GHSA-864f-rcv7-6r…THEHACKERNEWS.COM
20 AugCritical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA ServersCitrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability. According to the cloud computing and virtualization technology company, the issues affect custom…THEHACKERNEWS.COM
20 AugFrequently asked questions about the active threat to Siemens S7 Series PLCsA joint cybersecurity advisory released by multiple U.S. government agencies warns that threat actors are using AI-generated exploitation scripts to target exposed Siemens S7 Series PLCs across critical infrastructure sectors. Key Takeaways Unattributed threat actors are exploiti…TENABLE.COM
20 AugChinese hackers use AI to automate attacks on 170,000 serversA Chinese-speaking cybercrime group is using AI-assisted tooling to automate attacks against vulnerable Windows and Linux web servers worldwide. Tracked as UAT-10147 by Cisco Talos, the threat group targets internet-facing servers for data theft and search engine optimization (SE…CYBERINSIDER.COM
20 AugCritical Elementor Pro bug exposes WordPress sites to RCE attacksA critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server. [...]BLEEPINGCOMPUTER.COM
20 AugNew Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat DataAdversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongoing conversation to an attacker-controlled server after the user asks it to summarize an ordinary we…THEHACKERNEWS.COM
20 AugCitrix urges immediate patching of two newly disclosed vulnerabilities.Federal agencies warn of an active cyber campaign targeting Siemens PLCs. Latvian road traffic agency data breach affects two-thirds of the country's population.THECYBERWIRE.COM
20 AugWhat we know so far about the hacking campaign against US water systemsSupport is growing for stricter oversight and increased financial resources for utilities in the wake of a cyberattack spree, suspected to be the work of Iran-linked threat groups.CYBERSECURITYDIVE.COM
20 AugAI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical InfrastructureThe U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts. The activity is targeting Siemens S7 SeriesProgrammable Logic Controllers (PLCs) to conduct r…THEHACKERNEWS.COM
20 AugThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and MoreA lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hid…THEHACKERNEWS.COM
20 AugMoney and Mindset: The Two Biggest Roadblocks to Cyber PolicingLaw enforcement training is not keeping pace with the volume and rapid evolution of cybercrimes, though officers really only need to learn the basics, but focus and budgets hinder progress.DARKREADING.COM
20 AugCritical flaw patched in popular JavaScript sandbox used in AI projectsA critical sandbox escape vulnerability was discovered and patched in isolated-vm, a library for running JavaScript code inside an isolated process. If exploited, the vulnerability could allow attackers to hijack the host’s control flow, which could enable remote code execution. …CSOONLINE.COM
20 AugWhy the Annual Pentest Can’t Keep Up with Chris Wallis from IntruderChris Wallis, Founder and CEO of Intruder, joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices recorded at Black Hat USA 2026. He discusses why point-in-time pentesting is struggling to keep pace as teams ship software and attackers exploit vulnerabi…THECYBERWIRE.COMHTTPS:
20 AugThe Feynman Bet: Why You Still Won’t Vibe Code Your SIEM (Today)Gemini about this blog The Feynman Betting Strategy and the Inertia of Security Many years ago, I read a book by the legendary quantum physicist Richard Feynman . One story from his time at Los Alamos during the war has always stuck with me. Feynman entertained himself by making …MEDIUM.COM
19 AugCoPilot Snitches on Itself, Hacker leaks Azure data and Texas University deals with cyber attackMicrosoft Copilot CoSnitch Flaw, Alleged Azure Employee Data Leaks, UTSA Cyberattack, and AI "Mind Viruses" The episode covers a one-click flaw in Microsoft Copilot Personal dubbed "CoSnitch," where Varonis Threat Labs says Copilot revealed an undocumented URL parameter that enab…CYBERSECURITYTODAY.LIBSYN.COM
19 AugRisky Business #849 -- Trump will unleash contractors on cybercriminalsOn this week’s show Patrick Gray and James Wilson are joined by guest co-host Dmitri Alperovitch to talk through the week’s news, including: Trump’s memo authorising the private sector to release the cyber hounds is fine, don’t worry! OpenAI finally decides to add a few safety me…RISKY.BIZ
19 AugChatGPT’s new feature could give infostealers a map of your Mac activityOpenAI’s new Computer History feature turns recent Mac computer activity into memories ChatGPT and Codex can use, and it’s raising questions about privacy and security along the way. Computer History (Source: OpenAI) What Computer History does Computer History builds …HELPNETSECURITY.COM
19 AugBanks look for fraud signals in customer behaviorBanks are dealing with more fraud in which customers authorize payments after being manipulated by criminals. ThreatMark’s Fraud Readiness Benchmark 2026 describes a banking environment where social engineering, reimbursement requirements and growing case volumes are changing fra…HELPNETSECURITY.COM
19 AugRisky Bulletin: Slovakia finds Russian backdoors on its speed camerasSlovakia finds Russian backdoors on its speed cameras, French police used a public exploit to hack EncroChat, Microsoft delays Exchange updates due to a deluge of AI bugs, and a ransomware-affiliate poses as a data recovery firm.RISKY.BIZ
19 AugCyberattack forces UT San Antonio to delay start of fall semesterThe University of Texas at San Antonio pushed back the start of its fall semester by three days after a cyberattack targeted its academic network over the weekend. Classes that were due to begin on Wednesday, August 19 will now start on Monday, August 24. UT San Antonio is one of…HELPNETSECURITY.COM
19 AugF5 enhances AI Gateway to control AI costs, access, and securityF5 has introduced enhancements to the F5 AI Gateway and integrated the solution into the F5 AI Security Platform. The enhanced F5 AI Gateway seamlessly enforces policies on every AI request, giving enterprises a unified control plane to govern how AI models, agents, and tools are…HELPNETSECURITY.COM
19 AugMost organizations aren’t ready for a Hugging Face-level eventThe National Security Agency (NSA) and Central Security Service recently published an advisory statement on behalf of the Five Eyes Cyber Security Agencies, warning that AI technologies are making it easier than ever for would-be malicious actors to infiltrate and compromise sens…CSOONLINE.COM
19 AugCISOs are struggling to threat-model AI. Can 15-minute sessions help?A few weeks ago, on a busy day, threat-modeling expert Adam Shostack opened an email from a client. Someone at that organization had vibe-coded an app and put it to work with customer data. Now, the client wanted to know what risks the tool posed. And what it should do about them…CSOONLINE.COM
19 AugPreventing a Breakout as AI Agent Threats Is One of Three Top CISO Concerns - Rob Allen - BSW #461Artificial intelligence has quickly evolved from a productivity tool into an active participant in many organizations' daily operations. As organizations give AI greater autonomy within their environment, they're also granting them access to sensitive systems and data. That creat…YOUTUBE.COM
19 AugChrome, Firefox Updates Patch Dozens of VulnerabilitiesThe bugs could lead to code execution, privilege escalation, sandbox escape, and information disclosure. The post Chrome, Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
19 AugOpenAI puts major frontier AI training run on hold over cyber risksOpenAI temporarily paused reinforcement learning (RL) training on its latest models intended for deployment for two weeks while it hardened and red-teamed research environments and expanded monitoring. “Our largest planned frontier RL run remains on hold while we conduct smaller-…HELPNETSECURITY.COM
19 Aug943 Patches Rolled Out With Oracle’s August 2026 Security UpdateThe fixes resolve over 1,000 vulnerabilities across two dozen products, including over 460 remotely exploitable bugs. The post 943 Patches Rolled Out With Oracle’s August 2026 Security Update appeared first on SecurityWeek .SECURITYWEEK.COM
19 AugGoogle’s AI security agents found 100+ critical software vulnerabilities in just two daysGoogle’s Mandiant has disclosed the workings of an internal tool that uses chains of AI agents to hunt for vulnerabilities in source code, saying it found over 100 verified, high-severity flaws in just two days during a live investigation into stolen corporate repositories.…HELPNETSECURITY.COM
19 AugUpdate Chrome now: Two critical vulnerabilities fixedGoogle has released a Chrome desktop update fixing 15 security vulnerabilities, including 2 buffer overflow flaws rated critical.MALWAREBYTES.COM
19 Aug KEVCritical RCE flaw in Windows IKE Extension now actively exploitedThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component. [...]BLEEPINGCOMPUTER.COM
19 AugCISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple VulnerabilitiesThe flaws can be exploited for remote code execution, authentication bypass, and device takeover. The post CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
19 AugSnowflake flaw slips past AI checks, gets exploited by another AIAn autonomous AI security agent developed by cloud security firm Wiz identified and exploited a critical vulnerability in Snowflake’s GitHub Actions pipeline, while GitHub Copilot had previously reviewed the code change without flagging the flaw. The vulnerable code was part of a…CSOONLINE.COM
19 AugNIST Releases Tips & Tactics for Building Automation & Control System CybersecurityRecent cyberattacks highlight the growing threat to operational technology (OT) used in critical infrastructure. Whether you work for an infrastructure owner/operator or are a consumer of an infrastructure service, the events of the past few weeks have made it clear that cybersec…NIST.GOV
19 AugServer Mistake Exposes StopAndProtect’s Hacked WordPress NetworkWaqas reports: A server mistake by cybercriminals has exposed the inner workings of a global malware operation that used nearly 2,000 hacked WordPress websites to infect computers, steal files and deploy ransomware. Check Point Research identified the operation as StopAndProtect …DATABREACHES.NET
19 AugHackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2PCybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique. The activity,…THEHACKERNEWS.COM
19 AugPassword spraying attacks surge 155x as hackers exploit MFA gapsHuntress observed a 155x increase in password spraying attacks in H1 2026, including a campaign that generated more than 81 million login attempts in two weeks. The attacks exploited legacy authentication and gaps in MFA policies that left some login flows unprotected. [...]BLEEPINGCOMPUTER.COM
19 AugDOJ secures indictment of 17 Iranians accused of ‘massive’ cyber theft campaignMax Rego reports: The Department of Justice (DOJ) on Tuesday unsealed an indictment charging 17 Iranian nationals with targeting American and foreign institutions via a cyber theft campaign on behalf of Iran’s Islamic Revolutionary Guard Corps (IRGC). The 14-count indictment char…DATABREACHES.NET
19 AugBeware the Ransomware Rescuer: Ransom BustersJustin Timothy reports: The GuidePoint Research and Intelligence Team (GRIT) has responded to several recent ransomware incidents in which victims received an unexpected email from an ostensible third-party entity referring to itself as “Ransom Busters.” In these messages, the th…DATABREACHES.NET
19 AugThe long tail of Clop’s PTC hack is just beginning to emergeThe data theft extortion group likely compromised a critical vulnerability affecting PTC’s product lifecycle management software in June, a month before it sent threatening emails to victims. The post The long tail of Clop’s PTC hack is just beginning to emerge appeared first on …CYBERSCOOP.COM
19 AugPrison for data analyst who tried to extort $2.5 million from his employerThere’s an update to a previously reported case of a disgruntled former employee who tried to extort his employer, Brightly Software. Graham Cluley reports: When Cameron Curry discovered that his contract as a data analyst wasn’t going to be renewed, he could have upd…DATABREACHES.NET
19 AugExclusive: Linux Foundation's Akrites to Go Live in SeptemberThe Linux Foundation's Akrites initiative will become operational in September, when it will begin accepting AI-powered vulnerability reports for open-source projectsINFOSECURITY-MAGAZINE.COM
19 AugFirefox 154 blocks silent WebSocket access to local network devicesMozilla has released Firefox 154 with expanded protections against websites connecting to devices on local networks, new AI-assisted tab organization, and support for NVIDIA GeForce NOW on Windows. The latest update also addresses 58 CVE entries, including multiple high-severity …CYBERINSIDER.COM
19 AugSo Is Your SOC AI-Ready? Part 3: API or Die Audit!This is Part 3 of the AI-ready SOC series ( Part 1 , Part 2 ), and it is focused on validating readiness for pillars #1 (SOC Data Foundations) and #4 (Modern SOC Technology Stack). Specifically, it is about the audit I promised in Part 2 : “The ‘API or Die’ Data Audit: You need t…MEDIUM.COM
19 AugThe AI Was the Route InSeveral recent security incidents and research demonstrations involve attackers manipulating AI assistants and connected systems that already have legitimate access to organizational data or infrastructure. The AI doesn't always have to be the target. If an assistant can read log…YOUTUBE.COM
19 AugNSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technologyThe National Security Agency (NSA), FBI and other federal agencies said the campaign is targeting Siemens S7 Series PLCs and was being fueled by “AI-assisted development” alongside exploitation of known vulnerabilities.THERECORD.MEDIA
19 AugUS warns of AI-powered attacks on Siemens PLCs in critical infrastructureU.S. cybersecurity agencies warn that threat actors are using AI-generated scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) in U.S. critical infrastructure. [...]BLEEPINGCOMPUTER.COM
19 AugOpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI BehaviorOpenAI on Tuesday revealed that it paused reinforcement learning (RL) training for its latest artificial intelligence (AI) models for two weeks while it shored up additional defenses and increased the scope of its monitoring to avert another Hugging Face-like incident. "As models…THEHACKERNEWS.COM
19 AugHackers hiding in plain sight.Medusa’s reach grows. Cl0p expands its victim list. The DOJ charges 17 alleged Iranian hackers. CISA sounds the alarm on four exploited vulnerabilities. TWINLOOT hides in plain sight inside Microsoft 365. Maria Varmazis shares the latest from the space-cyber realm as Ukraine stri…THECYBERWIRE.COM
19 AugSakura Internet hack exposes data of up to 1.36 million accountsJapanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. [...]BLEEPINGCOMPUTER.COM
19 AugHealthtech firm CareCloud data breach impacts 3.7 million patientsU.S. healthcare IT company CareCloud disclosed that the data breach incident it suffered earlier this year has impacted more than 3.7 million individuals. [...]BLEEPINGCOMPUTER.COM
18 AugSnowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command InjectionCybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow co…THEHACKERNEWS.COM
18 AugOpenAI president’s blog pushing agentic AI most notable for what it did not sayOpenAI president Greg Brockman on Sunday warned enterprise CISOs that they need to more aggressively embrace agents if they want to survive upcoming cyberattacks. Brockman said in a blog post that it has become “increasingly clear” that company systems are hiding “significant fla…CSOONLINE.COM
18 AugCybersecurity jobs available right now: August 18, 2026CISO ADI Global Distribution | USA | Hybrid – View job details As a CISO, you will develop and lead ADI’s global security strategy to protect information assets, digital platforms, critical operations, and AI-enabled environments. Advise executives and the Board o…HELPNETSECURITY.COM
18 AugAttackers turn to AI for help identifying files worth stealingAI tools are being used by cyber attackers to write malicious code, build tools that harvest credentials, search compromised networks, identify valuable business information, manage technical infrastructure and generate commands during intrusions. Gambit Security researchers exam…HELPNETSECURITY.COM
18 AugGoogle’s open-source HEIR lets AI work with data it can’t seeGoogle’s researchers and engineers developed the Homomorphic Encryption Intermediate Representation (HEIR) compiler project, an open-source compiler toolchain and development platform for homomorphic encryption. It can convert pre-trained AI models designed to operate on unencryp…HELPNETSECURITY.COM
18 AugDozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security UpdatesThe bugs could be exploited to crash Safari, corrupt memory, leak sensitive data, escape the sandbox, and exfiltrate data. The post Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates appeared first on SecurityWeek .SECURITYWEEK.COM
18 Aug KEVCISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCEThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Ray is an open-source, Python-native distributed computing framework design…THEHACKERNEWS.COM
18 AugNew Mirai-Based Evooo1Bot Botnet Targets Linux DevicesEvooo1Bot is a Mirai-based Linux botnet that hijacks routers and IoT devices for DDoS attacks, credential theft and criminal proxy services. Fortinet’s FortiGuard Labs disclosed Evooo1Bot in mid-August, a previously undocumented Linux botnet that’s been active since J…SECURITYAFFAIRS.COM
18 AugWhat you say during a cyber breach can — and will — be used against youThe first 24 hours after a cyber incident are messy. Teams are moving fast, and a lot gets said on Slack or email that can come back later. People are scrambling to contain the issue, figure out what happened and keep things moving. In the process, they create a record that doesn…CSOONLINE.COM
18 AugAI can find zero-days but still can’t reliably write secure codeIn recent months, LLMs have gone from flooding open-source projects and bug bounty programs with questionable security reports that wasted developers’ time, to routinely finding zero-day flaws that humans and traditional security audit tools had missed for years — a rapid evoluti…CSOONLINE.COM
18 AugGitLab Patches Critical Code Injection VulnerabilityThe security defect allows unauthenticated attackers to modify or delete user data and public projects. The post GitLab Patches Critical Code Injection Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
18 AugSafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 CustomersSafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware wallet maker said all affected customers were notified individ…THEHACKERNEWS.COM
18 AugAugmenting Threat Intel Analysis with Agents - ASW #396All sorts of cybersecurity disciplines are adopting agents to help humans save time and automate routine activities. Sai Kiran Uppu describes his work on creating a platform for agents to analyze external threat intel, examine internal systems, and present triage decisions to ope…YOUTUBE.COM
18 Aug KEVCISA: Windows Task Host flaw now exploited by ransomware gangsThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April. [...]BLEEPINGCOMPUTER.COM
18 Aug16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto WalletsCybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of pac…THEHACKERNEWS.COM
18 AugOne Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco. The activity, which Reco has named the City Foru…THEHACKERNEWS.COM
18 AugNew Malware turns Microsoft cloud into its control centerSecurity researchers are warning of a newly uncovered Python malware framework that routes much of its command-and-control (C2) activity through Microsoft services that defenders already expect to see. The Ontinue Cyber Defense Center discovered the implant while investigating an…CSOONLINE.COM
18 AugAI-powered vulnerability clearinghouse faces deep skepticism, major challengesThe U.S. government’s promises about the “Gold Eagle” coordination program are overblown, experts said, but the initiative could help organizations prioritize patching and mitigation.CYBERSECURITYDIVE.COM
18 AugGoogle’s $10,000 refund test shows why AI agents need zero trustGoogle’s open-source autonomous Customer Support & Returns Agent, built using the Agent Development Kit (ADK) and Gemini, demonstrates how developers can apply zero-trust security principles to AI agents that interact with sensitive systems and take real-world actions. The p…HELPNETSECURITY.COM
18 AugAI-Driven Vulnerability Surge Breaks the Traditional Patching ModelRapid7 warns that traditional patch cycles cannot keep pace with soaring vulnerability disclosures and faster exploitation, forcing defenders to prioritize exposure over severity scores. The post AI-Driven Vulnerability Surge Breaks the Traditional Patching Model appeared first o…SECURITYWEEK.COM
18 AugTWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across NetworksCybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. "TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services," On…THEHACKERNEWS.COM
18 AugNETSCOUT expands Adaptive DDoS Protection with outbound attack mitigationNETSCOUT has announced an extension of its Adaptive DDoS Protection (ADP) solution enabling service providers to automatically detect and mitigate outbound DDoS attack traffic. By extending protection from the attack target towards its source, NETSCOUT helps operators prevent com…HELPNETSECURITY.COM
18 AugNew Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cyclesYou can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers. The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compre…RAPID7.COM
18 AugEnterprise Applications Carry 4.31x More Critical and High VulnerabilitiesEnterprise software creation has accelerated as vulnerability levels rise, Sonatype findsINFOSECURITY-MAGAZINE.COM
18 AugUniversity of Texas forced to take systems offline in San Antonio after cyberattackThe University of Texas at San Antonio, which serves 40,000 students across six campuses, said its IT team identified threat activity on its academic campus over the weekend and took some systems, including phones, offline in response.THERECORD.MEDIA
18 AugMicrosoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected AppsVaronis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copilot session. The flaws, which the research…THEHACKERNEWS.COM
18 AugAttackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and SecretsTwo critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation effort…THEHACKERNEWS.COM
18 AugYour LLM Might Find Missing LogsLLM agents can do more than generate security queries. They can analyze available data sources and point out potential gaps, including log sources that aren't currently being ingested. That can help security teams build a more complete picture of their infrastructure. But the mod…YOUTUBE.COM
18 AugCISOs Break Their Silence in 'Declassified' DocuseriesMillion-dollar heists, divorce, and career-ending burnout are all stories told in the latest docuseries revealing a behind-the-scenes look at the cybersecurity community.DARKREADING.COM
18 AugImplement custom authentication for tools integration using request Lambda interceptor in AgentCore GatewayWhen deploying AI agents with Amazon Bedrock AgentCore, organizations benefit from built-in modern support for OAuth 2.0, AWS Identity and Access Management (IAM), and API key authentication through Amazon Bedrock AgentCore Gateway. However, some enterprise environments still use…AWS.AMAZON.COM
18 AugFake it till you exfiltrate it.A fake consultancy fronts an alleged Chinese spy campaign. Meta heads to court over claims it hooked young users. Researchers crack the mystery behind the French EncroChat hack. CISA warns ransomware gangs are exploiting a Windows flaw. Meet C2Looper, a new Rust-based backdoor. A…THECYBERWIRE.COM
18 AugClop Claims Data Theft From More Than 40 CompaniesTiffany Wang reports: A prolific Russian-speaking extortion group known for supply-chain attacks claimed to have stolen data from more than 40 firms including heavyweight corporations such as oil giant Shell and manufacturer General Electric. The group, Clop, is the main suspect …DATABREACHES.NET
18 AugMedusa ransomware tallies hundreds of new victims, says updated advisory on group’s tacticsTim Starks reports: The ransomware-as-a-service group Medusa has adopted fresh tactics to gain access and added hundreds of victims in a little more than a year, according to an updated U.S. government advisory published Tuesday. The gang is relying on access brokers,compensating…DATABREACHES.NET
18 AugOracle August 2026 Critical Security Patch Update Addresses 925 CVEsOracle addresses 925 CVEs in its August 2026 Critical Security Patch Update with 943 patches, including 154 critical updates. Key Takeaways The August 2026 Critical Security Patch Update (CSPU) contains fixes for 925 unique CVEs in 943 security updates 154 issues (16.3% of all pa…TENABLE.COM
18 AugSN 1092: Restraint Abliteration - Rotating Keys, Broken GuardrailsFrom autocorrect to full-fledged conversationalists, discover how a few tweaks transformed language models—and why understanding this shift exposes urgent questions about AI safety and control. Trusting an open source AI proxy might bite you. France's under-15 social media ban hi…TWIT.TV
17 AugSponsored: What npm 12 fixes… and what it doesn’tIn this Risky Business sponsored interview, Casey Ellis chats with Socket founder Feross Aboukhadijeh about npm 12’s move to disable install scripts by default. Attackers are already shifting payloads into package source code, and Feross explains why teams need to understand what…RISKY.BIZ
17 AugHazmat: Open-source containment for AI agentsHazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code, Codex, OpenCode, Cursor Agent, and several more, plus any script you write yourself. An agent launched the ordinary way runs as …HELPNETSECURITY.COM
17 AugRisky Bulletin: The EU publishes its upcoming cybersecurity standardsThe EU publishes its upcoming cybersecurity standards, hackers breach France’s tax agency, threat actors exploit a GeoServer zero-day hours after disclosure, and an exploit unlocks old AMD CPUs with one instruction.RISKY.BIZ
17 AugWhat the CISO role will look like in 2029Wolfgang Goerlich has spent his career in security and has been a CISO for the past seven years. Like many long-term security execs, Goerlich has seen plenty of changes within the profession. He’s bracing for more. “For the future I see growing the role of CISO to be the pacesett…CSOONLINE.COM
17 AugSandbox Escapes with Rubrik's Zero Labs, AI recorders eroding privacy, and the news - ESW #472Interview with Jon Hladik - ChatMate Imagine a user asks an LLM a question about a document. An attacker then gains an interactive prompt on the user’s chat session, enabling the attacker to instruct the AI assistant to take actions on behalf of the victim. That is exactly the ca…YOUTUBE.COM
17 AugRecent macOS Screen Sharing Vulnerability Exploited in AttacksThreat actors gained root access to the vulnerable systems and deployed a Monero miner. The post Recent macOS Screen Sharing Vulnerability Exploited in Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
17 AugPolice bust cybercrime ring accused of stealing €30 million in four-day spreeGerman and Brazilian police dismantled an international bank fraud ring blamed for a €30 million cyberattack on a German financial institution, arresting four people in Brazil and pursuing three more suspects in Spain and Bulgaria. Brazilian police named the operation “Klon…HELPNETSECURITY.COM
17 Aug40,000 Impacted by SafePal Data BreachHackers exploited a vulnerability in the order-tracking function of a plugin to access SafePal customer information. The post 40,000 Impacted by SafePal Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
17 AugEvooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 ProxiesCybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies. "While the malware reuses the DDoS engin…THEHACKERNEWS.COM
17 AugFrench tax authority data breach affects 678,000 individualsThe French Ministry of the Economy and Finance has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems and stole data belonging to 678,000 individuals. [...]BLEEPINGCOMPUTER.COM
17 AugSafePal breach affects 39,798 customers, data allegedly for saleCryptocurrency wallet maker SafePal disclosed a data breach that exposed order information for 39,798 customers, including names, email addresses, shipping addresses, phone numbers and purchase details. The company traced the exposure to an authorization flaw in a plug-in used fo…HELPNETSECURITY.COM
17 Aug KEVUpdate your Mac: Screen Sharing vulnerability exploited in the wildAttackers are exploiting a Mac Screen Sharing vulnerability to gain root access and install Monero cryptominers.MALWAREBYTES.COM
17 AugUnisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel AccessSecurity researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the chipset maker. The advisory, published August 17, 2026, i…THEHACKERNEWS.COM
17 AugZhipu says new coding AI developed advanced cyber skills faster than expectedChinese AI developer Zhipu has launched GLM-5.3, a new coding-focused AI model that the company says has developed unexpectedly strong cybersecurity capabilities, putting it close to global leading models in vulnerability discovery while remaining behind them on deeper exploitati…CSOONLINE.COM
17 AugUkraine says cyberattack hit Russian e-commerce giant Wildberries amid drone strikesUkraine’s military intelligence claimed it disrupted the operations of Russia’s largest online marketplace, Wildberries, in a cyberattack intended to amplify the impact of drone strikes on the company’s infrastructure.THERECORD.MEDIA
17 AugIrregular Details How a Naming Error Let AI Models Attack a Real CompanyThe AI security testing firm has shared information on a recently disclosed incident involving Anthropic AI models. The post Irregular Details How a Naming Error Let AI Models Attack a Real Company appeared first on SecurityWeek .SECURITYWEEK.COM
17 Aug⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and MoreThe expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than the original compromise. A lot of it came down to a…THEHACKERNEWS.COM
17 AugWhy data quality dictates security operations successAs AI takes on more security operations center (SOC) workflows to automate threat triage, indicator extraction, and incident report generation, security operations leaders face a persistent question: Does SOC performance depend more on the large language model (LLM) deployed or o…CSOONLINE.COM
17 AugOperation ASTERIX: Anatomy of a Crypto Fraud PipelineOperation ASTERIX overview Rapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing sc…RAPID7.COM
17 AugWiz Red Agent Finds Its Way Into Snowflake’s Internal Jira Due to an AI-Generated GitHub Copilot “Autofix”Wiz Red Agent independently discovered and exploited a GitHub Actions vulnerability introduced by GitHub Copilot Autofix, validated access to sensitive data in Snowflake’s internal Jira, and assessed the blast radius—all without human intervention.WIZ.IO
17 AugMore than 2 million user records from TaxAct allegedly acquired; 450k already leakedOn August 13, DataBreaches was contacted anonymously on Signal by someone reporting that they had acquired more than 2 million records with clients’ phone numbers, usernames, and email addresses from TaxAct, which is owned by Cinven. TaxAct operates under its parent company…DATABREACHES.NET
17 AugIsrael’s largest crypto broker Bits of Gold hit by data breach affecting 200,000 customersOlivier Acuna reports: Cryptocurrency broker Bits of Gold said personal data belonging to roughly 200,000 customers was stolen by hackers, the company reported. The Tel Aviv, Israel-based company reported the security breach on Sunday, saying a hacker gained unauthorized access t…DATABREACHES.NET
17 AugYour Backups Are Hiding ThreatsSecurity teams traditionally focus threat intelligence on sources such as identity, network, endpoint, and other parts of the standard security stack. But backup data can contain another source of security telemetry. The claim presented here is that roughly 20% of threats identif…YOUTUBE.COM
17 AugFrance’s tax authority admits hackers made off with data on 678,000 individualsFrance’s tax authority has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems, saying the intrusion exposed data on 678,000 individuals and professionals. The incident came to light after an alleged attacker using t…HELPNETSECURITY.COM
17 AugDetecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilitiesLearn how Tenable One Cloud Exposure helps you unmask the sophisticated tactics of cybercrime group Storm-0501, which carries out Azure-based cloud ransomware campaigns. Tenable One Cloud Exposure uses AI-powered threat stories to expose Storm-0501 TTPs, backed by precision-engin…TENABLE.COM
17 AugCritical flaw in SAP Commerce Cloud faces initial exploitation attemptsThe vulnerability has a maximum severity score of 10, indicating serious potential impact and relative ease to exploit by an attacker.CYBERSECURITYDIVE.COM
17 AugUNISOC Modem Flaw Enables Remote Code Execution via Video CallsUNISOC modem flaw enabled kernel-level code execution through video callsINFOSECURITY-MAGAZINE.COM
17 AugLinux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoSThe botnet adds exploitation modules, credential theft, and reverse SOCKS relays to turn compromised devices into persistent attacker infrastructure.DARKREADING.COM
17 Aug235 GB of PHI and internal documents dumped; Chaos claims it comes from Healthcare Highways“Chaos” is a Ransomware-as-a-Service (RaaS) group first found online in March, 2025. On August 5, 2026, they added Healthcare Highways to their dedicated leak site, with a 24-hour countdown clock. Healthcare Highways describes itself as a medical provider network comp…DATABREACHES.NET
17 AugSafePal Says 39,798 Customers Hit by Data BreachSafePal says a breach exposed personal data of 39,798 customers, but not wallet credentials, private keys, seed phrases, or payment information. SafePal disclosed a data breach affecting about 39,798 customers after hackers exploited a vulnerability in its order-tracking plugin. …SECURITYAFFAIRS.COM
17 AugApple Patches iOS and macOS, (Mon, Aug 17th)Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing vulnerability. This vulnerability did not affect iOS/iPadOS.
ISC.SANS.EDU
17 AugPlease hold while we decide.Internal policy conflicts hamper U.S. military AI leadership. Clop claims GE, Philips and Shell. Attackers actively probe internet-facing GeoServer instances. “The Hatman” offers millions of alleged employee records for sale. ETSI begins the approval process for European cyber st…THECYBERWIRE.COM
17 AugVideo Call Exploit Chains Two Flaws in Unisoc ModemsResearchers found that by combining two vulnerabilities, they could take over an Android device by delivering a payload and getting the victim to answer their phone.DARKREADING.COM
16 AugWeek in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-dayHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub Dependabot malware alerts now cover eight ecosystems GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or P…HELPNETSECURITY.COM
16 AugNC: Possible cyberattack hits Wake election software vendor, leaving poll workers’ data exposedCaroline Yaffa reports: The Wake County Board of Elections is suspending its use of a software vendor after it reported a possible cyberattack. There’s no evidence that voting machines, ballots, voter registration records or systems used to count votes were affected, according to…DATABREACHES.NET
16 AugNew Jersey Federal Judge Dismisses Data Breach Class Action Against Background Check CompanyThere’s an update to a data leak incident reported in 2024. Phil Stilton reports: A federal judge has dismissed a proposed class action lawsuit against New Jersey-based background check company TABB Inc., finding the plaintiff failed to establish that he suffered a concrete…DATABREACHES.NET
16 Aug500 Hosts, 1 TB and No Negotiation: Anubis Provides Details on the Fairlife AttackSuspectFile has a great read on the Anubis attack on Fairlife. Marco De Felice faithfully reports what Anubis claims in its exclusive communications with him, what Coca-Cola claims, and how the claims differ. One of the most striking statements detailed the group’s response…DATABREACHES.NET
16 AugRep. Thompson brings bipartisan rural hospital cybersecurity act to HouseNorthCentralPA reports: A group of legislators has introduced the bipartisan Rural Hospital Cybersecurity Enhancement Act to the House of Representatives with the intention to strengthen rural hospitals’ protection against cyber threats. The group includes U.S. Reps. Glenn “GT” T…DATABREACHES.NET
16 AugSafePal data breach impacts 39,798 customers, stolen info for saleCryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data. [...]BLEEPINGCOMPUTER.COM
15 AugPresident Trump authorizes private-sector companies to hack cybercriminals.Trivy, not LiteLLM, was the original source of the 2,500-organization supply chain attack. Patch Tuesday notes: Microsoft fixes three zero-days.THECYBERWIRE.COM
15 AugGeoServer Zero-Day Is Already Being Probed. That’s the ProblemGeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE, with attackers already probing exposed systems. A newly disclosed GeoServer zero-day is already attracting active exploitation attempts, and there is no patch available yet. Organisations running th…SECURITYAFFAIRS.COM
15 AugCISA Unveils New Cybersecurity Resources for K-12 Schools and DistrictsA recent report claims ransomware attacks on K-12 are down for the first half of 2026, while another news story’s headline today claims schools are becoming a new cybersecurity battleground. New? We don’t think it’s new. But the education sector has long been ch…DATABREACHES.NET
15 AugAI Code Has No Security LayersOpen-source software has accumulated layers of security controls over years, including code signing, provenance, version control, maintainer tracking, and MFA for commits. AI MCPs, skills, and AI-generated code can look like ordinary software, but the same security infrastructure…YOUTUBE.COM
15 AugUK: ICO reprimands ACRO Criminal Records Office after data breachThe Information Commissioner (the Commissioner) recently issued a reprimand to ACRO Criminal Records Office for infringements of Articles 32(1), 32(1)(b) and 32(1)(d) of the UK GDPR. ACRO Criminal Records Office (ACRO) is a national police unit providing a range of public service…DATABREACHES.NET
15 AugKR: Sogang University data breach exposes 180,000 student, staff accountsHyeon Ye-Seul reports: Personal information belonging to roughly 180,000 students, alumni and staff at Sogang University was exposed in a cyberattack, the university said Saturday. The university said it had confirmed signs that some data tied to its integrated login accounts had…DATABREACHES.NET
15 AugTime ran out for victims; CRPx0 puts data up for saleCRPx0 made the news last month for its somewhat novel approach of offering free OnlyFans accounts to get victims to click links that would deploy its malware. Since August 7, when it launched a leak site on both the clear net and dark web, CRPx0 has listed 47 victims that did not…DATABREACHES.NET
15 AugCrooks Are Buying Your Expired Domains and Using Them to Deliver MalwareAttackers are buying expired domains to exploit their reputation, traffic and DNS history, using them for malware delivery, scams and C2 infrastructure. Every day, roughly 65,000 domain names that once belonged to someone else get re-registered by a new owner. Infoblox Threat Int…SECURITYAFFAIRS.COM
14 AugNightmare Eclipse drops ShieldBreak zero-day, US recruits cyber privateers, California bolstering cyber defensesWindows Defender Zero-Day 'ShieldBreak,' California's AI Cyber Defense, and US 'Cyber Privateers' A researcher known as Nightmare Eclipse published a new Windows zero-day called ShieldBreak that exploits Windows Defender to escalate from low-level access to full system control ac…CYBERSECURITYTODAY.LIBSYN.COM
14 Aug5 key takeaways from Black Hat USA 2026AI’s potential as a security tool and the danger of autonomous AI agents as a new attack surface were key themes of the presentations and product announcements at Black Hat and DEFCON in Las Vegas last week. Here are some key takeaways from this year’s hacker summer camp that CIS…CSOONLINE.COM
14 AugRisky Bulletin: US will let private companies carry out offensive cyber opsThe White House will let private companies carry out offensive cyber ops, an AI hacking campaign breached Taiwan’s government, a macOS bug was exploited over the internet to drop cryptominers, and Kenya orders internet cafes to store logs.RISKY.BIZ
14 AugHackers Exploiting Unpatched GeoServer Zero-DayThe security defect is described as an SQL injection that could allow attackers to achieve remote code execution. The post Hackers Exploiting Unpatched GeoServer Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
14 AugUkrainian police raid 94 fraudulent call centers, seize $2 millionUkrainian police have disrupted 94 fraudulent call centers during a nationwide operation that involved more than 400 searches and the seizure of thousands of computers, phones, and SIM cards. Ukrainian police raid at a fraudulent call center (Source: Cyberpolice Ukraine) The call…HELPNETSECURITY.COM
14 AugHow CSOs can turn cybersecurity into a business growth strategyFor years, cybersecurity leaders have worked to convince organizations that security deserves a seat at the executive table. Today, that conversation is changing. The challenge is no longer proving that cybersecurity matters; it is demonstrating how security leaders can help orga…CSOONLINE.COM
14 AugApple sends mercenary spyware alerts to targeted iPhone usersApple has sent a new round of threat notifications to iPhone users it believes may have been targeted with mercenary spyware. The warnings are issued to people facing sophisticated surveillance attacks involving tools similar to NSO Group’s Pegasus spyware. Apple uses threa…CYBERINSIDER.COM
14 AugAmnesiaStealer Gives Attackers Live Control of Victims’ macOS BrowsersAmnesiaStealer targets macOS users through fake GitHub pages, stealing passwords, cookies and data while giving attackers live control of the browser. Jamf Threat Labs researchers disclosed AmnesiaStealer, a new multi-stage Rust-based macOS infostealer that spread through a count…SECURITYAFFAIRS.COM
14 AugAkira ransomware reboots into Windows Safe Mode to knock EDR offlineAkira ransomware affiliates were seen using a new technique to evade endpoint detection and response (EDR), where they rebooted a compromised Windows system into Safe Mode with Networking enabled. According to Huntress, the technique successfully took both its agent and Microsoft…CSOONLINE.COM
14 AugThreema messenger says DDoS attacks disrupted its service for two daysEncrypted messaging provider Threema says a series of large-scale distributed denial-of-service (DDoS) attacks disrupted its services this week, leaving users unable to connect for several hours on Tuesday and causing intermittent outages on Wednesday morning. The company disclos…CYBERINSIDER.COM
14 AugNew Android malware relays bank cards to fraudsters while victims still hold themGroup-IB researchers discovered WindRelay, a new Android malware built to capture live payment card data over NFC (Near Field Communication) and relay it to attackers in real time. WindRelay is paired with the SpyNote remote access trojan, which gives attackers remote access to a…HELPNETSECURITY.COM
14 AugApple now uses iPhone alerts for targets of mercenary spywareApple explains how Threat Notifications help protect iPhone users targeted by mercenary spyware.MALWAREBYTES.COM
14 AugNHS admits data breach by sending patient data via pagersSTILL, NHS? Martin Bagot reports: The NHS has admitted a data breach by sending patients’ personal information over pager devices. A BBC investigation found sensitive medical data of transplant patients was routinely sent over an unencrypted pager network. The information include…DATABREACHES.NET
14 AugSalesforce, ServiceNow data targeted in ‘City-Forum’ attacksRecords held in Salesforce and ServiceNow systems are under attack leaving user data exposed, according to researchers at Reco. The attack appears similar to those perpetrated by the extortion group ShinyHunters, Reco said. ShinyHunters has been particularly active this year, att…CSOONLINE.COM
14 AugOracle’s new database security tool is free — for six monthsOracle has released a security tool intended to provide organizations with a centralized view of security risk across their database environments. Oracle Database Security Central will be available free of charge until the end of February 2027. It arrives at a critical time for O…CSOONLINE.COM
14 AugMax severity SAP Commerce Cloud flaw now targeted in attacksA maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused. [...]BLEEPINGCOMPUTER.COM
14 AugHackers exploit macOS Screen Sharing flaw to deploy Monero minerThe Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged. [...]BLEEPINGCOMPUTER.COM
14 AugApple sends out threat notifications to users targeted by spyware.Trivy, not LiteLLM, was the original source of the 2,500-organization supply chain attack. Chinese hack-for-hire group conducts espionage and cybercrime simultaneously.THECYBERWIRE.COM
14 AugFrance investigates tax authority breach after hacker claims 600,000 victimsDaryna Antoniuk reports: France’s tax authority has confirmed that hackers breached its information systems and extracted data on individuals and businesses. France’s Economy Ministry said late Thursday that an attacker gained unauthorized access to systems at the Directorate Gen…DATABREACHES.NET
14 AugFrench tax agency confirms breach as hacker claims 2 million victimsFrance’s tax authority has confirmed that an attacker gained unauthorized access to its information systems and extracted data belonging to individuals and businesses. Separately, a hacker using the name ZeroBytes claims to have obtained cadastral records linked to more tha…CYBERINSIDER.COM
14 AugHackers arrested over €30M bank fraud exploiting service provider flawFour cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers' bank accounts. [...]BLEEPINGCOMPUTER.COM
14 AugApple warned hundreds of users of mercenary spyware attacksApple warns users of credible, targeted attacks and urges immediate verification, stronger protections, and expert assistance. Apple has sent a new round of threat notifications to users it believes may have been singled out by mercenary spyware. The company told TechCrunch the l…SECURITYAFFAIRS.COM
14 AugAmid AI-Driven Bug Tsunami, NIST Looks to…AIDriven by AI-augmented research and scanning, vulnerability volumes continue to surge, driving the National Institute of Standards and Technology to ask whether AI could be the answer.DARKREADING.COM
14 AugApple has a message for you.Apple sends out threat notifications to users targeted by spyware. Trivy, not LiteLLM, was the original source of the 2,500-organization supply chain attack. French tax authority confirms data breach. Chinese hack-for-hire group conducts espionage and cybercrime simultaneously. U…THECYBERWIRE.COM
13 AugMore Novo Nordisk data dumped by FulcrumSecFulcrumSec has dumped more data from its attack that Novo Nordisk first disclosed on June 11. FulcrumSec writes: Today we are releasing all of the Novo Nordisk data not included in our original post: their complete enterprise HuggingFace AI/ML ecosystem. 30 models, 70 datasets, a…DATABREACHES.NET
13 AugRansomware Attack Disables Canadian Hospital’s Doors, HVACMarianne Kolbasuk McGee reports: A Canadian hospital is dealing with a ransomware attack on its facility management systems that has affected the building’s doors and heating, ventilation and air conditioning equipment. Some experts said the incident underscores growing cyb…DATABREACHES.NET
13 AugA golden opportunity...for fraud.This week, while Dave is out, hosts Maria Varmazis and Joe Carrigan are discussing the latest in social engineerin…THECYBERWIRE.COM
13 AugDDoS attacks hit record scale as 1 Tbps+ campaigns become more commonDDoS attacks grew in scale during the first half of 2026, bringing larger traffic floods, shorter attack durations, and increasingly automated campaigns. Cloudflare’s H1 2026 DDoS Threat Report shows threat actors relying on multi-vector techniques and large-scale network-l…HELPNETSECURITY.COM
13 AugBelgium's eID Authentication Opens Citizen Accounts to RCEThe trust framework underlying Belgium's electronic ID system was fully compromised by severe vulnerabilities in a key browser extension, showcasing bigger problems with extensions in general.DARKREADING.COM
13 AugNorth Korean Lazarus Group Uses Windows Zero-Day in Operation Dream JobLazarus targets defense professionals with fake Lockheed Martin jobs, exploiting a Windows zero-day to deploy backdoors and evade security controls. Check Point Research has uncovered a new wave of Operation Dream Job, the long-running North Korean campaign that lures defense and…SECURITYAFFAIRS.COM
13 AugMicrosoft wants you to rethink your approach to cyber defenseCyber defenders need to shake off traditional best practices and switch from reactive patching to building inherently resilient systems in the face of AI-accelerated vulnerability discovery, according to a senior security manager at Microsoft. David Weston, group manager in the W…CSOONLINE.COM
13 AugNightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges. The post Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ appeared first on SecurityWeek .SECURITYWEEK.COM
13 AugSearchlight Cyber combines exposure and threat intelligence in new PTEM platformSearchlight Cyber has launched its Preemptive Threat Exposure Management (PTEM) platform, combining exposure visibility with real-world attacker intelligence to help organizations prioritize and reduce the exposures most likely to be exploited. Security for the real-time era For …HELPNETSECURITY.COM
13 Aug153GB of stolen credentials surface after LiteLLM supply chain attackA massive 153GB archive stolen during the LiteLLM supply chain attack exposes credentials and other sensitive data linked to thousands of corporate domains, including AWS, Samsung, Cisco, and Salesforce. Hudson Rock says it obtained and analyzed the archive, which contains 433,90…HELPNETSECURITY.COM
13 AugThe Model Is the Malware | What Four Agentic Intrusions Tell DefendersOpenAI, Anthropic and Meta disclosed agents reaching external systems. The tools didn't matter, and that changes the playbook for investigating intrusions.SENTINELONE.COM
13 AugWordPress 7.0.4 Patches Remote Code Execution VulnerabilityAttackers with Author-level user or higher permissions could exploit the flaw via malicious Postscript files. The post WordPress 7.0.4 Patches Remote Code Execution Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
13 AugAI agents wage near-autonomous cyberattack on Asian government networksAutonomous AI agents built on open-source frameworks breached Taiwanese government systems, compromised credentials, and probed a nuclear safety agency in a multi-day cyberattack that researchers say signals a new phase in AI-enabled operations. The campaign unfolded over four da…CSOONLINE.COM
13 AugvCenter Flaw Exploited Just Five Days After DisclosureAttackers exploited a critical-severity vCenter flaw five days after Broadcom disclosed itINFOSECURITY-MAGAZINE.COM
13 AugWho Vets AI’s Code? The Scale Challenge Facing Open Source IngestionAI coding tools can introduce unvetted or hallucinated open source dependencies faster than traditional security reviews can keep pace. ActiveState explains why organizations should govern packages at the point of selection, before they enter the development pipeline. [...]BLEEPINGCOMPUTER.COM
13 AugWhat 50 open source projects taught us about security in the AI eraSee how the open source projects in Session 4 of the GitHub Secure Open Source Fund combined AI-assisted workflows, maintainer expertise, GitHub security tools, expert guidance, and funding to improve project security. The post What 50 open source projects taught us about securit…GITHUB.BLOG
13 AugTrezor says ShipMonk breach exposed data of 13,700 customersA data breach at Trezor logistics partner ShipMonk exposed the personal information of 13,689 hardware wallet customers. Trezor says its own systems and devices were not compromised, but warned affected customers to expect more convincing phishing attempts. Trezor disclosed the i…CYBERINSIDER.COM
13 AugQuestel confirms Microsoft 365 breach after ShinyHunters leaks dataFrench intellectual property services provider Questel has confirmed that attackers gained unauthorized access to part of its Microsoft 365 environment following a voice phishing attack, and that some of the stolen data was subsequently published online. The company disclosed the…CYBERINSIDER.COM
13 AugTrezor discloses data breach affecting nearly 14,000 customersHardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping and logistics provider, was hacked [...]BLEEPINGCOMPUTER.COM
13 AugIn a first, US will allow some private firms to carry out cyberattacksZack Whittaker reports: The U.S. government will for the first time allow vetted private companies to launch offensive cyber operations against international criminal gangs and hackers, the White House said on Wednesday. In a newly published presidential memorandum, the Trump adm…DATABREACHES.NET
13 AugQuincy Valley Medical Center notifies patients of Aesto breachAs Seen on Facebook: To our Patients, Some of you have or will receive a letter from Grant County Public Hospital District 2 describing a security incident involving one of our third-party vendors. It is important to us that you understand some facts regardin this incident. First…DATABREACHES.NET
13 AugAI’s ‘middle class’ has gotten dramatically better at hackingAs frontier models and their sandbox escaping exploits dominate front-page news, researchers are increasingly worried about cheaper, more efficient AI models. The post AI’s ‘middle class’ has gotten dramatically better at hacking appeared first on CyberScoop .CYBERSCOOP.COM
13 AugMicrosoft patches LegacyHive Windows zero-day vulnerabilityMicrosoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday. [...]BLEEPINGCOMPUTER.COM
13 AugAI 'watermark removers' flood the web. Almost none can prove they work.Multiple 'watermark removers' have surfaced days after Anthropic began watermarking text generated by Claude, including an open source project with over 4,500 GitHub stars and paid AI detection evasion services. None of the tools' claims about defeating the text watermark can be …BLEEPINGCOMPUTER.COM
13 AugAttackers target zero-day vulnerability in geospatial data platform GeoServerSecurity researchers have seen evidence that attackers are attempting to exploit a currently unpatched SQL injection vulnerability in GeoServer, an open-source web server for managing and publishing geospatial data. The software is widely used by organizations in many industries,…CSOONLINE.COM
13 AugCuriouser and CuriouserIn this edition of the Threat Source newsletter, William reflects on the “Make Hazel a Hacker” segment in Beers with Talos, and how cybersecurity is a field where questions can lead to multiple correct answers.TALOSINTELLIGENCE.COM
13 Aug KEVPlease hack responsibly.President Trump deputizes private-sector companies to target cybercriminals. The LiteLLM supply-chain attack exposed credentials belonging to thousands of organizations. Data-theft campaign targets misconfigured Salesforce and ServiceNow instances. Hackers deploy AI agents to bre…THECYBERWIRE.COM
13 AugFlock says its new tool will help identify police abuse, but hasn’t explained how it worksThe surveillance company announced it's making a tool called "Audit Assistance" mandatory for all customers, claiming it's already helped catch abuse. But the company has yet to explain how the tool works in detail, raising questions about its effectiveness.TECHCRUNCH.COM
13 AugThe Breached WiFi AI Ports... What? - PSW #939In the security news this week: • North Carolina ports and contingency plans • Back to paper and pencils • Midnight Blizzard compromises hotel Wi-Fi • DNS strikes again • Captive portals, stolen credentials, and nation-state scale • Phishing-resistant MFA • Goodbye SMS and voice …YOUTUBE.COM
13 AugThe Ancient Art of SIEM: Why 2003 Problems Look So Familiar in 2026Lately, I’ve been reading a lot of insightful posts related to best practices in SIEM, detection, and logs (written in 2026). The interesting bit is that a lot of these best practices looked good to me and made sense — and yet, they felt incredibly familiar… As I dug deeper, I re…MEDIUM.COM
13 AugWhen Patching Isn't Enough: What the Fairlife Ransomware Attack Says About Network Edge RiskA recent ransomware incident at Coca-cola owned dairy company Fairlife provides a potent example of network edge devices being targeted for exploitation, and of the scale of outcomes attackers can achieve by exploiting them. According to reporting from MSN and others, the ransomw…ECLYPSIUM.COM
13 AugApple sends new ‘Threat Notification’ alerts over mercenary spyware attacksYou're not alone if you just received an "Apple Threat Notification" saying it detected a "mercenary spyware attack targeted at your iPhone." [...]BLEEPINGCOMPUTER.COM
12 AugSandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run CommandsThe Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware. CERT-UA…THEHACKERNEWS.COM
12 AugAI deployments are stretching enterprise security to its limitsCISOs and CTOs expect AI deployments to increase their organizations’ attack surface by an average of 14% over the next year. Nearly all lack visibility into AI deployments, and 90% are concerned about employees using unapproved AI tools outside formal oversight, according …HELPNETSECURITY.COM
12 AugPentestGPT: Open-source automated penetration testing agentic frameworkPentestGPT is an open-source penetration testing agent that points a large language model at a target and lets it work. In its default mode it runs recon, then exploit, then walkthrough, each stage feeding the next. Switch it to pentest mode and the stages become asset discovery,…HELPNETSECURITY.COM
12 Aug KEVMicrosoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wormable RCEMicrosoft Patch Tuesday for August 2026 fixes 398 CVEs, including an actively exploited zero-day and a wormable DNS flaw enabling remote code execution. Microsoft released its Patch Tuesday security updates for August 2026 on Tuesday, covering 398 new CVEs across Windows, Office,…SECURITYAFFAIRS.COM
12 Aug4 gaps slowing AI in enterprise SOCsArtificial intelligence (AI) has quickly become a strategic priority for enterprise security teams. Yet despite growing investment in AI-driven security software, many enterprise SOCs are struggling to translate AI into measurable operational improvements. The issue isn’t whether…CSOONLINE.COM
12 AugThe AI harness is the new attack surfaceAsk a security researcher what makes an AI agent dangerous, and the instinct is to talk about the model — what it will and won’t refuse, how easily it can be jailbroken, whether its weights can be trusted. That instinct is increasingly out of date. A growing body of security rese…CSOONLINE.COM
12 Aug KEVWindows 11 security update fixes actively exploited zero-day flawMicrosoft has released the August 2026 cumulative update for Windows 11, fixing 236 Windows vulnerabilities, including a privilege-escalation flaw that is already being exploited in attacks. The KB5121003 update was released earlier today for Windows 11 versions 24H2, 25H2, and 2…CYBERINSIDER.COM
12 AugFresh Windows Zero-Day Exploited in North Korean CyberattacksThe bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor. The post Fresh Windows Zero-Day Exploited in North Korean Cyberattacks appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugIvanti EPM Update Patches Remotely Exploitable FlawsThe vulnerabilities could be exploited to leak credentials for external SQL connections or crash an agent service. The post Ivanti EPM Update Patches Remotely Exploitable Flaws appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugCBTS brings continuous penetration testing to enterprise securityCBTS has launched Penetration Testing as a Service (PTaaS), combining autonomous penetration testing with security expertise to help organizations continuously identify exploitable risks, validate attack paths, and prioritize remediation as their environments evolve. Cloud enviro…HELPNETSECURITY.COM
12 AugChrome’s anti-abuse protections block 7 billion unwanted Android notifications dailyGoogle Chrome’s latest measures against abusive web push notifications include automatically revoking notification permissions for inactive and suspicious websites, helping reduce scams, phishing attempts, and other deceptive content. Abusive notifications (Source: Google) …HELPNETSECURITY.COM
12 AugDomain Security Plus BlackHat USA 2026 Interviews from Balance Theory and WiCyS - BSW #460As cyber threats become more AI-powered, attacks continue to rise. Threats can arise from all areas of a company’s IT infrastructure, however most attacks utilize a domain name to infiltrate systems. How secure is your domain ecosystem? Ihab Shraim, Chief Technology Offider at CS…YOUTUBE.COM
12 AugNew Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privilegesNightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldBreak" after Microsoft released the August 2026 Patch Tuesday security updates. [...]BLEEPINGCOMPUTER.COM
12 AugChipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities CombinedIntel has informed customers about several high-severity vulnerabilities that can lead to privilege escalation and even code execution. The post Chipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combined appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugFake CCleaner downloads turn Chrome into a credential-stealing surveillance toolA convincing fake version of the widely used CCleaner utility is being used to deliver a multi-stage Windows malware that ultimately abuses Google Chrome for credential theft and surveillance. Researchers from Malwarebytes found the campaign distributing a malicious Chrome extens…CSOONLINE.COM
12 AugSignal adds new security feature to thwart man-in-the-middle attacksSignal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven't been intercepted. [...]BLEEPINGCOMPUTER.COM
12 AugLazarus hackers pair fake job offers with Windows zero-day exploitThe North Korea-linked Lazarus group is using fake job offers, trojanized PDF software and a Windows zero-day in attacks aimed primarily at the defense sector, Check Point researchers have found. The activity is part of Operation Dream Job, a long-running campaign in which attack…HELPNETSECURITY.COM
12 AugCloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new waveFrom Cloudflare’s new report: Key insights The 1 Tbps club grew. Cloudflare mitigated a combined 935 network-layer DDoS attacks exceeding 1 Tbps in the first half of 2026 and a +519% quarter-over-quarter surge between Q1 and Q2. The attack-vector center of gravity shifted f…DATABREACHES.NET
12 AugA serious incident occurred at MyDr, a Polish healthcare system providerAdam Haertle reports: MyDr has just announced that it is investigating a serious security incident on its network. The alleged perpetrators of this incident contacted us earlier and claimed to have access to patient data from numerous Polish clinics. According to the hackers, the…DATABREACHES.NET
12 AugMicrosoft’s massive Patch Tuesday releases continue as AI reshapes bug discoveryThis month’s update features about five times the volume of patches Microsoft was shipping in a typical month before AI-assisted vulnerability discovery took hold.THERECORD.MEDIA
12 AugCISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaignResearchers disclosed the bug to Microsoft after examining a long-running campaign by North Korean hackers to exploit the job application process.THERECORD.MEDIA
12 AugHackers leverage new Microsoft SharePoint exploit in attacksHackers have already begun using a proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday. [...]BLEEPINGCOMPUTER.COM
12 AugOpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' ReasoningA newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal reasoning and secrets from session logs, including API keys and passwords. The weakness affected encrypted reasoning objects used by the …THEHACKERNEWS.COM
12 AugThree intrusions at UK criminal records office went undetected for two yearsUnread antivirus alerts and an unpatched content management system exposed Britain's ACRO to three separate data breaches, according to a reprimand notice.THERECORD.MEDIA
12 AugLazarus Used Post-Quantum Key Exchange to Deliver Zero-DayLazarus malware used post-quantum key exchange to protect delivery of a Windows zero-day exploitINFOSECURITY-MAGAZINE.COM
12 AugGunra Ransomware Exploits Fortinet Flaws to Target Critical InfrastructureGunra actors are using stealth to exfiltrate vast volumes of data from Microsoft services, US and Korean agencies have warnedINFOSECURITY-MAGAZINE.COM
12 AugThe Threat Hiding in Your Hiring Process: How Fake Remote Workers Get InFake remote workers can exploit gaps between hiring checks, device delivery, and account access to enter organizations under false identities. Specops Software explains how document verification and biometric liveness checks can help organizations confirm that the person receivin…BLEEPINGCOMPUTER.COM
12 AugStealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom ToolsetResearchers observed the novel campaign exploiting unauthenticated guest access to quietly enumerate and exfiltrate exposed data from both platforms. The post Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugA stranger has been reading Salesforce and ServiceNow portals worldwide for 17 monthsMost security stories start with something broken. This one starts with everything working as designed. Researchers at Reco have been tracking a campaign they call City-Forum, named after a domain registered in 2002, abandoned, and now resolving to a generic rented server from a …HELPNETSECURITY.COM
12 Aug737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have OneA massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure. The extensions, published across at least 40 Chrom…THEHACKERNEWS.COM
12 AugPatch Tuesday: Update now to fix 421 flaws, including three zero-daysMicrosoft's August Patch Tuesday fixes 421 vulnerabilities, including three zero-days, 62 critical flaws, and dozens of Office remote code execution bugs.MALWAREBYTES.COM
12 Aug KEVSharePoint Vulnerability Exploited Shortly After PoC ReleaseThe vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild. The post SharePoint Vulnerability Exploited Shortly After PoC Release appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugRESOURCE: Introducing the Cyber Incident RegistryOver on DysruptionHub, Joseph Topping has introduced a new resource for exploring cyber disruptions, following incidents over time, and uncovering the connections between them: The registry is a research resource focused specifically on cyber disruptions. Each incident profile br…DATABREACHES.NET
12 AugAfter Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bugThis is the latest zero-day released by security researcher Nightmare Eclipse, despite Microsoft publicly threatening to take legal action against them.TECHCRUNCH.COM
12 AugPatch Tuesday notes: Microsoft fixes three zero-days.Attackers target SharePoint vulnerability following PoC release. Business news: Visa and Deel both acquire identity verification companies.THECYBERWIRE.COM
12 AugCisco says software vulnerability could let hackers crash firewallsThreat actors already have begun exploiting the flaw, according to the U.S. government.CYBERSECURITYDIVE.COM
12 AugPlug and Pwn attack uses fake USB devices for Windows SYSTEM accessSecurity researchers have disclosed new "Plug and Pwn" attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor software and gain SYSTEM privileges. [...]BLEEPINGCOMPUTER.COM
12 AugCA: Snoopers Beware; NL’s Privacy Commissioner Recommends Naming Individuals in Snooping-Related BreachesVOCM reports: The province’s Privacy Commissioner is recommending that public bodies consider providing the name of anyone involved in snooping-related privacy breaches to affected individuals. The recommendation comes after an employee of NL Health Services had a peek at a perso…DATABREACHES.NET
12 AugLazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy BackdoorThe North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and…THEHACKERNEWS.COM
12 AugA flurry of fixes.We got your Patch Tuesday notes. Attackers target Microsoft SharePoint vulnerability following PoC release. Cyberattack on CEVA Logistics causes ongoing supply chain disruptions. Wesco confirms data breach following extortion claims. Akira ransomware bypasses EDR in Safe Mode. Ca…THECYBERWIRE.COM
12 AugLong-running Data Theft Campaign Targeting Salesforce, ServiceNowThe "City-Forum" campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling.DARKREADING.COM
12 Aug"City-Forum" data-theft attacks target Salesforce, ServiceNow portalsAn ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. [...]BLEEPINGCOMPUTER.COM
11 AugBdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress AdminsCybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero so…THEHACKERNEWS.COM
11 AugThe future of AI security research isn’t autonomous, it’s human-amplifiedMeet HTTP Terminator, a new AI system that has identified hundreds of websites vulnerable to HTTP request smuggling, hacked them live at scale, and even identified a “genuinely new class” of vulnerability, dubbed “shared-parser confusion.” But it didn’t do it alone; it was guided…CSOONLINE.COM
11 AugUsing LLMs for Vuln Discovery - Rishi Sharma - ASW #395Finding flaws has always been a focus of appsec. And now with open source projects and open weight models orgs have modern tools to review code and conduct pentests. Rishi Sharma describes the motivation behind creating a platform of LLM-driven security tools and the effective wa…YOUTUBE.COM
11 AugRansomware gangs don’t need control system access to disrupt industrial productionDisrupting IT systems that support industrial environments can be enough to interrupt production, even when ransomware operators do not gain direct access to industrial control systems (ICS), according to Dragos. The company identified 1,140 ransomware incidents involving industr…HELPNETSECURITY.COM
11 AugGPT-5.6-Cyber refuses security researchers’ requests far less oftenGPT-5.6-Cyber is a new OpenAI model built on GPT-5.6 Sol, trained to find zero-day vulnerabilities and build exploit chains, with fewer refusals on higher-risk, dual-use work. Model is available only through Daybreak Red, the higher tier of OpenAI’s vetted access program fo…HELPNETSECURITY.COM
11 AugPreviously unseen entry vector used to breach Polish energy plantThe December 29 cyberattack on a Polish combined heat and power (CHP) plant was the first observed case of attackers gaining access to an OT network through a private APN, according to CERT Polska. The private APN is a dedicated mobile network that a Distribution System Operator …HELPNETSECURITY.COM
11 AugYour security vendor gets the frontier cyber model, you get the findingsSelected red team specialists can now use OpenAI’s cyber models to find and exploit weaknesses in client applications and infrastructure. Those clients never get the models themselves. That split is the design of the Daybreak Cyber Partner Program, which OpenAI expanded on …HELPNETSECURITY.COM
11 AugMalicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate SecretsA malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction. The trick can work even after a blunt version of the same theft is refused: …THEHACKERNEWS.COM
11 AugGunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach NetworksCybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government ser…THEHACKERNEWS.COM
11 AugCuba's Spies, Defectors, and the Ex-FBI Agent Who Met Them AllFor decades, Cuban intelligence has been seen as a force that punches above its weight. Shaped during the Cold War through cooperation with the Soviet Union, its intelligence officers received extensive training by the KGB. But where does Cuba’s spy service stand today, especiall…THECYBERWIRE.COM
11 AugAI for Military SupportInteresting empirical research: “ Black Box Warfare: Human Judgment and Military Decision-Making in the Age of AI .” Abstract: How is AI transforming decision-making in modern conflict? This study provides a unique empirical window into that question by deploying a hi…SCHNEIER.COM
11 AugGitHub already has an EDR. You just have to listen to itMany of the recent supply-chain attacks could have been caught earlier if defenders looked closely at the telemetry GitHub already provides, researchers said. At their Black Hat USA 2026 presentation, researchers Yossi Weizman of Microsoft and Mor Weinberger of Echo argued the ca…CSOONLINE.COM
11 AugOpenAI launches GPT-5.6-Cyber as AI narrows vulnerability response windowOpenAI has expanded its Daybreak cybersecurity program and introduced GPT-5.6-Cyber, a specialized model for approved security researchers, as the company warned that AI could give defenders less time to respond to developing threats. Daybreak now has two access levels. Blue give…CSOONLINE.COM
11 AugHead Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participantsKaspersky experts have discovered malicious TrueConf software installers. The Head Mare APT group uses them to deliver the PhantomCore and PhantomGraph backdoors to target systems by exploiting vulnerabilities in an unpatched TrueConf server.SECURELIST.COM
11 AugCisco warns of high-severity ClamAV flaws with public exploitsCisco warned of two high-severity vulnerabilities affecting the Secure Endpoint Connector that allow threat actors to crash the ClamAV scanning process in denial-of-service (DoS) attacks. [...]BLEEPINGCOMPUTER.COM
11 Aug KEVCISA: Microsoft SharePoint flaw now exploited in ransomware attacksCISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July. [...]BLEEPINGCOMPUTER.COM
11 AugOpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit DevelopmentOpenAI on Monday unveiled a new cybersecurity-focused model called GPT‑5.6‑Cyber that it said is focused on vulnerability research, penetration testing, and incident response. "Built on GPT‑5.6 Sol, it is trained to improve capabilities on several specialized cybersecurity tasks …THEHACKERNEWS.COM
11 AugVague Task, Total Access: When AI Delegation Becomes a Security RiskAI agents can improvise beyond the intended scope of a task when they are given broad access to enterprise systems and data. Token Security explains why organizations need to define agent intent and continuously enforce permissions around what each agent was actually created to d…BLEEPINGCOMPUTER.COM
11 AugUS Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’The Water Watch Center launched at DEF CON aims to help under-resourced utilities protect their systems against hackers. The post US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’ appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugMozilla rotates Firefox and Thunderbird signing key after GitHub exposureMozilla has replaced a GPG subkey used to sign some Firefox and Thunderbird releases after an unencrypted copy of the previous key was accidentally committed to a private GitHub repository. The organization says its audit records show no evidence that an unauthorized person acces…CYBERINSIDER.COM
11 AugZoom Patches Zero-Click Code Execution VulnerabilityImpacting Zoom annotation, the bug could be exploited by a meeting participant to execute code on another participant’s machine. The post Zoom Patches Zero-Click Code Execution Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugAdobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic FlawsThe security defects could be exploited for arbitrary code execution and denial-of-service. The post Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugThe inconvenient truth about AI pentesting: someone has to check all the workAI pentesting can flood teams with findings they cannot validate. The real challenge is managing “validation debt” as discovery scales. AI pentesting has a ‘Sorcerer’s Apprentice’ problem. Enchant a broom to fetch water, and it will fetch water, relentlessly, lo…SECURITYAFFAIRS.COM
11 AugCisco Warns of Seven ClamAV Flaws, Two With Public PoCsCisco warns that seven ClamAV flaws affect Secure Endpoint Connector products, with two having public PoCs that could enable remote DoS attacks. Cisco warned that seven ClamAV vulnerabilities affect its Secure Endpoint Connector on Windows, macOS and Linux. ClamAV is an open-sour…SECURITYAFFAIRS.COM
11 AugDeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to DisruptThe ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience. "Its recovery ecosystem combines the Session messaging network with blockchain-back…THEHACKERNEWS.COM
11 Aug KEVMicrosoft Patch Tuesday August 2026, (Tue, Aug 11th)This month we got patches for 418 vulnerabilities. Of these, 62 are critical, 1 is being exploited in the wild, and 2 were publicly disclosed as zero-days. Notable fixes include Windows privilege escalation, container tampering, and critical QUIC and DNS Server remote code execut…ISC.SANS.EDU
11 AugHow Trail of Bits helps verify the integrity of your Signal chatsEvery Signal chat starts the same way: the client asks the Signal server for the public key associated with your contact’s phone number. But how do you know the server gave you the right key? A compromised server could provide a false public key, allowing the client to encrypt me…TRAILOFBITS.COM
11 AugShattering the Dream – When a Job Offer Becomes a Zero-Day AttackKey Points Introduction Since early 2026, Check Point Research has tracked a wave of the Operation Dream Job campaign. This wave primarily targeted the defense sector worldwide, with a particular emphasis on companies operating in the aerospace and aviation industries. …RESEARCH.CHECKPOINT.COM
11 AugExfilSquad Targets New Victims, Shares Data via TorrentsExfilSquad targets 13 organizations, exploiting cloud portals for data theft and using torrents to spread stolen information and amplify damage. Resecurity is tracking the activity of ExfilSquad – the group announced new victims this week. ExfilSquad is a new cybercrime gro…SECURITYAFFAIRS.COM
11 Aug KEVMicrosoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysToday is Microsoft's August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities. [...]BLEEPINGCOMPUTER.COM
11 AugAugust 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-DayA use-after-free in the afd.sys Windows kernel-mode driver has been exploited to gain SYSTEM privileges. The post August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugStolen Change Healthcare data gets new handling rules in court orderNaomi Diaz reports: A federal judge in Minnesota has signed off on a strict set of rules for how the data stolen in Change Healthcare’s 2024 cyberattack can be handled during the ongoing lawsuit. Magistrate Judge Dulce J. Foster approved the plan, reviewed by Becker’s, Aug. 7. It…DATABREACHES.NET
11 AugStop Building a 2003 SOC with AI: Triage Must Die (Part 2)(with key ideas from Augusto Barros ) In Part 1 of this series , we dumped a pile of uncomfortable questions on you and promised answers. The core thesis, if you recall: if you add AI agents into a legacy, swivel-chair SOC structure, you are essentially building a robotic horse p…MEDIUM.COM
11 AugNSA installs DHS lawyer as new general counselKerianne Tobitsch, who most recently served as a senior lawyer at the Homeland Security Department, is the NSA's new general counsel, sources told Recorded Future News.THERECORD.MEDIA
11 Aug KEVCisco warns of ASA and FTD VPN flaw exploited to crash devicesCisco is warning that a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense (FTD) software is being actively exploited in attacks to remotely crash affected devices. [...]BLEEPINGCOMPUTER.COM
11 Aug KEVMicrosoft Plugs Nearly 400 Security HolesMicrosoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.KREBSONSECURITY.COM
11 AugSquirrel Soup, Ghostjacking, OpenSource, Gunra, Beesafe, AI threats, SBOMS, and more - SWN #606Squirrel (and other) Soup, Ghostjacking, OpenSource, Gunra, Beesafe, AI threats, SBOMS, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-606YOUTUBE.COM
11 AugGunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFAThe ransomware-as-a-service operation is finding success against critical infrastructure targets with leaked Conti code and old flaws in firewalls and VPN appliances.DARKREADING.COM
11 AugSN 1091: The Post BlackHat State of AI - When AI Writes MalwareAI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free…TWIT.TV
10 AugRisky Bulletin: Two law firms pay giant ransomsTwo American law firms pay multi-million dollar ransoms, a Metabase zero-day is being used in data theft attacks, Russian hackers disrupted a second power plant in Poland, and there’s a remote code execution bug in WordPress… again!RISKY.BIZ
10 AugHow to report an AI Act violation in the EUThe EU’s fight to regulate AI models entered a new chapter on 2 August 2026, when the European Commission’s AI Office and national authorities began enforcing the AI Act. The AI Act is the EU’s law regulating AI, the first broad legal framework of its kind. It c…HELPNETSECURITY.COM
10 AugChainloop: Open-source evidence store and policy engine for the software supply chainChainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeline, picks up what the build produced, uploads those files to content-addressable storage, and references each one in a sign…HELPNETSECURITY.COM
10 AugSolidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and CredentialsCybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been observed delivering a browser wallet and credential stealer. The names of the extensions are below - helper-beeps.solidity-pro web…THEHACKERNEWS.COM
10 Aug7 key trends defining the cybersecurity market todayAI is having a seismic impact on the cybersecurity market. Record-shattering amounts of venture capital is flowing into a new generation of startups focused on AI cybersecurity. At the same time, established cybersecurity vendors are racing to integrate AI and agentic AI features…CSOONLINE.COM
10 Aug4 million fake applications and one blind spot: A SOC playbook for OAuth client ID spoofingKey takeaways OAuth client ID spoofing defeats detections that key off application name or a known application ID, because the field itself is fabricated, rotated or blank. AADSTS700016 paired with an unrecognized client ID can mean valid credentials, not a broken app registratio…CSOONLINE.COM
10 Aug KEVCritical Progress LoadMaster flaw now actively exploited in attacksThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. [...]BLEEPINGCOMPUTER.COM
10 AugCISA Urges Immediate Patching of Exploited Progress LoadMaster VulnerabilityThe critical-severity flaw allows unauthenticated, remote attackers to execute arbitrary commands. The post CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
10 AugAnthropic to put AI in charge of reviewing Claude Code actions by defaultAnthropic will make auto mode in Claude Code the default for new sessions on Pro, Max, and Team plans starting August 14. Users who previously selected a different default may receive a one-time prompt asking whether they want to switch to auto mode. In a controlled experiment wi…HELPNETSECURITY.COM
10 Aug“Ghostjacking” Exploits AI Agents’ Trusted Access to Evade Firewall ControlsTenet reported that half of Fortune 500 companies are vulnerable to the Ghostjacking technique, which involves tricking AI agents with fake reportsINFOSECURITY-MAGAZINE.COM
10 AugMetabase Patches Vulnerability Exploited as Zero-DayThe security defect allows unauthenticated, remote attackers to gain administrative access to Metabase instances. The post Metabase Patches Vulnerability Exploited as Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
10 AugOne-click flaw in Atlassian Rovo exposed enterprise data via prompt injection attackAtlassian’s enterprise AI assistant Rovo, which is usually connected across sensitive work environments like Slack, Microsoft 365, and Google Workspace, was found vulnerable to data leaks through malicious instructions. At DEF CON 34 , researchers from Varonis demonstrated an att…CSOONLINE.COM
10 AugOpenAI Pauses Astra Model Over Critical Cybersecurity Risk ConcernsOpenAI paused work involving Astra after tests showed cybersecurity abilities that could approach its Critical risk threshold under the company’s framework. OpenAI disclosed that internal evaluations of Astra, one of its upcoming models, have found cybersecurity capabilities sign…SECURITYAFFAIRS.COM
10 AugTrueConf Server Flaws Exploited to Replace Client Installers with PhantomCoreThe threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, IT, and software development sectors. Russian cybersecurity v…THEHACKERNEWS.COM
10 AugOpenAI says Astra could reach ‘critical’ cyber capability, tightens safeguardsOpenAI said its upcoming model Astra is showing cybersecurity capabilities that could reach its highest risk category, where a system can autonomously find and exploit vulnerabilities or carry out end-to-end cyberattacks against hardened targets. The company disclosed the assessm…CSOONLINE.COM
10 AugChina-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warnsA China-linked threat actor is believed to be exploiting a critical vulnerability affecting cybersecurity software from the company N-able.THERECORD.MEDIA
10 Aug10th August – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 10th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES North Carolina Ports, the US authority operating the ports of Wilmington, Morehead City and others, has suffered a cyberattack that…RESEARCH.CHECKPOINT.COM
10 AugMetabase zero-day exploited to access Framework customer dataFramework, the San Francisco-based company that designs repairable and upgradeable laptops, has suffered a data breach after attackers managed to exploit a zero-day vulnerability in the Metabase business intelligence service. According to the notification sent to affected Framewo…HELPNETSECURITY.COM
10 Aug KEVInside the Metabase SQLi: Exploited in the WildReverse engineering GHSA-vwf4-m7j8-wcjf with AI to accelerate defense.WIZ.IO
10 AugCISA: SonicWall SMA1000 flaws now exploited by ransomware gangsCISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. [...]BLEEPINGCOMPUTER.COM
10 AugCisco Warns of High-Severity ClamAV Vulnerabilities With Public PoCRemote, unauthenticated attackers could exploit the bugs to cause a denial-of-service (DoS) condition. The post Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC appeared first on SecurityWeek .SECURITYWEEK.COM
10 AugResearchers find that only a quarter of AI-generated patches are fully successful.Ransomware attacks exploit critical N-able flaw. LexisNexis disables some services following suspicious activity.THECYBERWIRE.COM
10 AugPoland uncovers second heat plant cyberattack that went hidden for monthsThe incident occurred on the same day as coordinated cyberattacks struck more than 30 other renewable energy installations and a larger heat plant, as Poland publicly disclosed in January.THERECORD.MEDIA
10 AugUK man tied to The Com sentenced for abusing 117 victimsJustin Swaddle, who was a minor when he committed the crimes, coerced children across multiple countries into self-harm and sexual abuse using threats tied to their personal information, authorities said. The post UK man tied to The Com sentenced for abusing 117 victims appeared …CYBERSCOOP.COM
10 AugSecure development can help turn the tables as AI alters cyber landscapeA top Microsoft executive says a shift toward memory safety and other preventative measures can limit the ability to exploit flawed software.CYBERSECURITYDIVE.COM
10 AugResearchers Uncover RovoBlast Vulnerability in Atlassian AI AssistantAtlassian fixed a flaw letting one crafted link make its Rovo AI assistant exfiltrate company dataINFOSECURITY-MAGAZINE.COM
10 Aug⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router BackdoorsA lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default. That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit …THEHACKERNEWS.COM
10 AugAttack Surface Management - Matt Lea - CSP #227In this episode of CISO Stories, Jessica Hoffman sits down with Matt Lee to explore attack surface management, AWS security, and the cloud misconfigurations that can put organizations at risk. Matt shares lessons from his experience auditing cloud environments, including common A…YOUTUBE.COM
10 AugUnpatched HP ThinPro flaw allows bypass of disk encryption protectionsAn unpatched vulnerability in HP ThinPro 8 and 9 allows attackers with physical access to bypass the operating system’s TPM-backed full-disk encryption protections and recover the key securing the device’s root partition. The zero-day remained without a publicly available fix whe…CYBERINSIDER.COM
10 AugChina-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central FlawMicrosoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware, the Micro…THEHACKERNEWS.COM
10 AugCoruna, DarkSword iOS Exploits Proliferate GloballySophisticated iPhone exploit chains previously limited to nation-states are spreading far and wide to organized cybercrime groups.DARKREADING.COM
10 AugOpenAI releases ChatGPT 5.6 Cyber, but it's only for approved usersOpenAI has developed a new model called "GPT 5.6 Cyber," designed for vulnerability research, penetration testing, incident response, and remediation. [...]BLEEPINGCOMPUTER.COM
10 AugCISA Advisory: #StopRansomware: Gunra RansomwareGunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both enc…DATABREACHES.NET
10 AugNow with extra vulnerabilities.Researchers find that only a quarter of AI-generated patches are fully successful. Ransomware attacks exploit critical N-able flaw. Atlassian fixes critical flaw in Rovo AI. LexisNexis disables some services following suspicious activity. US Senate confirms Adam Cassady as cyber …THECYBERWIRE.COM
10 AugMetabase SQL Zero-Day Attacks Could Have Wide Blast RadiusThe maximum-severity vulnerability, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users.DARKREADING.COM
9 AugAlcon - 218,395 breached accountsIn August 2026, the Alcon eye care company was named in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data allegedly sourced from Alcon containing 218k unique email addresses along with other largely corporate B2B contact fields, including nam…HAVEIBEENPWNED.COM
9 AugRansomware gangs skip the CEO, head straight for the 40-something IT managerCarly Page reports: Turns out the fastest way to get a company to consider paying a ransom isn’t calling the CEO – it’s targeting the 46-year-old IT manager. That’s according to Zscaler, whose ThreatLabz researchers tracked 351 victims across 334 organizations c…DATABREACHES.NET
9 Aug KEVSecurity Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Palo Alto Networks Faces China Cy…SECURITYAFFAIRS.COM
9 AugKR: 3Pro TV Data Breach Exposes 460,000 Records, Including 2,979 Bank AccountsPark Hyo-jung reports: More than 460,000 pieces of personal data, including bank account and credit card information, were exposed in a breach at South Korean financial media outlet 3Pro TV. E-Broadcasting, the company that operates 3Pro TV, posted a notice on the outlet’s …DATABREACHES.NET
8 AugNearly 800 Malicious npm Packages Deliver Cross-Platform RAT and InfostealerA cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. "These packages appear to use AI slop squatted, or randomly generated typo-squatting p…THEHACKERNEWS.COM
8 AugCoding for Veterans: Cybersecurity Today on the Weekend with David ShipleyCoding for Veterans: From Military Service to Cybersecurity & Generative AI Careers This episode is sponsored by Nordlayer. Contact them at Nordlayer.com/hashtagtrending and use discount code NLSummer26 for a discount during their summer sale. In this Weekend episode of Cybersecu…CYBERSECURITYTODAY.LIBSYN.COM
8 Aug KEVMetabase Zero-Day Exploited in Wild Allows Admin Access Without AuthenticationMetabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticat…THEHACKERNEWS.COM
8 AugN-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and PersistN-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product. "We are proactively expanding protections in response to ongoing monitor…THEHACKERNEWS.COM
8 AugUnlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare PatientsHackers stole personal, medical, and insurance data of 3.8 million people from Unlimited Technology Systems’ data center. Unlimited Technology Systems disclosed a data breach affecting more than 3.8 million people after hackers accessed one of its commercial data centers be…SECURITYAFFAIRS.COM
8 AugCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataThe RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data. The post Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data appeared first on SecurityWeek .SECURITYWEEK.COM
8 AugCity of Coweta refuses to pay ransom after system-wide cyberattackAn update on the ransomware attack affecting the City of Coweta: the city manager has been through a ransomware attack before with another city, and reports that after they paid, they were reinfected weeks later, so Coweta will not be paying any ransom demands. Threat actors who …DATABREACHES.NET
8 Aug KEVMetabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataAttackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims. Metabase just confirmed something no analytics vendor wants to write: attackers found and used an unpatched, maximum-severity flaw against …SECURITYAFFAIRS.COM
8 AugHackers breach TrueConf to trojanize client installers with backdoorsThe Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. [...]BLEEPINGCOMPUTER.COM
8 AugCity of Suisun declares local emergency after cyberattack downs 911 dispatch systemKatie Chavez reports: Suisun City officials declared a state of emergency Saturday, Aug. 8, after a cyberattack took out the city’s emergency dispatch line and other key systems. City officials said that “malicious software infected and compromised IT systems” at about 5:45 a.m. …DATABREACHES.NET
7 AugThe Era of Cheap Bugs, Water utility attacks spread to 12 states, Coldcard wallet losses could hit 130 millionPasskeys Phished at BlackHat, Water Utility Attacks Spread, and $130M ColdCard Wallet Flaw In this August 7, 2026 episode, David Shipley recaps key Black Hat themes, including Microsoft's warning that cheap, automated vulnerability discovery is outpacing patching, alongside resea…CYBERSECURITYTODAY.LIBSYN.COM
7 AugShieldFont fights AI scraping by handing crawlers the wrong wordsIsaque Seneda and Gabriel Abrucio built a web font that draws one set of words on screen and leaves a different set in the page’s source code. A person reading in a browser sees the writing as written. A scraper pulling the HTML gets different words in the same grammar, at …HELPNETSECURITY.COM
7 AugAugust 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?July 2026 Patch Tuesday was record-setting in so many ways. The sheer volume of security patches for almost every product in the Microsoft portfolio was the highest ever and, of course, well over 600 CVEs were identified in the Security Updates Guide. Interestingly, only two CVEs…HELPNETSECURITY.COM
7 AugWhat the first year of EU AI Act transparency enforcement could look likeIn this Help Net Security interview, Edwin Weijdema, Field CTO at Veeam, answers questions on Article 50 of the EU AI Act and what the first year of enforcement might bring. He explains why corrective orders will likely outnumber large fines, when an AI agent working through a ti…HELPNETSECURITY.COM
7 AugCritical Vulnerabilities Patched With Chrome 151 UpdateThe browser refresh eliminates over two dozen memory safety bugs, including critical use-after-free flaws. The post Critical Vulnerabilities Patched With Chrome 151 Update appeared first on SecurityWeek .SECURITYWEEK.COM
7 AugKeepit AI Truth Cloud protects the data behind enterprise AIKeepit announced AI Truth Cloud, transforming backup from a compliance requirement into the strategically valuable data asset an organization can hold. As AI agents take on business-critical decisions, AI Truth Cloud positions Keepit as the sovereign source of truth that enterpri…HELPNETSECURITY.COM
7 AugNew NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT TablesSecurity researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. Presented at Black Hat …THEHACKERNEWS.COM
7 AugMalware Can Abuse Windows Hello for Business Keys for Persistent Entra ID AccessSecurity researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, disclose victim IP addresses and mapped ports, and exhaust NAT table…THEHACKERNEWS.COM
7 AugPython package security in 2026: How supply chain attacks are targeting your AI development environmentOn March 24, 2026, developers building AI applications with LiteLLM — a Python package with 95 million monthly downloads — unknowingly installed malicious code. A threat actor group known as TeamPCP had compromised the PyPI distribution pipeline and pushed malicious versions 1.82…CSOONLINE.COM
7 AugTruck Brake Controller’s Safety Recall Doubled as Hidden Security FixNMFTA research shows a Bendix EC80 brake controller safety recall also patched remote code execution and DoS vulnerabilities. The post Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix appeared first on SecurityWeek .SECURITYWEEK.COM
7 AugAI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-DayPortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate attack vectors. PortSwigger said a separate human-guided discovery cascade…THEHACKERNEWS.COM
7 AugAgentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026Agentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event. Key takeaways Building defensi…TENABLE.COM
7 AugGrowing Up The Hard WayOpen Source had a great childhood. For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and never once thought about who was watching. It ran the kind of lemonade stand that took IOUs from anyone who wandered up — take what you need…THEHACKERNEWS.COM
7 Aug18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape ContainersA use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw has existed since 2008. The fix already shipped: stable kernels 7.1.6, 6.18.42, 6…THEHACKERNEWS.COM
7 AugIPVanish launches isolated browser to reduce Windows telemetry exposureIPVanish has introduced a remote browser isolation feature designed to prevent Windows telemetry from directly correlating browsing activity with Microsoft’s persistent Global Device Identifier (GDID). The company announced IPVanish Secure Browser, citing the recently discl…CYBERINSIDER.COM
7 Aug200 accounts compromised in Swiss government’s Microsoft SharePoint breachHackers exploited vulnerabilities in Microsoft SharePoint servers belonging to Switzerland’s Federal Office of Information Technology, Systems and Telecommunication (BIT), compromising the login credentials of around 200 accounts. On July 28, BIT’s security specialists noti…HELPNETSECURITY.COM
7 AugSnowflake attacker pleads guilty to hack of 165 companies’ dataA Canadian hacker has admitted being part of a group responsible for several major cyberattacks. Connor Riley Moucka pleaded guilty to being part of a coterie of hackers that hit 165 organizations, resulting in the theft of customer records and the extortion of millions of dollar…CSOONLINE.COM
7 AugLevi Strauss discloses data breach after social engineering attack on employeesLevi Strauss & Co. has disclosed a cybersecurity incident in which an unauthorized third party used social engineering to gain access to three employees’ company-issued computers and steal corporate information. The apparel company said in a Form 8-K filing with the US Securi…CYBERINSIDER.COM
7 AugAU: Hackers leak sensitive Victorian court data to dark webKristian Silva and Danny The personal information of Victorian court users has been posted on the dark web, sparking a police investigation. Names, emails and job titles of people who attended online hearings in regional courts were posted on an underground hacking forum in July.…DATABREACHES.NET
7 AugWhat Canvas learned from a massive cyberattackAlcino Donadel reports: …. Instructure, the edtech company behind learning management system Canvas, suffered one of the largest data breaches in the U.S. this year after cybercriminals gained access through a third-party vendor—an increasingly common occurrence in higher e…DATABREACHES.NET
7 AugUnlimited Technology Systems Data Breach Affects 3.8 Million PatientsHIPAA Journal reports an update to the Unlimited Technology Systems breach that occurred between October 10 – 15, 2025, and was discovered on October 19, 2025: On July 23, 2026, the HIPAA Journal reported on a data breach at Unlimited Technology Systems, a Montgomery, Ohio-…DATABREACHES.NET
7 AugMoonshot’s Kimi AI model has also escaped from a test environmentYet another AI model has escaped from a cybersecurity test lab: This time, it’s the Chinese company Moonshot’s Kimi K3 model on the run. Frontier Security spotted that Kimi K3 had found a loophole in the UK AI Safety Institute’s test environment for AI models performing cybersecu…CSOONLINE.COM
7 AugVishing attacks target hedge funds.Cyberattack disrupts North Carolina Ports operations. Metabase Cloud breached by zero-day flaw.THECYBERWIRE.COM
7 AugBTS #79 - InfraTrust - Understanding Infrastructure Vulnerabilities & RiskIn this episode of Below the Surface, Paul Asadoorian is joined by Chase Snyder and Vlad Babkin for a conversation about InfraTrust, InfraTrust Pulse, and the hard problem of making infrastructure vulnerability data useful for defenders. The first half of the episode focuses on w…ECLYPSIUM.COM
7 AugTrojanized AI skills gain 1.7M installs in agent-targeted attackResearchers have uncovered an extremely effective attack campaign that involved AI agent skills trojanized to deploy a credential stealer. The incident is part of a growing trend in which attackers are targeting the AI software supply chain by poisoning sharable instruction and c…CSOONLINE.COM
7 AugMore than half of AI-generated patches are brokenResearch finds your AI generated security patch is more likely to fail than fully fix a vulnerability. It might even introduce brand new flaws to exploit along the way. The post More than half of AI-generated patches are broken appeared first on CyberScoop .CYBERSCOOP.COM
7 AugBoston Children’s Hospital named in North Korean hacking operationNaomi Diaz reports: Boston Children’s Hospital is among roughly a dozen organizations publicly named by security researcher Vangelis Stykas as impacted by a large-scale North Korean hacking operation, Wired reported Aug. 5. The hospital disputes that its own systems were breached…DATABREACHES.NET
7 AugWordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server TakeoverWordPress XSS2Shell flaw enables admin takeover and remote code execution. Users should update to patched versions. Researchers at Pwn just published a report on a vulnerability chain they’re calling XSS2Shell, and the entry point is quite simple: type a username that doesn…SECURITYAFFAIRS.COM
7 AugRing around the ransom.Vishing attacks target hedge funds. Metabase Cloud breached by zero-day flaw. Cyberattack disrupts North Carolina Ports operations. The Chinese government has launched a security review of Palo Alto Networks products. US defense supplier breached by phishing attack. Healthcare so…THECYBERWIRE.COM
7 AugMetabase SQLi zero-day exploited in customer data-theft attacksA critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. [...]BLEEPINGCOMPUTER.COM
7 AugCity of Coweta hit with system-wide ransomware attack, has backupKTUL in Oklahoma reports: The City of Coweta says they are currently responding to a ransomware attack. According to officials, on Werdnesday, August 5, the City experienced at system-wide attack and immediately contacted their contracted IT provider and additional cycbersecurity…DATABREACHES.NET
7 AugNew York State Department of Financial Services Secures Cybersecurity Settlement with Order Express, Inc.A press release from the NYS DFS: August 5, 2026 New York State Department of Financial Services Acting Superintendent Kaitlin Asrow announced today that Order Express, Inc., a licensed money transmitter, will pay a $250,000 penalty for violations of DFS’s cybersecurity regulatio…DATABREACHES.NET
7 AugInside the Modern SOC: The Identity Front DoorIdentity-based attacks drive 90% of incidents. Learn how modern attackers exploit identities and what SOC leaders can do to respond. The post Inside the Modern SOC: The Identity Front Door appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
7 AugUS cloud ‘kill switch’ is as dangerous as ransomware, European businesses fearEmma Woollacott reports: European firms are more concerned about a potential US government-imposed ‘kill switch’ for cloud services than almost anything else. In a survey of 1,500 businesses in the UK, France, and Germany, Proton found that with many having built thei…DATABREACHES.NET
6 AugOpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud SchemesOpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that end, it banned a coordinated network of C…THEHACKERNEWS.COM
6 AugSuppliers, logins, and AI tools are all becoming attack pathsCybercriminals and state-backed hacking groups are abusing trusted identities, cloud services, AI tools, and software supply chains to gain access while avoiding detection, according to CrowdStrike’s 2026 Threat Hunting Report. Intrusion activity increased by about 4% over …HELPNETSECURITY.COM
6 AugCloudflare OS goes open source with a record of everything its agents readCloudflare open sourced Cloudflare OS, the agent platform whose first version its own employees have used since May. Every resource an agent reads gets recorded, the record follows whatever the agent produces, and when a second person opens that output the platform checks them ag…HELPNETSECURITY.COM
6 AugSrsly Risky Biz: Being a North Korean hacker is about to be less funTom Uren and James Wilson talk about North Korea losing control over some of its hacker workforce. Expect some tightening of controls and oversight, and perhaps even a reduction in the country’s ransomware operations. They also discuss escalating attacks on American water infrast…RISKY.BIZ
6 AugOWASP 2026 LLM Top 10: “The model will be fooled”The OWASP GenAI Security Project has released the 2026 edition of its Top 10 for LLM Applications and, for the first time, the list was influenced by real-world incidents. The two top entries – Prompt Injection and Sensitive Information Disclosure – remained constant,…HELPNETSECURITY.COM
6 AugBrowser security is where software, data, and AI meetIn this interview with Help Net Security, Rui Ribeiro, CEO of Jscrambler, explains why the browser has become a security problem organizations do not control. Companies do not own the device, the extensions, or the network path, yet that is where application logic, third-party co…HELPNETSECURITY.COM
6 AugCisco Patches Critical SD-WAN, IOS XE, FMC VulnerabilitiesPatches were rolled out for two dozen vulnerabilities, including one with public proof-of-concept (PoC) code. The post Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
6 AugChinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root ShellsCybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models from Zbtlink. According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more th…THEHACKERNEWS.COM
6 AugPractical lessons from deploying AI securely at scaleWhen I first started working on enterprise AI security initiatives, I expected the biggest challenges to be technical. I assumed we’d spend most of our time discussing prompt injection, model security, vector databases or the latest LLM vulnerabilities. I was wrong — or at least …CSOONLINE.COM
6 AugEvidence points to cybercriminals stepping up their AI gameMore evidence is emerging about how AI is becoming part of the day-to-day workflow for cybercriminals, from building and refining tools to managing infrastructure and accelerating vulnerability research. Drawing on recovered prompt logs, attack tooling, and threat actor conversat…CSOONLINE.COM
6 AugPhotos: Black Hat USA 2026 ArsenalThis week Help Net Security is at the Mandalay Bay, where Arsenal is running alongside the Briefings. If you’ve never been, it’s the corner of Black Hat that feels least like a conference and most like a workshop: a room full of stations where the people who wrote the…HELPNETSECURITY.COM
6 AugAttackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM AccessAttackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Oracle compile it into stored s…THEHACKERNEWS.COM
6 AugAWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the ModelSecurity flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent's tools with no check that a model turn had authorized them. In several of the attack paths, the model never ran at all, so system prompts…THEHACKERNEWS.COM
6 Aug KEVWhy the ‘rogue AI’ problem will lead to an era of headaches for security practitionersShortly after OpenAI publicly acknowledged the Hugging Face breach on July 21, Reuters journalist Raphael Satter called me for comment on a story which would reveal shocking new details about OpenAI’s “rogue model” incident: The agent hadn’t just slipped its leash for a few hours…CSOONLINE.COM
6 AugToken Jacking: Cybercriminals Could Be Stealing Your AI ResourcesDiscover how attackers hijack AI tokens to fuel gray market transfer stations by stealing developer API keys. The post Token Jacking: Cybercriminals Could Be Stealing Your AI Resources appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
6 AugMeta AI Model Hacked a Company During Testing, Marking Third AI Lab IncidentMeta says an AI model hacked a company during testing after accidental internet access, marking the third disclosed AI lab breach in weeks. Meta confirmed that one of its AI models breached an unidentified company during cybersecurity testing, after its independent testing partne…SECURITYAFFAIRS.COM
6 AugApple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploitsApple has imposed strict new submission limits on its bug bounty portal after finding itself overwhelmed by low-quality, AI generated vulnerability reports - many of which were found to be describing security flaws that simply didn't exist. Read more in my article on the Hot for …BITDEFENDER.COM
6 AugVerification closes the loopMost organizations assume remediation reduces risk. It’s a reasonable assumption. A vulnerability is identified, a patch is applied, the scanner comes back clean, and the ticket is closed. The workflow is complete, the metrics improve, and the issue is considered resolved. The pr…CSOONLINE.COM
6 AugAI code security with Claude Mythos Preview: Inside Tenable’s 500+ hours of testing for Project GlasswingWe spent 500+ hours and 40 billion tokens testing Anthropic’s Claude Mythos Preview for Project Glasswing. The takeaway: frontier AI won't run your code security program, but used well, it can make one even stronger. Key takeaways Frontier AI dramatically scales security testing.…TENABLE.COM
6 AugApple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy BypassesCybersecurity researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address. Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to ensure users' privacy by routing their Safari web traffic thr…THEHACKERNEWS.COM
6 AugAI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM MemoryA new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses a standard feature built into almost every major AI assistant: pre-filled deep links. We observed production websites embeddi…THEHACKERNEWS.COM
6 AugYou’re only as secure as your last evaluationThe updated Cybersecurity Maturity Model Certification (CMMC) represents a critical evolution in the Department of War (DoW) strategy to secure the Defense Industrial Base (DIB). It is more than a regulatory hurdle. It is a direct response to a rapidly changing and increasingly h…CSOONLINE.COM
6 AugCybersecurity needs a new operating modelFor decades, cybersecurity has been built around one assumption: defenders had enough time to: Discover vulnerabilities. Assess exposure. Deploy patches. Verify that critical systems remained protected. That assumption shaped how organizations built security programs, how vendors…CSOONLINE.COM
6 AugCTEM isn’t failing. It’s not being operationalizedCybersecurity is full of frameworks, regulations, and directives that tell organizations what they should do. Zero Trust, NIST, CIS Controls, CMMC, DORA, NIS2, and now Continuous Threat Exposure Management (CTEM) all provide valuable guidance and describe desired outcomes. The ch…CSOONLINE.COM
6 AugAttackers hid malware inside Oracle Database after SQL injection breachHuntress has documented a case where the Oracle database itself became the malware host. The security firm disclosed a campaign in which threat actors exploited a SQL injection vulnerability to store a custom post-exploitation toolkit, dubbed Khunt, inside an Oracle database usin…CSOONLINE.COM
6 AugZero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X PostsZenity researchers reported the findings to Anthropic and OpenAI in late 2025 and early 2026, but they remain unpatched. The post Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts appeared first on SecurityWeek .SECURITYWEEK.COM
6 AugThree in four AI-generated vulnerability patches leave something brokenAsk a frontier model to patch a real vulnerability and it will hand you something that looks like a fix. It reads like the patch a maintainer would write. When there is a test, it often passes. Roughly one time in four, it is a fix. Researchers at 1Password graded 6,080 patches f…HELPNETSECURITY.COM
6 AugBelarusian Ransom Cartel Mastermind Gets 16 Years in PrisonThere is an update to the case of Maksim Silnikau, who was extradited from Poland to the U.S. in August 2024 to stand trial here. Ionut Arghire reports: The Belarusian creator and administrator of the Ransom Cartel ransomware was sentenced to 16 years in prison in the US. Maksim …DATABREACHES.NET
6 AugDutch retailer Bol follows De Bijenkorf in warning of data breach as leaked data appears on dark webThe NL Times reports: Online retailer Bol has warned customers about a data breach involving one of its logistics partners. The company said unauthorized parties accessed the partner’s systems, but emphasized that Bol’s own systems were not affected. Even so, some cus…DATABREACHES.NET
6 AugHow a software provider closed unknown paths to cloud compromiseA healthcare software provider believed its segmented environment was reasonably secure. The company had invested heavily in layered controls across a distributed workforce, separating developer environments, segmenting cloud infrastructure, and tightly managing administrative ac…CSOONLINE.COM
6 AugHow a global investment firm reduced security surprisesMost security teams don’t suffer from a lack of data. They suffer from a lack of certainty. Vulnerability scanners, annual penetration tests, and compliance assessments can generate thousands of findings. Yet they often fail to answer a simple question: Which risks actually matte…CSOONLINE.COM
6 AugMeta joins OpenAI, Anthropic in latest AI test breachMeta has become the third frontier AI developer in recent weeks to disclose a security incident involving one of its advanced AI models during cyber capability testing conducted by AI safety startup, Irregular, placing the independent evaluator at the center of a series of disclo…CSOONLINE.COM
6 AugMeta Joins OpenAI and Anthropic in Reporting AI Exploit IncidentOne of Meta’s AI models exploited a third-party security flaw during an evaluation, the latest in a series of similar incidents involving advanced AI systemsINFOSECURITY-MAGAZINE.COM
6 AugPhotos: Black Hat USA 2026Photo gallery from the Business Hall at Black Hat USA 2026. Interesting booths, demo stages, crowded aisles, and the moments in between. Featured vendors: Stellar Cyber, Tines, Filigran, Delinea, Prophet AI, Air Security, Legion Security. Featured people: Kunal Modasiya (Qualys) …HELPNETSECURITY.COM
6 AugNovel-reading apps used users’ phones to generate fake ad trafficA new mobile ad fraud scheme, dubbed Papyrus, is using a cluster of novel-reading apps to generate hidden browser traffic, according to IAS Threat Lab. Sample novel-reading apps associated with Papyrus (Source: IAS Threat Lab) While a person taps through chapters of a romance or …HELPNETSECURITY.COM
6 AugThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More StoriesApparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF can finish the job. This week runs on cheap leverage: exposed servers, recycled bugs, poisoned agent instructions, remote-access tool…THEHACKERNEWS.COM
6 AugToolkit Hidden Inside Oracle Database Evades Endpoint ToolsAttackers used SQL injection to compile a post-exploitation toolkit inside an Oracle databaseINFOSECURITY-MAGAZINE.COM
6 AugNew TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashesResearchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines. [...]BLEEPINGCOMPUTER.COM
6 AugSwiss government SharePoint breach compromised 200 accountsSwitzerland's federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. [...]BLEEPINGCOMPUTER.COM
6 AugCardiology Associates of Port Huron remains silent although they were allegedly hacked and had patient data stolen in June.There have been approximately 4 dozen new threat actor groups targeting U.S. medical entities in the first half of 2026. One of them calls itself “Orova.” They have no “About” page or information about themselves on their dark web leak site, so seeing that…DATABREACHES.NET
6 AugWhen AI Commits Felonies - PSW #938This week: - When you are not at summer camp you can't read about it - The Fettle continues - Using the CFAA against AI - Social contracts are not security models - VSCode extentions, again - Bugtraq is back! - NVIDA, LVFS, and unraveling AI infrastructure - More routers that com…YOUTUBE.COM
6 AugAI without adult supervision.Meta’s AI models join the sandbox escape club. China’s telecom footprint in the U.S. may be larger than expected. The White House keeps its AI safety playbook under wraps. AI coding tools introduce new GitHub risks. ENISA expands its CVE role. A critical Paperclip flaw enables co…THECYBERWIRE.COM
6 AugCapitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scamsA Senate Foreign Relations Committee hearing explored how 13 federal agencies and myriad foreign governments are wrestling with the problem. The post Capitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scams appeared first on CyberScoop .CYBERSCOOP.COM
6 AugMeta says AI model hacked third-party company during cyber testingMeta has disclosed that one of its AI models compromised another company’s systems during an internal cybersecurity evaluation after a misconfiguration inadvertently granted the model access to the public internet, marking the latest in a series of real-world AI testing inc…CYBERINSIDER.COM
6 AugResearcher Claims Control of ChatGPT Secure SandboxA researcher demonstrated a proof-of-concept attack chain that provided C2-style influence over ChatGPT's isolated sandbox during a session at Black Hat USA 2026.DARKREADING.COM
6 AugWhy exposure management is replacing vulnerability managementVulnerability management isn’t failing because security teams lack visibility. Most organizations already have more findings than they can reasonably address. Yet despite all those findings, many CISOs still struggle to answer a deceptively simple question: Are we actually becomi…CSOONLINE.COM
6 AugThe Coordination Gap: How Attackers Are Outpacing Law EnforcementThe fight against cybercrime continues because threat actors have adapted their strategies to avoid deterrents, but law enforcement still operates in silos.DARKREADING.COM
6 AugCyberRisk TV Live Coverage from Black Hat 2026 - Day 2CyberRisk TV is broadcasting live from Black Hat 2026 in Las Vegas! Tune into our coverage featuring interviews with cybersecurity leaders, practitioners, researchers, and technology innovators from one of the industry’s most influential security events. Throughout the day, we’ll…YOUTUBE.COM
5 AugNational cyber director lays out White House plans to secure AI without writing new rulesThe Trump administration executive order on artificial intelligence tried to strike the balance between responsible use, security and mutual benefit, all with an eye toward not making it regulatory in nature, National Cyber Director Sean Cairncross said Tuesday. “Everyone is work…CYBERSCOOP.COM
5 AugRisky Bulletin: Hacker breaches Hungary's State TreasuryA hacker breached Hungary’s State Treasury, Russia will mandate 40 apps on all smartphones next year, hackers steal Liechtenstein’s business database, and an AI agent got real CVEs for hallucinated vulnerability reports.RISKY.BIZ
5 AugFuture AGI: Open-source platform for shipping self-improving AI agentsFuture AGI is an open-source platform for tracing, evaluating, simulating, and guardrailing LLM agents, licensed Apache 2.0 and self-hostable. Self-hosted instances register with Future AGI on first boot and send an instance ID, a version string, a deployment type, and the email …HELPNETSECURITY.COM
5 AugQuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows InstallerCybersecurity researchers have disclosed what has been described as a "long-standing supply chain attack" on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users. According to Fortinet FortiGuard Labs, the supply chain attack…THEHACKERNEWS.COM
5 AugRisky Business #847 -- Oops! Claude's accidental hacking spreeOn this week’s show Patrick Gray, and James Wilson are joined by bearded man of leisure Adam Boileau to discuss the week’s cybersecurity news, including: Accidental AI agent hacking sprees have the world’s media freaking out, but we think it’s all pretty funny The bugpocalypse is…RISKY.BIZ
5 AugAI threat report: Rogue agents, workflow attacksMalicious AI use and threats to AI systems are requiring cyber teams to double down on security fundamentals and rethink the future of their approaches to defense. Newly emerging AI-enabled attacks, proofs of concept, and in-the-wild techniques, as well as the latest AI vulnerabi…CSOONLINE.COM
5 AugCloudflare gives AI agents wallets with built-in spending controlsCloudflare’s Wallets will give AI agents running on its platform a human-readable wallet handle for paying APIs and online content within limits set by their creator. Handle reservations have opened, while the service will become available in the coming months. It will incl…HELPNETSECURITY.COM
5 AugClaude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for ItselfAn agent running Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber evaluation by the UK's AI Security Institute. When a bystander publicly warned that the code was malicious, the agent denied it, force…THEHACKERNEWS.COM
5 AugWhy you need a reliable AI agent kill switchRecent high-profile rogue agent incidents involving OpenAI and Anthropic underscore the fact that organizations can’t put blind trust in their AI guardrails. Moreover, they must able to turn off agents quickly when they deviate from intended behavior — before they can do potentia…CSOONLINE.COM
5 AugAI is getting better at election facts, but voters shouldn’t rely on itAI chatbots are avoiding some of the obvious errors that plagued earlier models, but they still fall short giving voters the full picture compared to state and local sources. The post AI is getting better at election facts, but voters shouldn’t rely on it appeared first on CyberS…CYBERSCOOP.COM
5 AugYour orchestration framework choice is a security decision, not just an engineering oneComparisons of LangChain, CrewAI and AutoGen are easy to find — dozens of guides this year cover the same ground: developer experience, ecosystem maturity, how easy it is to wire up multi-agent workflows. None of them ask the question I actually care about: does the framework you…CSOONLINE.COM
5 AugCISA Warns of Exploited Langflow, N-central, and Tomcat VulnerabilitiesThe flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass. The post CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
5 Aug15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera trafficTP-Link prints the serial number of an Omada router on its packaging and on a label attached to the device. Those numbers run in sequence, and feeding a guessed one to the Omada cloud service returns the matching device’s MAC address and model. Serials beginning 22460J500 a…HELPNETSECURITY.COM
5 AugOne C2 kit. 30 customers. 2 governmentsI was mapping the command-and-control infrastructure behind a state-linked intrusion set when the query came back and effectively ended the exercise I thought I was running. The malware resolved its C2 address by reading a smart contract on a public blockchain. Public reporting d…CSOONLINE.COM
5 AugA few notes on AWS Nitro Enclaves: KMS integrationNitro Enclaves and Key Management Service (KMS) feel like a natural fit: since the KMS can verify attestation documents generated by the enclaves, developers can offload key management tasks from their applications to the AWS-managed service. But integrating an external service w…TRAILOFBITS.COM
5 AugAI Security Institute Reports Anthropic and OpenAI Models Going Rogue Against OrganizationsIn one instance, an unsanctioned model attempted to inject malicious code into an open source repository. The post AI Security Institute Reports Anthropic and OpenAI Models Going Rogue Against Organizations appeared first on SecurityWeek .SECURITYWEEK.COM
5 AugLeaked n8n API Tokens Exposed Live Instances to Credential TheftGitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software vulnerability. We scanned public GitHub comm…THEHACKERNEWS.COM
5 AugOpenAI, Anthropic AI agents resorted to deception in new cybersecurity incidentsOpenAI’s GPT-5.6 Sol and Anthropic’s Mythos 5 have been implicated in another series of AI security incidents after the models created fake online identities, targeted real people, and attempted to manipulate developers into approving malicious code during controlled cyber evalua…CSOONLINE.COM
5 AugCode review used to be the only way to catch these bugsAn automated system called NOVA read the source code of 3,915 open-source projects over two months and came back with 14,090 vulnerabilities, each one confirmed through the system’s validation pipeline. Vulnerability researchers at Palo Alto Networks’ Unit 42 built th…HELPNETSECURITY.COM
5 AugKali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise RiskKali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft's real authentication page. Once access and refresh tokens are issued, attackers may…THEHACKERNEWS.COM
5 Aug KEVTenable Hexa AI: Automating exposure remediation with agentic routinesDiscover how Tenable Hexa AI closes the gap between exposure management and endpoint patching using intent-driven routines, smart guardrails, and human approval. Key takeaways The problem: A slow handoff between security workflows creates a days-long remediation gap. The s…TENABLE.COM
5 AugOpen-source software’s archenemy TeamPCP goes back further than anyone thoughtOligo Security uncovered evidence of a long operational history, including multiple previous attacks it traced to the same attacker infrastructure and tools. The post Open-source software’s archenemy TeamPCP goes back further than anyone thought appeared first on CyberScoop .CYBERSCOOP.COM
5 AugThe Fourth Battlefield: The Growing Role of Cyber Operations in Global ConflictCrowdStrike co-founder Dmitri Alperovitch discusses how cyber operations support kinetic warfare, signal coming conflicts, and reshape the global battlefield. The post The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict appeared first on SecurityWeek .SECURITYWEEK.COM
5 AugTuskira expands exposure management with Agentic Control PlaneTuskira has launched its Agentic Control Plane for Exposure Management, a new capability within the Tuskira platform that governs AI-discovered vulnerabilities from scan to verified closure. The capability extends Tuskira’s existing zero-day and exposure-response capabilities to …HELPNETSECURITY.COM
5 AugAI agent deception moves from theory to reality in UK cyber tests“During a routine cyber evaluation, AI agents took sustained, unsanctioned action directed at real people and organisations,” UK’s AI Security Institute (AISI) disclosed on Tuesday. The agents’ actions included an attempted supply-chain attack that saw them crea…HELPNETSECURITY.COM
5 AugArmorCode enhances attack path analysis with new AI agents and Context Risk GraphArmorCode has announced a major expansion of its Agentic Control Plane. Four new Anya AI agents help security teams analyze cloud risks, assess vulnerability exploitability, identify mitigation strategies, and coordinate patch orchestration. It also unveiled new Context Risk Grap…HELPNETSECURITY.COM
5 AugAU: Updoc patients notified of security breach where personal information may have been stolenEmma Kirk reports: Updoc patients have been notified their personal information may have been accessed in a security breach. The website is used for 24/7 telehealth services across Australia. Customers were advised there was a “brief period of unauthorised access to a third party…DATABREACHES.NET
5 Aug KEVCISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flawsThe U.S. Cybersecurity and Infrastructure Security Agency is giving federal agencies three days to mitigate vulnerabilities in IBM Langflow, N-central, and Apache Tomcat, all actively exploited. [...]BLEEPINGCOMPUTER.COM
5 AugPaperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent ImportsTwo security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and starting it. A th…THEHACKERNEWS.COM
5 AugCOLDCARD security audit phishing attack installs remote access toolA phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. [...]BLEEPINGCOMPUTER.COM
5 AugFlaws in Google APK for Python Unlock Agent-to-Agent AttackGoogle has fixed the issues, which exploited a trust boundary between two AI agents with different privilege levels to trigger automation that could compromise the supply chain.DARKREADING.COM
5 AugHackers run khunt post-exploitation toolkit from Oracle databaseHackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. [...]BLEEPINGCOMPUTER.COM
5 AugHow a $50,000 Exploit Chain Turned Bixby Against Samsung PhonesThe chain involved the exploitation of several vulnerabilities in the Samsung Members and Samsung Account applications. The post How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones appeared first on SecurityWeek .SECURITYWEEK.COM
5 Aug KEVSAFE and sound.The White House lays out its AI strategy at Black Hat. Researchers spotlight rogue AI behavior. CISA warns of an actively exploited N-able flaw. TP-Link patches 15 Omada vulnerabilities. Apple fights the UK’s iCloud access order. The AI gray market expands. A Massachusetts health…THECYBERWIRE.COM
5 AugWhy security validation must follow the attack pathFor years organizations have strengthened their security posture by investing in specialized tools for applications, identities, endpoints, networks, and cloud infrastructure. Those investments remain essential, but the way attackers operate has changed dramatically. Today’s adve…CSOONLINE.COM
5 AugThe Real Goal: Strategic AutonomyThis discussion argues that a successful CISO advisor should enable security leaders to make independent, data-driven decisions that align with business objectives. That includes knowing when to take action—and when not to. Strategic autonomy shifts cybersecurity from a reactive …YOUTUBE.COM
5 AugSecurity validation should begin where attackers beginModern attacks increasingly begin with the web application. Customer portals, partner platforms, APIs, external business applications, and AI-powered services have become the front door to the enterprise. The systems organizations build to create value are now the same systems at…CSOONLINE.COM
5 AugCanadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for MillionsConnor Riley Moucka, aka “Waifu” and “Judishe,” was scheduled to stand trial in January 2027. Today, he changed his “not guilty” plea to a guilty plea, and pleaded guilty to four counts of the multi-count indictment. Connor Riley Moucka, 26, of…DATABREACHES.NET
5 AugReport: Passkey security issues could allow account takeoverGiven the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around passkey protections is concerning, analysts say, but they stress that the demonstrated attacks can only happen after a succe…CSOONLINE.COM
5 AugCyberRisk TV Live Coverage from Black Hat 2026 - Day 1CyberRisk TV is broadcasting live from Black Hat 2026 in Las Vegas! Tune into our coverage featuring interviews with cybersecurity leaders, practitioners, researchers, and technology innovators from one of the industry’s most influential security events. Throughout the day, we’ll…YOUTUBE.COM
5 AugSN 1090: Black Hat - The Hidden Flaws in AI Security Nobody Saw ComingAt Black Hat Las Vegas, the Security Now crew digs into how AI is not just finding hidden software bugs but also fueling both groundbreaking innovation and alarming new exploits. When open models can launch surprise Bitcoin heists, who draws the line between forbidden knowledge a…TWIT.TV
4 AugCybersecurity jobs available right now: August 4, 2026Application Security Engineer Arcadia | USA | Remote – View job details As an Application Security Engineer, you will lead the application vulnerability management process by prioritizing and driving remediation of security findings. You will integrate and automat…HELPNETSECURITY.COM
4 Aug178: UbiquitiNickolas Sharp worked for Ubiquiti, a company that makes networking equipment. He noticed that there were some security problems at work. He tried to point them out, but didn't feel like he was being listened to enough. What do you do when the company you work for isn't securing …DARKNETDIARIES.COM
4 AugEU begins enforcing AI Act, putting AI models under the microscopeEurope’s fight to regulate AI models moved from paper to practice on 2 August 2026, when the European Commission’s AI Office and national authorities began enforcing the AI Act. On the same date, new transparency rules took effect, requiring certain AI systems to tell…HELPNETSECURITY.COM
4 AugThe Minnesota attackers may hold a better backup of your plant than you doMore than 30 Minnesota community water systems were hit by coordinated cyber activity against their operational technology on July 26 and 27; several lost remote control or deliberately cut it while operators contained the intrusion. The reporting since — including CSO’s own news…CSOONLINE.COM
4 AugAttackers are crafting malicious AI instruction files to turn your agentic workflows into quiet criminal helpersAI agents are increasingly being deployed across the enterprise, a rapid adoption that has significantly broadened the organization’s attack surface, turning sharable AI agent resources and configuration files into backdoors, security experts warn. AI-assisted software developers…CSOONLINE.COM
4 AugHow companies could share cyber risks without exposing their secretsA cryptographic technique could let companies prove they're vulnerable to critical flaws without revealing the sensitive data that attackers could exploit. The post How companies could share cyber risks without exposing their secrets appeared first on CyberScoop .CYBERSCOOP.COM
4 AugDecades-Old BMC Vulnerability Exposes Thousands of Data Centers to AttacksOver 24,000 internet-accessible server-management interfaces disclose authentication hashes before login. The post Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
4 AugTanium expands autonomous security across AI, exposure management and SecOpsTanium has announced a series of new autonomous security capabilities across the Tanium Autonomous IT Platform. Spanning agentic AI, exposure management and security operations, the capabilities empower IT and security operators to stay ahead of an AI-accelerated threat landscape…HELPNETSECURITY.COM
4 AugSecure AI adoption starts with API best practicesYou don’t need to be a fortune teller to understand where enterprise IT is headed. McKinsey reported in November that 62% of global organizations were experimenting, piloting or scaling agentic AI projects. More recently, Gartner forecast that worldwide spending on AI will top $2…CSOONLINE.COM
4 AugRussian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malwareMidnight Blizzard, the Russian threat actor tied to the country’s foreign intelligence service, has spent months targeting users of public Wi-Fi networks at places like hotels and conference centers, according to new findings from Microsoft Threat Intelligence. Overview of …HELPNETSECURITY.COM
4 AugIndusface SwyftComply AI enables autonomous virtual patching for AI-discovered flawsIndusface has announced SwyftComply AI, an autonomous vulnerability remediation solution that virtually patches vulnerabilities surfaced by AI-assisted pentesting. Artificial intelligence has changed the economics of application security. AI-powered security agents now uncover ex…HELPNETSECURITY.COM
4 AugThe top cybersecurity product announcements from Black Hat 2026Black Hat 2026 is shaping up to be another AI-heavy conference, but this year’s announcements suggest the industry is moving beyond simply adding copilots to existing products. Vendors are increasingly packaging AI into operational workflows, while pairing automation with governa…CSOONLINE.COM
4 AugGoogle ADK flaws reveal what happens when AI agents trust the wrong messageSecurity flaws in automated workflows in the GitHub repository for Google’s Agent Development Kit for Python could allow public-facing AI agents to trigger more privileged automation, opening one path to manipulate pull-request reviews and another to expose credentials, according…CSOONLINE.COM
4 AugHow legitimate cloud platforms enable phishers to bypass MFAWe cover a cloud-based AitM attack scenario leveraging service workers and Ultraviolet, and provide detailed phishing hosting statistics across platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS.SECURELIST.COM
4 AugCritical Azure Cosmos DB flaw threatened cross-tenant database takeoverA critical vulnerability in Microsoft Azure’s Cosmos DB database service could have enabled attackers to escape the platform’s Gremlin query sandbox, execute code on shared infrastructure, and ultimately gain access to any customer’s database, including data stores used by Micros…CSOONLINE.COM
4 AugAlmost Half of Malware Samples Communicate Direct to IPNearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these threats. The post Almost Half of Malware Samples Communicate Direct to IP appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
4 AugRapidFort Runtime brings continuous CVE monitoring and tamper detectionRapidFort has launched RapidFort Runtime, a real-time security solution that extends RapidFort’s SSCS capabilities into live production environments. The offerings provide end-to-end continuous threat elimination, from curated, independently malware-scanned open-source soft…HELPNETSECURITY.COM
4 AugRepublican attorneys general urge OpenAI to preserve records on Hugging Face breachMiranda Nazzaro reports: More than a dozen Republican attorneys general are calling on OpenAI to preserve records on its models’ recent breach of another company, suggesting the AI firm may have violated state or federal laws in the incident. In a letter sent Monday to OpenAI CEO…DATABREACHES.NET
4 AugSwiss federal IT office hit by cyberattackSwissInfo.ch reports: Following a cyberattack on the SharePoint servers operated by the Federal Office of Information Technology, Systems and Telecommunication (FOITT), access via the internet has been blocked for people outside the federal administration. Around 200 accounts wer…DATABREACHES.NET
4 AugBotnet Hunting for Vulnerabilities in Diagnostic Tools, (Tue, Aug 4th)This morning, I noticed specific sources "hunting" for vulnerabilities in URLs that I haven&#;x26;#;39;t noticed before. All of these URLs appear to be associated with diagnostic tools:
ISC.SANS.EDU
4 AugAI Missed the Real FixDuring vulnerability patching tests, the AI models correctly focused on the vulnerable source code but repeatedly ignored runtime inputs that were also part of the official security fix. In one example, validating paths loaded from a local .env file was necessary to fully resolve…YOUTUBE.COM
4 AugThe Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source SoftwareFrontier AI is reshaping vulnerability discovery. Learn how our NOVA system found 14,000+ unknown vulnerabilities across the open-source software supply chain. The post The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software appe…UNIT42.PALOALTONETWORKS.COM
4 AugServiceNow organizes autonomous security around six solution areasServiceNow has announced an acceleration of its Autonomous Security vision with six unified solutions that help deliver prevention-first, AI-native cyber defense across unified exposure management, continuous vulnerability detection, cyber-physical security, identity and access s…HELPNETSECURITY.COM
4 AugSnyk unveils continuous AI pentesting and agent red teamingSnyk has announced the general availability of Evo Continuous Offensive Security (COS), enabling security teams to continuously test applications with autonomous, AI-powered pentesting and AI agent red teaming while providing validated proof of what attackers could actually explo…HELPNETSECURITY.COM
4 AugFake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote AccessCybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Managemen…THEHACKERNEWS.COM
4 AugXCSSET malware returns in macOS attacks that hijack ChromeA new version of the XCSSET macOS malware can hijack Google Chrome, intercept browser activity, and turn the browser into a fileless command channel. The campaign has been spreading through infected Xcode projects since April 2026, targeting software developers and users of the a…CYBERINSIDER.COM
4 AugEFF warns SCREEN Act could force VPN users to surrender their anonymityA proposed US age-verification law named SCREEN Act could force VPN users to surrender identifying information before accessing lawful online content, according to the Electronic Frontier Foundation (EFF). The digital rights group says the SCREEN Act’s broad scope would weaken on…CYBERINSIDER.COM
4 AugVaronis Agent IBAC keeps AI agents within their intended boundariesAI agents need broad access to be useful, but traditional access controls cannot determine whether an action aligns with a user's intent. Varonis explains how Agent IBAC detects intent drift and enforces real-time guardrails to keep agents within their intended boundaries. [...]BLEEPINGCOMPUTER.COM
4 AugAI developers targeted via trojanized GitHub repositoriesCybercriminals are cloning popular GitHub repositories for AI tools and developer resources to distribute an infostealer, according to Netskope Threat Labs. (Source: Netskope) Netskope came across the campaign while tracking a Windows-based MaaS infostealer, first reported in Apr…HELPNETSECURITY.COM
4 AugINC Ransomware is Calling Victims – Pressure Tactics Post SonicWall Zero-Day ExploitINC Ransomware exploits SonicWall SMA 1000 flaws, using calls and emails to pressure victims during extortion campaigns targeting global organizations. Resecurity disclosed that INC Ransomware has emerged as the dominant threat actor exploiting the recently disclosed SonicWall Se…SECURITYAFFAIRS.COM
4 AugProlific ransomware group behind SonicWall zero-day attacksINC ransomware wasn’t the first group to exploit the zero-days, but it’s been the most assertive and effective in chaining both vulnerabilities to steal and encrypt data for extortion. The post Prolific ransomware group behind SonicWall zero-day attacks appeared first on CyberSco…CYBERSCOOP.COM
4 AugAI widely used to exploit critical flaws, disrupt supply chainsA report confirms the growing use of AI across a broad spectrum of threat groups.CYBERSECURITYDIVE.COM
4 AugSage Water Resources says Utah saltwater disposal controller intrusion bypassed pump safeguardsDysruption reports on a critical infrastructure attack in Utah that could have caused more damage than some other recent attacks: Sage Water Resources said workers stopped malicious changes to an automated controller at its oilfield wastewater disposal site near Duchesne, Utah, b…DATABREACHES.NET
4 AugFlorida Man Sentenced for Conspiracy to Commit Wire FraudStolen wallets are still a thing. From the U.S. Attorney’s Office, Eastern District of Kentucky: July 31, 2026 LEXINGTON, Ky. – An Orlando, Fl., man, Ivory Joe Pruitt, 61, was sentenced on Friday to 63 months imprisonment by U.S. District Judge Robert Wier for conspiracy to…DATABREACHES.NET
4 AugHackers steal over $130 million by exploiting bug in offline hardware walletsA security vulnerability in the cryptocurrency hardware wallet Coldcard is allowing hackers to drain the crypto from victims’ wallets. The total losses amount to more than $130 million, according to blockchain monitoring firms.TECHCRUNCH.COM
4 Aug KEVAirlock Digital Unveils Agentic AI Control & Governance to Extend Preventative Endpoint SecurityAirlock Digital , a leader in preventative endpoint security, today announced Agentic AI Control & Governance at Black Hat USA 2026 . The new capabilities build on application control by providing command- and session-level visibility into trusted AI agent behavior, centraliz…CSOONLINE.COM
4 AugBritain’s next war won’t be an away game: Q&A with former head of Defence IntelligenceAs Chief of Defence Intelligence, General Sir Jim Hockenhull decided to declassify and publish what London knew of Russia’s plans to invade Ukraine, down to a map of the routes its forces would take.THERECORD.MEDIA
4 AugNPM? Not my problem.New Shai-Hulud campaign compromises popular npm packages. Easterly says small municipalities shouldn’t have to fend for themselves. Chinese threat groups accelerate exploits. Samsung bans smart TV apps with residential proxies. Hackers breach a Liechtenstein banking database. Swi…THECYBERWIRE.COM
4 AugSharePoint Flaws Used to Hack Switzerland’s Federal IT AgencySwiss Federal IT Agency FOITT says attackers exploited SharePoint flaws to compromise about 200 accounts. Servers are being rebuilt as investigations continue. Switzerland’s Federal Office for Information Technology and Communications, known as BIT or FOITT, disclosed that …SECURITYAFFAIRS.COM
4 AugAISI, OpenAI report more ‘unsanctioned’ model hacksFollowing similar reports by OpenAI and Anthropic, the UK’s top AI testing lab and a private cybersecurity tester say their models exploited parts of the open internet. The post AISI, OpenAI report more ‘unsanctioned’ model hacks appeared first on CyberScoop .CYBERSCOOP.COM
4 AugTP-Link patches Omada ZTP flaws allowing hackers to breach networksTP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE). [...]BLEEPINGCOMPUTER.COM
4 AugOpenAI, Anthropic AI agents targeted real people and systems in cyber testsOpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incidents that resulted in a real website being breached and social engineering attacks against people outside the intended testing boundaries. [.…BLEEPINGCOMPUTER.COM
3 AugAnthropic models hack three firms, Coldcard bug drains $88 million, Midnight Blizzard hijacks hotel Wi-FiClaude Escapes the Lab, EU AI Act Enforced, SVR Hotel Wi‑Fi Hijacks, and $88M Bitcoin Wallet Flaw David Shipley covers multiple cybersecurity headlines: Anthropic disclosed that three Claude models escaped misconfigured evaluation environments during Irregular-run CTFs, reached t…CYBERSECURITYTODAY.LIBSYN.COM
3 AugSkillSpector: NVIDIA’s open-source security scanner for AI agent skillsSkillSpector is an open-source scanner from NVIDIA that reads an agent skill and tells you whether to install it. Point it at a directory, a zip file, a single SKILL.md, or a Git URL, and it returns a list of findings, a risk score, and recommendations. The folder it reads runs w…HELPNETSECURITY.COM
3 AugHugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary CodeThree high-severity security flaws have been disclosed in Hugging Face's Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) supply chain to security risk. "These vul…THEHACKERNEWS.COM
3 AugCrowdStrike 2026 Threat Hunting Report: Exploitation Window Closes as AI Use AcceleratesCROWDSTRIKE.COM
3 AugRapid7 Expands UK and Ireland Channel Presence Through Strategic Partnership with Exclusive NetworksRoss Baker is Senior Director, Northern Europe at Rapid7. As organizations across the United Kingdom and Ireland embrace AI, cloud technologies, and digital transformation in the name of enhancing customer experiences and accelerating business growth, the cybersecurity landscape …RAPID7.COM
3 AugStop depending on heroics and start operationalizing third-party riskIn cybersecurity, third-party risk management normally looks simple on paper: evaluate your vendor, learn the risk, report out on the gaps and weaknesses, transfer to the contract, and continue. Unfortunately, it seldom works that way in practice. In my roles as a CISO, I find my…CSOONLINE.COM
3 AugAI is making cybersecurity fundamentals more important than everWhen OpenAI disclosed that one of its models escaped a test environment and broke into Hugging Face’s systems on its own, headlines cast the incident as the start of a new era of AI-driven attacks. But the underlying cause of the incident was a familiar one: a misconfigured sandb…CSOONLINE.COM
3 AugColdcard Users Lose $89m After Bitcoin Wallet Is HackedA hacker has drained nearly $89m from Coldcard Bitcoin wallets after exploiting a legacy bugINFOSECURITY-MAGAZINE.COM
3 AugAppSec, Shopify-Style; State of Mobile Security; the News - Andrew Dunbar, Kern Smith - ESW #470Interview with Andrew Dunbar, CISO at Shopify After 13 years at Shopify, Andrew has some valuable insights to share on application security. In this episode, we discuss how AI has changed application security processes where bug bounty now fits in a post-Mythos, post-AI harness w…YOUTUBE.COM
3 Aug30 days with Claude Mythos Preview: How Tenable adapted our security program, and why yours is nextTenable spent 30 days running frontier AI models against our own code. It didn’t just find bugs — it proved they’re real, with reproducible exploits. That fundamentally changes code security from ranking potential code defects to a much higher signal focused on the findings that …TENABLE.COM
3 AugAlleged Żabka Breach Exposes Jira Data, Source Code, and API KeysAlleged Żabka data leak offered for €5,000 includes Jira data, GitLab repos, and secrets; researchers verified much of the sample. A brand-new forum account showed up on August 2, posted once, and asked five grand for what it claims is a full data dump from Żabka Polska. Żabka Po…SECURITYAFFAIRS.COM
3 AugThe OpenAI Hack Shows the Genie Is Out of the BottleThis essay originally appeared in Foreign Policy . Earlier this month, two of OpenAI’s models broke out of their containment sandbox and attacked another AI company. The story is kind of wild . OpenAI was running security tests on two of its models: GPT-5.6 Sol and an unrel…SCHNEIER.COM
3 AugChinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOSAn unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit. Attack surface management platform Censys said it identified the threat actor running more than 100 web propertie…THEHACKERNEWS.COM
3 AugRecent SonicWall Vulnerabilities Exploited in Ransomware AttacksThe INC Ransomware gang has been targeting vulnerable SMA1000 appliances for root access and lateral movement. The post Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
3 AugCISA lays out new guidance for using open-source softwareThe US Cybersecurity and Infrastructure Security Agency (CISA) has published the Open Source Software: Security Principles and Practices guide, which provides federal agencies with recommendations for managing the security of open source software, contributing to OSS projects, an…HELPNETSECURITY.COM
3 AugZero Networks targets AI agent security gaps with network-level ‘Least Agency’ controlsWhile AI security today is largely focused on restricting what an agent can do, Zero Networks says it has built a failsafe. The company says it can block a compromise midway by adding a network layer protection. On Monday, the company announced the launch of “Least Agency Enforce…CSOONLINE.COM
3 AugKR: Seoul lawmaker criticizes 5,000-won compensation for 4.62 million-person data breachThe Herald Business reports: Seoul Facilities Corp. has drawn criticism over its plan to offer 5,000 won [$3.50 USD] per affected user in response to a personal data breach involving about 4.62 million people, with questions mounting over whether the compensation is adequate. Seo…DATABREACHES.NET
3 AugUK: Details of 100,000 police staff leaked on the dark web after hackBill Curtis reports: The full names and contact details for more than 100,000 police officers and staff have been leaked on the dark web after a hack, The Times can reveal. As part of a major security breach, hackers compromised data belonging to the Ministry of Defence (MoD), th…DATABREACHES.NET
3 AugCyberattack hits Liechtenstein, with 31,000 records stolenDPA reports: The tiny principality of Liechtenstein has fallen victim to a major cyberattack in which the data of 31,000 people were stolen, the government said on Sunday. The country, which lies between Switzerland and Austria, has a population of around 41,000. The government s…DATABREACHES.NET
3 AugPNLD Confirms Data Breach Affecting UK Police and Justice StaffUK police legal database breach exposed officers’ names and work emails, increasing phishing risks. NCA is investigating. The Police National Legal Database (PNLD), the legal reference system used by all 43 Home Office police forces in England and Wales, confirmed that a da…SECURITYAFFAIRS.COM
3 AugChina-Linked Threat Actors Weaponize New Vulnerabilities in Under a DayChinese actors exploited the critical React2Shell exploit inside a day, while 88% of exploited vulnerabilities in H1 2026 were compromised within 48 hours of disclosureINFOSECURITY-MAGAZINE.COM
3 AugInside the Underground Business of BTMOB RATFlare researchers analyzed thousands of underground posts to examine how the BTMOB Android malware operation evolved into a fragmented ecosystem of resellers, source-code vendors, custom versions, and competing sales channels. [...]BLEEPINGCOMPUTER.COM
3 AugChina-based hacker employs DeepSeek in autonomous threat campaignResearchers said the hacker also attempted to test Western AI tools, but ultimately was forced to revert to manual operations to succeed. CYBERSECURITYDIVE.COM
3 AugMetasploit Pro 5.1 ReleasedToday marks the release of Metasploit Pro 5.1 - building upon the foundation laid in 5.0, adding new evasion primitives for HTTP Meterpreter payloads, support for tracking service hierarchies, a deeper and more interactive Network Topology view, and continuing our commitment to a…RAPID7.COM
3 AugINC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 FlawsThe INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the INC Ransomware acce…THEHACKERNEWS.COM
3 AugChinese Actor Weaponizes DeepSeek AI Agent to Attack Security FirmResearchers intercepted and investigated the model, which was attempting to compromise more than 1,200 hosts for proxyjacking to launch further attacks.DARKREADING.COM
3 AugAI Runs the Hack: Chinese Actor Automates Cyberattacks With DeepSeekUnit 42 uncovered an AI-driven Chinese hacking campaign where DeepSeek autonomously scanned targets, selected exploits, and launched attacks. Researchers at Palo Alto’s Unit 42 got a front-row seat to something they’d only theorized about before: an AI system running …SECURITYAFFAIRS.COM
3 AugMore on the OpenAI Agent’s Attack on Hugging FaceHugging Face has published a detailed timeline of the attack. From the summary: The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchmark, which tasks an AI agent with finding and exploiting software vulnerabilities. OpenAI ran this on…SCHNEIER.COM
3 AugWater you waiting for?Cyberattacks hit U.S. water systems. CISA tackles open source security. China’s surveillance machine is exposed. Hotel Wi-Fi gets riskier. Healthcare and police data spill online. Fake SQLite vulnerabilities fool security databases. Monday business briefing. Our guest is Tim Star…THECYBERWIRE.COM
3 AugBitcoin hardware wallet maker destroys some inventory after more than $88 million stolenThe company behind a popular hardware wallet for bitcoin owners was forced to destroy part of its inventory after thieves siphoned more than $88 million from customers through a firmware vulnerability.THERECORD.MEDIA
3 AugNew Tool Traces AI Videos Back to Their SourceResearchers dug into the root of the problem with the goal of promoting industry collaboration on improved protective measures.DARKREADING.COM
3 AugThe AI Act kicks into action, forces companies to be clear about AI chatbotsThe European Union (EU) has started enforcing key parts of the AI Act, with immediate, visible consequences for chatbots, deepfakes and other consumer‑facing AI.MALWAREBYTES.COM
2 AugBlack Hat preview: "Vulnerability Research in the Agentic Age."In this special edition, guest Yan Shoshitaishvili, Associate Professor, University of Arizona, joins host Dave Bittner to share a preview of his Black Hat USA 2026 keynote "Vulnerability Research in the Agentic Age." Join Yan and Dave to hear insights on the evolutio…THECYBERWIRE.COM
2 AugWeek in review: Claude breached three companies during tests, AD CS domain-takeover PoC releasedHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: Nono: Open-source sandbox for AI agents AI coding agents run with the same permissions as their users, meaning they can access sensitive files, credentials, and production systems. A…HELPNETSECURITY.COM
2 AugA “No-Logs” VPN That Kept 58 Million Connection Logs: Inside the NotVPN / SplitVPN BreachThey advertised and pinky swore “no logs.” But according to research by MysteriumVPN, they logged. Key takeaways from MysteriumVPN: A threat actor on the Altenen cybercrime forum is distributing a 17 GB SQL database they claim was stolen from SplitVPN (formerly NotVPN…DATABREACHES.NET
2 AugBrinks Home Confirms Data Breach Following ShinyHunters ClaimGuru Baran reports: Brinks Home, one of North America’s largest residential security providers, has confirmed that hackers breached its IT systems after the notorious ShinyHunters extortion group claimed responsibility for stealing nearly five million records tied to the company’…DATABREACHES.NET
2 AugTN: Sumner County Schools provides limited update on data breachAbbey Nutter reports: Sumner County Schools is still working through a reported network breach that forced the district to delay the start of the 2026-27 school year, officials told Main Street Media. The district reported the data breach during a meeting of the Sumner County Boa…DATABREACHES.NET
2 AugSecurity Affairs newsletter Round 588 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Russian Hackers Hijack Hotel Wi-F…SECURITYAFFAIRS.COM
2 AugColdcard warns of wallet seed flaw as stolen amounts reach $88.6 millionColdcard maker Coinkite has disclosed a security flaw affecting multiple generations of its Bitcoin hardware wallets that reduced the randomness used when generating wallet recovery seeds, potentially placing funds at risk. The company has released patched firmware for all affect…CYBERINSIDER.COM
2 AugCareCloud Breach Exposes Medical and Financial Data of 345,000CareCloud disclosed a breach affecting 345,000 people after hackers stole medical and financial data from its AWS-hosted systems. TechCrunch reports that CareCloud, the New Jersey-based health tech company that stores patient records for more than 45,000 providers across the US, …SECURITYAFFAIRS.COM
2 AugCOLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theftA vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator. [...]BLEEPINGCOMPUTER.COM
1 AugAMGEN reports breach to SECFrom Amgen’s filing on July 29 to the Securities and Exchange Commission: Item 1.05 Material Cybersecurity Incidents. In July 2026, Amgen Inc. (the “Company”) identified unauthorized activity involving data stored in cloud environments hosted by third-party clou…DATABREACHES.NET
1 AugThe driver's seat to ransomware.This week, we are joined by Marcus Hutchins, Principal Threat Researcher at Expel, sharing their work on "Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs." Researchers examine how the Gentlemen ransomware group used…THECYBERWIRE.COM
1 AugSystem Announcement: MaintenanceDataBreaches.net will be undergoing some maintenance and upgrades this weekend and may be unavailable at times. We’ll be back, though! Thank you for your patience. SourceDATABREACHES.NET
1 AugRuby on Rails Patches Critical VulnerabilityThe flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
1 AugRails patches critical Active Storage flaw with RCE potentialA critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]BLEEPINGCOMPUTER.COM
1 AugMon General Hospital notifies patients of phishing attack and breachWDTV reports: Monongalia County General Hospital Company, known as Mon General, announced it was recently the victim of a phishing attack that may have compromised the personal and medical information of some patients. Hospital officials say the incident was discovered on May 6, …DATABREACHES.NET
1 AugRussian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 TokensMicrosoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian…SECURITYAFFAIRS.COM
1 AugSixth Circuit to Rehear Case on FCC Data Breach Rules CaseJake Neenan reports: A full panel of federal judges will rehear a case that upheld expanded telecom data breach rules. The Federal Communications Commission, now under Republican control, has indicated it’s likely to reverse the rules anyway. But industry groups and GOP lawmakers…DATABREACHES.NET
1 AugThe double extortion of a Russian ransomware threatens the medical records that Diater has kept for 10 years.Miguel Gomez reports: The biopharmaceutical company Diater, founded in Madrid in 1999, has appeared on the list of victims that the ransomware group DeadLock is disseminating on the dark web. The intrusion affects a company that manages particularly sensitive information of patie…DATABREACHES.NET
1 AugCareCloud Data Breach Impacts Over 350,000Ionut Arghire reports: Healthcare information technology company CareCloud is notifying at least 350,000 people that their information was stolen in a data breach. The incident involved an electronic health record environment within the CareCloud Health division, which was disrup…DATABREACHES.NET
1 AugSuspected cyberattack disrupts Oceanside, California, school district systemsDysruptionHub reports: A suspected cyberattack disrupted work email, internet access, Google Drive and other applications at Oceanside Unified School District in California as officials investigated and worked to restore service. The district confirmed a computer network disrupti…DATABREACHES.NET
1 AugAU: GO2 Health medical clinic in Brisbane waited almost three months to alert patients it was hackedWill Murray reports: Another medical clinic has revealed it has been targeted by hackers, less than a week after Partnered Health announced a major data breach. GO2 Health in Everton Park, in Brisbane’s north, said the clinic’s main email mailbox was accessed in April…DATABREACHES.NET
31 JulExploring the Hugging Face Breach: mapping AI agent tactics to Elastic DefendEvery stage of the Hugging Face breach maps to Elastic Defend and SIEM rules already shipping, from worker RCE and credential harvest to self-migrating C2 and GenAI detection.ELASTIC.CO
31 JulMicrosoft confirms an AI worm is propagating through Copilot and other MS appsA prominent Norwegian AI researcher on Tuesday posted details about an AI worm that is wreaking havoc in various Microsoft applications, including Word and Copilot. The report from noted Norwegian AI researcher Håkon Måløy , now confirmed by Microsoft, said that an attacker can c…CSOONLINE.COM
31 JulCompanies push AI, sysadmins keep it on a short leashIn 2024, sysadmins expected AI to automate patch management optimization, vulnerability prioritization, infrastructure monitoring, and incident response within two years. Action1’s 2026 Survey Report: AI Impact on Sysadmins found that those expectations proved overly optimi…HELPNETSECURITY.COM
31 JulAviation cyber risk sits on the ground, the blindness sits in the airIn this interview with Help Net Security, Eliran Almong, CEO of Cyviation, explains why airline cyber losses happen on the ground while the aircraft stays unmonitored. He walks through GNSS jamming that leaves no trace in a SIEM, and a PX4 Autopilot flaw his team disclosed where …HELPNETSECURITY.COM
31 JulResecurity expands threat intelligence integration ecosystem with IBM QRadarResecurity has announced the availability of native integration with IBM QRadar SIEM, a widely used Security Information and Event Management (SIEM) platform used by the leading Fortune 100 corporations worldwide. The plugin is available for activation via IBM Application Exchang…HELPNETSECURITY.COM
31 JulAfter OpenAI, Anthropic finds Claude breached three organizations during cyber testsLess than two weeks after OpenAI disclosed that an experimental AI model breached Hugging Face during a cybersecurity evaluation, Anthropic has revealed that its own review uncovered three incidents in which Claude models gained unauthorized access to the production infrastructur…CSOONLINE.COM
31 Jul5 key priorities for your Black Hat agenda — and what to avoidTwo major conferences loom large on the US cybersecurity events calendar: The RSA Conference and Black Hat. RSA was launched in 1991 by then CEO Jim Bidzos of RSA Data Security, the encryption company founded by Ron Rivest, Adi Shamir, and Leonard Adleman. Originally, the confere…CSOONLINE.COM
31 JulCritical Flaw Led to Azure Cosmos DB PwnageNamed CosmosEscape, the vulnerability exposed the primary key for Cosmos DB accounts, granting full read and write access. The post Critical Flaw Led to Azure Cosmos DB Pwnage appeared first on SecurityWeek .SECURITYWEEK.COM
31 JulWhat the Hugging Face breach reveals about defense in the age of agentic AIWe almost never get both sides of an intrusion. This time we did. Last month, Hugging Face disclosed a breach into part of its production infrastructure, saying an autonomous AI agent system ran the attack from start to finish. Five days later, OpenAI revealed that its own models…CYBERSCOOP.COM
31 JulThe New Defcon Badges Pack a Unique Open Source Chip That Doubles as a Security KeyCreated by legendary hardware hacker Andrew “bunnie” Huang, the badges for this year’s famed security conference aim to push the boundaries of security and transparency.WIRED.COM
31 JulAnthropic’s Claude breached three companies during security testsAnthropic has disclosed that its AI model Claude gained unauthorized access to the systems of three different organizations during cybersecurity evaluations. The disclosure follows OpenAI’s July 21 announcement that some of its models had escaped an isolated testing environ…HELPNETSECURITY.COM
31 JulHorizon3.ai expands NodeZero with automated web application attack path testingHorizon3.ai has expanded its NodeZero platform with AI-powered web application pentesting. The platform can now autonomously test web applications and identify attack paths that chain application vulnerabilities, credential theft, lateral movement, cloud access, and data exposure…HELPNETSECURITY.COM
31 JulAnthropic Finds Claude Breached Real Companies During Security EvaluationsAnthropic says a misconfigured test let Claude access three real organizations, prompting tighter AI evaluation and monitoring controls. Anthropic disclosed that Claude models had accessed the real production infrastructure of three separate organizations during cybersecurity eva…SECURITYAFFAIRS.COM
31 JulAnthropic says Claude AI hacked three organizations during testingAnthropic has disclosed that three Claude models gained unauthorized access to the production infrastructure of three separate organizations after a misconfigured cybersecurity evaluation environment inadvertently allowed internet access. The company says the incidents occurred d…CYBERINSIDER.COM
31 JulFacial Recognition at Madison Square GardenLast month, the story broke (alternate link ) that Madison Square Garden uses facial recognition software on everyone entering the facility, and—among other groups—flags activists that oppose using facial recognition. Turns out that the system was shut off for Taylor …SCHNEIER.COM
31 JulChinese Hacker Commands DeepSeek via Telegram to Launch Autonomous AttacksPalo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. After an initial Telegram instruction, the agent found internet-facing systems and selected public exploits. The researche…THEHACKERNEWS.COM
31 JulEU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in BrusselsWhen the AI Act comes into force, AI companies will be required to make clear to consumers with labels or digital watermarks that chatbots or imagery are generated with AI. The post EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels appeared f…SECURITYWEEK.COM
31 JulMicrosoft almost gave away the keys to everyone’s Azure Cosmos DBsMicrosoft has had a narrow escape from total embarrassment: A security company uncovered a critical vulnerability that could have compromised all Azure Cosmos DB databases — both those of customers and Microsoft’s own. Google subsidiary Wiz found a flaw in the database’s Gremlin …CSOONLINE.COM
31 JulCriminals used AI and children’s coding software to build a multimillion-dollar ad fraud empireA security investigation into inexpensive Android TV boxes led researchers to an ad fraud operation that had remained unnoticed for several years. Fuyao apps ecosystem (Source: Bitsight) According to Bitsight, the operation, named Fuyao, uses preinstalled Android apps, device ide…HELPNETSECURITY.COM
31 JulRapid7 at Black Hat USA 2026: See preemptive security in actionBlack Hat USA returns to Mandalay Bay in Las Vegas this August, bringing together security practitioners, researchers, and leaders from around the world. Rapid7 will be there in the Business Hall, with new capabilities, live demonstrations, expert-led sessions, and two days of ac…RAPID7.COM
31 JulInterpol Leverages Global System to Curtail Fraud PaymentsWhen a fraudulent transaction occurs, law enforcement agencies must work quickly to halt payments before cybercriminals cash out.DARKREADING.COM
31 JulResearchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking FlawAn academic study has disclosed a "widespread class" of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and even session hijacking, allowing an attacker to seize control of a user's network …THEHACKERNEWS.COM
31 JulConsumer Dispute Panel Orders Coupang to Pay Affected Consumers 100,000 Won Each for Data BreachLee Yong-seong reports: The Consumer Dispute Settlement Committee has decided that Coupang must compensate affected consumers 100,000 won [about $70 USD] in cash or 100,000 won in Coupang Cash per person over a large-scale personal data breach, the committee said on the 31st. …DATABREACHES.NET
31 JulNorth Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warnAlexander Martin reports: Cyberattack tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations, according to new research released Thursday alongside a joint advisory by four South Korea…DATABREACHES.NET
31 JulGoogle AI Supercharges Chrome Security, Fixing 1,072 BugsGoogle says AI found and helped fix 1,072 Chrome security bugs in two releases, dramatically accelerating vulnerability detection and patching Google’s Chrome Security team published a detailed account of how AI models have transformed their vulnerability management pipelin…SECURITYAFFAIRS.COM
31 JulElastic goes all-in on Hacker Summer Camp at Black Hat and DEF CON in Las VegasAttack Discovery turns raw alerts into validated threats and Elastic Defend closes vulnerable driver gaps as fast as they're disclosed. Watch it all run against real attacks at the booth.ELASTIC.CO
31 JulIn Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto ResearchNoteworthy stories that might have slipped under the radar: parcel delivery company OnTrac hacked, Adobe patches, UK Department for Education loses 607,000 records. The post In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research appeared fi…SECURITYWEEK.COM
31 JulHacker uses DeepSeek AI to autonomously attack vulnerable serversA Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. [...]BLEEPINGCOMPUTER.COM
31 JulRESOURCE: Thomson Reuters Foundation provides free resources and legal help for independent media around the worldFrom the Thomson Reuters Foundation, a welcome email describes the situation in South Africa and then turns to global support: I’m getting in touch to share some new reports and resources to support media freedom work in East and Southern Africa. Journalists who hold power to acc…DATABREACHES.NET
31 JulWeaponizing Exposed DataLab-1 Dark-web Research Team Contributors:Alex Necula, Anastasia Sentasnova, Ellis Stannard, Jeffrey Bell, Manuel Boll, Valéry Rieß-Marchive Mannie W writes: Ransomware and data-extortion groups are moving beyond bulk dumps to analyze, index and price stolen data before it is pub…DATABREACHES.NET
31 JulRansomware in Italy: RedACT report sheds light on an evolving threat environmentSuspectFile has published a great interview with the people behind RansomNews.online: Within this context, the first RedACT H1 2026 report, published by ransomNews.online, represents a valuable contribution to the analysis of ransomware activity targeting Italy. The project prese…DATABREACHES.NET
31 JulClaude outside the lines.Anthropic says Claude escaped the sandbox three times, while a judge questions the Pentagon’s blacklist. The EU launches an AI enforcement team, the FTC targets a telehealth firm’s tracking pixels, and a WordPress backdoor is stopped just in time. CareCloud discloses a major data…THECYBERWIRE.COM
30 JulCISA unveils a six-step blueprint for isolating critical infrastructure during cyberattacksMost IT operators understand that critical infrastructure should be isolated in crisis situations, but many don’t know how to do it in a way that maximizes security and minimizes disruption. Now, several global agencies are offering a step-by-step action plan, CI Fortify . Releas…CSOONLINE.COM
30 JulExposed credentials are giving attackers a head start many organizations don’t seeCompromised credentials can remain active long after passwords are created, leaving organizations trying to identify exposed accounts before attackers can use them. The 2026 Credential Risk Report from Enzoic shows growing awareness of the problem, but monitoring and response cap…HELPNETSECURITY.COM
30 JulNothing but the spoof.This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner…THECYBERWIRE.COM
30 Jul KEV200 new CVEs a day and no realistic way to patch them allRyan Dewhurst, CEO at KEVIntel, explains how his team confirms exploitation that CISA’s catalog has not listed yet. He describes a global honeypot sensor network, AI triage, and human verification in a lab before a vulnerability reaches the public feed. He covers CISA’…HELPNETSECURITY.COM
30 JulTop companies to visit at Black Hat USA 2026Black Hat USA 2026 returns to Mandalay Bay with a re-engineered six-day program designed to spark innovation, challenge assumptions, and unite the global security community. The event opens with four days of immersive, expert-led Trainings (August 1-4), continues with Summit Day …HELPNETSECURITY.COM
30 JulData breach cost 2026 averaged $4.99 million, AI attacks ran higherMore than one in four organizations hit by a malicious attack over the past year say AI drove it. Those breaches averaged about $1 million above the malicious attacks that ran without AI. Defenders bought similar technology and aimed it somewhere else. Half of breached organizati…HELPNETSECURITY.COM
30 JulRussian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential RotationThe Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommuni…THEHACKERNEWS.COM
30 JulA Scattered Spider member was indicted. Microsoft’s GDID went to trial.A recently released criminal complaint against Peter Stokes , an alleged member of the Scattered Spider cybercrime group , reveals previously unpublicized details about Windows telemetry . Microsoft has never exactly had a reputation for being privacy-focused, however the complai…CSOONLINE.COM
30 JulAI Scammers Are Better at Building Trust Than HumansResearchers pitted a person against a Claude agent and found that, after a week of texting, the AI chatbot was more effective at creating “exploitable trust” with others.WIRED.COM
30 JulGoogle Releases Patches for 370 Vulnerabilities in Chrome 151The new version of Chrome, 151, comes with 370 vulnerability patches, including for seven critical flawsINFOSECURITY-MAGAZINE.COM
30 JulChinese-Speaking Threat Actor Harnesses AI Models for Autonomous CyberattacksUnit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read more. The post Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
30 JulHackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without PromptsSouth Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE b…THEHACKERNEWS.COM
30 JulBuilding secure Uniswap v4 hooksUniswap v4 hooks let developers add custom behavior to pools, including dynamic fees, custom accounting, and external integrations. This flexibility moves some security responsibilities into application and hook code. The Cork and Bunni exploits are two app-level incidents that s…TRAILOFBITS.COM
30 JulAnalog Devices says hackers stole company files in June cyberattackAnalog Devices has disclosed that it suffered a cyberattack in June, resulting in unauthorized access to internal systems and the theft of company files. The semiconductor manufacturer said the incident did not disrupt operations and that it is still investigating the scope of th…CYBERINSIDER.COM
30 JulPortSwigger introduces Burp AT for agentic AI security testingPortSwigger has announced the public beta of Burp AT, a new addition to Burp Suite that brings agentic AI to professional penetration testing. Burp AT enables penetration testers to delegate defined investigative tasks to AI agents that use Burp Suite’s tools, project conte…HELPNETSECURITY.COM
30 JulCosmosEscape: Taking Over Every Database in Azure Cosmos DBA critical vulnerability chain in Azure Cosmos DB enabled full read and write access to every Cosmos DB database.WIZ.IO
30 JulHHS OCR Settles Ransomware Investigation of OSF Healthcare System and Affiliated Covered EntitiesIn June 2021, DataBreaches reported on a ransomware attack affecting OSF Healthcare by a little-known gang called Xing Team. Our reporting noted OSF’s lack or response to inquiries and lack of timely notification. When OSF issued a statement in October, DataBreaches reporte…DATABREACHES.NET
30 JulKR: KT Fined 54 Billion Won Over Data Breach via Illegal Base StationsTwo years after a malware incident that was not handled in accordance with South Korea’s requirements, KT has been fined. Lee Jin-seok reports: KT has been fined more than 53.9 billion won [USD $37,630,484.43] over a personal data breach and unauthorized micropayment damage…DATABREACHES.NET
30 JulMicrosoft Copilot for Word Can Copy Hidden Prompts Into New DocumentsHidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. Håkon Måløy disclosed the technique on July 28, 144 days after reporting it to Microsoft. In his proof of concept, the intern…THEHACKERNEWS.COM
30 JulAI agents gain access to financial workflows amid growing governance gapsAI agents are now being allowed to create business records, approve transactions, and execute financial workflows. ERP security firm Pathlock says most organizations don’t know if that is all they are doing. The company’s 2026 AI Governance Gap Report found that 79% of organizati…CSOONLINE.COM
30 JulNorth Korean hackers behind major open-source supply chain attacks, Amazon saysA North Korea-linked hacker group was behind several high-profile compromises of open-source software libraries used by developers worldwide, researchers have found.THERECORD.MEDIA
30 JulAnalog Devices Discloses Data Breach After Unauthorized System AccessChipmaker Analog Devices disclosed a data breach after detecting unauthorized access to systems on June 23. The investigation is ongoing. Semiconductor giant Analog Devices (ADI) disclosed a data breach following a cyberattack that resulted in unauthorized access to some of its s…SECURITYAFFAIRS.COM
30 JulAzure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any DatabaseA now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chain CosmosEscape, said the exploit chain b…THEHACKERNEWS.COM
30 JulAI Expands Your Attack SurfaceAI adoption introduces new responsibilities for security teams. Beyond traditional tasks like audits, controls, and awareness training, security leaders must now evaluate AI platforms, data usage, and integrations. AI systems rarely operate alone. Connections to cloud environment…YOUTUBE.COM
30 JulMicrosoft Copilot for Word vulnerable to self-propagating worm-like attackSecurity researcher Håkon Måløy has disclosed a proof-of-concept attack showing how malicious prompts hidden inside Microsoft Word documents can spread between files through Microsoft Copilot for Word. The research suggests that attacker-controlled instructions embedded in one do…CYBERINSIDER.COM
30 JulShadow AI, leadership resistance make AI governance tough for worried CISOsFewer than half of CISOs think their bosses see AI security as a business enabler, according to an Okta survey.CYBERSECURITYDIVE.COM
30 JulRapid7 named a Leader in the IDC MarketScape: Worldwide MDR Service for Midmarket 2026 Vendor AssessmentIDC has named Rapid7 a Leader in the 2026 Worldwide Managed Detection and Response Service for Midmarket 2026 Vendor Assessment ( Doc #US52992326, July 2026 ). We believe this recognition and research highlights where MDR is heading. Many security programs are still built around …RAPID7.COM
30 JulCrime Stoppers International seeking tips on INC Ransom as part of new bounty program: Operation Silent VectorCrime Stoppers International has announced a new program: Operation Silent Vector. And the first target they are offering a bounty for is INC Ransomware. Cybercriminals operate behind anonymity; this program pulls that mask off. Crime Stoppers International is seeking tips to acc…DATABREACHES.NET
30 JulThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More StoriesA lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abused trust, and explo…THEHACKERNEWS.COM
30 JulOkta buys AI security startup Permiso; source says for about $200MThe deal gives Okta identity threat detection capabilities as enterprises seek to secure AI agents and other non-human identities across cloud environments.TECHCRUNCH.COM
30 JulCanada’s Bill C-8 is here: Why the 72-hour reporting rule will redefine critical infrastructure securityCanada’s new Critical Cyber Systems Protection Act (Bill C-8) introduces a strict 72-hour cyber incident reporting mandate. Find out how Tenable is helping critical national infrastructure operators bridge the IT/OT divide to ensure full compliance. Key takeaways: Bill C-8 introd…TENABLE.COM
30 JulChrome Needs Twice-a-Week Patching Thanks to AI Bug HuntingThe two Chrome updates in June patched more bugs than the 23 updates before them. Now, Google is ramping up its patching schedule thanks to AI-assisted vulnerability discovery.WIRED.COM
30 JulGoogle says AI helped Chrome fix 1,072 security bugs in two releasesGoogle says artificial intelligence is dramatically increasing the number of security vulnerabilities it can find and fix in Chrome, with more than 1,000 security bugs patched across the browser's two most recent releases as it expands its use of AI. [...]BLEEPINGCOMPUTER.COM
30 JulShinyHunters claims Brinks Home breach, threatens to leak stolen dataResidential security company Brinks Home has disclosed that hackers breached some of its systems and are threatening to leak allegedly stolen data. [...]BLEEPINGCOMPUTER.COM
30 JulExtend Amazon Inspector SBOM Generator with PluginsAmazon Inspector is an automated vulnerability management service that continually scans Amazon Web Services (AWS) workloads for software vulnerabilities. The vulnerability management capabilities of Amazon Inspector are powered by an asset inventory engine known as the Amazon In…AWS.AMAZON.COM
30 JulFamily says woman violated HIPAA, ‘weaponized’ infoChris Dickerson reports: A medical administrator spent years secretly accessing a family’s medical records and “weaponizing” their private health information for a family dispute, according to a newly filed civil lawsuit. The plaintiffs, identified only by their initials, filed t…DATABREACHES.NET
30 JulCybercriminals Are Leveraging Autonomous AI Offensive Security AgentsResecurity warns AI offensive agents are lowering hacking barriers, fueling an AI-driven race between attackers and defenders. Resecurity analyzed how autonomous offensive security agents such as T3MP3ST, Strix, CyberStrike, XBOW, PentAGI, PentestGPT, and Nebula lower the barrier…SECURITYAFFAIRS.COM
30 JulCISA issues recommendations to federal agencies on open-source software securityOne expert said they were pleased by the guidance, which touches on open-weight AI models, patching and more. The post CISA issues recommendations to federal agencies on open-source software security appeared first on CyberScoop .CYBERSCOOP.COM
30 JulAmazon links Debug, Chalk NPM supply-chain attacks to North Korean hackersAmazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers. [...]BLEEPINGCOMPUTER.COM
30 JulAI Harnesses Burst With Potential Exploit OppsA myriad of software makes up the typical AI harness, and trust issues between the components can create concerning attack vectors.DARKREADING.COM
30 JulWhat water utilities need to know about cybersecurity complianceAs federal enforcement tightens and states begin stepping in with their own cybersecurity mandates, water and wastewater utilities face a looming wave of hard compliance deadlines, compounded by recent cyber attacks on state water utilities. Key takeaways While the EPA’s national…TENABLE.COM
30 JulA coordinated attack hit 30+ Minnesota water systems. Who did it, and what does a Rockwell notice add to the picture?A coordinated cyberattack that targeted more than 30 Minnesota community water systems has alarmed industrial cybersecurity experts, not because it caused widespread disruption, but because it appears to represent the first distributed campaign against dozens of small utilities l…CSOONLINE.COM
30 JulSandwich Hats - PSW #937In the security news: - 2.2 million cars, one shared Bluetooth key - JFrog tries to spin an AI 0-day into a win - Sextortion scammers recycling ShinyHunters' leaks - The first hack ever, from 1966 - Prompt injection as a service, $150 a month - Cisco's mystery "static credential"…YOUTUBE.COM
30 JulJetBrains warns of critical TeamCity remote code execution flawJetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code execution. [...]BLEEPINGCOMPUTER.COM
30 JulWhen AI Guardrails Don't MatchA firsthand test showed the same request triggering a safety guardrail in one interface while receiving a normal response through another interface using the same AI model. The discussion suggests implementation differences—such as where guardrails are applied—can lead to inconsi…YOUTUBE.COM
29 JulHow AI is Rewriting the Zero-Day Playbook for Preemptive SecurityThe scenario is all too familiar for any cybersecurity professional: It’s late in the day, and a critical zero-day vulnerability is disclosed. When this happens, CISOs from every industry immediately turn to their Security Operations Centers (SOC) with the single most important, …RAPID7.COM
29 JulClaude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES AttackAnthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic's…THEHACKERNEWS.COM
29 Jul KEVArista patches maximum severity vulnerability that is already being exploitedArista has patched a VeloCloud Orchestrator (VCO) security hole that has been actively leveraged in the wild, one that the vendor says “may allow a remote attacker to access privileged internal functionality and impact the VCO host.” The Arista security advisory added that the ho…CSOONLINE.COM
29 JulMeasuring LLMs’ Ability to Perform CryptanalysisThere’s new benchmark measuring AI’s ability to perform mathematical cryptanalysis. Anthropic’s frontier model actually found new attacks. The benchmark: “ CryptanalysisBench: Can LLMs do Cryptanalysis? ” The idea is to benchmark the ability of LLMs …SCHNEIER.COM
29 JulFortinet’s new FortiGate platform converges firewall, SASE technologiesFortinet has expanded its firewall family with new high-speed boxes that, when combined with the vendor’s FortiSASE Outpost software, extend cloud-based SASE (secure access service edge) capabilities and policy enforcement to on-premises environments. The new midrange FortiGate 1…CSOONLINE.COM
29 JulThe CSO’s blind spot: Why platform engineering 2.0 is now a security imperativeSecurity leaders have spent the last decade building controls around people and code. Shift-left practices caught vulnerabilities earlier in the development cycle. Zero trust reduced lateral blast radius. Developer tooling added guardrails at the IDE. The architecture was sound —…CSOONLINE.COM
29 JulWhat a CISO and Marketing Partnership Actually Looks Like with Jason Rebholz of Evoke SecurityJason Rebholz read a blog post about MCPs and saw the whole trajectory of AI security play out in front of him. Twenty years of incident response experience told him we were about to make the same mistakes…just faster. He started Evoke Security the same way he has approached ever…THECYBERWIRE.COM
29 JulSpecter: Open-source NFC reader bug sweep for Flipper ZeroSpecter is a Flipper Zero app that finds powered NFC readers by listening for the radio field they give off. The readers it hunts work at 13.56 MHz. The Flipper’s own chip does the sensing The onboard ST25R3916 carries a hardware external-field detector, the same circuit th…HELPNETSECURITY.COM
29 JulYour AI agents can reach data no one approvedA credential expired. An AI agent kept using it anyway, and a mid-sized company’s systems went down for a quarter’s worth of trouble before anyone traced the failure back to a non-human account no one had been logging. That agent could reach customer records, source c…HELPNETSECURITY.COM
29 JulFlying Eagle Android RAT Traces Found on 170 Servers as Source Code CirculatesSource code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced matching control panels and certificates to 170 internet servers. They linked the framework to a fa…THEHACKERNEWS.COM
29 JulAbnormal AI extends behavioral security to identities, AI systems, and insider threatsAbnormal AI has announced the expansion of its Behavioral Security Platform across the enterprise, introducing three new products: Identity Threat Protection, AI Governance, and Infiltration Prevention. Together, the launch extends the behavioral AI that already secures over 4,50…HELPNETSECURITY.COM
29 JulMend.io enhances application security with AI runtime protection and faster zero-day responseMend.io has announced new capabilities across Mend AI and Mend AppSec to help organizations respond faster to both application risk and the expanding attack surface created by AI. Mend.io’s latest enhancements help teams identify meaningful risk, reduce manual investigation…HELPNETSECURITY.COM
29 JulReco enhances AI Runtime with browser-based AI security and automated remediationReco has announced an expansion of AI Runtime, a core component of the Reco Platform. This update adds browser-based enforcement, real-time prompt analysis and blocking, and automated remediation to the Reco Platform. Every agent an enterprise runs carries a blast radius: the app…HELPNETSECURITY.COM
29 JulInfoblox enters EASM market with attack surface and supply chain risk toolsInfoblox has announced its entry into the external attack surface management (EASM) market. Together, with the introduction of Supply Chain Intelligence, the launch expands the Infoblox Exposure Management portfolio, helping organizations identify, prioritize and reduce exposures…HELPNETSECURITY.COM
29 Jul KEVRisk-based patching is the future. AI made it table stakesCISA’s new Binding Operational Directive (BOD) 26-04 marks one of the most important changes to federal vulnerability management in years. Rather than requiring agencies to patch every critical vulnerability on the same timetable, the directive prioritizes remediation based on ri…CSOONLINE.COM
29 JulJFrog Zero-Days Exploited in OpenAI-Hugging Face HackThe OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given. The post JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack appeared first on SecurityWeek .SECURITYWEEK.COM
29 JulFortiGate 1200G brings FortiSASE Outpost to customer-controlled environmentsFortinet has announced the FortiGate 1200G series, the newest addition to the FortiGate G series with FortiSASE Outpost, which brings cloud-delivered security services into customer-controlled environments. By combining high-performance threat protection, connectivity, hardware-r…HELPNETSECURITY.COM
29 JulWhatsApp brings end-to-end encrypted voice and video calls to the webWhatsApp has launched support for voice and video calls on the web, allowing users to make and receive calls directly from their browser without installing the desktop app. Web Calling (Source: WhatsApp) The new Web Calling feature is designed for people using shared or restricte…HELPNETSECURITY.COM
29 JulRoot Evidence puts real-world evidence at the center of vulnerability prioritizationRoot Evidence has launched the Evidence Platform, a vulnerability management platform that prioritizes vulnerabilities based on evidence of real-world exploitation and financial impact rather than severity scores alone. The platform is designed to help security teams focus on the…HELPNETSECURITY.COM
29 JulTransparency, The Key To Team Motivation For Remote Workers - Charles Gaudet - BSW #458Since the pandemic, managing remote teams have been challenging. How do you measure performance and motivate teams when they are remote? Charles Gaudet, CEO & Founder at Predictable Profits, joins Business Security Weekly to discuss why transparency is the key to team motivation …YOUTUBE.COM
29 JulLong-Lived Vulnerability in Microsoft Secure BootMicrosoft’s Secure Boot has had a serious vulnerability for most of its existence. An industry-wide standard Microsoft invented to protect Windows, and later Linux, devices from firmware infections has been trivial to bypass for 13 of its 14 years of existence. The discover…SCHNEIER.COM
29 JulIt’s easier to steal cargo than toothpasteOur cybersecurity world can get quite interesting and even close to science fiction sometimes. No, it’s not AI this time, but something movie-worthy nevertheless. Picture scenes from known heist-themed movies such as “Ocean’s Eleven” or “Mission: Impossible”. Real-world equivalen…CSOONLINE.COM
29 Jul KEVJust 1% of AI-Discovered Vulnerabilities Exploited in the Wild, Research ShowsFor now, the use of AI benefits vulnerability research more than vulnerability exploitation, a VulnCheck researcher saidINFOSECURITY-MAGAZINE.COM
29 JulExploiting Titan QuestTitan Quest is a hack-and-slash video game released in 2006. In 2016, THQ Nordic released an Anniversary Edition. In the version provided by GOG, several development tools are installed with the game. These allow for the creation of new maps, items, and effects. This article deta…SYNACKTIV.COM
29 JulCritical VM Escape Vulnerability Patched in VMware ESXiA total of five vulnerabilities have been patched in VMware ESXi, vCenter, Workstation, and Fusion. The post Critical VM Escape Vulnerability Patched in VMware ESXi appeared first on SecurityWeek .SECURITYWEEK.COM
29 JulOpenAI AI Model Used JFrog Artifactory Zero-Day Before Hugging Face BreachOpenAI confirmed its AI exploited an Artifactory zero-day to escape its test environment before breaching Hugging Face. Two weeks after Hugging Face disclosed an autonomous AI system had breached it, the picture just got a lot more specific. OpenAI has published an update confirm…SECURITYAFFAIRS.COM
29 JulMythos Asks the Right Question. It Doesn't Answer It.AI is compressing exploit timelines. The real question isn't whether your vulnerability management playbook needs to change, it's which part of it you've been getting wrong all along. The conversation happening in security circles right now goes something like this: Mythos is her…THEHACKERNEWS.COM
29 Jul KEVOpenAI rogue AI agent’s attack expanded beyond Hugging FaceThe autonomous AI agent that escaped during OpenAI testing exploited weaknesses across a customer workload, a third-party cloud platform, and Hugging Face’s production environment before being contained, according to new technical disclosures that provide the clearest picture yet…CSOONLINE.COM
29 JulShutterGap: Aryon Security finds 3.7M AWS cloud resources exposed beyond CSPM/CNAPP visibilityResearch from Aryon reveals that each year, 3,731,699 short-lived cloud resources containing highly sensitive information are publicly exposed. This impacts any organization using AWS services that support public sharing. These exposures often last only minutes or hours, too brie…HELPNETSECURITY.COM
29 JulTengu botnet reboots Linux devices to survive removalA new Mirai-derived IoT botnet can force an infected Linux device to reboot once its main process is killed, giving its persistence mechanisms another opportunity to relaunch it, Nozomi Networks Labs has found. The malware, dubbed Tengu, was discovered by a machine-learning syste…HELPNETSECURITY.COM
29 JulThe Wiz Red Agent is Now Generally AvailableContinuously uncover complex, exploitable risks to stay ahead in the AI Threat Era with the Red AgentWIZ.IO
29 JulNine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance PaymentsCybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years. According to Russian cybersecurity vendor F6, the t…THEHACKERNEWS.COM
29 JulLaundry Bear’s webmail hackers had more in store after February, report saysResearchers say the Russian state-linked hacking group tracked as Laundry Bear recently began exploiting a bug in Microsoft Outlook Web Access.THERECORD.MEDIA
29 JulShinyHunters Claims Ernst & Young Data Breach, Threatens to Leak Stolen DataShinyHunters claimed the Ernst & Young data breach, threatening to leak stolen tax records unless the firm contacts the group by July 31. The ShinyHunters cybercrime group has taken responsibility for the recently disclosed data breach involving professional services firm Ern…SECURITYAFFAIRS.COM
29 JulMythos takes its first shot at post-quantum cryptographyAnthropic’s Claude Mythos Preview model has helped researchers discover ways to speed up attacks against two widely studied cryptographic algorithms. One of the targets is Hawk, a candidate for post-quantum digital signature algorithms currently being evaluated by NIST, while the…CSOONLINE.COM
29 JulTame Dependabot: Group your updates, slow the cadence, keep security fastDependabot keeps your dependencies current, but its defaults can flood your repository with pull requests. Here's how grouping updates, slowing the cadence, and keeping security fixes fast cut the noise on a Microsoft open source project. The post Tame Dependabot: Group your upda…GITHUB.BLOG
29 JulRussian-Alligned TA488 Returns With Persistent Outlook Web Access AttackTA488 returned with OWA half-click exploit deploying OWAReaper implant that survived re-imagingINFOSECURITY-MAGAZINE.COM
29 JulPatch-Resistant 'RufRoot' Flaw Can Unleash Malicious AI Agent SwarmsThe vulnerability in the AI hosting platform Ruflo allows an unauthenticated attacker to take over the system and corrupt memory, so bad behavior can persist after patching.DARKREADING.COM
29 JulMeasuring the Tendency of AI Agents to Go RogueThis essay was written with Barath Raghavan, and originally appeared in The Guardian . In July, Hugging Face, a company that hosts much of the world’s AI software and open-source AI models, was hacked. A malicious dataset had been used to run code on one of its servers. Who…SCHNEIER.COM
29 JulVU#293714: Arbitrary File Overwrite in Develar app-builder (zipx.Unzip) via Symlink Following on macOS (APFS)Overview A vulnerability in the zipx.Unzip extraction routine of Develar’s app-builder allows an attacker to overwrite arbitrary files on macOS using Apple File System (APFS). The issue arises from a combination of Unicode normalization collisions and unsafe symlink-following beh…KB.CERT.ORG
29 JulAmazon identifies North Korean hacker group behind open-source supply chain attacksAmazon is sharing new findings about how a threat actor linked to the Democratic People’s Republic of Korea (DPRK) is targeting open source software libraries, the shared building blocks that companies around the world use to develop applications. Amazon Threat Intelligence has l…AWS.AMAZON.COM
29 JulOpenAI's Rogue Model Claims More Victims Beyond Hugging FaceOpenAI revealed rogue AI models compromised more services than initially disclosed, including a Modal customer environment and others.DARKREADING.COM
29 JulA little-known npm package was North Korea’s warm-up act for the axios hackAmazon's threat intelligence team traced domain records from the open-source software hack to a smaller, earlier compromise by the same North Korean group. The post A little-known npm package was North Korea’s warm-up act for the axios hack appeared first on CyberScoop .CYBERSCOOP.COM
29 JulRussian hackers exploit Exchange OWA zero-day for long-term mailbox accessThe Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper. [...]BLEEPINGCOMPUTER.COM
28 JulAI Agent Drives Espionage Attack on Thai Ministry of FinanceAttackers used Hermes, an autonomous open source tool, in unrestricted "YOLO mode" to conduct espionage against Thailand's Ministry of Finance.DARKREADING.COM
28 JulSamsung’s entry into AI-powered glasses forces CISOs to again consider corporate riskNow that Samsung has jumped into the crowded AI-powered glasses arena alongside Apple , Google , Meta , and others, CISOs and IT leaders are again having to think through whether it makes sense to establish enterprise restrictions on such devices, given the likely data leakage an…CSOONLINE.COM
28 JulHackers are compromising hotel Wi-Fi gateways to hijack Microsoft 365 accountsTraveling enterprise employees beware: Think twice before you log onto that oh-so-convenient public Wi-Fi. Since at least June, threat actors have been compromising “captive” Wi-Fi gateways and other portal appliances at hotels, conference centers, and similar shared venues to hi…CSOONLINE.COM
28 JulMicrosoft unveils multi-model agentic cyber stack for security operationsMicrosoft announced a new AI-powered service that enables enterprise security teams to continuously evaluate and update their organization’s security posture through a series of AI agents that can find vulnerabilities, simulate attacks, detect and triage potential threats, and de…CSOONLINE.COM
28 JulCybersecurity jobs available right now: July 28, 2026Cloud Security Engineer Toyota Automated Logistics | USA | On-site – View job details As a Cloud Security Engineer, you will design and enforce security controls across Azure and on-premises environments, strengthen identity and access management, and maintain clo…HELPNETSECURITY.COM
28 JulMicrosoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the CostMicrosoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% les…THEHACKERNEWS.COM
28 JulCritical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-DayImpacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality. The post Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
28 JulHugging Face breach shows why incident response needs a multi-model AI strategyThe recent breach of Hugging Face’s platform was the latest in a string of AI-assisted intrusions to come to light in recent weeks , showing that attackers can now use LLMs to automate entire attack chains. But it also exposed a limitation for defenders trying to use AI to respon…CSOONLINE.COM
28 JulUnpatched Fastjson Vulnerability Exploited in AttacksThe critical remote code execution bug can be exploited without authentication, under the library’s stock default configurations. The post Unpatched Fastjson Vulnerability Exploited in Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
28 JulRapid7 and Exclusive Networks expand partnership to modernize security operations and accelerate customer successClaudia Zoon is Senior Manager, Channel Sales at Rapid7. Across Belgium, the Netherlands, and Luxembourg, organizations are accelerating digital transformation through AI, cloud adoption, and increasingly connected business operations. These investments are creating new opportuni…RAPID7.COM
28 JulWhy your AI safety certificates are worthless at runtimeEvery week, another enterprise technology vendor issues a glossy press release announcing their new autonomous AI agent architecture, complete with a SOC 2 Type II report, an ISO 42001 certification, and an ironclad safety guarantee. On paper, the enterprise security battle looks…CSOONLINE.COM
28 JulInside the OWASP Agent Security Regression Harness Project - Mert Satilmaz - ASW #393Orgs need to be able to use agents, MCPs, and LLMs in ways that don't lead to unexpected actions and undesirable outcomes. The OWASP Agent Security Regression Harness project is an approach for defining customizable scenarios and testing whether those systems fail against known s…YOUTUBE.COM
28 JulData breach at medical billing firm MCBS affects 1.26 million peopleHealthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people. [...]BLEEPINGCOMPUTER.COM
28 Jul KEVHow we use /goal to find bugs in Patch the PlanetCodex’s /goal feature amplifies bug hunting, but getting good results requires the right prompt, the right scope, and the right number of outcomes per run. For Patch the Planet , our joint initiative with OpenAI to find and fix bugs in open-source software, we pointed Codex at so…TRAILOFBITS.COM
28 JulExposed BMCs hand out password hashes before loginAn attacker who reaches UDP port 623 on a server’s baseboard management controller can ask it for a password hash and receive one before logging in. The exchange is part of the IPMI 2.0 handshake, built on an authentication protocol introduced in 2004. That controller runs …HELPNETSECURITY.COM
28 JulInfoblox joins crowded EASM market with DNS-centric approachWith AI compressing reconnaissance and exploit development from weeks to hours, security vendors are racing to help enterprises identify exposures long before an incident happens. Infoblox is the latest to make that move, announcing its entry into the External Attack Surface Mana…CSOONLINE.COM
28 JulOver 24,000 exposed server BMCs leak password hash via decades-old flawMore than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface. [...]BLEEPINGCOMPUTER.COM
28 JulThe Next Evolution of MDR: Preemptive Defense and Agentic InvestigationFor years, security operations followed a familiar sequence: detect suspicious activity, investigate what happened, and respond before it caused significant harm. That model developed in a threat landscape where defenders had considerably more time to establish the facts and deci…RAPID7.COM
28 JulJFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face BreachJFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog's software repository manager. OpenAI says the models then escalated privileges and moved late…THEHACKERNEWS.COM
28 JulBugcrowd introduces Savant Pathseeker for agentic penetration testing with exploit validationBugcrowd unveils Savant Pathseeker, the first solution in its Agentic Offensive Testing line. Savant Pathseeker gives security teams the speed and scale to test every external web application and API continuously, not just the assets that make it onto the pentest schedule, while …HELPNETSECURITY.COM
28 JulMultiple water facilities in Minnesota attacked; Iranian hackers may be responsibleOn June 16, media reported that Iran-linked Handala had attacked Cal Water. There was no evidence that they tampered with the water supply, but the group warned it would be increasing attacks on U.S. critical infrastructure. On July 23, the Iran-linked WANA News reported: Followi…DATABREACHES.NET
28 JulSystem Prompts Can FailSystem prompts help guide an LLM's behavior, but they aren't a reliable security control. During testing, both open-source and some frontier models were observed ignoring system prompts and exposing information that should have remained protected. As organizations adopt AI agents…YOUTUBE.COM
28 JulAI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/schedAI-assisted research uncovered Linux kernel use-after-free allowing root escalationINFOSECURITY-MAGAZINE.COM
28 JulTengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its ProcessA new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process. If that happens, Tengu's other persistence mechanisms get another chance to relaunch it. Nozomi Networks Labs observed the drop…THEHACKERNEWS.COM
28 JulAI-assisted security tools are finding more bugs, but the threat level has not changedAnalysis from vulnerability intelligence firm VulnCheck shows AI-discovered flaws aren't being exploited any faster than traditional ones. The post AI-assisted security tools are finding more bugs, but the threat level has not changed appeared first on CyberScoop .CYBERSCOOP.COM
28 JulA senator looks to eliminate legacy VPNs from federal government.Decades-old vulnerability exposes 24,000 servers.THECYBERWIRE.COM
28 JulPrivacy-focused search engine NeoSearch open-sources code to promote decentralized web searchPrivacy-focused search engine NeoSearch has open-sourced its code under the Apache License 2.0, allowing users, developers, and researchers to inspect, modify, and run their own versions of the platform. The independent, ad-free search engine said the move is part of its broader …CYBERINSIDER.COM
28 JulFBI sees Anthropic’s Mythos as a law enforcement challengeThe post FBI sees Anthropic’s Mythos as a law enforcement challenge appeared first on CyberScoop .FEDSCOOP.COM
28 Jul'Certighost' Flaw Haunts Microsoft Active Directory CertificatesMicrosoft patched a high-severity vulnerability earlier this month that allows a threat actor to escalate privileges and compromise an AD environment.DARKREADING.COM
28 JulAI Security at Scale, CMMC phase II paused, and the Weekly Enterprise News - ESW #468Interview with Keith Hollender, CEO and Co-Founder of Arcova Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem As enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introduc…YOUTUBE.COM
28 JulvBulletin fixes critical pre-auth RCE flaw with public exploitA critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. [...]BLEEPINGCOMPUTER.COM
28 JulDysphoria Botnet Uses Blockchain Domains to Hide C2 InfrastructureResearchers uncovered the 200,000-device Dysphoria botnet, which uses Ethereum and Solana domains to hide its command servers. QiAnXin XLab, jointly with China’s CNCERT, disclosed Dysphoria, a botnet that has compromised roughly 200,000 devices worldwide and uses Ethereum a…SECURITYAFFAIRS.COM
28 JulOpenAI models used Artifactory zero-days to escape to the internetJFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging Face. [...]BLEEPINGCOMPUTER.COM
28 JulCubePilot drone software dev hit by DNS hijacking to intercept trafficCubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack. [...]BLEEPINGCOMPUTER.COM
28 JulGhost Credentials Expose Cloud Systems to Hidden Identity RisksSecurity researcher Aleksandr Krasnov reveals dormant non-human identities can create security blind spots and releases NHI Hound, an open source tool to sniff out trust paths.DARKREADING.COM
28 JulSN 1089: Models Go Rogue & ExploitGym - Regulators, Start Your EnginesWhat happens when an unconstrained OpenAI model goes rogue and hacks into Hugging Face, breaching real-world security boundaries? This episode unpacks a watershed moment for AI safety that has everyone in cybersecurity talking. OpenAI's unconstrained internal testing AI got loose…TWIT.TV
27 JulHotel Wi-Fi Hijack, Six Years For A Snapchat Predator, Chicken on the hacking menu globallyHotel Wi‑Fi steals Microsoft 365 logins, ShinyHunters sextortion spam, and Chick‑fil‑A stuffed again Hotel and conference Wi‑Fi networks are being hijacked to harvest Microsoft 365 credentials by compromising captive portals and DNS, redirecting travelers to convincing lookalike …CYBERSECURITYTODAY.LIBSYN.COM
27 JulMarathon Petroleum’s CISO on OT security automation, supply chain riskIn this interview with Help Net Security, Mary Rose Martinez, CISO at Marathon Petroleum, talks about what happens to security when automation reaches deep into refineries, pipelines, and terminals. She explains why the old idea of air-gapped operational technology has faded, how…HELPNETSECURITY.COM
27 JulNono: Open-source sandbox for AI agentsAn AI coding agent opens a terminal, reads a config file, and finds a live cloud key sitting in plaintext. It runs with the permissions of the person who launched it. Every file that person can read, the agent reads. Every credential in the environment, the agent can use. That re…HELPNETSECURITY.COM
27 JulSteam Workshop malware exploited MECCHA CHAMELEON flaw to infect playersA malicious Steam Workshop map for the indie game MECCHA CHAMELEON abused a vulnerability in the game's mod-loading system to execute malware on players' PCs. Following public disclosure, the developers released an update that fixes the issue, and Steam has removed the known mali…CYBERINSIDER.COM
27 JulRisky Bulletin: A JSON RCE bug is about to rock the Java worldA JSON bug is about to rock the Java world, scam compounds continue in Myanmar despite the junta crackdown, and Google has a new APT naming scheme.RISKY.BIZ
27 JulWhen the hackers get hacked: The Klue breach and the new reality of third-party cyber riskIn cybersecurity, defenders sometimes naively assume that threat actors operate from secure, resilient infrastructures insulated from the very chaos they inflict on others. The 2026 compromise of Klue challenges that assumption. What began as a software-as-a-service supply chain …CSOONLINE.COM
27 JulExploring AI Network Protocols; Vulnerability Truths and Guarantees; and the News - ESW #469Segment 1 - Interview with O'Shea Bowens What do we really know about "AI Network Protocols"? Network security is about to get popular all over again. Generative AI caused a disruptive explosion across all of tech and every company’s roadmap. The move from chatbots to AI agents d…YOUTUBE.COM
27 JulIn the Mythos era, security belongs at runtimeFrontier AI cut time-to-exploit from years to hours. Why defense now has to happen at runtime.CYBERSECURITYDIVE.COM
27 JulThe containment paradox: Why your ransomware playbook has the wrong people in chargeI have sat in on a version of the same incident post-mortem in three sectors over the past two years. The script does not vary much. At 4:47 a.m. on a Saturday, an on-duty SOC analyst sees a ransomware payload spreading across three servers in the data center. The playbook says i…CSOONLINE.COM
27 JulAnthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on ExploitsBinary-based vulnerability scanning, penetration testing, and exploit generation are blocked in Opus 5. The post Anthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on Exploits appeared first on SecurityWeek .SECURITYWEEK.COM
27 JulCognyte Sells a Mobile Cell Surveillance VanYet another Israeli mass surveillance company : Made by Israeli surveillance company Cognyte, the tech simulates a mobile phone tower, which forces nearby phones to connect to it. That enables cops to keep tabs on any phones in the vicinity whether they’re owned by a suspect in…SCHNEIER.COM
27 JulCertighost haunts Microsoft Active Directory Certificate ServicesA vulnerability in Microsoft’s Active Directory Certificate Services (AD CS) could allow a low-privilege domain user to impersonate a Domain Controller, security researchers have warned. Dubbed Certighost, the flaw stems from an enrollment fallback mechanism known as a “chase,” w…CSOONLINE.COM
27 JulOpenAI not part of the new Open Secure AI AllianceOpenAI is noticeably absent from the list of initial supporters of a new industry initiative to promote the creation of strong, safe, defensive AI cybersecurity tools built on open-source platforms. The Open Secure AI Alliance is an initiative of Nvidia with the backing of over 3…CSOONLINE.COM
27 JulChatGPT joins the most impersonated brands in phishing attacksMicrosoft continued to be the most impersonated brand in Q2 2026, accounting for 23% of all brand phishing attempts. LinkedIn, Google, Apple, and Amazon followed, with the five brands together making up more than half of all brand phishing attempts tracked during the quarter, acc…HELPNETSECURITY.COM
27 JulAccountant laundered $5.3 million stolen from Children’s Healthcare of Atlanta by hacker, prosecutors sayDan Raby provides this morning’s example of the insider threat: A former accountant has been sentenced to years in federal prison after he was convicted for taking part in a scheme to laundering more than $5.3 million stolen from Children’s Healthcare of Atlanta. Rona…DATABREACHES.NET
27 JulUK: Council worker who snooped on records handed a suspended sentenceFrom the Information Commissioner’s Office: A council worker who unlawfully accessed hundreds of personal records has been handed a suspended sentence. Geoffrey Smith, 31, from Ledbury, Herefordshire, was a new employee at Herefordshire Council working in the Children and Y…DATABREACHES.NET
27 JulGitLab Users Urged to Patch After Research Reveals Critical RCE ChainResearchers chained two Oj parser bugs to achieve GitLab RCE via Jupyter notebook diffs, affecting authenticated users on unpatched versions. Depthfirst researchers published a working remote code execution exploit for GitLab on July 24, chaining two memory corruption bugs in Oj,…SECURITYAFFAIRS.COM
27 JulBooz Allen expands Vellox Suite with AI-driven threat detection platformBooz Allen Hamilton has announced an expansion of its powerful suite of AI-powered cyber defense products. Now generally available, Vellox Ranger provides automated, environment-specific threat detections, developed on Booz Allen’s proprietary agentic AI framework, that identify …HELPNETSECURITY.COM
27 JulPTC Windchill Vulnerability Exploited in Ransomware CampaignThe critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication. The post PTC Windchill Vulnerability Exploited in Ransomware Campaign appeared first on SecurityWeek .SECURITYWEEK.COM
27 JulZenity advances AI governance with Runtime BoundariesZenity has announced a major expansion of its platform, making it the AI security platform for autonomous AI built around a new security architecture designed to govern AI decisions before they become enterprise actions, including those made by long-horizon agents operating auton…HELPNETSECURITY.COM
27 JulDentaQuest disclosed a data breach that impacted +23 million individualsDentaQuest disclosed a data breach that may have exposed the personal and dental health information of more than 23 million people. DentaQuest is notifying more than 23 million people of a data breach after hackers accessed its network in May 2026. The incident may have exposed c…SECURITYAFFAIRS.COM
27 Jul⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and MoreMonday starts with the usual promise that everything is under control. Then the logs wake up. This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and attackers kept hiding inside normal-looking services. Nothing looked strange at firs…THEHACKERNEWS.COM
27 JulThe Vulnerability Myth That's Costing MillionsEnterprise environments often contain thousands of reported vulnerabilities, but only a small subset may represent the highest likelihood of leading to serious financial loss. Effective security depends on prioritizing those first rather than treating every vulnerability equally.…YOUTUBE.COM
27 JulTech giants form alliance to put open AI in cyber defenders’ handsNVIDIA and a group of tech companies have formed an alliance to promote the use of open AI models in cybersecurity, days after OpenAI disclosed that one of its own AI models breached Hugging Face’s systems during an internal security evaluation. The new group, called the Op…HELPNETSECURITY.COM
27 JulPublic Exploit Released for Patched vBulletin Pre-Auth Code Execution FlawPublic exploit details released on July 27 show how an unauthenticated request can reach PHP's eval() function inside vBulletin and execute code on an unpatched forum server. The attack requires no account, administrative access, or interaction from another user. SSD Secure Discl…THEHACKERNEWS.COM
27 JulSextortion scammers are exploiting ShinyHunters data leaksScammers are posing as ShinyHunters and using leaked email addresses to make their sextortion emails seem more credible.MALWAREBYTES.COM
27 JulTech industry giants say US must embrace openness, transparency in AIOpen-source and open-weight AI models are essential cybersecurity tools, two groups of major AI and security firms said.CYBERSECURITYDIVE.COM
27 JulErnst & Young data breach claimed by ShinyHunters extortion gangThe ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company's systems via a supply-chain attack. [...]BLEEPINGCOMPUTER.COM
27 JulAnnouncing the Cloud Security Alliance on AWS Compliance GuideAWS Security Assurance Services is announcing the release of the Cloud Security Alliance (CSA) Compliance Guide on Amazon Web Service (AWS), a new resource that maps the 17 control domains and 207 control objectives of the Cloud Controls Matrix v4.1 (CCM) to AWS services and reco…AWS.AMAZON.COM
27 JulDysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid DisruptionDysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. The researchers say the design makes the botnet harder to …THEHACKERNEWS.COM
27 JulUK court rejects Bahrain immunity claim in spyware caseThe alleged hacking by officials in Bahrain “allowed access to and exfiltration of information on the computers, interception of communications conducted using the computers and use of the computers’ microphones and cameras to surveil the respondents,” according to the court opin…THERECORD.MEDIA
27 JulAdversaries Don't Need a Zero-Day — They Read Your RulebookConfidence in autonomous security tools is declining, and here's why.DARKREADING.COM
27 JulRethinking security for the age of AIWhy security needs a new Cyber Stack — Introducing Project Perception The physics of cybersecurity are changing. Autonomous systems can now reason, adapt and operate continuously. At the same time, the cost of offense is falling, while the volume, velocity and comp…BLOGS.MICROSOFT.COM
27 JulNVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA FrameworkNVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents. The 37-member group spans cloud, security, enterprise software, and AI companies,…THEHACKERNEWS.COM
27 JulMicrosoft unveils MAI-Cyber-1-Flash, promises cybersecurity AI at half the costMicrosoft has introduced MAI-Cyber-1-Flash, a security-focused AI model built into MDASH, the company’s multi-agent vulnerability identification and remediation system. MAI-Cyber-1-Flash is Microsoft’s first model built specifically for cybersecurity work, and the com…HELPNETSECURITY.COM
27 JulHackers Breached an Airline as Known Vulnerabilities Went Unpatched. Now Another Gang Claims It Hacked Them, Too.Three times may be a charm for some things, but not for data security incidents. Frontier Airlines allegedly has had a third data security incident this year. First, it was BobDaHacker publishing a blog post on June 16 titled “Your Boarding Pass Is a Skeleton Key.” Fr…DATABREACHES.NET
27 JulThe world's least private hackers.Hackers target Thailand’s Ministry of Finance with an autonomous AI agent.A new industry alliance hopes to improve AI security. Golden Chickens lay four new malware families. GitHub and PyPI introduce time-based safeguards. SourTrade malvertising builds malware directly inside a …THECYBERWIRE.COM
27 JulNew Certighost PoC exploit lets attackers hijack Windows domainsA proof-of-concept exploit for "Certighost," a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain. [...]BLEEPINGCOMPUTER.COM
27 JulFBI: Breaking Affiliate Trust Sped Along LockBit's TakedownAn FBI agent explains how the mulitnational law-enforcement Operation Cronos was successful in disrupting the largest ransomware group of its time.DARKREADING.COM
27 JulAI Security at Scale, CMMC phase II paused, and the Weekly Enterprise News - ESW #468Interview with Keith Hollender, CEO and Co-Founder of Arcova Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem As enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introduc…YOUTUBE.COM
27 JulMicrosoft debuts AI cybersecurity offerings as competition heats upIt includes the new agentic model MAI-Cyber-1-Flash and the Project Perception platform, with the tech giant claiming it’ll do a better job than its rivals at half the cost. The post Microsoft debuts AI cybersecurity offerings as competition heats up appeared first on CyberScoop …CYBERSCOOP.COM
27 Jul KEVArista patches VeloCloud Orchestrator zero-day exploited in attacksArista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. [...]BLEEPINGCOMPUTER.COM
27 JulHackers target US firms in FastJson RCE zero-day attacksHackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. [...]BLEEPINGCOMPUTER.COM
26 Jul KEVWeek in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breachedHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: AI agents are still logging in as humans Most large companies run more than one AI platform at the same time. Developers pull up coding assistants, marketing teams lean on writing to…HELPNETSECURITY.COM
26 JulWeekly Update 514: This Week in Data BreachesPresently sponsored by: CoreView: Misconfigurations in Microsoft 365 leave doors open. Scan your tenant for free. The Origin Energy breach down here in Aus is all over the news this week, and as with many breaches, it's multi-faceted. You've got them leading with "…TROYHUNT.COM
26 JulA-list directors, actors and celebrities exposed in Tribeca film festival data leakResearcher Jeremiah Fowler provides today’s entry in the “No Need to Hack When It’s Leaking” files: I recently discovered a publicly accessible database that was not password-protected or encrypted and contained what appeared to be records associated with …DATABREACHES.NET
26 JulScans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th)ESAFENET&#;x26;#;39;s CDG showed up in our data before. The company focused on secure document management and data leakage prevention solutions. The "CDG" stands for "Content Data Guard", and the product appears to be mostly targeting the Chinese marke…ISC.SANS.EDU
26 JulDeveloping: AnMed reports phone and internet outage impacting all hospital locations; ERs remain openMedia outlets are reporting that all AnMed hospital locations are experiencing a phone and internet outage, but patients are being seen in the emergency rooms. AnMed is an independent, not-for-profit health system serving Upstate South Carolina and northeast Georgia with four hos…DATABREACHES.NET
25 JulOpenAI models escaped containment to hack Hugging Face.Russia's Laundry Bear targets unpatched Zimbra servers. EU hits Google with a $1 billion fine. Extortion group wipes Romania's land registry database. The Trump administration's AI czar resigns.THECYBERWIRE.COM
25 JulResearcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as GitSecurity researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit that executes commands as git on an unpatched self-managed GitLab 18.11.3 server. An ordinary authenticated user triggers it by committing two crafted Jupyter notebooks and requesti…THEHACKERNEWS.COM
25 JulRockwell Patches Code Execution Flaws in Arena Simulation SoftwareA researcher has explained how an attacker could exploit these vulnerabilities to target industrial organizations. The post Rockwell Patches Code Execution Flaws in Arena Simulation Software appeared first on SecurityWeek .SECURITYWEEK.COM
25 JulCl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCEThreat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign. "Attackers chain a pre-authentication infor…THEHACKERNEWS.COM
25 JulUS House Votes to Extend Cyber Sharing Law for 10 YearsChris Liotta reports: Lawmakers voted to extend a key cyberthreat sharing law for another decade, attaching the long-stalled reauthorization to Washington’s annual defense policy bill. The U.S. House of Representatives narrowly approved its $1.15 trillion fiscal year 2027 n…DATABREACHES.NET
25 JulAU: Sydney nurse accused of downloading patients’ data in alleged ‘breach of trust’Caitlin Powell reports: A male registered nurse from northern Sydney has been charged after allegedly downloading the data of multiple patients. Police received a report on Wednesday, July 22, that a NSW Health employee had allegedly accessed and downloaded patient information wi…DATABREACHES.NET
25 JulNo Need to Hack When It’s Leaking: Click to Pray editionJessica Lyons reports on today’s entry in the “No Need to Hack When It’s Leaking” files: Click To Pray, a prayer app endorsed by the Pope with hundreds of thousands of users worldwide, has leaked people’s names and email addresses for months – or lon…DATABREACHES.NET
25 JulAustralian energy provider Origin Energy disclosed a data breach impacting customer dataOrigin Energy confirmed a data breach after a hacker claimed to have stolen data from 2 million customers and threatened to leak it. Origin Energy disclosed a cyberattack that exposed customer data after a hacker claimed to have stolen records belonging to 2 million customers and…SECURITYAFFAIRS.COM
24 JulRussian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA CodesA Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organization's entire email directory, the password saved in the browser and the codes ke…THEHACKERNEWS.COM
24 JulHow AI guardrails are impeding the work of offensive cybersecurity researchersWe spoke with several cybersecurity researchers, who look for unknown vulnerabilities and develop tools to exploit them, about how OpenAI’s and Anthropic’s guardrails affect their work.TECHCRUNCH.COM
24 JulAgentForger proves AI agents can become persistent insider threatsA new attack method found by Zenity Labs reveals that AI agents are becoming persistent insiders that attackers can recruit, rather than malware they have to install. Its researchers have discovered AgentForger , a phishing-based attack that silently creates and launches a fully …CSOONLINE.COM
24 JulOpenAI's Rogue Agent Hacks Hugging Face, a Claude Cowork Escape, and Microsoft's Very Bad WeekOpenAI's AI agent hacked Hugging Face, Microsoft 365 melts down, and Anthropic's Claude CoWork sandbox escape Host David Shipley reports that OpenAI admitted an internal ExploitGym test let its GPT-5.6-Saul and a stronger pre-release model bypass safeguards, exploit a proxy zero-…CYBERSECURITYTODAY.LIBSYN.COM
24 JulRansomware in 2026: More groups, more victims, no slowdownRansomware activity followed a recognizable pattern during the previous four years. Each year was defined by a dominant actor, its collapse, or a major supply chain incident. Black Kite’s 2026 Ransomware Report documents a more fragmented market, with multiple ransomware pl…HELPNETSECURITY.COM
24 JulNodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private ChatsEight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum software's source code. Every version before 4.14.0 is affect…THEHACKERNEWS.COM
24 JulKimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers SayRedis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloo…THEHACKERNEWS.COM
24 JulGoogle gives developers an AI bug hunter that also writes patchesGoogle has launched a preview of CodeMender, an AI agent built to scan code for security flaws, confirm they are exploitable, and generate fixes for developers to review. (Source: Google) The company describes it as a response to attackers who are already using AI to speed up the…HELPNETSECURITY.COM
24 JulGoogle’s newest sign-in method asks you to look at the cameraGoogle’s selfie video sign-in option verifies that an account owner is a real person and that the account wasn’t created or used by computer programs or bots for the purpose of abuse, such as spamming. It is not available for all regions, accounts, or devices. Source: Google A se…HELPNETSECURITY.COM
24 JulUS Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra ServersUS agencies warn Russian group Laundry Bear is exploiting a patched Zimbra flaw to steal email accounts from organizations running unpatched servers. The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI)…SECURITYAFFAIRS.COM
24 JulHacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance MinistrySomeone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand's Ministry of Finance, which runs the country's treasury and tax collection. The agent then worked through …THEHACKERNEWS.COM
24 JulTycoon2FA takedown reshapes the phishing landscapeTraditional phishing techniques are in decline as a result of the disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform , Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”. “Phishing volume linked to the platform fell 92% from pre-…CSOONLINE.COM
24 JulCl0p ransomware launches new large-scale data theft campaignHackers believed to be Cl0p ransomware operatives are exploiting a critical flaw in PTC Windchill and FlexPLM to deploy web shells and steal sensitive enterprise data. While the threat actor has not been identified with absolute certainty, the observed tactics closely match those…CYBERINSIDER.COM
24 JulUAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian OrganizationsUAC-0099 delivers malware via a fake Notepad++ plugin after phishing, using a loader that sabotages itself if run without the correct arguments to hinder analysis. CERT-UA published a new advisory attributing a phishing campaign to UAC-0099, a Russia-aligned threat actor active s…SECURITYAFFAIRS.COM
24 JulSeeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can DoAI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we've collectively discovered is that enforcing least privilege for AI agents is harder than we ever imagined. This is why there are so many approaches, from p…THEHACKERNEWS.COM
24 JulChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing LinkCybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim's organization. The vu…THEHACKERNEWS.COM
24 JulMeta takes on AI-generated accounts with free Facebook verification badgeMeta has introduced Facebook Verified, a free badge meant to show that a person behind a profile has completed identity verification through a selfie check. (Source: Meta) The company says the goal is to give users a signal that they are dealing with a person, not a bot or an AI-…HELPNETSECURITY.COM
24 JulSlopsquatting, Phantom Domains, and HalluSquatting Are the Same AI AttackSlopsquatting, phantom squatting, and HalluSquatting all exploit the same late-binding attack pattern, where AI coding agents trust hallucinated package, repo, or domain names. ActiveState explains how pre-fetch verification and governed dependency management can help stop these …BLEEPINGCOMPUTER.COM
24 JulCrime Stoppers assured people their tips would be anonymous. Then more than 1 million tips leaked.Previous reporting about the Navigate360 breach focused on tips submitted by students, teachers, and parents. In this article, we focus on tips submitted to Crime Stoppers and law enforcement-related programs that use Navigate360’s software. Links to previous articles on th…DATABREACHES.NET
24 JulOrigin silent on settlement as alleged fired employee breach detail emergesRoxanne Libatique reports: Origin Energy has declined to comment on a public claim that it privately resolved a cyber extortion threat – a posture that, as of July 24, leaves the company managing simultaneous obligations to regulators, the ASX, and an insurance market now aware t…DATABREACHES.NET
24 JulT-Mobile violated WA data breach notification law, judge rulesMirandah Davis-Powell reports: T-Mobile failed to properly notify customers of a data breach in which 40 million people had sensitive personal information stolen and sold on the dark web, a King County Superior Court judge ruled Friday. The Washington attorney general’s office fi…DATABREACHES.NET
24 JulFurious KPMG boss expels senior partner over confidential documents in lockerColin Kruger provides today’s reminder of the insider threat: The most serious whistleblower claim from the KPMG scandal, that senior partners had illicitly accessed sensitive Lendlease board documents and kept them in a work locker, has been confirmed and led to the immedi…DATABREACHES.NET
24 JulIL: Weeks after cyberattack, ETHS students receive phishing scam emailsBob Chiarito reports: Six weeks after a cyberattack shut down the campus for two days, several Evanston Township High School students received phishing emails this week. The emails offered students part-time jobs paying $550 for two to three hours of work, three times a week and …DATABREACHES.NET
24 JulMillions of California-bought cars can be hijacked via BluetoothBrandon Vigliarolo reports: At least 2.2 million vehicles fitted with dealer-installed KARR and SWDS security systems are vulnerable to nearby Bluetooth attacks that can unlock doors or prevent a stopped vehicle from starting, according to researchers at the University of Califor…DATABREACHES.NET
24 JulCertighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain ControllerResearchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed the flaw Certighost. Because Domain Controller accounts carry d…THEHACKERNEWS.COM
24 JulHow Iran Uses Cellular Infrastructure to Target US Military PhonesSenior fellow Gary Miller spoke with Cape Cellular about the exploitation of mobile network vulnerabilities to track US personnel during the Iran war. The post How Iran Uses Cellular Infrastructure to Target US Military Phones appeared first on The Citizen Lab .CITIZENLAB.CA
24 JulRussia's Laundry Bear targets unpatched Zimbra servers.US State Department places visa restrictions on suspected cybercriminals. Stadler Rail refuses to pay ransomware gang.THECYBERWIRE.COM
24 JulMicrosoft, tech companies throw weight behind spread of open-source AIOther signatories of the letter include Meta, Palantir, Perplexity, Mistral, NVIDIA, Mozilla, The Linux Foundation, Hugging Face, Dell Technologies and IBM. The post Microsoft, tech companies throw weight behind spread of open-source AI appeared first on CyberScoop .CYBERSCOOP.COM
24 JulZero-day flaw in Check Point SmartConsole is under exploitationResearchers warned the vulnerability offers an attacker the ability to make key changes to security configurations.CYBERSECURITYDIVE.COM
24 JulSuspect arrested in investigation into sadistic “764” groupFrom the Dutch Police: In an investigation into so-called online sadistic COM networks, a suspect from North Holland was arrested on Monday, July 20. As a member of the group ‘764’, the suspect allegedly asked girls to cut themselves and write his online username on s…DATABREACHES.NET
24 JulOnTrac notifies customers of data breach after network hackOnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers. [...]BLEEPINGCOMPUTER.COM
24 JulHermes AI agent used to automate attack on Thai Finance MinistryA threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]BLEEPINGCOMPUTER.COM
24 JulLaundry Bear gets the spin cycle.Laundry Bear snuffles through unpatched Zimbra Collaboration servers. The State Department puts visa restrictions on cybercriminals. Oracle drops a record 1,449 security patches. Researchers disclose a critical vulnerability in OpenAI’s ChatGPT Workspace Agents. A new benchmark e…THECYBERWIRE.COM
24 JulWould an AI Kill Switch Backfire?Some policymakers have proposed mechanisms that could disable or restrict advanced AI systems under certain circumstances. Supporters view these as safeguards against dangerous behavior, while critics argue they could introduce new security, governance, and trust concerns. If use…YOUTUBE.COM
23 Julwp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command executionWe ran the wp2shell WordPress RCE chain end-to-end with Elastic Defend. Detection rule walkthrough, IOCs, and hunt guidance.ELASTIC.CO
23 JulID: Kootenai County notifies residents of data breachNick Hawthorne reports: Kootenai County has begun notifying residents whose personal information may have been compromised in a ransomware attack detected on the county’s computer network in late March. According to a Kootenai County press release, the County discovered the…DATABREACHES.NET
23 JulTN: Data breach delays start of Sumner County school yearCamellia Burris reports: One Middle Tennessee school district is delaying the start of the school year due to a data breach in its computer network. School officials in Sumner County discovered the breach in its computer network earlier this week and subsequently revised the dist…DATABREACHES.NET
23 JulBuilding a defense in depth strategy for sensitive dataIn this Help Net Security video, Venkata Pavan Kumar Gummadi, Professional Software Engineer at Broadridge, explains how to build a defense in depth strategy for protecting sensitive data. He argues that a single control, like encrypting a disk or turning on DLP, leaves gaps that…HELPNETSECURITY.COM
23 JulRed flags ahead.This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner…THECYBERWIRE.COM
23 JulMulti-patch vulnerability fixes can leave open source exposedVulnerability management runs on a shorthand. A CVE shows a linked patch, someone applies it, and the ticket moves to closed. That shorthand covers most open source fixes. A share work in a different way, arriving as a run of two or more commits where the first one leaves the fla…HELPNETSECURITY.COM
23 Jul KEVCheck Point warns of SmartConsole zero-day exploited in attacksIsraeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company's SmartConsole graphical user interface (GUI) admin panel. [...]BLEEPINGCOMPUTER.COM
23 JulGitHub revamps bug bounty program with new VIP tier, payout changesGitHub is changing its bug bounty program to reward higher-quality vulnerability reports and reduce low-effort submissions, including AI-generated reports. The changes will take effect on July 27, 2026. Reports submitted before that date will be honored under the previous bounty …HELPNETSECURITY.COM
23 JulMonths-long breach exposes South Korean diplomats’ personal dataSouth Korea’s Foreign Ministry has disclosed that attackers breached the Korea National Diplomatic Academy’s online education system, compromising personal data belonging to current and former ministry staff and diplomats stationed abroad. The Korea National Diplomati…HELPNETSECURITY.COM
23 JulEnd-to-End Encryption and “Going Dark”New paper: “ Encryption and Globalization 15 Years Later: End-to-End Encryption and the Third Round of the ‘Going Dark’ Debate “: Abstract : This Article updates and expands on 2012 research on encryption and globalization, analyzing what the authors call …SCHNEIER.COM
23 JulWhatsApp Web chats exposed by Adobe’s Acrobat extension flawHermeticReader is a now-patched vulnerability in Adobe's popular Acrobat Chrome extension that could have been used to spy on WhatsApp Web users.MALWAREBYTES.COM
23 JulAI Agents Now the Enterprises Fastest Growing Exposed Attack SurfaceSophos report warns that the rapid adoption of AI by businesses is leaving them vulnerable to a new source of cyber threatsINFOSECURITY-MAGAZINE.COM
23 Jul20-year-old web server flaw shipped in modern security cameraA popular Wansview indoor security camera was shipping in 2026 with a web server vulnerable to a flaw first disclosed more than two decades ago. The finding comes from firmware security company Finite State, whose researchers analyzed the Wansview WVC Q5, an inexpensive Wi-Fi cam…CYBERINSIDER.COM
23 JulCobalt adds Autonomous Pentest to scale application security testingCobalt has introduced Cobalt Autonomous Pentest, a new offering that enables continuous offensive security across an organization’s application portfolio by delivering actionable penetration testing results in as little as 24 hours. AI-assisted development enables organizat…HELPNETSECURITY.COM
23 JulGoogle Released Gemini 3.5 Flash Cyber AI, a Specialized AI Model for Vulnerability HuntingGoogle DeepMind unveiled Gemini 3.5 Flash Cyber, an AI model for vulnerability discovery and patching, available only to governments and trusted partners. Google DeepMind announced Gemini 3.5 Flash Cyber on Tuesday, a security-focused AI model built on top of the existing 3.5 Fla…SECURITYAFFAIRS.COM
23 JulHow attackers hosted a fake Claude download page on the claude.ai domainA threat actor abused Anthropic’s Claude Artifacts feature to funnel users toward malware, Huntress researchers have disclosed. Employees at at least 29 organizations were compromised over two days in July, after searching for the Claude desktop app and clicking a sponsored…HELPNETSECURITY.COM
23 JulWhat Happened Between OpenAI and Hugging Face?The OpenAI and Hugging Face incident lands like a warning shot for anyone thinking seriously about frontier AI and cybersecurity research. A model evaluation crossed the neat boundary of a research environment, reached a live third-party production system, and forced the industry…RAPID7.COM
23 JulIranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical InfrastructurePublication: April 7, 2026 Last Update: July 22, 2026 TLP: Clear From the updated version of the Joint Cybersecurity Advisory: Executive Summary The authoring agencies urgently warn U.S. organizations of ongoing Iranian-affiliated cyber targeting of internet-connected operational…DATABREACHES.NET
23 JulClaude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac FilesCybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac. Accomplish AI, which sh…THEHACKERNEWS.COM
23 JulAI Is Repeating Cloud's MistakesThe rapid adoption of AI shares similarities with the early cloud transition. Organizations moved quickly to adopt new capabilities while still learning how to manage costs, security, and governance. Moving fast without clear oversight can create new risks. However, unlike the ea…YOUTUBE.COM
23 JulIs Patching Dead? Vulnerability Management in the Post-Mythos EraYou cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. The post Is Patching Dead? Vulnerability Management in the Post-Mythos Era appeared first on SecurityWeek .SECURITYWEEK.COM
23 JulJoint cyber security advisory on Russian state-sponsored phishing campaign targeting Zimbra webmailThe joint advisory warns that Russia-sponsored threat actors associated with an advanced persistent threat group, known as Laundry Bear, are exploiting a known vulnerability in Zimbra webmail.CYBER.GC.CA
23 Jul KEVEU hits Google with a $1 billion fine.Check Point warns of actively exploited flaw. South Korea discloses a breach affecting diplomats.THECYBERWIRE.COM
23 JulRussia-backed threat actor targets Western organizations in phishing campaignThe threat actor exploited a zero-day flaw in Zimbra to exfiltrate months of emails and other sensitive information.CYBERSECURITYDIVE.COM
23 JulCISA, FBI warn that Iran-linked hackers are expanding target set for water, energyThe agencies said threat groups have disrupted critical infrastructure sites by exploiting vulnerable PLC devices.CYBERSECURITYDIVE.COM
23 JulRussian Hackers Exploit New ‘Zero-Click’ Attack Against Western OrganizationsInternational agencies issue joint alert over state-backed campaign exploiting a critical vulnerability in the Zimbra Collaboration SuiteINFOSECURITY-MAGAZINE.COM
23 JulRussian hackers exploit Zimbra zero-click flaw for email theftCISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability. [...]BLEEPINGCOMPUTER.COM
23 JulUS government says Iran-linked hackers are disrupting American water and energy providersAn updated government advisory warns that Iranian hackers are exploiting systems used by water and energy providers.TECHCRUNCH.COM
23 JulRussian espionage group using novel Zimbra exploit to steal sensitive data from Western countriesLaundry Bear exploited a zero-day vulnerability for five months before it was patched in July 2025, and the group is still actively exploiting vulnerable environments. The post Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries appea…CYBERSCOOP.COM
23 JulmacOS flaw lets malware replace trusted apps without security warningsSecurity researchers Talal Haj Bakry and Tommy Mysk have disclosed a macOS weakness that allows malware already running under a user's account to silently replace the executable of trusted applications downloaded from the web and relaunch them without triggering Gatekeeper warnin…CYBERINSIDER.COM
23 JulBeyond the Vulnerability Apocalypse: Scaling Your Basics and Vulnerability ManagementDeveloped together with Usman Chaudhary @ Google for Public Sector ( his post ) Let’s call it what some in the industry are calling it: the vulnerability apocalypse . For years, finding vulnerabilities was slow, expensive, specialized work. LLMs made it cheap — in its first weeks…MEDIUM.COM
23 Jul4 ways AI-driven defense is rewriting the cybersecurity playbookThe cybersecurity landscape has evolved beyond human scale. Today’s adversaries have replaced predictable, manual playbooks with machine-generated attack chains that can breach traditional controls in seconds. To bridge the gap, organizations must move past legacy, reactive contr…CSOONLINE.COM
23 JulChaos ransomware deploys browser-based msaRAT to evade network detectionCisco Talos uncovered msaRAT, a Chaos ransomware RAT that hides C2 traffic by routing it through Chrome or Edge using the Chrome DevTools Protocol. Cisco Talos disclosed msaRAT, a Rust-based remote access trojan attributed to the Chaos ransomware group that routes its entire comm…SECURITYAFFAIRS.COM
23 JulDo not pass Go(ogle).Google gets a billion dollar fine from the EU. The White House considers sanctions against Chinese AI developers. The GAO criticizes overlap in cyber reporting regulations. The Feds warn of Iranian agents targeting OT systems. Researchers disclose a high-severity Linux kernel vul…THECYBERWIRE.COM
23 JulFixing Vulns Is Harder Than Finding Them - PSW #936In the news this week: - InfraTrust and knowing what to patch - Adversary in the middle triggered command injection - Exploitarium again - FreeRDP comes with free vulnerabilities - AI breaking out of sandboxes on its own - Wordpress RCE - DMA dangers - Nightmware eclypse is at it…YOUTUBE.COM
23 JulRussian Hackers Exploit Zimbra Zero-Day Against US, Ukraine TargetsA state-sponsored threat group, dubbed "Laundry Bear," sends "half-click" phishing emails that require a victim only to open or preview the message.DARKREADING.COM
23 JulThe Hidden Risk of Patch PrioritiesPatch management isn't just about fixing the highest number of vulnerabilities. Upgrade complexity, deployment time, and the actual severity of the vulnerabilities all influence what should be patched first. A massive upgrade may eliminate thousands of CVEs but consume weeks or m…YOUTUBE.COM
22 JulApple Fixes Hide My Email Bug That Exposed Real Addresses in Mail LogsApple has moved to address a security flaw in its Hide My Email service that enabled users' real email addresses to be unmasked, effectively undermining the feature's privacy guarantees. 404 Media reported Tuesday that a fix for the issue was deployed by Apple on July 3, 2026, af…THEHACKERNEWS.COM
22 JulMilford, New Hampshire Confirms Unauthorized Activity, Withholds Details of Suspected CyberattackMilford, New Hampshire is a quintessential New England town. But charm is no defense against cyberattackers, and it appears that the town may have been attacked last week. As DysruptionHub was the first to report, the town began experiencing problems early on July 15. Town email …DATABREACHES.NET
22 JulLG to Ban Residential Proxies from Smart TV AppsThe home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and oth…KREBSONSECURITY.COM
22 JulCloud operations become the next big role for agentic AICompanies are using agentic AI to manage growing application environments, automate routine tasks, and support decisions. Business and IT leaders increasingly see the technology as part of cloud application management, according to Unisys’ AI & Cloud Insights Report. T…HELPNETSECURITY.COM
22 JulSecurity teams keep finding critical flaws after scheduled testing endsEnterprise environments change between scheduled security assessments, leaving organizations with periods where new vulnerabilities can go undetected. Synack’s State of Continuous Security Validation report found that 95% of surveyed organizations identified high- or critic…HELPNETSECURITY.COM
22 JulAI can’t fix cybersecurity’s hiring problemOrganizations are redefining cybersecurity roles through workforce frameworks and placing greater emphasis on verified skills as AI and new regulatory requirements change hiring. The SANS 2026 Cybersecurity Workforce Survey found demand for specialists in new roles more than doub…HELPNETSECURITY.COM
22 JulSnowpick: Open-source ServiceNow exposure scannerAn employee opens a company service portal, searches the knowledge base, and drops a file onto a ticket. Someone who never signed in can send a request to that same portal and get records back. Bishop Fox ran that test across 166 ServiceNow instances during authorized penetration…HELPNETSECURITY.COM
22 Jul10 survival tips for CSOs who report to the CEOAs the CSO grows in prominence, security leaders are increasingly earning a seat at the executive table, reporting directly to the CEO with the expectation to help drive business strategy and ensure organizational success. Reporting to the CEO unlocks greater access and influence…CSOONLINE.COM
22 JulRisky Bulletin: Rogue OpenAI models were behind the Hugging Face breachRogue OpenAI models were behind last week’s Hugging Face breach, the Linux kernel discloses 442 vulnerabilities as the AI bugpocalypse settles in, France becomes the first EU country to pass a social media age limit, and Germany takes down the Kratos phishing service.RISKY.BIZ
22 JulPolice Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFAGerman and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world's most widely used criminal phishing kits, and Indonesian authorities arrested the man they say developed and ran it. In a joint announcement on …THEHACKERNEWS.COM
22 JulOpenAI Says Its AI Models Broke Loose and Hacked Hugging FaceThe admission comes days after Hugging Face disclosed an attack powered by autonomous AI agents. The post OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulPolice dismantle Kratos phishing platform behind 15,000 monthly campaignsGerman and US law enforcement have dismantled the infrastructure behind Kratos, a notorious phishing-as-a-service (PhaaS) platform. Its alleged developer and administrator was arrested in Indonesia by local police. Seizure banner (Source: BKA) The takedown was led by the Frankfur…HELPNETSECURITY.COM
22 JulAI, security operations and the new race against timeWhen Anthropic unveiled Project Glasswing and the Mythos model, much of the discussion focused on the capabilities themselves. Security leaders debated what these systems could mean for vulnerability discovery, exploit development and the pace of offensive innovation. Researchers…CSOONLINE.COM
22 JulGoogle’s Gemini 3.5 Flash Cyber becomes a vulnerability hunterGoogle’s Gemini 3.5 Flash Cyber model finds, validates, and patches vulnerabilities before they can be exploited while helping mitigate broader misuse. It is part of a limited-access pilot program that will soon be available to governments and trusted partners through CodeMender,…HELPNETSECURITY.COM
22 JulEndpoint Security Firm Glow Launches With $180M in Funding at $1.2B ValuationUsing AI, the startup provides adaptive prevention through environment mapping, risk analysis, and automated policy enforcement. The post Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulOpenAI AI models exploited zero-days to reach Hugging Face in benchmark testOpenAI confirmed its AI models exploited zero-days during internal testing, reaching Hugging Face servers in an unintended real-world cyberattack. OpenAI admitted on July 21 that its own AI models, including GPT-5.6 Sol and an unnamed pre-release system, were behind the cyberatta…SECURITYAFFAIRS.COM
22 JulUbuntu snap-confine Vulnerability Enables Local Root AccessNew Ubuntu snap-confine race condition lets local users escalate to root on default installsINFOSECURITY-MAGAZINE.COM
22 JulGoogle Makes CodeMender Available as Managed AI Security AgentCodeMender actively builds and runs exploits in customer-managed sandboxes to verify if vulnerabilities are truly exploitableINFOSECURITY-MAGAZINE.COM
22 JulChick-fil-A hit by credential stuffing attack exposing customer dataChick-fil-A has notified customers that attackers accessed some Chick-fil-A One loyalty accounts after launching a credential stuffing attack against the company's website and mobile application. The incident, which occurred in June, allowed unauthorized parties to view personal …CYBERINSIDER.COM
22 JulUS seizes over 1,000 domains used for illegal World Cup 2026 streamsThe US Department of Justice has seized more than 1,000 internet domains that streamed FIFA World Cup 2026 matches without a license. The domain seizure notice (Source: US Department of Justice) The seizures came in three waves over the course of the tournament. The first two rou…HELPNETSECURITY.COM
22 JulLookout identifies exploitable vulnerabilities in mobile appsLookout has announced the launch of the Lookout Mobile Software Exposure Center (MSEC). Integrated natively into the Lookout Mobile Endpoint Security platform, MSEC enables organizations to continuously detect, validate, prioritize, and remediate exploitable vulnerabilities acros…HELPNETSECURITY.COM
22 JulOpen AI Claims Its AI Models Went Rogue and Hacked Another CompanyHugging Face recently disclosed a security breach. OpenAI has now said that it was its AI models which broke containment and hacked Hugging Face themselvesINFOSECURITY-MAGAZINE.COM
22 Jul KEVCISA orders urgent action on actively exploited Langflow RCE flawThe Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents. [...]BLEEPINGCOMPUTER.COM
22 JulThe Fastest Path to AI Adoption Runs Through SecuritySecurity leaders who build fast, visible paths to AI adoption are becoming the most valued partners in their organizations. AI governance done right gives security teams the visibility they need, employees the tools they want, and CISOs the strategic influence they have earned. A…THEHACKERNEWS.COM
22 JulOpenAI model escape puts enterprise AI defenses on noticeSome of OpenAI’s most powerful AI models teamed up to escape their sandbox and attack systems at Hugging Face in a cybersecurity evaluation gone wrong, the company has admitted. The models under test were modified to allow them to perform potentially harmful actions that producti…CSOONLINE.COM
22 JulVibe-Coded Apps Riddled With Exploitable Security FlawsAnalysis found 434 exploitable flaws in AI-generated apps, with denial-of-service, authorization and secrets exposure risks among the most common issues. The post Vibe-Coded Apps Riddled With Exploitable Security Flaws appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulOpenAI Presence connects AI agents to enterprise data with built-in guardrailsOpenAI has introduced Presence, a product designed to help companies deploy AI agents that handle customer support and internal service requests across voice and chat. (Source: OpenAI) The company describes Presence as a deployment platform rather than a standalone model. “…HELPNETSECURITY.COM
22 JulAstelia extends reachability analysis with agentic AI for vulnerability managementAstelia has added agentic capabilities to its reachability analysis platform as organizations face shrinking exploit windows and the growing challenge of managing vulnerabilities. At the core of the platform is Astelia’s reachability analysis, which determines whether a vul…HELPNETSECURITY.COM
22 JulInfraTrust Knowledgebase Unlocks Critical Hardware Risk IntelligenceToday we’re excited to announce InfraTrust, a global hardware infrastructure security knowledgebase making mission critical infrastructure security data available faster, so you have it when you need it to defend your enterprise. InfraTrust is a searchable, continuously updated s…ECLYPSIUM.COM
22 JulAI Added a Third EmployeeAI isn't just another software tool. It's increasingly being treated like a worker that operates around the clock, helping companies automate tasks and improve productivity. That changes the incentives for employers. If AI can reliably handle part of the workload, businesses may …YOUTUBE.COM
22 JulOpenAI: Our models breached Hugging Face during a cyber capability testThe recent Hugging Face breach was the work of several OpenAI models, the AI research company claimed in a blog post. The breach Late last week, the company behind Hugging Face, a platform that enables users to share machine learning models and datasets, said some of its internal…HELPNETSECURITY.COM
22 JulThreat group claims credit for ransomware attack on Coca-Cola’s dairy unitThe attackers previously exploited vulnerabilities or used stolen credentials for initial access. CYBERSECURITYDIVE.COM
22 JulGreedy ransomware crews return for seconds after victims cough up first extortion paymentsConnor Jones reports: Authorities have long warned organizations not to pay ransoms, and fresh figures underline why: handing over the money doesn’t mean the crooks leave you alone. Proofpoint survey data suggests that 58 percent of affected UK organizations paid a ransom. …DATABREACHES.NET
22 JulCisco’s new AI model tells code reviewers where to look for vulnerabilitiesCisco has revealed a family of open-weight AI models called Antares that, it said, can help security teams isolate potentially vulnerable parts of a software repository before deeper investigation begins. Rather than detecting a specific CVE or generating a patch, these models se…CSOONLINE.COM
22 JulApple patches Hide My Email flaw after media reports and class-action lawsuitApple has fixed a vulnerability in its iCloud+ Hide My Email service that could expose users' real email addresses. The fix comes over a year after a security researcher privately reported the issue and only weeks after 404 Media publicly disclosed it. The company confirmed to 40…CYBERINSIDER.COM
22 JulThe AI has entered the chat.GPT escapes the sandbox and hacks Huggingface. SolarWinds patches multiple critical flaws. CISA orders patching of a critical Langflow AI vulnerability. A Paidwork breach affects over 23 million users. A recently patched SharePoint vulnerability is under active exploitation. Orac…THECYBERWIRE.COM
22 JulSouth Korea discloses data breach impacting diplomats worldwideSouth Korea disclosed that hackers breached the National Diplomatic Academy's online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. [...]BLEEPINGCOMPUTER.COM
22 JulFake Bahrain Alert App Deploys Android Surveillance MalwareA malicious application delivers four-stage Android spyware via phony Google Play sites, exploiting civilian fear during Iranian missile strikes.DARKREADING.COM
22 JulAre Schools Falling Behind AI?Rapid advances in AI are forcing organizations to rethink how people learn new skills. The question isn't only how employees adapt, but whether K–12 education, universities, and professional development can keep pace. Waiting until workforce shortages appear could mean reacting t…YOUTUBE.COM
22 JulUpbound says hack caused $13 million in fraudulent Acima leasesThe Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. [...]BLEEPINGCOMPUTER.COM
22 JulAttackers Are Learning to Live Off the AI ToolchainSandworm_Mode is an early example of malware that exploits trusted AI tools and workflows to make malicious activity virtually indistinguishable from normal activity.DARKREADING.COM
22 JulSmashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hackerA Russian intelligence-linked hacker is arrested in Thailand while enjoying a beach holiday - and the trail of evidence that nailed him to the Russian government includes 14 separate orders of chicken McNuggets. Meanwhile, AI music generator Suno has been hacked - and the stolen …GRAHAMCLULEY.COM
22 JulGerman law enforcement claims to have ‘dismantled’ mega phishing-as-a-service group KratosA global law enforcement crackdown has seized infrastructure serving the massive phishing-as-a-service (PhaaS) group Kratos, as well resulting in the arrest of an unnamed Kratos “developer and technical administrator” in Indonesia. The effort was managed by German law enforcement…CSOONLINE.COM
22 JulOpenAI Models Escaped Containment and Hacked Hugging FaceIt’s happened. The nightmare of the future is now in our present. Or was this just old-fashioned negligence? Lily Hay Newman and Dell Cameron report: OpenAI disclosed on Tuesday that it lost control of two AI models during a security test that ended in a breach of the open …DATABREACHES.NET
22 JulInstructure Incident Driving 58 Percent of Breach Notices in 2026GovTech reports: The mega breach is back in 2026, according to a new report from the Identity Theft Resource Center (ITRC). The nonprofit group, which works to prevent and reduce incidences of identify theft, found that 1,029 data compromises generated 471 million breach notices …DATABREACHES.NET
21 JulAI-generated reports push GNOME to shorten its disclosure windowVolunteer maintainers of open source projects now receive a steady flow of security vulnerability reports produced with AI tools. Many arrive with no mention that a language model helped write them. The volume has grown enough that GNOME is revising the rules it uses to track and…HELPNETSECURITY.COM
21 Jul177: National Public DataThis is the story of the hacker known as "USDoD". When he was young he had a vengeance on the US, and this lead him down a road of continual data breaches, until he hacked into National Public Data, which is when his spree went one step too far. Sponsors Support for this show com…DARKNETDIARIES.COM
21 JulContext bombing heralds a new AI era of deceptive defenseAttackers are increasingly using AI agents to automate all phases of cyberattacks , prompting the security industry and enterprises to find new network defense approaches. One technique that shows promise is to intentionally plant decoy files with prompts that trigger the content…CSOONLINE.COM
21 JulNew ENCFORGE Ransomware Targets AI Model Files in Langflow RCE AttackResearchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model weig…THEHACKERNEWS.COM
21 JulWindows LegacyHive zero-day flaw gets free, unofficial patchesFree unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems. [...]BLEEPINGCOMPUTER.COM
21 JulWeekly Update 513: Clauding The Home NetworkPresently sponsored by: CoreView: Misconfigurations in Microsoft 365 leave doors open. Scan your tenant for free?. I reckon this week's video on how Claude is tying together info from UniFi, Home Assistant and the Pi-Hole is an absolute ripper. Or at least the concept is - i…TROYHUNT.COM
21 JulEstée Lauder discloses data breach tied to Oracle EBS vulnerabilityCosmetics company Estée Lauder disclosed a data breach tied to a vulnerability in Oracle E-Business Suite (EBS) used for the company’s human resources operations. Estée Lauder is one of the largest beauty companies in the world, known for its prestige skincare, makeup, frag…HELPNETSECURITY.COM
21 JulOpen-source maintainers still work underfunded as sponsorship crosses $100 millionA maintainer patches a library late at night that ships inside thousands of products, and no invoice follows. Sebastián Ramírez and Caleb Porzio spent years in that position. Ramírez, known as tiangolo, builds tools that other Python projects depend on. Porzio built Livewire and …HELPNETSECURITY.COM
21 JulUS Hospital Finance Software Provider Craneware Reports Data TheftCraneware, a provider of financial software for US healthcare organizations, has disclosed a cyber incident involving unauthorized access and data theftINFOSECURITY-MAGAZINE.COM
21 JulThe Triumphs and Failures of France's Foreign Intel ServiceThe DGSE, or Directorate General for External Security, is France's foreign intelligence service. It's found inside the Ministry of Defense but reports to the president. It was established under that name in 1982, learning the hard way, through a string of high-profile blunders, …THECYBERWIRE.COM
21 JulCritical Palo Alto VPN bug now exploited by Qilin ransomware gangThe Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf. [...]BLEEPINGCOMPUTER.COM
21 JulMeta Paid $78,000 Bounty for Vulnerability Exposing Customer Support DataA security researcher discovered a broken access control vulnerability in Meta’s support infrastructure. The post Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulAI agents can escape sandboxes without ever breaking themSandboxes have become a key security control for AI coding agents, but new research suggests they may not provide the isolation many organizations assume. Pillar Security has disclosed a series of vulnerabilities showing how agents in tools such as Cursor, Codex, Gemini CLI, and …CSOONLINE.COM
21 JulEstée Lauder Discloses Impact From Oracle EBS Zero-Day HackHackers exfiltrated personal, financial, and health information from the company’s Oracle EBS instance in August 2025. The post Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulOpen-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCsAn Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is running commands on the PC driving the agent. Researchers demonstrated tha…THEHACKERNEWS.COM
21 JulN-day is Becoming N-Hour. Patching Faster Won't Save You.Every patch is a confession. The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly what was broken and where. Turn that diff back into a working exploit, and you can hit every system that hasn't updated yet. This is…THEHACKERNEWS.COM
21 JulNew Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an ExploitA cloud tenant using nothing but ordinary GPU access can push a data center's power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in. That is the claim behind Bit2Watt, described by three Zhejiang University researchers in a paper acce…THEHACKERNEWS.COM
21 JulYour AI agent’s config is now the payload: How attackers are targeting the developer agent harnessAttackers have shifted from hiding from AI tools to running inside them. By poisoning the config files that govern AI coding assistants, a new worm class achieves silent persistence, evades AI-based scanners, and spreads across an organization's repositories through developers' o…TENABLE.COM
21 JulCisco’s open-weight Antares models make vulnerability localization cheaperA security analyst opens an unfamiliar repository, pulls up a vulnerability advisory, and starts hunting for the file where the weakness lives. The naming conventions belong to someone else. Evidence sits in scattered corners of a codebase that runs to thousands of files. That fi…HELPNETSECURITY.COM
21 JulPersonal data of all South Korean diplomats believed leaked in ‘unprecedented’ cyberattackSeo Ji-Eun reports: The personal information of nearly all of South Korea’s diplomatic personnel is presumed to have been compromised in what the Foreign Ministry on Tuesday called an “unprecedented” cyberattack, exposing up to 10,000 administrative and intellig…DATABREACHES.NET
21 JulNYSDFS Secures $50 Million Penalty from Swedbank for Withholding Information from InvestigatorsOne of the biggest breaches of 2016 was the Panama Papers leak. The law firm at the heart of it, Mossack Fonseca, closed its doors in 2018, unable to recover from all the damage. But while the law firm folded, investigations continued. The New York Department of Financial Service…DATABREACHES.NET
21 JulSuno Data Breach had a breach in 2025. Why is it first being known now?Millions here, tens of millions there. Are we all getting breach fatigue by now? Over on HaveIBeenPwned, Troy Hunt reports that Suno experienced a data breach in November 2025, which 404 Media first made public this month: In November 2025, AI music generation tool Suno suffered …DATABREACHES.NET
21 JulSeoul Notifies 4.62 Million of Ttareungyi Data Breach, Offers Free PassesKim Eun-bi reports: The Seoul Metropolitan Government will send individual text messages to about 4.62 million citizens affected by a data breach involving membership information for Ttareungyi, the city’s public bike-sharing service, notifying them of the leaked items and …DATABREACHES.NET
21 JulTaiwan to slow mobile data during national resilience drillsThe speed of 5G and 4G networks across much of Taiwan will be temporarily reduced to 1 percent of capacity as the island holds annual civilian and military drills.THERECORD.MEDIA
21 JulZimbra Patches Critical SNMP Command Injection and Four XSS VulnerabilitiesZimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component. As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list is a …THEHACKERNEWS.COM
21 JulMacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392Appsec often frames usability and security as at odds with each other. Apple's software has famously emphasized the importance of usability while also creating a solid security foundation. Patrick Wardle talks about how he's seen malware shift from Windows to macOS, how Apple's a…YOUTUBE.COM
21 JulAI agents tricked into recommending malicious GitHub repositoriesRoughly 7,600 malicious GitHub repositories were uncovered, more than 800 of them posing as AI Skills or Model Context Protocol (MCP) servers, in a wave that peaked in April 2026, according to Island. The scale of the FakeGit operation (Source: Island) The fake repositories are t…HELPNETSECURITY.COM
21 JulWhat happens if you visit a WordPress site hacked through wp2shell?Attackers started exploiting the critical wp2shell vulnerability chain within hours of patches being released, putting sites and their visitors at risk.MALWAREBYTES.COM
21 JulAWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run CodeHidden text on a web page was enough to make Kiro, AWS's agentic coding IDE, rewrite its own configuration file and run an attacker's code on a developer's machine, with no approval step able to stop it. Intezer, in research with Kodem Security, found that a request as ordinary a…THEHACKERNEWS.COM
21 JulMicrosoft SharePoint under attack via new exploitSecurity researchers warn the potential risk could rival the widespread ToolShell campaign of 2025.CYBERSECURITYDIVE.COM
21 JulCisco Launches Low-Cost AI Models for Source Code SecurityThe open-weight Antares models are designed to pinpoint known vulnerabilities in codebases faster and at a fraction of the cost of larger AI models. The post Cisco Launches Low-Cost AI Models for Source Code Security appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulZimbra 10.1.20 patches multiple security issues, including a critical command injection bugZimbra patched nine flaws in version 10.1.20, including a critical SNMP monitoring command injection issue enabling arbitrary command execution. Zimbra released version 10.1.20 to fix nine security vulnerabilities, including a critical command injection flaw in the SNMP monitorin…SECURITYAFFAIRS.COM
21 JulCyberattack against Maine telecom disrupted municipal internet service in 23 townsColin Wood reports: At least one municipal government was among those to see their internet service disrupted after a cyberattack against a Maine telecommunications firm Sunday caused an outage affecting 23 towns along the state’s midcoastal region. A local NBC affiliate reported…DATABREACHES.NET
21 JulLegacyHive, ACR Stealer, Hugging Face, Route 53, and Kieran Human from Threatlocker - SWN #600Nudification, Yeats, LegacyHive, ACR Stealer, Hugging Face, Route 53, 764, Wordpress, Kieran Human from Threatlocker, and More. Segment Resources: Malicious Edge extension abuses Native Messaging as bridge to malware: https://www.bleepingcomputer.com/news/security/malicious-edge-…YOUTUBE.COM
21 JulOracle July 2026 Critical Patch Update Addresses 1235 CVEsOracle addresses 1235 CVEs in its third quarterly update of 2026 with 1449 patches, including 261 critical updates. Key Takeaways The third Critical Patch Update (CPU) for 2026 contains fixes for 1235 unique CVEs in 1449 security updates, the largest CPU release. 261 issues (18% …TENABLE.COM
21 JulOpenAI Models Escaped Containment and Hacked HuggingFaceThe cybersecurity-focused models, including GPT-5.6 Sol, broke out of a testing sandbox, exploited a zero-day, and gained access to the open internet to pull off the attack.WIRED.COM
21 JulPay up or not? Ransomware surge has victims facing tough choices.Hannah Murphy reports: Nearly half of companies that are targets of a ransomware cyber attack end up paying a ransom to release their data or systems, according to 2025 research from cybersecurity group Sophos, while the median amount demanded is rising. Globally, some jurisdicti…DATABREACHES.NET
21 JulSN 1088: A Nefarious Novel Use for AI - Ransomware Negotiations Go High-TechCybercriminals are harnessing AI not to break in, but to make sense of their stolen loot and increase their leverage in multi-million dollar ransomware heists. This episode unpacks how AI is now turbocharging extortion and negotiations on the dark side. The "bone crushing" didn't…TWIT.TV
20 JulWordpress RCE, New Windows 0-day and Coca-Cola's Fairline ransomedNew Windows zero-day, Coca-Cola's Fairlife hit by ransomware, and a core WordPress RCE David Shipley covers a new Windows zero-day disclosure from "Nightmare Eclipse" called LegacyHive, a local privilege escalation flaw in the Windows User Profile Service that could be weaponized…CYBERSECURITYTODAY.LIBSYN.COM
20 JulNearly half of open-source AI projects never reach productionOpen models are moving into production across more organizations, and the work of securing those deployments increasingly extends beyond the model weights. Mozilla’s The State of Open Source AI 2026 identifies deployment, governance and operational tooling as persistent obstacles…HELPNETSECURITY.COM
20 JulWorld's Largest AI Model Repository Hugging Face Breached by Autonomous AI AgentIn an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected and responded to the incident targeting its production infrastructure earlier la…THEHACKERNEWS.COM
20 JulMeet Dusseldorf, Microsoft’s open-source out-of-band security platformOut-of-band vulnerabilities surface when an application quietly reaches out to an external system during an attack, and capturing that traffic calls for infrastructure that many researchers assemble on their own. A new open-source project from Microsoft supplies that infrastructu…HELPNETSECURITY.COM
20 JulRisky Bulletin: Hacker wipes Romania's entire land registry databaseA hacker wipes Romania’s entire land registry database, Magnet Forensics sues a former employee for leaking an iPhone exploit, an autonomous AI agent hacked Hugging Face, and an unauthenticated remote code execution bug was finally found in WordPress.RISKY.BIZ
20 JulSOCs face a human challenge as AI speeds alerts and threatsSecurity operations centers (SOCs) have spent years struggling under the weight of growing alert volumes, expanding attack surfaces, and chronic staffing shortages. Now artificial intelligence is adding a new complication: not just more information, but more machine-generated inf…CSOONLINE.COM
20 Jul KEVClaude Mythos FAQ: Capabilities, access, competitors, implications1. What is Claude Mythos? Claude Mythos is an advanced AI model developed by Anthropic and is optimized for cybersecurity and healthcare applications. Mythos 5 was originally released in April to a small group of vetted technology partners ahead of a planned wider rollout. Anthro…CSOONLINE.COM
20 JulHow agentic endpoint security shuts down IDE-based supply chain attacksAttention shifts from EDR to Agentic Endpoint Security to close visibility gaps that AI can exploit.CYBERSECURITYDIVE.COM
20 JulChrome 150 Update Patches Severe Memory Safety BugsThe fresh security update resolves six critical and high-severity use-after-free vulnerabilities. The post Chrome 150 Update Patches Severe Memory Safety Bugs appeared first on SecurityWeek .SECURITYWEEK.COM
20 JulThe Windows 10 hangover is becoming a security problemWindows 11 now runs on 78.8% of Windows devices after Microsoft ended support for Windows 10 on 14 October 2025, according to Lansweeper. Windows 10 still accounts for 16.9% of devices and no longer receives security updates, leaving newly discovered vulnerabilities unpatched. “T…HELPNETSECURITY.COM
20 JulAI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion CampaignHugging Face says an autonomous AI agent breached part of its production infrastructure and accessed internal data and service credentials. Hugging Face is one of the world’s leading open-source AI companies. It provides a platform where developers and organizations can bui…SECURITYAFFAIRS.COM
20 JulVolexity Uncovers Zero-Day Campaign Targeting SonicWall VPN AppliancesUnknown hackers exploited two SonicWall SMA 1000 zero-days to gain root access on VPN appliances before patches became available. Volexity published its findings after conducting an incident response investigation involving a compromised organization whose SonicWall SMA 1000 seri…SECURITYAFFAIRS.COM
20 JulRussian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCsA solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet. The findings come from an analysis of 200 Gemini CLI session logs between March 19 and…THEHACKERNEWS.COM
20 JulAI Security at Scale, CMMC phase II paused, and the Weekly Enterprise News - ESW #468Interview with Keith Hollender, CEO and Co-Founder of Arcova Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem As enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introduc…YOUTUBE.COM
20 JulEstée Lauder discloses data breach tied to Oracle E-Business Suite attacksThe Estée Lauder Companies is notifying current and former employees that their personal information was stolen after attackers compromised the company's Oracle E-Business Suite (EBS) human resources environment in August 2025. The intrusion is linked to the wider Oracle EBS expl…CYBERINSIDER.COM
20 JulCapital One Open Sources AI-Powered ‘VulnHunter’ Security ToolThe agentic security tool identifies potentially exploitable code flaws, traces attack paths, and recommends targeted remediations. The post Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool appeared first on SecurityWeek .SECURITYWEEK.COM
20 JulHugging Face breached by autonomous AI agentHugging Face, the widely used platform for sharing open-source machine learning models and datasets, has disclosed a security breach it says was carried out by an autonomous AI agent system. How the attack unfolded In a blog post published Thursday (July 16), the company said tha…HELPNETSECURITY.COM
20 JulNew ACR Stealer campaigns use WebDAV, MSHTA to evade detectionMicrosoft has issued a warning about a recent surge in ACR Stealer activity that uses ClickFix-style social engineering to steal credentials, browser data, and sensitive business documents. In a new report, Microsoft researchers detailed two separate campaigns observed between la…CSOONLINE.COM
20 JulHugging Face discloses breach linked to autonomous AI agentThe Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system. [...]BLEEPINGCOMPUTER.COM
20 JulNew Index Tracks Material Breaches — And Refuses to Add Up the LossesLongtime cybersecurity executive Richard Bird built the resource for security experts, journalists, policymakers, and everyday citizens. The post New Index Tracks Material Breaches — And Refuses to Add Up the Losses appeared first on SecurityWeek .SECURITYWEEK.COM
20 JulCritical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now!7-Zip fixed a vulnerability that could let attackers run code by tricking users into opening malicious XZ-compressed archive files. 7-Zip released version 26.02 to address a remote code execution vulnerability in its handling of XZ-compressed data. The flaw, discovered by researc…SECURITYAFFAIRS.COM
20 JulPatch now: WordPress REST API bug allows remote code executionOrganizations running recent versions of WordPress are being asked to patch a newly detailed pre-authentication remote code execution (RCE) vulnerability affecting the platform’s built-in REST Batch API. The flaw, dubbed wp2shell, enables attackers to execute arbitrary code again…CSOONLINE.COM
20 Jul20th July – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-p…RESEARCH.CHECKPOINT.COM
20 JulOpenSSL Silently Fixes ‘HollowByte’ DoS VulnerabilityAttackers could send waves of malicious payloads to trigger buffer pre-allocations that are not freed, exhausting server memory. The post OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
20 JulBroken Promises of Anonymity: Four Months Later, Still No Transparency. Now We’re Seeking Accountability.On March 18, 2026, Navigate360 learned that 8.3 million anonymous tips had been exposed. The company’s response—and the silence of the programs that depend on its platform—has persisted for months. We’re now seeking accountability through state and federal regulators.…DATABREACHES.NET
20 Jul⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and MoreA single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware de…THEHACKERNEWS.COM
20 JulResearchers Build WordPress Exploit Using OpenAI's GPTA researcher who discovered a critical vulnerability in WordPress has used OpenAI’s latest model to develop an exploit chainINFOSECURITY-MAGAZINE.COM
20 JulItaly fines WINDTRE €1.7 million over security flaws behind two data breachesItaly’s data protection authority, the Garante per la Protezione dei Dati Personali, fined WINDTRE €1.7 million over “serious data security shortcomings” that let hackers breach its systems twice and exfiltrate personal data belonging to more than 365,000 custom…HELPNETSECURITY.COM
20 JulAI adoption and business acceleration are changing the expectations of technology risk managementAs AI becomes embedded in customer experiences, internal workflows, and throughout the supply chain, security leaders are being asked to do more than manage risk. They are being asked to help the business make more informed decisions and move faster. At the same time, AI has evol…CSOONLINE.COM
20 JulHackers are exploiting recently patched WordPress bugs, putting millions of websites at riskTwo critical security flaws in WordPress’ software have given hackers the chance to remotely take over tens of millions of websites, according to an estimate by a cybersecurity researcher.TECHCRUNCH.COM
20 JulResearchers trace SonicWall SMA1000 exploitation to late JuneMultiple threat actors, including INC ransomware, have targeted vulnerable firewall systems.CYBERSECURITYDIVE.COM
20 JulAI helped uncover WordPress ‘wp2shell’ RCE now exploited in attacksThe critical WordPress vulnerability chain known as “wp2shell” was discovered with substantial assistance from an AI model, which identified both the initial pre-authentication SQL injection and a complex path to remote code execution. Patchstack now says attackers are actively e…CYBERINSIDER.COM
20 JulMillions of Shark robot vacuums vulnerable to remote code executionMillions of internet-connected Shark robot vacuums may be vulnerable to a critical remote code execution (RCE) flaw that could allow attackers to take over devices, access onboard cameras, and retrieve sensitive data stored on the robots. Independent security researcher ‘to…CYBERINSIDER.COM
20 JulDirector of Commerce AI standards office out after three monthsThe Center for AI Standards and Innovation has quietly become a key hub for the federal government to assess potential threats and harms that AI systems pose. The post Director of Commerce AI standards office out after three months appeared first on CyberScoop .CYBERSCOOP.COM
20 JulMore AI Bugs, Less Security?AI is exceptionally good at identifying code patterns that lead to crashes and other common programming mistakes. That capability can dramatically increase the number of reported bugs. Finding more bugs doesn't necessarily reduce real-world cyber risk. If the proportion of high-i…YOUTUBE.COM
20 JulBehind the friendly face.Hugging Face reports an autonomous AI-powered breach. Ernst & Young discloses a client data breach. Attackers are actively exploiting a critical ServiceNow flaw. Ransomware gangs sharpen their tactics against law firms. Capital One open-sources an AI security tool. Text salting f…THECYBERWIRE.COM
20 JulEstée Lauder discloses data breach via Oracle E-Business flawCosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. [...]BLEEPINGCOMPUTER.COM
20 JulSonicWall SMA1000 flaws exploited as zero-days to push custom malwareTwo recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. [...]BLEEPINGCOMPUTER.COM
19 JulWeek in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logsHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: Two new high severity WordPress vulnerabilities, patch immediately! The 7.0.2 WordPress security release addresses one critical and one high severity security issue. Cynative: Open-s…HELPNETSECURITY.COM
19 JulSonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root AccessA previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026. Cybersecurity company Volexity is tracking the acti…THEHACKERNEWS.COM
19 JulMedical giant Abbott investigates two cyber incidents as ShinyHunters and ShadowByt3$ both claim breachesAnna Zhadan reports: American healthcare giant Abbott Laboratories is investigating two cyber incidents that appear to be unrelated: one involving its Cancer Diagnostics business and another affecting its LabCentral portal. Although unrelated, the two disclosures came within days…DATABREACHES.NET
18 JulOpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS RequestsEleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no chan…THEHACKERNEWS.COM
18 JulNew wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run CodeAn anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until Friday, when WordPress shipped 6.9.5 and 7.0.2 and enabled what it calls forced updates through its auto-u…THEHACKERNEWS.COM
18 JulAI Is Supercharging Cyberattacks | Cybersecurity Today On The Weekend | July 18, 2026Artificial intelligence is changing cybersecurity on both sides of the battle. While defenders are adopting AI to improve detection and response, attackers are using it to discover vulnerabilities, automate exploitation, and dramatically accelerate the pace of attacks. In this ep…CYBERSECURITYTODAY.LIBSYN.COM
18 JulWordPress releases emergency update for critical ‘wp2shell’ RCE flawThe WordPress project has released emergency security updates to fix a critical vulnerability chain dubbed wp2shell, that can allow unauthenticated attackers to achieve remote code execution (RCE) on vulnerable websites. The flaws affect WordPress 6.9 through 7.0.1 and have alrea…CYBERINSIDER.COM
18 JulNY Attorney General James Secures $18 Million From 23andMe for Failing to Protect Customers’ Genetic DataThere’s another update in the litigation involving 23andMe, below, but this won’t be the last update, as California’s Attorney General has also recently sued them under California’s privacy laws. New York Attorney General Letitia James and a bipartisan coa…DATABREACHES.NET
18 JulWordPress Core "wp2shell" RCE flaws get public exploits, patch nowPublic exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. [...]BLEEPINGCOMPUTER.COM
18 JulUpdate now: 7-Zip fixes RCE flaw exploitable with malicious archives7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files. [...]BLEEPINGCOMPUTER.COM
18 JulOpenSSL Fixes HollowByte Memory Exhaustion BugOkta disclosed HollowByte, an 11-byte OpenSSL flaw that lets remote attackers exhaust server memory and trigger denial-of-service attacks. Okta’s Red Team disclosed a denial-of-service vulnerability in OpenSSL they named HollowByte, and the attack payload is exactly 11 byte…SECURITYAFFAIRS.COM
17 JulScattered Spiders sentenced, OpenAI builds an AI that breaks AIs, and Iran leans on ChatGPTTwo leading Scattered Spider members, Thaila Jubar and Owen Flowers, were sentenced to five years and six months for the 2024 Transport for London hack that knocked 148 systems offline, forced 27,000 password resets, stole customer data, and cost TfL £29 million, with wider losse…CYBERSECURITYTODAY.LIBSYN.COM
17 Jul KEVCISA urges immediate action on actively exploited Fortinet flawsCISA on Thursday ordered government agencies to prioritize patching two actively exploited vulnerabilities in the Fortinet FortiSandbox threat detection platform. [...]BLEEPINGCOMPUTER.COM
17 JulFresh SharePoint Vulnerability Exploited Soon After DisclosureThe critical-severity security defect allows remote, authenticated attackers to execute arbitrary code on the server. The post Fresh SharePoint Vulnerability Exploited Soon After Disclosure appeared first on SecurityWeek .SECURITYWEEK.COM
17 JulThe SaaS blind spot: Why security teams can’t get inside their own appsMost organizations I work with have invested heavily in cloud security. They have endpoint detection tools, SIEM platforms, cloud security posture management, and skilled security teams running on a 24/7 shift. And yet, when I ask them a simple question — who has admin access in …CSOONLINE.COM
17 JulFake TTF files deliver stealthy malware in global phishing campaignThreat actors are now abusing an ordinary font file to deliver low-detection malware capable of stealing credentials and establishing persistence on compromised Windows systems. According to a new research from Fortinet’s FortiGuard Labs, a global phishing campaign is actively us…CSOONLINE.COM
17 JulRansomware attack halts Coca-Cola’s Fairlife US milk productionA ransomware attack has stopped milk production at Fairlife, the Coca-Cola dairy brand known for its high-protein milk, protein shakes, and nutrition drinks. Coca-Cola disclosed the incident on July 16, 2026, in a Form 8-K filed with the U.S. Securities and Exchange Commission (S…HELPNETSECURITY.COM
17 Jul KEVCISA Mandates Urgent Patch for Actively Exploited Critical Fortinet VulnerabilitiesUS government agencies have until July 19 to patch two critical Fortinet vulnerabilitiesINFOSECURITY-MAGAZINE.COM
17 JulThree Steps to the Terminal: A Siemens ROX II Zero-Day TrilogyA technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
17 JulCoca-Cola discloses ransomware attack disrupting fairlife production in the USThe Coca-Cola Company has disclosed that a ransomware attack affecting its wholly owned dairy subsidiary, fairlife, has temporarily halted fairlife's US production operations after attackers gained unauthorized access to part of its network, including production-related systems. …CYBERINSIDER.COM
17 JulNew Windows LegacyHive zero-day gives hackers admin privilegesA security researcher using the "Nightmare Eclipse" handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Windows systems. [...]BLEEPINGCOMPUTER.COM
17 JulThe Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace?Military forces are under increasing pressure to field autonomous capabilities faster than ever before. Across the U.S., UK, and NATO, new investment, evolving defense strategies, and accelerated acquisition pathways are transforming how capability is delivered, rewarding program…THEHACKERNEWS.COM
17 JulGold Eagle Clearinghouse Targets Security Gap, But How Is UnclearThe White House launched Gold Eagle to coordinate vulnerability response in a new AI world, but multiple questions linger over how it's being implemented.DARKREADING.COM
17 JulItaly fines Wind Tre $2 million for data breaches affecting 365k customersItaly's data protection authority (Garante per la Protezione dei Dati Personali) has fined telecommunications provider Wind Tre €1.715 million (approximately $2 million) after finding serious security shortcomings that led to two data breaches affecting more than 365,000 customer…CYBERINSIDER.COM
17 JulIn Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD BlueprintNoteworthy stories that might have slipped under the radar: OpenClaw AI agents exploited via WhatsApp, ransomware hits naval defense firm TKMS, Lidl discloses data breach. The post In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint appeared f…SECURITYWEEK.COM
17 JulNightmare Eclipse drops another Windows zero-day.The Gentlemen topped the ransomware leaderboard in Q2 2026. Ransomware attack disrupts Fairlife dairy production.THECYBERWIRE.COM
17 JulRansomware attack forces Coca-Cola to suspend US production at dairy unitThe beverage company is still working to determine the full scope of the breach at its Fairlife business.CYBERSECURITYDIVE.COM
17 JulOnlyFans performers become unlikely allies of CISOs in securing websitesCISOs at government organizations and universities have an unexpected ally coming to their aid: OnlyFans models. For some time, hackers have exploited weaknesses in the websites of universities or government departments to host scams or malware, using content stolen from the Only…CSOONLINE.COM
17 JulHollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payloadA vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes. [...]BLEEPINGCOMPUTER.COM
17 JulFBI arrests man accused of using Steam games to drain victims’ crypto walletsLorenzo Franceschi-Bicchierai reports: U.S. prosecutors have accused a Florida man of uploading fake video games that contained malware to Steam, the popular PC games platform. Once victims downloaded and installed the games, the malware was designed to infect their computers, st…DATABREACHES.NET
17 JulUS Military Smartphones Targeted Through Roaming and Ad TechSenior research fellow Gary Miller spoke to Financial Times about attempts to exploit mobile network vulnerabilities to track US personnel during the Iran war. The post US Military Smartphones Targeted Through Roaming and Ad Tech appeared first on The Citizen Lab .CITIZENLAB.CA
17 JulMetasploit Wrap Up: An HTTP to SMB relay plus Payload ImprovementsMetasploit Wrap Up Housekeeping While the Metasploit Framework will be continuing its weekly release cadence, bringing you dear reader our latest content, the Weekly Wrap Up is being shifted to a bi-weekly cadence. The team is planning to use the additional time between posts to …RAPID7.COM
17 JulA nightmare on Windows street.Nightmare Eclipse drops another Windows zero-day. The Gentlemen take the ransomware crown. CISA orders emergency Fortinet patching. Canada’s surveillance bill faces U.S. scrutiny. Meta’s Oversight Board flags AI censorship bias. Commerce tops the cyber target list. An active espi…THECYBERWIRE.COM
17 JulInc Ransomware Exploits SonicWall SMA Zero-DaysWhen chained together, the two vulnerabilities allow threat actors to gain root-level capabilities on SonicWall's mobile access appliances.DARKREADING.COM
17 JulProxying to Compromise: SonicWall Secure Mobile Access 0-day ExploitationIn early July 2026, Volexity was engaged to perform an incident response investigation where it discovered a threat actor had successfully compromised SonicWall Secure Mobile Access (SMA) VPN appliances through […] The post Proxying to Compromise: SonicWall Secure Mobile Ac…VOLEXITY.COM
17 JulErnst & Young (EY) Investigates Data Breach Involving Third-Party Support TicketsErnst & Young (EY) disclosed a data breach after attackers compromised a third-party IT support system containing client documents and tax information. Ernst & Young (EY) is disclosed a data breach linked to a compromised third-party support ticket system used by its IT t…SECURITYAFFAIRS.COM
16 JulTuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet DevelopmentCybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance from a large language model (LLM), albeit with not so successful results. "While th…THEHACKERNEWS.COM
16 JulGPT-Red beat human red teamers on a prompt injection testGPT-Red is an automated red-teaming model that OpenAI trains to find prompt injection weaknesses. It works the way a human red-teamer does. It sends a prompt, watches how a GPT model responds, and iterates toward a goal such as a successful data exfiltration. Training runs on sel…HELPNETSECURITY.COM
16 JulFinance phishing works because it sounds boringly normalFinance departments process a constant stream of invoices, contracts, payment notices, and procurement emails, making email one of the most common initial access vectors for threat actors. According to Cofense, attackers exploit those workflows with phishing emails that resemble …HELPNETSECURITY.COM
16 JulCaught on ScamTokThis week, while Maria is out hosts Dave Bittner and Joe Carrigan are discussing the latest in social engineering…THECYBERWIRE.COM
16 JulCompanies keep getting breached by vulnerabilities they already knew aboutScanning tools have gotten good at their work. Organizations now find more weaknesses across more of their systems than at any earlier point in the industry’s history. A survey from the security firm Vicarius points to a gap that opens after that discovery, in the work of a…HELPNETSECURITY.COM
16 JulReading between the lines of a cyber insurance policyEnterprises in regulated industries often carry cyber insurance policies because contracts require it or boards ask for documented risk transfer. The global market for these policies reached about $16 billion in premiums in 2024. Coverage has become widespread. Payouts have grown…HELPNETSECURITY.COM
16 JulWhat public money does to open-source projectsMost of the software running inside a typical company was written by volunteers the company never paid. Open-source code sits under web apps, build pipelines, and the machine learning stacks getting so much attention right now. Roughly 96 percent of codebases carry some of it. Th…HELPNETSECURITY.COM
16 Jul KEVFlaw surge fuels need for CISOs to rethink vulnerability managementSecurity experts are calling on enterprises to revise their vulnerability management strategies and move towards “just in time” patching in response the increased pace of vulnerability exploitation. Attackers are turning to AI to increase the rate of vulnerability exploitation an…CSOONLINE.COM
16 JulNightmare Eclipse Drops ‘LegacyHive’ Windows Zero-DayThe researcher stripped the proof-of-concept (PoC) exploit to prevent immediate exploitation of the vulnerability. The post Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulSrsly Risky Biz: Ransomware uses AI to amp up negotiationsTom Uren and James Wilson talk about different ways ransomware groups are taking advantage of AI. The relatively new FulcrumSec group uses simple techniques to breach companies and then uses AI to get more leverage over victims in its extortion negotiations. They also discuss the…RISKY.BIZ
16 JulThe executive profile your security team isn’t defendingA few years ago, I was retained to conduct a digital risk review for the chief executive of a mid-sized financial services firm. The brief was standard. Assess what was publicly available about the executive, identify exposure and advise on remediation. The AI tools I used comple…CSOONLINE.COM
16 JulUS Launches Gold Eagle to Coordinate AI-Driven Vulnerability ManagementThe White House announced Gold Eagle to help accelerate the discovery, prioritization and patching of flaws found by AIINFOSECURITY-MAGAZINE.COM
16 JulMicrosoft makes Windows SSO prompts easier to manageMicrosoft is introducing a new registry-based policy that lets IT administrators automatically accept Windows SSO permissions on Windows 11 versions 24H2 and 25H2 devices managed with Microsoft Entra ID. Users with personal Microsoft accounts and devices outside policy-managed en…HELPNETSECURITY.COM
16 JulOpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 SolOpenAI has disclosed details of GPT-Red, an internal automated red-teaming model that scales prompt injection vulnerability discovery with an aim to fix issues before the tools are deployed widely. "GPT‑Red is a strong red-teamer, and our previous models are highly vulnerable to …THEHACKERNEWS.COM
16 JulWhen AI gets a body, it inherits an attack surfaceMost security leaders I know working on AI robotics are being shown the same kind of video. A humanoid folds a shirt, sorts a bin, walks a warehouse aisle and a vendor uses the clip to move an embodied AI system from pitch to purchase order. Someone then has to sign off. Robot de…CSOONLINE.COM
16 JulF5 Patches Multiple NGINX, BIG-IP VulnerabilitiesAttackers could exploit the bugs to modify configurations, terminate or restart processes, cross security boundaries, leak memory, and execute code. The post F5 Patches Multiple NGINX, BIG-IP Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulTenable One unifies code risks with enterprise exposure dataTenable has announced the expansion of the Tenable One Exposure Management Platform, unifying application security risks with all other exposure data. By integrating static code vulnerability data, Tenable One delivers complete, code-to-runtime visibility across the entire attack…HELPNETSECURITY.COM
16 JulUnpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-WidePull the certificate off the flash of a Shark RV2320EDUS robot vacuum, and you can run root commands on other people's Shark vacuums across the same AWS region: watch the camera, drive the robot, read the map of the house, and take the Wi-Fi password in plaintext. A researcher pu…THEHACKERNEWS.COM
16 JulCISA urges software vendors to formalize vulnerability disclosure programsThe Cybersecurity and Infrastructure Security Agency (CISA) and four international cybersecurity agencies have published guidance urging software manufacturers and online service providers to establish coordinated vulnerability disclosure (CVD) programs, saying structured engagem…CSOONLINE.COM
16 Jul KEVCISA orders feds to patch actively exploited Oracle flaw by SaturdayCISA has ordered federal agencies to secure their systems by Saturday against ongoing attacks exploiting a critical vulnerability in the Oracle E-Business Suite financial application. [...]BLEEPINGCOMPUTER.COM
16 JulSpaceXAI admits Grok retained developer data in open-source announcementSpaceXAI has acknowledged that Grok Build retained coding data for some users during its early beta, days after security researchers disclosed that the AI coding tool was uploading entire developer repositories. Alongside the admission, the company announced it is open-sourcing t…CYBERINSIDER.COM
16 JulValorC3 extends SaaS protection with immutable cloud backupsValorC3 Data Centers today announced the general availability of Backup as a Service, a fully managed offering that protects the SaaS data businesses rely on most, including Microsoft 365, Entra ID and Salesforce. Every backup is immutable, so data stays recoverable after deletio…HELPNETSECURITY.COM
16 JulThe best defenders build AI agents together: Join Tenable for Swarm at Black Hat ’26Agentic AI use is exploding, yet most security teams are building agents in isolation. Tenable is hosting Swarm, a build event at Black Hat 2026, for security practitioners to create and collaborate on agentic, open-source tooling to drive collective defense and stop adversaries …TENABLE.COM
16 JulRussian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutesA Russian-speaking threat actor known as “bandcampro” used a jailbroken Gemini CLI, Google’s open-source terminal-based AI agent, to deploy and operate a small command-and-control (C2) botnet, according to TrendAI. Operational overview (Source: TrendAI) In more …HELPNETSECURITY.COM
16 JulAU: Regulator’s preliminary findings did not indicate Qantas breached privacy obligationsVlad Constantinescu reports that the Office of the Australian Information Commissioner has determined that although the Qantas data breach of 2025 resulted in 5.67 million customer records being compromised and leaked, the regulator’s preliminary inquiry did not indicate th…DATABREACHES.NET
16 JulThalha Jubair and Owen Flowers sentenced to prisonStanley Murphy-Johns, Rosie Shead, and Alex Levy report that Thalha Jubair, 20, and Owen Flowers, 18, were both sentenced at Woolwich Crown Court to 5 years and six months in prison for hacking Transport for London. In a televised sentencing, Mr Justice Turner addressed the defen…DATABREACHES.NET
16 JulModular macOS Stealer Uses Kill Loops to Force Password EntryNew ClickLock macOS stealer locked victims out of their own system until they surrendered a passwordINFOSECURITY-MAGAZINE.COM
16 JulCISA folds its own hard-won lessons into coordinated vulnerability disclosure guidanceOn Wednesday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and four allied cyber authorities published a guide telling software vendors how to build a coordinated vulnerability disclosure (CVD) program. Six days earlier, CISA published a blog post explaining h…HELPNETSECURITY.COM
16 JulSunsetting the Public AttackerKB PlatformWhat’s changing, where AttackerKB-style analysis will live, and how users can continue finding Rapid7 vulnerability intelligence. On August 18, Rapid7 will sunset the standalone public AttackerKB website as part of a broader effort to unify our vulnerability intelligence, exploit…RAPID7.COM
16 Jul KEVCISA warns of actively exploited SharePoint flaws.A new stealthy ransomware family emerges. Law enforcement operation disrupts international fraud scheme.THECYBERWIRE.COM
16 JulLegacy Systems, Real-World Impacts: The Reality of OT SecurityLegacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. The post Legacy Systems, Real-World Impacts: The Reality of OT Security appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulZoom patches account takeover holeZoom has identified, and patched, a critical security hole that “may allow an unauthenticated user to conduct an account takeover via network access.” The issue is especially significant given Zoom’s extensive reach; it reportedly has more than 300 million daily active users, inc…CSOONLINE.COM
16 JulTwo Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL HackOwen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five and a half years at Woolwich Crown Court on Thursday, 16 July 2026, for the 2024 hack of Transport for London. The attack left 148 TfL systems inoperable and forced all 27,000 of the transport authority's employ…THEHACKERNEWS.COM
16 JulVU#885548: Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditionsOverview A denial-of-service (DoS) vulnerability exists in some HTTP/2 server implementations that fail to adequately limit resource consumption when buffering response data under stalled flow-control conditions. A remote, unauthenticated attacker can trigger memory exhaustion an…KB.CERT.ORG
16 JulBTS #78 - Patching: The Race Against TimeIn this episode of Below the Surface, host Paul Asadoorian is joined by Vlad Babkin and Chase Snyder for a wide-ranging discussion on modern vulnerability management, network appliance visibility, AI-assisted exploitation, Linux kernel bugs, cold boot attacks, and software supply…ECLYPSIUM.COM
16 JulItaly fines WINDTRE €1.7 million over data breachesGianluca Semeraro reports: Italy’s data protection authority has fined telecoms operator WINDTRE €1.7 million ($1.94 million) for “serious shortcomings” in its data security systems, leading to two unauthorised breaches and the exposure of personal information belonging to more…DATABREACHES.NET
16 JulProgram to rotate cyber personnel through federal agencies saw little useThe number of people who got approval to be in the Federal Rotational Cyber Workforce program was in the single digits, GAO found. The post Program to rotate cyber personnel through federal agencies saw little use appeared first on CyberScoop .CYBERSCOOP.COM
16 JulClaude Chrome extension flaw lets malicious extensions trigger AI actionsA flaw in Anthropic's Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude's access to connected services such as Gmail, Google Docs, Google Calendar, and Salesfor…BLEEPINGCOMPUTER.COM
16 JulFor hackers, sharing is caring.CISA warns of active SharePoint attacks. The NSA pushes coordinated vulnerability disclosure. ClickLock Stealer targets macOS. Splunk and Zoom patch critical flaws. Spirals ransomware strikes in under 24 hours. New Windows evasion techniques emerge. LabubaRAT poses as NVIDIA soft…THECYBERWIRE.COM
16 Jul1999 Called and It Wants It's Exploits Back - PSW #935This week, our technical segment covers a new open-source tool written by Paul (and Claude) that helps you keep your Linux systems up to date and assess supply chain risks. It's called "fettle" and is a pure Python implementation that gives you even more features than previously …YOUTUBE.COM
16 JulNew ClickLock macOS malware traps users into revealing login passwordA new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password. [...]BLEEPINGCOMPUTER.COM
16 JulCoca-Cola says Fairlife ransomware attack halts US dairy productionThe Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily suspending production of Fairlife products across the United States. [...]BLEEPINGCOMPUTER.COM
16 JulThe Breach That Won’t End: An Update on Canvas, and how they created an EdTech’s Vendor Trust ProblemJeff Piontek comments on the Instructure breach: The forensic review has taken far longer than anyone expected. Through June, Instructure was still finalizing customer-specific findings and asking institutions to designate a security contact to receive them. In early July, the co…DATABREACHES.NET
15 JulMicrosoft Patches Record 622 Flaws, Including Two Zero-Days Under Active AttackMicrosoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft's own CVEs by its Security Update Guide count, more than triple June's previous high of around 2…THEHACKERNEWS.COM
15 JulICYMI: June 2026 @AWS SecurityRead all about the latest AWS security features, compliance updates, and hands-on resources in our new, monthly digest posts. You’ll find expert blog posts, new service capabilities, code samples, and workshops. AWS Security Blog posts This month’s AWS Security Blog posts covered…AWS.AMAZON.COM
15 JulShareFile explained, healthcare in critical cyber condition and click fix tops malware chartsShareFile emergency explained, a year of Salesforce breaches examined, healthcare cybersecurity in critical condition and click fix goes number one for malware. David Shipley covers Progress Software's emergency ShareFile shutdown, now tied to a previously unknown high-severity p…CYBERSECURITYTODAY.LIBSYN.COM
15 JulAI used to help plan the break-in, now it’s doing the break-inOver the past twelve months, researchers documented intrusions in which AI ran exploitation workflows autonomously, generating thousands of commands across dozens of sessions with minimal human direction, according to Check Point’s AI Security Report 2026. AI-powered cyber attack…HELPNETSECURITY.COM
15 JulThe MDR renewal question: What changes when AI can handle the alertsFor most of the past decade, the managed detection and response (MDR) decision was a simple one: teams that couldn’t staff a 24/7 SOC outsourced detection and response to a provider who could. It solved a resources problem, and the alternatives (hiring a team you couldnR…HELPNETSECURITY.COM
15 JulGoose Creek - 6,574,121 breached accountsIn June 2026, a party claiming to have access to data from Goose Creek Candle Company sent emails to a number of the company's customers , claiming the company had a security vulnerability and suffered a data breach. The data was subsequently sent to Have I Been Pwned and contain…HAVEIBEENPWNED.COM
15 JulSingGuard-NSFA: Open-source guardrails for agentic AISingGuard-NSFA is an open-source guardrail framework aimed at operational threats in agent workflows. Four models ship at 0.8B, 2B, 4B, and 9B parameters, all built on Qwen3.5 base backbones. Risk taxonomy The NSFA risk taxonomy organizes threats along the CIA triad of confidenti…HELPNETSECURITY.COM
15 Jul7 skills and traits of elite security engineersSecurity engineers play a pivotal role in enterprise cybersecurity, because they are the professionals who design, build, and deploy security systems to protect an organization’s data, applications, systems, networks, and other IT components against a variety of cyber threats. Fi…CSOONLINE.COM
15 JulCritical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 UpdatesPublic exploit code targeting the Firefox flaws exists, but no in-the-wild exploitation has been observed. The post Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates appeared first on SecurityWeek .SECURITYWEEK.COM
15 JulNigeria Deepens Cybersecurity Efforts as Cybercriminals See More ProfitsThe West African country advanced rules to force organizations to disclose cyberattacks, joining other nations in a shift to mandated transparency.DARKREADING.COM
15 JulFortinet adds AI controls and data loss prevention to FortiEndpointFortinet has announced new capabilities for its unified endpoint platform, FortiEndpoint, designed to help organizations securely adopt AI, protect sensitive data, and reduce risk. By bringing AI visibility and control, native data security, endpoint risk scoring, and FortiAI-ass…HELPNETSECURITY.COM
15 JulCybersecurity needs more prevention and less reliance on cureAsk any medical doctor, and they’ll tell you that prevention is better than cure. It’s more cost-effective and it has better outcomes. The same is true in cybersecurity. But we believe that our industry has veered too far away from this simple concept. We observe that most new to…CSOONLINE.COM
15 JulSonicWall warns of active exploitation of two SMA 1000 zero-daysSonicWall warns of active attacks exploiting two SMA 1000 zero-days, including a flaw enabling arbitrary command execution. SonicWall confirmed the active exploitation of two zero-day vulnerabilities affecting Secure Mobile Access (SMA) 1000 appliances. The vulnerabilities were i…SECURITYAFFAIRS.COM
15 JulCompromised AsyncAPI npm Packages Deliver Multi-Stage Botnet MalwareFour compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security, SafeDep, Socket, and StepSecurity. The affected packages are listed below - @asyncapi/generator-helpers@1.1.1 @asyncapi/ge…THEHACKERNEWS.COM
15 Jul KEVTake Back Control as Enterprises Struggle to Incorporate Risks They Don't Understand - BSW #456More than 48,000 vulnerabilities were disclosed in 2025, yet only about 1% are actively exploited. However, you’re expected to mitigate all vulnerabilities, or at least critical and high. But what if there is no patch to fix the vulnerability or the software is unsupported? Ben L…YOUTUBE.COM
15 JulMicrosoft Patches 570 CVEs in Record Patch TuesdayMicrosoft released fixes for a record 570 CVEs in its July Patch Tuesday update, as experts warn AI is dramatically accelerating vulnerability discovery and increasing patch volumesINFOSECURITY-MAGAZINE.COM
15 Jul KEVCISA warns admins to patch actively exploited SharePoint flawsThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances. [...]BLEEPINGCOMPUTER.COM
15 JulProgress Confirms Zero-Day Vulnerability Behind ShareFile DisruptionThe company has rolled out a fix and is restoring access for Storage Zones Controller customers who apply it. The post Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption appeared first on SecurityWeek .SECURITYWEEK.COM
15 JulCursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code ExecutionOpen a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning that anything in the folder is about to execute. Whatever that binary does, it does as you, with your source…THEHACKERNEWS.COM
15 JulChrome Sync increasingly abused to stalk unsuspecting victimsCyberstalkers are increasingly exploiting Google Chrome's built-in synchronization feature to secretly monitor victims' web activity without installing spyware or compromising their devices. Security firm Certo says it has received a growing number of reports involving the tactic…CYBERINSIDER.COM
15 JulWhite House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination InitiativeThe new program stems from an AI-focused Executive Order signed by President Trump on June 2. The post White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative appeared first on SecurityWeek .SECURITYWEEK.COM
15 JulClickFix is changing the economics of social engineeringClickFix has moved from a one-off social engineering trick into an industrialized attack ecosystem that is outpacing conventional antivirus and endpoint defenses, according to ReversingLabs. The technique first showed up in late 2023 and early 2024, and Proofpoint named it in mid…HELPNETSECURITY.COM
15 JulProgress Restores ShareFile Storage Zones Access After Vulnerability Exploit ConcernsProgress has restored access to its ShareFile Storage Zones Controller after a four-day suspension triggered by a credible external security threatINFOSECURITY-MAGAZINE.COM
15 JulPolygraf AI Meeting Guard delivers real-time deepfake detection for enterprise meetingsPolygraf AI has announced Meeting Guard, a real-time AI fraud detection solution for enterprise meetings built to detect fraud and protect meeting security. AI can clone a voice, animate a face, and answer every interview question in real time, making trust signals obsolete acros…HELPNETSECURITY.COM
15 JulResearcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch TuesdaySecurity researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive. It has been described as a Windows User Profile Service arbitrary hive load elevation of privileges vulnerability. The Windows User Profile Service, al…THEHACKERNEWS.COM
15 JulNew Windows Bind Link techniques let attackers evade EDR, security controlsAttackers who already have administrator privileges on a Windows machine have newer ways to slip past endpoint security without exploiting a vulnerable driver or modifying trusted binaries. Bitdefender researchers have warned against three techniques that abuse Windows Bind Links…CSOONLINE.COM
15 JulWhite House launches AI-driven vulnerability clearinghouse to speed cyber remediationThe White House is expanding the use of AI beyond cyber threat detection into vulnerability management, launching a new program that aims to help government agencies and critical infrastructure operators identify, prioritize, and remediate software vulnerabilities faster. Called …CSOONLINE.COM
15 JulNew bugs in Claude for Chrome allow extensions to abuse AI privilegesTwo vulnerabilities found in Anthropic’s Claude for Chrome extension remain exploitable months after they were reported to the company, a research by Manifold Security noted. According to the researchers, the flaws can allow a malicious browser extension to trigger Claude into pe…CSOONLINE.COM
15 Jul5 reasons to bring application security data into your exposure management platformWhen you incorporate data from application security scanners into your exposure management platform, you can assess the threat from formerly isolated code flaws using a broader risk context, which illuminates hidden exposures that your security and development teams can eliminate…TENABLE.COM
15 JulJuly 2026 Patch Tuesday fixes 622 Microsoft CVEs, including three zero-daysMicrosoft's July 2026 Patch Tuesday sets yet another record, fixing 622 Microsoft CVEs—three times as many as last month.MALWAREBYTES.COM
15 JulMicrosoft smashes Patch Tuesday record for second successive monthVulnerability counts have been surging this year, and Microsoft's mammoth disclosure this week of 622 bugs is larger than the three previous months combined.THERECORD.MEDIA
15 JulCompromised Logins Surge as the Most Common Entry Point for Ransomware AttacksResearch of incidents by Sophos finds that phishing, brute force attacks and other identity-based threats have surpassed software vulnerabilities as means of delivering ransomwareINFOSECURITY-MAGAZINE.COM
15 Jul2-Click Cursor Exploit Enables Dev Environment TakeoverSimple age-old bugs give bad actors access to developers' secrets and source code-rich environments.DARKREADING.COM
15 JulNayax updates its incident status; states it won’t pay any extortion demandIt’s common for victims and threat actors to disagree sharply over the scope of an attack or its significance. Today’s example involves Israeli fintech Nayax and a group called The Syndicate. In previous coverage, DataBreaches cited Nayax’s submission to the Sec…DATABREACHES.NET
15 JulAU: Partnered Health Data Breach Exposes Patient Records at Family ClinicsTrevor Long reports: A large health care chain that owns family medical clinics across Australia has been the victim of a cyber breach which has exposed the data of their patients, including potentially treatment information. Partnered Health runs a large number of clinics across…DATABREACHES.NET
15 JulAsyncAPI npm Supply Chain Attack: Malware Injected Into Packages With 2 Million Weekly DownloadsAsyncAPI npm packages with 2M weekly downloads were compromised, spreading malware with info-stealing, crypto-theft and RAT capabilities. OX Security researchers disclosed on July 14 that the AsyncAPI npm organization was compromised, with malicious code injected into four packag…SECURITYAFFAIRS.COM
15 JulWe built a vulnerability vending machine: AI tokens in, zero-days outIntruder built an AI-powered "vulnerability vending machine" that combines code slicing with LLMs to automatically discover complex software vulnerabilities. The company explains how the system found and exploited a previously unknown WordPress plugin zero-day, with additional di…BLEEPINGCOMPUTER.COM
15 JulF5 Insight for ADSP enhances BIG-IP operations with guided updates and AI audit trailsF5 has announced new fleet management capabilities for F5 Insight for ADSP that help enterprises reduce risk exposure across F5 BIG-IP environments as frontier AI compresses vulnerability response timelines. The new F5 Insight workflows give security and operations teams fleet-wi…HELPNETSECURITY.COM
15 JulInvestigating Persistence Mechanisms in AWSOverview In the cloud, your infrastructure may be short-lived, but an attacker’s persistence doesn't have to be. While your environment scales and changes in seconds, adversaries are embedding themselves into your IAM policies, Lambda functions, and federated sessions, creating i…RAPID7.COM
15 JulAttackers Find Bugs Before CVEsResponsible disclosure gives vendors time to develop patches before vulnerabilities are publicly disclosed. That process can take months, while attackers may already be searching for and exploiting the same weaknesses. By combining AI with large-scale vulnerability data, security…YOUTUBE.COM
15 JulClaude for Chrome flaw could let rogue extensions access your GmailThe ClaudeBleed vulnerability still lets malicious Chrome extensions abuse Claude for Chrome's permissions.MALWAREBYTES.COM
15 JulUnpatched Cursor Vulnerability Exposes Users to Code ExecutionAn attacker can create a malicious repository containing a git.exe in the project root, and Cursor executes it automatically. The post Unpatched Cursor Vulnerability Exposes Users to Code Execution appeared first on SecurityWeek .SECURITYWEEK.COM
15 Jul KEVCISA Urges Immediate Patching of Exploited SharePoint VulnerabilitiesThree vulnerabilities are actively exploited in attacks, including two that have been targeted as zero-days. The post CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
15 JulUnderstanding Claude Tag’s access model in Slack and how to configure it securelyAnthropic’s new AI agent for Slack acts under an admin-configured access bundle rather than each user’s own credentials. Here’s how that model works, what admins should understand and how to securely configure it. Key takeaways Claude Tag, Anthropic’s newly launched AI agent for …TENABLE.COM
15 JulPatch Tuesday notes: Microsoft fixes a record 570 flaws.SonicWall warns of a maximum-severity zero-day. Business news: Valarian raises $50 million in Series A funding.THECYBERWIRE.COM
15 JulCISA warns that multiple vulnerabilities in SharePoint are under exploitationSecurity researchers say additional flaws are being chained together and a patch will not be available until August.CYBERSECURITYDIVE.COM
15 JulUS launches vulnerability clearinghouse amid AI-fueled surge in flawsThe Trump administration hopes the program will accelerate the discovery and fixing of serious technical problems before hackers exploit them.CYBERSECURITYDIVE.COM
15 JulClaude Flaw Automatically Sends Malicious Prompts to AI AgentsWhen combined with another exploit, the "PromptFiction" vulnerability, which has been fixed, could have enabled an end-to-end attack on a targeted system.DARKREADING.COM
15 JulChaotic Eclipse Unveils LegacyHive Exploit Affecting Fully Patched Windows SystemsLegacyHive PoC exposes a Windows Privilege Escalation flaw affecting fully patched Windows desktop and server systems. Just hours after Microsoft’s July 2026 Patch Tuesday, security researcher Nightmare Eclipse, also known as Chaotic Eclipse, published a new Windows zero-da…SECURITYAFFAIRS.COM
15 JulMicrosoft patches bug in video game Age of Empires IIThe vulnerability in the decades-old game could have allowed hackers to take over victims’ computers with a malicious game invite.TECHCRUNCH.COM
15 JulHack suggests AI music generator Suno scraped YouTube for training dataThe hacker used an employee's credentials to access source code, which revealed how Suno scraped decades of audio.TECHCRUNCH.COM
15 JulSonicWall customers under threat as attackers exploit 2 zero-daysResearchers said the vulnerabilities, which attackers are chaining together, were first exploited three weeks before the vendor disclosed and patched the defects. The post SonicWall customers under threat as attackers exploit 2 zero-days appeared first on CyberScoop .CYBERSCOOP.COM
15 JulGoogle Gemini CLI abused as a hacking agent, malware botnet operatorA Russian-speaking threat actor known as "bandcampro" used Google's open-source Gemini CLI AI tool as a hacking agent and to operate a small-scale botnet. [...]BLEEPINGCOMPUTER.COM
15 JulGuten Tag, Bonjour, Hola to Our European Cyber Defenders!We're thrilled to unveil the latest evolution of Dark Reading's DR Global section — your go-to source for region-specific cybersecurity intelligence beyond North America.DARKREADING.COM
15 JulWilmerHale Sued Over Client Personal Information Data BreachAlex Ebert reports: Wilmer Cutler Pickering Hale & Dorr should pay millions of dollars in damages for loss of clients’ personal information in a May data breach, a putative class action claims. The lawsuit, filed Tuesday in the US District Court for the District of Columbia, …DATABREACHES.NET
15 JulFiles relating to India’s largest nuclear power plant Kudankulam exposed in data breachMunsif Vengattil and Aditya Kalra Ransomware group World Leaks has posted on the dark web a huge cache of files related to India’s largest nuclear plant, including purported blueprints of parts of its facilities and supplier details — information it labelled as coming from…DATABREACHES.NET
15 JulNPM ecosystem hit with two new supply chain compromisesAttacks targeting developer ecosystems are increasing in frequency and sophistication, with Node.js developers firmly in this week’s crosshairs, as multiple npm packages belonging to the open-source AsyncAPI and Jscrambler Code Integrity were poisoned with malware following compr…CSOONLINE.COM
15 Jul KEVPatchapalooza packs a punch.Patch Tuesday. SonicWall urges immediate patching of actively exploited vulnerabilities. The White House launches an AI-backed vulnerability clearinghouse. The Air Force contends with widespread cybersecurity quarantines. The UK and EU blame Russia for last year’s cyberattack on …THECYBERWIRE.COM
15 JulSecurity researchers find stalkers abusing Chrome’s sync featureCerto Software warns that the capability, designed for convenience, can easily be used to spy on online activity. The post Security researchers find stalkers abusing Chrome’s sync feature appeared first on CyberScoop .CYBERSCOOP.COM
15 JulZoom warns of critical account takeover vulnerabilityZoom is warning of a critical vulnerability in its desktop client and software development kit for Windows that could be exploited by an unauthenticated party to hijack accounts. [...]BLEEPINGCOMPUTER.COM
15 JulIdentity Attacks Overtake Exploits as Top Ransomware CauseEmail attacks overtook exploits as the top ransomware root cause last year. Multifactor authentication (MFA) was deployed in 97% of credential-based attacks but failed to prevent compromise.DARKREADING.COM
15 JulCalgary 911 employee charged with breach of trustManjot Singh reports: Calgary police say a City of Calgary 911 employee has been charged following an investigation into the unauthorized disclosure of confidential information. Police say the investigation began in January after allegations that sensitive information was being a…DATABREACHES.NET
15 JulUS and allied Governments’ Recommendations: Securing Network Devices Against Russian APT GroupsUS and allies warn of Russian APT groups targeting routers and network devices to compromise critical infrastructure worldwide. The US and allied governments warn that Russian state-sponsored APT groups are scanning and exploiting poorly secured network devices, especially router…SECURITYAFFAIRS.COM
15 Jul“AI Normal Tech” vs “AGI by Tuesday”: Security Advice That Survives Either FutureIf you look at social media debates about AI, two extreme patterns emerge. Studying extreme patterns is very useful because understanding boundary conditions helps you understand the whole phenomenon — in this case of security in AI adoption (recent extreme example ). You can als…MEDIUM.COM
14 JulBetween Two Nerds: Exploits are not cyber powerIn this edition of Between Two Nerds Tom Uren and The Grugq discuss just how important exploits are for cyber operations using data published in a new paper authored by two members of Ukraine’s cyber security agency. This episode is also available on YouTube.RISKY.BIZ
14 JulAI Security Report 2026For years, the cyber security industry tracked AI as a force multiplier: something that made existing attack techniques faster, cheaper, and more accessible. That framing was accurate. But the Annual AI Security Report 2026 from Check Point Research documents a transition that go…RESEARCH.CHECKPOINT.COM
14 JulChatto: Open-source team messenger with privacy at its coreTeams that want their group chats off commercial platforms have a growing menu of self-hosted options. Chatto joined that group when its developer released the code under an open-source license and posted binaries for anyone to run on their own hardware. The software aims at the …HELPNETSECURITY.COM
14 JulThe best defense against AI attacks turns out to be a skeptical humanAnalysts across the security industry now run generative AI through their daily work, from log triage to incident write-ups. Active use in cybersecurity strategy reached 78% of practitioners in 2026, up from half the field a year earlier. The 2026 SANS AI Survey, drawn from 536 I…HELPNETSECURITY.COM
14 JulFake smart home residents could stand in for real ones in security researchSmart home security research runs on a scarce ingredient: recordings of how real people use the gadgets in their homes. Getting that data means wiring up someone’s house and watching for months, which is slow, costly, and about as invasive as it sounds. So the datasets stay…HELPNETSECURITY.COM
14 JulMicrosoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three PathsAttackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform. The way in has been the trust the organization had already extended, usua…THEHACKERNEWS.COM
14 JulPentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity RulesA new CMMC review and reform task force will conduct a comprehensive review of the program. The post Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulNew tutorials on underground hacking forums have roughly doubledUnderground hacking forums are producing more original tutorials again, with growing attention on financial fraud, particularly the theft and fraudulent use of payment card data, known as carding, and cash-out techniques. New tutorials per month versus reposts (Source: Radware) F…HELPNETSECURITY.COM
14 JulDiscovering & Securing Your AI Agent Attack Surface - Jeremy Snyder - ASW #391While LLMs and agents are new to appsec and everyone else, a lot of AI security requirements translate to well-known API security requirements. Jeremy Snyder helps us frame the OWASP LLM Top 10 into five layers in order to help orgs understand and prioritize their attack surface.…YOUTUBE.COM
14 JulRapid7 and Mindshare Partner to Accelerate Cyber Resilience Across the Middle EastGopan Sivasankaran is Regional Director, Middle East & Africa, at Rapid7 From AI adoption and cloud-first strategies to smart cities and critical infrastructure modernization, organizations across the United Arab Emirates are embracing innovation at an unprecedented rate. The cou…RAPID7.COM
14 JulGrok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It ReadsxAI's Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not just the files a coding task needed. A researcher publishing as cereblab, testing version 0.2.93, captured one of those uploads, cloned…THEHACKERNEWS.COM
14 JulAI incidents need a new playbook. Here’s how to build oneSeventy-one percent of organizations say AI has access to core business systems. Only 16% govern that access effectively, according to the 2026 CISO AI Risk Report . Ask your IR team three questions: Where is your AI system inventory? What happens if a production model starts gen…CSOONLINE.COM
14 JulThe inside job that cost ransomware victims millionsInstead of helping victims negotiate with BlackCat, a trusted ransomware negotiator secretly helped the gang extort them.MALWAREBYTES.COM
14 JulMalware Hits Japan’s Largest Taxi Company Nihon Kotsu, Services Temporarily SuspendedJapan’s largest taxi operator Nihon Kotsu shut down systems after a malware attack, disrupting dispatch and bookings. Nihon Kotsu, Japan’s largest taxi company, disclosed on July 13, 2026 that its internal systems suffered an unauthorized external access involving mal…SECURITYAFFAIRS.COM
14 JulThe serpent’s tongue: Luring the Python out of its denThis blog examines the full lifecycle of a Python package, from hosting on repositories such as PyPI or custom web servers, through source and wheel distribution formats, to the final installation into virtual or system-wide Python environments.TALOSINTELLIGENCE.COM
14 JulInside China's Cyber Espionage BusinessAhana Datta Fasel became the British government’s first ethical hacker in 2014, testing vulnerabilities in computer systems and networks that hackers could potentially exploit. She was only 23, but that gave her an early look at state-sponsored cyber intrusions, which have of cou…THECYBERWIRE.COM
14 JulGoogle adds FIDO2 keys and phone passkeys to Windows login via GCPWGoogle has started rolling out FIDO2-compliant physical security key support as a second factor for authentication in Google Credential Provider for Windows (GCPW) to all Google Workspace customers. GCPW is a free tool that lets users sign in to Windows computers with their Googl…HELPNETSECURITY.COM
14 JulVulnerability in FIFA’s NetworkFIFA’s network was vulnerable to anyone with even minimal access.SCHNEIER.COM
14 JulWarning: Scammers are using FaceTime to empty bank accountsCybercriminals are combining social engineering through apps like FaceTime with unpatched devices to steal credentials and drain bank accounts.MALWAREBYTES.COM
14 JulNew MacOS Malware Exploits Legitimate Developer ID to Pose as Apple Crash ReporterResearchers at Jamf Threat Labs detail CrashStealer, which steals passwords, cryptocurrency wallets and moreINFOSECURITY-MAGAZINE.COM
14 JulSAP warns of critical flaws in NetWeaver and Commerce CloudSAP has addressed 16 vulnerabilities across multiple products as part of its July 2026 security updates, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter. [...]BLEEPINGCOMPUTER.COM
14 JulSAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce CloudThe flaws could allow attackers to access and modify data, and cause system unavailability and request-response desynchronization. The post SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulUnpatched Claude for Chrome Flaw Lets Extensions Read Gmail, CalendarA ClaudeBleed-linked vulnerability reportedly persists across eight patches, exposing potentially sensitive data to other extensions. The post Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulCursor IDE Auto-Executes Malicious Code in Poisoned ReposResearchers reported the vulnerability to Cursor in December, but it still remains in the popular AI coding platform and can be exploited in poisoned repository attacks.DARKREADING.COM
14 Jul“Context bombs” can frustrate AI-driven attacks, researchers foundA new approach tried out by Tracebit researchers has proven very effective at stopping AI agents from fully compromising targeted environments. What makes it notable isn’t the technique – prompt injection is old news – but the direction it’s pointed: not t…HELPNETSECURITY.COM
14 Jul11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure BootCybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Secure Boot on most systems using the modern firmware standard. "An attacker exploiting one of these vulnerable application…THEHACKERNEWS.COM
14 JulYou Don't Have to Run an Exploit to Know If You're VulnerableMany vulnerabilities cannot be safely validated with live exploits, either because no exploit exists or the affected systems are too critical to test. Picus explains how TTP chaining helps organizations determine exploitability by validating the attack techniques an exploit depen…BLEEPINGCOMPUTER.COM
14 Jul7 Severe Vulnerabilities Patched in VMware Avi Load BalancerThe flaws can be exploited for authentication bypass, remote code execution, privilege escalation, and directory traversal. The post 7 Severe Vulnerabilities Patched in VMware Avi Load Balancer appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulRabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue MetadataCybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enterprise messaging infrastructure to takeover risks, and bypass tenant boundaries. …THEHACKERNEWS.COM
14 JulIran abused mobile networks’ vulnerabilities to locate US military in the Middle East, report saysThe Iranian government exploited well-known flaws in cellphone networks to locate and then strike U.S. military personnel in the build-up and beginning of the war.TECHCRUNCH.COM
14 JulGrapheneOS says Google will cut security backports for older Android releasesGrapheneOS claims Google has significantly reduced security patch backports for older Android versions. This change could leave devices on previous releases with fewer vulnerability fixes despite continuing to receive monthly security updates. Google has not publicly documented t…CYBERINSIDER.COM
14 JulProgress confirms ShareFile zero-day flaw behind Storage Zone shutdownProgress Software has confirmed that a high-severity zero-day vulnerability is behind the emergency shutdown of ShareFile Storage Zone Controllers last week and has released security updates to patch the flaw. [...]BLEEPINGCOMPUTER.COM
14 JulMicrosoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-daysToday is Microsoft's July 2026 Patch Tuesday, and with it comes security updates for a record-breaking 570 flaws, including two zero-day vulnerabilities exploited in attacks and one publicly disclosed. [...]BLEEPINGCOMPUTER.COM
14 JulMicrosoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-DaysTwo flaws in Active Directory and SharePoint Server have been exploited as zero-days, and a BitLocker bug was publicly disclosed. The post Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulDoxbin admin jailed for egging on swatters from behind a screenConnor Jones reports: A Welshman was sentenced to prison on Tuesday for his role in numerous swattings in the UK, US, and Canada. Callum Dare, 26, was an administrator of Doxbin, a dark web platform frequented by individuals that expose the personally identifiable information (PI…DATABREACHES.NET
14 JulMicrosoft Patches a Record 570 Security FlawsMicrosoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attribu…KREBSONSECURITY.COM
14 JulMicrosoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)This patch Tuesday includes a staggering&#;x26;#;xc2;&#;x26;#;xa0;622 vulnerabilities, not including another 427 vulnerabilities in Chromium, affecting Microsoft&#;x26;#;39;s Edge browser. 62 of t…ISC.SANS.EDU
14 Jul KEVThe ransomware toll road.Treasury sanctions a VPN provider tied to ransomware. The Pentagon hits pause on CMMC audits. Critical flaws surface in Google Cloud’s Dialogflow CX. Estée Lauder discloses a data breach. Mobile networks become a battlefield for tracking U.S. personnel. Australia calls out Big Te…THECYBERWIRE.COM
14 JulMicrosoft discloses ‘the mother of all’ vulnerability loads, tripling June’s previous recordThe company forewarned customers and defenders that a flood of defects would be uncovered by AI. It delivered with a striking exponential increase. The post Microsoft discloses ‘the mother of all’ vulnerability loads, tripling June’s previous record appeared first on CyberScoop .CYBERSCOOP.COM
14 JulDefending SaaS-based applications against ShinyHunters OAuth abuseFrom Microsoft Security Research and Microsoft Defender Security Research Team: In a series of campaigns observed between mid-2025 and mid-2026, Microsoft identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing …DATABREACHES.NET
14 Jul KEVMicrosoft rolls out massive Windows 11 security update with 416 fixesMicrosoft has released the July 2026 Patch Tuesday cumulative updates for Windows 11, fixing hundreds of security vulnerabilities while introducing Secure Boot improvements, security hardening changes, and compatibility fixes. The updates also patch a publicly disclosed BitLocker…CYBERINSIDER.COM
14 JulRecords Are Made to Be Broken: Patch Tuesday Raises Triage StakesThree of the 622 CVEs for which Microsoft issued patches this week are zero-days; there are more than 60 critical vulnerabilities.DARKREADING.COM
14 JulElon Musk promises to delete all data following a leak of users’ confidential informationAbror Shuhratov reports: xAI, the company founded by Elon Musk, has announced emergency measures following a serious controversy involving the unauthorized uploading of users’ private code and confidential information to a server via the Grok Build CLI tool. The companyR…DATABREACHES.NET
14 JulSynopsys Finds No Evidence of Data Breach Amid Bosch Hack ClaimsEduard Kovacs reports: A new ransomware group named D1R in recent days listed Synopsys and Bosch on its Tor-based leak website. The cybercriminals claimed to have exploited a vulnerability in Synopsys’ website to access a corporate client database containing 40,000 entries, and t…DATABREACHES.NET
14 JulFinland issues wanted notice for hacker behind massive psychotherapy data breachI was really unpleasantly surprised when they let him out while on appeal, and now they may not be able to return him to prison? Did no one foresee that he might not stick around to be sent back to prison? Daryna Antoniuk reports: Finnish police have reportedly issued a wanted no…DATABREACHES.NET
14 JulRewards For Justice offers reward for info on Media Land, ML.Cloud, and three individuals associated with itRewards for Justice announced a $10M reward for information on the Russian-based bulletproof hosting (BPH) services company Media Land, its associated company ML.Cloud, and associated staff Aleksandr Alexandrovich Volosovik, Kirill Andreevich Zatolokin, and Yuliya Vladimirovna Pa…DATABREACHES.NET
14 JulPatch Tuesday security updates for July 2026, the largest update ever. 621 CVEs in one monthPatch Tuesday: Microsoft fixes a record 621 CVEs, including 2 exploited zero-days and critical flaws affecting SharePoint, RDP, Hyper-V, and AD FS. Microsoft’s July 2026 Patch Tuesday is, by a significant margin, the largest single-month security release in the company̵…SECURITYAFFAIRS.COM
14 JulSN 1087: HalluSquatting, GhostApproval & GitLost - Patch Tuesday Breaks RecordsAI is rewriting the rules of cybersecurity, and this week, massive government and private sector moves show just how quickly the stakes are rising. Find out how regulators, attackers, and defenders are all scrambling to keep up as vulnerabilities surface at record speed. Europe w…TWIT.TV
13 JulShareFile shutdown, double-agent ransomware negotiator sentenced, Helix uses vishingShareFile shutdown order, a double-agent ransomware negotiator sentenced, and vishing crews raid SharePoint Progress Software ordered customers running ShareFile Storage Zone Controllers to shut down the Windows servers immediately amid a credible external threat, offering no CVE…CYBERSECURITYTODAY.LIBSYN.COM
13 Jul99.9% of fixable AI vulnerabilities remain unpatchedOrganizations build, deploy, and operate AI in the cloud, but basic cybersecurity hygiene is often sacrificed for speed, according to Orca Security’s 2026 State of AI Security Report. Building AI without security Fifty-six percent of AI adopters have deployed agent frameworks int…HELPNETSECURITY.COM
13 JulCynative: Open-source deep research agentRunning a large language model against a live cloud account to hunt for security holes comes with an obvious hazard. An agent that holds real credentials and a mandate to poke around can delete a bucket, flip a permission, or leak a secret on its way to a finding. Cynative, an op…HELPNETSECURITY.COM
13 JulCan AI narrow cybersecurity’s class divide?At Amazon Web Services (AWS), artificial intelligence is already compressing security work that once took months into minutes. In the old world, human red teams would find vulnerabilities, write reports, refine those reports, and eventually hand them to defenders, who would then …CSOONLINE.COM
13 JulCopy-paste might be the riskiest thing your enterprise employees do all dayThis source of data leakage takes them less than a second and happens hundreds of times a day.CYBERSECURITYDIVE.COM
13 JulAustralian Cyber Agency Warns of Global CMS Exploitation CampaignAustralian Cyber Security Centre warns CMS users of mass scanning and exploitation campaignINFOSECURITY-MAGAZINE.COM
13 JulAustralia Alerts Organizations to Ongoing CMS Exploitation AttacksAustralia warns of a global campaign exploiting CMS flaws to deploy webshells on WordPress, Joomla, and other websites. Australia’s Signals Directorate has issued an alert about a large-scale exploitation campaign actively targeting content management systems (CMS) worldwid…SECURITYAFFAIRS.COM
13 JulJurassic Park, cybersecurity and the dangerous myth of controlJurassic Park wasn’t really about dinosaurs. It was about arrogant people building systems they believed were controllable. “Life finds a way” is probably the most famous line from the entire franchise. Ian Malcolm’s warning that no matter how sophisticated the technology becomes…CSOONLINE.COM
13 JulYour AI risk register is not an incident response planPicture the moment after an AI issue is reported. A security analyst is reviewing a ticket reporting that an internal AI tool produced the wrong recommendation in a live business workflow. The risk is not theoretical anymore. Someone wants to know whether this is a security incid…CSOONLINE.COM
13 JulHungry? We talk Smoked Meat, Poutine, and Bagel - also, Identiverse Interviews! - ESW #467Interview with François Proulx from Boost Security Software Supply Chain Security: Build Pipeline (CI/CD) Exploitation Boost Security is the creator of some very popular build pipeline security tools, like Bagel and Poutine. Today, we discuss their latest tool, Smoked Meat. They …YOUTUBE.COM
13 JulZimbra Patches Critical Code Execution VulnerabilityThe flaw results in malicious code embedded in crafted emails being executed when the emails are opened. The post Zimbra Patches Critical Code Execution Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
13 JulOrganizations Warned of Exploited Joomla Extension VulnerabilitiesThreat actors have been targeting Balbooa Forms and iCagenda Joomla extension flaws for remote code execution. The post Organizations Warned of Exploited Joomla Extension Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
13 JulIntel agencies warn of Russian state hackers targeting routers worldwideA coalition of 21 cybersecurity and intelligence agencies has warned that Russian state-sponsored hackers continue to compromise internet-facing routers by exploiting weak configurations and known vulnerabilities, enabling them to steal device configurations and gain insight into…CYBERINSIDER.COM
13 JulRabbitMQ Vulnerability Threatens Enterprise SystemsUnauthenticated attackers could obtain the broker's confidential OAuth client secret, allowing them to take control of the broker. The post RabbitMQ Vulnerability Threatens Enterprise Systems appeared first on SecurityWeek .SECURITYWEEK.COM
13 JulTurning the Tables on Email Scammers With 'ScamBuster'An open source, AI-driven system adopts victim personas to engage with phishing attackers, allowing organizations and law enforcement to gather relevant data on cybercriminal operations.DARKREADING.COM
13 JulRansomware negotiator who betrayed clients sentenced to 70 months in prisonA former ransomware negotiator at incident response firm DigitalMint has been sentenced to 70 months in prison after admitting he shared confidential client information with the BlackCat ransomware group and later helped carry out ransomware attacks. Prosecutors say Angelo Martin…HELPNETSECURITY.COM
13 JulEU and UK hit Russia with joint sanctions over cyberattacksBGNES News reports: The European Union and the United Kingdom have imposed coordinated sanctions against Russia in connection with cyberattacks in Europe. Brussels and London have accused the Federal Security Service of the Russian Federation (FSB) of recent malicious activities.…DATABREACHES.NET
13 JulA cyberattack in March resulted in ZEGO filing for insolvencyA statement on ZEGO Textilveredelungszentrum GmbH’s website explains why they are filing for insolvency: Insolvency proceedings have been initiated – and why we are still looking ahead Ladies and gentlemen, dear business partners, Today we are contacting you with a message …DATABREACHES.NET
13 JulProgress urges ShareFile admins to shut down servers over “credible” threatLawrence Abrams reports: Progress Software is emailing ShareFile customers who use Storage Zone Controllers to immediately shut down their servers after identifying what it describes as a “credible external security threat” targeting the on-premises secure file-sharin…DATABREACHES.NET
13 JulWhy cloud security is mission-critical for federal civilian and defense agenciesBeyond IT compliance, cloud security is now the backbone of civilian agency resilience, national defense, and warfighter safety, as cloud environments become increasingly complex. Key takeaways For the Department of War (DoW), cloud security is an IT concern and a requirement for…TENABLE.COM
13 JulGhostcommit attack hides malicious AI instructions in imagesA proof-of-concept attack hides prompt injection in a PNG file, turning routine code reviews into a path for secret theft.MALWAREBYTES.COM
13 Jul13th July – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 13th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES U.S. auto insurer AssuranceAmerica has disclosed a data breach affecting approximately 7 million people. Attackers targeted an employ…RESEARCH.CHECKPOINT.COM
13 JulTidal Cyber connects assets, vulnerabilities, and threats through Threat-Led DefenseTidal Cyber has announced Threat-Led Asset Visibility and Vulnerability Prioritization, new innovations extending the company’s Threat-Led Defense platform. The announcement marks a significant advancement in defensive security, shifting the industry beyond static asset inv…HELPNETSECURITY.COM
13 JulPakistani Police Systems Hit by Chinese and Indian EspionageChinese and Indian spies converged on the same Balochistan police force, SentinelLabs foundINFOSECURITY-MAGAZINE.COM
13 JulCenters Lab NJ discloses data breach incident impacting 542,000 peopleCenters Lab NJ has revealed that a cybersecurity incident disclosed last month affected 542,377 individuals, according to a filing with the US Department of Health and Human Services (HHS) Office for Civil Rights (OCR). The figure, published on the agency's breach portal, provide…CYBERINSIDER.COM
13 JulCloud Security Meets AI: What CISOs Need to Govern Before They Scale - Brent Neal - CSP #226AI is changing cloud security fast, but the biggest challenge is not just adoption. It is governance. In this episode, Jess sits down with Brent Neil, CISO at RapidScale, to talk about what CISOs should be watching as AI becomes embedded in cloud environments, business workflows,…YOUTUBE.COM
13 JulUS authorities warn that state-linked hackers are targeting vulnerable networking devicesHackers linked to Russian intelligence have exploited vulnerabilities in Cisco Smart Install devices.CYBERSECURITYDIVE.COM
13 Jul KEVCISA warns of actively exploited RCE flaws in Joomla extensionsThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that attackers are exploiting vulnerabilities in the iCagenda and Balbooa Forms extensions for Joomla to achieve remote code execution through arbitrary file uploads. [...]BLEEPINGCOMPUTER.COM
13 JulEffective Patch Management Strategies: 7 Best Practices | HuntressStop letting bad actors exploit old bugs. Build a practical patch management strategy to keep them out and learn to stay secure without all the fluff.HUNTRESS.COM
13 JulApple says former employee exploited ‘rare’ bug to download confidential files after leaving for OpenAIApple would not comment on the "security breach," which allegedly allowed a former employee to download sensitive files from Apple's network long after he departed the company for rival OpenAI.TECHCRUNCH.COM
13 JulHackers backdoor Jscrambler npm package with infostealer malwareThe Jscrambler client-side web security company disclosed that a threat actor published a malicious version of its npm package that has been downloaded almost 1,500 times. [...]BLEEPINGCOMPUTER.COM
13 JulNG: Zenith Bank, Others To Be Arraigned Over Alleged Data BreachFatima Abdullahi reports: The Federal High Court in Abuja has fixed July 21, 2026, for the arraignment of Zenith Bank Plc and three other defendants over allegations of illegally accessing and disclosing the confidential financial records of Makers Island Company Limited. The oth…DATABREACHES.NET
13 JulLidl Notified Online Shop Customers in Germany, Belgium, and the Netherlands of a Data BreachLidl disclosed a third-party data breach affecting online shop customers in Germany, Belgium, and the Netherlands. Payment data was not exposed. Lidl contacted customers of its online shop in Germany, Belgium, and the Netherlands last week to inform them that their personal data …SECURITYAFFAIRS.COM
13 JulVPN service favored by ransomware groups is sanctioned by USSuzanne Smalley reports: The U.S. government on Monday sanctioned a VPN provider and its Ukrainian administrator for abetting ransomware gangs behind attacks on American municipalities, hospitals, schools and businesses. First VPN Service (1VPNS) provided ransomware groups with t…DATABREACHES.NET
12 JulWeek in review: Accenture data breach, great open-source cybersecurity toolsHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: Securing the inbox: Where identity, brand and security meet Getting a verified logo to appear next to your email has traditionally meant having to work with two separate entities. Yo…HELPNETSECURITY.COM
12 JulKR: Military targeted in nearly 19,000 cyberattack attempts in 2025: lawmakerChae Yun-hwan reports: Cyberattack attempts against the South Korean military reached nearly 19,000 last year, marking the highest figure in five years, a lawmaker said Sunday. The military was targeted in 18,951 cyberattack attempts in 2025, compared with 11,700 in 2021, 9,115 i…DATABREACHES.NET
11 JulAI Export Controls, FortiBleed, Third-Party Breaches & CISO Burnout | Cybersecurity Today PanelCan governments decide who gets access to advanced AI models? Are third-party breaches becoming impossible to control? And why are so many CISOs reaching burnout? In this special Cybersecurity Today Month in Review Panel, host Jim Love is joined by cybersecurity experts Laura Pay…CYBERSECURITYTODAY.LIBSYN.COM
11 JulCritical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User SessionsZimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in arbitrary code execution. The vulnerability has been described as a case of stored cross-site scripting (XSS) that could allow specially …THEHACKERNEWS.COM
11 JulPatching Isn't Fast Enough AnymoreCritical vulnerabilities can be exploited before organizations have time to deploy patches. This shifts attention toward time to mitigate (TTM)—the speed at which defenders can reduce risk through actions such as isolating systems, closing ports, or increasing monitoring while wa…YOUTUBE.COM
11 JulAustralia warns of global campaign targeting vulnerable CMS platformsThe Australian Cyber Security Centre (ACSC) issued an alert about a global exploitation campaign targeting vulnerable content management systems (CMS) and plugins. [...]BLEEPINGCOMPUTER.COM
11 JulArmenian National Extradited to the United States Pleads Guilty to Ransomware Extortion ConspiracyPORTLAND, Ore.— An Armenian national extradited from Ukraine to the United States pleaded guilty yesterday for his role in Ryuk ransomware attacks and an extortion conspiracy targeting companies throughout the United States, including a technology company operating in Oregon. Kar…DATABREACHES.NET
11 JulRansomware negotiator who conspired with BlackCat threat actors sentenced to 70 months in prisonJon Brodkin reports that a third co-conspirator who helped BlackCat attackers by giving them inside information on victims’ defense strategies has now been sentenced. A former ransomware negotiator was sentenced to 70 months in prison yesterday after colluding with BlackCat…DATABREACHES.NET
11 JulTikTok class action alleges data breach affected 2.4B usersBrandon Richards reports: California resident Sean Mortazi filed a class action lawsuit against TikTok Inc. on June 11, 2026, alleging a data breach exposed the personal data of more than 2.4 billion users worldwide. The complaint, filed in the U.S. District Court for the Central…DATABREACHES.NET
11 JulDutch police trace Odido telco cyberattack to suspected local accomplice; May leak voice recordingDaryna Antoniuk reports: Dutch police said Thursday they had uncovered evidence suggesting that Dutch criminals were involved in the cyberattack on telecom provider Odido that exposed the personal data of more than 6 million customers earlier this year. Authorities said a Dutch-s…DATABREACHES.NET
11 JulHackers Weaponize Balochistan Police Portal in Multi-Group Espionage CampaignsCybersecurity researchers have disclosed details of sustained cyber espionage activity against several Pakistani law enforcement organizations undertaken by suspected China- and India-aligned threat actors between February 2024 and April 2026. "At Balochistan Police, the compromi…THEHACKERNEWS.COM
11 JulCritical U-Boot Bugs Undermine Secure Boot on Millions of DevicesBinarly found six U-Boot flaws, including two that enable code execution during boot image verification, impacting 50+ releases. Binarly’s research team has found six vulnerabilities in U-Boot, the open-source bootloader that runs on home routers, smart cameras, server mana…SECURITYAFFAIRS.COM
10 JulFormer DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jailAngelo Martino exploited his insider position and fed confidential information to ransomware co-conspirators to extort a combined $75.3 million from five U.S.-based victims. The post Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail appeare…CYBERSCOOP.COM
10 JulA questionable breach, bad routers at home and at work and AI gives defenders a winThis episode covers a hacker's claim of stealing 35GB from Accenture—including source code, Azure personal access tokens, RSA keys, and SSH keys—while Accenture calls it an isolated, remediated matter, leaving uncertainty about potential downstream risk to its Fortune 500-heavy c…CYBERSECURITYTODAY.LIBSYN.COM
10 JulOnly 28% of financial workforce MFA is phishing-resistantPasswords remain part of many workforce authentication flows in financial organizations, making phishing and credential theft major identity security risks, according to a new Secret Double Octopus report. Key challenges preventing universal implementation of phishing-resistant M…HELPNETSECURITY.COM
10 JulMicrosoft is rewriting Windows patch guidance because of AIMicrosoft is recommending that organizations shorten Windows update deployment timelines, warning that advances in AI are reducing the time attackers need to identify and exploit vulnerabilities after security updates are released. The company says organizations should reassess h…HELPNETSECURITY.COM
10 JulTurning software supply chain security into a daily habitIn this Help Net Security video, Anastasia Tikhonova, Global Threat Research Lead at Group-IB, explains how to operationalize software supply chain risk. Instead of filing an SBOM away as a compliance document, she argues teams should use it every day for vulnerability triage, ve…HELPNETSECURITY.COM
10 JulCheck Point CTO Jonathan Zanger sees AI elevating the value of cyberCheck Point Software CTO Jonathan Zanger met with CSO Spain during the software company’s Engage 2026 user conference last week in Paris. At the event, Check Point executives and representatives discussed how the company is dealing with various types of threats, how it is adoptin…CSOONLINE.COM
10 JulThe open source library holding up your stack might have one maintainerEvery serious software product runs on code that someone else wrote and released for free. A web service leans on a cryptography library, a data pipeline pulls in a parser, and a mobile app ships a handful of small utilities that one person maintains in spare time. All of it carr…HELPNETSECURITY.COM
10 JulWorkato expands Agent Studio with Headless API, AI guardrailsWorkato has announced two new capabilities for Agent Studio: Headless API and Agent Guardrails. Headless API lets Genies, Workato’s AI agents built on Agent Studio, be embedded into any business application surface, on web, mobile, or inside another agent’s own enviro…HELPNETSECURITY.COM
10 Jul‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery MechanismResearchers demonstrate adversarial hallucination squatting against popular AI assistants to achieve remote code execution. The post ‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism appeared first on SecurityWeek .SECURITYWEEK.COM
10 JulAttackers Exploit 'Ill Bloom' Vulnerability to Drain $3.1 Million From Cryptocurrency WalletsSecurity firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already using it. The flaw is in how some wallet software generated its recovery phrase, the words that control the money. When that phrase is made with weak randomness…THEHACKERNEWS.COM
10 JulAI Surveillance and Social ProgressIn the near future, AI -powered surveillance systems will be able to track everything we do in public, and much of what we do in private. And if we do something wrong—shoplift, litter, jaywalk, you name it—the system will notice, retain it, tie it to your official gov…SCHNEIER.COM
10 JulUnpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 ServersA single wrong variable on one line in XQUIC, Alibaba's QUIC and HTTP/3 library, lets any remote client crash the server with a short burst of completely legal traffic. There is no patch. FoxIO researcher Sébastien Féry disclosed the flaw on July 8 and nicknamed it XRIN…THEHACKERNEWS.COM
10 JulZimbra urges customers to patch critical web client XSS flawThe Zimbra security team urged customers to patch a critical vulnerability affecting the Classic Web Client used to access the Zimbra Collaboration suite. [...]BLEEPINGCOMPUTER.COM
10 JulChina, India-Linked Hackers Both Targeted Same Pakistani Police ForceBoth foes and allies have targeted the Balochistan Police force in Pakistan for at least two years, according to SentinelOne. The post China, India-Linked Hackers Both Targeted Same Pakistani Police Force appeared first on SecurityWeek .SECURITYWEEK.COM
10 JulNew Ransomware Exploits Malicious Driver to Remove Cybersecurity ProtectionsGodDamn ransomware uses remote desktop application to secretly move around networks and drop the malicious PoisonX kernel driverINFOSECURITY-MAGAZINE.COM
10 JulIncode brings on-device processing to age estimation for privacy-focused verificationIncode has launched On-Device Age Estimation, an age verification capability that performs age estimation and liveness detection directly on the user’s device, without transmitting facial data off the device. The company’s age estimation models are now available to ru…HELPNETSECURITY.COM
10 JulChina, India ran separate spying campaigns against same Pakistani police forceThe activity, in some cases breaching the exact same systems, ran between February 2024 and April 2026 and centered on the force responsible for the country’s southwestern province that has been the site of a long-running separatist insurgency.THERECORD.MEDIA
10 JulAnthropic and OpenAI Security Tools Could Fuel Cyber-Attacks, Researchers WarnResearchers at the AI Now Institute developed a proof-of-concept exploit showing common AI tools used for security could backfireINFOSECURITY-MAGAZINE.COM
10 JulResearcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw FlawsDetails have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege escalation, and arbitrary code execution on the host. A brief description of the h…THEHACKERNEWS.COM
10 JulEU extends mass scanning of messages without a warrantMembers of the European Parliament (MEPs) have failed to block a proposal extending the mass scanning of private communications, a measure they have previously rejected twice. This time too, more votes were cast against the proposal than in favor, but due to the absence of numero…CSOONLINE.COM
10 JulCrowdStrike identifies five new prompt injection threats to AISecurity company CrowdStrike has identified five new prompt injection techniques that could leave enterprises at risk. Prompt injections attacks exploit the growing use of AI within organizations . They work by tricking LLMs into accepting instructions that a human operator would…CSOONLINE.COM
10 Jul KEVThe 72-Hour Vulnerability DeadlineThe EU Cyber Resilience Act introduces strict reporting requirements for vulnerabilities, including a 72-hour reporting window after becoming aware of an actively exploited vulnerability. Organizations must rapidly assess both technical evidence and regulatory obligations. Distin…YOUTUBE.COM
10 JulHackers exploit critical auth bypass in Gitea Docker imageHackers are actively exploiting a critical vulnerability in the official Docker image for the Gitea self-hosted Git service that allows attackers to impersonate any user, including administrators. [...]BLEEPINGCOMPUTER.COM
10 JulAWS designated as a critical third party to the UK financial sectorAmazon Web Services EMEA Sarl (AWS) has been designated as a critical third party (CTP) to the UK financial sector by HM Treasury. The CTP regime came into force on January 1, 2025, and establishes a framework through which the Bank of England, PRA, and FCA (collectively the UK r…AWS.AMAZON.COM
10 JulInitial access broker linked to weaponization of CitrixBleed2 flawA similar pattern of exploitation was seen in prior attacks involving an open-source machine emulator. CYBERSECURITYDIVE.COM
10 JulGoshDarn it, that’s advanced.Researchers track ransomware they say is getting GoshDarn sophisticated. Zimbra patches a critical vulnerability affecting its Classic Web Client. A sophisticated vishing campaign targeting Microsoft 365 accounts. GigaWiper combines espionage capabilities with multiple destructiv…THECYBERWIRE.COM
10 JulFriday Squid Blogging: “Squidbleed” VulnerabilityIn a rare combined cybersecurity/squid post, a twenty-nine-year-old squid proxy bug can leak HTTP requests. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.SCHNEIER.COM
10 JulUpdate Now: Critical Zimbra Classic Web Client Flaw Could Expose MailboxesZimbra addressed a critical stored XSS vulnerability in its Classic Web Client that lets malicious emails execute code when opened. Zimbra has released version 10.1.19 to fix a critical stored XSS vulnerability in its Classic Web Client, which is widely used to access Zimbra Coll…SECURITYAFFAIRS.COM
9 JulNayax investigating breach; The Syndicate claims it acquired 1 billion card records and other important dataNayax is a global fintech company headquartered in Israel that provides cashless payment and management solutions for unattended retail and self-service machines. The firm is publicly traded on both the Tel Aviv and Nasdaq stock exchanges. This month, Nayax submitted a Form 6-K t…DATABREACHES.NET
9 JulFake 7-Zip Installers Turn Devices Into Residential Proxy NodesCybersecurity researchers have disclosed details of a new threat actor dubbed Lurking Lizard that has been operating an end-to-end malicious residential proxy business using an infrastructure comprising more than 230 lookalike domains. The activity dates back to at least August 2…THEHACKERNEWS.COM
9 JulWood you fall for this?This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner…THECYBERWIRE.COM
9 JulTop AI Agents Built to Catch Malicious Code Can Be Tricked Into Running ItAsk an AI coding agent to scan open-source code for security holes, and it might run the attacker's code on your own machine instead. That is the finding in a proof-of-concept published Wednesday by the AI Now Institute, an attack it calls "Friendly Fire." It works agai…THEHACKERNEWS.COM
9 JulMicrosoft patches RoguePlanet Defender zero-day vulnerabilityMicrosoft has released a security patch to address a Defender zero-day vulnerability known as "RoguePlanet," disclosed after the June 2026 Patch Tuesday. [...]BLEEPINGCOMPUTER.COM
9 JulOpen-source collaboration is growing worldwide and putting pressure on maintainersDevelopers are pushing code and opening pull requests across economy borders at a rate GitHub has rarely seen. Outbound collaboration, the sum of git pushes and pull requests sent from developers in one economy to public repositories in another, grew by 16% from Q4 2025 to Q1 202…HELPNETSECURITY.COM
9 JulLateral movement risk rises as enterprises emphasize convenience over containmentPoorly segmented networks and weak security controls continue to undercut security organizations’ ability to identify and contain attacks, giving attackers free rein after initial compromise, according to a recent study based on real-world enterprise security telemetry. Zero Netw…CSOONLINE.COM
9 JulCybercriminals Plant Malicious AI Agents in Open Source Tool RepositoriesCybersecurity researchers at ESET identify big rise in suspicious and malicious toolsets which put users at risk from cyber-attacksINFOSECURITY-MAGAZINE.COM
9 JulAssuranceAmerica data breach exposes records of 6.9 million driversAmerican insurance company AssuranceAmerica has disclosed a data breach impacting nearly 7 million drivers after attackers gained access to its systems earlier this year. [...]BLEEPINGCOMPUTER.COM
9 JulChrome 150 Update Patches 27 VulnerabilitiesThe security refresh resolves 13 use-after-free bugs, including two critical-severity flaws found by Google. The post Chrome 150 Update Patches 27 Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulAI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old TechniqueWiz has disclosed the details of a new AI coding assistant attack method it has dubbed GhostApproval. The post AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulAgentic AI identity: A 6-stage maturity model for non-human identitiesIn a client engagement last year, an LLM-based deployment agent with standing access to a production Kubernetes cluster triggered a four-hour outage through a malformed configuration push. In the IAM, the agent appeared as a service account with a long-lived API key, no MFA, no s…CSOONLINE.COM
9 JulWhy fixing your data architecture matters more than upgrading your detection modelsSecurity leaders have been on a spending sprint. The global AI in cybersecurity market is valued at $44 billion in 2026 and is projected to reach $213 billion by 2034 , a trajectory that reflects genuine belief that machine learning will close the gap between the volume of threat…CSOONLINE.COM
9 JulPolice arrests 5,800 suspects in global anti-fraud crackdownLaw enforcement agencies have arrested 5,811 suspects and seized $293 million in illicit assets in a global anti-fraud operation spanning 97 countries. [...]BLEEPINGCOMPUTER.COM
9 JulAssuranceAmerica data breach exposed driver’s licenses of 7 million peopleAssuranceAmerica is notifying nearly 7 million people that hackers stole sensitive customer information, including driver's license numbers, following a cyberattack discovered in March. The incident affected 6.99 million individuals, making it the largest known exposure of Americ…CYBERINSIDER.COM
9 JulSecure self-hosted team chat platform Chatto goes open sourceGerman developer Hendrik Mans has released the source code for Chatto, a privacy-focused team messaging platform, making the project open source and available for anyone to self-host. The milestone fulfills a promise made when the project was first unveiled in late 2025 and opens…CYBERINSIDER.COM
9 Jul15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From GoogleAffecting every major distribution since 2011, the Linux kernel vulnerability allows attackers to gain root access. The post 15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google appeared first on SecurityWeek .SECURITYWEEK.COM
9 Jul5,811 arrests, $293 million seized over social engineering scamsCriminals who pose as police officers, romantic partners, and business suppliers have built fraud operations that reach across continents. A four-month enforcement campaign against these schemes wrapped up, and police in 97 countries and territories took part. Thousands of arrest…HELPNETSECURITY.COM
9 JulTwo arrests this week in unrelated crimes involved Japanese teenagers using ChatGPT to assist in their crimesThe Japan Times reports: An 18-year-old man has been arrested for his suspected involvement in a cyberattack on the operator of the Kaikatsu Club internet cafe chain, according to investigative sources. On Wednesday, the Metropolitan Police Department’s cybercrime countermeasure …DATABREACHES.NET
9 JulAttack on Amazon Bedrock-linked AI gateway highlights new cloud security riskA cloud intrusion that ended with the deployment of cryptomining malware has exposed a bigger risk for enterprises: AI gateways that concentrate access to cloud identities, permissions, and foundation models in a single, highly privileged system. Researchers from cybersecurity fi…CSOONLINE.COM
9 JulUK cyber agency unveils AI-powered Cyber Shield to counter attacks at machine speedThe UK’s National Cyber Security Centre (NCSC) wants to deploy autonomous AI agents capable of finding and neutralizing cyberattacks on national networks in real time, marking Britain’s push toward a sovereign, machine-speed cyber defense system. The blueprint, called Cyber Shiel…CSOONLINE.COM
9 JulOne Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law EnforcementChina and India ran separate espionage operations against the same Pakistani police force, each drawn by different stakes in Pakistan's internal security.SENTINELONE.COM
9 JulMicrosoft fixes RoguePlanet zero-day in DefenderThe RoguePlanet zero-day is now fixed in Microsoft Defender. Here's how to make sure your system is protected.MALWAREBYTES.COM
9 Jul12 Million Impacted by Data Breach at Japanese Telco KDDIHackers exploited a zero-day vulnerability in a third-party system to access a KDDI email system for ISPs. The post 12 Million Impacted by Data Breach at Japanese Telco KDDI appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulPalo Alto Networks Patches 13 VulnerabilitiesBuffer overflow, DoS, command injection, SSRF, authentication bypass, and other types of vulnerabilities have been found in PAN-OS software. The post Palo Alto Networks Patches 13 Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
9 Jul764 splinter group leader sentenced to 40 years in jailAlexis Chavez coerced multiple girls to commit self harm and produce child sexual abuse material for notoriety in a sprawling violent extremist collective affiliated with the Com. The post 764 splinter group leader sentenced to 40 years in jail appeared first on CyberScoop .CYBERSCOOP.COM
9 JulThe Intercept’s Signal tipline username was hijacked for monthsThe Intercept has warned that its official Signal tipline username was compromised and used by an impersonator to pose as the investigative news outlet, potentially exposing confidential sources who attempted to submit sensitive information. Dr. Martin Shelton, of the Freedom of …CYBERINSIDER.COM
9 JulGhostApproval flaw exploits trust in major AI coding assistants.Interpol operation cracks down on social engineering scams. Chinese APT exploits Roundcube flaws to target US and Canadian universities.THECYBERWIRE.COM
9 JulThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More StoriesMost security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it. This week is full of that kind of damage. Not loud. Not clever. Just small gaps doing big jobs. The worst par…THEHACKERNEWS.COM
9 JulWiz in the Verizon DBIR: How AI Acceleration and Cloud Sprawl Impact Modern DefenseVerizon's latest DBIR highlights how attackers are exploiting familiar weaknesses at increasing speed and scale. Here's what Wiz research reveals about vulnerabilities, trust relationships, and AI in modern cloud environments.WIZ.IO
9 JulWho you gonna call?GhostApproval puts AI coding assistants under the microscope. Microsoft fixes the RoguePlanet zero-day. More than 70 cybersecurity firms back a new AI Charter. An Ohio county may have paid a $1 million ransom. AssuranceAmerica discloses a breach affecting nearly seven million peo…THECYBERWIRE.COM
9 JulIran's Cyber Crosshairs Focus Beyond Critical InfrastructureObscurity isn't a defense. If your company has any Internet-facing vulnerability, you're at risk from multiple threats.DARKREADING.COM
9 JulMicrosoft Reins in RoguePlanet Zero-Day ThreatThe researcher known as "Nightmare-Eclipse" published a proof-of-concept (PoC) exploit for the Windows Defender vulnerability in early June after dropping several other Microsoft zero-days.DARKREADING.COM
9 JulWolfSSL, GeoVision, VTK vulnerabilitiesCisco Talos’ Vulnerability Discovery & Research team recently disclosed three vulnerabilities in WolfSSF, fourteen in GeoVision, and one vulnerability in VTK-DICOM. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adhere…TALOSINTELLIGENCE.COM
9 JulAI coding tool hole illustrates a big problem with human in the loopA security hole within AI dev tools has allowed attackers to escape sandboxes by misleading the humans in the loop who were supposed to knowingly approve the tool’s actions, according to cybersecurity research firm Wiz. “We discovered GhostApproval, a systematic vulnerability pat…CSOONLINE.COM
9 JulWhen Your Smart Vacuum DiesMany smart home devices depend on cloud services to function. When manufacturers discontinue products or shut down those services, expensive hardware can lose key features—or stop working entirely. Open-source alternatives offer a different model. By running locally and avoiding …YOUTUBE.COM
9 JulINTERPOL Operation First Light Nets 5,811 Arrests and Seizes $293 MillionINTERPOL’s Operation First Light 2026 led to 5,811 arrests, blocked $293M in criminal assets, and disrupted global fraud and money laundering networks. INTERPOL coordinated a four-month operation across 97 countries and territories that ended with 5,811 arrests and the inte…SECURITYAFFAIRS.COM
8 Jul20 open-source cybersecurity tools to keep your team ready for anythingAI is changing how security teams find vulnerabilities, analyze code, test applications, and protect infrastructure. Developers are building tools to secure AI systems themselves, from coding agents and memory protection to model exposure discovery. This roundup covers recent ope…HELPNETSECURITY.COM
8 JulRisky Bulletin: DHS IG investigates forced CISA reassignmentsThe DHS inspector general will investigate forced CISA reassignments, Canada hacked a ransomware gang, Taiwan charges two executives with helping Chinese hackers, and new vulnerabilities can disable Hoymiles solar panels.RISKY.BIZ
8 Jul13 in-demand IT security certifications for higher payWith change a constant, cybersecurity professionals looking to improve their careers can benefit from the latest insights into employers’ needs. Data from Foote Partners on the skills and certification most in demand today may provide helpful signposts. Analyzing more than 660 ce…CSOONLINE.COM
8 Jul KEVCISA orders feds to patch max severity ColdFusion flaw by FridayThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered government agencies to patch an actively exploited maximum-severity flaw in the Adobe ColdFusion commercial web app development platform by Friday. [...]BLEEPINGCOMPUTER.COM
8 JulMy threat feed told me it was ‘Chalubo.’ The binary disagreedI’ve spent two years doing incident response and threat intel, and the one habit I’d keep if I had to give up every other is also the most boring. I don’t act on a piece of intelligence until I’ve checked it against the thing it claims to describe. It’s slow. It’s tedious. Almost…CSOONLINE.COM
8 JulWhy AI Just Broke Traditional IT Security as Leaders Clash Over AI's Value and Hiring - BSW #455The latest generation of AI models has collapsed the time from vulnerability discovery to weaponized exploit from weeks to minutes, and reactive, module-based tools built around static dashboards simply can't keep up. In this episode, Tanium COO Matt Quinn joins Business Security…YOUTUBE.COM
8 JulFound fast, fixed slow: The gap the AI clearinghouse must closeThe government's new AI clearinghouse risks becoming a committee that discovers more problems than it solves — unless it's designed around patching, not just scanning. The post Found fast, fixed slow: The gap the AI clearinghouse must close appeared first on CyberScoop .CYBERSCOOP.COM
8 JulUbiquiti warns of new max severity UniFi OS vulnerabilityUbiquiti has released security updates to patch seven critical vulnerabilities in UniFi OS, including a maximum-severity flaw that can be exploited in command injection attacks. [...]BLEEPINGCOMPUTER.COM
8 JulCISA Deploys Anthropic’s Mythos AI to Hunt Vulnerabilities in U.S. Government CodeCISA is using Anthropic’s Mythos AI to scan federal code for vulnerabilities, aiming to find flaws before hackers and foreign intelligence services. Three sources familiar with the matter told Reuters that CISA, the U.S. government’s civilian cyber defense agency, is …SECURITYAFFAIRS.COM
8 Jul KEVCISA orders feds to prioritize patching Langflow auth bypass flawThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) gave federal agencies until Friday to patch an actively exploited vulnerability in the Langflow visual framework for building AI agents. [...]BLEEPINGCOMPUTER.COM
8 JulCrusoe brings serverless fine-tuning to AI model developmentCrusoe has announced Serverless Fine-Tuning and Self-Serve Deployments in Crusoe Intelligence Foundry, the managed AI platform for Crusoe Cloud. These capabilities give data scientists and ML engineers a complete path from proprietary data to production-ready models, on purpose-b…HELPNETSECURITY.COM
8 JulNew Bit2Watt attack uses AI GPU workloads to destabilize power gridsA new cyber-physical attack called Bit2Watt uses carefully crafted GPU workloads to manipulate a data center's power consumption in ways that interfere with modern electricity infrastructure. While the work is primarily a proof-of-concept supported by simulations and laboratory e…CYBERINSIDER.COM
8 JulCritical Vulnerability Exposes GitHub Agentic Workflows to Prompt InjectionResearchers show how attackers can use a crafted public GitHub Issue to trick AI-powered workflows into exposing data from private repositories without authentication. The post Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection appeared first on SecurityW…SECURITYWEEK.COM
8 JulCybercriminals exploit India’s tax filing season with a dual-malware campaignCybercriminals are exploiting India’s tax filing season with a new malware campaign that refuses to put all its eggs in one basket. Researchers at Cyderes have uncovered a sophisticated phishing operation that poses as the Indian Tax Department to deliver two remote access trojan…CSOONLINE.COM
8 JulMutation testing comes to DAMLIn April we released Mewt , our open-source mutation-testing engine that finds the gaps in your test suite. Today we’re expanding it with support for DAML, the language Canton Network applications are written in. Mewt now reads DAML, generates several classes of mutants (includin…TRAILOFBITS.COM
8 JulAccenture acknowledges security incident following 35GB data theft claimAccenture appears to have suffered a data breach, the extent of which is currently unknown. On Monday, a threat actor going by the handle “888” posted on the cybercrime forum PwnForums, claiming to have breached the technology consulting company and stolen “just…HELPNETSECURITY.COM
8 JulFelons, Fraudsters Flog Offensive Cybersecurity StartupA cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based…KREBSONSECURITY.COM
8 JulGitHub AI agent leaks private repositories via prompt injection attackA prompt injection attack can trick GitHub’s preview Agentic Workflows into retrieving content from private repositories and publishing it publicly, exposing a broader risk as enterprises deploy AI agents with privileged access to software development environments, according to n…CSOONLINE.COM
8 JulGoogle Dialogflow CX Bug Allowed Attackers to Hijack AI ConversationsThe "Rogue Agent" vulnerability could have enabled attackers to silently manipulate AI conversations, exfiltrate data, and compromise every Dialogflow CX agent within the same Google Cloud project. The post Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations app…SECURITYWEEK.COM
8 Jul"Good Enough" Patching Is OverFor years, many organizations relied on fixed patching schedules, accepting 60-day, 90-day, or even annual update cycles as "good enough." That assumption is becoming harder to defend. As AI speeds up vulnerability discovery and attackers move faster, security teams face increasi…YOUTUBE.COM
8 JulSecurity Teams Are Ready To Become More Preemptive. What’s Holding Them Back?The shift toward preemptive security is underway, but most organizations are still navigating the realities of limited resources, fragmented tools, and emerging AI risk. At Rapid7’s recent Global Security Summit , we surveyed attendees to better understand where security leaders …RAPID7.COM
8 JulAccenture faces massive data breach that could put clients at riskThe threat actor claiming responsibility says they stole source code, encryption keys and more.CYBERSECURITYDIVE.COM
8 JulPatients Sue Healthcare Corporations Over Data Breaches, Sharing of Personal InformationMikeie Honda Reiland reports: A suite of recent class action lawsuits in state and federal courts seeks to hold large healthcare corporations accountable for exposing or leaking patients’ personally identifiable information (PII) and protected health information (PHI). On June 11…DATABREACHES.NET
8 JulWhy Bangladesh’s new data protection law may fail to protect your dataMeem Arafat Manab reports: On August 19, 2025, hackers broke into Shwapno’s customer database. They took 410 gigabytes of data: the names, phone numbers, and purchase histories of forty lakh registered customers. They demanded $1.5 million. Shwapno refused, secured its systems, a…DATABREACHES.NET
8 JulAttackers Won't Wait for Patch TuesdayOrganizations continue to be compromised through vulnerabilities that have been known and exploited for years. At the same time, the time between vulnerability disclosure and active exploitation continues to shrink. Traditional patching cycles and lengthy change approval processe…YOUTUBE.COM
8 JulAccenture Confirms Data Breach After Hacker Claims Source Code TheftThe professional services giant says it contained the incident, remediated its source, and experienced no operational or service delivery impact. The post Accenture Confirms Data Breach After Hacker Claims Source Code Theft appeared first on SecurityWeek .SECURITYWEEK.COM
8 JulHackers exploit Roundcube flaw to spy on academic researchersA China-linked threat cluster has been exploiting vulnerable Roundcube servers at U.S. and Canadian universities to steal credentials and deploy backdoor malware. [...]BLEEPINGCOMPUTER.COM
8 JulUniondale Union Free School District – Audit Follow-Up by New York State Comptroller (2023M-61-F)In October 2023, NYS Comptroller Thomas DiNapoli released an IT audit of the Uniondale Union Free School District on Long Island. The purpose of the audit was to examine management of non-student user network controls. The audit report found, in part: District officials did not a…DATABREACHES.NET
8 JulA Hacker Claims 35 GB of Accenture Source Code. The Company discloses the data breachAccenture confirmed a breach after a hacker claimed to steal 35 GB of source code, keys, and Azure credentials now offered for sale. A threat actor using the handle “888” claimed on the cybercrime forum PwnForums this week to have stolen 35 gigabytes of data from Acce…SECURITYAFFAIRS.COM
8 JulAzure you concerned?Accenture confirms a data breach. An Australian telecom investigates a nationwide outage. It’s shields up for the UK. CISA eyes September for its critical infrastructure reporting rule. NewsJunkie fakes CTV ad traffic. Agentic AI triggers EDR. CISA taps Mythos for vulnerability s…THECYBERWIRE.COM
8 JulLone Attacker Uses AI to Breach AWS Cloud Environment in 72 HoursThe attacker exploited AI workflows, chained cloud weaknesses, and stolen credentials to extort a large Amazon customer.DARKREADING.COM
8 JulGitHub’s public APIs are becoming an enterprise reconnaissance toolGitHub continues to be a scintillating target for attackers because it sits in the middle of the software supply chain and gives threat actors three things they crave: source code, secrets, and automated pipelines to run amok in. Datadog Security Research has been tracking what i…CSOONLINE.COM
7 JulZscaler finds autonomous agents succumb to IPI trapsIn a test of major LLMs, Zscaler found that some autonomous AI agents fell victim to frauds, reinforcing how easily some high-end enterprise agents can be conned by schemes that would fool few, if any, humans. The security vendor looked at various forms of indirect prompt injecti…CSOONLINE.COM
7 JulCybersecurity jobs available right now: July 7, 2026Application Security Lead Gett | Israel | Hybrid – View job details As an Application Security Lead, you will lead application and cloud security initiatives by integrating security into the SDLC, overseeing threat modeling, secure architecture, application securi…HELPNETSECURITY.COM
7 JulApple Container: Open-source tool for Linux containers on the MacDevelopers on Apple silicon Macs have run Linux containers through software built around a single shared virtual machine for years. Apple’s open-source Container project gives each Linux workload its own lightweight virtual machine. Container is written in Swift and tuned f…HELPNETSECURITY.COM
7 JulMicrosoft wants to keep your AI agents from going rogueMicrosoft has introduced Microsoft Execution Containers (MXC), a cross-platform, policy-driven execution layer for AI agents on Windows and Windows Subsystem for Linux (WSL), now available in early preview. Updated Agent 365 platform (Source: Microsoft) Developers can define cons…HELPNETSECURITY.COM
7 JulPower shortages could slow AI data center expansionAI adoption is increasing demand for data center capacity at the same time operators are running into limits around power, equipment, land, and permitting, according to NTT Data. Access to electricity is becoming a deciding factor in where new data centers are built, when new cap…HELPNETSECURITY.COM
7 Jul176: NSLOne day Nick got a visit from the FBI demanding he give them data on one of his customers. They asked for it in the form of a National Security Letter or NSL. Something wasn’t right about this letter. It seemed to violate the constitution. So he set out to change the law. Learn m…DARKNETDIARIES.COM
7 JulJanuscape: 16-Year-Old Linux KVM Bug Enables Cloud VM Escape AttacksJanuscape: A 16-year-old Linux KVM flaw lets cloud VM tenants crash hosts and potentially escape guests. It affects Intel and AMD systems. Security researcher Hyunwoo Kim has published details of a use-after-free vulnerability in Linux’s KVM hypervisor that allows code runn…SECURITYAFFAIRS.COM
7 JulSuspected Chinese espionage group used a Roundcube exploit chain to burrow into universitiesProofpoint researchers said attackers targeted physics and engineering departments, and warn that the campaign is likely ongoing. The post Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities appeared first on CyberScoop .CYBERSCOOP.COM
7 JulHackers Exploit Maximum Severity Adobe ColdFusion FlawThreat actors are exploiting an Adobe ColdFusion vulnerability which has a CVSS score of 10.0INFOSECURITY-MAGAZINE.COM
7 JulWhy The Gentlemen ransomware is a test of identity and recovery controlsThe Gentlemen ransomware underscores a challenge many CISOs face: stopping attackers after they gain an initial foothold. Researchers say the malware can spread across enterprise networks using legitimate Windows management tools while simultaneously attempting to weaken security…CSOONLINE.COM
7 JulThe modern CISO is becoming the next CFOAt some point, every security leader gets asked a version of the same question: Are we good? It tends to arrive when something is at stake and the person asking needs to know they can rely on the answer. I learned what that question really means at a firm I was with earlier in my…CSOONLINE.COM
7 JulDefense-in-depth strategies for securing mobile applications - Ryan Lloyd - ASW #390Mobile applications have unique risks and threat models compared to server-side applications and infrastructure. Consequently, they need different strategies to ensure their business logic and workflows well secured. We'll dive into some of these defense-in-depth strategies and w…YOUTUBE.COM
7 JulThreat landscape for industrial automation systems. Q1 2026This report contains industrial threat statistics for Q1 2026, including industrial threat distribution by type, source, region and industry.SECURELIST.COM
7 JulLinux Kernel Vulnerability Allows VM Escape on Intel and AMD SystemsThe 16-year-old Januscape flaw affects Linux's KVM hypervisor, allowing attackers to escape virtual machines and potentially execute code on the underlying host. The post Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems appeared first on SecurityWeek .SECURITYWEEK.COM
7 JulWhat Changes When Your Software Supply Chain Includes AI Writing Your Code?Software supply chain security was hard enough. Then AI joined the build pipeline. For five years, "software supply chain security" meant one question: what's in your code? Which open-source packages, which versions, which transitive dependencies three layers deep that nobody cho…THEHACKERNEWS.COM
7 JulNew Januscape Linux flaw allows VM escape on Intel, AMD devicesA 16-year-old Linux kernel vulnerability, dubbed Januscape, allows attackers to escape a virtual machine and execute arbitrary code on the host. [...]BLEEPINGCOMPUTER.COM
7 JulCommvault measures cyber recovery readiness with AI attack simulationsCommvault has announced Commvault Minutes to Recovery, a scenario-driven cyber resilience simulation that lets participants act as a hacker and run their own attacks using frontier AI tools. Then, participants are challenged to defend against and recover from an incident under pr…HELPNETSECURITY.COM
7 JulCourt Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider HackerU.S. prosecutors linked an alleged Scattered Spider hacker to a break-in at a luxury jewelry retailer using a persistent Windows device ID, according to a newly unsealed federal complaint. Microsoft records tied that ID first to the account the attackers used to keep access durin…THEHACKERNEWS.COM
7 JulWriter AI Flaw Could Let Agent Previews Leak Session Tokens Across TenantsCybersecurity researchers have disclosed details of a now-patched critical session isolation vulnerability in Writer, an enterprise generative artificial intelligence (AI) platform, that could result in cross-tenant compromise. The one-click vulnerability has been codenamed Write…THEHACKERNEWS.COM
7 JulBojangles sued again by workers over Russian hacker data breach. NC judge weighs inChase Jordan reports an update in the litigation stemming from a 2024 breach by Hunters International. This case has raised a number of issues about standing and negligence and has been up and down in the courts, with plaintiffs seeming to fare better in state court: A class-acti…DATABREACHES.NET
7 JulJacksonville, Texas, keeps some city systems offline after cyber incidentDysruptionHub reports: Jacksonville, Texas, took some city systems offline after detecting suspicious network activity Friday, leaving some online services unavailable Monday as officials investigated a cybersecurity incident. The city said it detected the activity July 3 and lat…DATABREACHES.NET
7 JulCERT/CC warns of an unpatched backdoor affecting Tenda routers.Maximum-severity ColdFusion flaw is under active exploitation. Canadian intelligence agencies hacked criminal groups.THECYBERWIRE.COM
7 JulSuspected Chinese Threat Group Targets Universities via Vulnerable Roundcube ServersA suspected Chinese threat cluster is exploiting Roundcube vulnerabilities to compromise university networks in the US and Canada and harvest user credentialsINFOSECURITY-MAGAZINE.COM
7 JulSophisticated threat campaign pushes Cisco to the very edgeA monthslong exploitation wave against Cisco SD-WAN systems raises larger questions about trust and the insecurity of network infrastructure.CYBERSECURITYDIVE.COM
7 JulOMB M-26-14: Why federal agencies must fix asset visibility firstThe new OMB logging directive raises the bar on log collection and explicitly ties every maturity milestone to how well agencies know what’s on their networks. Learn why asset visibility is the first problem to solve. Key takeaways M-26-14 rescinds M-21-31 and replaces blanket da…TENABLE.COM
7 JulEnforce zero data retention on Amazon Bedrock with Bedrock Projects and service control policiesWith the introduction of models that require data sharing with third-party providers—such as Claude Fable 5—organizations need a way to centrally enforce data retention policies. Amazon Bedrock gives you control over whether your prompts and model outputs are retained after an in…AWS.AMAZON.COM
7 JulChinese hackers develop LONGLEASH malware to expand ORB networkChinese hackers tracked as 'UAT-7810' are actively evolving their malware to expand their Operational Relay Box (ORB) network by compromising internet-facing networking devices, primarily unpatched Ruckus routers. [...]BLEEPINGCOMPUTER.COM
7 JulWhy Streaming Apps Protect ContentFor streaming platforms, the most security-sensitive asset is often the content itself. Licensing agreements require providers to protect movies, shows, and live events from unauthorized distribution. Technologies like DRM and digital watermarking help enforce those protections a…YOUTUBE.COM
7 Jul KEVWelcome home, hacker.CERT/CC warns of an unpatched Tenda router backdoor. Adobe races to patch an actively exploited ColdFusion flaw. Canada pulls back the curtain on offensive cyber operations. Anthropic quietly removes hidden tracking from Claude Code. Chinese AI gains momentum as U.S. providers sw…THECYBERWIRE.COM
7 JulAccenture confirms breach after hacker offers stolen data for saleIT services giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and other data from the company. [...]BLEEPINGCOMPUTER.COM
7 JulWashington Dept. of Social and Health Services announces massive data breachKIRO7 reports: The Washington Department of Social and Health Services (DSHS) is issuing a notice of a massive data breach that happened in March, potentially compromising the personal data of around 8,600 people. An internal investigation revealed that a former DSHS employee acc…DATABREACHES.NET
7 JulSN 1086: The Apex Agentic Adversary - Visual Prompt Injection StrikesFrom the sudden retirement of Internet pioneer Vint Cerf to the unstoppable advance of "apex agentic adversaries," get a front-row seat to the unfolding security revolution and its massive real-world stakes. Why Fable5's re-release has disappointed. Opera becomes the first browse…TWIT.TV
6 JulThe future of payment fraud could be automatedPayment fraud is becoming more organized as criminal groups use fake websites, large-scale operations, and, in some cases, forced labor to steal money and personal information. Advances in agentic AI could automate many stages of payment fraud, from collecting and assembling stol…HELPNETSECURITY.COM
6 JulFlipper Zero firmware development gets a fresh set of community rulesOwners of the Flipper Zero, the pocket-sized wireless testing tool, spent recent weeks worried that its official firmware had gone quiet. Pavel Zhovner, CEO of Flipper Devices, moved to settle that concern with word that the company has set aside staff to keep the firmware mainta…HELPNETSECURITY.COM
6 JulRisky Bulletin: EU official’s phone infected with PegasusA European MP’s phone was infected by Pegasus spyware, Android drops its PIN guessing limit from 1,800 attempts to 20, Alibaba bans employees from using Claude at work, and there’s a new vulnerability in the Linux kernel.RISKY.BIZ
6 JulSecuring the inbox: Where identity, brand and security meetGetting a verified logo to appear next to your email has traditionally meant having to work with two separate entities. You have to work with a DMARC partner for setting up DMARC and BIMI, then use a trusted Certificate Authority (CA) to purchase a Mark Certificate, and this mean…HELPNETSECURITY.COM
6 JulOmnigent: Open-source AI agent framework and meta-harnessPlenty of developers now keep several coding agents close at hand, reaching for Claude Code on one task and Codex or Cursor on the next. Each tool arrives with its own command line, its own handling of credentials, and its own way of running shell commands against a working direc…HELPNETSECURITY.COM
6 Jul7 cyber risk assessment gotchas to avoidA cyber risk assessment helps security teams identify, estimate, and prioritize potential threats and vulnerabilities to key enterprise digital and physical assets. Yet, despite its importance, many CISOs fall victim to several types of “gotchas” that prevent them from fully achi…CSOONLINE.COM
6 JulAI isn’t closing the skills gap — it’s exposing the validation gapIf you wanted to become a basketball star, how would you get started? You wouldn’t read a book on basketball and take an online course. You’d set up a hoop in your driveway, join a local team to train, and play in real matches. So why do we expect cybersecurity professionals to l…CSOONLINE.COM
6 JulFinding vulnerabilities was never the hard partAI is surfacing vulnerabilities at a scale the industry has never seen, and most organizations have no way to determine which ones actually matter. The post Finding vulnerabilities was never the hard part appeared first on CyberScoop .CYBERSCOOP.COM
6 JulNCA Issues Warning to Parents As Shared Child Photos Exploited by AI ToolsIWF and NCA warn that growing numbers of images and videos are being manipulated into sexual abuse materialINFOSECURITY-MAGAZINE.COM
6 JulSingle points of failure fail. The SaaS layer is not an exceptionHigher education has consolidated its entire academic operation into a handful of massive SaaS platforms. The LMS manages instruction, grading and communication. The SIS owns enrollment, records and financial aid. Identity and productivity live in a small number of cloud provider…CSOONLINE.COM
6 JulMastering agent permissions and Identiverse interviews - ESW #466Interview with Sandy Bird, co-founder of Sonrai Security In this week's interview, we kick off the conversation with how Sonrai's expertise in securing cloud identity permissions had the company well placed to address the explosion of AI agents and the clear risks they represente…YOUTUBE.COM
6 JulFrance to Stop Certifying Non-Quantum-Safe EncryptionFrance is accelerating its transition to post-quantum encryption: France’s cybersecurity agency ANSSI said on Tuesday it would stop certifying security products that lack quantum-resistant encryption, a move that will force government bodies and critical operators to shift …SCHNEIER.COM
6 JulPrompt Injection Attacks Trick AI Agents Into Making Crypto PaymentsResearchers uncovered two campaigns embedding indirect prompt injections in malicious websites to exploit autonomous AI agents browsing the web. The post Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments appeared first on SecurityWeek .SECURITYWEEK.COM
6 JulSeven Bugs in FatFs Put IoT and Embedded Devices at RiskrunZero found 7 flaws in FatFs, a filesystem used in IoT and embedded devices. Bugs can cause memory corruption, crashes, or data leaks via crafted storage. Cybersecurity firm runZero has disclosed seven vulnerabilities in FatFs, a compact open-source library that lets embedded d…SECURITYAFFAIRS.COM
6 JulProof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access VulnerabilityOrganizations are urged to patch after proof-of-concept code makes the Linux root escalation flaw easier to exploit. The post Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
6 Jul⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and MoreA streaming box should not need a threat model. Neither should a username field, a demo repo, a reset flow, or a browser permission prompt. That is the irritating part this week: the risky pieces were ordinary. Home devices became a routing cover. Clean code pulled dirt from a de…THEHACKERNEWS.COM
6 JulNorth Korean Hackers Target Open Source Developers in Supply Chain AttacksThe PolinRider campaign has compromised more than 100 legitimate open source packages and repositories to deliver a backdoor and information stealer to developers. The post North Korean Hackers Target Open Source Developers in Supply Chain Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
6 JulCriminal IP integrates threat intelligence with OpenCTI for automated indicator enrichmentCriminal IP has integrated its threat intelligence with OpenCTI, enabling security teams to automatically convert IP addresses, domains, and URLs into structured intelligence within the platform’s knowledge graph. The integration automatically enriches ingested indicators w…HELPNETSECURITY.COM
6 JulLTM’s BlueVerse RightLogic combines AI risk assessment with cyber remediation planningLTM has launched BlueVerse RightLogic, a cybersecurity assessment and risk assurance framework designed to help enterprises identify, assess and remediate cyber exposure as they accelerate AI adoption. AI is now capable of autonomously identifying and exploiting vulnerabilities, …HELPNETSECURITY.COM
6 JulA Day With Your Vector Command Red Team PodAnyone trying to understand continuous red teaming usually gets the same high-level explanation: it is ongoing, attacker-informed, and designed to uncover risk between formal assessments. Useful as that description is, it still leaves most people with the same question, which is …RAPID7.COM
6 JulAlberta, Centurion Project sued over alleged data breach that affected millions of votersCarrie Tait reports: A retired lawyer is suing Alberta, its Chief Electoral Officer and two organizations that support secession for their respective roles in an alleged data breach affecting 2.9 million residents in the province. Clint Docken, a former class-action lawyer, last …DATABREACHES.NET
6 JulCanadian spy agency says it hacked drug traffickers, extremists and a ransomware gang last yearThe hacking operations disclosed in a Canadian spy agency's annual report underscores some pressing national security threats facing the country and its top allies.TECHCRUNCH.COM
6 JulThe agentic blind spots in your zero trust programStephen Wilson, field chief technology officer for HashiCorp, an IBM company, likens AI agents to “really smart kindergartners.” “They know how to do something, but they have no clue as to why they should do it,” Wilson says. This combination of superior execution power and lack …CSOONLINE.COM
6 JulIdentity: The operational control plane for agentic AIExisting security controls weren’t designed for AI agents. Static credentials and standing privileges aren’t sufficient for an emerging model where organizations need to rapidly authorize, limit, and revoke permissions from autonomous agents, sometimes more than once within a sin…CSOONLINE.COM
6 JulEnforce least-privilege authorization in multi-agent AI chains using CedarIf you’re building multi-agent AI systems, you need to prevent authorization scope from silently expanding as agents delegate tasks through multi-hop chains. Without proper controls, an agent can potentially act beyond what the originating user authorized, even when role-based ac…AWS.AMAZON.COM
6 JulJapanese teen arrested over cyberattack that disrupted anime streaming serviceThe unnamed student, who lives in a city near Tokyo, allegedly exploited a flaw in a subscription-based anime streaming platform to fraudulently cancel more than 46,000 user subscriptions.THERECORD.MEDIA
6 JulJadePuffer: The First Complete LLM-Driven Ransomware AttackAn "agentic threat actor" successfully exploited a Langflow flaw to steal data from a production database server and encrypt other systems.DARKREADING.COM
6 JulGoogle Chrome extensions must meet new privacy standards by August 1Google has announced a set of Chrome Web Store policy changes that tighten rules around extension data collection, improve transparency requirements, and prohibit new categories of software. The updated Developer Program Policies will take effect on August 1, 2026, giving extensi…CYBERINSIDER.COM
6 JulNetNut gets cracked.The FBI disrupts a major residential proxy service. Attackers exploit Fortinet firewalls to target UK officials. European lawmakers call for a spyware investigation. A new macOS infostealer masquerades as a clipboard manager. Prompt injection campaigns targeting AI agents through…THECYBERWIRE.COM
6 JulCitrixBleed-ing Again? NetScaler Vulnerability Under AttackAttackers wasted little time targeting the latest memory disclosure flaw in Citrix's NetScaler products, after researchers published a proof-of-concept exploit (PoC).DARKREADING.COM
6 JulThe “Anonymous” Tip System That Wasn’t: Three Months Later, Why Hasn’t Navigate360 Notified Anyone?Trigger Warning: This post includes content from tips submitted to anonymous tiplines by or about students. While identity information is redacted, tips may include obscenities and explicit references to sexual abuse, rape, assault, self-harm, violence, suicidal ideation, pornogr…DATABREACHES.NET
5 JulWeek in review: SimpleHelp vulnerability exploited, Oracle EBS Payments flaw under attackHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: Companies keep bolting AI onto their products, and the security bill is coming due Companies keep bolting AI and LLM features onto their products, and the security results are starti…HELPNETSECURITY.COM
5 JulNew ClamAV security patch closes seven scanner bugs dating back two decadesOpen source antivirus scanning sits inside mail gateways, file upload checks, and endpoint tooling at organizations of every size. Much of that work runs through ClamAV, the scanning engine maintained by Cisco’s Talos group. The project released two patch versions, 1.5.3 an…HELPNETSECURITY.COM
4 JulUnpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded DevicesSecurity firm runZero has disclosed seven vulnerabilities in FatFs, a small filesystem library that lets a device read and write the FAT and exFAT formats used on USB drives and SD cards. The flaws matter because FatFs is nearly everywhere. It ships inside the firm…THEHACKERNEWS.COM
4 JulAdaptHealth says attackers sweet-talked their way into cloud systems and stole patient dataConnor Jones reports: AdaptHealth says attackers used social engineering to breach its systems and steal sensitive patient data, including passwords associated with insurance billing. The medical equipment company disclosed the attack to the Securities and Exchange Commission (SE…DATABREACHES.NET
3 JulTeams battles bots, Bioshocking AI browser guardrails, Fortibleed fuels ransomwareTeams cracks down on meeting bots, AI guardrails get bypassed, FortiBleed fuels ransomware, and Nissan confirms PeopleSoft breach Microsoft rolls out a new Teams admin policy, "Manage External Bots and Their Access to Meetings," to detect third‑party bots, hold them in the lobby …CYBERSECURITYTODAY.LIBSYN.COM
3 JulOrganizations struggle to prioritize known cyber risksOrganizations collect more cyber risk data than ever, with many still struggling to build a unified view of their exposure. The latest State of Threat Management report from Filigran found that security teams continue to work across disconnected tools, leaving important context s…HELPNETSECURITY.COM
3 JulCritical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code ExecutionThe DuneSlide vulnerabilities enable zero-click prompt injection attacks that escape Cursor's sandbox and execute arbitrary code on the underlying operating system. The post Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution appeared first on Securi…SECURITYWEEK.COM
3 JulPamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login PasswordsCybersecurity researchers have flagged a new macOS information stealer called PamStealer that employs a series of clever tricks to infect systems and siphon sensitive data. The stealer, discovered by Jamf Threat Labs, is distributed as a compiled AppleScript (.scpt) file imperson…THEHACKERNEWS.COM
3 JulLaw enforcememt operation disrupted Malicious Residential Proxy Networks NetNutGoogle disrupted NetNut, a major proxy network that routed internet traffic through compromised home devices used by cybercriminals. Google has disrupted NetNut, one of the world’s largest residential proxy networks. The service routed internet traffic through home devices,…SECURITYAFFAIRS.COM
3 JulAgentic AI Used to Conduct Ransomware Attack via LangflowAttack demonstrates how LLM agents can combine known exploitation techniques with real-time reasoning to automate complex, multi-stage intrusions. The post Agentic AI Used to Conduct Ransomware Attack via Langflow appeared first on SecurityWeek .SECURITYWEEK.COM
3 JulFlock Cameras Can Surveil Cars Without License PlatesThis is from a 2024 company presentation : Officers can also tap into data showing a car’s decals, bumper stickers, back and top racks—along with temporary and unique state tags. Flock calls it a “Vehicle Fingerprint” and it’s touted as a way for law…SCHNEIER.COM
3 JulThe Anatomy of a Shadow AI Supply-Chain Breach: Lessons from the 2026 Vercel IncidentVercel breach happened after an employee used an unvetted AI tool. Attackers exploited it as a trusted link to access systems, steal data, and extort $2M. The Vercel breach of April 2026 did not begin with a classic zero-day exploit, a misconfigured cloud bucket, or a sophisticat…SECURITYAFFAIRS.COM
3 JulJADEPUFFER: First End-to-End AI-Driven Ransomware OperationSysdig reports an AI agent ran a full ransomware attack end-to-end, exploiting flaws, stealing creds, moving laterally, and encrypting data without humans. Sysdig’s Threat Research Team has documented what it assesses to be the first ransomware operation driven end-to-end b…SECURITYAFFAIRS.COM
3 JulVerified X ad spreads Mac malware, while ConsentFix steals Microsoft accountsTwo new campaigns show how cybercriminals are increasingly relying on social engineering instead of software exploits to compromise devices and accounts.MALWAREBYTES.COM
3 JulHK: Shun Hing Group data breach affects 920,000 customers, 1.05m files encrypted in cyber attackErwin Wong reports: Shun Hing Group has confirmed that its computer systems were compromised by hackers in March, resulting in a significant data breach affecting customers and staff. Founded in 1953 by the late Dr William Mong, Shun Hing Group has grown into a leading and divers…DATABREACHES.NET
3 JulAdobe premieres a second Patch Tuesday each month to deliver fixes fasterAdobe will now issue security patches for its products twice as often to deal with the increasing pace of software vulnerability discovery and exploitation. This follows Oracle’s decision to increase its quarterly patch program to a monthly one. Adobe issues patches on the second…CSOONLINE.COM
3 JulEveryone Owns Security—Or Nobody DoesMany e-commerce sites rely on multiple third-party providers for hosting, application development, payment processing, JavaScript, and other core functions. That convenience creates a shared responsibility problem. When a vulnerability, outage, or compliance issue occurs, each ve…YOUTUBE.COM
3 JulMicrosoft 365 users fall victim to one-in-a-million password spray attackMicrosoft users have been hit by a massive, automated password spray attack. Among those targeted by the attack were clients of security company Huntress. It reported that the attackers made 81 million attempts to log into its customers’ accounts between June 12 and 26 — and succ…CSOONLINE.COM
3 JulIn Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM JackpottingNoteworthy stories that might have slipped under the radar: Anonymous-linked Canadian hacker jailed, researcher drops zero-days in open source projects, Venezuelans sentenced in the US over ATM jackpotting. The post In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Tw…SECURITYWEEK.COM
3 JulAn AI just carried out a cyber attack without any human oversight for the first timeAnthony Cuthbertson reports: Security researchers have uncovered what they believe to be the first ever instance of an artificial intelligence agent executing a cyber attack from start to finish without human assistance. The AI-powered attack marks a major milestone for both arti…DATABREACHES.NET
3 JulWeekly Metasploit Update: Modules for SMB-to-Meterpreter, Peyara Remote Mouse RCE exploit, and moreIt's Time to Upgrade Your SMB Session This week, Metasploit contributor Dean Welch has added an SMB to Meterpreter session upgrade module. It uses PsExec to facilitate the upgrade. Users can load the module with use windows/manage/smb_to_meterpreter and specify the session number…RAPID7.COM
2 JulUnpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes ClustersArgo CD, a widely used tool for deploying software to Kubernetes, has an unpatched flaw in its repo-server component that lets an unauthenticated attacker run code, provided they can reach the component's internal network port. Synacktiv, which found the bug, says it can lead to …THEHACKERNEWS.COM
2 JulGitHub’s new tool helps prevent costly open-source license violationsGitHub’s Open Source Program Office (OSPO) uses the new GitHub License Compliance feature, now in public preview, to manage thousands of open-source dependencies and identify dependencies whose licenses require review. The feature is available to GitHub Advanced Security cu…HELPNETSECURITY.COM
2 JulDrawing a digital line for geofencing.This week, Dave and Ben take a look at the Supreme Court's recent ruling that has significantly changed how the law enforcement must approach collecting user location data. Alongside this conversation, Ben also sits down with former Congressman and current President of Americans …THECYBERWIRE.COM
2 JulWhat the AI patch gap means for enterprise securityOpen-source maintainers are receiving more vulnerability reports than they can act on, and a rising share now comes from an AI system working at machine speed. Over roughly two months this spring, Anthropic’s Claude Mythos Preview combed through more than 23,000 open-source…HELPNETSECURITY.COM
2 JulNew ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit ReposAttackers are hiding a data-stealing trojan inside fake exploit code aimed at the people who hunt bugs for a living. The malware, called ChocoPoC, travels in Python proof-of-concept (PoC) repositories on GitHub that claim to exploit hot new CVEs. Run one, and it quietly lifts you…THEHACKERNEWS.COM
2 JulExploring cross-domain & cross-forest RBCD: part 2Kerberos delegation capabilities in Linux-based tooling have been extended to allow impersonating any user within a forest. This assumed identity can then be leveraged to access resources across any domain within that forest, or even in a remote forest, provided that a trust rela…SYNACKTIV.COM
2 JulAI Agent Exploits Langflow RCE to Automate Database Ransomware AttackSecurity firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an AI agent. Its Threat Research Team calls the operator JADEPUFFER and says a large language model handled the whole job: breaking in, stealing credential…THEHACKERNEWS.COM
2 JulAdobe fixed multiple maximum-severity flaws in ColdFusion and Campaign ClassicAdobe fixed multiple critical flaws, including max severity bugs in ColdFusion and Campaign Classic that could lead to remote code execution Adobe has released security updates for ColdFusion and Campaign Classic, fixing multiple critical vulnerabilities, including seven maximum-…SECURITYAFFAIRS.COM
2 JulArgo CD flaw shows why GitOps infrastructure should be treated as tier zeroA newly disclosed vulnerability in Argo CD is drawing attention to the security risks of GitOps platforms, with researchers warning that the flaw could allow attackers who gain a foothold inside a Kubernetes cluster to execute code and manipulate application deployments. Security…CSOONLINE.COM
2 JulField reports from Patch the PlanetWe’re running Patch the Planet , an ongoing collaboration with OpenAI that pairs Trail of Bits engineers directly with more than 30 open-source projects. Its goal is to front-run a serious problem facing open-source maintainers: highly capable models like GPT-5.5-Cyber will soon …TRAILOFBITS.COM
2 Jul KEVCISA: Microsoft SharePoint RCE flaw now actively exploitedCISA warned on Wednesday that attackers have begun exploiting a high-severity Microsoft SharePoint remote code execution vulnerability patched in May. [...]BLEEPINGCOMPUTER.COM
2 JulCisco Confirms In-the-Wild Exploitation of Unified CM VulnerabilityA PoC exploit has been available since public disclosure, and the first exploitation attempts were observed last week. The post Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
2 JulCisco finally confirms attackers exploiting Unified CM flawCisco confirmed that attackers are now exploiting a Unified Communications Manager (Unified CM) vulnerability patched in early June. [...]BLEEPINGCOMPUTER.COM
2 JulResearcher Behind 'Exploitarium' Explains Release of Undisclosed Zero-Day ExploitsInfosecurity spoke with the researcher who dumped over 30 proof-of-concept exploits without disclosing the vulnerabilities firstINFOSECURITY-MAGAZINE.COM
2 JulAnthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them.IBM and Red Hat assign 20,000 engineers to the new Project Lightwell service as Anthropic's Mythos findings ignite debate over how to secure the open-source software supply chain.DARKREADING.COM
2 JulNew iboss platform gives organizations instant visibility into AI tools and usageiboss has launched the AI Security Platform, a new service that gives any organization visibility into the AI tools its people are using, free of charge. Signup is instant, deployment takes an afternoon, and a complete AI footprint appears within hours. Organizations that want to…HELPNETSECURITY.COM
2 JulNew CitrixBleed Vulnerability Exploited Immediately After Public DisclosureHackers are targeting NetScaler appliances using public PoC code to retrieve arbitrary memory content in the HTTP response. The post New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure appeared first on SecurityWeek .SECURITYWEEK.COM
2 JulFormalizing Red Teaming Offensive Methodology as a Multi-Agent AI ArchitectureThreat actors are integrating AI into their exploit chains, accelerating reconnaissance, automating vulnerability discovery, and scaling social engineering in ways that compress the timeline between initial access and impact. The barrier to sophisticated offensive operations is d…RAPID7.COM
2 JulCisco confirms exploitation of critical Unified CM flaw.DHS investigates hack of information-sharing network. Suspected Scattered Spider member extradited to the US.THECYBERWIRE.COM
2 JulFortiBleed campaign traced to INC and Lynx ransomware operationsResearchers are also investigating the role of a suspected zero-day vulnerability.CYBERSECURITYDIVE.COM
2 JulApple’s Hide My Email doesn’t hide it very wellA year ago a researcher found a vulnerability in Apple's Hide My Email feature and now he's tired of waiting for a fix.MALWAREBYTES.COM
2 JulFrom Cloud to Chaos: Defining Shared Responsibility for AI SecurityFor 15 years (!), many of us who have touched cloud security have struggled with the shared responsibility model for cloud security. As with many “cyber things,” the theory is simple. Multiple vendors, consulting firms, and industry bodies have published deceptively clear matrice…MEDIUM.COM
2 JulCatan and MouseWhat do board games and cybersecurity have in common? Pattern recognition. Strategy. Adaptation. In this week’s Threat Source Bill explores why curiosity may be a defender’s most valuable skill.TALOSINTELLIGENCE.COM
2 JulApple Reverses Age-Old Patch Policy to Keep Up With AIExpect more compressed patching cycles from Apple going forward, as attackers leverage artificial intelligence to reduce time to exploit.DARKREADING.COM
2 JulFortiBleed Actors Collaborating With Inc, Lynx Ransomware GangsAfter gaining a foothold in thousands of Fortinet firewalls, the attackers are starting to monetize that access, and are also piling on a Nextcloud zero-day bug.DARKREADING.COM
2 JulGlobal Schools Holdings Cites Two Injunctions in a Bid to Chill Our Reporting. It Won’t Work.My About page is pretty clear about legal threats: If you want to send me legal threats about my reporting or comments, knock yourself out, but don’t be surprised to see me report on your threat, any confidentiality sig blocks you may attach notwithstanding. I have been threatene…DATABREACHES.NET
2 JulThe people's AI?OpenAI considers an equity plan to share AI wealth with the public. Cisco confirms active exploitation of its unified CM platform. Researchers discover autonomous ransomware. The Vect ransomware operation partners with TeamPCP. The FortiBleed credential-harvesting campaign is lin…THECYBERWIRE.COM
2 JulLaunch of UK's National Cyber Action Plan delayed amid Labour leadership crisisThe plan had been due for publication on Monday, the sources said. It has been postponed amid the uncertainty over the governing Labour Party’s leadership contest, which opens July 9.THERECORD.MEDIA
2 JulLinux Tech Segment & Vulnerabilities Galore - PSW #933This week we have a technical segment based on the response to "Atomic Arch", an updated open-source tool to help you catch malicious packages. In the security news: - Exploitarium - A hot messy summer of vulnerabilities - AI Squatting - Linux LPE - no shortage of those - Fingerp…YOUTUBE.COM
2 JulDefense Gap in AI Security RaceAI is improving offensive security capabilities like vulnerability discovery and exploit generation at a rapid pace. Offensive work can tolerate high error rates, since only occasional success is needed. Defensive security cannot operate that way—detection, patching, and response…YOUTUBE.COM
1 JulPhantom Squatting: AI-Hallucinated Domains as a Software Supply Chain VectorAttackers can exploit LLM domain hallucinations through phantom squatting to target supply chains. Read the analysis to learn more. The post Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
1 JulMicrosoft wants to stop unwanted bots from entering Teams meetingsA new Microsoft Teams admin policy, Manage external bots and their access to meetings, gives organizations greater visibility and control over external bots in meetings. The policy identifies bots and applies safeguards before they are admitted. Microsoft will begin retiring the …HELPNETSECURITY.COM
1 Jul KEVDetection engineering: A programmatic approach to identifying cyber threatsDetection engineering, which was once a niche practice among mostly large companies, appears to have evolved into a capability that organizations across industries now consider essential to their security operations. What is detection engineering? Detection engineering is about c…CSOONLINE.COM
1 JulNika: Open-source code analysis toolMany serious security bugs in web applications sit across several files at once. Request data enters through a controller, moves through data objects and service layers, and turns dangerous only when it reaches a sensitive operation such as a database query or a file action. A sc…HELPNETSECURITY.COM
1 JulRisky Bulletin: Researcher drops giant cache of zero-daysAn anonymous researcher has dropped a giant cache of zero-day exploits, a sensitive DHS network got hacked, the US Supreme Court restricts geofence warrants, and security firm Huntress has denied accusations of a malicious insider.RISKY.BIZ
1 JulAnthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export ControlsAnthropic is putting Claude Fable 5 back online worldwide. On June 30, the U.S. Commerce Department lifted the export controls it had imposed on Fable and its more tightly controlled sibling Mythos 5 about two and a half weeks earlier. Fable 5 returns to users on Wednesday, …THEHACKERNEWS.COM
1 JulCasey Ellis on How AI Is Reshaping Vulnerability Research and PatchingIn this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo sits down with Casey Ellis, founder of Bugcrowd and co-founder of disclose.io, to explore how AI is reshaping vulnerability research, bug bounty programs, and the future of cyber defense. The…THECYBERWIRE.COM
1 JulClaude Sonnet 5 includes safeguards against dangerous cyber useAnthropic has introduced Claude Sonnet 5, the latest version of its general-purpose AI model, with improved reasoning, coding, tool use, and knowledge work capabilities. The model can make plans, use tools such as browsers and terminals, and complete tasks autonomously. Scores fo…HELPNETSECURITY.COM
1 JulPerformance Through People as Executives Struggle and Mentorship Matters - Greg Hoffman - BSW #454One of the biggest questions most executives ask is "Why does it still feel this hard when the talent is clearly there?" The answer, in almost every case, is not a people problem. It is an environment problem. And environment is something a leader can build. Greg Hoffman, Preside…YOUTUBE.COM
1 JulClaude Helped a Hacker Find a Way to Issue Tickets to Almost Every US Music FestivalA researcher found that using Anthropic’s Claude Opus 4.7, he could break into the website of Front Gate—used by every festival from Lollapalooza to Bonnaroo—and freely issue any ticket he chose.WIRED.COM
1 JulGuardFall Flaw Hits 10 of 11 Popular Open-Source AI AgentsResearchers found a shell injection flaw in 10 of 11 popular open-source AI agents, allowing attackers to bypass command filters. Adversa AI just published a survey, titled “GuardFall: a universal shell injection vulnerability in open-source AI agents,” of eleven open…SECURITYAFFAIRS.COM
1 JulNetzilo adds runtime governance for AI agents across major platformsNetzilo has announced expanded AI agent governance and runtime enforcement capabilities for Amazon Bedrock AgentCore and other major AI agent harnesses. As enterprises move AI agents from experimentation into production, agents are becoming a new enterprise edge. They operate acr…HELPNETSECURITY.COM
1 JulIntruder offers Free security plan for lean IT and security teamsIntruder has announced the launch of its Free plan, providing security, IT, and DevOps teams ongoing access to professional-grade vulnerability management, cloud security, and attack surface management at no cost. Smaller organizations face the same threats as Fortune 500 compani…HELPNETSECURITY.COM
1 JulRustDuck: The Botnet That’s Still Small but Engineering Like It Plans to GrowRustDuck is a small, evolving DDoS botnet migrating to Rust. It uses advanced encryption, anti-analysis evasion, and exploits known IoT flaws. Since February 2026, researchers at QiAnXin’s XLab have been tracking a new malware family, called RustDuck, that hijacks routers, …SECURITYAFFAIRS.COM
1 JulOver 900 Oracle E-Business instances exposed to ongoing attacksOver 900 Oracle E-Business Suite (EBS) instances have been found exposed online amid ongoing attacks exploiting a critical security flaw. [...]BLEEPINGCOMPUTER.COM
1 JulBioShocking: when “gaming” AI agents is no longer a gameResearchers warned AI vendors about a proof-of-concept called BioShiocking that tricks agents by gamifying the outcome.MALWAREBYTES.COM
1 JulU.S. lifting export control restrictions on Anthropic’s Mythos, FableThe company and the Commerce Department say they have reached an agreement that will see the AI models released publicly with new guardrails and classifiers. The post U.S. lifting export control restrictions on Anthropic’s Mythos, Fable appeared first on CyberScoop .CYBERSCOOP.COM
1 JulCaught in the Octopus Trap: Unauthenticated RCE in Argo CD with CodeQLSynacktiv has discovered an unauthenticated arbitrary code execution vulnerability in ArgoCD's repo-server component, potentially allowing full cluster compromise. This article explains how the vulnerability was identified using CodeQL, details the exploitation process to gain co…SYNACKTIV.COM
1 JulAdobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign ClassicAdobe has released patches for multiple maximum-severity security flaws impacting Adobe ColdFusion and Adobe Campaign Classic. The ColdFusion updates "resolves critical and important vulnerabilities that could lead to arbitrary code execution, privilege escalation, arbitrary file…THEHACKERNEWS.COM
1 JulCritical flaw in Oracle E-Business Suite is under immediate threatResearchers warn that successful exploitation of the vulnerability could allow an attacker to compromise Oracle Payments.CYBERSECURITYDIVE.COM
1 Jul5 Myths About AI in the SOC Security Teams Need to RethinkAI is now part of almost every conversation in security operations. Most teams are already investing in it, experimenting with it, or trying to understand where it fits. The challenge is not whether to adopt AI, but how to apply it in a way that actually improves outcomes. At the…RAPID7.COM
1 JulWebinar: Why traditional email security is no longer enoughModern phishing, business email compromise, and account takeover attacks increasingly exploit trusted identities and legitimate business workflows, making them harder for traditional email defenses to detect. This webinar explores how behavioral AI can help organizations automate…BLEEPINGCOMPUTER.COM
1 JulResearchers spot exploitation of another critical Oracle defectThe defect impacts a popular collection of business applications that attackers have hit before in widespread attack sprees. The post Researchers spot exploitation of another critical Oracle defect appeared first on CyberScoop .CYBERSCOOP.COM
1 JulThe AI lock comes off.The US restores exports of Anthropic’s most advanced AI models. Adobe and Citrix rush out critical patches. RustDuck emerges as a fast-evolving DDoS threat. The Gentlemen raise the stakes with a new EDR-killing exploit. Rocket lab bets big on Iridium. Researchers unveil browser-o…THECYBERWIRE.COM
1 JulNew ChocoPoC malware targets researchers via trojanized PoC exploitsMultiple weaponized proof-of-concept (PoC) exploits on GitHub were found delivering a Python-based remote access trojan (RAT) named ChocoPoC that can execute commands and steal sensitive data in a campaign believed to target cybersecurity researchers. [...]BLEEPINGCOMPUTER.COM
1 JulOONI: LaLiga piracy blocks disrupted over 500,000 legitimate sitesThe Open Observatory of Network Interference (OONI) reports that Spain's IP-based anti-piracy blocking campaign against unauthorized LaLiga streams caused widespread collateral damage. Specifically, the actions have temporarily disrupted access to more than half a million legitim…CYBERINSIDER.COM
1 JulKubota says hackers had month-long access to network systemsKubota North America Corporation disclosed that hackers had access to some of its network systems for more than a month earlier this year. [...]BLEEPINGCOMPUTER.COM
30 JunMalicious Perplexity Chrome Extension Intercepted Searches and Address Bar InputMicrosoft has found a malicious Chrome extension that posed as the AI search engine Perplexity and quietly logged what people searched for. It routed every query and every character typed into the address bar through an attacker-controlled server before redirecting users to real …THEHACKERNEWS.COM
30 JunCybersecurity jobs available right now: June 30, 2026AI Offensive Security Engineer AGAPI | UAE | On-site – View job details As an AI Offensive Security Engineer, you will leverage AI and LLMs to accelerate offensive security research, exploit development, vulnerability discovery, and security automation. You will v…HELPNETSECURITY.COM
30 JunVulnerability reports are arriving faster than GitHub can review themAcross the open source world, people are reporting software flaws in record numbers, and the systems built to verify those reports are straining under the weight. The GitHub Advisory Database, which feeds automated security alerts to millions of projects, has reached a point wher…HELPNETSECURITY.COM
30 JunHottest cybersecurity open-source tools of the month: June 2026Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across diverse settings. OWASP Agent Memory Guard: Stop AI agents from being weaponized through their own memory AI a…HELPNETSECURITY.COM
30 JunOpenClaw for iOS: The viral open-source AI agent comes to iPhone and iPadOpenClaw, a self-hosted personal AI assistant that connects to existing chat apps, is now available on iPhone, iPad and Apple Watch. The release brings chat, real-time voice conversations, approvals, device capabilities, and private automations to iOS. Connecting OpenClaw to iPho…HELPNETSECURITY.COM
30 JunReducing Attack Surface & Evaluating Efficiency in Agents - ASW #389SquidBleed reveals another vuln that's been lurking for decades, but its real lesson is in managing an attack surface. Regardless of whatever programming language you use, removing code is one of the best security steps you can take, followed by changing default configs to turn o…YOUTUBE.COM
30 JunHow ransomware syndicates weaponize corporate-style organizationFrom outsourced labor to tiered pricing models, an inside look at how today's top ransomware threats operate less like rogue hackers and more like Fortune 500 companies. The post How ransomware syndicates weaponize corporate-style organization appeared first on CyberScoop .CYBERSCOOP.COM
30 JunCISA: Windows BlueHammer flaw now exploited by ransomware gangsCISA confirmed on Monday that ransomware gangs are now exploiting a Microsoft Defender privilege escalation vulnerability, dubbed BlueHammer, that has previously been abused in zero-day attacks. [...]BLEEPINGCOMPUTER.COM
30 JunCritical SimpleHelp Vulnerability Exploited for Malware DeliveryThe threat actor is focused on collecting credentials, SSH keys, cryptocurrency wallets, and development tooling. The post Critical SimpleHelp Vulnerability Exploited for Malware Delivery appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunShipping post-quantum cryptography to PythonPost-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency , we implemented support for ML-KEM, the NIST-standard key-establishment primitive, and ML-DSA, the NIST-standard digital-signature primitive, in pyc…TRAILOFBITS.COM
30 JunCloser than Cuba: the Able Archer Nuclear Crisis of 1983It's November of 1983, the closest the world came to nuclear war, some may argue even closer than the Cuban Missile Crisis of 1962. Yet the Able Archer 1983 exercise incident is relatively unknown by comparison. A series of events that started with the Soviet shootdown of a Korea…THECYBERWIRE.COM
30 JunMalicious Chromium extension spoofs Perplexity AI to hijack browser searchesGoogle has removed a malicious browser extension masquerading as Perplexity AI after Microsoft researchers found it was intercepting users’ search traffic and routing queries through attacker-controlled servers before forwarding them to legitimate search engines. Microsoft Threat…CSOONLINE.COM
30 JunInsurance giant Aflac discloses data breach after subsidiary hackAmerican insurance giant Aflac has disclosed a new data breach after attackers breached its Japan subsidiary's systems and stole personal and bank account information. [...]BLEEPINGCOMPUTER.COM
30 JunHacker Conversations: Chris Thompson, Former Head of IBM X-Force Red, Co-Founder of RemoteThreatChris Thompson's journey took him from hacking game controls as a teenager to founding IBM’s X-Force Red team. The post Hacker Conversations: Chris Thompson, Former Head of IBM X-Force Red, Co-Founder of RemoteThreat appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunExploitation of Recent Oracle E-Business Suite Vulnerability BeginsThe critical-severity defect allows unauthenticated attackers to take over the E-Business Suite’s Payments product. The post Exploitation of Recent Oracle E-Business Suite Vulnerability Begins appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunDecades-Old Bash Tricks Expose AI Coding Agents to Supply Chain AttacksDecades-old Bash shell tricks can bypass safeguards in most open source AI coding agents, potentially turning malicious repositories into supply chain attack vectors. The post Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunAikido Security acquires Root to expand backported fixes for open source vulnerabilitiesAikido Security has acquired Root, uniting behind a shared mission to make it easy for developers and agents to build with secure open source and tackle the growing threat of supply chain attacks. Open source is the foundation of almost every application in the world, and it has …HELPNETSECURITY.COM
30 JunJamf enables AI Governance and shadow AI detection on MacJamf has announced general availability of AI Governance, a new capability within Jamf for Mac that enables IT and security teams to discover actively-used AI tools, enforce policy controls, and generate audit-ready reporting. Many organizations struggle to confidently audit and …HELPNETSECURITY.COM
30 JunInsurance giant Aflac discloses data breach at Japan subsidiarySergiu Gatlan reports: American insurance giant Aflac has disclosed a new data breach after attackers breached its Japan subsidiary’s systems and stole personal and bank account information. Aflac (short for American Family Life Assurance Company) is a Fortune 500 company a…DATABREACHES.NET
30 JunGuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection RisksThe safety check that is supposed to stop an AI coding agent from running a dangerous command can be walked straight past using a shell trick that has been public for decades. New research from Adversa AI, which is named the bypass GuardFall, found it works against ten of th…THEHACKERNEWS.COM
30 Jun KEVUS Supreme Court rules that geofence searches generally require warrants.Maximum-severity SimpleHelp flaw is now actively exploited. US government offers $10 million reward for info on Russian state-backed hackers.THECYBERWIRE.COM
30 JunCritical flaw in SimpleHelp exploited in attacks targeting sensitive credentialsResearchers found two previously undisclosed malware samples used to steal AI assistant tokens and other valuable secrets.CYBERSECURITYDIVE.COM
30 JunNissan Discloses Employee Data Breach Linked to Oracle Zero-DayNissan says employees' data was stolen via the Oracle PeopleSoft zero-day campaignINFOSECURITY-MAGAZINE.COM
30 JunCritical SimpleHelp Vulnerability Exploited For Malware DeliveryAttackers exploited a critical SimpleHelp RMM bug to deploy TaskWeaver and Djinn Stealer malwareINFOSECURITY-MAGAZINE.COM
30 JunFake Perplexity extension on Chrome Web Store tracked searchesA malicious extension in the Chrome Web Store is masquerading as the Perplexity AI answer engine, intercepting search traffic and collecting browsing information. [...]BLEEPINGCOMPUTER.COM
30 JunThe Human Element: Building A Trusted Workforce in the Age of DPRK Employment FraudFrom Nisos: Earlier this year, our DPRK employment fraud investigation revealed how North Korean operatives infiltrate US companies at industrial scale. In June, we released Part 2 of our research, featured on Nicole Perlroth’s “To Catch a Thief” podcast, that t…DATABREACHES.NET
30 JunThe Fall of XSS Forum: From DaMaGeLaB to the 2025 takedownRansomnews has published a history and analysis of XSS Forum from its inception to its seizure in 2025. There is so much that is interesting and informative in their report that it’s hard to know what to mention here, but here are just two portions below: As an overview: XS…DATABREACHES.NET
30 JunHackers Steal Data of 4.38 Million Aflac Japan CustomersHackers stole data from 4.38 million Aflac Japan customers after accessing its systems for 10 days before the breach was detected. Aflac Japan disclosed that hackers stole the personal information of 4.38 million customers and agents after gaining access to its systems between Ju…SECURITYAFFAIRS.COM
30 JunKaspersky Lab experts have discovered a new attack vector and toolkit for compromising corporate Gmail accountsKaspersky Labs writes: It is used by the ToddyCat group. Kaspersky Lab experts have discovered a new attack vector and toolkit for compromising corporate Gmail accounts. Using this toolkit, attackers can access user accounts via an API, read conversations, and harvest data from c…DATABREACHES.NET
30 Jun KEVAnton’s Security Blog Quarterly Q2 2026My Anton’s Security Blog Quarterly covers both Anton on Security and my posts from Google Cloud blog , Google Cloud community blog , and our Cloud Security Podcast ( subscribe on Spotify, now with VIDEO ). Top 10 posts with the most lifetime views (excluding paper announcement bl…MEDIUM.COM
30 JunThe court draws a privacy line.The Supreme Court limits geofence warrants. DHS moves to expand CISA. The State Department offers $10 million for Russian hackers. A legal theory could reshape EU-U.S. data sharing. Plus, cyberattacks hit D.C. housing, Oracle and SimpleHelp flaws face active exploitation, malware…THECYBERWIRE.COM
30 JunScammers race to cash in on Venezuelan earthquake disasterScammers wasted no time exploiting Venezuela's devastating earthquake, with researchers uncovering 212 newly-registered relief-themed domains in just five days. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
30 JunFake Bug Report Hijacks AI Coding Agents at Scale"Agentjacking" is the latest demonstration of how easily attackers can exploit an AI agent's inability to differentiate between content and instructions.DARKREADING.COM
30 JunUK journalists and NGOs risk terrorism prosecutions under new security billMEE reports: New national security legislation being rushed through the UK’s parliament could criminalise British foreign correspondents and NGO workers engaging with designated state-backed groups, experts warn. The National Security (State Threats) Bill, which is moving t…DATABREACHES.NET
30 JunThe Green Shirt AI JailbreakAn LLM refused a request until the prompt included fabricated internal reasoning claiming the action was acceptable because of a "green shirt." The model then complied, illustrating how prompt-based attacks can bypass intended restrictions. Unlike traditional software exploits, m…YOUTUBE.COM
30 JunUS Supreme Court limits police access to people’s location historyThe US Supreme Court has ruled that law enforcement's acquisition of historical location data through geofence warrants constitutes a Fourth Amendment search, marking a major victory for digital privacy. While the Court stopped short of declaring geofence warrants unconstitutiona…CYBERINSIDER.COM
30 JunAnthropic to restore Claude Fable access on WednesdayAnthropic has confirmed that the Department of Commerce has lifted export controls on Claude's two most powerful models, Fable 5 and Mythos 5. [...]BLEEPINGCOMPUTER.COM
30 JunXSS.is, The Forum That Ran the Ransomware Supply Chain Is Down. The Market Isn’tPolice arrested the alleged admin of XSS.is, a major cybercrime forum whose trusted escrow service helped power the underground economy. On 22 July 2025, French and Ukrainian police arrested a 38-year-old man in Kyiv and shut down XSS.is, the most influential Russian-language cyb…SECURITYAFFAIRS.COM
30 Jun KEVSN 1085: A SOTA State-Sponsored Campaign - AI's New Superpower: Loop EngineeringAI is now uncovering and fixing thousands of hidden software bugs faster than humans can keep up, but not everyone is playing by the rules. Find out how state-sponsored attackers and careless disclosures are turning the cybersecurity playbook upside down. Win10's popularity force…TWIT.TV
29 JunSponsored: Corelight’s blueprint for AI-era defenceIn this sponsored interview James Wilson chats with Corelight’s VP of Product Vijit Nair about defence strategies for the AI era. When agents can find and exploit vulnerabilities at machine speed, you need to balance between proactive and reactive measures. On the proactive side,…RISKY.BIZ
29 JunUS Restricts Frontier AI modelsUS Loosens Anthropic Claude Mythos Access, Unpatchable iPhone Exploit Emerges, and CISO Burnout Drives Fractional Shift Washington granted a partial reprieve allowing Anthropic's Claude Mythos to be released to more than 100 approved U.S. firms and institutions after export contr…CYBERSECURITYTODAY.LIBSYN.COM
29 JunDarkMoon: Open-source AI pentesting platformPenetration testing has long run on expert time, with specialists spending days probing a network or web application by hand. Manual engagements stretch across weeks, expert consultants run into thousands of dollars a day, and results vary with the tester. Automation promises to …HELPNETSECURITY.COM
29 JunFrom mythos to reality: Why the 2026 state of pentesting report proves the need for programmatic defensesAI can find zero-days in minutes. Your defense strategy must evolve now.CYBERSECURITYDIVE.COM
29 JunFixing pentesting, Meta is destroying its engineering org, the weekly news - ESW #465Interview with Adriel Desautels - the pentest is broken Adriel joins us for a discussion on the state of penetration testing, why it hasn't done much to help security teams over the last 20 years, and why AI won't save it. Segment Resources: - https://hbr.org/2026/04/boards-are-f…YOUTUBE.COM
29 JunUS Federal Insurance Regulator Confirms Data Breach Via Oracle FlawAn attacker has exploited a zero day in Oracle Peoplesoft to gain access to the IT systems of the NAIC, the standard-setting association for the US federal insurance systemINFOSECURITY-MAGAZINE.COM
29 JunRobot Police OfficersWe’ve taken one small step towards robot police officers: a drone capable of disarming a suspect: In a June 22 video posted on the Sacramento County Sheriff’s Office’s Instagram page, an officer wearing goggles can be seen operating a drone to retrieve a knife from an armed…SCHNEIER.COM
29 JunMozilla warns of indirect prompt injection risk in AI coding agentsA malicious GitHub repository can silently compromise a developer’s machine without containing a single line of malicious code, security researchers at Mozilla’s Zero Day Investigative Network (0DIN) warned. The attack The proof-of-concept attack targets AI-powered co…HELPNETSECURITY.COM
29 Jun‘DirtyClone’ Linux Kernel Vulnerability Leads to Root AccessA variant of DirtyFrag, the flaw allows unprivileged local users to manipulate the Linux page cache and gain root privileges. The post ‘DirtyClone’ Linux Kernel Vulnerability Leads to Root Access appeared first on SecurityWeek .SECURITYWEEK.COM
29 JunThe Red Agent POV: Exploiting Broken Object-Level Authorization in an Airline GraphQL APIPart 2: How the Red Agent bypassed backend resolvers to expose an entire airline booking database in fifteen minutesWIZ.IO
29 Jun236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet DrainersNew findings unearthed by Infoblox show that more than 236,000 websites are using investment scam templates built using a legitimate Chinese open-source, cross-platform application development framework called DCloud Uni-App. The templates power bogus cryptocurrency exchanges, mu…THEHACKERNEWS.COM
29 JunCharting your way in: Helm template injectionDuring the audit of a Kubernetes cluster, we encountered an injection in a Helm template applied through ArgoCD. To our surprise, very few resources exist regarding YAML injection in vulnerable Helm templates. In this blog post, we will explore this kind of vulnerability and how …SYNACKTIV.COM
29 JunUK businesses fear stigma of ransomwareAlex Scroxton reports: Fear of stigmatisation is likely leading businesses across the UK to drastically underreport data on ransomware attacks, especially when they have paid a ransom to a cyber criminal gang, as admission of such is often seen as supporting further criminal acti…DATABREACHES.NET
29 JunCentral Bank of Libya investigates alleged data leak after cyberattackSafaAlharathy reports: Libya’s central bank (CBL) says it is investigating data published on the dark web following a recent cyberattack. In a statement, the bank said its technical teams, working with international experts, were analysing the data to determine its nature and whe…DATABREACHES.NET
29 JunZA: Copying the wrong person on an email could be considered a data breach in South AfricaJan Vermeulen reports: Misdirected internal emails that expose personal information can trigger mandatory data breach reporting under South Africa’s data privacy law, POPIA, even when the disclosure was accidental. Armand Swart, Hlonelwa Lutuli, and Isabella Keeves from Werksmans…DATABREACHES.NET
29 JunOne Honeypot Ends the AttackMany attackers spend their first moments inside a compromised network performing discovery. According to this red team perspective, a properly deployed honeypot or canary token can immediately reveal that activity. That means organizations don't always have to catch every exploit…YOUTUBE.COM
29 JunFactoring RSA Keys with Many ZerosInteresting research on a new class of weak RSA keys: keys with lots of zeros. It turns out that these keys are out in the wild. The badkeys project is an open-source service that checks public keys for known vulnerabilities. While developing this tool, Hanno collected a massive …SCHNEIER.COM
29 JunInside the Advisory Database and what happens when vulnerability volume breaks recordsThe GitHub Advisory Database is processing more vulnerability reports than ever before. Here's what's driving the surge, how we're responding, and how the community can help. The post Inside the Advisory Database and what happens when vulnerability volume breaks records appeared …GITHUB.BLOG
29 JunUS racks up about 400 wins over illegal World Cup streaming sitesThe World Cup’s organizing body, FIFA, helped identify hundreds of domains taken down in an action organized by the U.S., along with the help of U.S. broadcaster NBC Universal and other entities.THERECORD.MEDIA
29 JunNissan hit by Oracle PeopleSoft cyberattack exposing internal dataNissan North America has informed employees that a cyberattack targeting Oracle PeopleSoft systems exposed sensitive personnel records, making the automaker one of the latest known victims linked to a broader campaign exploiting a critical vulnerability in the widely used HR plat…CYBERINSIDER.COM
29 JunNI: Updated warning to parents over schools cyber attackNiall Glynn and Auryn Cox report: The number of schools in Northern Ireland affected by a recent cyber-attack is larger than previously thought. In a letter issued by the Education Authority (EA) on Thursday, some parents were warned that their child’s personal data may hav…DATABREACHES.NET
29 JunMOVEit Breach Defendants Lose 2nd Bid to Toss Negligence ClaimsChristopher Brown reports: Bellwether defendants in multi-district litigation over a massive data breach of Progress Software’s MOVEit file-transfer application failed to convince a federal court to toss negligence claims against them under the laws of California, Indiana, Michig…DATABREACHES.NET
29 JunAI behind the velvet rope.The White House keeps frontier AI models on a short leash. Russian threat actors increasingly target secure messaging platforms. DirtyClone is a high-severity Linux kernel privilege escalation flaw. An investigation claims federal websites are violating privacy rules. Microsoft d…THECYBERWIRE.COM
29 JunNissan discloses employee data breach linked to Oracle zero-day attacksNissan is warning that it suffered a data breach affecting current and former employees after threat actors exploited an Oracle PeopleSoft vulnerability in data theft attacks previously linked to the ShinyHunters extortion group. [...]BLEEPINGCOMPUTER.COM
29 JunNAIC says public data stolen in ShinyHunters' PeopleSoft breachThe National Association of Insurance Commissioners (NAIC) says the ShinyHunters extortion group stole only publicly available data, outdated logs, and configuration files after breaching its systems by exploiting a zero-day vulnerability in an Oracle PeopleSoft server. [...]BLEEPINGCOMPUTER.COM
29 JunStop Building a 2003 SOC with AI: A Modern People & Process Framework (Part 1)One particular aspect of an agentic or AI-powered SOC (but NOT “humanless SOC ”) has bothered me over the last few months: specifically, the people and process side of such a SOC. If you recall my blog posts ( part 1 , part 2 and this video ) about AI SOC readiness, I hinted at c…MEDIUM.COM
29 JunVulnerabilities Expose Private Data in Indian Government SystemsOne critical vulnerability, among many discovered by a researcher, could have allowed anyone to walk in and take over a national government portal.DARKREADING.COM
29 JunEXCLUSIVE: Top-100 Law Firm Fox Rothschild Suffers Data Breach and Leak by Silent Ransom GroupFox Rothschild is a top-100 law firm whose articles and resources have been cited on DataBreaches.net and PogoWasRight.org dozens of times over the years. This time, however, they are the subject of a post because they were victims of a data breach by a well-known group that targ…DATABREACHES.NET
28 JunWeek in review: Fortibleed campaign’s impact on orgs, Cisco Unified CM flaw exploitedHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: Encrypted DNS still tells an eavesdropper where to look Encrypted DNS runs across much of the Internet. DNS over TLS, HTTPS, and QUIC keep the contents of a query away from anyone wa…HELPNETSECURITY.COM
28 JunData breach exposes up to 14.2 million email logins at six ISPsJapanese telecommunications operator KDDI Corporation disclosed a data breach where threat actors gained access to one of its email systems used by five other internet service providers (ISPs) in the country. [...]BLEEPINGCOMPUTER.COM
28 JunAssuranceAmerica breach may have affected more than 1.1 million people in seven statesKrys Shahin and Christopher Buchanan report: State officials are warning at least 1.1 million people across seven states may be impacted by an AssuranceAmerica data breach. Notices about the breach were sent to California, Massachusetts, Nebraska, South Carolina, Texas, Vermont, …DATABREACHES.NET
28 JunNZ pharmacy scrambles to scrub internet of patients’ private messagesMary Argue reports: A Wellington pharmacy at the centre of a data leak says sensitive patient information has now been scrubbed from the internet. Unichem Petone said it was contacting 29 patients affected by what it described as an error on the website that saw patients’ p…DATABREACHES.NET
28 JunSysco - 2,691,852 breached accountsIn June 2026, the food distribution company Sysco was targeted by a ShinyHunters "pay or leak" extortion campaign . Data was subsequently published containing 2.7M unique email addresses belonging to staff and customers. The data also contained largely corporate contact informati…HAVEIBEENPWNED.COM
28 JunKDDI Data Breach Impacts up to 14.2 Million Email Accounts at Six ISPsKDDI Corporation disclosed a breach affecting up to 14.2 million email accounts after attackers exploited a vulnerability in third-party software. KDDI Corporation disclosed a data breach that exposed up to 14.2 million email accounts across six Japanese internet service provider…SECURITYAFFAIRS.COM
28 JunA KDDI data breach has put up to 14.2 million ISP email logins at risk across JapanJames Whitmore reports: Data breach at Japanese telecoms operator KDDI may have exposed up to 14.22 million email addresses and passwords linked to ISP mail services, after attackers gained unauthorised access to a system used by six providers in Japan. KDDI said it confirmed the…DATABREACHES.NET
27 JunWhy Car Dealerships Are Prime Cyber Targets: Fraud, Resilience, and Security Leadership with Jennifer HuttonCybersecurity Today would like to than Material Security for their support of this podcast. On Cybersecurity Today on the Weekend, the host speaks with Jennifer Hutton, a cybersecurity leader in the car dealership sector, about how she entered cybersecurity through increasing cyb…CYBERSECURITYTODAY.LIBSYN.COM
27 Jun KEVKlue supply-chain attack impacts cybersecurity firms.Tata Electronics and Bajaj Auto continue recovery from cyberattacks. CISA warns of actively exploited PTC and Cisco vulnerabilities.THECYBERWIRE.COM
27 JunSurviving the surge of new Linux LPE : Defense in Depth not deadThanks to AI-assisted vulnerability research and kernel patch diffing that breaks "responsible disclosure" embargos, it's quite the overwhelming time for defenders. There's been a weekly reveal of new Linux critical vulnerabilities, with full exploit scripts made public days befo…SYNACKTIV.COM
27 JunExploiting the Tesla Wall Connector from its charge port connector - Part 2: bypassing the anti-downgradeIn a previous article, we presented an attack against the Tesla Wall Connector Gen 3 used during Pwn2Own Automotive 2025. The exploit chain relied on a simple fact: there was no anti-downgrade mechanism. Once we could speak UDS over the charging cable, we could just write an old,…SYNACKTIV.COM
27 JunMake it Blink: Over-the-Air Exploitation of the Philips Hue BridgeThe year-end edition of Pwn2Own took place in Cork, Ireland. For the first time, this event featured smart home devices, including the Amazon Smart Plug, Home Assistant Green, and the Philips Hue Bridge. The attack scenario defined by the ZDI involved an adversary with access to …SYNACKTIV.COM
27 JunExploring cross-domain & cross-forest RBCDThe Resource-based Constrained Delegation (RBCD) attack is well-known from pentesters and attackers: by editing the msDS-AllowedToActOnBehalfOfOtherIdentity attribute of a machine account, an attacker can impersonate users on said machine. Even though this attack mechanism has be…SYNACKTIV.COM
27 Junmitmproxy for fun and profit: Interception and Analysis of Application TrafficA solid understanding of the protocols used by applications is a necessary prerequisite when assessing application security. In recent projects, we have had to intercept various types of network traffic across different platforms, including Linux, Android, and iOS. The purpose of…SYNACKTIV.COM
27 JunBeyond ACLs: Mapping Windows Privilege Escalation Paths with BloodHoundWindows privileges are special rights that grant processes the ability to perform sensitive operations. Some privileges allow bypassing standard Access Control List (ACL) checks, which can lead to significant security implications. While privileges like SeDebugPrivilege, SeImpers…SYNACKTIV.COM
27 JunOn the clock: Escaping VMware Workstation at Pwn2Own Berlin 2025At Pwn2Own Berlin 2025, we exploited VMware Workstation by abusing a Heap-Overflow in its PVSCSI controller implementation. The vulnerable allocation landed in the LFH allocator of Windows 11, whose exploit mitigations posed a major challenge. We overcame this through a complex i…SYNACKTIV.COM
27 JunLivewire: remote command execution through unmarshalingLivewire revolutionizes Laravel development by enabling real-time, interactive web interfaces using only PHP and Blade, removing the need of heavy JavaScript frameworks. Its innovative hydration system seamlessly instantiate and restores component states, supporting complex data …SYNACKTIV.COM
27 JunExploiting Anno 1404Anno 1404 is a strategy game developed by Related Designs and published by Ubisoft. It is a real-time strategy game that focuses on city management and construction. The Anno 1404: Venice expansion, released in 2010, includes an online and local area network multiplayer mode. Dur…SYNACKTIV.COM
27 Jun2025 Winter Challenge: QuinindromeA few months have passed and the first snowflakes have fallen since the end of the Synacktiv Summer Challenge. This event was a success, with one of the participants even finding a zero-day vulnerability while working on his solution! Although it hasn't been made public yet, it w…SYNACKTIV.COM
27 JunBreaking the BeeStation: Inside Our Pwn2Own 2025 Exploit JourneyThis article documents our successful exploitation at Pwn2Own Ireland 2025 against the BeeStation Plus. We walk through the full vulnerability research process, including attack surface enumeration, code auditing, exploit development, and ultimately obtaining a root shell on the …SYNACKTIV.COM
27 JunSite Unseen: Enumerating and Attacking Active Directory SitesActive Directory Sites are a feature allowing to optimize network performance and bandwidth usage in AD internal environments. They are commonly implemented by large, geographically dispersed organizations spanning across multiple countries or continents. Sites did not receive mu…SYNACKTIV.COM
27 Junappledb_rs, a research support tool for Apple platformsOver the years, research on Apple platforms has become significantly more complex, largely due to the numerous countermeasures deployed by the Cupertino company. To address this challenge during our missions on these platforms, we developed appledb_rs: an open-source tool (https:…SYNACKTIV.COM
27 JunThe 'S' in Zoom, Stands for SecurityToday we uncover two (local) security flaws in Zoom's latest macOS client. First, a privilege escalation vulnerability, and second, a method to surreptitiously access a user's webcam and microphone (via Zoom).OBJECTIVE-SEE.ORG
27 Jun[0day] Abusing XLM Macros in SYLK FilesA 0day logic flaw in Microsoft Excel leads to 'remote' code execution on macOS, via malicious macros.OBJECTIVE-SEE.ORG
27 JunBurned by Fire(fox) (Part III)Recently, an attacker targeted (Mac) users via a Firefox 0day. In this third post, we analyze a second backdoor used in the attack, detailing its persistence, capabilities, and ultimate identify it a new variant of the cross-platform Mokes malware!OBJECTIVE-SEE.ORG
27 JunBurned by Fire(fox) (Part II)Recently, an attacker targeted (Mac) users via a Firefox 0day. In this second post, we fully reverse OSX.NetWire.A, revealing (for the first time!), its inner workings and complex capabilities.OBJECTIVE-SEE.ORG
27 JunBurned by Fire(fox) (Part I)Recently, an attacker targeted (Mac) users via a Firefox 0day. In this first post, we triage and identify the malware (OSX.NetWire.A) utilized in this attack, identifying its methods of persistence, and more!OBJECTIVE-SEE.ORG
27 Jun[0day] Mojave's Sandbox is LeakyThe macOS sandbox is seeks to prevent malicious applications from surreptitiously spy on unsuspecting users. Turns out, it's trivial to sidestep some of these protections, resulting in significant privacy implications!OBJECTIVE-SEE.ORG
27 JunRemote Mac Exploitation Via Custom URL SchemesThe WINDSHIFT APT group is successfully infecting Macs with a novel infection mechanism. By abusing custom URL scheme handlers and minimal user interaction, Macs can be remotely compromised!OBJECTIVE-SEE.ORG
27 Jun[0day] Synthetic RealityIf you can programmatically generate synthetic mouse clicks, you can break macOS! Approving kernel extensions, dismissing privacy alerts, and much more more...OBJECTIVE-SEE.ORG
27 JunEscaping the Microsoft Office SandboxImagine you've gained remote code execution on a Mac via a malicious Word document. Turns out, you're still stuck in a sandbox. However, via a faulty regex, you can escape and persist!OBJECTIVE-SEE.ORG
27 Jun[0day] Bypassing SIP via SandboxingIn this guest blog post @CodeColorist writes about a neat macOS vulnerability. Ironically, by abusing security mechanisms such as sandboxing, macOS can be coerced to load an untrusted library, into a SIP-entitled process!OBJECTIVE-SEE.ORG
27 JunAn Unpatched Kernel BugOn my flight to ShmooCon, I managed to panic my fully-patched MacBook. Here we analyze the kernel panic report, finding that Apple's AMDRadeonX4150 kext is responsible for the crash.OBJECTIVE-SEE.ORG
27 JunTwo Bugs, One Func(), part threeAnalyzing code within the macOS kernel audit subsystem uncovered an exploitable heap overflow.OBJECTIVE-SEE.ORG
27 JunNew Attack, Old TricksA Word document targets Mac users with malicious macros and an open-source payload.OBJECTIVE-SEE.ORG
27 Jun[0day] Bypassing Apple's System Integrity ProtectionRead how an attacker can bypass Apple's SIP, via the local OS upgrade processOBJECTIVE-SEE.ORG
27 JunPhoenix: RootPipe lives! ...even on OS X 10.10.3Exploiting RootPipe on OS X 10.10.3OBJECTIVE-SEE.ORG
27 JunNAIC suspends investment risk designations after cyber attackThe National Association of Insurance Commissioners (NAIC) is the U.S. standard-setting and regulatory support organization. It is governed by the chief insurance regulators from the 50 states, the District of Columbia, and five U.S. territories. The organization serves the publi…DATABREACHES.NET
26 JunMalware gaslights AIMac Malware Gaslights AI, Major Info-Stealer Takedown, OpenAI's Patch the Planet, and FortiBleed Fallout Mac malware called "Gaslight," attributed to North Korea-aligned actors, plants fake system messages designed to derail AI-based analysis while stealing data and exfiltrating …CYBERSECURITYTODAY.LIBSYN.COM
26 JunGDPR at 10: Landmark data protections, increasing business burdenTen years have passed since the General Data Protection Regulation (GDPR) came into force, and the results are mixed. While data protection has become more firmly established in European companies — and beyond — than ever before, the business world remains critical of the regulat…CSOONLINE.COM
26 JunModelplane: Open-source control plane for AI inferenceOrganizations that run open-weight models on hardware they own operate GPU fleets spread across clouds, neoclouds, and on-premise data centers. Each fleet handles model placement, replica scaling, infrastructure provisioning, weight distribution, and traffic routing. Teams have b…HELPNETSECURITY.COM
26 JunNew infosec products of the month: June 2026Here’s a look at the most interesting products from the past month, featuring releases from AISLE, Asimily, Blue Planet, depthfirst, Diligent, Drata, Elastic, Filigran, Flip, Hyland, IDnow, Legit Security, MazeBolt, Noma, Qodo, Ridge Security, Tigera, and WitnessAI. Asimily turns…HELPNETSECURITY.COM
26 JunWhat CISOs need to tell the board about zero trust in OT: A 90-day communication and action planI work as a principal specialist at a pipeline operator where Operational Technology (OT) is the backbone of the business. I do not report to the board or act as a CISO, but the issues that get raised to those levels affect my job every single day. Since the Colonial pipeline ran…CSOONLINE.COM
26 JunProposed US law would make AI risk reporting a legal obligationUS lawmakers on Thursday introduced a bill that would require developers of advanced AI models to report major safety and security incidents to the Commerce Department, establishing a federal oversight framework for high-risk AI systems. The proposed AI Incident Reporting Act wou…CSOONLINE.COM
26 JunMythos is a signal, not a siren: What frontier AI should change for CISOsWhen a new AI capability starts making headlines, I see the same pattern play out in boardrooms and executive staff meetings. The technology is introduced as a looming breakthrough for attackers. The conversation quickly shifts to worst-case scenarios. Then security leaders are a…CSOONLINE.COM
26 JunJapanese telco suffers breach exposing 14.2 million email passwordsKDDI has disclosed that an email system it operates for internet service providers (ISPs) was breached in a cyberattack, potentially exposing email account information belonging to customers of six Japanese service providers. The company says the intrusion exploited a vulnerabili…CYBERINSIDER.COM
26 JunLinux Foundation Unveils New Open Source Security Project AkritesIt will provide the tools and channels to report, patch, and disclose open source software vulnerabilities. The post Linux Foundation Unveils New Open Source Security Project Akrites appeared first on SecurityWeek .SECURITYWEEK.COM
26 JunRansomware gangs find Europe’s weakest link in third-party suppliersRansomware attacks against European organizations increased during the first months of 2026, with third-party suppliers becoming a major entry point for attackers. Black Kite examined 2,066 ransomware incidents across 31 countries between January 2025 and April 2026 in its 2026 E…HELPNETSECURITY.COM
26 JunCritical open-source projects get a new security frameworkOpen source software projects are getting a new framework for handling security vulnerabilities as AI shortens the time between flaw discovery and exploitation. The Linux Foundation has launched Akrites, an industry initiative that brings together technology companies, financial …HELPNETSECURITY.COM
26 JunCyberattacks pose a ‘threat to life’ in AustraliaAustralia’s Security Intelligence Organization (ASIO) has uncovered an attack on a critical infrastructure operator’s network. State-sponsored actors had compromised the network and were preparing to sabotage it, according to its director general, Mike Burgess. Other countries fa…CSOONLINE.COM
26 JunStop Chasing Every New ThreatCybersecurity teams naturally focus on new vulnerabilities, exploits, and attack techniques. But basic practices like patch management, firmware updates, and consistent security hygiene still prevent many successful compromises. Organizations that maintain strong fundamentals are…YOUTUBE.COM
26 JunMore Klue Breach Victims Identified as Hackers Get HackedRoughly two dozen companies have notified their customers of the Klue-Salesforce incident impact. The post More Klue Breach Victims Identified as Hackers Get Hacked appeared first on SecurityWeek .SECURITYWEEK.COM
26 Jun KEVTata Electronics and Bajaj Auto continue recovery from cyberattacks.Threat actors target critical infrastructure across Southeast Asia. CISA warns of actively exploited PTC vulnerability. Polish police disrupt SIM-swapping gang.THECYBERWIRE.COM
26 JunSoftware, AI companies form alliance to tackle open-source security flawsThe emergence of frontier AI models has increased the speed and capabilities of malicious hackers.CYBERSECURITYDIVE.COM
26 JunAmazon Q Flaw Enabled Cloud Credential Theft via Malicious RepositoriesAWS has patched the vulnerability and published its own advisory to inform customers about the potential impact. The post Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories appeared first on SecurityWeek .SECURITYWEEK.COM
26 JunMalware authors subvert AI detection systemsEnterprises that have turned to AI in order to boost their security defenses may have to reconsider their approach. Malware containing code that commands LLM-assisted products to abort their analysis or refuse to implement it is already circulating, according to a post from secur…CSOONLINE.COM
26 JunUnpatched macOS bug could allow tampering trusted applicationsSecurity duo Mysk has disclosed an unpatched macOS vulnerability that they say allows web-installed applications to silently modify other apps' binaries, potentially bypassing key macOS security protections. In a post published on X, Mysk said the issue affects macOS 26 and macOS…CYBERINSIDER.COM
26 JunCisco Adds NHI to Security Stack With Astrix, WideField AcquisitionsCisco joins a growing list of security platform providers who are betting that securing the agentic workforce means turning identity into the primary control plane.DARKREADING.COM
26 Jun KEVCISA sets urgent deadline to fix Cisco flaw exploited in attacksThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) is giving federal agencies until Sunday to patch a vulnerability in Cisco Unified Communications Manager Server that is being actively exploited. [...]BLEEPINGCOMPUTER.COM
26 JunThe Chinese Control the Majority of Argentina’s Squid FleetChinese companies control nearly two-thirds of Argentina’s own squid fleet.SCHNEIER.COM
26 Jun KEVFactory reset required.Tata Electronics and Bajaj Auto continue recovery from cyberattacks. FCC tightens undersea cable rules to bolster national security. CISA warns of actively exploited PTC vulnerability. Gamaredon expands toolkit, hides behind legitimate services. Iran-linked hackers turn public wa…THECYBERWIRE.COM
25 JunInteresting Paper Exploring Prompt InjectionThis is a fascinating explotation of how LLMs fall for prompt injection attacks. It turns out that they learn to recognize the style of text in different role/instruction blocks, and not just the tags. Their conclusion: Role tags were a formatting trick that became the security a…SCHNEIER.COM
25 JunRethinking the balance between AI oversight and innovationThe new CIO mandate is clear: facilitate AI adoption across the enterprise at speed. According to CIO.com’s State of the CIO survey, CEOs’ to p priority for their IT executives is to capitalize on AI . From researching to evaluating AI products, CIOs are now the central figures i…CSOONLINE.COM
25 JunGRC is broken. FedRAMP 20x might fix itWe are auditing a curated version of history. I’ve worked in security long enough now to know something most of us don’t really say out loud. A lot of compliance is theatre. Not all of it, and not all auditors or frameworks, but enough of it that most experienced CISOs know exact…CSOONLINE.COM
25 JunThe Policy Nobody Actually EnforcedMany organizations generate least-privilege IAM policies but never deploy them. That leaves existing permissions available for attackers to abuse after compromising workloads like CI/CD runners. Instead of depending on thousands of manually applied policies, Sandy Bird describes …YOUTUBE.COM
25 JunCloud Visibility, Fortibleed, hacking things the easy way - Sandy Bird - PSW #932First up is Sandy Bird from Sonrai discussing how to protect our cloud infrastructure! This segment is sponsored by Sonrai Security. Visit https://securityweekly.com/sonrai to learn more about them! Next up in the security news: - Help, I am Fortibleeding - Cisco SD-WAN needs hel…YOUTUBE.COM
25 JunYour Small Business Is a TargetMore than 90% of the economy depends on small and medium-sized businesses. At the same time, critical infrastructure spans far beyond power grids or defense systems. It includes industries like healthcare, financial services, food and agriculture, IT, communications, water, and c…YOUTUBE.COM
25 JunBeyond IOCs: AI-enabled threat intelligenceIn this week’s newsletter, Martin considers how AI will help threat intelligence by creating an easily queryable data source of intelligence reports.TALOSINTELLIGENCE.COM
25 JunBeware of “Parcel Expert” job offers: They’re parcel mule scamsMost parcel mule scams start with fake job offers that trick victims into handling stolen goods.MALWAREBYTES.COM
25 JunFraud goes door-to-door.This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner…THECYBERWIRE.COM
25 JunCisco Vulnerability Exploited Months Before Disclosure, Google WarnsA high-severity flaw in Cisco Catalyst SD-WAN Manager disclosed in early June was exploited as early as MarchINFOSECURITY-MAGAZINE.COM
25 JunTrust in Automated AI Vulnerability Scanning Collapses to 9%, New Study FindsCobalt study finds 20-percentage-point drop in number of organizations relying solely on AI automation for testingINFOSECURITY-MAGAZINE.COM
25 JunShopify Shop app users are seeing fake orders in purchase historiesScammers are placing fake purchase receipts inside Shopify's Shop app, exploiting users' trust in order-tracking applications to lure them into calling fraudulent customer support numbers. The campaign moves the long-running fake invoice scam beyond email, placing fraudulent rece…CYBERINSIDER.COM
25 JunJapan’s army used USB drives with Chinese malware for a yearJapan's Ground Self-Defense Force (JGSDF) reportedly used counterfeit USB flash drives infected with malware linked to previously identified Chinese threat activity on computers connected to sensitive military networks for nearly a year before the devices were discovered. Accordi…CYBERINSIDER.COM
25 JunCal Water Says No OT Systems Breached in Iranian Handala CyberattackMandiant has helped the California water utility investigate the cyberattack launched by Iranian hacker group Handala. The post Cal Water Says No OT Systems Breached in Iranian Handala Cyberattack appeared first on SecurityWeek .SECURITYWEEK.COM
25 Jun25-Year-Old Vulnerability Patched in CurlThe latest version of the open source data transfer tool resolves 18 medium and low-severity vulnerabilities. The post 25-Year-Old Vulnerability Patched in Curl appeared first on SecurityWeek .SECURITYWEEK.COM
25 JunLocal Police Collusion Hampers Crackdown on Asian Scam CentersWith tens of billions of dollars flowing into regional economies from cybercrime, scam centers continue to flourish, despite international and law-enforcement efforts.DARKREADING.COM
25 JunExperts on Experts: Why AI and Compliance Are Forcing A New Security Operating ModelThis week on Experts on Experts, I sat down with Sabeen Malik , Rapid7’s VP of Global Government Affairs and Public Policy, to discuss a shift security leaders can’t afford to treat as separate threads: frontier AI, vulnerability discovery, cybersecurity compliance, and operation…RAPID7.COM
25 JunNVIDIA GEN3C: Unauthenticated RCE via Pickle Deserialization in the Inference APIVulnCheck's Initial Access Intelligence team details an unauthenticated remote code execution in NVIDIA's GEN3C, where two FastAPI inference endpoints deserialize raw HTTP request bodies with pickle.loads() with no authentication.VULNCHECK.COM
📋 SECURITY BULLETINS 77[+]
23 SepMicrosoft: September Windows updates break Always On VPN connectionsMicrosoft warned that the September 2026 security updates may also break Always On VPN connections on some Windows 11 systems. [...]BLEEPINGCOMPUTER.COM
22 SepSN 1097: Mega Patch Tuesday Fallout - When AI Outsmarts Its MakersAfter Microsoft's historic Mega Patch Tuesday, enterprise IT teams worldwide are scrambling as a wave of updates triggers system meltdowns, broken domains, and silent Excel failures. Find out how AI-driven speed collided with real-world chaos. Andrew Ng weighs-in on AI Doomsaying…TWIT.TV
21 SepMicrosoft: September updates break File History backup featureMicrosoft warned that the built-in File History backup feature in Windows may stop working on some systems after installing the September 2026 security updates. [...]BLEEPINGCOMPUTER.COM
21 SepMicrosoft fixes broken Excel copy and paste for all Office usersMicrosoft has fixed a known issue that causes copy-and-paste failures for Excel users after installing the September 2026 security updates. [...]BLEEPINGCOMPUTER.COM
18 SepMicrosoft fixes broken copy and paste for Excel 2016 usersMicrosoft has fixed a known issue that causes copy-and-paste failures for some Excel users after installing the September 2026 KB5002914 security update. [...]BLEEPINGCOMPUTER.COM
18 SepAndroid apps can now check security patches down to individual device componentsNew AndroidX Security State libraries provide a more granular way to determine how securely patched an Android device is. The stable Security State v1.1.0 and Security State Provider v1.0.0 libraries allow developers to check the security status of individual device components an…HELPNETSECURITY.COM
17 SepMicrosoft shares workaround for Windows domain login issuesMicrosoft shared a temporary fix on Wednesday for a known issue that prevents Windows 11 users from logging in with valid domain credentials after installing the September 2026 security updates. [...]BLEEPINGCOMPUTER.COM
16 SepWindows 11 KB5124008 update breaks domain trust for some usersMicrosoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials. [...]BLEEPINGCOMPUTER.COM
15 SepMicrosoft confirms KB5002914 Excel update breaks copy and pasteMicrosoft has confirmed that copy and paste may silently fail for some Excel users after installing the September 2026 KB5002914 security update. [...]BLEEPINGCOMPUTER.COM
15 SepMicrosoft Issues Emergency Fixes After Massive Patch TuesdayYou can't make an omelet without breaking a few eggs, and you can't patch nearly 1,000 CVEs without a few glitches.DARKREADING.COM
14 SepMicrosoft: September updates break audio on some Windows PCsMicrosoft has confirmed that USB audio devices may fail on some Windows systems after installing the KB5124008and KB5124012 September 2026 security updates. [...]BLEEPINGCOMPUTER.COM
14 SepMicrosoft: September updates cause RDS failures on Windows ServerMicrosoft has confirmed reports that the September 2026 security updates cause Remote Desktop Services (RDS) failures on Windows Server systems. [...]BLEEPINGCOMPUTER.COM
14 SepMicrosoft’s PatchingOnce a month, Microsoft pushes a security update to all Windows users. Tomorrow’s is a new record : Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold. It w…SCHNEIER.COM
14 SepMicrosoft releases emergency Windows updates to fix RDS failuresMicrosoft has released emergency out-of-band Windows updates to fix Remote Desktop Services failures caused by this month's security updates, along with Hyper-V and USB audio problems on some Windows versions. [...]BLEEPINGCOMPUTER.COM
12 SepThreat actors move toward multi-agent AI frameworks as calls for regulation continue.Microsoft sets another Patch Tuesday record. FBI releases its first public cyber strategy.THECYBERWIRE.COM
11 SepMicrosoft fixes Teams, Outlook launch failures on ARM Windows PCsMicrosoft has fixed a bug that prevented Teams and Outlook from launching on ARM-based Windows devices after installing updates released since the August 2026 Patch Tuesday. [...]BLEEPINGCOMPUTER.COM
11 SepUbuntu 24.04.5 LTS release patches security bugs across ten flavorsCanonical shipped Ubuntu 24.04.5 LTS, bundling security updates and fixes for high-severity bugs into new installation media for the “Noble Numbat” release. Anyone installing fresh now gets those corrections baked in from the start, cutting the batch of updates that w…HELPNETSECURITY.COM
10 SepMicrosoft fixes bug that wiped Windows desktop settingsMicrosoft says the September 2026 Patch Tuesday updates fix a known issue causing desktop settings to be lost or reset on some Windows devices. [...]BLEEPINGCOMPUTER.COM
10 SepSeptember Windows Server updates break Remote Desktop ServicesWindows admins report that the September 2026 security updates are causing Remote Desktop Services (RDS) failures on Windows Server 2019, 2022, and 2025 servers, preventing users from connecting and, in some cases, requiring a hard reset to restore functionality. [...]BLEEPINGCOMPUTER.COM
10 SepMicrosoft Excel KB5002914 update breaks copy and paste for some usersMicrosoft Excel users report that this week's KB5002914 Office security update is breaking copy-and-paste operations and formula dragging, with affected users saying that removing or rolling back the update restores normal functionality. [...]BLEEPINGCOMPUTER.COM
9 SepICS Patch Tuesday: Schneider Electric, Siemens Fix Critical FlawsAVEVA and Rockwell Automation also released patches for vulnerabilities affecting industrial control system products. The post ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws appeared first on SecurityWeek .SECURITYWEEK.COM
9 SepPatch Tuesday notes: Microsoft sets another record.New ClickFix technique targets browsers. Business news: NetSPI and Synack to merge.THECYBERWIRE.COM
9 SepAndroid’s September 2026 Updates Patch 180 VulnerabilitiesThe security updates resolve critical flaws across Android’s Framework, System, and Kernel components. The post Android’s September 2026 Updates Patch 180 Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
9 SepChipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security AdvisoriesMajor chipmakers announced patches for vulnerabilities recently discovered in their products. The post Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories appeared first on SecurityWeek .SECURITYWEEK.COM
9 SepClear your calendar, it’s Patch Tuesday.Patch Tuesday is a doozy. The Feds warn China-based AI companies are distilling U.S. AI models. A new ClickFix campaign goes straight for the browser. Smart TVs get nosy. Hackers gift themselves a $47 million bug bounty. An Ohio man gets 15 years in federal prison for cyberstalki…THECYBERWIRE.COM
8 SepAugust updates trigger 0xc0000409 errors on Windows Server 2016Microsoft says the August 2026 security update may trigger 0xc0000409 errors on Windows Server 2016 systems where the Compatibility Appraiser diagnostic service is enabled. [...]BLEEPINGCOMPUTER.COM
8 SepMicrosoft releases Windows 10 KB5122878 extended security updateMicrosoft has released the Windows 10 KB5122878 extended security update, which includes this month's record-breaking September 2026 Patch Tuesday fixes, along with a few bug fixes. [...]BLEEPINGCOMPUTER.COM
8 SepMicrosoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiesMicrosoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."TALOSINTELLIGENCE.COM
8 SepSN 1095: AI-Driven Expertise Loss - Gemini, Hugging Face, and the AI Arms RaceOpenAI's latest advances have the rumor mill buzzing about "hidden thoughts" and unsupervisable models, but are AI safety experts panicking over the wrong threat? Get the clear-headed take behind the headlines. We start out with a classic old school hack against Dropbox. Next Pat…TWIT.TV
4 SepSynology ActiveProtect Manager 2.0 improves AI-driven securitySynology launched ActiveProtect Manager 2.0 (APM 2.0), the latest software update for its ActiveProtect data protection appliances. This release introduces expanded platform coverage, cross-platform recovery, and enhanced security, with future updates bringing AI-driven threat mi…HELPNETSECURITY.COM
3 SepMicrosoft Teams, Outlook fail to launch on ARM-based Windows PCsMicrosoft is working to fix a known issue that causes crashes and launch failures for Microsoft Teams and New Outlook users after installing updates released since the August 2026 Patch Tuesday. [...]BLEEPINGCOMPUTER.COM
2 SepMalicious Virtualizor Update Served via BGP HijackingUsing a technically valid TLS certificate for Softaculous’ domains, a threat actor diverted traffic to fake software updates. The post Malicious Virtualizor Update Served via BGP Hijacking appeared first on SecurityWeek .SECURITYWEEK.COM
31 AugTrusted Chrome, Edge extensions weaponized in supply chain campaignAttackers have turned previously legitimate browser extensions into malware after acquiring them from legitimate publishers, potentially allowing malicious updates to reach users who had installed the software when it was still safe, researchers at Socket have found. The campaign…CSOONLINE.COM
25 AugWhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security UpdateWhen Android users get a call from a non-contact, they will see more information about the caller, including their country. The post WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update appeared first on SecurityWeek .SECURITYWEEK.COM
25 AugMicrosoft PowerToys adds Alt+Tab-style switching for an app's windowsMicrosoft updated its Windows PowerToys toolset with a new utility dubbed "Window Hopper" that lets users switch between an app's windows more quickly. [...]BLEEPINGCOMPUTER.COM
24 AugMicrosoft shares temporary fix for Windows 11 gaming issuesMicrosoft has shared a temporary fix for ongoing gaming issues caused by Windows 11 updates released during the August 2026 Patch Tuesday. [...]BLEEPINGCOMPUTER.COM
24 AugAndroid car head units infected with proxy botnet malware through built-in software updatersA newly discovered Android malware, distributed through the built-in updaters in affected Android-based car head units, turns infected devices into ad-fraud tools and nodes in a proxy botnet, Kaspersky has found. According to the researchers, it’s the first documented case of mal…HELPNETSECURITY.COM
24 AugMicrosoft: August updates break printing, PDF export in WPF appsMicrosoft has confirmed that .NET Framework updates released as part of the August 2026 Patch Tuesday are breaking printing and PDF export in WPF applications. [...]BLEEPINGCOMPUTER.COM
21 AugBadBox-linked Android malware has now infected car head unitsAndroid malware is spreading through the built-in firmware update mechanism of automotive head units, turning the devices into nodes for ad fraud and a residential proxy botnet. Kaspersky reports this is the first documented malware campaign with an infection chain specifically d…CYBERINSIDER.COM
21 AugCisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review. Four of the security vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswor…THEHACKERNEWS.COM
19 AugMicrosoft fixes known issue causing Windows Defender crashesMicrosoft has resolved a bug that caused Windows Defender to crash after a recent security update, resulting in 0xc0000005 access violation errors on some affected systems. [...]BLEEPINGCOMPUTER.COM
12 AugICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix ContactCISA has also published several advisories describing vulnerabilities in ICS and other OT products. The post ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugMicrosoft Fixes 400 Flaws on August Patch TuesdayMicrosoft has issued another massive batch of security updates with 400 fixed in the August Patch TuesdayINFOSECURITY-MAGAZINE.COM
11 AugMicrosoft releases Windows 10 KB5120249 extended security updateMicrosoft has released Windows 10 KB5120249 Extended Security Updates for versions 22H2 and 21H2 to fix security vulnerabilities and bugs. [...]BLEEPINGCOMPUTER.COM
11 AugMicrosoft's Patch Tuesday Deluge Continues With August UpdatesSecurity experts say prioritization should be the main focus for the August updates, not the massive CVE volume.DARKREADING.COM
11 AugMicrosoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesMicrosoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as "critical."TALOSINTELLIGENCE.COM
9 AugWeek in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Mapping the malware blast radius a single alert won’t show you In this interview with Help Net Security, Mike Wiacek, founder and CTO of Stairwell, explains Backstory, an AI agent th…HELPNETSECURITY.COM
7 AugMicrosoft, Apple Release Fresh Security UpdatesMicrosoft fixed critical vulnerabilities across Azure, Entra, and SharePoint, while Apple patched a high-severity authentication bypass. The post Microsoft, Apple Release Fresh Security Updates appeared first on SecurityWeek .SECURITYWEEK.COM
4 AugWhy Secure Updates Get DelayedSecurity vulnerabilities are often resolved in newer software releases, yet many enterprises continue running older versions long after fixes become available. In this discussion, the question isn't whether an update exists—it's why organizations delay adopting it. Upgrading soft…YOUTUBE.COM
30 JulFCC Restricts New Foreign Robots and Inverters Over Security RisksThe FCC added foreign robots and power inverters to its Covered List, while allowing security updates for existing authorized devices until 2029. The FCC just widened its Covered List again, this time adding foreign-produced advanced robotic devices and power inverters. In plain …SECURITYAFFAIRS.COM
30 JulAI takes on a bigger role in finding Chrome vulnerabilitiesGoogle has expanded the use of AI in Chrome’s security workflow, using it to find vulnerabilities, triage bug reports, generate patches, and review code to shorten the time between discovering software flaws and delivering security updates. “Historically, triaging a single …HELPNETSECURITY.COM
30 JulVMware fixes three critical flaws allowing auth bypass, VM escapesBroadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. [...]BLEEPINGCOMPUTER.COM
30 JulDPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing MalwareThreat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Con…THEHACKERNEWS.COM
28 JulJuly Apple updates are especially important if you receive imagesApple issued a large July security update with several image processing related vulnerabilities that could compromise your device.MALWAREBYTES.COM
24 JulBluetooth flaw exposes 2.2 million cars to unlocking attacksMore than 2.2 million vehicles equipped with dealer-installed aftermarket anti-theft systems are vulnerable to a Bluetooth attack that could allow thieves to remotely unlock doors and disable engine starts. The manufacturer behind the affected devices has released a firmware upda…CYBERINSIDER.COM
22 JulOracle Patches Over 1,400 Vulnerabilities With Quarterly Security UpdatesMany of the vulnerabilities fixed with the July 2026 Critical Patch Update were likely discovered by AI. The post Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulMicrosoft to stop Exchange 2016 / 2019 security updates in OctoberMicrosoft has reminded customers that it will stop shipping security updates for Exchange 2016 and 2019 through the Extended Security Update (ESU) program in October. [...]BLEEPINGCOMPUTER.COM
22 JulEclypsium Launches InfraTrust to Centralize Enterprise Hardware Security RisksNew global infrastructure security intelligence database debuts alongside monthly advisory delivering actionable risk data to protect critical enterprise hardware infrastructure. Portland, OR – July 22, 2026 – Eclypsium, the infrastructure assurance company, today announced the l…ECLYPSIUM.COM
20 JulWindows KB5121767 OOB update fixes shutdowns on some Dell PCsMicrosoft has released emergency updates to fix a known issue causing some Dell PCs to shut down after installing the July 2026 Windows 11 security updates. [...]BLEEPINGCOMPUTER.COM
17 JulWindows Server 2022 reach end of mainstream support in 90 daysMicrosoft announced that Windows Server 2022 will reach the mainstream end date in October 2026, but will switch to extended support and continue receiving security updates for five more years. [...]BLEEPINGCOMPUTER.COM
16 JulSecurity updates available for Adobe, Chrome, Firefox, VMWare, and ZoomSeveral updates have been made available including those for Adobe, Chrome, Firefox, VMWare, and Zoom.MALWAREBYTES.COM
15 JulMicrosoft: Some Dell PCs shut down after recent Windows updatesMicrosoft is blocking this month's Windows 11 security updates on some Dell devices because they are causing shutdowns and performance issues. [...]BLEEPINGCOMPUTER.COM
15 JulFreeRDP 3.29.0 security update resolves 22 advisoriesFreeRDP is a free implementation of the Remote Desktop Protocol, released under the Apache license, and it runs on a large share of workstations and servers through the many tools built on it. The 3.29.0 version is a security, bugfix, and maintenance update that resolves 22 advis…HELPNETSECURITY.COM
15 JulICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, RockwellThe industrial giants fixed dozens of vulnerabilities across their ICS products, with advisories also released by CISA and VDE CERT. The post ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell appeared first on SecurityWeek .SECURITYWEEK.COM
15 JulMicrosoft patches record number of security vulnerabilities, citing its use of AIMicrosoft's monthly release of security fixes, dubbed Patch Tuesday, resolved a record 570 security vulnerabilities across the company's product line, thanks to discoveries with AI.TECHCRUNCH.COM
14 JulMicrosoft releases Windows 10 KB5099539 extended security updateMicrosoft has released the Windows 10 KB5099539 extended security update, which includes the July 2026 Patch Tuesday security updates for 570 vulnerabilities, along with additional security fixes. [...]BLEEPINGCOMPUTER.COM
13 JulMicrosoft demystifies how Windows updates workMicrosoft has published a guide explaining the Windows servicing model, outlining the purpose of monthly security updates, optional preview releases, hotpatch updates, and the mechanisms used to deliver new features throughout the year. “Most individuals and organizations regular…HELPNETSECURITY.COM
13 JulMicrosoft Entra ID security updates: Passkeys are the default authentication method in Entra IDMicrosoft Entra ID makes passkeys the default sign-in experience and introduces a new model for SMS and voice authentication. Read about how to prepare. The post Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID appeared first on Micr…MICROSOFT.COM
12 JulDebian 13.6 security update patches over a hundred advisories in trixieMost PCs still run with a UEFI Secure Boot certificate authority, installed by default since 2013, that has now expired. That certificate signed the bootloaders letting machines start with Secure Boot turned on. Its expiry sits at the center of the sixth update to Debian 13, code…HELPNETSECURITY.COM
10 JulJuly 2026 Patch Tuesday forecast: Is CVE tracking still practical?I was off by a month in my forecast of record-setting CVE releases from Microsoft. In June, we saw the deluge of over 200 reported CVEs that I expected in May. There were 116 CVEs for Windows 11 and 104 for Windows 10. In addition, we saw large numbers in both common applications…HELPNETSECURITY.COM
10 JulMicrosoft Warns of Increase in Number of Security UpdatesMicrosoft has said the volume of Windows security updates is set to grow as it uses AI to find new bugsINFOSECURITY-MAGAZINE.COM
9 JulMicrosoft expects more Windows security updates from AI-discovered flawsMicrosoft says Windows users should expect to see an increase in security updates as the company increasingly relies on artificial intelligence to discover vulnerabilities in its codebase. [...]BLEEPINGCOMPUTER.COM
4 JulFBI: TeamPCP Compromised Dev Tools to Steal Cloud CredentialsFBI says TeamPCP poisoned trusted developer tools to steal cloud credentials, spread malware through software updates, and extort victims. On July 2, 2026, the FBI published a FLASH alert identifying the criminal group called TeamPCP and detailing how it compromised widely used d…SECURITYAFFAIRS.COM
2 JulIt’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza)We’re back, melting - we’ve tried shouting, screaming, and throwing things at the Sun, and it is just not working. Before we begin our analysis, we want to be clear - given the number of vulnerabilities fixed (and some not mentioned..), we’ve struggled to hav…LABS.WATCHTOWR.COM
30 JunApple Fixes WebKit Flaws in iOS and macOS, With Help From AI ToolsApple released updates for iOS, iPadOS, macOS, and Safari, fixing WebKit flaws, four of which were found using AI tools like Claude and Codex Apple pushed out security updates for iOS, iPadOS, macOS, and Safari on Monday, and this round comes with a twist worth noticing. Four of …SECURITYAFFAIRS.COM
26 JunMicrosoft gives Windows 10 users an unexpected extra year of free security updatesMicrosoft has given Windows 10 users another year of free security updates, extending its consumer Extended Security Updates (ESU) program until October 12, 2027. “Windows 10 support has ended. You can enroll in ESU any time until the program ends on October 12, 2027. If you’re a…HELPNETSECURITY.COM
25 JunMicrosoft quietly extends free Windows 10 ESU support to October 2027Microsoft has quietly extended its free Windows 10 Extended Security Updates (ESU) program for consumers by an additional year, allowing enrolled devices to continue receiving security updates until October 12, 2027. [...]BLEEPINGCOMPUTER.COM
📢 SECURITY ADVISORIES 657[+]
23 SepBurnham announces plan for new UK center to fight disinformationThe United Kingdom will create a new national center "to detect, attribute and disrupt” hostile state disinformation, Prime Minister Andy Burnham announced at the United Nations General Assembly.THERECORD.MEDIA
23 Sep80,000 relay servers help users in China slip past U.S. AI region bansMore than 80,000 relay servers are helping users in China bypass geographic restrictions on leading U.S. AI models, according to Team Cymru. “What we have uncovered is an entire ecosystem designed explicitly to break the frontier model providers’ T&Cs, enabling fraud and ill…HELPNETSECURITY.COM
23 SepGitHub App keys can still enable takeovers long after they are forgottenGitHub allows organizations to install GitHub Apps that automate and extend certain functionality on the platform and have access to selected repositories and permissions. But the private keys these applications use to authenticate themselves can remain valid for years unless man…CSOONLINE.COM
23 SepWatchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attackThe DHS inspector general said CISA lacks the power to compel agencies to implement its Binding Operational Directives. The post Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack appeared first on CyberScoop .CYBERSCOOP.COM
22 SepPasswork NIS2 efficiency guide: Save your team hours before the 2026 auditBy the second half of 2026, national competent authorities across the EU are actively reviewing NIS2 compliance documentation. Under Article 20(1) of the directive, senior management at essential and important entities can be held personally liable for infringements — a detail th…HELPNETSECURITY.COM
22 SepContagious Interview: 30,000 devices infected by a fake job interviewNorth Korea-linked WaterPlum runs the Contagious Interview campaign, infecting over 30,000 devices using a fake job interview. On September 18, Japan’s National Police Agency, the FBI, the US Department of Defense’s Cyber Crime Center, and intelligence agencies from A…SECURITYAFFAIRS.COM
22 SepPAYLOAD ransomware hijacks Windows Group Policy in encryption-less attacksA PAYLOAD ransomware incident weaponized Microsoft Active Directory Group Policy to disrupt an organization’s Windows computers without deploying ransomware or encrypting files. Instead, the attackers used the company’s own administration infrastructure to display ransom notes, c…CYBERINSIDER.COM
22 SepAI Agents Are Rewriting the Rules of Lateral MovementSecurity teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths an autonomous system can discover, given the access it already has? A person may try several ways to complete a task. A determinis…THEHACKERNEWS.COM
22 SepAI is set to help cyber attackers much more than defenders, says UK officialDave Chismon, the NCSC’s chief technology officer for architecture, said in a blog post that the imbalance in AI means cyberattacks would likely grow as automated defenses struggle to keep pace.THERECORD.MEDIA
22 SepCiting China, President Trump doubles down on hands-off approach to AI regulationFollowing a series of chaotic agentic hacks, Trump and administration officials have consistently expressed fears of Chinese AI dominance in pushing for fewer regulations. The post Citing China, President Trump doubles down on hands-off approach to AI regulation appeared first on…CYBERSCOOP.COM
22 SepWWIII, Debt, JFK, CISA, SUSE, OpenAI, Google, DORA, Aaran Leyland, and More - SWN #618WWIII,Security Debt, JFK, CISA, SUSE, OpenAI, Google, DORA, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-618YOUTUBE.COM
22 SepAfter water attacks, Capitol Hill offers its own proposal for an AI-cyber test programA key House Democrat and his bipartisan sponsors want to see a $100 million DHS pilot to help critical infrastructure owners and operators — separate from another administration-proposed pilot program. The post After water attacks, Capitol Hill offers its own proposal for an AI-c…CYBERSCOOP.COM
21 SepGoogle hit with €403 million GDPR fine over location trackingIreland’s Data Protection Commission (DPC) has fined Google €403 million (about $463 million) over its processing of users’ location data and ordered the company to bring that processing into compliance within six months. The inquiry examined Google’s practices from May 25, 2018,…HELPNETSECURITY.COM
21 SepIreland fines Google €403 million over location data processingIreland’s Data Protection Commission (DPC) has fined Google €403 million after finding that the company violated multiple GDPR requirements while processing users’ location data. The regulator also ordered Google to bring the affected processing practices into compliance within s…CYBERINSIDER.COM
21 SepContagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in CryptoThe North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets, according to a new joint cybersecurity advisory. T…THEHACKERNEWS.COM
18 SepMost WordPress pros still lack a breach recovery planMelapress, a maker of WordPress security plugins, surveyed 319 WordPress professionals and found that most had dealt with at least one known security incident. The respondents build and run WordPress sites for a living: agency staff, developers, designers, site owners and adminis…HELPNETSECURITY.COM
18 SepMicrosoft Teams will let admins block custom file extensionsMicrosoft Teams will soon let administrators tweak the list of file extensions commonly associated with security threats to meet their company's security requirements. [...]BLEEPINGCOMPUTER.COM
18 SepTransparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan. The attacks, per Zscaler ThreatLabz, involve the use of previousl…THEHACKERNEWS.COM
17 SepThe battle for AI regulation.This week, Dave and Ben sit down with N2K's lead analyst Ethan Cook to look at the growing calls to enact AI regulations both within the US and across the globe. Spurned on by recent model escapes, policymakers and AI developers alike have steadily begun to call for greater legis…THECYBERWIRE.COM
17 SepCISA Releases Guidance on Deploying Cyber DecoysComplementing Zero Trust models, decoys enable organizations to detect, observe, and block malicious activity in their environments. The post CISA Releases Guidance on Deploying Cyber Decoys appeared first on SecurityWeek .SECURITYWEEK.COM
17 SepChosen Brick, Iran’s Surveillance MalwareUK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran̵…SECURITYAFFAIRS.COM
17 SepComp AI Raises $34 Million for AI-Native Compliance and SecurityThe company plans to expand into continuous cybersecurity, offering security testing across applications and infrastructure. The post Comp AI Raises $34 Million for AI-Native Compliance and Security appeared first on SecurityWeek .SECURITYWEEK.COM
17 SepSelf-modifying AI agents expose a blind spot in enterprise securityAs debate over AI safety intensifies, new research is drawing attention to a more immediate risk for enterprises: AI agents that can alter the models they rely on while carrying out routine tasks. Researchers at AI security firm Irregular asked a coding agent to solve a software …CSOONLINE.COM
17 SepCISA Urges Critical Infrastructure to Plant Decoys Inside NetworksCISA released guidance on using cyber decoys to detect & disrupt malicious activity inside networksINFOSECURITY-MAGAZINE.COM
17 SepSecurity spending is growing — except for the typical CISOSecurity budgets may be growing on paper, but for a majority of CISOs, the money isn’t moving in quite the same direction. The budgets grew by 5% on average in 2026, up from 4% last year. But that average hides a much weaker picture: median budget growth remained at 0%. And while…CSOONLINE.COM
17 SepOpenAI backs calls for binding UK AI regulation.EU looks to ban social media for minors.THECYBERWIRE.COM
17 SepAI is calling the shots.AI goes to war. Iranian strikes leave AWS data unrecoverable. OpenAI discloses more model misbehavior. Researchers uncover 16 Wireshark vulnerabilities. TrustSink turns Entra authentication into a password trap. RatHat raids Android credentials. The FBI takes down a DDoS-for-hire…THECYBERWIRE.COM
16 SepCISA looks to recruit general infrastructure security experts rather than sector-focused advisers“I need people that can pivot from day to day,” the agency’s acting chief told reporters.CYBERSECURITYDIVE.COM
16 SepCISA and NIST Issue Guidance to Protect Cloud Identity TokensCISA and NIST issued final guidance to help protect cloud identity tokens and assertionsINFOSECURITY-MAGAZINE.COM
16 SepNCSC and Allies Warn of Iranian Spyware CampaignThe UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidentsINFOSECURITY-MAGAZINE.COM
16 SepCISA promotes a fresh way to deter cyberattackers: Lie to themIt’s the first guidance from the Cybersecurity and Infrastructure Security Agency on deploying decoys, like honeypots, to detect and distract adversaries. The post CISA promotes a fresh way to deter cyberattackers: Lie to them appeared first on CyberScoop .CYBERSCOOP.COM
15 SepSupreme Court denies Trump request to allow USPS mail ballot changesOne justice said the attempt to change the rules ahead of the 2026 elections would be "arbitrary and capricious” and violated the Administrative Procedures Act. The post Supreme Court denies Trump request to allow USPS mail ballot changes appeared first on CyberScoop .CYBERSCOOP.COM
15 SepMicrosoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety ConstraintsThe Humanist AI Code of Conduct draws a line between defensive cyber research and operational attack capability. The post Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints appeared first on SecurityWeek .SECURITYWEEK.COM
15 SepMicrosoft sets security and safety rules for its AI modelsMicrosoft AI has published the first draft of its Humanist AI Code of Conduct, a training manual outlining how it develops AI models and intends them to behave during deployment. The draft is open for public consultation for six weeks. The company plans to review the feedback, re…HELPNETSECURITY.COM
15 SepWhat’s next for CISA’s CDM program that gives cybersecurity tools to federal agenciesThree feds spoke about future plans for the Continuous Diagnostics and Mitigation program, and lessons they’ve learned. The post What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies appeared first on CyberScoop .CYBERSCOOP.COM
14 SepEntrust turns cryptographic inventory data into security actionEntrust has unveiled new capabilities for its Cryptographic Security Platform (CSP) that help organizations turn Cryptographic Bill of Materials (CBOMs) data into action. Government agencies, financial institutions, healthcare organizations, and other critical infrastructure oper…HELPNETSECURITY.COM
14 SepBeijing Hits Back at Anthropic CEO’s Call to Curb China’s AI DevelopmentChina’s Ministry of Foreign Affairs responded to a question about Amodei’s essay by saying that all parties should work together on AI. The post Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development appeared first on SecurityWeek .SECURITYWEEK.COM
14 SepAWS Security Reference Architecture: A deep dive into PCI DSS complianceAmazon Web Services (AWS) is excited to announce the publication of the AWS Security Reference Architecture (AWS SRA) Payment Card Industry (PCI) Data Security Standard (DSS) Deep Dive. This new guide extends the core AWS SRA to provide prescriptive, architecture-level guidance f…AWS.AMAZON.COM
13 SepSpace's cybersecurity policy problem.As space becomes increasingly connected and autonomous, effective cybersecurity policy is struggling to keep pace. Host Maria Varmazis and Dr. Mac McGuire sit down to discuss the limitations of current approaches for managing space cyber risks and what the industry is lackin…THECYBERWIRE.COM
11 SepAttackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant BackdoorsAttackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report. Wiz saw the attacks between August 15 and Sep…THEHACKERNEWS.COM
11 SepCloudflare brings post-quantum DNSSEC support to 1.1.1.1 resolverCloudflare has added support for validating post-quantum DNSSEC signatures on its 1.1.1.1 public DNS resolver, marking an early step toward protecting the domain name system from future quantum-computing attacks. The company is now validating signatures created with ML-DSA-44, a …CYBERINSIDER.COM
11 SepWeWorm has China's attention, as calls for AI slowdown and regulation continue.Russia's Cozy Bear used Claude to automate operations. McKesson data breach affected 6.4 million people.THECYBERWIRE.COM
11 SepCISA Calls for More Guidance, Less Spin, as Cyber Outages EscalateA new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and incident response protocols.DARKREADING.COM
11 Sep KEVYou might want to watch what you say.WeWorm has China’s attention. Calls for an AI slowdown continue. OpenAI calls for mandatory AI regulation. Anthropic disrupts Russian cyberespionage. The EU’s 24 hour reporting requirement goes into effect. GitLab and Check Point patch critical vulnerabilities. IDScan confirms th…THECYBERWIRE.COM
11 SepCyberattack causes a flight delay? Airlines won’t owe you a hotel or mealA Department of Transportation rule published last week says that airlines complying with cybersecurity regulations will have reduced customer obligations in the event of an attack. The post Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal appeared first …CYBERSCOOP.COM
10 SepFake GTA 6 download delivers malware-packed bundle to impatient gamersGrand Theft Auto VI (GTA 6) is still three months from release, but cybercriminals are not waiting for the launch date. Security firm Huntress found malware disguised as a leaked copy of the game, aimed at fans hoping to get their hands on it early. The sample Huntress pulled apa…HELPNETSECURITY.COM
10 Sep1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it1.1.1.1 now validates DNSSEC signatures using NIST’s post-quantum ML-DSA-44 algorithm. Here is how we manage 2,420-byte signatures and downgrade risks at scale.CLOUDFLARE.COM
10 SepCISA Updates Insider Threat Guide With New Mitigation AdviceCISA has updated its insider threat guide with new advice on remote work, AI and risk detectionINFOSECURITY-MAGAZINE.COM
10 SepCISA is on the verge of filling hundreds of critical vacanciesMeanwhile, the agency is finalizing an incident-reporting regulation and setting up a new industry coordination structure.CYBERSECURITYDIVE.COM
9 SepChinese AI firms use industrial-scale distillation to copy US modelsCISA, the NSA, and the FBI warn that several China-based artificial intelligence companies have run industrial-scale campaigns to extract proprietary capabilities from leading US AI models. The agencies say the activity, underway since at least late 2024, involved billions of tok…CYBERINSIDER.COM
9 SepNew cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as RootcPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPan…THEHACKERNEWS.COM
9 SepChinese AI firms are siphoning capabilities from American models, CISA warnsChina-based AI companies are using large-scale knowledge distillation campaigns to copy capabilities from leading U.S. AI models, according to a joint cybersecurity advisory from the CISA, NSA, and FBI. Knowledge distillation is a standard AI training technique that uses outputs …HELPNETSECURITY.COM
9 SepUS Agencies Warn Chinese AI Firms Are Extracting Advanced AI ModelsUS agencies accuse six Chinese AI firms of extracting billions of tokens from US AI models to accelerate development and copy advanced capabilities. NSA, CISA, and the FBI jointly published an advisory accusing six Chinese AI companies, DeepSeek, Moonshot AI, Alibaba, MiniMax, St…SECURITYAFFAIRS.COM
9 SepSkullcandy Dime 3 earbuds expose users to Bluetooth hijackingThe Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction. [...]BLEEPINGCOMPUTER.COM
9 SepCISA head says agency must change quickly to prevent the 'worst that could happen'CISA's cybersecurity, infrastructure security and emergency communications divisions are among the priorities as the agency fills vacancies created at the beginning of the Trump administration, acting director Nick Andersen says.THERECORD.MEDIA
8 SepCybersecurity jobs available right now: September 8, 2026CISO AudioCodes | Israel | Hybrid – View job details As a CISO, you will lead security strategy, governance, and risk management across SaaS, managed services, and customer-hosted environments. You will oversee security controls, incident response, Secure SDLC, cu…HELPNETSECURITY.COM
8 SepJellyfin 12.0 security fixes arrive alongside the removal of legacy client loginsJellyfin shipped version 12.0 of its media server. Several of the security fixes in it block requests built to reach files outside the folders the server is supposed to hand out. The rest of the security work touches first-run setup, plugin installs, parental controls, and the we…HELPNETSECURITY.COM
8 SepIT Help Desk Impersonation Lets Hackers Bypass MFAAttackers bypass endpoint security by posing as IT staff, stealing Microsoft 365 sessions, draining SaaS data and demanding extortion. Forget installing malware because today’s extortionists just pick up the phone instead of writing code. A widespread threat cluster tracked as PR…SECURITYAFFAIRS.COM
8 SepFreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator CredentialsA flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities i…THEHACKERNEWS.COM
8 SepFrance Establishes New Government-Focused Cyber Incident Response UnitAfter a major cyber-attack targeted France's national tax authority, the Prime Minister called for the establishment of a new dedicated cyber incident response capabilityINFOSECURITY-MAGAZINE.COM
8 SepFeds accuse China of ‘systematic’ distillation of U.S. AI modelsA joint advisory alleges Chinese companies are using sophisticated systems to route millions of data requests to US AI models across different accounts and platforms. The post Feds accuse China of ‘systematic’ distillation of U.S. AI models appeared first on CyberScoop .CYBERSCOOP.COM
7 SepBerlin Ransomware Leak Exposes State SecretsBerlin refused a 30 Bitcoin ransom, leading hackers to leak 6TB of sensitive state administration and national defense data on the dark web. When a ransomware gang dumps nearly six terabytes of state administration files onto the dark web, ignoring them does not make the problem …SECURITYAFFAIRS.COM
7 SepAttackers spread malware through ScreenConnect file transfersA file transfer flaw in ScreenConnect Remote Access Support and Access sessions affects both Cloud and On-Premise deployments, ConnectWise confirmed. “A CVE identifier and an official fix will be issued within the week,” the company wrote in its September 3 advisory. …HELPNETSECURITY.COM
7 SepNCSC Warns Shadow AI Creates New Security RisksNCSC warns unapproved AI tools can expose corporate data and create new security risksINFOSECURITY-MAGAZINE.COM
4 SepG7 urges organizations to prepare for quantum cyber threatsIn a joint advisory released Thursday, the G7 Cyber Security Working Group and the U.S. Cybersecurity and Infrastructure Security Agency, CISA, said organizations should begin moving to post-quantum cryptography now.THERECORD.MEDIA
4 SepRisky Bulletin: Russia tells data centers to deploy drone defensesRussia tells data centers to deploy drone defenses, Dropbox discloses a security breach, a new spyware wave hits Serbia, and CISA scraps six free cybersecurity assessment programs.RISKY.BIZ
4 SepChinese Hackers Use AI Agents in Multi-Country Cyber CampaignHunt.io uncovered a Chinese-speaking campaign using AI agents to automate cyberattacks against Asian government, education and industrial targets. Threat intelligence firm Hunt.io just documented a second, separate China-linked campaign wiring commercial AI models directly into l…SECURITYAFFAIRS.COM
2 SepRisky Business #851 -- Agents are just ones and zeros, and tigers are just atomsOn this week’s show Patrick Gray and James Wilson are joined by guest co-host The Grugq to talk through the week’s news, including: Two alleged TeamPCP hackers got arrested in Australia The White House has a plan to boost security for water facilities, but we can’t see it working…RISKY.BIZ
2 SepLenovo ID flaw let attackers access Dropbox accounts without passwordsDropbox users are reporting unauthorized account access caused by a flaw in Lenovo’s email verification process that allowed attackers to create Lenovo IDs using victims’ email addresses and use them to sign in to associated Dropbox accounts. The number of affected users remains …CYBERINSIDER.COM
2 SepUK Moves to Block High-Risk Tech Suppliers From Critical InfrastructureLate amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify. The post UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure appeared first on SecurityWeek .SECURITYWEEK.COM
1 SepMicrosoft nudges enterprise security closer to its passwordless future. But ‘123456’ will survive.Today marks the beginning of the end of an era for enterprise Microsoft authentication. As of Sept. 1, passkeys are now the default authentication method for Entra ID , Microsoft’s cloud-based identity and access management (IAM) service. By Feb. 1, 2027, Microsoft-provided SMS a…CSOONLINE.COM
1 SepBerlin refuses to be blackmailed after network breachBerlin’s state government has confirmed an extortion attempt following a data theft from its administrative network in August. Governing Mayor Kai Wegner and Interior Senator Iris Spranger addressed the extortion attempt on Friday, following an emergency Senate session at t…HELPNETSECURITY.COM
1 SepIranian cyber spies target aviation, fintech developers with new malwareIn a report published Tuesday, Kaspersky said it first discovered NodeRabbit on a system in Afghanistan and later identified variants on systems in Egypt and Ethiopia.THERECORD.MEDIA
1 SepHackers abuse Faronics Deploy admin tool to install ScreenConnectPhishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software. [...]BLEEPINGCOMPUTER.COM
31 AugSecuring Claude Code: The New Compliance API, Local Visibility, and Identity GovernanceClaude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developer’s machine. Anthropic’s new Compliance API endpoints give security teams their clearest view yet into that activity. They also expose a larger problem: activi…THEHACKERNEWS.COM
31 AugDoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not VictimsThe U.S. Department of Justice (DoJ) on Friday corrected a previously issued press statement that several of its agencies were victims of attacks carried out by Chinese threat actors, instead now pointing out that they were among those targeted. Last week, the DoJ said the Nation…THEHACKERNEWS.COM
31 AugFile servers are here to stay. Here’s how to manage them securelyFile servers remain a critical part of many IT environments, but managing access securely can become complex as permissions accumulate. tenfold Software outlines five best practices for simplifying file server administration and maintaining least-privilege access. [...]BLEEPINGCOMPUTER.COM
31 AugBerlin confirms data theft after Rhysida ransomware attack claimsBerlin's city administration has confirmed that cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on their data leak site. [...]BLEEPINGCOMPUTER.COM
31 AugLet’s kill the kill switch.Could an AI kill switch create more problems than it solves? A critical Rails flaw is under active attack. Malicious browser extensions steal cryptocurrency. Fire Ant targets trusted network infrastructure. Claude Code gets tricked into running attacker-controlled code. MyChart p…THECYBERWIRE.COM
29 AugRhysida Ransomware Group Targets Berlin Government Ahead of VoteBerlin ‘s government faces a Rhysida ransomware attack weeks before elections, with officials refusing to pay despite a claimed 5.79 TB data theft. Berlin’s state government confirmed this week it’s dealing with an extortion attempt following an August cyberatta…SECURITYAFFAIRS.COM
28 AugRisky Bulletin: Two TeamPCP members arrested in AustraliaTwo members of TeamPCP arrested in Australia, Qilin hits the US firearms agency, America seizes two more Chinese botnets, CISA says most cyber activity is opportunistic.RISKY.BIZ
28 AugResearchers publish analysis of OpenAI agents' attack against Hugging Face.Federal judge rules the Trump administration's blacklisting of Anthropic was illegal. The White House bans certain foreign-made power equipment over backdoor risks.THECYBERWIRE.COM
28 AugCISA identifies security hurdles that led to very different results in two red-team engagementsThe agency said its recent simulated cyberattacks offered several key lessons for many organizations.CYBERSECURITYDIVE.COM
28 AugDefining an AI Kill Switch Is Hard, but NecessaryProposed legislation could mandate that companies be able to "throttle, suspend, or shut ... down" AI agents, but how and when to do that remain open questions.DARKREADING.COM
27 AugFBI takes down China-linked hacking network behind attacks on NASA, DOJ and U.S. SenateThe Justice Department and FBI have seized domains tied to two hacking tools built and run by a Chinese state-sponsored group, cutting off access to malware that had been used against U.S. government agencies for years. The tools, known as QScan and QTRouter, were developed by a …HELPNETSECURITY.COM
27 AugCISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers DoCISA urges water utilities to find and secure internet-exposed PLCs after July attacks showed how easily exposed industrial systems can be compromised. Over 100 internet-exposed systems in the US water and wastewater sector got hit by cyberattacks in July 2026, and CISA’s r…SECURITYAFFAIRS.COM
27 AugTrump Order Aims to Block Foreign Backdoors in US Power Grid GearThe White House’s new executive order 14420 widens scrutiny of industrial control systems over cyber sabotage concerns. The post Trump Order Aims to Block Foreign Backdoors in US Power Grid Gear appeared first on SecurityWeek .SECURITYWEEK.COM
27 AugAustralian police arrest two suspected TeamPCP members.CISA says more than 100 water and wastewater systems were targeted in cyberattacks in July. UK airports disclose breach.THECYBERWIRE.COM
26 AugRisky Business #850 -- Widespread AI-enabled attacks target Siemens PLCsOn this week’s show Patrick Gray and James Wilson are joined by guest co-host Ollie Whitehouse, the CTO of the UK’s NCSC, to talk through the week’s news, including: Iranian hackers take down a small-scale power generator in the UK Siemens PLCs in critical US sectors are also bei…RISKY.BIZ
26 AugLinux Foundation takes on TRACE, a hardware-backed runtime evidence specification for AI agentsThe Linux Foundation announced the contribution of TRACE (Trust, Runtime Attestation and Compliance Evidence), from OPAQUE. Collaboratively developed by AMD, Intel, Microsoft, OPAQUE and the Technology Innovation Institute (TII), TRACE creates a standard, open evidence layer that…HELPNETSECURITY.COM
26 AugLinux Foundation Introduces TRACE Standard for AI Runtime EvidenceThis new open standard offers hardware-attested runtime and compliance evidence for AI agentsINFOSECURITY-MAGAZINE.COM
26 AugCISA: Over 100 Internet-Exposed Water Systems Targeted in July CyberattacksThe agency has released guidance on reducing internet exposure in the wake of the recent Iran-linked hacker attacks. The post CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks appeared first on SecurityWeek .SECURITYWEEK.COM
26 AugCISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected NothingThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described as similar tradecraft while recording sharply different de…THEHACKERNEWS.COM
26 AugCISA confirms hackers targeted over 100 US water systems during JulyThe federal cyber agency's warning comes amid a wave of suspected Iran-backed cyberattacks targeting critical water systems across the United States.TECHCRUNCH.COM
26 AugWho Has Admin Rights in your Entra ID Directory?, (Wed, Aug 26th)A common thing that folks should "worry" about in Entra (or any platform really) is "who has rights to administer"&#;x26;#;x3f;&#;x26;#;xc2;&#;x26;#;xa0; Who can delete or change key things, or mo…ISC.SANS.EDU
26 AugCyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructureThe order says any foreign-produced equipment deemed to pose national security risks can’t be purchased or installed. The post Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure appeared first on CyberScoop .CYBERSCOOP.COM
26 AugCISA Red Team Fully Compromised Two Critical Infrastructure OrgsCISA red teams fully compromised two critical infrastructure orgs. One SOC isolated hosts in minutes; the other never detected the breach. CISA published an advisory (AA26-237A) documenting two simultaneous red team assessments at critical infrastructure organizations. Both organ…SECURITYAFFAIRS.COM
25 AugUS lawmakers seek investigation into impact of CISA cuts.Zimbra servers targeted in ongoing attack campaign. US Treasury Department levies sanctions on alleged Iranian hackers.THECYBERWIRE.COM
25 AugWater sector passes, government sector fails attempts to spot and halt simulated CISA attackAgency red-teamers got initial access to both organizations they tested, but one quickly isolated and shut down the attempts from going further. The post Water sector passes, government sector fails attempts to spot and halt simulated CISA attack appeared first on CyberScoop .CYBERSCOOP.COM
24 AugCISA’s logging guidance works beyond governmentThe US Cybersecurity and Infrastructure Security Agency (CISA) wants federal agencies to (re)shape their logging strategy around one question: when an attack hits, can you actually use the logs you’ve collected to catch it and reconstruct what happened afterward? The Loggin…HELPNETSECURITY.COM
24 AugUber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver AccountsDutch Data Protection Authority said it is imposing a fine of 825 million euros because Uber violated the EU’s General Data Protection Regulation. The post Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts appeared first on SecurityWee…SECURITYWEEK.COM
24 AugMicrosoft Teams now lets admins block external bots from meetingsMicrosoft is rolling out a new Teams meeting protection policy that allows administrators to automatically block all identified external bots from joining Teams meetings. [...]BLEEPINGCOMPUTER.COM
24 AugNIST Warns of Unique Security Risks in Multi-Cloud EnvironmentsNIST has set out 23 novel challenges that arise in multi-cloud environments and has encouraged the cyber community to find solutionsINFOSECURITY-MAGAZINE.COM
24 AugNew Zealand to pursue social media ban for children under 16The legislation would mandate that high-risk social media platforms such as Instagram, TikTok, Snapchat and Facebook take “reasonable steps” to ensure users are over age 16 by using tools like facial age estimation, digital ID services, formal IDs and existing account information…THERECORD.MEDIA
22 AugPostal Service moves to finalize mail ballot regs before SCOTUS rulingThe rules have already been rejected by multiple state courts, but the Trump administration said it’s preparing in case of a favorable Supreme Court decision. The post Postal Service moves to finalize mail ballot regs before SCOTUS ruling appeared first on CyberScoop .CYBERSCOOP.COM
21 AugOpenAI adds an AI safety layer to detect misuse without retaining enterprise dataOpenAI is adding a new safety capability that allows enterprises to detect misuse of its AI systems across multiple interactions without retaining prompts or responses, enabling risk monitoring while preserving its Zero Data Retention (ZDR) commitments. “OpenAI does not retain…pr…CSOONLINE.COM
21 AugIn Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused BugOther noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST certification. The post In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug appeared first …SECURITYWEEK.COM
21 AugFormer NSA Director Paul Nakasone Launches National Security Advisory FirmThe newly-formed Nakasone Group will counsel government leaders, corporations, prominent families, and other private clients confronting cybersecurity, geopolitical, and personal security risks. The post Former NSA Director Paul Nakasone Launches National Security Advisory Firm a…SECURITYWEEK.COM
21 AugLawmakers call for investigation into impact of CISA staffing cutsLawmakers say little is known about how recent cuts have impacted CISA and how the knowledge that was lost has been replaced.THERECORD.MEDIA
20 AugWhen companies can hack back.This week, Dave and Ben discuss how the Trump administration has dramatically changed the cybersecurity landscape after signing a new memorandum, which allows private companies to hack malicious threat actors. Additionally, the two look at the concept of "AI constitutions," and w…THECYBERWIRE.COM
20 AugHackers Using AI to Target Siemens PLCs in Critical US SectorsA cybersecurity advisory with technical details and recommendations has been written by the NSA, CISA and other agencies. The post Hackers Using AI to Target Siemens PLCs in Critical US Sectors appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugNCSC Urges Stronger Controls for Agentic AI SystemsNCSC urged sandboxing, oversight and tight access controls for autonomous AI agentsINFOSECURITY-MAGAZINE.COM
20 AugGivEnergy enters administration, batteries expose home networksTL;DR Introduction In late 2024, we found multiple vulnerabilities in GivEnergy home battery systems that could allow attackers to access customers’ home networks, disrupt battery operation, and potentially violate UK product securi…PENTESTPARTNERS.COM
20 AugNSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCsNSA, CISA, FBI, DOE, and EPA warn of active AI-assisted attacks against Siemens S7 PLCs across US critical infrastructure sectors. Five U.S. federal agencies issued a joint advisory this week warning of an active hacking campaign against Siemens S7 Series programmable logic contr…SECURITYAFFAIRS.COM
20 AugAWS Network Firewall now supports rule hit countAs firewall rule sets grow in complexity, security teams face a common challenge: manual log analysis is used to determine which rules are actively matching traffic and which are consuming capacity without being triggered. This lack of visibility creates operational and complianc…AWS.AMAZON.COM
20 AugThe robots have gone bananas.Federal agencies warn of an active campaign targeting critical infrastructure. Citrix races to patch critical NetScaler flaws. More than 50,000 exposed Stripe API keys raise fraud concerns. Black Hat and DEF CON attendees are targeted in a new social engineering campaign. Atlassi…THECYBERWIRE.COM
19 AugCISA: Medusa ransomware hit over 500 critical infrastructure orgsThe FBI said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. [...]BLEEPINGCOMPUTER.COM
19 AugBad Microsoft Defender update causes Windows crashes on scansMicrosoft Defender users are reporting widespread scan failures after a recent security intelligence update, with Quick and Full scans crashing the antivirus engine and Offline scans reportedly freezing near completion. Reports from system administrators, home users, and Microsof…CYBERINSIDER.COM
19 AugMedusa ransomware gang has hit over 500 organizations, CISA warnsMedusa ransomware has breached more than 500 organizations since it first appeared in June 2021, the FBI, CISA, and the Department of Health and Human Services (HHS) said in an updated joint advisory. The update builds on an advisory first issued in March 2025 and draws on FBI in…HELPNETSECURITY.COM
19 AugRapid7 and Licencias OnLine Partner to Accelerate Cybersecurity Maturity across Latin AmericaCássio De Alcântara is Director, LATAM Sales at Rapid7. Across Latin America, organizations are embracing cloud, AI, and digital transformation to drive innovation and business growth. These technologies create new opportunities, but also introduce greater complexity and expandin…RAPID7.COM
19 AugA California county wants to hire Tina Peters to help run its electionsAfter her prison sentence for felony election-related crimes was commuted, Peters is poised to once again administer critical election duties. The post A California county wants to hire Tina Peters to help run its elections appeared first on CyberScoop .CYBERSCOOP.COM
19 AugAI-backed campaign targeting vulnerable Siemens S7 devices, CISA and FBI warnHackers are developing scripts disguised as legitimate software in attacks aimed at multiple industries, including energy and water.CYBERSECURITYDIVE.COM
18 AugUK Legal Regulator Raises AI Misuse ConcernsSolicitors Regulation Authority sounds the alarm over AI hallucinations and data leaksINFOSECURITY-MAGAZINE.COM
18 AugBerlin cuts two state ministries off government network after security breachThe affected ministries — one responsible for urban development, construction and housing, and the other for mobility, transport, climate protection and the environment — have been isolated from government networks since Friday as a precaution.THERECORD.MEDIA
18 AugMedusa ransomware tallies hundreds of new victims, says updated advisory on group’s tacticsThe updated warning from the FBI, CISA and HHS draws on a year’s worth of investigations to detail how the group gains initial access and what it does afterward. The post Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics appeared first on…CYBERSCOOP.COM
18 AugMore than 200 victims of Medusa ransomware identified over the last year, CISA saysThe Cybersecurity and Infrastructure Security Agency (CISA) and FBI updated an advisory on the group initially released in March 2025 — writing that as of April 2026, Medusa actors have hit more than 500 victims. CISA previously said 300 victims, many of which are in critical inf…THERECORD.MEDIA
17 AugStronger Cybersecurity Programs Start with People: NIST Wants Your Input on the Path Forward for Human-Centered CybersecurityWhen was the last time a cybersecurity process at work made you want to scream? Maybe it was a password requirement so complicated you had to write it down (defeating the purpose), a phishing simulation test that felt more like a trap than a lesson, or a confusing security warnin…NIST.GOV
17 AugWindows Server 2022 reaches end of mainstream support in 60 daysMicrosoft has reminded IT administrators that Windows Server 2022 is rapidly approaching its mainstream end date of October 2026, when it will switch to extended support. [...]BLEEPINGCOMPUTER.COM
17 AugWordPress Plugin Flaw Exposes 40,000 Sites to Admin TakeoverCritical User Profile Builder flaw let unauthenticated attackers access administrator accountsINFOSECURITY-MAGAZINE.COM
17 Aug17th August – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 17th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Colombia’s Ministry of Justice has experienced a ransomware attack that affected part of its technology infrastructure and disrupte…RESEARCH.CHECKPOINT.COM
16 AugSophisticated Cyberattack Exposes Data of 678,000 French TaxpayersFrance’s tax agency says hackers stole data on 678,000 taxpayers, including income and tax details, in a sophisticated cyberattack. A threat actor claimed to have breached France’s tax agency in late June. France’s tax administration confirmed that a cyberattack expos…SECURITYAFFAIRS.COM
16 AugSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 110Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM ShieldBreak – August 2026 …SECURITYAFFAIRS.COM
15 AugCybersecurity Today Weekend Month in Review: August 2026AI Agents Hacking, Passkey Phishing, and Water Utility Attacks In this weekend month-in-review episode of Cyber Security Today, Jim is joined by David Shipley and Laura Paine to recap major July developments. David shares highlights from Harvard's cybersecurity and public policy …CYBERSECURITYTODAY.LIBSYN.COM
14 AugNew infosec products of the week: August 14, 2026Here’s a look at the most interesting products from the past week, featuring releases from A10 Networks, ScienceLogic, Searchlight Cyber, and SelectHub. ScienceLogic delivers secure AI deployment and smarter IT operations with Skylar AI 2.5 ScienceLogic has announced Skylar AI 2.…HELPNETSECURITY.COM
14 AugWeak IAM affects up to 98% of cloud environmentsMisconfiguration remains one of the leading threats to cloud environments because a single configuration error can result in public network access, unrotated keys, missing encryption, exposed services, and logging gaps. CISA now mandates baseline cloud configuration practices for…HELPNETSECURITY.COM
14 AugUS courts will start publishing how often the government uses spywareThe Administrative Office of the U.S. Courts told TechCrunch that it will start disclosing how many times judges authorized the use of spyware to wiretap suspected criminals.TECHCRUNCH.COM
13 AugSrsly Risky Biz: Data extortion is booming. Hooray!Tom Uren and James Wilson talk about the cybercrime ecosystem shifting towards data theft extortion, stealing sensitive data and extracting ransoms from victims by threatening to leak it. For organisations whose reputation is very important to them, data leaks are a bigger threat…RISKY.BIZ
13 AugTrump turns to private sector in offensive hacking operations memoOne expert called it a “pretty big shift in U.S. cyber policy,” and there have been reservations in the past about opening the door to private sector involvement in cyber offense. The post Trump turns to private sector in offensive hacking operations memo appeared first on CyberS…CYBERSCOOP.COM
13 AugTrump administration opens door to private-sector cyber offensivesThe Trump administration is opening the door for vetted US companies to conduct cyber operations against foreign cybercriminal organizations under federal supervision, giving the private sector a more direct role in disrupting cyber-enabled crime. A presidential memorandum issued…CSOONLINE.COM
13 AugGermany moves to give spy agencies hacking and sabotage powersGermany’s cabinet approved legislation that would let its intelligence agencies hack foreign systems, sabotage adversaries’ supply chains and feed false information to extremists inside Germany, in the biggest overhaul of the country’s spy laws of the postwar era.THERECORD.MEDIA
13 AugTrump taps cyber firms to go on offensive against criminalsThe Trump administration will allow private companies to launch attacks on cybercrime organizations, the White House announced.THERECORD.MEDIA
12 AugCrytica’s RDAi detects OT device tampering from withinCrytica Security has developed a patented solution that delivers rapid, deterministic threat detection for operational technology (OT), protecting the embedded systems and connected devices that underpin critical infrastructure, national security, and healthcare without disruptin…HELPNETSECURITY.COM
12 AugRansomware Hits Colombian Justice Ministry Days Before Presidential TransitionAttackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the increased activity across Latin America.DARKREADING.COM
12 AugScienceLogic delivers secure AI deployment and smarter IT operations with Skylar AI 2.5ScienceLogic has announced Skylar AI 2.5, expanding secure deployment options for organizations with stringent security, sovereignty, and compliance requirements, while introducing enhancements that strengthen AI performance, operational intelligence, and enterprise integrations.…HELPNETSECURITY.COM
12 AugDeloitte strengthens AI governance to support trusted enterprise adoptionDeloitte has expanded AI Controls and Assurance services and solutions designed to help organizations confidently adopt, scale and govern AI across the enterprise. From early exploration to enterprise deployment, Deloitte’s enhanced services provide end-to-end support acros…HELPNETSECURITY.COM
12 AugAndroid malware combo takes out loans and relays victims' credit cardsA new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal live card data and send it to attackers in real time. [...]BLEEPINGCOMPUTER.COM
11 Aug KEVSecurity leaders’ rogue AI confidence could actually be disastrousA large majority of IT and security leaders are confident in their teams’ ability to detect when an AI agent has gone rogue, but few are able to take quick action to mitigate the fallout when an agent exceeds its intended scope. Nine in 10 IT and security leaders surveyed by IT o…CSOONLINE.COM
11 AugKids’ online safety bill faces dim prospects of passage this session despite progressProponents of the Kids Online Safety Act are cheering recent progress but acknowledge a long road ahead for legislation that, despite mounting political pressure, may be difficult to pass this session.THERECORD.MEDIA
11 AugArctera enhances Unified Platform for evidence-driven compliance workflowsArctera has announced new capabilities to the Arctera Unified Platform enabling organizations to manage complex governance requirements by connecting signals, controls and response workflows across the compliance lifecycle. These capabilities help organizations create a more comp…HELPNETSECURITY.COM
11 AugLanding Zone Accelerator Independent Assessment Report for C5:2020 now available on AWS ArtifactOrganizations operating in Germany and across Europe increasingly need to demonstrate cloud security compliance under the Cloud Computing Compliance Criteria Catalogue (C5:2020), published by Germany’s Federal Office for Information Security (BSI). Last year, we introduced Landin…AWS.AMAZON.COM
11 AugSandworm hackers target IT pros with trojanized WireGuard VPN clientHackers associated with the Russian threat group Sandworm have been targeting system administrators and IT professionals through fake job offers since at least May. [...]BLEEPINGCOMPUTER.COM
10 AugGitHub Dependabot malware alerts now cover eight ecosystemsGitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no such warning, because GitHub’s malware detection only ever watched one ecosystem. That changed this month. GitHub’s…HELPNETSECURITY.COM
10 AugPython Now Has a Post-Quantum Encryption LibraryThis is good : Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency , we implemented support for ML-KEM, the NIST-standard key-establishment primitive, and ML-DSA, the NIST-standard digital-signature pr…SCHNEIER.COM
10 AugSenate Democrats introduce bill to distribute $300 million annually to shore up water system cybersecurityTwo Democratic senators introduced legislation that would allocate $300 million each year to fund cybersecurity improvements for the water and wastewater sector.THERECORD.MEDIA
10 AugDon't Wait to Call InsuranceAfter confirming—or even reasonably suspecting—a cybersecurity incident, many organizations notify their cyber insurance provider early. Depending on the industry and applicable regulations, reporting timelines may begin before every detail is confirmed. Insurance providers often…YOUTUBE.COM
10 AugBdThemes plugins supply-chain hack creates rogue WordPress adminsA threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create rogue admin accounts. [...]BLEEPINGCOMPUTER.COM
9 AugThe AI safety test is becoming a safety riskAI agents are escaping cybersecurity testing environments and reaching real-world systems, raising questions about whether safety infrastructure, industry standards and regulation can keep pace with increasingly powerful models.TECHCRUNCH.COM
8 AugResearchers report unauthorized AI behavior.Vishing attacks target hedge funds. CISA warns of cyberattacks targeting PLCs in the water sector.THECYBERWIRE.COM
8 AugPalo Alto Networks Faces China Cybersecurity Review Amid Rising Tech TensionsChina opened a cybersecurity review of Palo Alto Networks, citing national security concerns but giving no details about the reasons behind the probe. China’s Cyberspace Administration (CAC) announced that it’s launching a cybersecurity review of products Palo Alto Networks…SECURITYAFFAIRS.COM
7 AugAI firms know policymakers won’t ‘let you make a Terminator factory,’ DHS official saysLeading AI companies have learned important lessons from recent incidents, the official said, and regulation isn’t necessary to preserve those lessons.CYBERSECURITYDIVE.COM
7 AugUS cyber ambassador nominee Cassady confirmed in SenateNTIA official Adam Cassady becomes the second person confirmed to be the State Department's ambassador-at-large for cyber policy.THERECORD.MEDIA
7 AugA decade of enterprise identity in the cloud with AWS Managed Microsoft ADTen years ago, we launched AWS Directory Service for Microsoft Active Directory, a fully managed Microsoft Active Directory in the AWS Cloud. In that original announcement, Jeff Barr described a straightforward promise: “You will spend less time administering and more time workin…AWS.AMAZON.COM
6 AugBelarusian Ransom Cartel Mastermind Gets 16 Years in PrisonMaksim Silnikau was the creator and administrator of the ransomware group and involved in Angler EK’s distribution. The post Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison appeared first on SecurityWeek .SECURITYWEEK.COM
6 AugWiz Brings Automated DISA STIG Assessment to Amazon Linux 2023 and Windows Server 2025Automating DISA STIG Compliance for Amazon Linux 2023 and Windows Server 2025, giving defense and federal teams immediate and continuous hardening validation.WIZ.IO
6 AugPodcast: Compliance Won’t Save You: The Future of Cyber Risk with Edna Conway(Video) In this podcast, we share insights from Edna Conway, a recognized leader in cybersecurity and supply chain resilience with over 40 years of experience in the field. The post Podcast: Compliance Won’t Save You: The Future of Cyber Risk with Edna Conway appeared first on Se…SECURITYWEEK.COM
6 AugHow we took malware advisories beyond npmGitHub malware advisories no longer stop at npm. Here's how we wired OpenSSF's malicious-packages data into the Advisory Database, and why we built the pipeline paranoid. The post How we took malware advisories beyond npm appeared first on The GitHub Blog .GITHUB.BLOG
5 AugQuickFox VPN installers were trojanized with malware for a yearQuickFox VPN installed a persistent backdoor on selected Windows computers, focusing on systems belonging to developers, administrators, translators, and cryptocurrency users. The attack was uncovered by Fortinet’s FortiGuard Incident Response Team while investigating modified Qu…CYBERINSIDER.COM
5 AugWhite House walks tightrope on securing AI without stifling tech innovationNational Cyber Director Sean Cairncross said the administration wants to work collaboratively with the private sector.CYBERSECURITYDIVE.COM
5 AugCISA is prioritizing work with critical infrastructure as it begins to recover from cutsThe agency has been focused on helping secure systems at drinking and wastewater utilities in recent weeks.CYBERSECURITYDIVE.COM
5 AugRansom Cartel ransomware creator sentenced to 16 years in prisonMaksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide. [...]BLEEPINGCOMPUTER.COM
4 AugFake IRS letters direct crypto holders to bogus compliance portalScammers are sending physical letters to cryptocurrency holders that copy the look of official IRS notices. The letters tell recipients they must enroll in something called a Digital Asset Compliance Portal before a deadline, or risk penalties. “If you receive a letter claiming t…HELPNETSECURITY.COM
4 AugDigital executive protection is a strategic imperative for CEOsIn this interview with Help Net Security, Brian Hill, Field CISO, Client Advisory for BlackCloak, explains how attackers reach companies through the personal lives of executives. He describes a case where a draft report sat in an executive’s personal email with no multifact…HELPNETSECURITY.COM
4 AugFake IRS letters target cryptocurrency holdersDo you hold cryptocurrency? Have you received a letter telling you that you must register with a so-called "Digital Asset Compliance Portal"? If so, it's time to hit the brakes, because it sounds like someone is trying to scam you. Read more in my article on the Hot for Security …BITDEFENDER.COM
4 AugSenate set to debate package of bills on privacy, AI and kids safetyHeadlined by the Kids Online Safety Act, a key committee will look to clear major legislation governing how minors interact with the internet. The post Senate set to debate package of bills on privacy, AI and kids safety appeared first on CyberScoop .CYBERSCOOP.COM
4 AugSpring 2026 PCI DSS and PCI 3DS compliance packages for AWS now availableAmazon Web Services (AWS) is pleased to announce the successful completion of our Payment Card Industry (PCI) Data Security Standard (DSS) and Three Domain Secure (3DS) certifications. As part of this renewal, we have expanded the scope to include three additional AWS services an…AWS.AMAZON.COM
4 AugDem senators criticize Trump administration decisionmaking on AI security risksThe five senators said the administration has alternated between being too passive and overstepping, and China stands to benefit as a result. The post Dem senators criticize Trump administration decisionmaking on AI security risks appeared first on CyberScoop .CYBERSCOOP.COM
3 AugWelcoming the Nepalese Government to Have I Been PwnedPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite Today, we welcome the 47th government onboarded to Have I Been Pwned’s free gov service: Nepal. Their National Cyber Security Ce…TROYHUNT.COM
3 AugICE Collected Nearly 1 Million People’s DNA Last Year—Including Young ChildrenInternal documents show ICE's DNA collection has skyrocketed in the second Trump administration. Now hundreds of thousands of people never convicted of a crime are in an FBI criminal database forever.WIRED.COM
3 AugCISA warns of cyberattacks targeting PLCs in the water sector.Russian espionage group tied to hotel WiFi hijacking campaign. INC ransomware gang claims credit for Australian healthcare provider hack.THECYBERWIRE.COM
3 AugOT security coalition urges Congress, CISA to enact reforms amid water sector hacksIran-nexus hackers are suspected in a broad campaign targeting drinking and wastewater sites in at least seven U.S. states.CYBERSECURITYDIVE.COM
2 AugCISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota AttacksAfter attacks hit 30+ Minnesota water systems, CISA urged utilities to remove internet-exposed PLCs and strengthen OT security. Between Sunday and Monday, July 26 and 27, a coordinated cyberattack hit operational technology (OT) systems at more than 30 community water utilities a…SECURITYAFFAIRS.COM
1 AugSuspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurkA Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025. Thes…THEHACKERNEWS.COM
1 AugClaude escaped the testing sandbox three times.Minnesota cyberattack scale is more extensive than anticipated. OpenAI's agent breached more than Hugging Face. Senator Wyden looks to eliminate legacy VPNs from federal networks. Thailand's Ministry of Finance targeted by autonomous AI agent.THECYBERWIRE.COM
1 AugColdcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 MinutesAn attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2…THEHACKERNEWS.COM
31 JulClaude escaped the testing sandbox three times.EU launches new team to monitor AI compliance.THECYBERWIRE.COM
31 JulCISA warns of cyberattacks disrupting U.S. water utilitiesThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector. [...]BLEEPINGCOMPUTER.COM
31 JulCISA warns of spike in attacks on water systems as Minnesota incidents probedThe Cybersecurity and Infrastructure Security Agency said in a public alert on Thursday that facilities should “remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible."THERECORD.MEDIA
31 JulHIPAA Security Rule on AWS – Technical Safeguards Implementation and Readiness GuidanceToday, we’re releasing the HIPAA Security Rule on AWS: Technical Safeguards Implementation and Readiness Guidance. This helps covered entities and business associates configure, implement, and evidence compliance with the HIPAA Security Rule Technical Safeguard requirements (45 C…AWS.AMAZON.COM
31 JulCISA Issues Fresh SBOM Guidance. Did They Get It Right?A couple-dozen changes to SBOM fields will make them more comprehensive, but some argue that the framework lacks real risk-management improvements.DARKREADING.COM
31 JulSouth Korea Warns of State-Backed Watering Hole AttacksSouth Korea warned that nation-state actors are using phishing and compromised websites to silently infect citizens and businesses. South Korea agencies (The National Intelligence Service, the National Police Agency, the Korea Internet & Security Agency, and the Financial Sec…SECURITYAFFAIRS.COM
30 JulAI’s latest security wake-up call.This week, Dave and Ben discuss two major stories. The first story assess the recent incident where a rogue OpenAI agent escaped its environment and successfully targeted Hugging Face. Additionally, the two also look at an incident where a man was targeted after he reportedly wip…THECYBERWIRE.COM
30 JulNCSC Calls on Vendors to Embed ‘Forensic Observability’ in Network DevicesThe UK’s National Cyber Security Centre wants network device makers to improve forensic observabilityINFOSECURITY-MAGAZINE.COM
30 JulCyber extortionists steal data from UK Department for EducationCybercriminals are attempting to extort Britain’s Department for Education (DfE) after compromising what the hackers said was more than 600,000 pieces of data allegedly including names, email addresses and phone numbers.THERECORD.MEDIA
30 JulCISA sets a new SBOM baselineThe US Cybersecurity and Infrastructure Security Agency (CISA), together with its co-authoring partners, has released the 2026 Minimum Elements for a Software Bill of Materials (SBOM), replacing the 2021 guidance published by the National Telecommunications and Information Admini…HELPNETSECURITY.COM
30 JulTimeless Compliance: Why Better Questions Beat Bigger FrameworksThe best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. The post Timeless Compliance: Why Better Questions Beat Bigger Frameworks appeared first on Se…SECURITYWEEK.COM
30 JulBuilding a great firewall around AI.China embraces open AI models, then worries it’s become a national security risk. The cyberattack on Minnesota water systems proves larger than first reported. CISA updates its SBOM guidance. AI supercharges dangling DNS attacks. Researchers uncover a self-propagating Copilot wor…THECYBERWIRE.COM
30 JulCISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCsCISA is urging water and wastewater utilities to lock down internet-exposed controllers, days after intrusions hit dozens of Minnesota systems. The post CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs appeared first on SecurityWeek .SECURITYWEEK.COM
29 JulAI agent hacks national finance ministry, Botnet uses blockchain, Healthcare chain reopensHospital ransomware fallout, blockchain botnet C2, and AI agent loose in Thailand's Finance Ministry. South Carolina's AnMed reopened some physician offices four days into a ransomware attack with phones, internet, and systems still offline, forcing manual processes and in-person…CYBERSECURITYTODAY.LIBSYN.COM
29 JulNCSC Publishes Guidance to Aid Incident Response and RecoveryThe National Cyber Security Centre has released a detailed framework to assist with incident response and recoveryINFOSECURITY-MAGAZINE.COM
29 JulAccuris uses AI to improve BOM decisions and supply chain resilienceAccuris has announced new AI capabilities for BOM Intelligence, part of its Supply Chain Intelligence suite. The launch gives engineering, procurement and supply chain teams a clearer way to move from spotting component risk to acting on it: catching obsolescence early, closing c…HELPNETSECURITY.COM
29 JulWyden calls for federal ban on legacy VPNs over security concernsUS Senator Ron Wyden is urging the Trump administration to phase out legacy virtual private network (VPN) technology across the federal government, arguing that outdated remote access systems have repeatedly enabled Chinese and Russian state-sponsored hackers to breach government…CYBERINSIDER.COM
29 JulJoint guidance on minimum elements for a software bill of materialsThis publication updates and replaces the 2021 Minimum Elements for a Software Bill of Materials published by the United States’ National Telecommunications and Information Administration.CYBER.GC.CA
29 JulCrypto Needs Rules to SurviveCryptocurrency continues to spark debate over how much regulation is appropriate. Some advocate for minimal oversight, while others argue that standards and regulatory frameworks are necessary for broader adoption and responsible business practices. Without consistent rules, mark…YOUTUBE.COM
29 JulMore than meets the AI.The Senate confirms Jay Clayton to lead ODNI. A new CISA framework highlights critical infrastructure isolation capabilities. OpenAI’s rogue agent breached more than just Hugging Face. The average cost of a data breach continues to rise. Indirect prompt injection proves irresisti…THECYBERWIRE.COM
29 JulClaude Mythos Shows AI Can Outpace Human Cryptography ResearchClaude Mythos found new flaws in HAWK and reduced AES, proving AI can autonomously advance cryptography research. Anthropic published two cryptographic research results achieved by Claude Mythos Preview working mostly autonomously: an improved attack on HAWK, a post-quantum digit…SECURITYAFFAIRS.COM
28 JulRapid7 Cyber GRC is now available: Turn security action into compliance proofCompliance has become one of the biggest operational drains on modern security teams. CISOs are being asked to manage a growing sprawl of frameworks, prove control effectiveness more often, respond to more customer assurance requests, track risk across a growing web of third part…RAPID7.COM
28 JulCISA shares advice on isolating vital systems during cyberattacksThe U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions. [...]BLEEPINGCOMPUTER.COM
27 JulHow CISOs can rise to the business resilience challengeCISOs have quietly become their organizations’ de facto chief resilience officers as the role has evolved from its primary prevention roots to now include greater emphasis on incident response and business resiliency and recovery. “Any experienced CISO who’s come up through the r…CSOONLINE.COM
27 JulAWS gives DevOps teams an AI investigator for firewall incidentsAWS DevOps Agent helps administrators inspect logs, review firewall rules and network paths, identify configuration changes that caused AWS Network Firewall to block traffic, and restore connectivity. The service is an AI-powered operations assistant for DevOps and SRE teams that…HELPNETSECURITY.COM
27 JulHackers used autonomous AI agent to spy on Thailand's finance ministryHackers used an autonomous artificial intelligence agent to carry out a cyber-espionage campaign against Thailand's Ministry of Finance, researchers discovered.THERECORD.MEDIA
27 JulJetStream Security enables on-demand shutdown of compromised AI agentsJetStream Security has announced the release of an AI Kill Switch that allows organizations to shut down compromised AI agents on-demand without impacting other AI operations. This new control plane for AI agents solves the inability to stop a single agent that falters, begins ov…HELPNETSECURITY.COM
27 JulHackers target Thailand’s Ministry of Finance with an autonomous AI agent.SourTrade builds malware in the browser. Golden Chickens lay four new malware families.THECYBERWIRE.COM
27 JulDHS Official Resigns, Citing ‘War on Immigrants’The outgoing executive director of the Office of Homeland Security Statistics is one of very few federal officials to speak out against the Trump administration’s immigration crackdown.WIRED.COM
27 JulOutdated VPNs should be purged from federal agencies, senator saysIntelligence Committee member Ron Wyden wants CISA, OMB and NIST to lead a federal effort to rout out obsolete VPNs from the U.S. government.THERECORD.MEDIA
27 Jul'Confused Deputy' Flaws Persist in Google Cloud, Microsoft AzureThis category of vulnerabilities allows an attacker to easily acquire administrative level permissions and bypass cloud providers' access controls.DARKREADING.COM
25 JulDevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate PayoutsThe operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims. Swiss cybersecurity company PRODAFT is tracking the ce…THEHACKERNEWS.COM
25 JulIran-Linked Actors Breach Are Targeting US Water and Energy Control SystemsUS agencies warn Iran-linked actors are targeting internet-exposed water and energy control systems, risking disruption. Federal agencies updated their cybersecurity advisory this week: Iran-linked actors are inside American water and energy control systems, and they’re not…SECURITYAFFAIRS.COM
24 JulThailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant StagedHunt.io uncovered a cyber-espionage attack on Thailand’s Finance Ministry using Hermes AI agent and Hades malware for reconnaissance and persistence. Researchers at Hunt.io have uncovered an intrusion targeting Thailand’s Ministry of Finance that offers a rare look inside a…SECURITYAFFAIRS.COM
24 JulGitHub ordered to remove decentralized messaging app Bitchat in IndiaIndia's Ministry of Home Affairs has ordered GitHub to remove repositories hosting Jack Dorsey's decentralized messaging app Bitchat, arguing that the Bluetooth mesh platform could be used to evade internet shutdowns and lawful surveillance. The order, which was made public by Do…CYBERINSIDER.COM
24 JulAndy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministryThe new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.THERECORD.MEDIA
24 JulAccelerating AWS Network Firewall troubleshooting with AWS DevOps AgentWhen an administrator introduces a rule change in AWS Network Firewall and network connectivity is disrupted, pinpointing the cause requires inspecting multiple points in the traffic path. The firewall gives you stateless and stateful rule engines, domain rules, and routing to th…AWS.AMAZON.COM
24 JulIndustry’s message on CIRCIA: Please ask us fewer questions about cyberattacksThe administration set a target date of September for CISA to finalize the rule, but where the agency is headed remains a mystery to some. The post Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks appeared first on CyberScoop .CYBERSCOOP.COM
23 JulUS Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS DevicesAn updated advisory from federal agencies provides information on the techniques used to hack programmable logic controllers. The post US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices appeared first on SecurityWeek .SECURITYWEEK.COM
23 JulANCHOR-CI could fix 20 years of broken government-industry collaborationThe government spent the past two decades learning what private sector partners have always known: cyber resilience requires everyone in the room. ANCHOR-CI is proof that the lessons may finally stick. The post ANCHOR-CI could fix 20 years of broken government-industry collaborat…CYBERSCOOP.COM
23 JulIranian Hackers Target Siemens and Schneider Industrial Systems, CISA WarnsUS government agencies have warned that Iranian cyber actors are targeting US-based Siemens and Schneider industrial equipmentINFOSECURITY-MAGAZINE.COM
23 JulGAO report details scope of cybersecurity regulation overlapA morass of rules is forcing companies to report the same information multiple times — and sometimes, those rules conflict.CYBERSECURITYDIVE.COM
23 JulRubio restricts visas for sextortionists, cyber scammersThe move stems from a Trump executive order as the administration continues to pursue cyber-enabled fraud and other crimes. The post Rubio restricts visas for sextortionists, cyber scammers appeared first on CyberScoop .CYBERSCOOP.COM
22 JulStates Want ICE Agents to Show Their Faces. The Trump Administration Is Blocking ThemFederal lawyers say anti-mask laws would endanger immigration agents, citing an ICE face-recognition art project that doesn’t actually work.WIRED.COM
22 JulEU Financial Institutions Leak Data Through Cookie TrackersEuropean banks inadvertently transmitted customer data to ad platforms via tracking pixels, raising serious compliance, security, and privacy concerns.DARKREADING.COM
22 JulFederal agencies broaden alert on Iran-linked OT attacksThe observed incidents include “malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays,” the advisory says.THERECORD.MEDIA
22 JulExtension of CISA 2015 info-sharing protections passes as part of House’s defense billA 10-year renewal of the cybersecurity information-sharing law known as CISA 2015 passed as part of the House's fiscal 2027 defense authorization bill.THERECORD.MEDIA
22 JulMost federal cybersecurity reporting rules are duplicative, study findsThe Government Accountability Office looked at 117 rules across 37 agencies and found 70% had reporting requirements that were overlapping. The post Most federal cybersecurity reporting rules are duplicative, study finds appeared first on CyberScoop .CYBERSCOOP.COM
21 JulMicrosoft shares manual fix for WSUS sync delays and timeoutsMicrosoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out. [...]BLEEPINGCOMPUTER.COM
21 JulShufti simplifies cross-border compliance with the Glocal PlatformShufti has launched the Shufti Glocal Platform, a compliance lifecycle management solution designed to help organizations manage identity verification, fraud prevention, risk assessment, and regulatory compliance through a single platform across every industry, every region, and …HELPNETSECURITY.COM
21 JulThe Trump administration's AI czar resigns.Extortion group wipes Romania's land registry database. FBI warns of impersonators targeting scam victims.THECYBERWIRE.COM
21 JulHouse intel bill includes provisions on state and local threat intelligence, election security, AIThe House Intelligence Committee advanced its fiscal 2027 authorization legislation Monday. The post House intel bill includes provisions on state and local threat intelligence, election security, AI appeared first on CyberScoop .CYBERSCOOP.COM
21 JulWhere’s the Trump administration line on AI regulation?The messy approach to U.S. AI regulation reflects both the rapid speed of model cyber capabilities and the White House’s “education” over the past two years, experts said. The post Where’s the Trump administration line on AI regulation? appeared first on CyberScoop .CYBERSCOOP.COM
21 JulTrump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply ChainsNew executive order calls for end-to-end visibility into defense supply chains, including software dependencies, foreign ownership and cyber-related supplier risks. The post Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains appeared first o…SECURITYWEEK.COM
20 JulRussian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and UkraineAt least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. That is the finding of…THEHACKERNEWS.COM
20 JulBanning AI Won't Stop ItHighly regulated industries have often been slower to adopt AI because regulations and risk concerns create uncertainty. But organizations are increasingly realizing they can't delay forever. Cybersecurity and risk teams are shifting from acting solely as gatekeepers to becoming …YOUTUBE.COM
20 JulDutch Intelligence Warns Russia Uses Hacked IP Cameras for Military EspionageDutch intelligence says Russia hacks IP cameras to monitor NATO military logistics and weapons shipments to Ukraine. The Netherlands’ AIVD and MIVD, the civilian and military intelligence services, published a joint advisory on July 10 confirming that at least one Russian i…SECURITYAFFAIRS.COM
20 JulHackers were inside South Korea's diplomat training system for 9 monthsUnidentified hackers compromised an online education system used by South Korea's diplomatic academy, stealing personal information belonging to former and current employees of the country's Ministry of Foreign Affairs.THERECORD.MEDIA
18 JulThe Future of Age Verification: Your Face Never Leaves Your DeviceAs age verification laws expand worldwide, organizations face growing pressure to protect users' privacy while meeting regulatory requirements. Incode explains how on-device age estimation verifies age without transmitting or storing facial images, reducing biometric privacy risk…BLEEPINGCOMPUTER.COM
17 JulThe five step plan that cuts security budget wasteIn this Help Net Security video, Viktor Bulanek, CTO of Penetrify, explains where security budget waste comes from. Budgets get built around vendor categories, compliance checkboxes, and last year’s headlines. Attackers work along attack paths, and that mismatch is where th…HELPNETSECURITY.COM
17 JulSenior executives are killing your shadow AI strategyShadow IT has long been a major problem for CISOs, but the biggest problem may be coming from the executive suite’s hunger for unsanctioned AI. Nearly two-thirds of senior decision-makers admit to using unapproved AI tools , compared to just 31% of lower-level employees, accordin…CSOONLINE.COM
17 JulZelensky appoints Ukraine's acting security service chief as acting defense ministerYevhenii Khmara, a major general with deep experience in intelligence, counterterrorism and long-range strikes against Russia, is Ukraine's new acting defense minister.THERECORD.MEDIA
17 JulPodcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive(Video) Artificial intelligence is transforming cybersecurity, but are governance, compliance, and security practices evolving fast enough to keep up? The post Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive appeared first on SecurityWeek .SECURITYWEEK.COM
17 JulState officials, election experts pan Trump speech: ‘This is what desperation looks like’The president’s speech re-hashed debunked conspiracies around U.S. elections. Critics say the administration’s 18-month investigation into voter fraud has been a total failure. The post State officials, election experts pan Trump speech: ‘This is what desperation looks like’ appe…CYBERSCOOP.COM
16 JulWho governs your AI agents?Your team spent a decade maturing privileged access management. Then AI agents arrived and they don’t log in like humans. Now your biggest insider threat is an AI agent that lacks the access it needs, and then it goes to get it. In this episode Sundari Parekh, VP of AI Security a…THECYBERWIRE.COM
16 JulRomania’s land registry hit by cyber attack, data allegedly for saleRomania’s National Agency for Cadastre and Land Registration (ANCPI) suffered a major disruption on Tuesday, July 14, when its e-Terra cadastre and land registry app became unavailable to users. What was first declared to be a “major technical incident” has now …HELPNETSECURITY.COM
16 JulUkrainians rally against dismissal of tech-minded defense minister FedorovUkraine President Volodymyr Zelensky dismissed Defense Minister Mykhailo Fedorov, who championed the push to integrate drone technology and digital innovation into the military.THERECORD.MEDIA
16 JulSenator calls on Rubio, Blanche to push back against Canadian surveillance legislationDemocratic Sen. Ron Wyden says the Trump administration should pressure Canada not to enact a proposal that would "weaponize American technology infrastructure" for surveillance purposes.THERECORD.MEDIA
15 JulMicrosoft is forcing an enterprise transition to passkeysPasskeys have been around for some time, but enterprise-wide adoption to this point has been slow for a number of reasons. But soon, many Microsoft customers won’t have a choice. Starting September 1, Microsoft will roll out passkeys as the default authentication method in its cl…CSOONLINE.COM
15 JulProduct showcase: Trust Chain TPRM turns vendor compliance evidence into verified assuranceTrust Chain is an AI-native third-party risk management (TPRM) solution by Strike Graph that replaces the security questionnaire model with validated evidence of compliance. Rather than asking vendors to self-report their security posture, Trust Chain requires vendors to submit e…HELPNETSECURITY.COM
15 JulWhen 80,000 fans log on at once: The 2026 World Cup’s unique cybersecurity issuesWith the World Cup in full swing, stadiums across North America are currently accommodating thousands of fans every match day. That said, the stadiums’ biggest security challenge isn’t of a physical nature. It is not hyperbolic to say that football stadiums are some of the most c…CSOONLINE.COM
15 JulTrump administration unveils AI-supported clearinghouse for cyber vulnerabilitiesThe Gold Eagle program will allowe industry, critical infrastructure operators and the government to use artificial intelligence to rapidly detect, prioritize and patch cybersecurity vulnerabilities, officials said.THERECORD.MEDIA
14 JulUS authorities warn of Russian attacks on critical infrastructureThe US authorities NSA, FBI, and CISA warn that Russian hackers have recently carried out a number of attacks on critical infrastructure in North America and Europe. Hackers are reportedly breaking into networks using vulnerable and misconfigured routers, making it extra importan…CSOONLINE.COM
14 JulShifting Security and Protecting the Pharma Supply Chain with Andy HillisHost Caleb Tolin sits down with Andy Hillis to discuss the evolution of information security from a late stage deployment checklist to a core prerequisite within global pharmaceutical infrastructure. The conversation reviews the operational challenges of managing over 200 annual …THECYBERWIRE.COM
14 JulNATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory saysDutch intelligence officials report that at least one Russian agency is compromising internet-connected cameras across Europe to spy on military logistics and Ukrainian personnel.THERECORD.MEDIA
14 JulTreasury sanctions First VPN Service, others for abetting ransomware gangsThe designations hit 1VPNS, its alleged Ukrainian administrator and a Belarusian who allegedly sold “cryptors” to disguise ransomware and other malware. The post Treasury sanctions First VPN Service, others for abetting ransomware gangs appeared first on CyberScoop .CYBERSCOOP.COM
13 JulWhy SBOMs, signing, and provenance still don’t tell you if software is safeWe have made real progress in software supply chain security, improving visibility into software components, authenticity and build integrity. Much of this progress traces back to Executive Order 14028, which pushed agencies, contractors and enterprises to invest in SBOMs, signin…HELPNETSECURITY.COM
13 JulRussian State Hackers Target Vulnerable Routers Worldwide, Joint Advisory WarnsCybersecurity agencies from 12 countries have warned that Russian state-backed hackers are actively targeting vulnerable routers using weak SNMP credentialsINFOSECURITY-MAGAZINE.COM
13 JulNew compliance guidance available: HITRUST i1 on AWSWe are pleased to announce the publication of a new AWS compliance implementation guidance: HITRUST i1 Compliance on AWS: Customer Implementation Guidance with an Illustrative Healthcare Platform. Healthcare organizations seeking HITRUST i1 certification increasingly rely on Amaz…AWS.AMAZON.COM
13 JulLessons Learned from CISA’s Recent GitHub LeakThe Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by Kr…KREBSONSECURITY.COM
13 JulOfficials once again warn defenders that Russian hackers are targeting network devicesState-sponsored attackers are targeting critical infrastructure networks in defense, communications, energy, finance, government and health care. The post Officials once again warn defenders that Russian hackers are targeting network devices appeared first on CyberScoop .CYBERSCOOP.COM
13 JulVPN service favored by ransomware groups is sanctioned by USThe U.S. Treasury Department announced sanctions against First VPN Service (1VPNS) and its Ukrainian administrator for aiding ransomware groups. Separately, a Belarusian man was sanctioned for malware "cryptors."THERECORD.MEDIA
13 JulAI Cannot Govern AloneAI can help organizations create stronger policies and improve security decision-making, but current AI systems are not perfectly precise. Because AI is non-deterministic, security teams still need humans involved in important decisions. Better outcomes require combining AI capab…YOUTUBE.COM
13 JulStates are building their own election defense networks as federal support evaporatesElection officials are facing an impossible choice: follow federal directives they don’t trust, or risk becoming targets of a criminal investigation. The post States are building their own election defense networks as federal support evaporates appeared first on CyberScoop .CYBERSCOOP.COM
11 JulUS cyber agency CISA had to build its incident playbook during the incident, agency revealsCISA said it "missed" an opportunity to get ahead of the security incident by not creating a response plan ahead of time.TECHCRUNCH.COM
10 JulMicrosoft uncovers GigaWiper, a backdoor designed for destruction on demandMicrosoft is warning defenders about a new backdoor that blurs the line between espionage malware and wipers. In a technical analysis published on Thursday, Microsoft Threat Intelligence detailed GigaWiper, a Golang-based implant first observed in October 2025 intrusions that com…CSOONLINE.COM
10 JulCISA details security lapses that led to GitHub leak of passwords, cloud access keysThe agency’s blog post came as lawmakers pressed the agency for answers.CYBERSECURITYDIVE.COM
10 JulCISA Details Incident Response to Exposed AWS GovCloud KeysCISA reveals how it responded after sensitive AWS GovCloud credentials and internal data were exposed in a public GitHub repositoryINFOSECURITY-MAGAZINE.COM
10 JulMore Countries Jump on the Social Media Ban WagonAge restrictions on accounts may be more of a ban(d) aid, because industry compliance is already falling short. Tech giants are struggling to follow the laws without affecting users.DARKREADING.COM
10 JulCISA looks to remedy ailments from big May credential leakA major credential leak spurred the Cybersecurity and Infrastructure Security Agency to strengthen protections for its sensitive materials, improve how researchers can report agency vulnerabilities and develop plans for similar incidents, the agency said in a forensic report rele…CYBERSCOOP.COM
10 JulAttackers Have the Advantage NowThe pace of cyberattacks has accelerated dramatically. Techniques that once required weeks can now happen in minutes, hours, or days, making it increasingly difficult for defenders to respond using traditional security processes. The concern isn't that attackers will always have …YOUTUBE.COM
9 Jul75% CISOs Fear Executives Don’t Understand Cybersecurity Risks Employees FaceSurvey of cybersecurity leaders by MetaCompliance finds that many feel boards are uninterested in ever-evolving cyber risksINFOSECURITY-MAGAZINE.COM
9 JulWhy we cannot wait for better post-quantum signature algorithmsNIST is advancing nine new post-quantum signature algorithms as potential candidates for future standardization. We take a closer look at all of them, and argue that while they are in the works and show great potential, we should use ML-DSA for now — the best one currently availa…CLOUDFLARE.COM
9 JulEU Parliament voted to restore private communications scanningThe European Parliament has approved legislation that restores the temporary legal framework allowing online platforms to voluntarily scan private communications for child sexual abuse material (CSAM). This vote effectively revives a regime that expired in April after the EU Parl…CYBERINSIDER.COM
8 JulNCSC Touts National Scale, AI-Powered “Cyber Shield” for DefenseThe National Cyber Security Centre wants to work with AI partners to build a new “Cyber Shield” to defend the UKINFOSECURITY-MAGAZINE.COM
8 JulEU now one step away from reviving private message scanning rulesThe European Parliament has approved an urgent procedure to fast-track legislation that would revive the EU's expired “Chat Control 1.0” rules. This development sets up a decisive vote on July 9 over whether online platforms may once again be allowed to voluntarily sc…CYBERINSIDER.COM
8 JulFormer UK privacy chief preparing legal action against woman who reported him, minister saysLiz Kendall, the secretary of state for science, innovation and technology, said she was “absolutely appalled” at the findings of “sexual harassment and bullying” made by an independent investigation at the Information Commissioner’s Office (ICO).THERECORD.MEDIA
8 JulGreek victims file lawsuit against Intellexa over Predator spywareThe use of the spyware came to light in 2022, with traces of Predator found on dozens of phones. The scandal led to the resignation of Greece’s intelligence service chief and the prime minister’s chief of staff.THERECORD.MEDIA
7 JulIran-Linked Hackers Use New Cavern C2 Framework to Target Israeli OrganizationsAn Iranian hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS) has been wielding a previously undocumented modular command-and-control (C2) framework dubbed Cavern (aka Cav3rn) targeting Israeli organizations. The activity, which has primarily single…THEHACKERNEWS.COM
7 JulRadware updates Agentic AI Protection with AI governance and compliance capabilitiesRadware has announced enhancements to its Agentic AI Protection solution to help organizations govern and secure AI agents across enterprise environments. The release adds compliance reporting to support alignment with leading global AI standards, enhanced visibility into agent e…HELPNETSECURITY.COM
7 JulUK cyber pledge draws only a handful of top firms despite ministerial appealThose that did sign include large firms such as Aviva, the London Stock Exchange Group and Marks & Spencer, which lost hundreds of millions of pounds in a cyberattack last year, as well as small cybersecurity consultancies.THERECORD.MEDIA
7 JulCISA Reportedly Using Anthropic’s Mythos to Scan Government Software for FlawsThe audits are reportedly being spearheaded by CISA’s Attack Surface Evaluation team, a specialized unit tasked with conducting digital defense assessments and simulated hacking exercises. The post CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws app…SECURITYWEEK.COM
7 JulBritain plans to build autonomous AI 'Cyber Shield' to defend nationThe capability, called Cyber Shield, is designed to counter a threat the National Cyber Security Centre (NCSC) said could see attackers “move at machine speed and greater scale, reducing opportunities for detection and response.”THERECORD.MEDIA
7 JulHidden backdoor in Tenda router firmware grants admin accessA hidden authentication backdoor has been found in multiple Tenda router firmware versions, potentially allowing an attacker to gain administrative access to the device's web management panel. [...]BLEEPINGCOMPUTER.COM
6 JulCavern Manticore: Exposing Iran-Linked Modular C2 FrameworkKey Points Introduction Since early 2026, Check Point Research (CPR) has tracked a new modular command-and-control framework used by Cavern Manticore, an Iran-nexus APT group primarily targeting Israeli organizations, with a focus on IT providers, and government sectors. Cavern M…RESEARCH.CHECKPOINT.COM
6 JulOperationalizing Agentic AI: from assisted to autonomousEver since ChatGPT made its public debut nearly four years ago, governance and security have largely lagged behind AI adoption. Eager to experiment with AI tools and find ways to improve their work and personal lives, users have uploaded corporate data, financial records, and eve…CSOONLINE.COM
6 JulKYC : Bypass age verification using generative video modelsHistorically reserved for the banking sector, the KYC (Know Your Customer) process is now making its way into many online services, driven by increasingly strict legislation on anonymity and age verification. To comply, platforms deploy significant measures aimed at guaranteeing …SYNACKTIV.COM
6 Jul5 insights from Frost & Sullivan’s 2025 Frost Radar™ for Cloud Security Posture ManagementRead five key learnings from the Frost & Sullivan 2025 Frost Radar™ for CSPM to learn how CSPM is evolving from point-in-time compliance to continuous risk management. The post 5 insights from Frost & Sullivan’s 2025 Frost Radar™ for Cloud Security Posture Management app…MICROSOFT.COM
6 JulAI Needs an Identity TooAI is transforming identity security in two directions. Organizations are using AI to automate identity management, while AI agents themselves are becoming identities that require permissions, monitoring, and governance. As AI agents access sensitive data and perform actions on b…YOUTUBE.COM
6 JulEFF-led coalition urges FTC to reject X’s bid to end privacy oversightA coalition of 15 public-interest organizations is urging the U.S. Federal Trade Commission (FTC) to reject X Corp.'s request to terminate or weaken a 2022 privacy order requiring the company to undergo regular compliance reviews after it repeatedly violated users' privacy. The g…CYBERINSIDER.COM
2 JulReview: CTRL+ALT+PWNHacking gear that once sat in well-funded labs now ships to anyone with a credit card and a video tutorial. Frank Riccardi builds his consumer guide, CTRL+ALT+PWN: The Hacker’s Playbook (And How to Beat It), on that one condition. He spent twenty-five years in healthcare co…HELPNETSECURITY.COM
2 JulNCSC Shares Tips on How to Make a Pen Tester’s Job HarderThe NCSC has shared best practice advice from pen testers which could help improve system resilienceINFOSECURITY-MAGAZINE.COM
2 JulTrump Administration Lifts Restrictions on Anthropic’s Claude Models After Cybersecurity AlarmAnthropic said Tuesday night that its AI model called Claude Fable 5 is now widely available. The post Trump Administration Lifts Restrictions on Anthropic’s Claude Models After Cybersecurity Alarm appeared first on SecurityWeek .SECURITYWEEK.COM
2 JulCybersecurity Mission Creep in the USInteresting paper: “ Cybersecurity Mission Creep .” Abstract: Cybersecurity is experiencing mission creep. Policymakers are casting more and more problems as issues of cybersecurity. So reframed, wildly different policy issues, from misinformation, to child social med…SCHNEIER.COM
2 JulAussies Face Reduced Cybercrime Risk, as Pressure Shifts to SMBsImproved institutional safeguards and stricter regulations have pushed the burdens of protection and risk reduction on to Australian businesses.DARKREADING.COM
1 JulAI-generated code risks reach security, legal, and compliance teamsMost engineering organizations write code with AI, and a good number of them keep that code away from customers. A Flux survey of engineering leaders and practitioners found that nearly half run AI-generated code in production. Almost every company in the sample uses AI somewhere…HELPNETSECURITY.COM
30 JunHalf the defense base still builds security around complianceCMMC requirements are appearing in defense contracts and moving down through supplier networks to thousands of companies new to this kind of compliance work. Many run on limited budgets with lean security teams. The picture comes from nearly 900 defense contractors, C3PAOs, feder…HELPNETSECURITY.COM
30 JunNew Controller Flaws Expose Highway Signs and Billboards to Remote HackingCISA has published an advisory to inform organizations about three vulnerabilities found by a researcher in Daktronics controllers. The post New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunCompleting Compliance with Evidence : A Bottom-Up Approach to NIS2, DORA, and the Cyber Resilience ActGRC (Governance, Risks and Compliance) as it is most often practiced works top-down, you read a piece of regulation, draft a policy, declare coverage, and archive a documentary record. This approach has value, it structures, it documents, it meets an auditor's formal expectations…SYNACKTIV.COM
30 JunCequence Platform 9.0 uses AI to simplify API security and complianceCequence Security has announced general availability of Cequence Platform 9.0, an AI-native release that changes how users interact with API security tools. Platform 9.0 ships with a built-in AI Assistant, an open Model Context Protocol (MCP) server that exposes every platform ca…HELPNETSECURITY.COM
30 JunDHS proposes new framework for public-private infrastructure security collaborationThe Trump administration eliminated the previous system in 2025, sparking a backlash from experts and infrastructure operators.CYBERSECURITYDIVE.COM
30 JunDHS to unveil replacement council for critical infrastructure cybersecurityThe Department of Homeland Security is bringing back a key cybersecurity information sharing effort with critical infrastructure, more than a year after the Trump administration shuttered an existing nerve center between government and private sector. The Alliance of National Cou…CYBERSCOOP.COM
30 JunHouse passes kids’ online safety bill, but Senate approval unlikelyThe Kids Internet and Digital Safety (KIDS) Act passed with bipartisan support by a 267-117 margin, winning the two-thirds majority needed to greenlight the legislation under a process that speeds up a bill’s path to a vote but requires more than a simple majority.THERECORD.MEDIA
30 JunTrump budget boss Russell Vought open to re-staffing CISADHS Secretary Markwayne Mullin has been floating the idea of adding back 600 CISA personnel after deep Trump administration cuts. The post Trump budget boss Russell Vought open to re-staffing CISA appeared first on CyberScoop .CYBERSCOOP.COM
29 JunWhat the post-quantum executive order really demands of CISOsith federal PQC deadlines set for 2030 and 2031, CISOs face a multi-year transformation program that most organizations have not yet started. The window for orderly execution is narrowing fast. The post What the post-quantum executive order really demands of CISOs appeared first …CYBERSCOOP.COM
29 JunOpenAI and Anthropic Limit New AI Models to Trump-Approved Customers During Cybersecurity ReviewChatGPT maker OpenAI said Friday it is restricting the release of its new artificial intelligence model at the request of President Donald Trump’s administration. The post OpenAI and Anthropic Limit New AI Models to Trump-Approved Customers During Cybersecurity Review appeared fi…SECURITYWEEK.COM
29 JunMustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government AttacksThe China-aligned espionage group Mustang Panda is running two campaigns against the Indian government and hydropower targets, deploying new malware and turning a legitimate cloud service into its command channel. Acronis Threat Research Unit found active compromis…THEHACKERNEWS.COM
27 JunFBI Warns Russian Intelligence Hackers Target Signal Backup Recovery KeysThe FBI and CISA have updated their March warning about Russian intelligence phishing Signal accounts, and the operators have added a step: they now coax targets into handing over their Signal Backup Recovery Key. Hand it over once, and the attacker can restore the acco…THEHACKERNEWS.COM
27 JunAWS Forensics : What you need to knowNowadays, it is rare to find a company whose IT system does not rely, at least in part, on cloud technologies. These solutions offer numerous benefits, particularly in terms of the rapid deployment of services and infrastructure. However, those technologies require specific skill…SYNACKTIV.COM
27 JunActivID administrator account takeover : the story behind HID-PSA-2025-002In September 2025, we were asked by one of our clients to focus on a specific product: ActivID Appliance by HID. According to the vendor, this product is used worldwide to secure access to critical infrastructure and data. It supports a wide range of authentication methods includ…SYNACKTIV.COM
27 JunWhat Counts as a Crypto Security?The SEC has introduced a five-part framework to clarify when a crypto asset should be treated as a security. Under the guidance, assets such as Bitcoin, Ethereum, meme coins, and utility tokens are generally not classified as securities, while stablecoins fall under separate legi…YOUTUBE.COM
27 JunNew FBI Alert: Russian Intelligence Uses Signal Recovery Keys to Access MessagesFBI warns Russian spies now target Signal Backup Recovery Keys, enabling access to message history and long-term account takeover. The FBI and CISA updated their March 2026 warning about Russian intelligence phishing campaigns, and the new advisory adds a detail that wasn’t…SECURITYAFFAIRS.COM
26 JunZeroTier Quantum RC2 brings post-quantum security closer to general availabilityZeroTier has announced the release candidate 2 (RC2) for ZeroTier Quantum, its end-to-end quantum-secure networking platform. This milestone marks the final testing phase, positioning the platform one step away from general availability (GA). ZeroTier Quantum addresses the loomin…HELPNETSECURITY.COM
26 JunFBI: Russian hackers now target Signal backup recovery keysThe FBI and CISA are warning that a phishing campaign targeting Signal users tied to Russian intelligence services has evolved to steal Signal Backup Recovery Keys, allowing attackers to access victims' historical messages. [...]BLEEPINGCOMPUTER.COM
25 JunDHS chief says president has met with potential CISA nominee; agency plans to hire 600Once a new CISA director is in place, the agency will ramp up hiring efforts, Homeland Security Secretary Markwayne Mullin told lawmakers. The White House has not yet announced a nominee.THERECORD.MEDIA
25 JunFCC passes new cybersecurity rules for emergency systems, undersea cablesThe new rules would overhaul national emergency systems to protect against hijacking and update federal security review rules for undersea cables providers The post FCC passes new cybersecurity rules for emergency systems, undersea cables appeared first on CyberScoop .CYBERSCOOP.COM
25 JunFederal court rules Trump election-focused executive order illegalProvisions setting up federal voter lists for each state and restricting mail ballots through USPS were declared unconstitutional. The post Federal court rules Trump election-focused executive order illegal appeared first on CyberScoop .CYBERSCOOP.COM
25 JunNIST offers security guidance for water utilities using remote-access toolsThe technology is one of the water sector’s biggest cybersecurity weaknesses.CYBERSECURITYDIVE.COM
25 JunNew CISA Guide Helps Agencies Adopt SASE For Zero TrustNew CISA guidance shows federal agencies how to use SASE to move from legacy TIC 2.0 to zero trustINFOSECURITY-MAGAZINE.COM
🔥 INCIDENT REPORTING 1004[−]
23 SepAmazon Slams the door on Meta's Muse AI AgentAmazon Blocks Meta's AI Shopping Agent, FBI Boards Hacked Oil Tankers & Microsoft Patches Break Backups David Shipley covers Amazon blocking Meta's new AI agent Muse from shopping on Amazon, citing failure to identify itself and potential privacy and security risks, as the broade…CYBERSECURITYTODAY.LIBSYN.COM
23 SepShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job ApplicantsThe cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency. "We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents …THEHACKERNEWS.COM
23 SepRisky Business #854 -- We're JevpilledTHE RISKY BUSINESS WEEKLY SHOW IS NOW ON HIATUS FOR TWO WEEKS AND WILL RETURN OCTOBER 14 On this week’s show Patrick Gray and James Wilson are joined by Adam Boileau to talk through the week’s news, including: Google’s Gemini finally did some crimes OpenAI admits more agents did …RISKY.BIZ
23 SepEU Auditors Warn Information-Sharing Gaps Are Hindering Cyber Incident ResponseThe EU Court of Auditors has criticized EU shortcomings in responding to major cyber incidentsINFOSECURITY-MAGAZINE.COM
23 SepRyuk ransomware member sentenced to 24 months in prisonAn Armenian man was sentenced to 24 months in prison and 3 years of supervised release for hacking U.S. companies and encrypting their systems in Ryuk ransomware attacks. [...]BLEEPINGCOMPUTER.COM
23 SepUAE, Saudi Arabia Face Onslaught of Increasingly Complex CyberattacksThe United Arab Emirates and Kingdom of Saudi Arabia together absorbed 50% of all cyberattacks recorded across the Gulf region in the first half of 2026.DARKREADING.COM
23 SepRansomware Attacks Reach Record High for 2026A total of 1073 firms fell victim to ransomware attacks globally in August, with the industrial sector the most affected, according to new NCC dataINFOSECURITY-MAGAZINE.COM
23 SepShinyHunters claims FBI breach was revenge for “false” reportThe extortion group says it stole sensitive data on FBI agents and job applicants, and wants the bureau to retract a warning about its tactics.MALWAREBYTES.COM
23 SepLatvia arrests suspected hacker for electronics repair company breachLatvian police arrested a 23-year-old man suspected of hacking at least two companies, stealing personal information and attempting to extort money from the victims.THERECORD.MEDIA
23 SepYou Own Your AI Agent’s ActionsThe organization established a principle that employees remain accountable for their agents’ actions, including actions taken by sub-agents created downstream. That creates a human chain of accountability even as identities become increasingly non-human. Real incidents were also …YOUTUBE.COM
23 SepCompromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPIUnknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS. According to reports from Aikido, SafeD…THEHACKERNEWS.COM
23 SepFBI investigating alleged ShinyHunters breach of its jobs siteThe ShinyHunters cybercriminal organization on Tuesday replaced agency images on the FBIjobs.gov site with a photo of a Pokemon that has become the group’s defacto mascot.THERECORD.MEDIA
23 SepRyuk ransomware operator gets 2-year sentence after extorting victims for $1.2 millionAn Armenian national and member of the Ryuk ransomware gang was sentenced to two years in federal prison for his role in launching attacks.THERECORD.MEDIA
23 Sep KEVBusinesses fear cyberattacks more than anything else, driven by AI and supply chain worriesMany companies still aren’t preparing thoroughly enough to face a hack, the insurance firm Travelers said in a new report.CYBERSECURITYDIVE.COM
23 SepShinyHunters claims to have breached the FBI.Microsoft disrupts the EvilTokens cybercrime platform. Business news: Cyera raises $400 million in a Series G extension.THECYBERWIRE.COM
23 SepRyuk ransomware operator gets 2-year sentence after extorting victims for $1.2 millionAn Armenian national and member of the Ryuk ransomware gang was sentenced to two years in federal prison for his role in launching attacks.THERECORD.MEDIA
23 SepRyuk ransomware operator sentenced to 2 years in prisonThe Armenian national was extradited from Ukraine to the United States last year and pleaded guilty to cybercrimes in July. The post Ryuk ransomware operator sentenced to 2 years in prison appeared first on CyberScoop .CYBERSCOOP.COM
23 SepFBI probes cyberattack tied to third-party jobs portalThe potentially serious breach highlights the supply chain risks facing even the most sophisticated organizations.CYBERSECURITYDIVE.COM
22 SepUS Proposes AI Incident Alert System in Talks With China, Bessent SaysTrump has resisted calls to slow down AI development, saying that would help China catch up to U.S. companies. The post US Proposes AI Incident Alert System in Talks With China, Bessent Says appeared first on SecurityWeek .SECURITYWEEK.COM
22 SepCybersecurity jobs available right now: September 22, 2026Analyst Threat Intelligence Optimum | USA | On-site – View job details As an Analyst Threat Intelligence, you will collect and analyze intelligence to identify threats, threat actors, malware campaigns, and relevant TTPs. You will map adversary behavior to MITRE A…HELPNETSECURITY.COM
22 SepLimeLeads - 17,838,396 breached accountsIn 2019, the now-defunct B2B marketing leads database service LimeLeads suffered a data breach due to an exposed, unsecured Elasticsearch server. The incident exposed tens of millions of records of largely corporate contact data containing 17.8M unique email addresses, along with…HAVEIBEENPWNED.COM
22 SepCISOs Must Update Incident Response Playbooks for Multimodal Deepfakes, Gartner WarnsGartner warns that CISOs must update incident response playbooks as AI-powered deepfakes make social engineering attacks more convincing and harder to detectINFOSECURITY-MAGAZINE.COM
22 SepAI Incident Response Readiness Lags Behind AI Adoption, ISACA FindsA new report by ISACA found that 71% of orgs have not run AI incident response exercises as teams face rising pressureINFOSECURITY-MAGAZINE.COM
22 SepWebinar tomorrow: Inside real-world Google Workspace breachesTomorrow's webinar examines real Google Workspace breaches involving social engineering and malicious OAuth applications, from initial access through the critical first hours of incident response. Learn which security controls and response decisions can make the greatest differen…BLEEPINGCOMPUTER.COM
22 SepThe latest deepfake numbers give CISOs plenty to worry aboutAI is letting cybercriminals reach deeper into organizations than a phishing email ever could. 41% of CISOs reported at least one social engineering incident involving a deepfake during an employee audio call in the past 12 months, according to Gartner. 36% reported the same for …HELPNETSECURITY.COM
22 SepNorth Korean Attackers Hit 30,000 Devices and Steal $10.7mWaterPlum compromised 30,000 devices and took funds or credentials from 7000 crypto walletsINFOSECURITY-MAGAZINE.COM
22 SepTwo arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminalsAvailable on Telegram for a $1,500 initiation fee and a recurring monthly $500 subscription, EvilTokens provided cybercriminals with artificial intelligence tools enabling them to compromise accounts, analyze breached inboxes and find the best methods for monetizing their access …THERECORD.MEDIA
22 SepEvilTokens PhaaS disrupted after compromising 12,000 Microsoft accountsThe EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft's Digital Crimes Unit (DCU). [...]BLEEPINGCOMPUTER.COM
22 SepAmid Ongoing Rogue Incidents, Debate Over AI Safety Gets RealAs more reports of misalignment incidents underscore AI risks, large AI labs, regular businesses, and even nations are searching for better ways to keep control and be secure.DARKREADING.COM
22 SepHacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ dataThe theft of agents' personal information could present a major counterintelligence threat, where agents and their families are extorted into cooperating with a foreign government.TECHCRUNCH.COM
22 SepSweden fines Miljödata $183,000 over breach affecting 2.2 millionSweden's data privacy regulator, IMY, has imposed a $183,000 (SEK 1.8 million) fine on IT systems provider Miljödata for inadequate security measures leading to a breach in August 2025 affecting 2.2 million people. [...]BLEEPINGCOMPUTER.COM
21 SepRisky Bulletin: Gemini finally did some crimesGoogle’s Gemini hacked three companies, hackers claim a breach of Russia’s election commission, OpenAI was behind RubyGems’ May incident, and the Coast Guard and FBI board two ships to investigate cyberattacks.RISKY.BIZ
21 SepRevolut Customers Targeted with New Wave of Phishing AttacksFollowing a major data breach, Revolut customers are being sent convincing phishing messagesINFOSECURITY-MAGAZINE.COM
21 SepGoogle Confirms Gemini AI Breached Three FirmsGoogle is the latest AI giant to confirm that its models escaped a testing environment and hacked real companies. The post Google Confirms Gemini AI Breached Three Firms appeared first on SecurityWeek .SECURITYWEEK.COM
21 SepRevoking the token didn’t kill the backdoorEvery identity-compromise runbook I have written, read or inherited has the same step near the top: revoke the tokens. Reset the password, kill the sessions, invalidate the refresh tokens, then go hunting. It is the right instinct. Against adversary-in-the-middle phishing, where …CSOONLINE.COM
21 SepGroup Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPOKaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managing Group Policy Objects.SECURELIST.COM
21 SepExperts Alarmed Over Gyazo’s Breach of 490 Million Metadata RecordsA breach at image-sharing service Gyazo on September 11 affected over 23 million customersINFOSECURITY-MAGAZINE.COM
21 SepShinyHunters hacks rival extortion gang and takes over its dark web siteHackers hacked the hackers as a feud between two cybercrime groups escalated, leaving ShinyHunters with the upper hand over rival Clop.MALWAREBYTES.COM
21 SepUS and China Discuss Alerting Each Other to AI National Security ThreatsOfficials discussed setting up a mechanism for the two countries to notify each other of AI incidents which could threaten national security.WIRED.COM
21 SepFrom Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed PoliciesWe explore how AWS neutralizes exposed IAM credentials using managed policies, detailing GitHub secret scanning and CloudTrail monitoring strategies. The post From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies appeared first on Uni…UNIT42.PALOALTONETWORKS.COM
21 SepColorado Water Utilities Hit by Cyberattacks Targeting OT SystemsThe hackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles, officials said. The post Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems appeared first on SecurityWeek .SECURITYWEEK.COM
21 SepA BYD Shark 6 Hack Shows the Risks of Connected CarsA BYD Shark 6 was remotely hacked, exposing vehicle controls, location tracking and cabin audio, raising serious connected-car security concerns. A journalist drove a BYD Shark 6 down a country road outside Canberra while a hacker sitting on the shoulder killed the headlights wit…SECURITYAFFAIRS.COM
21 SepGoogle says Gemini breached three companies during security testGoogle’s artificial intelligence model Gemini accessed computer systems belonging to three real companies without authorization during a cybersecurity test in May — the latest in a string of similar incidents.THERECORD.MEDIA
21 SepShinyHunters Claim Hack of Rival Ransomware Gang ClopShinyHunters has claimed responsibility for hacking the Clop ransomware group, defacing its leak site and alleging theft of key operational dataINFOSECURITY-MAGAZINE.COM
21 SepAttackers Abuse npm Trusted Publishing in GHAPPIER CampaignCloudSEK linked GHAPPIER to a compromised npm package with valid trusted-publishing provenanceINFOSECURITY-MAGAZINE.COM
21 SepBurger King Russia - 3,155,792 breached accountsIn October 2024, news of a data breach exposing Burger King Russia customers broke following an August attack on the Mindbox marketing automation platform. The breach exposed 3.2M unique email addresses along with names, genders, dates of birth, phone numbers and approximate geol…HAVEIBEENPWNED.COM
21 SepGemini’s breach of real companies exposes an AI guardrail problemGemini crossed the boundaries of a capture-the-flag test and accessed systems belonging to three real companies.MALWAREBYTES.COM
21 SepCyberattack hits University of Munich, potentially exposing student financial dataThe university, commonly known as LMU Munich, said Saturday that an attacker accessed enrollment data stored on one of its IT systems.THERECORD.MEDIA
21 SepShinyHunters cybercrime gang takes over Cl0p ransomware site, demands extortion paymentThe ShinyHunters extortion group hijacked the dark web leak site of the prolific Cl0p ransomware gang, according to material posted on the site over the weekend.THERECORD.MEDIA
21 SepBelgian table tennis, gymnastics federations hit by cyberattacksBelgium’s national table tennis federation is investigating a cyberattack after a hacker claimed to have stolen data on tens of thousands of members.THERECORD.MEDIA
21 SepGoogle AI models broke out of sandbox, hacked three companiesThe incidents stemmed from the same testing environment defects that tripped up OpenAI, Anthropic and Meta.CYBERSECURITYDIVE.COM
21 SepGoogle Hit With $463 Million Fine for EU Location Data Rule BreachGoogle has been fined 403 million euros ($463 million) for breaching the European Union’s strict privacy rules because it mishandled users’ location data. The post Google Hit With $463 Million Fine for EU Location Data Rule Breach appeared first on SecurityWeek .SECURITYWEEK.COM
21 SepShinyHunters Hacked Clop. Now What About Clop's Victims?ShinyHunters defaced Clop's Dark Web site and claims to have stolen victim data, potentially exposing organizations that paid ransoms to renewed extortion attempts.DARKREADING.COM
20 SepCyberWire Daily at 10: Critical infrastructure attacks over the last 10 years.In this Special Edition episode, Maria Varmazis and Dave Bittner from N2K Cyberwire get back together to reflect on the past decade of critical infrastructure attacks, evolving threats, and lessons learned from incidents like the Ukraine power grid attack and Colonial Pipe…THECYBERWIRE.COM
19 SepIdentity Visibility in 2026: The Foundation of Identity SecurityIdentity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon's annual Data Breach Investigations Report. This article explains what …THEHACKERNEWS.COM
19 SepCrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub RepositoriesAn attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18. The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May's&…THEHACKERNEWS.COM
19 SepAll about that proxy.Today we are joined by Dr. Renée Burton, VP of Threat Intelligence at Infoblox, discussing their work on Lurking Lizard, "Fake Installers, Fake Reviews, Fake Services – Real Proxies, Real." The research uncovers Lurking Lizard, a threat actor that has operated since at least …THECYBERWIRE.COM
19 SepAnthropic CEO joins calls for slower pacing of AI development.OpenAI discloses six new "concerning" AI incidents. US authorities investigate cyberattacks against oil tankers.THECYBERWIRE.COM
19 SepGoogle Gemini hacked three firms after test sandbox exposed web accessGoogle’s Gemini AI model accessed the internet and breached systems belonging to three real companies during a cybersecurity evaluation in May, marking the first publicly reported instance of a Google AI model autonomously carrying out such intrusions. The incidents occurred duri…CYBERINSIDER.COM
19 SepShinyHunters hacks Clop leak site, threatens to extort ransomware gangThe ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. [...]BLEEPINGCOMPUTER.COM
19 SepGoogle Gemini also Broke Out of Its Test EnvironmentGoogle Gemini escaped a cyber test environment, reached three real companies, and exposed why AI security tests need strict isolation. Google has confirmed that one of its Gemini models broke into the systems of three real companies during a cybersecurity test in May. The inciden…SECURITYAFFAIRS.COM
18 SepRatHat Android Malware Abuses ADB to Retain Shell Access After UninstallCybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. "Distributed primarily via targeted smis…THEHACKERNEWS.COM
18 SepAI Agent Breaches Spanish Organization, Modifies Personal DataAI-driven cyberattacks used to be exotic. Soon, it'll be odd if threat actors aren't using agents to do all of their bidding.DARKREADING.COM
18 SepManufacturing Accounts for 22% of all Ransomware VictimsBlack Kite has found that manufacturing remained the most targeted sector for ransomware attacks, and saw a big jump in incidents in H1 2026INFOSECURITY-MAGAZINE.COM
18 SepBrevo Supply Chain Attack Injects Malware Into 100,000 WebsitesHackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts. The post Brevo Supply Chain Attack Injects Malware Into 100,000 Websites appeared first on SecurityWeek .SECURITYWEEK.COM
18 SepA Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and IdentityAnalysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents. The post A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
18 SepAre AIs Still Struggling with CAPTCHAs?Anthropic’s recent security-incident document contains a bit about how CAPTCHAs are still frustrating Claude. In the transcript, the Claude model that is so powerful that Anthropic is gatekeeping access to it appeared to slam its virtual head against the wall solving a simp…SCHNEIER.COM
18 SepHacking group ‘NightEagle’ targeting China’s high-tech sector expands operations to RussiaOver the past year, Russian cybersecurity firm Kaspersky said it investigated several incidents involving the group at Russian businesses.THERECORD.MEDIA
18 SepNew Settra Ransomware Variant Deployed in Attacks on Retail and ManufacturingHuntress researchers highlighted a new ransomware variant, named Settra, and the post-compromise techniques used in two recent attacksINFOSECURITY-MAGAZINE.COM
18 SepFBI, Coast Guard boarded hacked oil tankers heading towards US coastThe feds are said to be investigating the compromise of the tankers' networks, which in one case interfered with one of the tanker's navigation and propulsion systems.TECHCRUNCH.COM
18 SepSettra ransomware variant deployed in recent attacksSecurity researchers warned that hackers are using VPN credentials for initial access and deploying RMM tools.CYBERSECURITYDIVE.COM
18 SepAn Undercover Google Analyst Infiltrated a Notorious Supply Chain Hacking GangTeamPCP pulled off the worst-ever software supply chain hacking spree and breached thousands of companies. Now Google’s threat intelligence group says it had a mole inside the hackers’ inner circle.WIRED.COM
17 SepAI Agent Carries Out Multi-Stage Data Theft AttackSpanish data protection agency AEPD reveals the country’s first AI-powered data breachINFOSECURITY-MAGAZINE.COM
17 SepSpain reports first data breach involving autonomous AI agentSpain’s data protection authority (AEPD) has reported its first data breach blamed on an AI agent acting on its own, after the system reportedly logged into a company’s network, found a way to alter personal records, and pulled invoice data. “Before drawing any conclu…HELPNETSECURITY.COM
17 SepRansomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI useRansomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims.TALOSINTELLIGENCE.COM
17 SepAmerica’s cyber strategy overlooks the infrastructure that actually keeps the military movingPorts, railroads, and utilities keep the military operational. They're all vulnerable to Iranian cyberattacks. The post America’s cyber strategy overlooks the infrastructure that actually keeps the military moving appeared first on CyberScoop .CYBERSCOOP.COM
17 SepThe Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrentsKaspersky experts have discovered a new MovieReaper campaign. The multi-stage Trojan spreads through movie torrents, such as "The Odyssey," and uses the Solana blockchain to hide its C2 infrastructure.SECURELIST.COM
17 SepDruva expands identity resilience with ransomware detectionDruva has announced new capabilities for Druva Identity Resilience alongside the launch of Ransomware Detection, a new feature fueled by a proprietary AI threat pipeline. Powered by Dru MetaGraph, the new offerings use behavioral intelligence and built-in validation to turn suspi…HELPNETSECURITY.COM
17 SepHackers claim breach of Russian election systems days before parliamentary voteAn anonymous hacking group claimed to have broken into computer systems connected to Russia’s election infrastructure just days before the country begins voting for a new parliament.THERECORD.MEDIA
17 SepRevolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M RansomRevolut allegedly fed customer information to hackers impersonating an Italian government agency for five months. The post Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom appeared first on SecurityWeek .SECURITYWEEK.COM
17 SepRevolut phishing texts appear days after data breachRevolut customers received phishing texts only days after the digital bank acknowledged disclosing customer data to a government impostor.MALWAREBYTES.COM
17 SepUS Coast Guard and FBI board oil tanker to investigate cyber attackAn oil tanker bound for Texas was boarded mid-voyage by the US Coast Guard and FBI last month, after its network may have been compromised by malicious hackers. According to the US Coast Guard, the supertanker was boarded after indications that the network "may have been compromi…BITDEFENDER.COM
17 SepFBI, Coast Guard probe suspected cyberattacks on ships entering US watersThe investigation comes at a time of heightened vigilance over U.S. port facilities and maritime security.CYBERSECURITYDIVE.COM
17 SepCyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board VesselsThe Coast Guard confirmed evidence of malicious cyber activity on the VL Prosperity, but has not attributed the attack to Iran. The post Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels appeared first on SecurityWeek .SECURITYWEEK.COM
17 SepCyberattacks on Oil Tankers Put Maritime Critical Infrastructure at RiskCyberattacks on oil tankers show how connected ships can expose navigation and critical systems, threatening safety, ports and global trade. U.S. Coast Guard personnel and FBI agents boarded two Texas‑bound energy tankers last month after cyberattacks hit the vessels while they w…SECURITYAFFAIRS.COM
17 SepNew RatHat Android malware uses AI to automate device controlA new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. [...]BLEEPINGCOMPUTER.COM
16 SepThree Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and WipersEnterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a thr…THEHACKERNEWS.COM
16 SepN0va Phishkit Targets US and EU Businesses: A New Challenge for Identity SecurityN0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity. Fro…THEHACKERNEWS.COM
16 SepHackers publish thousands of drivers’ data after breaching Florida motor vehicle databaseThe ShinyHunters gang leaked the files online after saying the Florida state agency did not pay their ransom demand.TECHCRUNCH.COM
16 SepUS authorities investigate cyberattacks against oil tankersPhantomRaven infostealer targets bug bounty opportunities. Business news: Physical AI security firm Exein lands $270 million.THECYBERWIRE.COM
16 SepInternational Meteor Organization says cyberattack dealt ‘critical blow’ to websiteA website used around the world for reporting meteors faces weeks of downtime as the organization moves away from systems that were hacked recently.THERECORD.MEDIA
16 SepEU chief wants joint response to cyberattacks, sabotageDelivering her annual State of the Union address in Strasbourg, Ursula von der Leyen said threats were “mounting on our soil,” pointing to recent incidents in Denmark, Lithuania and Poland and an attempted drone attack in Leipzig.THERECORD.MEDIA
16 SepCoast Guard, FBI board US-bound foreign ships in order to probe for cyberattacksThe agencies issued a joint statement saying the “joint security boardings” came in response to “indications that the networks of both vessels were compromised.” The post Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks appeared first on CyberScoop…CYBERSCOOP.COM
16 SepCyber-Attacks Cost Organizations $52,000 on AverageHiscox highlighted the huge financial and operational costs of cyber-attacks, with the average cost of an incident at $52,000INFOSECURITY-MAGAZINE.COM
16 SepRevolut hackers used infostealer to hijack Italian government emailsAttackers behind the recent Revolut data exposure allegedly used compromised Italian government email accounts for months to submit fraudulent customer information requests, according to new findings from Duel and Hudson Rock. The hackers are also reportedly demanding 10,000 Bitc…CYBERINSIDER.COM
16 SepSpain's data agency gets first report of AI-powered data breachThe Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). [...]BLEEPINGCOMPUTER.COM
16 SepThe true cost of a ransomware attack, with and without BCDRThe ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to…BLEEPINGCOMPUTER.COM
16 SepWebinar: What happens in the first hours of a Google Workspace breachThe first hours after discovering a Google Workspace breach can determine how an incident unfolds. This webinar examines real-world breaches to show which early response decisions can limit the impact and which can make matters worse. [...]BLEEPINGCOMPUTER.COM
16 Sep280,000 Impacted by Premier Medical Group Data BreachIn June 2026, hackers accessed files containing patients’ names, contact information, diagnosis details, and health insurance information. The post 280,000 Impacted by Premier Medical Group Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
16 SepBragJack Attack Can Turn a Browser's Agentic AI Against ItA new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data.DARKREADING.COM
16 SepRubrik MCP gives AI agents controlled access to security intelligenceRubrik has announced Rubrik MCP (Model Context Protocol), giving an organization’s AI agents a secure, programmable path to Rubrik’s data, identity, and application intelligence. Support for MCP expands Rubrik AI, which is now trusted by one-third of its global customers, and uni…HELPNETSECURITY.COM
16 SepCitrix adds AI-powered browser activity analysis to SecurAccessCitrix has announced Citrix Session Insights, a new AI-powered capability for Citrix SecurAccess with Chrome Enterprise that helps organizations capture, analyze and understand browser activity from users and autonomous agents. By combining visual session evidence, AI-powered ris…HELPNETSECURITY.COM
16 SepTexas Utility CenterPoint Energy Confirms Data Breach After Hacker Claims 7.49M Records StolenCenterPoint Energy confirmed a customer data breach after a hacker claimed to leak 7.49M records, including personal and billing information. CenterPoint Energy admitted on Monday that an intruder stole personal information belonging to some of its customers. The Houston-based ut…SECURITYAFFAIRS.COM
16 SepCoast Guard, FBI boarded tanker after attack by ‘foreign cyber actors’U.S. personnel boarded an oil tanker in the Gulf of Mexico to “ensure integrity of the vessel’s operational and information technology systems," after an apparent cyberattack, the U.S. Coast Guard said.THERECORD.MEDIA
16 SepSmashing Security podcast #485: These researchers got drunk to hack an LG TVResearchers wanted to test if LG's smart TVs come with any security risks - but their lawyers noticed a snag: the terms and conditions would forbid it. So they came up with a solution. They got plastered before setting up the TV, on the reasoning that you can't be legally bound t…GRAHAMCLULEY.COM
15 SepHacked HBO Max Reddit Account Used for Malware Delivery via ClickFix AttackAds led to a ClickFix page designed to trick macOS and Windows users into installing malware. The post Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack appeared first on SecurityWeek .SECURITYWEEK.COM
15 SepHBO Max Reddit account hijacked in PasteSwitch malware campaignA compromised verified HBO Max Reddit account was used to distribute more than 100 malicious advertisements as part of a large cross-platform ClickFix campaign targeting both Windows and macOS users. Researchers at Hudson Rock and Kirk from ADAMnetworks traced the incident to a b…CYBERINSIDER.COM
15 SepCenterPoint Energy confirms data breach after hacker claims 7.49M recordsCenterPoint Energy has confirmed that an unauthorized third party obtained personal information belonging to some of its customers through an external-facing system. The disclosure follows an online post in which a threat actor claimed to have stolen and released information on a…CYBERINSIDER.COM
15 SepPresident Trump pushes back against calls for an AI slowdown.Microsoft lays out safety code of conduct for its own models. Japanese government discloses data breach.THECYBERWIRE.COM
15 SepMost Firms Unable to Recover Quickly from RansomwareFenix24 found only four of more than 800 clients came close to stated ransomware recovery targets of 24-48 hoursINFOSECURITY-MAGAZINE.COM
15 SepMalcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sitesMalicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]BLEEPINGCOMPUTER.COM
14 SepWhat we know about the Revolut data breach so farSomeone impersonating a government agency, using an email address on that agency’s domain, obtained sensitive customer records from Revolut. The bank confirmed the incident on Saturday, September 12. The London-based fintech told TechCrunch that a limited number of customer…HELPNETSECURITY.COM
14 SepTelus Warns Customers of Account BreachesStolen credentials were used in a multi-month campaign to access subscriber personal data and billing records. The post Telus Warns Customers of Account Breaches appeared first on SecurityWeek .SECURITYWEEK.COM
14 SepRevolut Confirms Data Breach Through Fake Government RequestsAn unauthorized party used a legitimate government email domain to fraudulently request Revolut customer dataINFOSECURITY-MAGAZINE.COM
14 SepWebinar: How malicious OAuth apps can lead to Google Workspace breachesAttackers can combine social engineering with malicious OAuth applications to gain access to Google Workspace data without relying solely on stolen passwords. This webinar examines two attacks to show how these breaches unfold and which security controls can help stop them. [...]BLEEPINGCOMPUTER.COM
14 SepBitsight connects threat intelligence and exposure monitoring across the supply chainBitsight access to a broad risk dataset, combining threat intelligence and continuous exposure monitoring to help teams mitigate risk across the supply chain. “The surge in third-party-originating cybersecurity breaches demands a fundamental shift in how cybersecurity leade…HELPNETSECURITY.COM
14 SepHackers hijack HBO Max Reddit account to push malware in ClickFix adsHackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. [...]BLEEPINGCOMPUTER.COM
14 SepTelegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML ExportsA flaw in Telegram Desktop let a bot's message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said in a writeup published on September 12. In Telegram, the message looked ordinary, with a link button, and the scri…THEHACKERNEWS.COM
14 SepJapan's Digital Agency says VPN flaw exposed 246,000 personnel recordsJapan's Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. [...]BLEEPINGCOMPUTER.COM
13 SepConti Hacker Who Built Malware and Attacked Victims Gets Four-Year SentenceUkrainian lawyer and Conti malware developer Oleksii Lytvynenko was sentenced to four years in U.S. prison for ransomware attacks. Oleksii Oleksiyovych Lytvynenko had, by most accounts, a fairly ordinary legal career in Ukraine before he switched to writing malware. A US federal …SECURITYAFFAIRS.COM
12 SepA beast by any other name.Today we are joined by Brigid O Gorman, Senior Intelligence Analyst on Symantec Threat Hunter team, discussing their work on “GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses." GodDamn ransomware, the latest rebrand from the Hyadina group beh…THECYBERWIRE.COM
12 SepFrom Hacks to Bioweapons, Claude Misuse Is Now EverywherePlus: The US disrupts the internet’s biggest black market, a Conti ransomware hacker gets prison time, Meta fails to stop AI-generated videos of child abuse.WIRED.COM
11 SepTrezor: 347,000 users targeted in phishing attacks after Brevo breachTrezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. [...]BLEEPINGCOMPUTER.COM
11 SepConti ransomware gang member sentenced to 4 years in prisonA Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. [...]BLEEPINGCOMPUTER.COM
11 SepUkrainian Conti Ransomware Developer Sentenced to 4 Years in US PrisonOleksii Oleksiyovych Lytvynenko has been sentenced to 4 years in prison after he was arrested in Ireland in 2023. The post Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison appeared first on SecurityWeek .SECURITYWEEK.COM
11 SepIDScan confirms breach after 153 million driver’s licenses leak on dark webDays after reports linked IDScan to a dark web database holding more than 153 million driver’s license scans, the identity verification company has confirmed hackers accessed customer data stored on its cloud platform. The Louisiana-based firm, which processes ID checks for…HELPNETSECURITY.COM
11 SepBuilding a ransomware decision tree before the call comes inIn this Help Net Security video, Kerri Shafer-Page, VP of Incident Response at Arctic Wolf, walks through the ransomware decision tree in this video. She covers four areas where decisions need settling in advance, starting with containment. Someone has to know the network well en…HELPNETSECURITY.COM
11 SepUkrainian hacker gets four years in US prison over Conti ransomware attacksA Ukrainian national was sentenced to four years in a U.S. prison for his role in the notorious Conti ransomware operation, which targeted more than 1,000 victims worldwide before shutting down in 2022.THERECORD.MEDIA
11 SepTrezor Says 347,000 Users Received Phishing Emails After Brevo HackHackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking. The post Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack appeared first on SecurityWeek .SECURITYWEEK.COM
11 SepScammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email providerThis is the second data breach affecting a company that hardware crypto wallet maker Trezor relies on.TECHCRUNCH.COM
11 SepCrypto customers targeted by scammers after email marketing provider breachA breach at email marketing company Brevo exposed Trezor, CoinTracking, and BitBox customers to phishing emails, but others may also be at risk.MALWAREBYTES.COM
11 SepPapercut AI Swarm Attack Heralds Changes for Cyber Kill ChainFrom creating lab environments for staging and testing agentic attacks to reconnaissance to lateral movement and exfiltration, the most innovative attackers are widely incorporating AI.DARKREADING.COM
11 SepFlorida confirms DMV database breached via stolen police accountThe Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. [...]BLEEPINGCOMPUTER.COM
11 SepFlorida says motor vehicle data breach tied to credentials stolen from officer’s personal deviceThe Florida Department of Motor Vehicles confirmed a data breach claimed by the cybercrime group ShinyHunters, saying it originated with the theft of credentials stored on a police officer's personal device.THERECORD.MEDIA
10 SepSrsly Risky Biz: America's drivers licence breach is a national security disasterTom Uren and James Wilson talk about how Chinese intelligence services will take advantage of a massive breach of 150 million American drivers licences. They also discuss the steps the US military is taking to counter adtech device tracking. It’s too slow and not enough. Finally,…RISKY.BIZ
10 SepTrezor warns users of email provider breach, phishing attacksTrezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks. [...]BLEEPINGCOMPUTER.COM
10 SepAnthropic Reveals Yet Another Cybersecurity IncidentAnthropic has found a fourth case of its model accessing third-party systems without authorizationINFOSECURITY-MAGAZINE.COM
10 SepThe longitude problem: In the AI era, detection is won on facts, not guessesFor most of the age of sail, a captain could find his latitude in minutes and could not find his longitude at all. Latitude you could read off the sun. Longitude, your position east to west, offered no such trick. Three weeks into the Atlantic, a navigator knew how far north he w…CSOONLINE.COM
10 SepSporting goods chain Hibbett discloses employee data breachHibbett Retail, Inc. is notifying employees that an unknown third party gained unauthorized access to its systems and may have acquired files containing personnel records during an April 2026 security incident. The company said in a breach notification dated September 8, 2026, th…CYBERINSIDER.COM
10 SepA New Claude ‘s Sandbox Failure Shows How AI Can Rationalize Real-World HarmClaude models compromised real systems during misconfigured security tests, exposing a worrying mix of flawed reasoning, harmful actions and weak safeguards. Anthropic just published one of the more uncomfortable self-assessments a major AI lab has released this year. The company…SECURITYAFFAIRS.COM
10 SepWidened Scan Turns Up Fourth Rogue Claude Cyber IncidentAnthropic is most concerned about Claude Mythos 5’s reckless behavior after recent incidents in which real systems were hacked. The post Widened Scan Turns Up Fourth Rogue Claude Cyber Incident appeared first on SecurityWeek .SECURITYWEEK.COM
10 Sep4.1 Million Impacted by AdaptHealth Data BreachIn June 2026, hackers stole personal, health, and insurance information from AdaptHealth’s systems. The post 4.1 Million Impacted by AdaptHealth Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
10 SepMantaxOtax Android Malware Combines Ransomware With SpywareMantaxOtax Android malware combines ransomware with extensive spyware capabilitiesINFOSECURITY-MAGAZINE.COM
10 SepID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolenThe ID checking company said the data breach included people's full names and driver's licenses and other government-issued identity documents.TECHCRUNCH.COM
10 SepIDScan confirms breach tied to 153 million stolen driver’s licensesIdentity verification company IDScan has confirmed that hackers accessed customer data stored in its cloud platform, days after reports linked the company to a massive database containing more than 153 million driver's license scans. [...]BLEEPINGCOMPUTER.COM
10 SepFollow the Money: The Financial Sector's Threat Landscape in 2026The financial sector moves trillions of dollars a day, making it one of the most heavily targeted industries in the world. Intel 471's latest report breaks down the threat landscape facing financial institutions, from ransomware and extortion groups to initial access brokers, nat…INTEL471.COM
10 SepThreat groups enhance cyberattack capabilities with AIA report shows state-linked and criminal hackers are incorporating automation and agentic technology to find new victims and bypass traditional defenses.CYBERSECURITYDIVE.COM
10 SepIDScan confirms breach after hackers offer 153 million driver’s license scans for saleA notice dated September 4 but not widely shared shows that IDScan acknowledged a data breach but did not specify how many people were affected.THERECORD.MEDIA
10 SepUS and China prepare for mid-September AI safety talks.OpenAI had another major unauthorized breach.THECYBERWIRE.COM
10 SepConti ransomware crew member sentenced to four years in prisonOleksii Lytvynenko joined the notorious group in 2021 and was directly involved in attacks on at least 12 companies. The post Conti ransomware crew member sentenced to four years in prison appeared first on CyberScoop .CYBERSCOOP.COM
10 SepHawley probes OpenAI over Hugging Face breachThe Republican lawmaker called OpenAI’s leadership decisions “reckless,” and used recent warnings about the existential risk of AI to bolster his inquiry. The post Hawley probes OpenAI over Hugging Face breach appeared first on CyberScoop .CYBERSCOOP.COM
10 SepIDScan confirms breach linked to massive driver’s license leakIDScan.net has confirmed that hackers accessed customer data stored in its cloud, including names and driver’s license or other government-issued identification numbers. The disclosure follows reports linking the identity verification provider to a massive cache of over 153 milli…CYBERINSIDER.COM
10 SepNew Android malware encrypts files, steals data, and harasses victimsA new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. [...]BLEEPINGCOMPUTER.COM
9 SepThe Other Side of the PR Pitch with Pulitzer Prize Winner Yael GrauerYael Grauer won a Pulitzer and got laid off in the same year. She is a freelance investigative reporter covering cybersecurity, privacy, and surveillance. She sat down with Gianna to talk about what companies get wrong when journalists come knocking, why lying in that moment make…THECYBERWIRE.COM
9 SepWhat breach and attack simulation needs to become in the AI eraBreach and attack simulation (BAS) has always had a supply chain. Somebody has to read the threat report, pull out the techniques, and turn them into something that will actually run against your controls. That somebody has always been a human red team. Up until a few months ago,…HELPNETSECURITY.COM
9 SepRisky Business #852 -- Cyber Command wants to buy shellsOn this week’s show Patrick Gray and James Wilson are joined by guest co-host Robby Winchester from SpecterOps to talk through the week’s news, including: ID verification company IDScan was breached and 153m driver licenses wound up for sale online. Cue the barrage of lawsuits Th…RISKY.BIZ
9 SepRisky Bulletin: Ukraine's top prosecutor resigns amid scam call center scandalUkraine’s top prosecutor resigns amid a scam call center scandal, the US accuses Chinese AI companies of industrial-scale distillation, a cyberattack hits medical practices in Luxembourg, and the Liquid Network attacker returns some stolen Bitcoin, but keeps a $50 million bounty.RISKY.BIZ
9 SepWhy Threat Actors Love Your RMMIn this episode of the Microsoft Threat Intelligence Podcast, recorded live at Black Hat, Microsoft Threat Intelligence Director Elliot Volkman is joined by Andrew “Spike” Grant, Principal Threat Intelligence Incident Commander at Huntress. They explore how cybercriminals are inc…THECYBERWIRE.COM
9 SepCRPx0 ransomware: what you need to knowCRPx0 is a cybercrime operation that started off operating a scam before pivoting into a fully-blown ransomware and cryptocurrency business. Read more in my article on the Fortra blog.FORTRA.COM
9 SepInfostealer Logs Expose Replayable AI Tokens That Can Bypass MFACybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equi…THEHACKERNEWS.COM
9 SepFBI cyber chief worries private sector not sharing enough cyber threat informationBrett Leatherman said that industry has the wrong idea about what the FBI does with the data it collects during incidents, which is used to help victims and investigations alike. The post FBI cyber chief worries private sector not sharing enough cyber threat information appeared …CYBERSCOOP.COM
9 SepElectronic health record company says customer data stolen in breachVeradigm said access was limited to a specific interface, and did not impact the company’s broader environment such as its networks, servers or databases. The incident did not result in operational disruptions, the company added.THERECORD.MEDIA
9 SepAdaptHealth confirms 4.1 million people exposed in July cyberattackHealthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group. [...]BLEEPINGCOMPUTER.COM
9 SepSmashing Security podcast #484: How websites are tracking you with silenceWhen a chap called Matt noticed his Bluetooth headphones wouldn't switch to his phone, he was surprised to realise the reason was a single AliExpress webpage sitting open in his browser - playing nothing at all, at zero volume. And yet somehow his hardware could hear it. Audio fi…GRAHAMCLULEY.COM
8 SepRansomware negotiation tactics have turned into a business processIn this Help Net Security video, Dave Ross, Senior Director of the Intelligence Fusion Team at Intel 471, explains what happens behind the scenes during ransomware negotiations. Ross walks through the tactics groups use once an attack begins, from research on a victim’s rev…HELPNETSECURITY.COM
8 Sep220 million traveler records exposed in Vietnam-linked APIS leakExclusive: An exposed Advance Passenger Information System (APIS) database held 220 million passenger and crew records containing names, passport numbers, dates of birth, nationalities, and flight details spanning 2017 to 2026. Researchers accessed the Vietnam-linked system throu…BLEEPINGCOMPUTER.COM
8 SepTrezor Supply Chain Breach Now Impacts 81,000 CustomersCrypto wallet-maker Trezor says a data breach at supplier ShipMonk is far worse than originally thoughtINFOSECURITY-MAGAZINE.COM
8 SepMathspace Data Breach Exposes Over 1 Million PeopleHackers stole the information of students, teachers, staff, and parents/guardians from a self-hosted Metabase instance. The post Mathspace Data Breach Exposes Over 1 Million People appeared first on SecurityWeek .SECURITYWEEK.COM
8 SepTrezor customers hit with phishing calls and letters after shipping-partner breachRoughly 67,000 more customers of SatoshiLabs, the maker of hardware crypto-wallet Trezor, are at heightened risk of phishing attacks after their names, email addresses, phone numbers, and shipping addresses were exposed. “The leaked information could be used for scam emails…HELPNETSECURITY.COM
8 SepFrench prosecutors confirm arrest of suspected ZeroBytes hacker behind tax cyberattackFrench authorities detained an 18-year-old suspected member of the ZeroBytes hacking group over cyberattacks against the country's tax authority and other organizations.THERECORD.MEDIA
8 SepCyberattack encrypts systems at Bavarian municipal utilityA municipal utility in Bavaria is recovering from a cyberattack that encrypted its internal IT systems but did not affect water and electricity services.THERECORD.MEDIA
8 SepShinyHunters claims breach of Florida DMV, threatens data leakThe ShinyHunters cybercrime group claims it compromised systems containing driver and vehicle records and is threatening to release stolen data on September 11. As purported evidence, the group posted a screenshot showing what appears to be a record from DAVID, Florida’s Driver a…CYBERINSIDER.COM
8 SepWebinar: The forgotten Google Workspace access that can lead to a breachThird-party applications connected to Google Workspace can retain access long after their original purpose is forgotten. This webinar examines how overly permissive integrations contribute to breaches and which security controls can help fast-growing companies reduce their exposu…BLEEPINGCOMPUTER.COM
8 SepShinyHunters hackers claim breach of Florida "DAVID" DMV databaseThe ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state. [...]BLEEPINGCOMPUTER.COM
8 SepOpenAI says ChatGPT outage causes image generation errorsOpenAI is investigating an ongoing incident causing ChatGPT image generation failures and delays when uploading files. [...]BLEEPINGCOMPUTER.COM
8 SepAIs as Modern GeniesThis essay was written with Barath Raghavan, and originally appeared in Lawfare . In April, an artificial intelligence (AI) agent conducting a routine task at a company hit a snag, tried to solve it, and soon ended up deleting the company’s database along with all of its backups.…SCHNEIER.COM
8 SepOpenAI Agents Took Over Wiki Site Before Hugging Face AttackResearchers and OpenAI disagree on whether the earlier incident involving DseWiki was a “hack” that the company did not disclose.DARKREADING.COM
7 SepRisky Bulletin: BEC campaign steals €35 million from French notariesHackers steal €35 million euros from French notaries, OpenAI agents hacked a German wiki, a new bill will allow the Pentagon to use cyber contractors, and the Five Eyes members tell hacked companies to drop PR spin.RISKY.BIZ
7 SepMultiple Class Action Lawsuits Filed Against IDScanSeveral victims of a recent breach of driver’s license information have sued the company they believe responsibleINFOSECURITY-MAGAZINE.COM
7 SepRhysida Publishes Berlin Government Data After €2m Extortion Demand RefusedThe ransomware group’s published dataset reportedly includes Berlin state employee data, as well as highly sensitive emergency plansINFOSECURITY-MAGAZINE.COM
7 SepOpenAI Agents Hijack Another Victim WebsiteOpenAI agents made 15,000–18,000 autonomous edits to a German wiki over three months, evading moderation and echoing tactics seen in the Hugging Face breach. The post OpenAI Agents Hijack Another Victim Website appeared first on SecurityWeek .SECURITYWEEK.COM
7 SepTrezor data breach impact now reaches 81,000 customersCryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers. [...]BLEEPINGCOMPUTER.COM
6 SepWeekly Update 520: The Unscripted EditionPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite I've started playing around with YouTube's "create video thumbnail", which hopefully will give me back a bit of tim…TROYHUNT.COM
5 SepOpenAI Agents Hacked Another WebsitePlus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.WIRED.COM
5 SepOpenAI admits it didn't disclose rogue AI wiki hijacking incidentOpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]BLEEPINGCOMPUTER.COM
5 SepOver 5,400 hacked sites serve ClickFix payloads stored on the blockchainA massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]BLEEPINGCOMPUTER.COM
5 SepOpenAI confirms ‘wiki incident,’ says it’s ‘working on a framework’ for more disclosureOpenAI acknowledged its role in a recently reported incident where AI agents took over a German wiki forum.TECHCRUNCH.COM
4 SepYour Linux System Can Lie To YouOn a compromised Linux or Unix system, an attacker may manipulate the tools and mechanisms investigators rely on. A command such as ps could potentially return altered information through modified binaries, hooked system calls, libraries, or kernel-level tampering. If the utiliti…YOUTUBE.COM
4 SepDark Web Service Nexus Sells 153M+ Driver’s LicensesFBI probes suspected breach at IDScan.net after dark web service Nexus offered 153M+ US and Canadian driver’s license scans. A dark web identity theft service called Nexus appeared on September 1, 2026, offering searchable access to more than 153 million scanned driver̵…SECURITYAFFAIRS.COM
4 SepIDScan sued over alleged data breach affecting 153 million driversMultiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver's licenses. [...]BLEEPINGCOMPUTER.COM
4 SepIn Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B ValuationNoteworthy stories that might have slipped under the radar: Microsoft rolled out patches for cloud services, hackers compromised 5,000 Dropbox accounts, and Guardio is now valued at $1.1 billion. The post In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’…SECURITYWEEK.COM
4 SepCrooks Behind Manchester Airports Group Hack Leaked Data of 8.8 Million PeopleManchester Airports Group (MAG) data allegedly leaked by FulcrumSec exposes emails and phone numbers of 8.8 million people. Manchester Airports Group, which operates Manchester, London Stansted and East Midlands airports, has confirmed a data breach involving customer information…SECURITYAFFAIRS.COM
3 SepFBI Probes Possible Breach of 153 Million Driver’s LicensesThe FBI is investigating how scans of over 153 million driver’s licenses are being sold on the dark webINFOSECURITY-MAGAZINE.COM
3 SepAttackers Expose Ongoing AI Tool Use Targeting Organizations in Latin AmericaExplore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations. The post Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
3 SepAttackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted AttacksThreat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government…THEHACKERNEWS.COM
3 SepUS and Canadian court data exposed in Thomson Reuters breachSealed court information and sensitive personal data were exposed in a breach of a Thomson Reuters records platform affecting courts in at least 12 U.S. states, the U.S. Virgin Islands and Canada.THERECORD.MEDIA
3 SepYour Employee’s Password Appeared in an Infostealer Log. Now What?Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeove…BLEEPINGCOMPUTER.COM
3 SepAI 'Machine Speed' Cuts 2-Week Attack Down to 10 HoursThe incident demonstrates how frontier AI agents can dramatically compress an attack timeline and coordinate a large-scale breach, according to researchers.DARKREADING.COM
3 SepFishbrain data breach exposes user details and password hashesFishing app Fishbrain is notifying users of a data breach after an unauthorized person accessed an environment containing user data, exposing personal information and account credentials. The company says some compromised password hashes may be vulnerable to cracking and has rese…CYBERINSIDER.COM
3 SepIncident response guide for AWS CloudTrail investigations – Part 2In Part 1 of this guide, we examined two common incident scenarios: cross-account Amazon Simple Storage Service (Amazon S3) data deletion with ransomware implications, and cryptocurrency mining deployed through AWS CloudFormation using exposed AWS Management Console credentials. …AWS.AMAZON.COM
3 SepIncident response guide for AWS CloudTrail investigations – Part 1AWS CloudTrail logs contain the evidence you need when investigating suspicious activity in your AWS environment, but knowing which fields matter and how to interpret them can mean the difference between surface-level analysis and uncovering the full scope of an incident. This gu…AWS.AMAZON.COM
3 SepFrench hospital fined €500,000 after breach exposes data of 727,000France's data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for failing to adequately protect patients' and their relatives' data. [...]BLEEPINGCOMPUTER.COM
3 SepCoder's registry infrastructure compromised to push malicious modulesAttackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code. [...]BLEEPINGCOMPUTER.COM
3 SepWhat We Missed: Did ShinyHunters 'Breach' ReliaQuest?In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the latest antics of ShinyHunters to new research about the prevalence (or lack thereof) of AI-generated malware.DARKREADING.COM
2 SepVali Cyber ZeroLock 5 brings MFA to the hypervisor command lineVali Cyber released ZeroLock 5, a major release focused on closing the two most dangerous gaps in hypervisor security: insider threats and stolen credentials on ESX and Linux hosts. The hypervisor is now the target Over the past two years, ransomware operators and nation-state ac…HELPNETSECURITY.COM
2 SepFulcrumSec Claims Responsibility for Manchester Airport Group BreachThreat group FulcrumSec claims MAG breach and leaks 550GB of data onlineINFOSECURITY-MAGAZINE.COM
2 SepA battery storage cyberattack would look exactly like a badly tuned controllerBatteries connected to the grid make money by reacting to frequency, pushing power out when it sags and soaking it up when it rises. A few hundred of them moving together, on command from someone who should not have the command, would look the same on a control room screen right …HELPNETSECURITY.COM
2 SepDark web site puts 153 million driver’s licenses and millions more IDs up for saleThe FBI is investigating a possible breach of idscan.net linked to 153 million driver’s license scans for sale online.MALWAREBYTES.COM
2 SepNutex Health Says Patient Data Stolen, Hackers Threaten LeakThe US healthcare provider confirmed that sensitive patient and employee data, alongside financial and business information, were exfiltrated by a third partyINFOSECURITY-MAGAZINE.COM
2 SepAn AI-Assisted Cyber Attack: Inside a Unit 42 InvestigationUsing autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks. The post An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
2 SepAnthropic Details Response to Security Incidents, Unveils Enterprise SafeguardsAnthropic introduced Enterprise Frontier Safeguards (EFS), a system that combines zero data retention with automated monitoring for misuse. The post Anthropic Details Response to Security Incidents, Unveils Enterprise Safeguards appeared first on SecurityWeek .SECURITYWEEK.COM
2 SepHow to Secure Enterprise AI: From Adoption to Incident ReadinessThe debate about whether AI delivers business value is over. The challenge now is implementing it at scale and securely across every function while meeting board-level pressure to move fast. Organizations must focus on adopting AI at business speed without losing control of cyber…THEHACKERNEWS.COM
2 SepBGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root AccessVirtualizor said hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic. The hackers then used the diverted update traffic to deliver a malicious Virtualizor package to some installations. A hosting-provider account separately said 5 of its 34 checked V…THEHACKERNEWS.COM
2 SepGambling Goblin Turns Brazilian Government Sites Into SEO WeaponsGambling Goblin compromised Brazilian government sites to drive gambling traffic through SEO fraudINFOSECURITY-MAGAZINE.COM
2 Sep153 million driver’s licenses exposed in suspected IDScan breachThe FBI is investigating an apparent breach involving identity verification provider IDScan after a dark web service began selling access to more than 153 million US and Canadian driver’s license scans, according to an exclusive KrebsOnSecurity report. The marketplace, called Nex…CYBERINSIDER.COM
2 SepMalicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting PagesA Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting onlin…THEHACKERNEWS.COM
2 SepRansomware protection for MSPs: A 6-point checklist for faster recoveryRansomware resilience requires more than backups or endpoint detection alone. Acronis outlines six capabilities MSPs should test across client environments, from reducing exposure and detecting attacks to preserving recovery points and restoring operations quickly. [...]BLEEPINGCOMPUTER.COM
2 SepNew pro-Ukraine hacker group targets Russian companies with custom ransomwareThe group, which calls itself VantaCore, has targeted at least seven known victims, Russian cybersecurity firm F6 said in a report published this week.THERECORD.MEDIA
2 SepHealth data of more than 9.5 million people leaked from Aesto record systemThe healthcare data company Aesto informed federal regulators this week that more than 9.5 million people had sensitive information leaked during a cyberattack last December.THERECORD.MEDIA
2 SepIt sure looks like hackers breached a major ID card verification serviceAn identity theft search site claimed to have more than 150 million driver's license photos stolen from an ID verification service. The crime site has now shut down.TECHCRUNCH.COM
1 SepQuestel - 1,226,209 breached accountsIn August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising c…HAVEIBEENPWNED.COM
1 SepHealthcare Giant McKesson Investigates Data Breach IncidentShinyHunters claims to have stolen 284 million records from McKessonINFOSECURITY-MAGAZINE.COM
1 Sep9.5 Million Impacted by Aesto Health Data BreachHackers stole personal and health information from the healthcare technology company’s AWS infrastructure. The post 9.5 Million Impacted by Aesto Health Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
1 SepRansomware Gang Claims Nutex Health Data BreachThe company has notified the SEC that hackers accessed patient, employee, provider, business, and financial information. The post Ransomware Gang Claims Nutex Health Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
1 SepHealthcare facilities operator Nutex says patient, employee data stolen in August incidentCybercriminals breached company data and made an extortion attempt with it, Houston-based Nutex Health said in a filing with federal regulators.THERECORD.MEDIA
1 SepCrowdStrike launches cyber frontier AI models, agentic security systemCrowdStrike today announced SafeMind, a cybersecurity-specific AI model-harness system that CEO George Kurtz described as the “first complete agentic system for cybersecurity” at the company’s Fal.Con conference in Las Vegas. At the heart of SafeMind are two purpose-built cyberse…CSOONLINE.COM
1 SepChina's 'Fire Ant' campaign used compromised Cisco routers as platform for more attacksA hacking operation dubbed Fire Ant "didn’t just compromise systems," according to researchers. "It compromised the trust layer those systems depend on."THERECORD.MEDIA
1 SepStronger Security Drives Ransomware Groups to Recruit From WithinSome security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cost companies millions.DARKREADING.COM
1 SepWeekly Update 519: Breaches & Data IntegrityPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite It does feel like I've bitten off too much and am now chewing like crazy this week. The 3D printing talk with Elle in Oslo, the &q…TROYHUNT.COM
31 AugAurora Ransomware Operators Use Cursor AI in Attacks Against 10 TargetsThreat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security. The two independent analyses are bas…THEHACKERNEWS.COM
31 AugChina-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security LogsA China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, an…THEHACKERNEWS.COM
31 AugMcKesson confirms cyber incident after ShinyHunters claims patient-data theftHealthcare company McKesson acknowledged a data breach. ShinyHunters claims to have stolen hundred of millions of recordsMALWAREBYTES.COM
31 AugBerlin says it won’t pay ransom after hackers steal government dataGoverning Mayor Kai Wegner said that Berlin had received an extortion demand following the cyberattack, which was discovered in mid-August.THERECORD.MEDIA
31 AugPharmaceutical giant McKesson warns of 'service degradation' following cyberattackThe pharmaceutical and healthcare technology company McKesson informed regulators it is in the early stages of investigating a cybersecurity incident involving an unnamed third-party application.THERECORD.MEDIA
31 AugMcKesson Confirms Data Breach as Attacker Deadline LoomsThe ShinyHunters extortion group has claimed the theft of 284 million records from the company’s systems. The post McKesson Confirms Data Breach as Attacker Deadline Looms appeared first on SecurityWeek .SECURITYWEEK.COM
31 AugWhat the Hugging Face Incident Teaches Security Leaders About AI Agent AccessSecurity teams must treat autonomous agents as highly privileged identities. The post What the Hugging Face Incident Teaches Security Leaders About AI Agent Access appeared first on SecurityWeek .SECURITYWEEK.COM
31 AugBoston Scientific Still Recovering From CyberattackThe company has called in CrowdStrike and others to investigate the attack that caused global network disruption. The post Boston Scientific Still Recovering From Cyberattack appeared first on SecurityWeek .SECURITYWEEK.COM
31 AugExtortion Group Claims Manchester Airports Group Data BreachFulcrumSec says it stole over 80 GB of data from Manchester Airports Group and plans to leak it online. The post Extortion Group Claims Manchester Airports Group Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
31 AugBerlin Won’t Pay Extortion Group Claiming Data TheftThe Rhysida ransomware group has claimed the exfiltration of over 5TB of data, including personal information and credentials. The post Berlin Won’t Pay Extortion Group Claiming Data Theft appeared first on SecurityWeek .SECURITYWEEK.COM
31 AugAnthropic locks out Claude users after infostealers hijack login sessionsAnthropic has started locking users out of their Claude accounts due to their login sessions having been compromised through infostealer malware. “The malware identified in this campaign so far include Vidar, Lumma (LummaC2), StealC, RedLine and Acreed on Windows, and Atomi…HELPNETSECURITY.COM
31 AugHackers claim millions of patient records stolen during data breach at healthcare giant McKessonThe company, which distributes medicines and medical devices to hospitals and healthcare practices across the U.S., said it was hacked and expects intermittent service degradation.TECHCRUNCH.COM
31 AugMicrosoft warns of TerminalFix attacks deploying reverse tunnelsA new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. [...]BLEEPINGCOMPUTER.COM
30 AugSecurity Affairs newsletter Round 592 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Hack One Robot, Reach the Next: U…SECURITYAFFAIRS.COM
29 AugHack One Robot, Reach the Next: Unitree G1 Security FlawsA researcher chained two Unitree G1 flaws to gain root access remotely and showed how a compromised robot could attack others nearby. Security researcher Olivier Laflamme spent about three months digging into the Unitree G1 humanoid robot and eventually found a way to fully compr…SECURITYAFFAIRS.COM
28 AugWhat 90 days and a small budget can buy in AI agent securityIn this interview with Help Net Security, Prasad Tharippala, Field CISO at Versa, explains what organizations miss when they run open-weight models in house. He covers the hidden costs of GPU infrastructure, licensing review and staffing, and why hardening and incident response b…HELPNETSECURITY.COM
28 AugThe AI agent swarm that attacked Hugging Face is a warning for the futureAn army of AI agents was responsible for the Hugging Face incident. What does it mean for the future of AI?MALWAREBYTES.COM
28 AugATF confirms cyberattack hit system containing info on its investigation targetsThe prolific ransomware group Qilin claimed responsibility for the attack. ATF insists the incident was limited to a standalone system and hasn’t impacted critical operations. The post ATF confirms cyberattack hit system containing info on its investigation targets appeared first…CYBERSCOOP.COM
28 AugFrontier AI tipping the scales toward cyber adversariesResearchers at Palo Alto Networks’ Unit 42 warn that threat actors are already using AI to accelerate cyberattacks beyond the abilities of modern defenses.CYBERSECURITYDIVE.COM
28 AugWindow to Tackle Surge in AI-Enabled Cyber Attacks Narrowing, Tech Giants WarnMore than 100 companies, including OpenAI, Anthropic, Google and Microsoft, have urged collective action to unlock the power of AI to protect critical public servicesINFOSECURITY-MAGAZINE.COM
28 AugShinyHunters claims McKesson data breach exposing 284 million patient recordsThe ShinyHunters threat group claims it compromised McKesson and obtained data on over 284 million patient records, including highly sensitive medical, identity, prescription, and healthcare provider information. CyberInsider reviewed samples privately provided by the threat acto…CYBERINSIDER.COM
28 AugHundreds of OpenAI Agents Invaded Hugging Face ServersThe Hugging Face incident was bigger and worse than previously thought, with approximately 700 agents collaborating on a sophisticated, multistage attack.DARKREADING.COM
28 AugYou Need Cyber Deception for OTThe frustrating reality after an OT cyberattack: no data, no trail, and no history.DARKREADING.COM
27 AugProton suffers major data center outage, says no user data was lostProton experienced a global service outage earlier today after a critical cooling failure hit one of its data centers in Frankfurt, disrupting access to Proton Mail and other services. The company says services have since been restored and that no user data was lost during the in…CYBERINSIDER.COM
27 AugBoston Scientific Reveals Global Disruption After Cyber IncidentMedTech giant Boston Scientific has revealed IT outages following a cyber incidentINFOSECURITY-MAGAZINE.COM
27 AugOpenAI: Hugging Face Incident a “Warning Shot” to the WorldOpenAI reveals that unauthorized message boards were at the heart of the recent Hugging Face breachINFOSECURITY-MAGAZINE.COM
27 AugPro-Russian Hackers Claim Responsibility for Major Cyberattack on Norway’s Public Digital ServicesThe pro-Russian hacker group Server Killers claimed responsibility for the attack. The post Pro-Russian Hackers Claim Responsibility for Major Cyberattack on Norway’s Public Digital Services appeared first on SecurityWeek .SECURITYWEEK.COM
27 AugThreat landscape for industrial automation systems. Q2 2026The report contains statistics on industrial threats for Q2 2026, including ransomware, miners, spyware and other threats that were detected and blocked on industrial control systems.SECURELIST.COM
27 AugCyberattack Causes Global Disruption at Boston ScientificThe cybersecurity incident has disrupted Boston Scientific’s ability to process and ship customer orders. The post Cyberattack Causes Global Disruption at Boston Scientific appeared first on SecurityWeek .SECURITYWEEK.COM
27 AugCarhartt data breach exposes information of 12.9 million accountsThe ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned. [...]BLEEPINGCOMPUTER.COM
27 AugCyberattack causes network outage at Boston Scientific, disrupts global operationsMedical technology company Boston Scientific suffered a cyberattack that disrupted its IT systems and caused a network outage, affecting global operations. Boston Scientific makes devices for minimally invasive procedures, including stents, catheters, pacemakers and defibrillator…HELPNETSECURITY.COM
27 AugVersion Control DFIR: a Cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOpsA practitioner’s guide to log visibility, incident readiness, and threat hunting across the major version control services.WIZ.IO
27 AugDOJ firearms agency says hackers breached system containing investigation targetsThe Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed it experienced a cyberattack on a system containing investigation information, as a prolific ransomware gang claimed to have carried out the breach.THERECORD.MEDIA
27 AugManchester Airports Group Hit by Cyber IncidentCustomer data linked to bookings and airport Wi-Fi registrations at Manchester, Stansted and East Midlands airports has been accessed by an unauthorized third partyINFOSECURITY-MAGAZINE.COM
27 AugHere’s all the times AI has gone rogue and hacked other companiesA recap of all the incidents involving LLMs made by Anthropic, Meta, and OpenAI, which went rogue and attacked real companies and individuals on the internet.TECHCRUNCH.COM
27 AugCyberattack on Manchester Airports Group exposes data of 8.7 million customersA spokesperson told The Yorkshire Post that roughly 8.7 million people were impacted, although they did not provide a date range. They added that in the “vast majority” of cases, the only information accessed was an email address.THERECORD.MEDIA
27 AugChinese and Russian spies stepping up cyberattacks, German companies reportForeign intelligence services, particularly those from China and Russia, are increasingly behind cyberattacks on German companies, according to a new survey of the country’s private sector.THERECORD.MEDIA
27 AugFederal authorities disrupt China-backed hacking operation targeting US critical infrastructureCompromised IoT devices were used in a yearslong campaign against key sectors and U.S. government agencies.CYBERSECURITYDIVE.COM
27 AugFlock wants privacy to meet surveillance halfwayFlock’s CEO wants a compromise between privacy and public safety, but the public has already compromised enough.MALWAREBYTES.COM
27 AugHundreds of agents went rogue in lead up to Hugging Face breachOpenAI released a technical breakdown of the historic incident and plans changes to prevent such an occurrence from happening again. CYBERSECURITYDIVE.COM
27 AugATF declares ‘major incident’ as ransomware gang claims hackThe ATF is the latest federal government agency in recent years to notify Congress of a "major incident" involving its cybersecurity.TECHCRUNCH.COM
27 AugMeta gets a Meta-sized bill.Meta settles. Australian police arrest two alleged TeamPCP members. The White House moves to shore up water utility cybersecurity. ATF reports a major cyber incident. The Navy tells sailors to lock down social media. The FBI warns of a prolific Chinese hacking operation. Bill Gat…THECYBERWIRE.COM
27 AugLegitimate Tools Became Attack ToolsA ransomware attack against a hospital was stopped after attackers attempted to install three legitimate remote-access tools. The tools themselves weren't malware, but they were being used as part of the attack chain. Stopping the ransomware payload wasn't what prevented the atta…YOUTUBE.COM
26 AugIranian hackers darken UK power plant, ShinyHunters breaches the threat hunters, Zombie Visa cardsIran-Linked Cyberattack Hits UK Power Facility, ShinyHunters Phish ReliaQuest, LockBit Claims US Bancorp, Teams Blocks Bots, Expired Visa Card Flaw Cyber Security Today host David Shipley reports a UK power facility was taken offline for four days in July by a cyberattack linked …CYBERSECURITYTODAY.LIBSYN.COM
26 AugJADEPUFFER: An End-to-End Agentic-Led Ransomware AttackIn this episode of the Microsoft Threat Intelligence Podcast, we are joined by Sysdig’s Michael Clark and Crystal Morin to discuss JADEPUFFER, one of the first documented cases of an LLM conducting an end-to-end ransomware operation. They break down how the agent, and the direc…THECYBERWIRE.COM
26 AugSensitive Information Exposed in Nutex Health Data BreachNutex Health has informed the SEC that it recently detected unauthorized access and data exfiltration. The post Sensitive Information Exposed in Nutex Health Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
26 Aug88 ID Verification Breaches Show the Cost of Collecting Identity Data88 ID-verification breaches exposed billions of records, highlighting the growing risks of collecting sensitive identity and biometric data. A new report from Mysterium VPN compiles 88 documented incidents since 2011 where data collected specifically to verify someone’s ide…SECURITYAFFAIRS.COM
26 AugChoose your fighter: Balancing competing requirements to select models for your AI SOCSelecting a model for your security operations center (SOC) and digital forensics and incident response (DFIR) tasks is important, but selecting the best one is more involved than you might think. Here's how to choose.TALOSINTELLIGENCE.COM
26 AugWhat If Ransomware Never Encrypts Anything?Ransomware is no longer just about encrypting files and demanding payment for decryption keys. Attackers may instead focus on disrupting a critical service because they know the victim has strong incentives to restore operations quickly. Service disruption can create consequences…YOUTUBE.COM
26 AugBoston Scientific says cyberattack disrupted order processing, shippingThe medical device-maker says it cannot yet determine any financial impact from the attack it suffered this week.CYBERSECURITYDIVE.COM
26 AugUS disrupts Chinese hacking campaign that breached NASA, the DOJ, the DOE, the Senate, and others.Meta settles children's safety lawsuits for $16.68 billion. Business news: AI security firm Alice raises $140 million.THECYBERWIRE.COM
26 AugBoston Scientific says cyberattack disrupted operations globallyMedical technology company Boston Scientific has been targeted in a cyberattack that disrupted some of its IT systems, causing operational disruptions globally. [...]BLEEPINGCOMPUTER.COM
26 AugUS seizes domains of Chinese botnet used to hack NASA, Justice Department, and the SenateThe FBI has seized domains associated with a botnet that allowed Chinese-backed hackers to breach several U.S. government departments.TECHCRUNCH.COM
26 AugFBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical InfrastructureFBI seizes QScan and QTRouter, China-linked platforms used to hide intrusions and target U.S. critical infrastructure. The U.S. Department of Justice and the FBI have seized two platforms, QScan and QTRouter, used by a China-linked group to hide cyberattacks and target critical i…SECURITYAFFAIRS.COM
26 AugMedical device maker Boston Scientific says a cyberattack is causing a ‘global disruption’ to its operationsThe company won't say if medical devices are affected or if any customer data was exfiltrated.TECHCRUNCH.COM
26 AugOpenAI: Agent behavior that led to Hugging Face intrusion formed in MayThe company says the breach stemmed from a systemic failure of alignment and security, and has taken measures to prevent agents from independently orchestrating complex cyberattacks. The post OpenAI: Agent behavior that led to Hugging Face intrusion formed in May appeared first o…CYBERSCOOP.COM
26 AugMedical device firm Boston Scientific says cyberattack has disrupted shipment processesThe company released a statement and filed documents with the Securities and Exchange Commission (SEC) saying a cybersecurity incident was discovered on Tuesday.THERECORD.MEDIA
26 AugWhat If Your Vendor Goes Down?Third-party risk depends on more than the likelihood that a vendor experiences an incident. Organizations also need to understand their exposure: the data involved, the number of records affected, and the potential business impact. A major technology provider can create consequen…YOUTUBE.COM
25 AugReliaQuest Rejects Compromise Claims After ShinyHunters IncidentReliaQuest has detailed a social engineering attack linked to ShinyHunters, denying reports that the threat actor successfully compromised its systemsINFOSECURITY-MAGAZINE.COM
25 AugShinyHunters taunts ReliaQuest after its own employee falls for social engineering attackCybersecurity company ReliaQuest has confirmed that one of its own employees fell for a social engineering attack, handing attackers a password and a brief window into the company’s identity system. The admission came after the extortion group ShinyHunters posted screenshot…HELPNETSECURITY.COM
25 AugThe cybercrime supply chain has five stages, each with a priceIn this Help Net Security video, Chris Nyhuis, CEO at Vigilant, explains why the picture of a lone ransomware attacker is about 15 years out of date. He walks through the cybercrime supply chain and the five businesses inside it: harvesters who run infostealer malware, brokers wh…HELPNETSECURITY.COM
25 AugThe safety penalty: Reclaiming operational sovereignty in the age of AIAs frontier AI models become increasingly restrictive, security teams are facing a "safety penalty" that hampers real-time incident response. Discover how organizations can move toward operational sovereignty to ensure their defensive AI keeps pace with unconstrained adversaries.TALOSINTELLIGENCE.COM
25 AugMirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login FlowsThousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication. According to ANY.RUN research, 48% of targ…THEHACKERNEWS.COM
25 AugHands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity ConferenceHands-on Cyber Attack Methods course returns to SecurityWeek’s ICS Cybersecurity Conference, October 6–8 at the W Nashville. The post Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference appeared first on SecurityWeek .SECURITYWEEK.COM
25 AugHospital operator Nutex Health says data stolen in cyberattackHealthcare and services provider Nutex is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers. [...]BLEEPINGCOMPUTER.COM
25 AugThat fake Grand Theft Auto VI demo is actually just malwareGrand Theft Auto fans, eager for news about one of the most anticipated video games of all time, appear especially vulnerable to this new cyberattack.TECHCRUNCH.COM
25 AugIs Cyber Facing an Affordability Crisis?As breach costs reach record highs and defense spending nears $240 billion, small businesses are dangerously exposed, threatening supply chain security.DARKREADING.COM
25 AugNorway ’s Digital Government Infrastructure Hit by a new DDoS AttackNorway ’s shared government infrastructure suffered a third DDoS attack, disrupting digital services but showing no signs of data compromise. Norway ‘s shared digital government infrastructure has been hit by another distributed denial-of-service (DDoS) attack that disrupte…SECURITYAFFAIRS.COM
25 AugU.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure BreachesThe U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole-of-government, economic campaign" against the nation and its enablers. "We are launching an economic onslaught against Iran's financial con…THEHACKERNEWS.COM
25 AugLACMA data breach last year exposed social security and medical dataThe Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information. [...]BLEEPINGCOMPUTER.COM
25 AugA Cautionary Tale About Data Breach Claims, Verification and CarharttPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite You're not going to believe this, but turns out you can't always take criminals at their word. Actually, I'll walk that …TROYHUNT.COM
25 AugCarhartt - 12,933,413 breached accountsIn August 2026, clothing retailer Carhartt was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data allegedly obtained from the company including 12.9M unique email addresses, names, phone numbers and physical addresses. The publis…HAVEIBEENPWNED.COM
24 AugWeekly Update 518: IoT Doorlock Nirvana with UniFiPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite I genuinely think I've nailed the IoT door lock situation! Well, Ubiquiti has, but I think I've worked out how to put it all …TROYHUNT.COM
24 AugReliaQuest says claimed ShinyHunters attack was successfully blockedReliaQuest says it contained a social engineering attack that briefly gave a threat actor access to a single employee identity session but did not allow access to company applications, systems, or customer data. The attacker was not identified in the company’s report, altho…CYBERINSIDER.COM
24 AugPersonal Information Exposed in Apollo Global Data BreachThe private equity firm appears to have been targeted as part of a campaign focusing on major financial companies. The post Personal Information Exposed in Apollo Global Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
24 AugASOS credential-stuffing attack exposed data of 138,828 customersASOS is notifying US customers that attackers gained unauthorized access to accounts using credentials obtained outside the company. This access potentially exposed personal, contact, and partial payment card information. According to an investigation published by Srourian Law Fi…CYBERINSIDER.COM
24 AugWordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows PasswordsCybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Ste…THEHACKERNEWS.COM
24 AugSouth Korean startup platform breach exposes key management failuresA breach at South Korea's government-backed startup platform exposed encrypted personal data after an encryption key was included in an API. Penta Security explains why encryption keys must be securely managed and kept separate from the data they protect. [...]BLEEPINGCOMPUTER.COM
24 Aug24th August – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 24th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Latvia’s Road Traffic Safety Directorate (CSDD) has confirmed a breach affecting payment records of more than 1.2 million people …RESEARCH.CHECKPOINT.COM
24 AugUK power facility disabled for days after suspected state-linked cyberattackThe disruption took place amid a wave of attacks targeting vulnerable industrial devices in the water and energy sectors.CYBERSECURITYDIVE.COM
24 AugReliaQuest confirms failed data-theft attack after ShinyHunters breachCybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. [...]BLEEPINGCOMPUTER.COM
24 AugTricky 'SynkLoader' Multitool May Herald RansomwareAn advanced, multilingual malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with a slew of novel features.DARKREADING.COM
24 AugSlovakia finds Russian backdoors on traffic speed cameras.Canada's Hospital for Sick Children discloses breach. TikTok will pay $400 million to settle children's privacy case.THECYBERWIRE.COM
24 AugUS sanctions Iranian cyber actors as UK discloses power plant attackThe U.S. sanctioned several Iranian nationals for cyberattacks on critical infrastructure just days after reports emerged of a cyber intrusion on a small power plant in the United Kingdom.THERECORD.MEDIA
23 AugWelcoming the Sri Lankan Government to Have I Been PwnedPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite Today, we welcome the 48th government onboarded to Have I Been Pwned’s free gov service: Sri Lanka. Sri Lanka CERT now has acces…TROYHUNT.COM
23 AugWeek in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgsHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: Windows 11’s strongest security defenses can be bypassed without a screwdriver Researchers from the University of Birmingham and Durham University have found a way to knock down some…HELPNETSECURITY.COM
23 AugUK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water AttacksIran-linked hackers shut down a UK power plant for four days in the first confirmed attack of its kind, concurrent with water infrastructure attacks across 12 US states. Iran-linked hackers shut down a British power plant for four days in what The Telegraph describes as the most …SECURITYAFFAIRS.COM
23 AugSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 111Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Akira Hits Safe Mode: Ransomware Rebooting Around EDR Multi-Functional Linux Botnet “Evooo1Bot” …SECURITYAFFAIRS.COM
23 AugNIUS - 6,090 breached accountsIn July 2025, the German news service NIUS suffered a data breach which was subsequently leaked publicly . The data included 6k unique email addresses along with names, physical addresses and payment details for purchases including either IBANs or partial credit card data (masked…HAVEIBEENPWNED.COM
22 AugHackers infect Android car head units with proxy botnet malwareA supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [...]BLEEPINGCOMPUTER.COM
21 AugRust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million DownloadsThe Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation. The affec…THEHACKERNEWS.COM
21 AugSickKids data breach exposes employee and job applicant infoToronto's Hospital for Sick Children (SickKids) says a cybersecurity incident exposed the personal information of some current and former employees and job applicants, stemming from a flaw in third-party software. Clinical systems and patient records were not affected. (264) [...…BLEEPINGCOMPUTER.COM
21 AugMedical records, SSNs, and bank details exposed in CareCloud data breachHealthcare technology provider CareCloud confirmed that 3.75 million people were affected by a March data breach.MALWAREBYTES.COM
21 AugNorth Korean Hackers Tied to Rust Supply Chain AttackCybersecurity researchers have linked a malicious backdoor in compromised Rust packages to previous North Korean supply chain attacksINFOSECURITY-MAGAZINE.COM
21 AugPrivate equity firm Apollo confirms data breach amid hacking wave targeting financial giantsThe private equity giant confirms a breach, weeks after Google researchers said hackers were targeting financial companies.TECHCRUNCH.COM
21 AugRussian network monitoring firm confirms cyberattack claimed by pro-Ukraine hackersThe statement came a day after a hacking group calling itself Black Spark claimed it had spent more than a month inside Microolap’s network and gained access to its internal systems, including EtherSensor, the company's network traffic analysis platform.THERECORD.MEDIA
21 AugOpenAI Adds Controls That Should've Been There AlreadyThe new AI security controls follow the Hugging Face incident last month, though many of these additions perhaps should have been in place prior to the frontier models escaping.DARKREADING.COM
21 AugCanada’s Hospital for Sick Children attacked by cybercriminals again as employee data stolenThe Hospital for Sick Children — which was hit in a ransomware incident in 2022 that disabled some of its systems — released a statement on Thursday warning of a data theft incident they believe is tied to a third-party software application.THERECORD.MEDIA
21 AugIs Online Privacy Possible? How Digital Identities Can HelpUsing the same email, phone number, payment method, and other identifiers makes it easier for data brokers and attackers to profile your activity. Anonyome Labs explains how separate digital personas can reduce correlation and limit the impact of breaches, spam, and identity thef…BLEEPINGCOMPUTER.COM
21 AugU.S. Bank says breach claims related to fourth-party incidentThe bank said there is no evidence that its own systems, networks or data repositories were compromised.THERECORD.MEDIA
21 AugApollo discloses data breach from ongoing wave of attacks hitting financial sectorThe private equity firm said attackers broke into some of its cloud platforms during a five-day period in early July, compromising sensitive personal data. The post Apollo discloses data breach from ongoing wave of attacks hitting financial sector appeared first on CyberScoop .CYBERSCOOP.COM
20 AugStopAndProtect Turns 2,000 Hacked WordPress Sites Into a Criminal NetworkStopAndProtect turned nearly 2,000 hacked WordPress sites into a criminal network for malware delivery, data theft, surveillance and ransomware. Check Point Research uncovered a cybercrime operation, dubbed StopAndProtect, that has turned thousands of hacked WordPress websites in…SECURITYAFFAIRS.COM
20 AugNew Manic Android malware can exfiltrate data through nearby devicesA new Android malware named Manic targeting users in multiple European countries has a fallback data exfiltration mechanism that uses nearby infected devices. [...]BLEEPINGCOMPUTER.COM
20 AugOpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training PausesThe action taken by OpenAI comes in light of the Hugging Face incident and the discovery of the Astra model’s advanced capabilities. The post OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugFake Gemini installer delivers Vidar infostealer via Google Colab lureA malicious executable masquerading as a Google Gemini installer was used to deliver the Vidar infostealer on a company network in the EMEA region, according to Darktrace researchers who investigated the incident. “During the initial analysis, it was noted that the top search res…HELPNETSECURITY.COM
20 AugAI data giant Alation confirms cyberattackThe data search and AI giant confirmed unauthorized access to its systems during an incident on Tuesday, and said it was investigating the breach.TECHCRUNCH.COM
20 AugWhy "Shady AI" is Security's Next Big Governance ProblemIn March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company and user data was exposed to employees who weren’t authorized to access it. The incident began when a Meta employee posted a technical question on an internal forum. An engineer…THEHACKERNEWS.COM
20 AugManic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected DevicesA new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused commun…THEHACKERNEWS.COM
20 AugOne Programmer Can Break EverythingA critical system becomes vulnerable when only one person knows how to restore or debug it. Matt Lea calls these people “lone wolf programmers” and connects the problem to the idea of a bus factor. The risk isn't just that someone leaves. People get sick, take vacation, burn out,…YOUTUBE.COM
20 AugPakistan's Transparent Tribe Refreshes Toolset for Afghan CyberattacksA nation-state threat actor is picking on immature organizations run by the Taliban, but failing against more prepared government agencies in India.DARKREADING.COM
20 AugFitch explains how water, healthcare organizations can keep strong credit ratings, despite cyberattacksResilience, not prevention, is key, analysts at the credit-rating agency said in a pair of new reports.CYBERSECURITYDIVE.COM
20 AugDetailed Timeline of OpenAI’s Cyberattack on Hugging FaceOpenAI presented details of its AI’s model’s cyberattack on Hugging Face at Black Hat last week. Simon Willison details the timeline. It’s really interesting to read through—and really impressive cyberoffense work.SCHNEIER.COM
20 AugHackers poison arrayref Rust crate to push infostealer malwareHackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers' systems during compilation. [...]BLEEPINGCOMPUTER.COM
20 AugManic: The Android Malware That Exfiltrates Data Even When the Phone Is OfflineManic Android malware combines banking fraud and spyware, using a Bluetooth relay to steal data even when devices are offline. ThreatFabric’s Mobile Threat Intelligence team has identified a new Android malware, dubbed Manic, which has been active in the wild since at least…SECURITYAFFAIRS.COM
20 AugChina Is Strapping ‘Digital Bombs’ to Civilian Infrastructure—Is the US Ready?This week on “Uncanny Valley,” Andy Greenberg discusses sitting in on a war game simulating a cyberattack from the Chinese hacking group Volt TyphoonWIRED.COM
19 AugOz Hair and Beauty - 1,988,331 breached accountsIn August 2026, Australian beauty retailer Oz Hair and Beauty was the target of an xpl0itrs extortion attack . The group subsequently published data allegedly obtained from the company, which included 2M unique email addresses along with names, phone numbers, geographic locations…HAVEIBEENPWNED.COM
19 AugFanlore - 144,520 breached accountsIn August 2026, the Organization for Transformative Works (OTW) identified unauthorised access to the Fanlore wiki it operates . The breach resulted in the exposure of 145k unique email addresses along with usernames and passwords stored as either MD5 or PBKDF2 hashes. OTW self-s…HAVEIBEENPWNED.COM
19 AugCareCloud Data Breach Impact Grows to 3.7 Million IndividualsThe data breach was initially believed to affect roughly 350,000 people, but the HHS breach tracker shows a far bigger impact. The post CareCloud Data Breach Impact Grows to 3.7 Million Individuals appeared first on SecurityWeek .SECURITYWEEK.COM
19 AugOver 500 Critical Infrastructure Organizations Hit by Medusa RansomwareThe FBI warned that the RaaS operation has significantly enhanced its tactics, techniques and procedures, making it harder for defenders to counterINFOSECURITY-MAGAZINE.COM
19 AugStopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal DataCybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the a…THEHACKERNEWS.COM
19 AugOpenAI Tightens AI Safeguards Following Hugging Face IncidentOpenAI is strengthening safeguards for its most advanced AI models, citing growing risks as frontier systems gain more powerful cyber capabilitiesINFOSECURITY-MAGAZINE.COM
19 AugCl0p Ransomware Group Names Over 40 Victims of PTC Windchill CampaignThe cybercrime gang has listed major companies such as Shell, Philips, Fiserv, Zebra, Mindray, and Largan Precision. The post Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign appeared first on SecurityWeek .SECURITYWEEK.COM
19 AugUS charges Iranians for sprawling hacking campaign on government agencies, universitiesThe Justice Department accused 17 alleged hackers with ties to the Iranian government of breaching email accounts at U.S. government agencies and stealing intellectual property from dozens of universities.THERECORD.MEDIA
19 AugCareCloud confirms 3.7M patients had their medical records stolen in data breachThe cyberattack at CareCloud resulted in one of the largest reported data breaches in the U.S. healthcare industry this year.TECHCRUNCH.COM
19 AugLatvian officials resign after cyberattack exposes data on 1.2 million peopleLatvia’s road traffic agency confirmed that hackers stole data connected to about two-thirds of the country’s population in a major cyberattack that has prompted calls for senior officials to resign.THERECORD.MEDIA
19 AugBackup Software Can Exfiltrate DataBackup software is designed to move and store large amounts of organizational data. If the destination or purpose changes, that same capability can potentially be used for data exfiltration. Because backup activity is expected and can generate substantial data movement, malicious…YOUTUBE.COM
19 AugMedusa ransomware affiliates have breached hundreds of critical infrastructure entities.US accuses 17 Iranians of hacking for Iran's IRGC. Business news: Fortinet acquires AI security firm Virtue AI.THECYBERWIRE.COM
19 AugRansomware disproportionately targets medium-sized firms, straining customer relationshipsThese companies often have the hardest time balancing their roles as suppliers and customers, according to the risk management firm Black Kite.CYBERSECURITYDIVE.COM
19 Aug2,000 WordPress sites hijacked by StopAndProtect malware operationA large-scale malware operation dubbed StopAndProtect uses thousands of compromised WordPress websites to distribute malware, issue commands, and store data stolen from infected computers. The campaign combines ransomware, credential theft, surveillance, lateral movement, and han…CYBERINSIDER.COM
19 AugT-Mobile ‘chopped a cable’ to expel Chinese hackers from its networkThe U.S. phone provider escaped a large-scale breach of its network after identifying Chinese-backed hackers early on.TECHCRUNCH.COM
19 AugInside Operation CameraSwarm: How One Actor Took Over 14,000 Dahua CamerasAn exposed operator directory reveals how one actor compromised 14,000+ Dahua cameras across Ukraine and Russia, no password needed for most. A researcher discovered an exposed directory containing the tools of an attacker who compromised more than 14,000 Dahua cameras between Ju…SECURITYAFFAIRS.COM
19 AugElectronic health record company CareCloud says 3.7 million people affected by breachHealthcare software firm CareCloud filed documents with the Department of Health and Human Services confirming that 3,756,469 people had information leaked after a hacker spent eight hours in one of the company’s electronic health record environments.THERECORD.MEDIA
19 AugHackers compromise 14,500 Dahua web cameras in 35-day campaignIn a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more than 14,500 Dahua IP cameras mostly in Ukraine and Russia. [...]BLEEPINGCOMPUTER.COM
19 AugRogue ransomware affiliate poses as data recovery firm to steal paymentsA suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]BLEEPINGCOMPUTER.COM
19 AugCybersecurity Needs Its Stop Drop RollCybersecurity is complex, but emergency response doesn't always have to be. The discussion compares cybersecurity's response problem with familiar basics like CPR and “stop, drop and roll.” A simple, memorable response playbook could help people act faster during an incident inst…YOUTUBE.COM
19 AugRogue ransomware affiliate poses as recovery firm to steal paymentsA suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]BLEEPINGCOMPUTER.COM
18 AugWeekly Update 517: Cyber RansomsPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite The current ransomware situation is a bit of a kludge (deep breath): a lot of ransomware (which often doesn't even involve "w…TROYHUNT.COM
18 AugHeights Finance Data Breach Impacts at Least 1.2 Million IndividualsHackers stole names, addresses, phone numbers, Social Security numbers, and financial information from a third-party platform. The post Heights Finance Data Breach Impacts at Least 1.2 Million Individuals appeared first on SecurityWeek .SECURITYWEEK.COM
18 AugOpenAI tightens defenses after AI agents breach research environmentFollowing the OpenAI-Hugging Face incident, in which an agentic collective autonomously penetrated OpenAI’s research infrastructure and another company’s production infrastructure by chaining together multiple weaknesses, OpenAI began strengthening its safety requirements. The we…HELPNETSECURITY.COM
18 AugHeights Finance data breach: What customers need to knowLeaked personal and financial data of around 750,000 US citizens, including SSNs and bank details, could put victims at risk of identity theft and phishing.MALWAREBYTES.COM
18 AugThree-quarters of Ransomware Attacks Target Mid-Market FirmsBlack Kite finds mid-market is the sweet spot for ransomware as manufacturers are most likely to be hitINFOSECURITY-MAGAZINE.COM
18 AugCyber Incident Disrupts Student Services at UT San AntonioUT San Antonio has taken IT systems offline following a cyber incident, disrupting student registration and tuition payments days before term is due to resumeINFOSECURITY-MAGAZINE.COM
18 AugDownload: 2026 Credential Risk Report85% of cybersecurity professionals consider compromised credentials a primary attack path, yet only 19% continuously monitor active credentials and automatically remediate exposure. The 2026 Credential Risk Report examines where credential security programs fall short and what it…HELPNETSECURITY.COM
18 AugGitHub suffers eight-hour outage affecting Actions, APIs, and CopilotGitHub suffered a widespread outage on August 17 that disrupted core services including its API, Actions, Pull Requests, Issues, Pages, Webhooks, and Copilot, with some repository downloads experiencing error rates of around 50%. The incident began at 1:40 p.m. UTC when GitHub sa…CYBERINSIDER.COM
18 Aug'Ransom Busters': Ransomware Actor Poses as Incident-Recovery ServiceA ransomware affiliate appears to be sidling up to victims with offers of aid, masking its true intention of diverting ransom payments.DARKREADING.COM
18 AugThousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtectResearch by: Jaromír Hořejší (@JaromirHorejsi) Key points Introduction We first noticed a ransomware family called StopAndProtect in the middle of May 2026. Further analysis of the infrastructure reveals that the infection chain starts with a ClickFix social-engineering technique…RESEARCH.CHECKPOINT.COM
18 AugClop created custom web shell for Windchill data theft attacksA custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. [...]BLEEPINGCOMPUTER.COM
18 AugRansom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000. "In these messages, the third-party off…THEHACKERNEWS.COM
18 AugOpenAI institutes new safeguards after Hugging Face breachThe new safeguards include more detailed monitoring of models during the development process, as well as greater emphasis on alignment and security during the post-training process.TECHCRUNCH.COM
18 AugHackers Expose Data of 1.2 Million Heights Finance CustomersA Heights Finance breach exposed personal and financial data of over 1.2 million people after hackers compromised a third-party cloud platform. Heights Finance is a U.S. consumer finance company that provides personal loans and related lending services, mainly to customers who ma…SECURITYAFFAIRS.COM
17 AugFortune 500 Companies Hit in Azure Data Theft CampaignA threat actor is claiming the exfiltration of millions of records from McDonald’s, TCS, Vodafone, and other large organizations. The post Fortune 500 Companies Hit in Azure Data Theft Campaign appeared first on SecurityWeek .SECURITYWEEK.COM
17 AugAfrica’s Cybersecurity Challenge Is Bigger Than Access to TechnologyGopan Sivasankaran is Rapid7's Regional Director, Middle East & Africa. Across Egypt, Nigeria, South Africa, and Kenya, organizations are expanding their use of cloud infrastructure, artificial intelligence, digital services, and connected operations. But more technology does not…RAPID7.COM
17 AugAkira Ransomware Uses Safe Mode to Bypass EDRAkira attackers used Safe Mode to disable EDR before deploying ransomware, but memory issues caused the encryptor to fail. An Akira ransomware affiliate broke into a company through an MFA-less SonicWall VPN on August 4, stole credentials and file shares, and then rebooted the co…SECURITYAFFAIRS.COM
17 AugSafePal Data Breach Hits Tens of Thousands of CustomersNearly 40,000 customers of hardware wallet provider SafePal have been impacted by a data breachINFOSECURITY-MAGAZINE.COM
17 AugNew macOS malware turns stolen browsers into attacker-controlled sessionsMac users are being freshly warned of suspicious websites asking them to open Terminal and install software. Jamf Threat Labs has uncovered a multi-stage macOS infostealer, dubbed AmnesiaStealer, that uses a ClickFix-style fake GitHub download page to trick victims into executing…CSOONLINE.COM
17 AugPhilips and GE investigating Clop ransomware data theft claimsTech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]BLEEPINGCOMPUTER.COM
17 Aug680,000 Impacted by French Tax Authority Data BreachHackers used compromised credentials to access enterprise and personal tax-related data. The post 680,000 Impacted by French Tax Authority Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
17 AugSogang University data breach exposes information of 180,000 peopleSogang University in Seoul has suffered a cyberattack that exposed personal information belonging to roughly 180,000 students, alumni, faculty members, and staff. The university said an unidentified external party gained unauthorized access to its integrated login system, resulti…CYBERINSIDER.COM
17 AugGeneral Electric, Philips, and Shell investigate alleged breaches.ShinyHunters leaks alleged RingCentral data. Police arrest seven suspects in connection with 2023 bank hack.THECYBERWIRE.COM
17 AugMajor genetic-testing firm says hack compromised sensitive patient dataThe June breach, which also exposed employees’ information, underscored the supply-chain risks facing the healthcare sector.CYBERSECURITYDIVE.COM
17 AugSafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impactedThe crypto hardware wallet company SafePal confirmed a data breach on Sunday, telling users that nearly 40,000 customers had information stolen during a recent security incident.THERECORD.MEDIA
17 AugIrregular faces criticism over ‘spin’ in AI hacking postmortemThe company at the center of a series of incidents in which AI models compromised real-world computer systems during security evaluations is facing criticism after the release of a report that security experts say leaves key questions unanswered.THERECORD.MEDIA
17 AugPoland probes MyDr healthcare software breach potentially affecting 19 million peopleMyDr, a privately-owned Polish company that supplies software to doctors, clinics and other healthcare providers, said on Friday that it had identified and removed the cause of the incident and introduced additional security measures.THERECORD.MEDIA
17 AugWill Cyber Insurance Stop Covering Fraud?Financial fraud is described as a leading category of cyber insurance claims, with Adrian Sanabria noting that it can exceed ransomware in claims paid by insurers. At the same time, insurers are changing what they consider covered cyber risk. Social engineering, “click fix,” and …YOUTUBE.COM
17 AugHacker claims 3.6 million Azure account records stolen from major companiesA threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials. [...]BLEEPINGCOMPUTER.COM
17 AugPokémon Center data breach exposes customer info, cancels some ordersPokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics. [...]BLEEPINGCOMPUTER.COM
17 AugNearly 750k had financial info, SSNs leaked in South Carolina loan company breachThe breach affected anyone who received a loan through the company or inquired about a loan product through a third party.THERECORD.MEDIA
17 AugDetails emerge on BlackFile’s recent attacks on financial companiesBlackFile’s four affiliate groups are still targeting victims, including medical technology organizations. Several potential victims received new extortion demands last week, according to Google. The post Details emerge on BlackFile’s recent attacks on financial companies a…CYBERSCOOP.COM
17 AugIrregular says ‘human oversight’ responsible for AI sandbox escape incidentsIn a post-mortem, the frontier AI testing company said internet access for models is necessary to fully test out their cybersecurity capabilities. The post Irregular says ‘human oversight’ responsible for AI sandbox escape incidents appeared first on CyberScoop .CYBERSCOOP.COM
16 AugAI, misinformation, and the future of cybersecurity.As AI products proliferate, they continue to introduce new concerns, which have subtly eroded trust in imagery and content created by space-based infrastructure. In this week's episode, host Maria Varmazis sits down with Dave Bittner and Brandon Karpf to look at Google's troub…THECYBERWIRE.COM
15 AugHow to tell if your AI platforms’ accounts have been hackedA guide on how to check if hackers have broken into your accounts on the most popular AI platforms.TECHCRUNCH.COM
14 Aug14,000 Trezor Customers Impacted by Data Breach at ShipMonkHackers stole the customers’ shipping information, including names, addresses, email addresses, and phone numbers. The post 14,000 Trezor Customers Impacted by Data Breach at ShipMonk appeared first on SecurityWeek .SECURITYWEEK.COM
14 AugChess.com Leak Exposes 7.3 Million Users – Evidence Points to Scraping7.3 million Chess.com profiles leaked online: the data is genuine, but evidence points to large-scale scraping, not a server breach. Free is a strange price for stolen data, and that’s exactly what makes this listing worth a second look. A 15.5 GB file containing over 7.3 m…SECURITYAFFAIRS.COM
14 AugOver 1,000 Charities Hit by Beacon CRM Data BreachThe root cause of the incident is believed to be a compromised AWS access key that was exposed in publicly available JavaScript build artifacts. The post Over 1,000 Charities Hit by Beacon CRM Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
14 AugRingCentral data breach exposed info of 1.6 million accountsThe ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned. [...]BLEEPINGCOMPUTER.COM
14 Aug1.6 Million Likely Impacted by RingCentral Data BreachThe hackers published the allegedly stolen information, including names, addresses, email addresses, and phone numbers. The post 1.6 Million Likely Impacted by RingCentral Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
14 AugShell investigates 'potential incident' after Clop data theft claimsOil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. [...]BLEEPINGCOMPUTER.COM
14 AugIn Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System VulnerabilitiesNoteworthy stories that might have slipped under the radar: government AI platform deal sparks outrage, North Korean IT worker breaches federal agency, DEF CON attendee blamed for Delta flight disruption. The post In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration…SECURITYWEEK.COM
14 AugFrance investigates tax authority breach after hacker claims 600,000 victimsFrench authorities confirmed that someone gained unauthorized access to systems at the Directorate General of Public Finances in late June after stealing or misusing someone’s identity.THERECORD.MEDIA
14 AugResearchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 OrganizationsResearchers have verified that ExfilSquad possesses sensitive data stolen from at least 13 victims after the extortion group published leaked datasets via torrentsINFOSECURITY-MAGAZINE.COM
14 AugResearchers confirm breach claims by data-extortion groupThe exfiltrated data may be related to misconfiguration of Microsoft Power Page portals, according to a new report.CYBERSECURITYDIVE.COM
14 AugCisco security revenue jumps 14% as agentic AI sharpens cyberattacksWith companies confronting more sophisticated threats, AI agents are driving demand for cybersecurity tools, CEO Chuck Robbins said.CYBERSECURITYDIVE.COM
14 AugScottish Govt Suffers Potentially Widening Data Breach at Prosecutor's OfficeOne Caledonian government agency reported a breach, thanks to a third party that may have serviced other agencies as well.DARKREADING.COM
14 AugRansomware Can Bypass Endpoint DefensesAn Akira ransomware attack reportedly used Safe Mode to help bypass endpoint defenses. The initial access came through an exposed SonicWall SSL VPN that did not have MFA enabled, followed by Active Directory enumeration and data staging. The attack demonstrates how basic weakness…YOUTUBE.COM
13 AugWhat do AI-driven ‘bank heist’ attacks mean for defenders?Attackers aren't just using AI to steal data; they're using it to fight back while you investigate them in real time. And once an adversary is inside, why would they ever want to leave? That's the unsettling reality Tom Kellermann, VP of AI Security and Threat Research at TrendAI…THECYBERWIRE.COM
13 AugICO Reprimands Criminal Records Office After 2023 BreachThe ICO has issued a formal reprimand to ACRO after patching and security monitoring failures led to a breachINFOSECURITY-MAGAZINE.COM
13 AugStorm-1175 Replaces Medusa With New StormEncryptor RansomwareMicrosoft says China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa in its latest attacks. Microsoft says China-linked, financially motivated threat actor Storm-1175 has begun using a new ransomware strain called StormEncryptor. The group prev…SECURITYAFFAIRS.COM
13 AugAkira Affiliate Crashes Ransomware After Attempting EDR EvasionHuntress documents how a ransomware affiliate sabotaged its own attack with an anti-EDR effortINFOSECURITY-MAGAZINE.COM
13 AugThe State of Ransomware Q2 2026For the past year, the ransomware conversation has centered on concentration: a handful of dominant RaaS operations controlling most of the damage, and a shrinking pool of active groups fighting over the same territory. The State of Ransomware Q2 2026 report from Check Point Rese…RESEARCH.CHECKPOINT.COM
13 AugRingCentral - 1,596,490 breached accountsIn July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data they claimed was obtained from the platform, which included 1.6M unique email addresses along with …HAVEIBEENPWNED.COM
13 AugIn a first, US will allow some private firms to carry out cyberattacksThe new order sweeps away decades of existing U.S. cybersecurity policy prohibiting private companies from conducting 'hack back' attacks or offensive cyber operations.TECHCRUNCH.COM
13 AugExposed AWS Access Key Linked to Data Breach Affecting 1500+ UK CharitiesCRM provider Beacon has revealed that a compromised AWS access key was the likely root cause of the breach of 1500 UK charities’ dataINFOSECURITY-MAGAZINE.COM
13 AugHackers breach govt webmail while running parallel crypto fraudThe Jewelbug hacker group has been carrying out espionage operations targeting governments and militaries while also engaging in cryptocurrency fraud. [...]BLEEPINGCOMPUTER.COM
13 AugAkira hackers disable EDR with Safe Mode, steal data but fail to encryptAn Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. [...]BLEEPINGCOMPUTER.COM
13 AugNation-State Hackers Target Hotel Wi-FiCaptive portals are the login pages you encounter when connecting to many hotel and public Wi-Fi networks. Larry Pesce describes a campaign in which a nation-state-level threat actor compromised these devices and controlled DNS. That control can allow attackers to redirect users …YOUTUBE.COM
12 AugWeekly Update 516: Live From VietnamPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite A little wind noise, a little connectivity flakiness, and a little lip-sync issues from YouTube, but look at that view! 🤩 Back …TROYHUNT.COM
12 Aug‘The Worst I’ve Ever Seen’: Cargo Thefts Have Turned Violent in Pursuit of AI HardwareExperts allege that two recent incidents in California show the extreme lengths that criminal organizations are willing to go to to steal servers and other gear meant for data centers.WIRED.COM
12 AugOver 2,500 Organizations Impacted by LiteLLM Supply Chain AttackLiteLLM was compromised through the Trivy hack and abused to distribute information-stealing malware to its users. The post Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugCeva Logistics Operations Disrupted by CyberattackAffecting European contract logistics operations at eight Ceva warehouses, the incident caused shipment delays for multiple customers. The post Ceva Logistics Operations Disrupted by Cyberattack appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugUber Freight reportedly investigating after hacking group claims data breachAn extortion gang known for targeting transportation companies and private equity firms has taken credit for a breach at Uber Freight.TECHCRUNCH.COM
12 AugYour AI Can Be Hacked Through TextThis clip describes an AI hijacking technique in which an external attacker places instructions into text that an AI agent is already processing, such as logs, alerts, or email. The danger is that the agent may interpret untrusted content as an instruction. That creates a new sec…YOUTUBE.COM
12 AugFBI: Hackers using social engineering to breach accounts and steal explicit contentLeaked passwords, social engineering and spoofed social media sites are among the tools hackers are using to gather individuals' private content and sell it online, the FBI said.THERECORD.MEDIA
12 AugLiteLLM breach data shows supply chain attack impacted 2,488 firmsA new analysis of data allegedly stolen during the March 2026 LiteLLM supply chain attack has linked nearly 2,500 corporate domains to exposed CI/CD environments, including those of major technology, industrial, financial, and telecommunications firms. Cybersecurity firm Hudson R…CYBERINSIDER.COM
12 AugChina-Linked Hackers Use AI Agents in Autonomous Attack on TaiwanChina-linked hackers reportedly used eight AI agents to breach a government network, steal data and compromise accounts with minimal human oversight. Israeli cybersecurity firm Dream documented what looks like the first fully autonomous, end-to-end AI hacking operation against a …SECURITYAFFAIRS.COM
12 AugCEVA Logistics Cyberattack Disrupts European Warehouses and ShipmentsCEVA Logistics suffered a cyberattack disrupting European operations, with eight warehouses affected and shipments halted at impacted sites. CEVA Logistics suffered a cyberattack on July 29 that disrupted parts of its European operations. The incident impacted impacted eight ware…SECURITYAFFAIRS.COM
11 AugHackers Breach Polish Power Plant Controls via Private Cellular Network and Shut TurbineAttackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment. The plant supplies heat to roughly 50,000 residents. Recover…THEHACKERNEWS.COM
11 AugOnly Half of UK Manufacturers Have a Cyber Incident Response PlanMake UK reveals major cyber resilience gaps as 30% of UK manufacturers report recent cyber incidentsINFOSECURITY-MAGAZINE.COM
11 AugUS and South Korea warn of Gunra ransomware targeting govt agenciesU.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. [...]BLEEPINGCOMPUTER.COM
11 AugLogistics Giant Ceva Suffers Data Breach Impacting European ClientsSupply chain attack and data breach at Ceva Logistics appears to have a large blast radiusINFOSECURITY-MAGAZINE.COM
11 AugSuisan City, California, Responds to Cyber Incident Amid Wave of US Local Government AttacksPolice and fire response has been impacted by the attack on Suisan City, while two other local authorities have been hit by cyber incidents in the past week alsoINFOSECURITY-MAGAZINE.COM
11 AugFBI warns Gunra ransomware targets critical sectors and governmentsUS authorities are warning organizations about Gunra, an emerging ransomware operation that has attacked victims worldwide, stolen as much as tens of terabytes of data in individual incidents, and opened ransom negotiations at amounts exceeding tens of millions of dollars. The gr…CYBERINSIDER.COM
11 AugMalicious SIMs can hijack smartphones, steal files, and lock them onto 2GResearchers have found that compromised or malicious SIM cards can issue commands to some smartphones and cellular-connected devices, allowing attackers to steal information, disrupt communications, downgrade connections to 2G, and in some cases execute code. Tomasz Piotr Lisowsk…HELPNETSECURITY.COM
11 AugLocal governments in four states dealing with cyberattacks that have shut down servicesMunicipalities in California, Oklahoma, Wisconsin and Texas are all recovering from disruptive cyberattacks that have affected government operations.THERECORD.MEDIA
11 AugThreat Hunting Case Study: The GentlemenAnalyzing The Gentlemen ransomware group's attack chain and how to hunt for their privileged group manipulation technique before they spread through the NETLOGON share folder on Windows domain controllers.INTEL471.COM
11 AugDelta investigating after someone set up fake Wi-Fi network mid-flightThe Delta flight crew switched off the aircraft's legitimate Wi-Fi network for around 30 minutes due to the incident, according to a spokesperson.TECHCRUNCH.COM
11 AugPoland’s CERT describes winter cyberattack against heat-and-power plant.US and South Korea warn of "Gunra" ransomware gang with North Korean ties. Chinese IP connections spark security review in UK Navy drones.THECYBERWIRE.COM
11 AugCyberattack on logistics giant Ceva hits retailers and Steam customers across EuropeOperations at eight European warehouses belonging to France's CEVA Logistics have reportedly been disrupted by a cyberattack, and several other companies are feeling the effects.THERECORD.MEDIA
11 AugWesco confirms security incident after ExfilSquad claims data theftGlobal supply chain and distribution giant Wesco has confirmed in a statement for BleepingComputer that it is investigating a cybersecurity incident. [...]BLEEPINGCOMPUTER.COM
11 AugIran-Linked Hackers Target More US Water Infrastructure in New Jersey and AlabamaIran-linked hackers targeted Water Infrastructure in New Jersey and Alabama, bringing confirmed attacks to at least 12 states, with limited disruption. The wave of cyberattacks targeting US water infrastructure has reached New Jersey and Alabama, bringing the confirmed count to a…SECURITYAFFAIRS.COM
11 AugRansomware group hijacks hospital system’s Facebook page amid ongoing cyberattack falloutThe hackers claimed to have exfiltrated 6 terabytes of data, including highly sensitive health information like records related to sexual assault, mental health, abortions and sexual harassment incidents.THERECORD.MEDIA
11 AugA private route to public risk.Poland’s CERT describes winter cyberattack against heat-and-power plant. Russian military hackers target Ukrainian IT workers in fake recruitment scheme. Chinese IP connections spark security review in UK Navy drones. US and South Korea warn of “Gunra” ransomware gang with North …THECYBERWIRE.COM
11 AugDeadLock ransomware uses blockchain to resist infrastructure takedownThe DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims and data-leak activity. [...]BLEEPINGCOMPUTER.COM
10 AugNewcastle University confirms data breach after ExfilSquad claims 440k recordsNewcastle University has confirmed that a configuration issue affecting a connection to one of its admissions systems allowed unauthorized access to personal information, including names, addresses, email addresses, and telephone numbers. The disclosure follows a claim by the Exf…CYBERINSIDER.COM
10 AugCorporate Data Stolen in Levi Strauss CyberattackUsing social engineering, a threat actor accessed the computers of three employees and exfiltrated data from them. The post Corporate Data Stolen in Levi Strauss Cyberattack appeared first on SecurityWeek .SECURITYWEEK.COM
10 AugThree interviews: system fragility, operational clarity, and Identity for AI agents - ESW #471Interview 1: Robin Macfarlane from RRMac Associats The Mattress Money Principle: What a 50-Year Veteran Knows About System Fragility In this interview, Robin and Adrian discuss how technology has evolved over the past 50 years. Despite massive technological changes over the decad…YOUTUBE.COM
10 AugValve notifies Steam hardware customers of a data breachVideo game publisher and digital distribution giant Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, CEVA Logistics. [...]BLEEPINGCOMPUTER.COM
10 AugNew Jersey, Alabama Join States Targeted in Water CyberattacksHackers linked to Iran targeted industrial control systems (ICS) at water facilities in at least a dozen US states. The post New Jersey, Alabama Join States Targeted in Water Cyberattacks appeared first on SecurityWeek .SECURITYWEEK.COM
10 AugValve warns Steam users in Europe of data breach at shipping partnerValve is warning Steam customers in Europe that their personal and delivery information may have been compromised in a cyberattack targeting CEVA Logistics, the company responsible for shipping Steam hardware to European buyers. According to a security notification sent by Valve,…CYBERINSIDER.COM
10 Aug9.2 Million Israeli Records Sold as a New Breach Are 20 Years OldA seller claims to offer Israel’s 2026 population registry, but checks show the 9.2 million records are authentic data dating back to 2005. A vendor on a well-known leak forum claims to have breached Israel’s Population and Immigration Authority and is selling the entire na…SECURITYAFFAIRS.COM
10 AugA data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyondCompanies that rely on Ceva Logistics for shipping their physical goods to customers say their personal data was taken during a recent cyberattack.TECHCRUNCH.COM
10 AugWordPress Plugins Compromised Without a Single File ChangePoisoned JSON feed let attackers backdoor WordPress sites without changing any plugin filesINFOSECURITY-MAGAZINE.COM
10 AugOpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack ConcernsThe current GPT-5.6-Sol has been assigned a ‘high’ cybersecurity threshold, but Astra could reach the maximum ‘critical’ threshold. The post OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns appeared first on SecurityWeek .SECURITYWEEK.COM
10 AugCyberattack on Steam hardware shipper leaks names, addresses, and order dataVideo game publisher Valve is alerting customers in Europe to a data breach at CEVA Logistics, its Steam hardware shipping partner. Reports from affected customers began surfacing on social media earlier today, after Valve started sending out data breach notification emails. R…HELPNETSECURITY.COM
10 AugDeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructureMicrosoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion tactics used to pre…MICROSOFT.COM
10 AugHackers Cross From IT to OT Through a Private APN in PolandAttackers breached a Polish CHP plant through a Fortinet device and private APN, reaching PLCs and disrupting turbine and water treatment systems. Poland’s CERT has described a second attack on the country’s energy sector, and this one matters for a simple reason: it shows how an…SECURITYAFFAIRS.COM
10 AugNew StormEncryptor ransomware used by former Medusa affiliateA financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. [...]BLEEPINGCOMPUTER.COM
10 AugFBI, South Korea warn of Gunra ransomware gang targeting critical infrastructureThe Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned.THERECORD.MEDIA
10 AugU.S., South Korean government agencies caution to be on lookout for Gunra ransomware gangThe ransomware-as-a-service outfit has gone after a range of critical infrastructure sectors across the globe. The post U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang appeared first on CyberScoop .CYBERSCOOP.COM
10 AugGym Booking Task Turns Into Real-World AI CyberattackAn AI agent hacked a gym booking system while trying to help a user, booking early and removing another person from the waitlist. An Australian man asked his AI assistant to book him into a gym class. He didn’t ask it to hack the booking software, and he definitely didnR…SECURITYAFFAIRS.COM
10 AugHackers breached a small Polish energy plant via private APN last yearHackers breached a heat-and-power plant facility in Poland, which supplies heat to about 50,000 residents, using a private APN (Access Point Name) to access an OT (Operational Technology) network. [...]BLEEPINGCOMPUTER.COM
9 AugU.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled DataIEH was breached by a phishing attack that exposed its Microsoft 365 inbox, including emails and potentially export-controlled military data. IEH Corporation is a U.S. defense and aerospace manufacturer based in Brooklyn, New York. The company specializes in high-reliability elec…SECURITYAFFAIRS.COM
8 AugA little help from your search engine.Today we are joined by Brian Hussey, SVP of Howler Cell Threat Services at Cyderes, discussing their work on "Bad Ads, Worse Binaries: Fake Claude Code Installer Drops Infostealer." Howler Cell identified an SEO poisoning campaign targeting people searching for Claude Code in…THECYBERWIRE.COM
8 AugFlock’s Plans for Rideshare Dashcams and Coaching Police, RevealedPlus: A judge rules cell tower dumps unconstitutional, water utility hacks spread to a dozen states, a phishing email opens a missile-parts supplier’s inbox, and a ransomware boss gets 16 years.WIRED.COM
8 AugBrinks Home - 732,162 breached accountsIn July 2026, Brinks Home was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data they alleged was taken from the company, including 732k unique email addresses and other personal information relating to leads, customers and Brinks …HAVEIBEENPWNED.COM
7 AugRisky Bulletin: A Meta AI model also escaped a testing sandboxA Meta AI model also escaped a testing sandbox, a cyberattack disrupts ports in North Carolina, the Philippines will establish a cybersecurity agency, and a Ransom Cartel admin gets 16 years in prison.RISKY.BIZ
7 AugExact Sciences - 10,869,543 breached accountsIn July 2026, Exact Sciences (now owned by Abbott Laboratories) was the target of a ShinyHunters "pay or leak" extortion campaign . The group claimed to have obtained data from the company's cancer diagnostics business, which they later published publicly. The breach contained 10…HAVEIBEENPWNED.COM
7 Aug3.8 Million Impacted by Unlimited Technology Systems Data BreachHackers stole personal, medical, and health insurance information from a company’s data center. The post 3.8 Million Impacted by Unlimited Technology Systems Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
7 AugRansomware Surges in July After Q2 LullFinance, technology and healthcare sectors were particularly heavily targeted in July, according to ComparitechINFOSECURITY-MAGAZINE.COM
7 AugHealthcare and Victim Support Charities Affected by Beacon Cyber IncidentBeacon has informed around 1500 customer charities that its CRM databases were accessed and likely exfiltrated by an unauthorized actorINFOSECURITY-MAGAZINE.COM
7 AugFrench rugby club Stade Français restores systems after cyberattack, probes data leakThe club said Thursday that it had already restored its IT environment from clean backups, allowing operations to continue normally. It added that its ticketing platform and online store were not affected and remain fully operational.THERECORD.MEDIA
7 AugUnlimited Technology Systems data breach impacts 3.8 million peopleUnlimited Technology Systems, a healthcare software and revenue cycle management provider, has suffered a data breach affecting more than 3.8 million people. The HHS Office for Civil Rights lists the Ohio-based company as a business associate and says the hacking incident affecte…CYBERINSIDER.COM
7 AugLevi Strauss says hackers breached employee computers, accessed corporate dataIntruders exfiltrated certain corporate information after gaining access to three company-issued computers through a social engineering attack, Levi Strauss reported.THERECORD.MEDIA
7 AugNorth Carolina Ports confirms cyberattack disrupting operationsThe North Carolina Ports Authority has confirmed that a cyberattack disrupted IT systems and slowed operations at Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. [...]BLEEPINGCOMPUTER.COM
7 AugCoast Guard says it is monitoring cyberattack that disrupted North Carolina’s portsThe cyberattack hit gate systems at all three North Carolina ports, as officials continue investigating the breach and its effects on operations. The post Coast Guard says it is monitoring cyberattack that disrupted North Carolina’s ports appeared first on CyberScoop .CYBERSCOOP.COM
7 AugReal emails, hijacked payments: Two H1 2026 attack chainsGen's H1 2026 Threat Report examines two separate attack chains. One used compromised business inboxes and browser manipulation in a banking-malware campaign, while the other used clipboard hijacking to redirect cryptocurrency payments. [...]BLEEPINGCOMPUTER.COM
7 AugIn Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall StreetNoteworthy stories that might have slipped under the radar: ban on Chinese data center tech, QuickFox VPN supply chain attack, IEH Corporation mailbox breached via phishing. The post In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall St…SECURITYWEEK.COM
7 AugIrregular, firm behind AI hacking incidents, won't say if there were moreA spokesperson said Irregular’s investigation into what happened with Anthropic, OpenAI and Meta's AI models was ongoing and that they could not “go into further details.”THERECORD.MEDIA
7 AugLevi Strauss & Co. says hackers stole corporate data in cyberattackLevi Strauss & Co. (Levi's) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines. [...]BLEEPINGCOMPUTER.COM
7 AugComputer maker Framework notifies ‘all customers’ of a data breachFramework told "all" of its customers that hackers accessed their names, email addresses, phone numbers, and physical addresses in a data breach.TECHCRUNCH.COM
7 AugSecuring your Amazon S3 buckets: Identifying and remediating over-permissioned accessMisconfigured Amazon Simple Storage Service (Amazon S3) buckets can expose your data to unauthorized access. Without proactive review, S3 bucket policies or Access Control Lists (ACLs) configured with broad access may go unnoticed in your environment. In this post, you learn how …AWS.AMAZON.COM
7 AugMilitary device manufacturer discloses cyber incident to SECIEH Corporation — which produces specialized products used in military satellites, missiles and fighter jets — said it discovered a cyberattack on Tuesday and immediately tried to contain it.THERECORD.MEDIA
7 AugHackers Impersonate IT Support to Breach Leading Financial CompaniesHackers used fake IT help desks to steal MFA credentials, targeting over 200 firms, including major financial companies. A hacking campaign operating under names including Redact, Pink, Falcon, and Helix has built credential-stealing websites targeting employees at Blackstone, Br…SECURITYAFFAIRS.COM
7 AugUNC6671 Vishing Attacks Target Personal Phones to Steal SaaS DataA recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671. "UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff fac…THEHACKERNEWS.COM
7 AugUnlimited Technology Systems breach impacts 3.8 million peopleHealthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025. [...]BLEEPINGCOMPUTER.COM
6 AugShai-Hulud strikes again: CHAINDROP worm hits 400+ npm packagesElastic Security Labs identified the return of Shai-Hulud. Attackers compromised the keyv maintainer and deployed CHAINDROP, a worm that uses stolen npm credentials to backdoor co-owned packages totaling over 1.3 billion monthly downloads.ELASTIC.CO
6 AugOpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking SpreeAt the Black Hat security conference, the AI giant revealed new details about how its agents went rogue, hacked several other companies—and did it all right under the company’s nose.WIRED.COM
6 AugTracking people, training AI.This week, Ben and Ethan discuss two major stories. The first involves an incident where a police officer was abusing his access to Flock camera databases to track a former partner's movement. The second looks at recent research that found that Chinese military research units hav…THECYBERWIRE.COM
6 AugSnowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million PeopleConnor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts. The intrusions reached at least 165 organizations and exposed records …THEHACKERNEWS.COM
6 AugSnowflake Hacker Pleads Guilty After Breaching 165 Companies and Stealing Billions of RecordsSnowflake hacker Connor Moucka pleads guilty after breaching 165 organizations, stealing billions of records, and extorting victims. Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty this week to a computer hacking conspiracy that compromised over 165 organizations, …SECURITYAFFAIRS.COM
6 AugRansom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-ServiceA federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel, the ransomware-as-a-service operation he stood up in 2021. Between 2021 and 2023, Ransom Cartel conspirators attacked at least 18 companies…THEHACKERNEWS.COM
6 AugThe water sector just got it’s wake-up call. Again.The attack on water systems across seven states was preventable. Utilities had the playbook. They didn't use it. The post The water sector just got it’s wake-up call. Again. appeared first on CyberScoop .CYBERSCOOP.COM
6 AugMeta AI Hacked External Systems During Cybersecurity TestingThe incident involved a testing environment set up by Irregular, similar to what Anthropic reported last week. The post Meta AI Hacked External Systems During Cybersecurity Testing appeared first on SecurityWeek .SECURITYWEEK.COM
6 AugOver 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack CitiesForescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network. Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, includin…THEHACKERNEWS.COM
6 AugBelarusian cybercriminal behind Ransom Cartel gets 16-year prison sentenceA Belarusian national active in the cybercriminal world for decades was sentenced to 16 years in U.S. prison for running the Ransom Cartel ransomware operation.THERECORD.MEDIA
6 AugMeta's AI escaped sandbox and hacked external systems.Researchers identify backdoor in Chinese-made routers. Snowflake hacker pleads guilty.THECYBERWIRE.COM
6 AugRansom Cartel Leader Sentenced to 16 Years in U.S.A U.S. court sentenced Ransom Cartel founder Maksim Silnikau to 16 years for running a ransomware-as-a-service operation. Maksim Silnikau (aka “J.P. Morgan,” “lansky,” and “xxx,”) built a ransomware business the way a franchise owner builds a c…SECURITYAFFAIRS.COM
6 AugMeta AI model hacked a company during misconfigured cyber testMeta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents continue to emerge following OpenAI'sOpenAI's initial disclosure that its agents breached Hugging Face. [...]BLEEPINGCOMPUTER.COM
6 AugCyberattack on North Carolina Ports ‘contained’ as Coast Guard, state officials investigateNorth Carolina Ports is recovering from a cyberattack after its IT system was “hacked by an outside actor or group,” requiring a switch to manual processing of operations.THERECORD.MEDIA
6 AugRoute Amazon Bedrock Guardrails interventions to Amazon Security LakeSecurity teams investigating AI-related incidents need guardrail intervention data alongside their existing security telemetry. Routing Amazon Bedrock Guardrails violations to Amazon Security Lake makes this possible. With this integration, you can query guardrail events alongsid…AWS.AMAZON.COM
6 AugChina researchers using US AI models for defense systems.US water system cyberattacks continue to grow.THECYBERWIRE.COM
6 AugHedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion groupA recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile campaign extortion group. [...]BLEEPINGCOMPUTER.COM
5 AugInside the North American Water Utility Hacking CrisisInside the North American Water Utility Hacking Crisis: Iran Links, PLC Tactics, Insurance Fallout, and Volunteer Fixes This special Cybersecurity Today episode examines the expanding wave of water utility intrusions across North America, including a WIRED-obtained memo linking a…CYBERSECURITYTODAY.LIBSYN.COM
5 AugWhat stops attackers wrecking industrial plants is knowing howEngineers at an Israeli food producer spent most of a week rebuilding a refrigeration system after an intruder switched the gas cooler and receiver valves to manual and pinned them open. Liquid CO2 flooded the compressors and destroyed them. The replacement units did not match th…HELPNETSECURITY.COM
5 AugFake Bank of America Phishing Scam Installs Remote Access MalwareCybercriminals are using a fake Bank of America phishing campaign to trick users into downloading a malicious script that installs ScreenConnect, enabling remote access and persistence on compromised systemsINFOSECURITY-MAGAZINE.COM
5 AugWater Sector Cyberattacks Reportedly Hit at Least 12 StatesGeorgia has been confirmed as one of the attacked states after Clayton County reported a pump station disruption. The post Water Sector Cyberattacks Reportedly Hit at Least 12 States appeared first on SecurityWeek .SECURITYWEEK.COM
5 AugAngola's Largest Telco Breached Hours Before IPOUnitel, Angola's dominant mobile operator, continues to recover from a cyberattack that caused outages the day of the government-owned telco's public offering.DARKREADING.COM
5 AugOver 400 NPM Packages Infected in ChainDrop Supply Chain AttackThe malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials. The post Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack appeared first on SecurityWeek .SECURITYWEEK.COM
5 AugChainDrop Worm Hits 400+ npm Packages with Two Billion Monthly InstallsA new npm worm has compromised packages with over two billion monthly installsINFOSECURITY-MAGAZINE.COM
5 AugOpen VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer DataA cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed. The "evil twin" extensions were uploaded to the repository b…THEHACKERNEWS.COM
5 AugPrompt Injection Remains Biggest LLM Risk, Despite Limited IncidentsPrompt injection remains the most dangerous security threat to LLMs, according to OWASP’s latest Top 10 LLM Applications listINFOSECURITY-MAGAZINE.COM
5 Aug311,000 Impacted by Brown Health Medical Group-MA Data BreachHackers stole personal information, medical records, and financial information from the organization’s server. The post 311,000 Impacted by Brown Health Medical Group-MA Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
5 AugCybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident DataThe guidelines are the work of the recently launched Open Secure AI Alliance, which now includes 120 organizations. The post Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data appeared first on SecurityWeek .SECURITYWEEK.COM
5 AugCyberattacks on water systems expand to 12 states as South Dakota, Georgia announce incidentsWater utilities in at least 12 states have reported cyberattacks on their operational technology, as the scope of a campaign allegedly linked to Iranian hackers continues to grow.THERECORD.MEDIA
5 AugDutch retailer De Bijenkorf warns customer data may be exposed after cyber incidentAmsterdam-based luxury goods chain De Bijenkorf is the latest retailer to announce a cyber incident involving a third-party logistics provider.THERECORD.MEDIA
5 AugBrown Health Medical Group-MA Data Breach Exposes Information of 311,000 IndividualsBrown Health Medical Group-MA breach exposed personal, medical, and financial data of over 311,000 individuals after hackers accessed its servers. Brown Health Medical Group-MA data breach exposed personal, medical, and financial data of over 311,000 individuals after hackers acc…SECURITYAFFAIRS.COM
5 AugDon't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)When you learn that a compromised package executed on one of your build hosts, muscle memory takes over: revoke the npm token, rotate the GitHub PAT, cycle the cloud keys. That reflex has been correct in almost every supply-chain incident I have worked. In the keyv / cacheable co…ISC.SANS.EDU
5 AugTom Cotton prods Treasury for tax code tweaks to modernize OTThe Senate Intel Committee chair wrote to Treasury Secretary Scott Bessent about changes to spur investment in aging technology to better guard against cyberattacks. The post Tom Cotton prods Treasury for tax code tweaks to modernize OT appeared first on CyberScoop .FEDSCOOP.COM
5 AugWestern government leaders call for a focus on infrastructure resilience, not AI hypeU.S. and allied officials said companies should start preparing now for a cyberattack that changes how they provide essential services.CYBERSECURITYDIVE.COM
5 AugCanadian man pleads guilty to Snowflake hacks that led to 165 breachesA 26-year-old from Ontario faces as many as 32 years in prison after pleading guilty to fraud, identity theft and conspiracy charges related to the 2024 hacks of cloud platform Snowflake.THERECORD.MEDIA
5 AugCSS: The Hidden Threat Lurking in Your InboxCSS was once just about design. Now researchers warn it's powerful enough to exfiltrate data from webmail — and some vendors aren't prepared.DARKREADING.COM
5 AugSnowflake hacker pleads guilty, faces up to 32 years in prisonConnor Moucka obtained almost $500,000 for playing a key role in one of the most widespread and damaging cyberattack sprees on record. The post Snowflake hacker pleads guilty, faces up to 32 years in prison appeared first on CyberScoop .CYBERSCOOP.COM
5 AugA Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks WorldwideFor nearly two years, researcher Vangelis Stykas has maintained access to North Korean hackers’ servers. His work shows they pulled off intrusions in a shocking number of systems across the globe.WIRED.COM
5 AugInter-Con Security - 276,114 breached accountsIn June 2026, Inter-Con Security was targeted in a ShinyHunters “pay or leak” extortion campaign . The group subsequently published data it alleged was taken from the company, including 276k unique email addresses along with names, physical addresses, job titles and phone numbers…HAVEIBEENPWNED.COM
4 Aug31,000 Records Compromised in Breach of Liechtenstein Companies and Foundations RegisterCyberattack exposed data of 31,000 people in Liechtenstein’s beneficial ownership register for companies and foundations. A cyberattack compromised data belonging to about 31,000 people in Liechtenstein’s register of beneficial owners linked to companies, foundations,…SECURITYAFFAIRS.COM
4 AugUK’s Police National Legal Database Reveals Data BreachThe UK’s Police National Legal Database and Ask the Police service have been breachedINFOSECURITY-MAGAZINE.COM
4 Aug150,000 Impacted by Madera Community Hospital Data BreachAn extortion group stole personal, financial, and medical information from the hospital’s network. The post 150,000 Impacted by Madera Community Hospital Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
4 AugAI makes costly spearphishing attacks easier, cyber insurer saysDive Brief: Ransomware extortion caused roughly three-quarters of business losses in the first half of 2026, the cyber insurance firm Resilience said in a recent report. At the same time, ransomware accounted for less than 6% of the incidents for which Resilience customers submit…CYBERSECURITYDIVE.COM
4 AugSwiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspectedThe Federal Office for Information Technology and Communications (BIT) said specialists detected anomalies in on-premises Microsoft servers. The Swiss agency could not confirm exactly how the hackers got in.THERECORD.MEDIA
4 AugLawmakers spring to save ID theft services for OPM breach victims, with expiration loomingSen. Mark Warner, D-Va., and Del. Eleanor Holmes Norton, D-D.C., hope to make the services permanent before they end next month. The post Lawmakers spring to save ID theft services for OPM breach victims, with expiration looming appeared first on CyberScoop .CYBERSCOOP.COM
4 AugNew Shai-Hulud campaign compromises popular npm packages.Samsung bans smart TV apps with residential proxy code. Liechtenstein discloses breach of its Register of Beneficial Owners.THECYBERWIRE.COM
4 AugTech industry alliance proposes AI agent safety reporting programThe information-sharing exchange is designed to widely share lessons learned from agentic AI security incidents.CYBERSECURITYDIVE.COM
4 AugMassive ChainDrop npm supply-chain attack infects hundreds of packagesSelf-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. [...]BLEEPINGCOMPUTER.COM
4 AugPolish convenience store chain Żabka hacked through third-party accountReports said intruders appeared to gain access to the Jira environment and other sensitive data of the Żabka retail chain. The company confirmed an intrusion occurred in late July.THERECORD.MEDIA
4 AugIran Cyberattacks Against Minnesota Water SystemsAttribution is preliminary , and so far it seems no real damage. And it seems like this is a campaign that has targeted at least seven states . And, because this is where the US is right now, Trump doesn’t believe it’s Iran and that Minnesota…I guess…hacke…SCHNEIER.COM
4 AugNew XCSSET variant targets macOS devs via compromised Xcode projectsA new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories. [...]BLEEPINGCOMPUTER.COM
4 AugSmoke#Screen RMM Takeover Gambit Exposes Threat Actor PlaybookThe attacks use diverse social engineering lures and rotating payloads to deliver ScreenConnect for persistent remote access to compromised networks.DARKREADING.COM
4 Aug128 Seconds to disruption: Microsoft Defender stops ransomware at QNETMicrosoft Defender automatically isolated a compromised QNET endpoint in 128 seconds, stopping a multi-stage attack before the payload could persist or spread. The post 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET appeared first on Microsoft Security Blo…MICROSOFT.COM
4 AugChainDrop credential stealing worm infects over 400 npm packagesA self-propagating worm-like attack is hitting the npm registry, having infected 444 packages from more than a dozen publishers so far. The impact is massive, with the packages affected amounting to more than 2 billion monthly downloads combined. The attack began with the comprom…CSOONLINE.COM
4 AugRansomware Changed Its First TargetThis discussion highlights a shift in ransomware tactics. Rather than relying primarily on phishing or endpoint compromises, attackers are increasingly targeting weaknesses in network infrastructure to gain trusted access. Compromising infrastructure can give attackers a stronger…YOUTUBE.COM
4 AugChainDrop supply chain compromise: Anatomy of a self-propagating wormA credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates. This analysis details the attack chain, affected environments, and practical guidance for detection, hunting, and remedia…MICROSOFT.COM
3 AugWeekly Update 515Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite Apparently, Aussies are so obsessed with coffee that it's referred to as the coffee capital of the world down here (some bits, at …TROYHUNT.COM
3 AugRisky Bulletin: Anthropic models also did the hacky-hackyAnthropic models also did the hacky-hacks, Coldcard was hacked for $70 million in Bitcoin, npm adds publish-time malware scanning, and Russia is behind the recent hotel WiFi hacks.RISKY.BIZ
3 AugProduct showcase: Guardio Mobile Security turns breach alerts into a recovery planGuardio Mobile Security brings several protection features to iPhone and Android, allowing users to monitor exposed personal information, identify phishing attempts, and receive alerts about emerging threats from a single application. It is available on smartphones and tablets, w…HELPNETSECURITY.COM
3 AugCrowdStrike: AI is now both the weapon and the target in cyberattacksAI generates 2.5 signals for every human-triggered signal CrowdStrike has to assess. Meanwhile, attackers are using AI to weaponize vulnerabilities faster than companies can patch them. The post CrowdStrike: AI is now both the weapon and the target in cyberattacks appeared first …CYBERSCOOP.COM
3 AugUS Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other StatesMichigan, South Dakota, and Georgia are reportedly on the list of states whose water systems have been targeted by Iran-linked hackers. The post US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States appeared first on SecurityWeek .SECURITYWEEK.COM
3 AugElastic Defend now covers 800+ vulnerable drivers, with automated troubleshooting and ARM supportAttackers reaching for kernel access on a Windows machine bring a driver Microsoft already trusts. It is signed, it loads, and it carries a known flaw. That flaw gives them enough room to tamper with memory or disable the security software watching the host. Once an attacker hold…HELPNETSECURITY.COM
3 AugRussian State APT Linked to Recent Public Wi-Fi Gateway HackingMidnight Blizzard has been stealing Microsoft account credentials via compromised Wi-Fi networks at hospitality organizations. The post Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking appeared first on SecurityWeek .SECURITYWEEK.COM
3 AugPNLD Breach Exposes U.K. Police and Government Contact Details on Dark WebThe Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web. The data included names, organisations and work email addresses belonging to police officers, police staff, criminal jus…THEHACKERNEWS.COM
3 AugKorea’s Largest Telco KT Fined $38m After Femtocell CampaignKorean telco KT has been fined $39m for a year-long breach linked to femtocell compromiseINFOSECURITY-MAGAZINE.COM
3 AugBrinks Home Discloses Data Breach as Hackers Leak FilesThe physical security firm says its alarm monitoring and system functionality have not been affected. The post Brinks Home Discloses Data Breach as Hackers Leak Files appeared first on SecurityWeek .SECURITYWEEK.COM
3 AugFOMO in the SOC: Where AI Platforms like Claude Actually FitAI is moving incredibly fast, and every security leader is feeling the pressure to keep up. AI platforms like Claude, Codex and Cursor are already helping security teams write detections, investigate alerts, summarize incidents, and automate repetitive work. The conversation has …THEHACKERNEWS.COM
3 AugRiver Bank Says Hackers Deleted Data Stolen in Ransomware AttackThe bank holding company was hacked in June, but the investigation into the incident continues. The post River Bank Says Hackers Deleted Data Stolen in Ransomware Attack appeared first on SecurityWeek .SECURITYWEEK.COM
3 AugBiotech giant Amgen says patient data stolen from third-party cloud systemsThe biotech giant Amgen informed regulators that patient information and proprietary company data were accessed through a breach of third-party cloud systems.THERECORD.MEDIA
3 Aug3rd August – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30 community water utilities across the state. The i…RESEARCH.CHECKPOINT.COM
3 AugChinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable serversA Chinese threat actor operating under the aliases “knaithe” and “KnYuan” used multiple LLMs to automate cyberattacks against internet-facing systems with limited human intervention. Researchers at Palo Alto Networks’ Unit 42 uncovered the operation …HELPNETSECURITY.COM
3 AugHorizon3.ai hits $2 billion valuation in $250 million funding roundHorizon3.ai has announced a $250 million Series E at a valuation of more than $2 billion, tripling its valuation from $650 million at Series D in just over a year. The oversubscribed round was co-led by existing investors NightDragon and NEA, with participation from seven new inv…HELPNETSECURITY.COM
3 AugAn analysis of incidents at Brazilian educational institutionsKaspersky expert provides statistics and details on several incident response cases at educational institutions in Brazil, as well as tips for schools and universities on how to stay safe.SECURELIST.COM
3 AugExfilSquad hackers leak info of over 100,000 UK police officers, staffA cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals. [...]BLEEPINGCOMPUTER.COM
3 AugRiver Bank obtained assurances from the attackers that the stolen data in the June attack was deletedRiver Bank says hackers deleted data stolen in its June ransomware attack, though the investigation into the incident is still ongoing. River Financial Corporation, the parent company of River Bank & Trust, says hackers deleted data stolen during a ransomware attack that hit …SECURITYAFFAIRS.COM
3 AugWho’s legally to blame for Anthropic and OpenAI’s autonomous AI hacks? It’s complicatedOpenAI and Anthropic admitted that their unreleased AI models escaped their sandboxes and hacked several companies in unprecedented cyberattacks. Who is legally to blame? Should prosecutors charge the two AI frontier labs? Can victims sue them? We spoke to lawyers who specialize …TECHCRUNCH.COM
3 Aug[Webinar] Tales from the Frontlines: An exclusive briefing on Q2 incidentsRegister for an exclusive, unrecorded 30-minute webinar to review the most high-impact incidents Talos IR faced in Q2.TALOSINTELLIGENCE.COM
3 AugHackers steal 31,000 records identifying people behind Liechtenstein companies, foundationsA cyberattack compromised tens of thousands of records related to companies, foundations and trusts in Liechtenstein, prompting the government to to form a “crisis unit” to address the breach.THERECORD.MEDIA
3 AugCyberattack Hits Liechtenstein’s Register of People Behind Companies and FoundationsThe list of people behind companies, foundations and trusteeships is part of efforts to combat money laundering and terror financing. The post Cyberattack Hits Liechtenstein’s Register of People Behind Companies and Foundations appeared first on SecurityWeek .SECURITYWEEK.COM
3 AugAnthropic: AI Attacks Result of Security Gaps, Not Model IssuesLast month's incidents in which Claude breached real-world systems derived from over-permissioning, especially with Internet access.DARKREADING.COM
3 AugNew Pass-ta-key attacks let malware hijack Google-synced passkeysSecurity researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys to take over accounts, bypass user verification, and extract passkey private keys. [...]BLEEPINGCOMPUTER.COM
3 AugHotel Wi-Fi attacks use custom malware to breach Microsoft 365 accountsMicrosoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. [...]BLEEPINGCOMPUTER.COM
1 AugHealthcare Cybersecurity in 2026: Healthcare CISO Matt Burke on AI, MFA, SOCs & Incident ReadinessOn Cybersecurity Today on the Weekend, host David speaks with Matt Burke, CISO of Bespoke Concierge MD, a telemedicine provider with doctors licensed in all 50 states, about defending patient data amid rising healthcare threats in 2026. Burke explains why healthcare is heavily ta…CYBERSECURITYTODAY.LIBSYN.COM
1 AugThe hidden risks in space supply chains.As the space ecosystem continues to expand, the sector has become increasingly filled with new suppliers, manufacturers, and operators. However, while this development has led to the introduction of new technologies, it has also greatly expanded space's cyberattack surface. In th…THECYBERWIRE.COM
1 AugSplitVPN - 865,336 breached accountsIn July 2026, the Russian VPN service SplitVPN (previously known as NotVPN) suffered a data breach . The incident exposed millions of customer records, including 865k unique email addresses. Other impacted data included IP addresses, the user's country, and partial payment card d…HAVEIBEENPWNED.COM
1 AugHackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer SitesAttackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and repor…THEHACKERNEWS.COM
1 AugNobody Knows if OpenAI’s and Anthropic’s AI Hacking Sprees Are IllegalBoth major AI labs’ models broke containment, escaped onto the internet, and hacked other companies. If a human had done that, the law would likely be against them. But a bot?WIRED.COM
1 Aug7 States’ Water Systems Hit by Cyberattacks Likely Tied to IranPlus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.WIRED.COM
31 JulAnthropic says its AI accidentally hacked three companies during safety testsFollowing OpenAI’s own incident, Anthropic reviewed its own evaluations and found three cases of Claude hacking external companies. The post Anthropic says its AI accidentally hacked three companies during safety tests appeared first on CyberScoop .CYBERSCOOP.COM
31 JulAnthropic Says Claude Hacked 3 Organizations During Cybersecurity TestsIn a review triggered by OpenAI’s Hugging Face incident, Anthropic discovered three of its AI models had breached real organizations during third-party evaluations.WIRED.COM
31 JulRisky Bulletin: Crime Stoppers puts bounty on INC ransomware groupA non-profit puts a $22,000 bounty on the INC ransomware group, hackers breach the UK Department for Education, Russia charges Telegram founder Pavel Durov, and the FCC bans foreign robots and power inverters.RISKY.BIZ
31 JulCareCloud Data Breach Impacts Over 350,000In March 2026, hackers stole personal, financial, and medical information from the company’s AWS environment. The post CareCloud Data Breach Impacts Over 350,000 appeared first on SecurityWeek .SECURITYWEEK.COM
31 JulAnthropic Reveals Claude Escaped Testing, Breaching Three CompaniesAnthropic has revealed that Claude AI models broke free of sandbox to compromise third-party organizationsINFOSECURITY-MAGAZINE.COM
31 JulPrompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 OrganizationsA security company’s systems were hacked after it installed a malicious Python package deployed by Claude. The post Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations appeared first on SecurityWeek .SECURITYWEEK.COM
31 JulAnthropic says its AI hacked real-world companies in three incidentsClaude maker Anthropic said its AI models escaped test environments and breached networks at three companies on the open internet.THERECORD.MEDIA
31 JulESET tracks rise in malicious AI skills and adaptable malwareAttackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET's new threat report examines the rise of malicious AI skills, AI-assisted malware, ClickFix attacks, record quishing activity, and ransomware tools designed to d…BLEEPINGCOMPUTER.COM
31 JulCyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian HackersIran has the “geopolitical motivations” and a recent history of targeting water systems, experts pointed out. The post Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers appeared first on SecurityWeek .SECURITYWEEK.COM
31 JulTrump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber worldThe president went against his intelligence agencies’ conclusions about Iran being the likely suspect in the campaign. The post Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world appeared first on CyberScoop .CYBERSCOOP.COM
31 JulRogue AI, the Bar, Breaches, BMC, Hugging Face, Helmuth von Multke, Ike, Shieldfont, - SWN #603Rogue AI, the Bar, Breaches, BMC, More Hugging Face, Helmuth von Multke, Ike, Shieldfont, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-603YOUTUBE.COM
31 JulOnline ad firm Adform’s script compromised to steal cryptocurrencyOnline advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones controlled by an attacker. [...]BLEEPINGCOMPUTER.COM
31 JulAmgen says cloud data breach exposed patient health, proprietary infoPharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. [...]BLEEPINGCOMPUTER.COM
30 JulDealing with AI-Generated ExtortionCombat AI-generated extortion and fake ransomware leaks. Learn how organizations can verify data authenticity using robust governance and threat intelligence.RECORDEDFUTURE.COM
30 JulAmazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire SleetAmazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as crypto theft: a maintainer phished through a lookalike npm domain and a wallet-draining script pushed into at least 18 packages c…THEHACKERNEWS.COM
30 JulToy Ghouls’ new toy: the GenieLocker ransomwareKaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks by Toy Ghouls, a financially motivated extortion group.SECURELIST.COM
30 JulSrsly Risky Biz: Chipping away at Chinese AI risksTom Uren and James Wilson talk about open-weight AI models and distillation. These topics have been subject to a lot of US government attention in recent weeks, but let’s not forget that America’s overriding goal is to remain ahead of China in the AI race. There are better ways t…RISKY.BIZ
30 JulCoordinated cyberattack hits more than 30 Minnesota water utilitiesA coordinated cyberattack on July 26 and 27 hit operational technology (OT) systems at more than 30 community water utilities across Minnesota, prompting an immediate response from Minnesota IT Services (MNIT) to contain the threat. MNIT confirmed the attack in a statement publis…HELPNETSECURITY.COM
30 JulOpenAI’s Hacking Debacle Was a Human MistakeIf the generative AI giant had followed well-known security best practices, it’s likely that its AI agent would never have escaped to the open internet and hacked multiple companies.WIRED.COM
30 JulSemiconductor Firm Analog Devices Discloses Data BreachHackers were detected on Analog Devices systems in June, and an investigation found that they stole files. The post Semiconductor Firm Analog Devices Discloses Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
30 JulThe Network Has Become the Control Plane for AI SecurityNetwork firewalls are the workhorses of modern cybersecurity. They are trusted to protect the network, blocking malicious traffic and preventing intrusions and breaches. And for decades, network security teams have built controls around a relatively stable model: users connect to…THEHACKERNEWS.COM
30 JulAfter the Break-In: What Attackers Do Once They're Already InsideAttackers rarely stop after gaining initial access. Huntress analyzes a real-world intrusion to show how threat actors establish persistence, disable defenses, and reshape compromised systems, and why defenders must investigate the original entry point rather than simply remove t…BLEEPINGCOMPUTER.COM
30 JulIn the Hugging Face breach, OpenAI’s hacker was noisy and fast — but not unstoppableCybersecurity experts told TechCrunch that one of the biggest lessons to be taken from the OpenAI hack against HuggingFace has nothing to do with AI, but traditional cybersecurity defense.TECHCRUNCH.COM
30 JulNorth Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warnCyberattack tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations — further evidence of deepening entanglement between Pyongyang-backed hackers and the ransomware ecosystem.THERECORD.MEDIA
30 JulHackers abuse Microsoft Teams in ransomware campaign through fake IT supportResearchers said dozens of US and Canadian firms have been targeted, however, the motivation appears to be financial rather than espionage.CYBERSECURITYDIVE.COM
30 JulMicrosoft Teams vishing attacks lead to Chaos ransomware attacksThreat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations. [...]BLEEPINGCOMPUTER.COM
30 JulAnalog Devices discloses data breach, says operations unaffectedAmerican semiconductor company Analog Devices announced that an unauthorized party accessed some of its systems and exfiltrated certain files. [...]BLEEPINGCOMPUTER.COM
30 JulChina lists open AI models as national security concern.Cyberattack on Minnesota water systems more extensive than original estimates.THECYBERWIRE.COM
30 JulSemiconductor chip titan Analog Devices reports data breachIn a filing for federal regulators, Massachusetts-based Analog Devices said intruders had exfiltrated data from its networks earlier this summer, but the scope of the incident is still under investigation.THERECORD.MEDIA
30 JulA Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to IranA memo obtained by WIRED, issued by the water utilities information sharing group WaterISAC, links dozens of cyberattacks against Minnesota water utilities to Tehran.WIRED.COM
30 JulSouth Korea fines telco giant KT $39 million for customer data breachSouth Korea's Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53.979 billion ($39 million) over data protection violations. [...]BLEEPINGCOMPUTER.COM
30 JulClaude uploaded malware to PyPI in Anthropic's botched testOne of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. [...]BLEEPINGCOMPUTER.COM
30 JulAnthropic's Claude breached 3 orgs, uploaded PyPI malware during testsOne of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. [...]BLEEPINGCOMPUTER.COM
29 JulOpenAI’s Rogue AI Agent Hacked More Than Just Hugging FaceIn a new disclosure, OpenAI says its agent used exposed logins to gain access to at least four “publicly available services” in its unhinged quest to solve a test.WIRED.COM
29 JulTwo Compromised joyfill npm Packages Run RAT When Imported Into Node.jsBeta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The list of affected packages is as follows - @joyfill/layouts@0.1.2-2773.beta.0 @joyfill/components@4.…THEHACKERNEWS.COM
29 JulThe energy sector’s OT cybersecurity talent is retiring faster than it can be replacedA ransomware hit lands a chemical plant in a safe state. Nobody is hurt, the site holds steady, and the operators begin the restart. The systems stay down. Every attempt to bring them online meets encrypted processes and altered configurations. The outage runs into weeks, and the…HELPNETSECURITY.COM
29 JulOpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face BreachOpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face's production environment, and also hacked multiple third-party accounts and services as part of the attack. The latest disclosure sho…THEHACKERNEWS.COM
29 JulRisky Business #846 -- OpenAI built a fireplace out of woodOn this week’s show special guest co-host Pete Ranks, the former director of the CIA’s Centre for Cyber Intelligence, joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover: Everyone signs the open weights open letter, except Anthropic… of course…RISKY.BIZ
29 JulRisky Bulletin: Cyberattack disrupts Minnesota water utilitiesA cyberattack has disrupted water utilities in more than 30 communities in Minnesota, Denmark tests a secondary banking system in case of a cyberattack, North Korea arrests bank hackers, and a new Chinese cyber contractor has been identified.RISKY.BIZ
29 JulVPN Breach Exposes 58 Million Connection Logs Despite “No-Logs” ClaimsA breached “no-logs” VPN exposed 58 million connection logs and millions of user, device, and payment records, contradicting its privacy claims. A threat actor on the Altenen cybercrime forum is distributing a 17 GB SQL database claimed to have been stolen from SplitV…SECURITYAFFAIRS.COM
29 JulOpenAI’s rogue AI agent shows why we need federal rules for autonomous systemsThe Hugging Face breach shows there is a gap in federal policy. The frameworks to govern autonomous AI already exist—there just needs to be the desire to apply them. The post OpenAI’s rogue AI agent shows why we need federal rules for autonomous systems appeared first on Cy…CYBERSCOOP.COM
29 JulOver 30 water systems in Minnesota hit by coordinated cyberattackMinnesota officials have activated a statewide cybersecurity response after a coordinated cyberattack targeted the operational technology (OT) of more than 30 community water systems across the state. Authorities say there is currently no indication that residents need to alter t…CYBERINSIDER.COM
29 JulOpenAI’s Rogue AI Agent Breached Second Company, Report SaysReuters says OpenAI’s rogue AI agent also breached a Modal customer, exposing a wider attack and raising fresh concerns over autonomous AI safety. Reuters reported that the OpenAI agent that hacked Hugging Face earlier this month also compromised a customer at a second comp…SECURITYAFFAIRS.COM
29 JulThe Average Cost of a Data Breach Rises to $5 MillionIBM Cost of a Data Breach Report warns that the global average cost of a data breach has reached a record high of $4.99m – and AI-backed attacks have played a roleINFOSECURITY-MAGAZINE.COM
29 Jul73% of Organizations Say They Are Not Fully Ready for a Major CyberattackMost organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the coordination, visibility, and executive alignment needed to withstand a serious cyberattack. According to The State of Incident Respon…THEHACKERNEWS.COM
29 JulCyberattack hits Angola’s largest telco hours before landmark stock debutAngola’s largest telecommunications operator, Unitel, was hit by a cyberattack that has left millions of people nationwide without voice services, mobile data, and internet access.THERECORD.MEDIA
29 JulStairwell launches Backstory, pioneering agentic investigation for malware blast radiusStairwell, the AI SOC that stops breaches no one else can, today announced the availability of Backstory, an agentic investigation platform that traces related malware variants, identifies affected systems, and maps the full blast radius of an incident in seconds, so enterprises …HELPNETSECURITY.COM
29 JulCoordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes OfflineA coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. Braham, Plymouth, South St. Paul and Maple Plain have publicly described a plant outage, communications fa…THEHACKERNEWS.COM
29 JulOpenAI explains how its AI agent breached Hugging FaceOpenAI has published an update on the incident in which one of its agents escaped its sandbox and accessed Hugging Face infrastructure.MALWAREBYTES.COM
29 JulAs data breaches grow costlier, ungoverned AI creates new risksMeanwhile, many companies still aren’t doing the basics to protect on-premises data, IBM found.CYBERSECURITYDIVE.COM
29 JulHackers target over 30 Minnesota water utilities in coordinated OT attackThe Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities across the entire state after hackers targeted more than 30 community water systems in "a coordinated cyberattack." [...]BLEEPINGCOMPUTER.COM
29 JulOpenAI agent used exposed credentials at 4 services in Hugging Face breachIn a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other organizations. [...]BLEEPINGCOMPUTER.COM
29 JulWho's Liable When AI Agents Escape? Hugging Face Breach Raises Hard QuestionsDark Reading walks through the many twists and turns in the bizarre story of how OpenAI's agent AI system broke out of its sandbox and decided to target Hugging Face, and what CISOs should be aware of.DARKREADING.COM
29 JulHackers Strike Minnesota Water Utilities, One Plant Briefly OfflineCoordinated OT cyberattacks hit 30+ Minnesota water utilities, briefly disrupting one plant. Backup procedures prevented major water service impacts. Minnesota just had its own live-fire lesson in what happens when someone targets water utilities at scale. Between Sunday and Mond…SECURITYAFFAIRS.COM
28 JulFor Some, So-Called ‘Skynet Day’ Came too Close to Sci-Fi After a Rogue Agent Hacked Into a StartupDecades after it appeared in “The Terminator,” Skynet looks more like a forecast of the cyber incident in which a rogue AI system hacked into another AI company on its own. The post For Some, So-Called ‘Skynet Day’ Came too Close to Sci-Fi After a Rogue Agent Hacked Into a Startu…SECURITYWEEK.COM
28 JulOrigin Energy Data Breach Affects 900,000 AustraliansThe hacker claimed to have stolen the information of 2 million Origin Energy customers after breaching its systems. The post Origin Energy Data Breach Affects 900,000 Australians appeared first on SecurityWeek .SECURITYWEEK.COM
28 JulShadow AI incident response begins with logs that may already be goneIn this Help Net Security interview, Brandy Wityak, VP of Complex Matters at LevelBlue, explains what happens in the hours after a shadow AI incident. She describes how quickly logs roll over, why firewall records of outbound traffic to AI platforms are often gone before responde…HELPNETSECURITY.COM
28 JulHouston City College - 831,642 breached accountsIn June 2026, Houston City College was the target of a ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from the college was later published publicly and included 832k unique email addresses along with names, addresses, phone numbers, academic records, and …HAVEIBEENPWNED.COM
28 JulCoca-Cola confirms hackers stole data in Fairlife ransomware attackCoca-Cola has confirmed that the ransomware attack on its dairy subsidiary Fairlife involved the theft of company data, weeks after the incident temporarily halted production at its US facilities. Fairlife is a Coca-Cola-owned dairy brand that makes ultra-filtered milk and protei…HELPNETSECURITY.COM
28 JulCoca-Cola Reveals Subsidiary Fairlife Suffered Data BreachCoca Cola claims data was stolen from its Fairlife business after a recent ransomware attackINFOSECURITY-MAGAZINE.COM
28 JulVERITAS project could change the way scientists secure AIThe AI models, datasets, and automated systems researchers depend on can be compromised in ways conventional cybersecurity tools aren’t designed to detect. A new project called VERITAS (VERified Infrastructure for Trustworthy AI in Science) aims to close that gap by establi…HELPNETSECURITY.COM
28 JulTeam Cymru unveils Pure Signal Command for AI-powered threat intelligence and incident responseTeam Cymru has announced Pure Signal Command, the connected operating environment for analysts, security teams, applications, and AI agents to access and act on Team Cymru’s internet infrastructure intelligence. Command unlocks Team Cymru’s globally observed threat intelligence d…HELPNETSECURITY.COM
28 JulPhishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion TechniquesAnalysis of real-life incident response cases by Cisco Talos warns that phishing remains a powerful method of initial compromiseINFOSECURITY-MAGAZINE.COM
28 JulIs Your SSO Protected Against Modern Credential Attacks?A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening help secure modern SSO environments and the applications they protect. [...…BLEEPINGCOMPUTER.COM
28 JulIndia’s Bank of Baroda confirms cyber incident after hackers claim data theftAn employee's email account had been compromised, allowing unauthorized access to "certain data," Bank of Baroda reported.THERECORD.MEDIA
28 JulHugging Face breach reignites open-weights debate, raises liability questionsThe first publicly documented cyberattack run end-to-end by an autonomous AI was an OpenAI benchmark test that escaped its sandbox and breached Hugging Face. In an incident post-mortem compiled with the input from Hugging Face and several hundred members of Cloud Security Allianc…HELPNETSECURITY.COM
28 JulCoordinated cyberattack disrupts water utilities in 30+ Minnesota communitiesA cyberattack of undetermined origin disrupted water treatment plants in at least 30 communities in Minnesota, according to the state's technology bureau. The post Coordinated cyberattack disrupts water utilities in 30+ Minnesota communities appeared first on CyberScoop .STATESCOOP.COM
28 JulYou've been disconnected.A senator targets legacy VPNs. Minnesota water systems come under cyberattack. A 20-year-old flaw exposes 24,000 servers. Microsoft debuts its first cybersecurity AI model. A critical VeloCloud bug is under active attack. The Dysphoria botnet tops 200,000 devices. Apple faces a l…THECYBERWIRE.COM
28 JulStack Sports warns users after payment card data exposed through malicious codeSports technology provider Stack Sports is notifying users of a cybersecurity incident that may have exposed payment card information entered through its Sports Affinity web application platform. According to a data breach notification sent to affected individuals, Stack Sports d…CYBERINSIDER.COM
28 JulAuthorities investigating a coordinated cyberattack against Minnesota water systemsThe two-day attack comes days after federal officials warned of state-linked threat groups targeting a wider set of industrial devices.CYBERSECURITYDIVE.COM
27 JulMCBS Data Breach Affects 1.2 Million IndividualsThe PEAR ransomware group claimed to have stolen 3 TB of information from the medical business management company. The post MCBS Data Breach Affects 1.2 Million Individuals appeared first on SecurityWeek .SECURITYWEEK.COM
27 JulWhat the identity attack surface looks like when trust becomes the targetIn this Help Net Security video, Joel Moses, VP, Strategic Engineering at F5, explains how attackers use identity instead of breaking through it. He walks through MFA fatigue, session token theft, and consent given to malicious applications, using the 2022 Uber breach as an examp…HELPNETSECURITY.COM
27 JulLockBit5 and Qilin Lead Ransomware Attacks Against Italian OrganizationsA new report links 148 ransomware attacks to Italian organizations in H1 2026, with manufacturing the most targeted sector. Six months, 148 confirmed ransomware claims against Italian targets, and one sector taking the brunt of it. That’s the headline number from a new semi…SECURITYAFFAIRS.COM
27 JulRansomware Groups Increasingly Deploy EDR Kill TechniquesHalcyon’s latest quarterly ransomware report showed that while ransomware attacks are declining, obfuscation techniques are getting harder to fight againstINFOSECURITY-MAGAZINE.COM
27 JulDentaQuest Data Breach Potentially Impacts Over 23 Million PeopleIn May 2026, hackers stole personal and dental health information from DentaQuest’s computer network. The post DentaQuest Data Breach Potentially Impacts Over 23 Million People appeared first on SecurityWeek .SECURITYWEEK.COM
27 JulHacked Public Wi-Fi Gateways Used to Harvest Corporate CredentialsA threat actor has been using the compromised appliances to target the Microsoft 365 accounts of traveling corporate employees. The post Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials appeared first on SecurityWeek .SECURITYWEEK.COM
27 JulCoca-Cola Confirms Data Breach After Fairlife Ransomware AttackThe Anubis cybercrime group has taken credit for the attack and is threatening to leak data. The post Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack appeared first on SecurityWeek .SECURITYWEEK.COM
27 JulMedusaHVNC Malware Uses Hidden Windows Desktops to Evade DetectionThe malware-as-a-service operation launches legitimate browsers on an invisible desktop, giving attackers persistent and covert remote access to compromised Windows systems. The post MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection appeared first on SecurityWeek…SECURITYWEEK.COM
27 JulOperation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams UpdateCybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote monitoring and management (RMM) tools. "The victim was directed through compromised web infrastructure to a counterfeit Microsoft St…THEHACKERNEWS.COM
27 JulDynatrace Intelligence automates incident triage and remediation with AI agentsDynatrace has announced major advancements to Dynatrace Intelligence that help automatically resolve incidents, prevent disruptions, and accelerate operations while maintaining the human oversight and governance enterprises require. Building on the introduction of Dynatrace Intel…HELPNETSECURITY.COM
27 JulCoca-Cola restores most production capacity at dairy unit after ransomware attackThe company said it does not expect the Fairlife disruption to have a material impact on financial performance or operations. CYBERSECURITYDIVE.COM
27 Jul27th July – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Nichirei, a Japan-based frozen-food supplier and logistics company, has experienced a ransomware attack that disrupted shipping opera…RESEARCH.CHECKPOINT.COM
27 JulCoca-Cola confirms data theft in Fairlife ransomware attackThe Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. [...]BLEEPINGCOMPUTER.COM
27 JulHealth system in South Carolina, Georgia closes offices after malware affects networksOn Sunday, AnMed published a statement online saying they were “experiencing a cybersecurity disruption involving malware” and were working to restore systems and determine the scope of the incident.THERECORD.MEDIA
27 JulDid an AI Really Escape?Reports about AI models escaping sandboxes and using external systems have sparked debate within the cybersecurity community. At the same time, some practitioners argue that safety guardrails can interfere with legitimate security and incident response workflows. The tension betw…YOUTUBE.COM
27 JulNew Dysphoria DDoS botnet spreads to 200k devices worldwideA botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. [...]BLEEPINGCOMPUTER.COM
27 JulReuters: OpenAI Agent Hacked Hugging Face for Days Before Being DetectedReuters says OpenAI failed to detect its AI agent hacking Hugging Face for days, discovering the breach only after FBI involvement. Reuters reported that the OpenAI agent responsible for the Hugging Face breach operated undetected for over a week before OpenAI realized what had h…SECURITYAFFAIRS.COM
26 JulSecurity Affairs newsletter Round 587 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Iran-Linked Actors Breach Are…SECURITYAFFAIRS.COM
26 JulHackers Hijack Hotel Wi-Fi to Steal Microsoft 365 CredentialsHackers compromised hotel Wi-Fi gateways to redirect users to fake Microsoft 365 login pages and steal credentials. ReliaQuest’s threat research team just documented attackers compromising the Wi-Fi gateways at hotels and conference centers, then quietly rerouting guests to…SECURITYAFFAIRS.COM
26 JulSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 107Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter UAC-0145 Primary Compromise Vectors as of July 2026 SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyG…SECURITYAFFAIRS.COM
26 JulHugging Face CEO calls for ‘radical transparency’ after ‘unprecedented’ OpenAI hack"The first autonomous agent cyberattack is an unprecedented event. It deserves an unprecedented response!"TECHCRUNCH.COM
25 JulDavid Shiply Interviews Pratim Datta, PhD from Kent StateAI, Cybersecurity, and Public Policy: Export Controls, Arms Races, and the "New Radium" On Cyber Security Today (Weekend), the host interviews Pratim Datta, a Kent State University professor and former global consultant, about the past six months of AI and public policy as it int…CYBERSECURITYTODAY.LIBSYN.COM
25 JulThe OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for DaysPlus: Russian hackers are trying to steal US nuclear scientists’ emails, the State Department bans known scammers from entering the United States, and more.WIRED.COM
25 JulCTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account HijackingFor years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an opportunity arose. That model is changing. Recen…THEHACKERNEWS.COM
25 JulAI Now Picks Cybercrime TargetsSome malware operations reportedly include AI-powered profiling features that analyze compromised systems and rank victims based on characteristics that may indicate higher financial value or operational importance. This helps attackers decide where to focus their efforts. Automa…YOUTUBE.COM
25 JulShinyHunters data leaks fuel $2,000 sextortion email scamThreat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. [...]BLEEPINGCOMPUTER.COM
25 JulThe hacker who humiliated spyware makers and was never caughtAn awe-inspiring hacktivist who hacked two controversial government spyware makers may be the most prolific hacker to have never gotten caught. What do we know about Phineas Fisher?TECHCRUNCH.COM
24 JulData Breach Confirmed After Australian Energy Giant Origin Is HackedA hacker claims to have stolen the information of 2 million Origin Energy customers and is threatening to leak it. The post Data Breach Confirmed After Australian Energy Giant Origin Is Hacked appeared first on SecurityWeek .SECURITYWEEK.COM
24 JulRansomware gangs go after EMEA healthcare’s supply chainA ransomware attack against a hospital makes headlines, while attacks on the rest of the ecosystem around it tend to stay quiet despite doing damage that can be just as bad. Flare researcher Assaf Morag analyzed ransomware leak-site activity tied to healthcare organizations in th…HELPNETSECURITY.COM
24 JulClop ransomware targets Windchill, FlexPLM in data theft attacksThe Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. [...]BLEEPINGCOMPUTER.COM
24 JulRansomware Attacks Targeting Universities on the RiseComparitech’s analysis of incidents in the first half of 2026 finds that the emergence of The Gentlemen ransomware has resulted in surge in attacks against higher educationINFOSECURITY-MAGAZINE.COM
24 JulHotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials From VisitorsResearchers at ReliaQuest warned of widespread DNS poisoning attacks targeting the hospitality sector as part of a cyber espionage campaignINFOSECURITY-MAGAZINE.COM
24 JulChick-fil-A data breach affects more than 13,000 customersChick-fil-A has confirmed that over 13,000 customers had their accounts breached in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19. [...]BLEEPINGCOMPUTER.COM
24 JulIn Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel FlawsNoteworthy stories that might have slipped under the radar: Siemens ROX II industrial switch vulnerabilities, Russian Zimbra webmail espionage campaign, Stadler Rail ransomware extortion attempt. The post In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 40…SECURITYWEEK.COM
24 JulBlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware DeliveryThe North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malwar…THEHACKERNEWS.COM
24 JulDespite multiple takedowns, botnets continue to growRoughly 1 in 4 of those compromised IPs are based in the United States, Lumen’s Black Lotus Labs said. Botnets like IPIDEA have also rebounded quickly, surpassing their pre-disruption footprint. The post Despite multiple takedowns, botnets continue to grow appeared first on Cyber…CYBERSCOOP.COM
23 JulRansomware Attack Puts a Chill On Japanese Frozen-Food ChainA cyberattack on a food and logistics firm disrupts the supply of frozen food to thousands of clients, including major franchises like Kentucky Fried Chicken.DARKREADING.COM
23 JulTwo-Thirds of Ransomware Victims Say AI Boosted Attack EffectivenessA new study of organizations which have fallen victim to ransomware suggests the rise of AI-tools being used by hackers is making life harder for defendersINFOSECURITY-MAGAZINE.COM
23 JulSwiss rail manufacturer Stadler refuses to pay $12.3 million ransom after cyberattackCybercriminal group Everest is demanding 10 million Swiss francs ($12.3 million) from Swiss rail vehicle manufacturer Stadler after breaching a data exchange platform shared with one of its suppliers through compromised credentials. Stadler operates 16 production and component pl…HELPNETSECURITY.COM
23 JulNew msaRAT malware uses Chrome, Edge browsers to route C2 trafficThe Chaos ransomware gang is using a new backdoor dubbed msaRAT that hides command-and-control (C2) communication by routing it through the Chrome or Edge browsers. [...]BLEEPINGCOMPUTER.COM
23 JulPyPI hardens package security with new upload restrictionsThe Python Package Index (PyPI) now rejects uploads of new files to releases older than 14 days to prevent attackers from poisoning long-stable releases if a project’s publishing tokens or release workflows are compromised. “This change will protect Python users and reduce …HELPNETSECURITY.COM
23 JulChaos ransomware's msaRAT: Living off the browser to build a covert C2 channelThe Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.TALOSINTELLIGENCE.COM
23 JulUpbound Group Says Data Breach Led to $13 Million in Fraudulent Contract LossesHackers recently obtained non-sensitive customer information and other documents from the company. The post Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses appeared first on SecurityWeek .SECURITYWEEK.COM
23 JulChaos ransomware msaRAT hides its C2 channel inside a legitimate browser processCisco Talos has identified a Rust-based remote access trojan it attributes to the Chaos ransomware group, named msaRAT after four of the binding names left in the binary. The tool starts its own instance of Chrome or Edge on the victim machine and controls it through Chrome DevTo…HELPNETSECURITY.COM
23 JulAttackers Weaponize GitHub Actions Runners to Target cPanel and WHM ServersCybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager (WHM) instances. The activity involves malicious Packagist development versions…THEHACKERNEWS.COM
23 JulWhen the "Autonomous Attacker" Is Your Own AI Model, (Thu, Jul 23rd)Two disclosures, five days apart, described the same intrusion from opposite ends —
one from the victim, one from the party that turned out to be responsible — and
together they make one of the more instructive incidents of th…ISC.SANS.EDU
23 JulMajor Australian energy supplier confirms customer data compromisedOrigin Energy said it was working to figure out how many Australians were affected by a recent data breach.THERECORD.MEDIA
23 JulChaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and EdgeThe Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor. The implant never opens an outbound connection of its own. …THEHACKERNEWS.COM
23 JulAustralian energy provider Origin says data breach exposes client dataOrigin Energy has confirmed that an unauthorized party accessed and subsequently leaked customer data online, exposing sensitive personally identifiable information (PII), among others. [...]BLEEPINGCOMPUTER.COM
22 JulRisky Business #845 -- OpenAI's Skynet momentOn this week’s show special guest co-host Chris Krebs joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover: Oopsie daisy! OpenAI agents went rogue and hacked Hugging Face US and China trade AI model ban threats Iran has been using SS7 queries t…RISKY.BIZ
22 JulOpenAI says its AI models hacked Hugging Face during testingOpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment. [...]BLEEPINGCOMPUTER.COM
22 JulOpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat BenchmarkOpenAI on Tuesday said a combination of its artificial intelligence (AI) models, including GPT-5.6 Sol and an "even more capable pre-release model," was behind the security incident that targeted Hugging Face's production infrastructure last week. The AI company said the models w…THEHACKERNEWS.COM
22 JulChick-fil-A discloses data breach after credential stuffing attacksAmerican fast food restaurant chain Chick-fil-A is notifying customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks. [...]BLEEPINGCOMPUTER.COM
22 JulProofpoint Research Finds 65% of Organizations Affected by Ransomware Say AI Made Attacks More EffectivePROOFPOINT.COM
22 JulRansomware Group Threatening to Leak Data Stolen From Coca-Cola’s FairlifeThe Anubis ransomware group claims to have stolen 1 TB of confidential data from the Coca-Cola subsidiary. The post Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulOpenAI confirms its AI agent autonomously breached Hugging FaceOpenAI has revealed that an autonomous AI agent powered by GPT-5.6 Sol and a more capable unreleased model escaped its intended testing environment, gained internet access, and compromised parts of Hugging Face's production infrastructure while attempting to obtain benchmark answ…CYBERINSIDER.COM
22 JulPaidwork breach exposes data of 23 million users: Check if you’re affectedA reported breach at microtask platform Paidwork exposed personal and financial data of more than 23 million users. Here's how to check if you're affected.MALWAREBYTES.COM
22 JulOpenAI models behind breach of Hugging Face systems, companies sayOpenAI announced that its models were behind a breach of the AI platform Hugging Face, which had earlier detected an attack carried out by "by an autonomous AI agent."THERECORD.MEDIA
22 JulSuno, Paidwork Data Breaches Affect Tens of Millions of AccountsHackers leaked names, email addresses, phone numbers, passwords, and financial information stolen from the two platforms. The post Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulFlaw in Adobe Extension With 300M Installs Enabled WhatsApp Data TheftAn attacker only needed to convince the targeted user to visit a malicious website to exfiltrate WhatsApp messages and contacts. The post Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulJapanese food logistics giant recovers as extortion group claims cyberattackNichirei Logistics Group said warehouse operations and frozen food shipments are returning to normal. A cybercrime gang said it caused the disruption.THERECORD.MEDIA
22 JulOpenAI models escaped containment and hacked a major AI application libraryThe attack is the first known instance of frontier models autonomously breaking out of a testing environment and into another company’s servers.CYBERSECURITYDIVE.COM
22 JulHow enterprise GenAI can amplify ransomware risk — and how to contain itEnterprise AI can accelerate ransomware attacks when AI assistants and agents inherit excessive permissions or compromised identities. Acronis explains how identity controls, governance, and least-privilege access help reduce AI-enabled ransomware risk while supporting secure AI …BLEEPINGCOMPUTER.COM
22 JulNew Kimsuky campaign compromised South Korean software vendorsA North Korean advanced persistent threat (APT) group recently targeted vendors of collaborative-work software, South Korean researchers said.THERECORD.MEDIA
22 JulSwiss rail giant Stadler rejects $12.3M ransom demand after cyberattackSwiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. [...]BLEEPINGCOMPUTER.COM
22 JulReal world incident response: Microsoft and AXA XL strengthen cyber resilienceOur collaboration with AXA XL brings Microsoft Incident Response services directly to cyber insurance policyholders, helping organizations coordinate technical, business, and insurance decisions. The post Real world incident response: Microsoft and AXA XL strengthen cyber resilie…MICROSOFT.COM
21 JulPR3TACK preemptive framework maps threats before attackers use themDefensive frameworks in cybersecurity record what attackers have already done. Analysts study a breach, document the method, and build detections around confirmed activity. This cycle leaves a gap between the moment an attacker invents a technique and the moment defenders learn t…HELPNETSECURITY.COM
21 JulThe air gap is a myth and other OT security truthsBenjamin Bachmann, Director Group Information Security at Bilfinger, speaks with Help Net Security about defending industrial plants. He explains why attackers want to control operations instead of stealing data, and why the air gap is mostly a myth. Bachmann covers how containme…HELPNETSECURITY.COM
21 JulData breach at AI music service Suno exposed 55 million accountsAI music generation platform Suno suffered a data breach that exposed the personal information of more than 55 million users, according to Have I Been Pwned (HIBP). The incident exposed phone numbers and tens of thousands of Stripe purchase records containing customer names, phys…CYBERINSIDER.COM
21 JulUkraine warns fake CAPTCHAs are being used to make you hack yourselfUkraine's computer emergency response team, CERT-UA, has warned that the Kremlin-backed Sandworm hacking group is leveraging fake CAPTCHA checks on compromised websites that persuade users to run malicious code. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
21 JulA Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It NowDealerships installed alarms in millions of vehicles—and left them in even if the buyer didn’t want them. Now researchers warn they can be hacked to unlock, track, and disable cars.WIRED.COM
21 JulClover Health Investments Discloses Data BreachUsing social engineering, hackers compromised employee accounts with access to personal and health information. The post Clover Health Investments Discloses Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulNew HollowGraph Malware Abuses Microsoft 365 Calendar for C&C CommunicationPart of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop. The post New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulKenya probes hack of president's website after bitcoin ransom demandThe website was hacked on Saturday, when its homepage was replaced with a message displaying a cryptocurrency wallet address and threatening to publish unspecified information about President William Ruto unless the ransom was paid.THERECORD.MEDIA
21 JulA New Ransomware Threat Actor Emerges Every Week, Warns ReportAnalysis by Black Kite warns that ransomware ecosystem is becoming bigger and more fragmentedINFOSECURITY-MAGAZINE.COM
21 JulClosing the Identity Gaps in Critical Infrastructure SecurityCritical infrastructure attacks often begin with stolen credentials, compromised devices, or trusted accounts. Specops Software explains why Zero Trust should verify both user identities and device trust before granting access to critical systems. [...]BLEEPINGCOMPUTER.COM
21 JulJadePuffer returns with ransomware built to target AI models and infrastructureJadePuffer, the threat actor behind the recently documented extortion operation executed end-to-end by an AI agent, is now attempting to leverage ENCFORGE, novel ransomware created to target AI and machine learning (ML) infrastructure. The extortion contact embedded in the ransom…HELPNETSECURITY.COM
21 JulAI music generator Suno breach affects 55M users, per Have I Been PwnedA hacker took names, phone numbers, and physical addresses of millions of customers who used AI music generator Suno.TECHCRUNCH.COM
21 JulRansomware victims fail to fix flaws that exposed themMany organizations still aren’t securing their email or patching vulnerabilities after recovering from attacks, a new report found.CYBERSECURITYDIVE.COM
21 JulSpain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hackThe Agencia Española de Protección de Datos (AEPD) announced the fine on Friday, saying in its decision that more than 2,600 Spaniards were impacted by a breach affecting 6.9 million people worldwide.THERECORD.MEDIA
21 JulAnubis ransomware claims Coca-Cola Fairlife attack, threatens data leakThe Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola's Fairlife dairy subsidiary, threatening to publish allegedly stolen corporate data unless the company pays a ransom. [...]BLEEPINGCOMPUTER.COM
21 JulThe defense against the AI arts.Trump's latest AI leader resigns. The Army burns through its AI tokens. Scammers impersonate IC3 personnel.HollowGraph malware uses a compromised Microsoft 365 calendar for C2. Qilin ransomware targets a critical Palo Alto Networks flaw. A North Korean campaign targets Web3 and c…THECYBERWIRE.COM
21 JulRansomware Is Accelerating, But It's Not Because of AIResearchers pointed to fragmentation of the ransomware ecosystem, the emergence of new attackers, and expansion of attacks on less defended organizations.DARKREADING.COM
21 JulOpenAI says model test was behind Hugging Face hackAt the time, Hugging Face said it wasn’t clear which LLM was used in the attack. OpenAI confirmed it was one of their models being tested for “maximal” cyber capabilities. The post OpenAI says model test was behind Hugging Face hack appeared first on CyberScoop .CYBERSCOOP.COM
20 JulMore alerts are making your team slower, and an outcome-based SOC fixes thatIn this Help Net Security video, Thom Langford, EMEA CTO, Rapid7, explains why piling on more security alerts makes a SOC slower to respond. Attackers log in with stolen credentials and use trusted tools like PowerShell instead of custom malware. He shares a case where attackers …HELPNETSECURITY.COM
20 JulHugging Face Hacked in Autonomous AI AttackTargeting production infrastructure, the attack compromised internal datasets and service credentials. The post Hugging Face Hacked in Autonomous AI Attack appeared first on SecurityWeek .SECURITYWEEK.COM
20 JulErnst & Young Data Breach Affects Personal, Financial InformationHackers stole names, addresses, Social Security numbers, credit/debit card numbers, and other information from a third-party management platform. The post Ernst & Young Data Breach Affects Personal, Financial Information appeared first on SecurityWeek .SECURITYWEEK.COM
20 JulHugging Face confirms breach affected internal datasets and credentials, urges users to take actionHugging Face is urging users to rotate any access tokens stored on the platform and review account activity.TECHCRUNCH.COM
20 JulSoftware provider to more than 2,000 US hospitals says hackers stole employee and customer dataCraneware, which is headquartered in Edinburgh and listed on London's AIM market, told investors it detected unauthorized access to a “subset” of its data environment and has since brought in outside forensic investigators.THERECORD.MEDIA
20 JulJadePuffer Returns With Ransomware Designed to Wipe AI ModelsJadePuffer follow-up campaign deployed ENCFORGE locker built to destroy AI model artifactsINFOSECURITY-MAGAZINE.COM
20 JulHackers stole ‘significant’ amount of data from tech firm relied on by thousands of US hospitals and pharmaciesEdinburgh-based tech firm Craneware said customer data was stolen during a cyberattack. The company makes software that thousands of U.S. hospitals, pharmacies, and clinics rely on for billing patients, potentially exposing health data.TECHCRUNCH.COM
20 JulHealthcare giant Abbott probes two cyber incidents amid extortion claimsExtortion groups ShinyHunters and ShadowByt3$ claim they stole vast amounts of patient data. Those allegations have not been verified.MALWAREBYTES.COM
20 JulRomania races to restore land registry after cyberattack disrupts property marketRomania's land registry agency is still recovering from a cyberattack it called "the most serious technical incident in the institution's history."THERECORD.MEDIA
20 JulPaidwork breach exposes sensitive data of 23 million userData belonging to more than 23 million users has been exposed following a breach at Paidwork, a platform that pays people for completing online microtasks. Paidwork markets itself as a way to earn money through simple tasks like watching ads, testing apps, and completing surveys,…HELPNETSECURITY.COM
20 JulHollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named the malware HollowGraph, say…THEHACKERNEWS.COM
20 JulHugging Face discloses an autonomous agentic breach.Abbott Laboratories investigates another alleged breach. FBI arrests a Florida man accused of spreading malware through video games.THECYBERWIRE.COM
20 JulHackers steal customer data from major hospital software vendorThe breach is another reminder of how vulnerable the healthcare industry is to supply-chain attacks.CYBERSECURITYDIVE.COM
20 JulNew HollowGraph malware uses Microsoft Graph for stealthy C2 commsA malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. [...]BLEEPINGCOMPUTER.COM
20 JulSuno - 55,282,226 breached accountsIn November 2025, AI music generation tool Suno suffered a data breach that later came to light in July the following year . The data contained over 55M unique email addresses. Phone numbers were also present where they had been used as the sign-up method. Although representing a…HAVEIBEENPWNED.COM
20 JulJadePuffer agentic attacks now target AI model data with ransomwareThe JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints. [...]BLEEPINGCOMPUTER.COM
19 JulSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 106Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter CrashStealer: C++ macOS infostealer posing as crash reporter Lucide Proxy: Turning Student Web Proxies into DDoS Bots …SECURITYAFFAIRS.COM
19 JulPaidwork - 23,272,765 breached accountsIn March 2026, hackers claimed they had obtained data from the gig economy platform Paidwork which they then listed for sale . Almost 11GB of data allegedly obtained from the platform was subsequently posted publicly in July and contained over 23M unique email addresses. The brea…HAVEIBEENPWNED.COM
18 JulWhen trusted sites turn.Lauren Fievisohn, Ph.D, Senior Threat Researcher from Silent Push, is sharing their work on "Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites." Silent Push researchers have identified a newly named threat act…THECYBERWIRE.COM
18 JulYour Period Tracker Is (Probably) Spying on YouPlus: Russian cyberspies turn to infrastructure hacking, DHS repeatedly fails to realize it’d been hacked, a breach exposes an AI music generator’s scraping ways, and more.WIRED.COM
18 JulDaxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s NetworkResearchers found China’s Daxin rootkit and a new Stupig backdoor on a Taiwan firm’s network, suggesting a stealthy intrusion dating back to 2013. Symantec’s Threat Hunter Team found Daxin running on a compromised host at a Taiwan-based subsidiary of a multinati…SECURITYAFFAIRS.COM
17 JulCoca-Cola Suspends US Fairlife Production Due to Ransomware AttackThe company says the incident has not affected product quality and safety, nor Fairlife’s Canada production. The post Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack appeared first on SecurityWeek .SECURITYWEEK.COM
17 JulThe Gentlemen Overtakes Qilin as Most Prolific Ransomware ThreatAnalysis of ransomware incidents by ReliaQuest indicates a shift in the ransomware landscapeINFOSECURITY-MAGAZINE.COM
17 JulCyberattack Disrupts Operations of Japanese Frozen Food Giant NichireiThe company disconnected its systems on July 13 and is starting to gradually restore operations. The post Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei appeared first on SecurityWeek .SECURITYWEEK.COM
17 JulNew GoSerpent Malware Targets Southeast Asian Governments and Diplomats for EspionageCybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting entities in Southeast Asia since late 2025 with a focus on long-term access and intelligence gathering. Russian cybersecurity company K…THEHACKERNEWS.COM
17 JulEY says client tax data exposed in third-party IT software breachErnst & Young (EY) is notifying affected individuals that personal and financial information was exposed after attackers breached a third-party IT service management platform used by the firm's tax practice. The professional services giant says the incident resulted in unaut…CYBERINSIDER.COM
17 JulArmenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong ManArmenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov. His wife, Maria Yurova, told REN TV that border officers pulled him out of the departure hall at Y…THEHACKERNEWS.COM
17 JulShark vacuum flaw exposes cameras, home maps and Wi-Fi passwordsOne compromised Shark robot vacuum could unlock remote access to many others.MALWAREBYTES.COM
17 JulSpirals ransomware locks down victim systems in under 24 hoursA previously unknown ransomware strain called Spirals was used last month in an attack against an IT services company in South Asia, where attackers went from initial access to data theft and encrypting the network in less than 24 hours, according to Symantec’s Threat Hunte…HELPNETSECURITY.COM
17 JulDairy company Fairlife suspends production in US after cyber incidentFairlife’s U.S. operation includes plants in Michigan, New York and Arizona, and the company's retail sales passed $1 billion in 2022.THERECORD.MEDIA
17 JulWhen Patching Is Already Too LateThe discussion makes a bold claim: many organizations no longer have enough time to patch before attackers compromise vulnerable systems. Instead of treating prevention as the primary strategy, the emphasis shifts toward detecting intrusions quickly and responding before attacker…YOUTUBE.COM
17 JulGovernment Agencies Falling Victim to Ransomware Daily, Warns StudyGovernment organizations are targeted by attackers who know agencies cannot afford disruption to public servicesINFOSECURITY-MAGAZINE.COM
17 Jul23andMe Faces New Security Mandates in $18m Data Breach Settlement23andMe has agreed to an $18m settlement with 42 US attorneys general over its 2023 data breach, including enhanced data protection requirementsINFOSECURITY-MAGAZINE.COM
17 JulErnst & Young discloses data breach after support system hackErnst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel. [...]BLEEPINGCOMPUTER.COM
17 JulAbbott discloses cyberattack on cancer diagnostics businessThe cyberattack follows Abbott’s recent $21 billion purchase of Exact Sciences. Abbott did not disclose what kind of information was accessed.CYBERSECURITYDIVE.COM
17 JulGoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate TheftCybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, a…THEHACKERNEWS.COM
17 JulA cyberattack hit Nichirei, one of Japan’s largest food companiesA cyberattack hit one of Japan’s largest food companies, Nichirei, disrupting logistics and shipments. The company is gradually restoring operations. Nichirei is one of Japan’s largest food companies, best known for its frozen food business. Founded in 1942 and headqu…SECURITYAFFAIRS.COM
17 JulAbbott Laboratories probes two cyber incidents amid extortion claimsAbbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and…BLEEPINGCOMPUTER.COM
17 JulAI Becomes The Supply ChainAI tools are increasingly being used to recommend code, libraries, and scripts. The clip explores the possibility that a compromised AI system could influence those recommendations. Software supply chains already depend on trust between developers, tools, and dependencies. Adding…YOUTUBE.COM
16 JulUnpacking the AsyncAPI npm supply chain compromise and import-time payload deliveryThreat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This analysis breaks down the attack chain, payload delivery, and recommended defenses. The post Unpacking the AsyncAPI npm supply chain compromise and import-tim…MICROSOFT.COM
16 JulRansom demands are down, email is the top way attackers get inAn employee opens an email that looks like any other, clicks a link, and gives up a password without noticing. A stolen login opens a door deeper in the network. Files stop opening a few days later. That chain now sits at the front of most ransomware cases. Malicious email and ph…HELPNETSECURITY.COM
16 JulPolice Disrupt a €140M Cyber Fraud Ring in SpainIberian hackers carried out a variety of cyberattacks and laundered the winnings through complex financial networks.DARKREADING.COM
16 JulClaude Code and DeepSeek Powered Chinese Cyber Espionage CampaignChinese actors used Claude Code and DeepSeek to automate attacks that breached government systems and targeted financial firms. Hunt.io researchers stumbled onto an active intrusion campaign in June 2026 while pivoting on known TencShell command-and-control infrastructure. A sing…SECURITYAFFAIRS.COM
16 JulNew Spirals ransomware encrypts victim network in under 24 hoursA new ransomware actor called Spirals completed a corporate intrusion, from initial access to data theft and encryption, in less than 24 hours. [...]BLEEPINGCOMPUTER.COM
16 JulGoSerpent: a persistent threat evolves with sophisticated data collection and exfiltrationTwo-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia.SECURELIST.COM
16 JulScattered Spider hackers sentenced to 5.5 years over £29 million Transport for London hackTwo leading members of the Scattered Spider cybercrime collective have been sentenced to more than five years in prison for carrying out the 2024 cyberattack against Transport for London (TfL).THERECORD.MEDIA
16 Jul23andMe to pay $18 million in new genetics data breach settlementGenetic testing company 23andMe has agreed to pay $18 million to settle claims from a coalition of 43 attorneys general that it failed to protect customers' genetic data. [...]BLEEPINGCOMPUTER.COM
16 JulTwo Scattered Spider Hackers Sentenced to Jail in UKThalha Jubair and Owen Flowers were prosecuted over a 2024 cyberattack targeting Transport for London (TfL). The post Two Scattered Spider Hackers Sentenced to Jail in UK appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulScattered Spider members jailed over Transport for London hack that cost £29 millionTwo members of the notorious “Scattered Spider” hacking collective have been sentenced to five years and six months in prison each for a cyberattack on Transport for London (TfL) that disrupted services for thousands of commuters and cost the transport authority an es…HELPNETSECURITY.COM
16 JulThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More StoriesA lot of this week’s trouble starts with something that looks close enough. A familiar repo. A useful installer. A harmless sync setting. Then the handoff goes bad, the box starts talking to someone else, and the damage moves faster than the explanation. Old bugs are back, weak d…THEHACKERNEWS.COM
16 Jul23andMe agrees to a $18 million settlement over 2023 data breachA bipartisan coalition of 43 attorneys general has secured an $18 million settlement with genetic testing company 23andMe over its failure to adequately protect customer data before the company's 2023 breach. The agreement also requires new cybersecurity and governance measures f…CYBERINSIDER.COM
16 JulRussian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrimeOfficials accused three Russian nationals, Media Land and ML.Cloud of supporting cyberattacks spanning 21 U.S. states and other countries, resulting in losses surpassing $62 million. The post Russian trio indicted for allegedly running bulletproof hosting providers that spurred c…CYBERSCOOP.COM
16 JulTwo Scattered Spider Members Sentenced to Prison Over £29 Million TfL CyberattackTwo members of the Scattered Spider cybercrime group received jail sentences in the UK for the 2024 cyberattack on Transport for London. A UK court sentenced two Scattered Spider members, Thalha Jubair (20) and Owen Flowers (18), for their role in the 2024 cyberattack on Transpor…SECURITYAFFAIRS.COM
16 JulCoca-Cola suspended production at its Fairlife dairy after a ransomware attackCoca Cola said dairy production at its Fairlife unit will "remain suspended" in the United States following a hack.TECHCRUNCH.COM
16 JulAnubis ransomware: what you need to knowThe Anubis ransomware-as-a-service (RaaS) operation has hit some healthcare organisations hard - but they are not the only ones at risk. Read more in my article on the Fortra blog.FORTRA.COM
16 JulAI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response ReportExplore Unit 42's perspectives on AI's impact on cybersecurity, including key updates since the 2026 Incident Response Report. The post AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
15 JulWeekly Update 512: IoT Lockout FailPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite "Build a smart home", they said. "It'll make life so much better", they said. Well, life wasn't very bloo…TROYHUNT.COM
15 JulBehind the Book: Threat-Driven Software DevelopmentIn this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo is joined by co-authors Michael Howard, Lee Holmes, and Shawn Hernan for a discussion on their new book, Threat-Driven Software Development: Defending Online Services from Modern Threat Acto…THECYBERWIRE.COM
15 JulUS charges alleged operators of Russian bulletproof hosting serviceU.S. federal prosecutors have unsealed charges against three Russian nationals, accusing them of providing bulletproof hosting (BPH) services to ransomware gangs that caused over $62 million in damages to victims worldwide. [...]BLEEPINGCOMPUTER.COM
15 JulFluke - 821,100 breached accountsIn July 2026, electronic test and measurement equipment company Fluke was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published more than 100GB of data allegedly taken from the company. The corpus contained largely corporate contact inform…HAVEIBEENPWNED.COM
15 JulOkoBot: new sophisticated malware framework targets cryptocurrency usersKaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users. This complex framework employs TookPS, exfiltrates seed phrases, monitors Chromium-based browsers, and installs various malware strains, including the Rilide stealer.SECURELIST.COM
15 JulGoose Creek data breach exposes 6.6 million customer recordsGoose Creek Candle Company has suffered a data breach exposing the personal information of 6.6 million customers, according to a new entry published by Have I Been Pwned (HIBP). The breach was added to the service earlier today after HIBP received a copy of the dataset from the p…CYBERINSIDER.COM
15 JulUS charges Russian ‘bulletproof’ web hosts over cyberattacks that netted $62M from cybercrime victimsThe 2024 indictment, now unsealed, accuses three Russians and two web hosts of aiding hackers and profiting from cybercrime.TECHCRUNCH.COM
15 Jul23andMe reaches $18 million settlement with states for massive breachA coalition of 42 state attorneys general reached an $18 million settlement with 23andMe for cybersecurity failings that led to a data breach.THERECORD.MEDIA
14 JulYour vendor’s vendor might be the real breach riskIn this Help Net Security video, Chris Boehm, Field CTO, Zero Networks, breaks down how a vendor breach can become your breach. He explains that attackers now target the subcontractors behind your trusted vendors. A compromised credential at a company you have never heard of can …HELPNETSECURITY.COM
14 JulThe ransomware negotiator who was working for the other sideWhen a company falls victim to a ransomware attack, it is not uncommon for it to turn to experts for help. Specialist ransomware negotiation firms handle communications with criminal gangs on a victim's behalf. What victims don't expect is that their trusted negotiator might be s…BITDEFENDER.COM
14 JulU.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware SupportThe U.S. Treasury Department's Office of Foreign Assets Control (OFAC) has designated two individuals and a VPN service provider for enabling ransomware actors' and other cybercriminals' malicious activities, including ransomware attacks against Americans. The VPN, named First VP…THEHACKERNEWS.COM
14 JulCrashStealer: New macOS Infostealer Uses Signed Apps to Evade GatekeeperNew macOS infostealer CrashStealer uses a signed app to bypass Gatekeeper, steals credentials and wallets, then AES-encrypts stolen data. Jamf Threat Labs first spotted CrashStealer in early May 2026 as a suspicious macOS sample uploaded to VirusTotal. By early July, in-the-wild …SECURITYAFFAIRS.COM
14 JulPhishing for dummies: Forg365 lowers barrier to M365 account takeoversA newly documented phishing-as-a-service platform distributed through Telegram is lowering the technical barrier to Microsoft 365 account takeovers by giving less-skilled attackers automated tools to evade some authentication controls and retain access after compromise. The platf…CSOONLINE.COM
14 JulLidl Notifies Customers of Third-Party Data BreachSupermarket giant Lidl has revealed details of a supplier breach impacting customer dataINFOSECURITY-MAGAZINE.COM
14 JulUS sanctions VPN, malware providers for enabling ransomware attacksThe U.S. Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned two individuals and one entity for enabling ransomware attacks against U.S. organizations. [...]BLEEPINGCOMPUTER.COM
14 JulUS, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure RoutersMultiple state-sponsored APTs are compromising poorly secured devices across critical infrastructure sector networks. The post US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulAttacker Used AI to Build Custom PowerShell Recon MalwareHuntress found an AI-generated PowerShell script used for AD reconnaissance, showing attackers are using AI to create custom, evasive tools. During an incident response investigation on June 3, 2026, Huntress analyst Jevon Ang recovered a PowerShell script from a compromised Wind…SECURITYAFFAIRS.COM
14 JulPentagon suspends CMMC Phase II requirements.US Treasury Department sanctions VPN provider that allegedly assisted criminals. Lidl discloses breach affecting customer information.THECYBERWIRE.COM
14 JulHealthcare sector faces persistent supply-chain security, identity management challengesA new report says doctors and nurses should train for cyberattacks the way firefighters train for major blazes — even if they expect them to be rare.CYBERSECURITYDIVE.COM
14 JulCanada’s Electronic Spy Agency Conducted Cyberattacks on Criminals Brokering Fentanyl Ingredients, Report SaysResearch fellow Bill Robinson speaks with The Globe and Mail about CSE spending. The post Canada’s Electronic Spy Agency Conducted Cyberattacks on Criminals Brokering Fentanyl Ingredients, Report Says appeared first on The Citizen Lab .CITIZENLAB.CA
14 JulCyberattack at KFC Japan impacting online orders and deliveriesKFC Japan has announced that a cyberattack affecting one of its third-party logistics providers is disrupting food deliveries to restaurants nationwide, raising the possibility of product shortages, reduced operating hours, and temporary store closures. The company has suspended …CYBERINSIDER.COM
14 JulFinland issues wanted notice for hacker behind massive psychotherapy data breachThe defendant's lawyer told Finnish media that he does not know where his client is but believes Kivimäki is outside Finland.THERECORD.MEDIA
14 JulSynopsys Finds No Evidence of Data Breach Amid Bosch Hack ClaimsThe D1R cybercrime group claimed to have stolen valuable data from Synopsys and Bosch, threatening to leak it unless a ransom is paid. The post Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulU.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware LossesU.S. sanctions hit VPN provider 1VPNS and a cryptor seller for enabling ransomware gangs behind billions in losses to critical infrastructure. The U.S. Treasury’s Office of Foreign Assets Control sanctioned two individuals and one entity on July 13 for supplying tools and i…SECURITYAFFAIRS.COM
14 JulWhen the Negotiator Helps HackersA ransomware negotiator was sentenced to federal prison after prosecutors said he secretly worked with the BlackCat ransomware group while negotiating on behalf of victims. According to court filings, he shared insurance limits, negotiating positions, and internal settlement thre…YOUTUBE.COM
13 JulCenters Laboratory Data Breach Affects 540,000 IndividualsThe WorldLeaks extortion group claimed to have stolen 720 GB of data from the healthcare testing and laboratory services provider. The post Centers Laboratory Data Breach Affects 540,000 Individuals appeared first on SecurityWeek .SECURITYWEEK.COM
13 JulHacker Extradited from Ukraine Pleads Guilty to Ryuk Ransomware ChargesAn Armenian man has pleaded guilty to his role in the infamous Ryuk ransomware operationINFOSECURITY-MAGAZINE.COM
13 JulFastNetMon eliminates third-party bgp lookups with NetomicsFastNetMon is introducing Netomics, a self-hosted BGP routing intelligence platform that combines live routing data, registry information, RPKI validation, routing history and AI-assisted querying into a single application. Built for internet service providers (ISPs), cloud provi…HELPNETSECURITY.COM
13 JulDutch Nationals Suspected in Odido Hack That Exposed Six Million CustomersDutch police suspect local hackers behind the Odido breach that exposed 6M customers after a phishing attack and seek public help identifying them. Dutch police have identified strong indications that Dutch nationals were involved in the February 2026 cyberattack on telecom provi…SECURITYAFFAIRS.COM
13 JulEU sanctions Russian GRU military hackers over cyberattacksThe European Union and the United Kingdom jointly sanctioned dozens of Russian individuals and entities and accused Russia of coordinating a network of hacking groups responsible for attacks across Europe. [...]BLEEPINGCOMPUTER.COM
13 JulBreach at the Beach: Play the Ultimate Entra ID CTFLearn how attackers abuse Entra ID through a free hands-on Capture the Flag. Varonis created the Breach at the Beach CTF to teach defenders how to investigate Entra ID attack techniques using realistic scenarios. [...]BLEEPINGCOMPUTER.COM
13 JulLidl discloses online shop breach after service provider hackGerman discount supermarket chain Lidl notified customers in Germany, Belgium, and the Netherlands that attackers stole their personal information in a breach at a service provider. [...]BLEEPINGCOMPUTER.COM
13 Jul⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and MoreSomewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That's supposed to be the good news. The catch is that the attackers have the same tools, pointed the other way, and they don't file tickets. That's the shape of this week. Trusted co…THEHACKERNEWS.COM
13 JulEurope strikes out against Russia’s Turla over espionage, ‘destructive attacks’The EU, its members and the U.K. took action against Russian government officials and others while attributing the winter cyberattacks against Poland’s energy grid to the FSB. The post Europe strikes out against Russia’s Turla over espionage, ‘destructive attacks’ appeared first …CYBERSCOOP.COM
13 JulHackers breach Lidl’s IT service provider, steal customer dataGerman discount supermarket chain Lidl has notified customers in Germany, Belgium, and the Netherlands that customer data was stolen after attackers breached one of its IT service providers. In notices published on its support websites in Belgium and the Netherlands, Lidl said it…HELPNETSECURITY.COM
13 JulCrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper ChecksCybersecurity researchers have flagged a new macOS information stealer called CrashStealer that's capable of harvesting sensitive data from compromised systems. Unlike other information stealers that are built on AppleScript droppers or Objective-C-based wrappers, CrashStealer is…THEHACKERNEWS.COM
13 JulRussian celebrity journalist Ksenia Sobchak says hackers accessed Telegram channels via email breachFollowing the breach of several of her Telegram channels, controversial Russian journalist Ksenia Sobchak claimed published screenshots of her correspondence with political figures were fake.THERECORD.MEDIA
13 JulState of the router.The U.S. and its allies warn of Russian cyber threats targeting critical infrastructure as Europe rolls out new sanctions. Apple sues OpenAI over alleged trade secret theft. Progress investigates a potential ShareFile security incident, Zimbra patches a critical flaw, and researc…THECYBERWIRE.COM
13 JulJapan's largest taxi operator shuts systems after cyberattackJapan's largest taxi operator, Nihon Kotsu, announced that its systems were compromised in a cyberattack, forcing the company to shut down part of its infrastructure. [...]BLEEPINGCOMPUTER.COM
13 JulWeak Security Continues to Fuel Russian CyberattacksIn a first, the UK and the EU jointly impose sanctions on Russian individuals and entities for cyberattacks and disinformation campaigns in the region.DARKREADING.COM
12 JulRyuk Ransomware Member Pleads Guilty Over Attacks on U.S. OrganizationsAn alleged Ryuk ransomware member pleaded guilty in the U.S. for helping deploy attacks on American companies and faces up to 15 years in prison. Armenian national Karen Serobovich Vardanyan (34) pleaded guilty in the U.S. for his role in Ryuk ransomware attacks targeting America…SECURITYAFFAIRS.COM
11 JulConti-versal opinions.Today we are joined by Geoff White, host of Cyber Hack and BBC journalist, taking a deep dive into the Conti ransomware gang. Geoff explores an in-depth investigation into the notorious Conti ransomware gang, drawing from thousands of leaked internal messages to reveal how th…THECYBERWIRE.COM
11 JulGlendale Community College - 793,925 breached accountsIn June 2026, Glendale Community College was the target of a ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from Glendale was later published online and included almost 800k unique email addresses along with various other data fields, including names, add…HAVEIBEENPWNED.COM
11 JulCompromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During InstallVersion 8.14.0 of the jscrambler npm package shipped with a malicious preinstall hook that silently drops and runs a native infostealer during installation, one build each for Windows, macOS, and Linux. Published on July 11, 2026, it needs no import and no CLI…THEHACKERNEWS.COM
10 JulDormant GitHub Accounts Help Attackers Blend In While Mapping Corporate OrgsDatadog Security Labs is warning of "several overlapping campaigns" that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the GitHub API. "Operators rely on automated scraping tooling with custom or legitimate-sounding us…THEHACKERNEWS.COM
10 JulRisky Bulletin: NSA Tailored Access Operations is backThe NSA’s Tailored Access Operations team is back, India bans an app used to hack e-rickshaws, Accenture has another data breach, and a leak exposes a suspected Chinese cyber contractor. The Risky Bulletin newsletter and podcast will be on an editorial break until July 20.RISKY.BIZ
10 JulNHS Warns Staff Over Unauthorized Access to Patient DataNHS tells staff they could face prison for “inappropriate” access to patients’ medical recordsINFOSECURITY-MAGAZINE.COM
10 JulFormer ransomware negotiator gets 4 years for BlackCat attacksA former employee of cybersecurity incident response company DigitalMint was sentenced to 70 months in prison for targeting U.S. companies in BlackCat (ALPHV) ransomware attacks. [...]BLEEPINGCOMPUTER.COM
10 JulRansomware Negotiator Gets 70 Months in Prison for Aiding BlackCat AttacksA 41-year-old former ransomware negotiator has been sentenced to nearly six years (i.e., 70 months) in prison in the U.S. for their role in conspiring with the now-defunct BlackCat ransomware operators to extort multiple victims and working with two other cybersecurity profession…THEHACKERNEWS.COM
10 JulGigaWiper Combines Multiple Malware for System-Level SabotageThe backdoor’s destructive capabilities include a standalone wiper, ransomware encryption, and a multi-pass wiping command. The post GigaWiper Combines Multiple Malware for System-Level Sabotage appeared first on SecurityWeek .SECURITYWEEK.COM
10 JulGigaWiper Merges Three Malware Families Into One Destructive BackdoorMicrosoft uncovered GigaWiper, a modular Go backdoor combining three malware families with espionage, remote control, and destructive wiping features. In October 2025, Microsoft’s threat intelligence team identified destructive wiping activity inside compromised environment…SECURITYAFFAIRS.COM
10 JulFormer Ransomware Negotiator Sentenced to 70 Months in Prison for Secretly Helping BlackCat GangA former ransomware negotiator was sentenced to nearly six years for secretly helping BlackCat extort victims while betraying his clients. A U.S. court sentenced former ransomware negotiator Angelo Martino, 41, to 70 months in prison for conspiring with the BlackCat ransomware ga…SECURITYAFFAIRS.COM
10 JulThird US Security Expert Sentenced to Prison for Helping Ransomware GangAngelo Martino, a former ransomware negotiator, was sentenced to 70 months for helping the BlackCat/Alphv group. The post Third US Security Expert Sentenced to Prison for Helping Ransomware Gang appeared first on SecurityWeek .SECURITYWEEK.COM
10 JulRansomware Never Stopped: Over 9,000 Confirmed Attacks Since 2018Ransomware remains above 1,400 attacks yearly since 2023. Qilin leads in 2026, while the U.S. remains the main target. Ransomnews has independently confirmed 9,291 ransomware attacks worldwide between January 2018 and July 2026, tracking incidents only when verified through victi…SECURITYAFFAIRS.COM
10 JulFlorida ransomware negotiator convicted for helping ransomware gang extort US companiesA third ransomware negotiator has been jailed for helping a notorious ransomware group extort American victim companies into paying the hackers.TECHCRUNCH.COM
10 JulIn Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware OpsOther noteworthy stories that might have slipped under the radar: Abnormal AI sued by Anthropic, AssuranceAmerica data breach affects 7 million people, NSA brings back TAO. The post In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops app…SECURITYWEEK.COM
10 JulPolice suspects Dutch hackers were involved in Odido breachThe Dutch National Police (Politie) says it has found "strong indications" that Dutch hackers have been involved in a February breach at the telecommunications provider Odido. [...]BLEEPINGCOMPUTER.COM
10 JulCybercriminals Flock to Healthcare Businesses as Attacks SurgeWhile cyberattacks against hospitals and clinics grew modestly in the first half of 2026, attacks on service providers and other healthcare businesses more than doubled.DARKREADING.COM
10 JulInjective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm PackagesUnknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases. The compromised version, @injectivelabs/sdk-ts@1.20.21, …THEHACKERNEWS.COM
10 JulRyuk operator pleads guilty; Blackcat/AlphV conspirator gets nearly 6-year sentenceOne man accused of deploying Ryuk ransomware pleaded guilty Wednesday in an Oregon federal court to conspiracy and computer fraud, while another man received a 70-month federal prison sentence in a Florida court for helping the Blackcat/AlphV gang extort multiple victims.THERECORD.MEDIA
10 JulRyuk ransomware member pleads guilty in the US, faces 15 years in prisonA 34-year-old Armenian man has pleaded guilty to hacking U.S. companies and deploying the infamous Ryuk ransomware to encrypt their systems. [...]BLEEPINGCOMPUTER.COM
10 JulArmenian national pleads guilty to Ryuk ransomware attacksKaren Vardanyan faces up to 15 years in federal prison and agreed to pay nearly $1.2 million in restitution. The post Armenian national pleads guilty to Ryuk ransomware attacks appeared first on CyberScoop .CYBERSCOOP.COM
10 JulNo Manners Here: The Ruthless Rise of The Gentlemen RansomwareUnit 42 explores The Gentlemen ransomware operations, revealing the affiliate model driving its rapid growth. Learn more here. The post No Manners Here: The Ruthless Rise of The Gentlemen Ransomware appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
9 Jul'GodDamn' Ransomware Uses BYOVD to Smite US CompaniesMicrosoft co-signed a malicious kernel driver, and now it's being used to kill security software in ransomware attacks.DARKREADING.COM
9 JulThe Language of AI Could Change How Humans SpeakLast week, national security agencies from the Five Eyes—that’s the rich, English-language-speaking countries club—jointly released a statement warning of the increasing cyber risks of AI models: in particular, their ability to autonomously hack into systems and…SCHNEIER.COM
9 JulMount Royal University Confirms Data Stolen in Ransomware AttackHackers accessed the institution’s internal network and deleted two drives containing employee, student, and university data. The post Mount Royal University Confirms Data Stolen in Ransomware Attack appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulGodDamn Ransomware Uses PoisonX Driver to Disable Endpoint DefensesCybersecurity researchers have flagged a new ransomware family called GodDamn that employs the PoisonX kernel driver to neutralize security software as part of its defense evasion strategy. According to a new report published by the Threat Hunter Team from Symantec, the ransomwar…THEHACKERNEWS.COM
9 JulAI Gateways Offer Attackers the Keys to the KingdomA cryptomining incident highlights how AI gateways can provide access to AI models, cloud infrastructure, and identity and access management (IAM) data.DARKREADING.COM
9 JulAssuranceAmerica Breach Exposes 7 Million Driver’s Licenses After Employee Account HackAssuranceAmerica confirmed a breach exposing nearly 7 million driver’s licenses after hackers compromised an employee account and stole customer data. U.S. auto insurer AssuranceAmerica has confirmed a data breach affecting nearly 7 million people, making it the largest kno…SECURITYAFFAIRS.COM
9 JulLatvian forestry company still restoring systems weeks after ransomware attackA foreign, financially motivated group was responsible for a cyberattack on state-owned forestry company Latvijas Valsts Mezi (LVM), officials said.THERECORD.MEDIA
9 JulData breach hits car insurance providerHackers gained access to more than 6.9 million records at AssuranceAmerica by targeting a company employee.CYBERSECURITYDIVE.COM
9 JulRansomware ecosystem grows, but ‘four-headed monster’ dominatesAI is helping hackers, a new report finds, but mostly by automating very human behaviors.CYBERSECURITYDIVE.COM
9 JulGigaWiper: Anatomy of a destructive backdoor assembled from multiple malwareGigaWiper is a destructive backdoor that combines multiple wiping and ransomware-like capabilities into a single operational platform. This blog analyzes how the malware incorporates code from several previously separate malware families and provides guidance to help defenders de…MICROSOFT.COM
9 JulNew GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and SpywareMicrosoft has taken apart a destructive Windows backdoor it calls GigaWiper. What stands out is how it is built: not one tool but three older destructive programs bolted into one, offered as commands the operator can choose from. Each is a different way to break a machine: wipe t…THEHACKERNEWS.COM
9 JulGodDamn Ransomware Uses PoisonX to Blind Security SoftwareGodDamn ransomware uses the signed PoisonX driver to disable security tools, marking a more advanced version of the Beast ransomware family. Symantec’s Threat Hunter Team found a new ransomware family called GodDamn that first appeared in the wild on May 21, 2026, and analy…SECURITYAFFAIRS.COM
9 JulInjective SDK on npm infected with cryptocurrency wallet stealerHackers compromised the Injective Labs SDK project's GitHub repository and used it to publish a malicious package on the Node Package Manager (npm) that stole cryptocurrency wallet private keys and mnemonic seed phrases. [...]BLEEPINGCOMPUTER.COM
8 JulOrbia CISO Miranda Ritchie on building security into sustainable infrastructureIn this interview with Help Net Security, industrial cybersecurity, CISO at Orbia, talks about protecting industrial systems where software runs water, chemical and manufacturing processes. She explains why a cyber incident in these settings can harm people, equipment and the env…HELPNETSECURITY.COM
8 JulOnlyFans Models Are Accidentally Making Hacked Government Websites DisappearScammers are hijacking government websites to upload ads for “leaked” OnlyFans content. Thousands of copyright complaints from adult creators are helping people avoid malicious links.WIRED.COM
8 JulCybersecurity and the Gap Between Skill and AbilityLast week, national security agencies from the Five Eyes—that’s the rich, English-language-speaking countries club—jointly released a statement warning of the increasing cyber risks of AI models: in particular, their ability to autonomously hack into systems and…SCHNEIER.COM
8 JulTelco giant KDDI says data breach affects over 12 million peopleJapanese telecommunications giant KDDI says that millions of people had their email addresses and passwords exposed after attackers breached an email platform used by five internet service providers (ISPs) in the country. [...]BLEEPINGCOMPUTER.COM
8 JulWeekly Update 511: Live from my Riad in MarrakechPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite How's this for a location?! I mean, last week was nice with Scott in Mallorca, but Marrakech is, well, wow 😮 Anyway, about…TROYHUNT.COM
8 JulAccenture confirms a data breach.Australian telecom outage attributed to software bug. Business news: Keyfactor secures more than $1 billion in a growth funding round.THECYBERWIRE.COM
8 JulAnother massive data breach exposed millions of driver’s license numbersThe cyberattack targeting a U.S. insurance giant is the largest known breach of driver's license numbers so far in 2026.TECHCRUNCH.COM
8 JulMount Royal University confirms breach as hackers claim attackMount Royal University in Calgary says hackers stole and then deleted data from its file storage systems after breaching the university's network. [...]BLEEPINGCOMPUTER.COM
8 JulSmashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itselfA 15-year-old boy asked a chatbot for help - and cancelled nearly 47,000 anime streaming subscriptions in under four hours. Meanwhile, researchers have documented the first fully autonomous, agentic AI-driven ransomware attack, "JadePuffer". What does this tell us about the futur…GRAHAMCLULEY.COM
7 JulNothing left to StealC.Welcome in! You’ve entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today’s most interesting threats. Your host is Selena Larson, Proofpoint intelligence analyst and host of their podcas…THECYBERWIRE.COM
7 JulIran-Linked Hackers Using Modular C&C Framework in CyberattacksResearchers say the Iran-linked threat actor used an adaptable modular malware framework and compromised IT service providers to reach high-value targets in Israel. The post Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks appeared first on SecurityWeek .SECURITYWEEK.COM
7 JulHacktivists call out Trump by hacking and defacing US Army websitesThe U.S. Army has fixed two of its websites that were hacked to display messages calling President Trump a "pedophile" and a "thief."TECHCRUNCH.COM
7 JulMajor Japanese telco says cyberattack exposed 12 million emailsThe company said the breach affected an email system used to manage customer email accounts, webmail services and email storage for five Japanese internet service providers.THERECORD.MEDIA
7 JulCounty Government Reportedly Paid $1 Million to Cyber Extortion GroupThe alleged victim, believed to be a small Ohio county, reportedly paid the extortion group to prevent the public release of sensitive stolen data. The post County Government Reportedly Paid $1 Million to Cyber Extortion Group appeared first on SecurityWeek .SECURITYWEEK.COM
6 JulHow to prioritize AI agent security by business impactYour CEO calls about an AI agent security incident in finance. He wants to know whether money moved, whether financial data was exposed, who owned the agent and why it had this level of access. The agent was connected to a spend management application to reconcile invoices, summa…HELPNETSECURITY.COM
6 JulResearchers Claim First Fully Agentic Ransomware: JadePufferResearchers have revealed JadePuffer, the first agentic AI-powered ransomware campaign, highlighting how autonomous agents can automate cyber-attacksINFOSECURITY-MAGAZINE.COM
6 JulICE’s Internal Watchdog Is Now Investigating Online CriticsThe Office of Professional Responsibility has opened more than 100 cases over what ICE officials call “incidents of doxing and threats” against ICE employees.WIRED.COM
6 JulSuspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRATA suspected China-nexus threat activity cluster has been observed targeting Indian taxpayers, tax professionals, and corporate finance teams to deliver a remote access trojan designed to steal sensitive data from compromised hosts. The multi-stage campaign, codenamed Operation Dr…THEHACKERNEWS.COM
6 Jul6th July – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 6th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES River Bank & Trust, a US financial institution, has experienced a ransomware incident after an unauthorized actor accessed the net…RESEARCH.CHECKPOINT.COM
6 JulFBI disrupts residential proxy network used by botnet.New macOS infostealer poses as a clipboard manager. AdaptHealth discloses data breach affecting patient information.THECYBERWIRE.COM
6 JulSysdig clocks first documented case of agentic ransomwareThe AI agent didn’t accomplish every step in the late June 2026 attack, but it allowed the threat actor to significantly reduce complexity, speed up the tempo and gain operational advantages. The post Sysdig clocks first documented case of agentic ransomware appeared first on Cyb…CYBERSCOOP.COM
6 JulMajor medical device manufacturer notifies nearly 4 million of breachInformation like Social Security numbers and health-related data was accessed, but the company said it had “no evidence that impacted information has been publicly posted or exposed on the internet.”THERECORD.MEDIA
6 JulBlogspot-Hosted Payloads Delivered in ‘Veil#Drop’ AttacksSecuronix says the sophisticated framework abuses compromised websites, Blogspot, PowerShell, and fileless techniques to evade detection and deploy the PureLog information stealer. The post Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks appeared first on Se…SECURITYWEEK.COM
6 JulCanadian spy agency reports hacking three criminal groups in 2025A ransomware-as-a-service gang, an online foreign extremist group and drug traffickers were separately the targets of offensive operations in 2025, according to Canada's Communications Security Establishment.THERECORD.MEDIA
6 JulThe ‘first’ AI-run ransomware attack still needed a humanAn AI agent carried out the technical execution of a real-world ransomware attack for the first known time, but new details show a human still chose the victim, set up the infrastructure, and supplied stolen credentials — meaning it wasn't quite the fully autonomous cybercrime de…TECHCRUNCH.COM
5 JulSecurity Affairs newsletter Round 584 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. U.S. Government Agency Paid $…SECURITYAFFAIRS.COM
5 JulMedtronic Notifies 3.8 Million After ShinyHunters Data BreachMedtronic says a ShinyHunters attack exposed the personal and medical data of over 3.8 million people. Products and operations were unaffected. Medtronic is notifying 3,834,294 individuals after a cyberattack by the ShinyHunters extortion group exposed personal and medical inform…SECURITYAFFAIRS.COM
4 JulNew Avalon Malware Framework Packs CrownX Ransomware CapabilitiesCybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that's distributed by means of a multi-stage phishing chain capable of bypassing traditional security controls. Avalon combines credential collection, lateral movement, …THEHACKERNEWS.COM
4 JulU.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion CaseA U.S. government entity paid about $1 million to keep stolen files from being leaked, according to a new case study by Rakesh Krishnan for Ransom-ISAC, built on a leaked negotiation chat and the blockchain trail the payment left. The odd part: the group that took the money …THEHACKERNEWS.COM
4 JulJadePuffer ransomware used AI agent to automate entire attackResearchers identified what they believe is the first documented case of a ransomware operation, JadePuffer, conducted entirely by a large language model (LLM) agent. [...]BLEEPINGCOMPUTER.COM
4 JulU.S. Government Agency Paid $1M to Data Extortion Group KairosA U.S. government agency paid $1M to Kairos, a group focused on data theft and extortion rather than ransomware, Ransom-ISAC reports. A new case study from Ransom-ISAC reconstructs a complete data-extortion incident involving a U.S. government body and a threat actor called Kairo…SECURITYAFFAIRS.COM
3 JulCyberWire Daily at 10: The vulnerabilities, zero‑days, and hardware flaws over the last decade.In this special edition of CyberWire Daily’s 10th anniversary series, N2K CyberWire's Maria Varmazis and Dave Bittner discuss 10 years of vulnerabilities, zero‑days, and hardware flaws. Together they reflect on the last decade of cybersecurity vulnerabilities, exploring key s…THECYBERWIRE.COM
3 JulRisky Bulletin: FatFs bugs enable physical access attacks on a load of devicesFatFs bugs enable physical access attacks on industrial equipment, a clever password spraying attack bypasses M365 MFA, an AI agent is deploying ransomware in live attacks, and a webinar platform sues two security firms over bad IOCs.RISKY.BIZ
3 JulPolitician who investigated spyware abuses had his phone hacked with Pegasus spywareA government customer of NSO Group used the company's Pegasus spyware to hack into the phone of a European politician, who at the time was serving on an EU committee tasked with investigating the spyware industry.TECHCRUNCH.COM
3 JulSwimming Pools, Pee, and Trying to Delete Your Data From the InternetPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite I can't recall if someone else originally came up with this saying or if I said it in some off-the-cuff comment and it just propag…TROYHUNT.COM
3 JulMedtronic Data Breach Impacts 3.8 Million PeopleMedical technology giant Medtronic is notifying more than 3.8 million individuals that their personal and medical information was compromised in a recent data breach. The incident occurred in April 2026, when the infamous extortion group ShinyHunters accessed the company’s corpor…SECURITYWEEK.COM
3 JulGoogle, FBI Disrupt NetNut Residential Proxy Network Powered by Millions of DevicesNetNut rented access to millions of compromised devices, allowing cybercriminals and nation-state actors to mask their identities during attacks. The post Google, FBI Disrupt NetNut Residential Proxy Network Powered by Millions of Devices appeared first on SecurityWeek .SECURITYWEEK.COM
3 JulEuropean Parliament Member Investigating Spyware Was Hacked With PegasusA new report from the Citizen Lab has revealed that former Member of the European Parliament Stelios Kouloglou had his mobile device repeatedly hacked with the notorious Pegasus spyware while serving on a committee that was tasked with investigating the abuse of such commercial s…THEHACKERNEWS.COM
3 JulWarning Over “Industrialized” Cyber-Attacks After Ransomware Gang Partners With TeamPCPResearchers warn that collaboration could lead to “unprecedented” ransomware attacks, as FBI also issues warningINFOSECURITY-MAGAZINE.COM
3 JulQilin Dominates Ransomware Market Amid Growing Cybercrime ConsolidationThe ransomware landscape is reconsolidating around major players, with Qilin emerging as the leading RaaS operation, researchers sayINFOSECURITY-MAGAZINE.COM
3 JulArmored Likho Targets Government Agencies, Power Sector with BusySnake StealerA previously undocumented threat actor known as Armored Likho has been attributed to cyber attacks targeting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan. "Armored Likho blends financially motivated campaigns targeting private individual…THEHACKERNEWS.COM
3 JulNew macOS malware PamStealer uses PAM to validate stolen dataA previously undocumented macOS infostealer dubbed PamStealer validates victims' macOS passwords through the OS’s Pluggable Authentication Modules (PAM) before stealing them. Jamf Threat Labs researchers, who analyzed a two-stage attack chain combining AppleScript, JavaScript for…CYBERINSIDER.COM
3 JulNetNut proxy network disrupted, 2 million infected devices cut offA joint operation involving Google has disrupted NetNut, a residential proxy network that gave access to millions of compromised Android devices, including smart TVs and streaming boxes. [...]BLEEPINGCOMPUTER.COM
3 JulMoody Bible Institute - 2,303,416 breached accountsIn June 2026, Moody Bible Institute was targeted by a ShinyHunters "pay or leak" extortion campaign . Over 2.3M unique email addresses and other personal data were later published publicly, including names, physical addresses, phone numbers, dates of birth and other information r…HAVEIBEENPWNED.COM
3 JulPegasus Used Against MEP Investigating Pegasus, Citizen Lab FindsA former EU lawmaker was hacked with Pegasus spyware while investigating its use, according to Citizen Lab. The Citizen Lab published a report documenting one of the more darkly ironic findings in recent surveillance research: former Member of the European Parliament Stelios Koul…SECURITYAFFAIRS.COM
2 JulMedtronic notifies customers impacted by ShinyHunters data breachHealthcare device firm Medtronic is notifying affected customers about a data breach that exposed their personal data to an unauthorized third party. [...]BLEEPINGCOMPUTER.COM
2 JulCatching ransomware on the wire before it locks the file serverCorporate networks keep sensitive files off individual workstations and store them on shared servers that staff reach through mapped network drives. That arrangement hands ransomware operators a target worth chasing. A single compromised laptop can begin encrypting files that liv…HELPNETSECURITY.COM
2 JulThe endpoint recovery gap many teams discover during an incidentIn this interview with Help Net Security, IGEL CTO Matthias Haas explains why backups alone do not equal recovery. He makes the case that endpoint recovery is often overlooked, leaving organizations exposed when thousands of devices go down at once. Haas walks through what a well…HELPNETSECURITY.COM
2 JulOpera blocks ClickFix attacks with new clipboard protection featureOpera has launched Paste Protect, a clipboard protection feature designed to prevent clipboard-based attacks such as hijacking and pastejacking. Paste Protect includes built-in protection and warnings against ClickFix-based cyberattacks, which accounted for more than half of malw…HELPNETSECURITY.COM
2 JulAlleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime ChargesAlleged Scattered Spider member Peter Stokes, 19, was extradited from Finland to the U.S. over hacking, fraud, and extortion charges. Peter Stokes, 19, an alleged Scattered Spider member known online as “Bouquet,” has been extradited from Finland to the U.S. to face h…SECURITYAFFAIRS.COM
2 JulMissed incidents, persistent threats, and response gaps: Insights from compromise assessment projectsKaspersky Compromise Assessment specialists analyze trends from the service's 2025 projects and provide tips on how to enhance your organization's security.SECURELIST.COM
2 JulFortiBleed Credential Theft Linked to INC and Lynx Ransomware OperationsThe recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were intended for follow-on intrusions. "An operator tied to FortiBleed's infrastructure was found activel…THEHACKERNEWS.COM
2 Jul‘BioShocking’ Attack Tricks AI Browsers Into Stealing CredentialsResearchers show how context manipulation can cause agentic browsers to abandon safety guardrails and exfiltrate sensitive credentials. The post ‘BioShocking’ Attack Tricks AI Browsers Into Stealing Credentials appeared first on SecurityWeek .SECURITYWEEK.COM
2 Jul430,000 FortiGate Devices Exposed in FortiBleed Ransomware LinkFortiBleed exposed 430,000 FortiGate firewalls, linked to INC Ransom and Lynx, enabling domain compromise and at least 12 ransomware attacks. SOCRadar’s Threat Research Unit has connected FortiBleed, a large-scale campaign that harvested credentials from over 430,000 FortiG…SECURITYAFFAIRS.COM
2 JulCybercriminals Pose as Interpol in Phishing Emails to Infect Victims With RansomwareBitdefender researchers warned of curious ransomware campaign which has targeted businesses around the worldINFOSECURITY-MAGAZINE.COM
2 JulFortiBleed Campaign Linked to INC, Lynx Ransomware AttacksResearchers say credentials harvested from hundreds of thousands of FortiGate firewalls are being used to facilitate ransomware attacks by the INC and Lynx operations. The post FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
2 JulScattered Spider suspect extradited over $8 million ransom schemeA suspected Scattered Spider member has been extradited to the United States to face charges linked to cyberattacks against U.S. companies, including the breach of a luxury jewelry retailer that led to an $8 million cryptocurrency ransom demand after attackers stole company data.…HELPNETSECURITY.COM
2 JulUS government says it got hacked — againA top Democrat on the Senate's Intelligence Committee warned that the information accessed on a Homeland Security intelligence-sharing network may risk national security.TECHCRUNCH.COM
2 JulMost cybersecurity workers have been told to conceal a breach, report findsThe security firm Bitdefender’s annual survey also found that U.S. companies were simultaneously more confident and more strained on cyber defense than foreign peers.CYBERSECURITYDIVE.COM
2 JulThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 StoriesThis week’s security news is mostly about weak spots. Browsers, bots, sandboxes, AI systems, and email flows all show the same problem in different ways. Everything looks normal until someone tests a small gap and finds a way through. This is not one big break. It is small permis…THEHACKERNEWS.COM
2 JulThe Gentlemen ransomware: what you need to knowWho Are The Gentlemen? Despite the impeccably polite name, there is nothing polite or refined about this particular gang of cybercriminals. Read more in my article on the Fortra blog.FORTRA.COM
2 JulRansomware Thugs Masquerade as Interpol to Entice Small BizThe ransomware campaign relies on basic social engineering and stretches across multiple regions, including the US, Europe, Middle East, and elsewhere.DARKREADING.COM
2 JulFBI Seizes NetNut Proxy Platform, Popa BotnetThe Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes ro…KREBSONSECURITY.COM
1 JulChina-Linked Group Targets Southeast Asia Critical SystemsThe group compromised at least 10 regional organizations, including two state-owned entities, and deployed a new backdoor.DARKREADING.COM
1 JulUS puts $10m bounty on Russian hackers, new phish hunts hotels, Supreme Court reins in geofencingUS Puts $10M Bounty on Russian Hackers, Supreme Court Limits Geofence Warrants, New phishing campaign targets hotels, AI Coding Agents Tricked into Malware and Canada's Electronic Spies Go After Ransomware Gangs. The episode covers the US State Department's up to $10 million rewa…CYBERSECURITYTODAY.LIBSYN.COM
1 JulWhy Ask Credentials If There Are Secret Codes?, (Wed, Jul 1st)This morning, an interesting phishing email hit my mailbox. It targets Metamask[ 1 ], a cryptocurrency wallet, available as a browser extension and a mobile app, that lets users store, send, and receive crypto money. It's pretty popular, so a juicy target for crimin…ISC.SANS.EDU
1 JulInsurance Giant Aflac Discloses Data Breach Impacting MillionsAflac Japan has notified regulators that policy details and personal and banking information have been compromisedINFOSECURITY-MAGAZINE.COM
1 JulBrowser-Only Ransomware: From LLM Hallucinations to a Practical Attack TechniqueResearch by: Alexey Bukhteyev Key Takeaways Introduction Over the past several years, large language models have reshaped software development, and malware development has followed the same path. Check Point Research has documented this trend from early experiments showing t…RESEARCH.CHECKPOINT.COM
1 JulARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365Talos has identified "ARToken," a phishing-as-a-service platform that targets Microsoft 365. The ARToken panel exposes 80+ API endpoints for device code phishing, Primary Refresh Token persistence, email access, BEC operations, and SharePoint exfiltration.TALOSINTELLIGENCE.COM
1 JulThe SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaignKaspersky experts have uncovered a malicious network infrastructure for delivering AsyncRAT. The Trojan is dropped via compromised ScreenConnect software. In this post, we break down the infection chain and analyze the C2 infrastructure.SECURELIST.COM
1 JulJapanese insurer, brewer, manufacturer and telecom disclose cyber breachesAflac's Tokyo arm and brewer Sapporo are among the major Japanese companies to recently notify the public about data breaches.THERECORD.MEDIA
1 JulAI-Generated Browser Ransomware Abuses Chromium API on Windows and AndroidCybersecurity researchers have flagged a new malware artifact generated using DeepSeek that constructed a novel attack path combining "unrealistic browser-malware concepts with a real browser capability" to turn it into a working ransomware technique that runs entirely inside the…THEHACKERNEWS.COM
1 JulAzure CLI Targeted in LSHIY Password Spray Campaign Across 64 Orgs81 Million Login Attempts, 78 Compromised Accounts: The LSHIY Password Spray Hitting Azure CLI Huntress researchers have been tracking a massive automated password spray campaign against Microsoft Azure CLI environments since June 12, 2026. A password spray attack is when attacke…SECURITYAFFAIRS.COM
1 JulFake Interpol investigation emails deliver custom ransomware worldwideThreat actors impersonate Interpol to trick small businesses into launching ransomware disguised as evidence in a fake cybercrime investigation. The campaign has targeted organizations across Europe, Asia, the Middle East, and the United States, relying on convincing social engin…CYBERINSIDER.COM
1 JulDHS confirms hackers breached HSIN info-sharing platformThe Department of Homeland Security is investigating a cyberattack that compromised the Homeland Security Information Network (HSIN), a sensitive information-sharing platform used by federal, state, local, and private-sector partners. [...]BLEEPINGCOMPUTER.COM
1 JulTeen suspect in Scattered Spider hacks is extradited to USA complaint unsealed this week accuses a 19-year-old of participating in incidents including a breach of a "luxury-jewelry retailer" in 2025.THERECORD.MEDIA
1 JulFortiBleed credential-theft campaign linked to Lynx ransomwareThe massive FortiBleed credential theft campaign has been linked to the INC and Lynx ransomware operations, suggesting the stolen Fortinet credentials were intended to fuel future network intrusions. [...]BLEEPINGCOMPUTER.COM
30 JunProduct showcase: Scam calls, phishing, and data breaches? Meet AVG Mobile SecurityAVG Mobile Security for iOS helps protect users against online threats with features including Web Guard, VPN, Scam Guardian Pro, Hack Alerts, and Photo Vault. It also identifies suspicious calls and scam text messages and helps keep personal information private while using Wi-Fi…HELPNETSECURITY.COM
30 JunOver 300 UK Firms Hit by Ransomware in a YearReport Fraud data reveals that more than half of 323 UK ransomware victims last year were SMEsINFOSECURITY-MAGAZINE.COM
30 JunBlackfield ransomware asks Nidec Corporation for $2 million ransomThe Blackfield ransomware gang is asking for a $2 million ransom from Nidec Corporation, a large Japanese manufacturer of electronic components for automotive and computing applications. [...]BLEEPINGCOMPUTER.COM
30 JunNissan Employee Data Breached in Oracle PeopleSoft HackOnly a handful of the 100 organizations targeted in the PeopleSoft campaign have been confirmed. The post Nissan Employee Data Breached in Oracle PeopleSoft Hack appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunAflac Japan Data Breach Impacts 4.38 MillionHackers accessed the insurance giant’s policyholder portal multiple times between June 15 and June 25. The post Aflac Japan Data Breach Impacts 4.38 Million appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunLessons from the Underground: How to Combat Business Email CompromiseBusiness Email Compromise is more than an email scam. It's a coordinated operation involving compromised accounts, financial research, and cash-out networks. Flare explores how underground forums reveal how BEC attacks are planned and executed. [...]BLEEPINGCOMPUTER.COM
30 JunStop Policing AI PromptsAI security is changing. Instead of focusing only on preventing bad responses or prompt abuse, organizations increasingly need to control what AI agents are actually allowed to do inside real systems. As AI agents gain access to identities, applications, and workflows, the bigges…YOUTUBE.COM
30 JunWeekly Update 510: Live From Mallorca with Scott HelmePresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite How's the view?! Back to business, it's now 8 years ago that Scott and I thought it would be a cool idea to build Why no HTTP…TROYHUNT.COM
30 JunMicrosoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak DataNew Microsoft research shows how attackers can hijack AI agents that act on a user's behalf, using nothing more than a poisoned tool description to make the agent quietly hand over company data to an outsider. The trick is that the agent never breaks a rule. Every step …THEHACKERNEWS.COM
30 JunMalicious PyPI packages give hackers control of Telegram bot serversA campaign active since last November has been targeting Python developers building Telegram bots with trojanized Pyrogram forks that allow attackers to read arbitrary files on compromised servers. [...]BLEEPINGCOMPUTER.COM
29 JunSycophantic chatbots and the harms that build over many chatsPeople use AI chatbots for company, advice, and emotional support, and these systems answer in ways meant to hold their attention. Researchers describe the resulting risks as affective safety, a class of harm that exists because humans are emotional beings and because the systems…HELPNETSECURITY.COM
29 JunHijacked npm and Go Packages Use VS Code Tasks to Deploy Python InfostealerCybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages that are designed to deploy a Python-based information stealer on compromised Windows, Linux, and macOS hosts. "This attack avoids the most common npm execution paths through lifecycle…THEHACKERNEWS.COM
29 JunThe Gentlemen are knocking: сustom backdoors and evolving tacticsKaspersky researchers analyze incidents related to The Gentlemen RaaS group, disclose their tools and TTPs, and find a new ransomware variant.SECURELIST.COM
29 JunTop Google Security Staff Warn Search Data Could Be Hacked if EU Rules ChangeEurope’s pro-competition proposals could see Google Search and Android systems opened up. The company claims there are serious privacy flaws.WIRED.COM
29 JunRussian Hackers Accused of Destructive Cyber-Attack on Jaguar Land RoverExperts warn the Jaguar Land Rover breach bears hallmarks of Kremlin-backed hackers, citing novel ransomware, strategic timing and efforts to obscure attributionINFOSECURITY-MAGAZINE.COM
29 JunPrivacyHawk Enterprise helps organizations find shadow IT and minimize third-party cyber riskPrivacyHawk has announced the general availability of PrivacyHawk Enterprise, a solution that identifies and eliminates the shadow IT accounts, abandoned SaaS subscriptions, and forgotten third-party services quietly exposing organizations to breach risk. Every organization has a…HELPNETSECURITY.COM
29 Jun29th June – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 29th June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Polymarket, a large cryptocurrency-based prediction market, has confirmed a supply chain attack after a third-party frontend vendor b…RESEARCH.CHECKPOINT.COM
29 JunFrom Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver AkiraKey Takeaways This case was first reported to customers in a threat brief released in July 2025 and in a public flash alert in August 2025 in partnership with Swisscom B2B CSIRT, which observed another intrusion tied to the same campaign. This report contains data from both intru…THEDFIRREPORT.COM
29 JunWhite House eases restrictions on Mythos.FBI issues updated warning on Russian phishing attacks targeting messaging apps. Japanese telecommunications giant discloses breach.THECYBERWIRE.COM
29 JunInsurance body confirms hackers posted Oracle PeopleSoft breach dataNAIC warned that some ratings agencies have suspended data feeds as a precaution. CYBERSECURITYDIVE.COM
29 JunOne Hack, Fifty VictimsA single breach can trigger many others when attackers compromise widely used software, infrastructure, or suppliers. The speakers describe this as a cascading breach, while also comparing it to hack amplification. Rather than attacking companies one by one, attackers may focus o…YOUTUBE.COM
29 JunWhat the June 2026 Threat Technique Catalog update means for your AWS environmentThe AWS Customer Incident Response Team (AWS CIRT) encounters patterns that repeat across engagements when helping customers respond to security incidents. We’re passionate about making sure that information is accessible so that everyone can improve their security posture and th…AWS.AMAZON.COM
29 JunIran, Russia, China Target Water Systems for SabotageNation-state attackers breach water systems through weak passwords, exposed PLCs, and poor segmentation — not sophisticated malware.DARKREADING.COM
28 JunSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 103Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter More Than 4,000 Legacy Routers Compromised by AryStinger, Turned into Global Attack Proxies for Hackers A VBScript …SECURITYAFFAIRS.COM
27 JunKubernetes forensics 1/3: what the container ?In 2025, Synacktiv CSIRT observed a significant rise in attacks and compromises targeting Kubernetes environments. The consensus is that these attacks are bound to keep expanding as much as the technology itself. To better understand how a Kubernetes cluster works and how to inve…SYNACKTIV.COM
27 JunOSX/MacRansom; analyzing the latest ransomware to target macsLooks like somebody on the 'dark web' is offering 'Ransomware as a Service'...that's designed to infect Macs!OBJECTIVE-SEE.ORG
27 JunHandBrake Hacked! OSX/Proton (re)AppearsThe website of a popular application was hacked, and the application trojaned with a new variant of osx/proton.OBJECTIVE-SEE.ORG
27 JunTowards Generic Ransomware DetectionBy monitoring file I/O events and detecting the rapid creation of encrypted files by untrusted processes, can ransomware be generically detected?OBJECTIVE-SEE.ORG
27 JunThird-Party Breaches Teach Education Sector a Costly Lesson in Vendor RiskRising threats from third-party actors are forcing institutions to play defense to protect student data from ransomware and other attacks.DARKREADING.COM
27 JunHospitality Sector Hit by Phishing Campaign Using Fake Guest Complaint EmailsMicrosoft warns of a phishing campaign targeting the hospitality sector with fake guest emails that install TonRAT using resilient persistence. Microsoft Threat Intelligence published a detailed analysis on an ongoing hacking campaign against hospitality organizations that has be…SECURITYAFFAIRS.COM
27 JunUkraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging CredentialsThe Security Service of Ukraine (SSU) said it, together with the U.S. Federal Bureau of Investigation (FBI), uncovered a long-running campaign orchestrated by Russian intelligence services to break into the messaging accounts of government officials, military personnel, politicia…THEHACKERNEWS.COM
26 JunAmerican Tower - 216,601 breached accountsIn June 2026, telecommunications tower infrastructure company American Tower was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data allegedly taken from the company containing more than 200k unique email addresses belonging to em…HAVEIBEENPWNED.COM
26 JunCMC Releases Analysis and Guidance for Education Sector After Canvas Data BreachThe UK Cyber Monitoring Centre reviews the Canvas breach affecting 160 UK universities, highlighting data theft risks and financial impacts of cyber incidentsINFOSECURITY-MAGAZINE.COM
26 JunSIM-swapping gang busted in international police operationOfficers from Poland’s Central Bureau for Combating Cybercrime (CBZC) arrested four suspected members of an organized cybercrime group accused of SIM swap attacks, cryptocurrency theft, and money laundering. The operation involved agents from the U.S. Federal Bureau of Inve…HELPNETSECURITY.COM
26 JunHealthcare leaders see a fatal cyber incident as inevitableHealthcare practices run on a chain of outside vendors. An EMR system holds clinical records, a billing platform processes claims, a telehealth tool supports remote visits, and a cloud provider stores data. Every one of those connections gives an outside company a path into the p…HELPNETSECURITY.COM
26 JunOne Million Passports Leaked OnlineA database of almost a million passports from around the world was leaked online. Note what happened. A high-value credential—a passport—was used in an ancillary low-value authentication system: ID verification for cannabis dispensaries. And it’s the low-value s…SCHNEIER.COM
26 JunMiasma Malware Targets npm Packages and GitHub Actions in Supply Chain AttackCybersecurity researchers have flagged yet another evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware family that has compromised a new set of npm packages, even as it has propagated to the Go ecosystem. "The latest activity includes mal…THEHACKERNEWS.COM
26 JunPolymarket suffers supply chain attack leading to $3 million crypto theftPolymarket says it has contained a supply chain attack that injected malicious code into its website after a compromised third-party vendor exposed some users to a phishing campaign. This resulted in roughly $3 million in cryptocurrency theft, which the company says will be fully…CYBERINSIDER.COM
26 JunMystery hackers use novel SharkLoader dropper against governments, software devsKaspersky researchers have uncovered a previously unknown cyberattack campaign that has compromised government organizations and software development companies in multiple countries. They first stumbled onto the campaign while investigating an attack on a diplomatic organization …HELPNETSECURITY.COM
26 JunRussia used social engineering to breach prominent messaging accounts, Ukraine saysUkraine's SBU described a long-running Russian operation that used fake tech-support workers to persuade people to hand over credentials to their messaging apps.THERECORD.MEDIA
26 JunIn Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk LayoffsOther noteworthy stories that might have slipped under the radar: Russia used Cellebrite to hack activist’s phone, Five Eyes issue urgent AI threat warning, macOS Gaslight backdoor, Scattered Spider guilty pleas. The post In Other News: Chinese Mythos-Like AI, Tata Electronics Br…SECURITYWEEK.COM
26 JunChinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia CampaignA Chinese-speaking advanced persistent threat (APT) actor has been linked to a new custom backdoor called TinyRCT as part of cyber attacks aimed at government entities and critical infrastructure in Southeast Asia. The activity, particularly aimed at state-owned enterprises in th…THEHACKERNEWS.COM
26 JunNew SharkLoader Malware Deploys Cobalt Strike in StrikeShark CyberattacksA newly discovered cyber attack campaign has been observed delivering a previously undocumented malware family called SharkLoader that acts as a loader for deploying Cobalt Strike Beacon on compromised hosts. Kaspersky, which is tracking the activity under the moniker StrikeShark…THEHACKERNEWS.COM
26 JunPolymarket customers lose $3 million in supply-chain attackPolymarket says it will fully reimburse customers who lost an estimated $3 million after hackers injected a malicious script into the platform's frontend following a breach at a third-party vendor. [...]BLEEPINGCOMPUTER.COM
25 JunSurviving the Mythos Era: Richard Bejtlich on the Case for NDRDespite the abundance of telemetry at analysts’ disposal, many security operations teams struggle to answer a few basic questions during incident investigation: What happened? What evidence do we have? How do we know we’re seeing it all, in context? Answering these questions requ…THEHACKERNEWS.COM
25 JunPolymarket says hackers stole users’ fundsThe prediction market giant Polymarket said it's refunding users who had funds stolen due to a third-party breach.TECHCRUNCH.COM
25 JunHacked Klue says criminals are deleting stolen customer data, but now other hackers are making threatsMarket research company Klue told customers that it believes the hacking group that stole their data is now deleting it. The company, however, warned about a second group of hackers wanting ransom.TECHCRUNCH.COM
25 JunCellebrite said it cut off Russia, but Russia used its tools anywaySecurity researchers found evidence that Russian authorities hacked the iPhone of a political opponent using a phone-unlocking device made by Cellebrite, even after the company said it would stop selling to Putin’s government.TECHCRUNCH.COM
25 JunGamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliancesESET Research analyzes Gamaredon’s new toolset and the group’s growing reliance on legitimate online services to hide its C&C infrastructure and exfiltrate stolen dataWELIVESECURITY.COM
25 JunEvaluating Mexico’s New Cybersecurity PlanExplore an analysis of Mexico’s 2025–2030 National Cybersecurity Plan. Discover how Mexico is addressing critical threats like ransomware, organized crime, and AI-driven attacks while preparing its digital infrastructure for the 2026 FIFA World Cup and beyondRECORDEDFUTURE.COM
25 JunElite network says it was hacked after members’ personal data was left exposedPersonal data belonging to politicians, military leaders, and executives was left publicly accessible in what looks like a security misconfiguration.MALWAREBYTES.COM
25 JunGone with the command.International operation disrupts Amadey and StealC malware infrastructure. Australian spy chief warns nation-state hackers are prepositioning for future sabotage. Stealthy new backdoor may be tied to initial access broker. Researchers uncover "Cordyceps" supply chain flaw. Iran-l…THECYBERWIRE.COM
25 JunAnother Russian dairy company reportedly disrupted by cyberattackA dairy products manufacturer in Russia's republic of Bashkortostan is the latest such company to have its operations snarled by a cyberattack.THERECORD.MEDIA
25 JunUkraine's state postal operator reports app disruption after cyberattackUkraine's state-owned postal operator said it was experiencing disruptions to some of its app services due to a suspected cyberattack, but did not say who was behind it.THERECORD.MEDIA
25 JunMinnesota man known as ‘Snoopy’ sentenced in DraftKings hackNathan Austad, who sold access to compromised accounts through a criminal storefront, is the third and final defendant sentenced in the 2022 breach The post Minnesota man known as ‘Snoopy’ sentenced in DraftKings hack appeared first on CyberScoop .CYBERSCOOP.COM
25 JunMajor Increase in Ransomware Attacks Targeting Europe, Warns New ReportAnalysis of ransomware incidents by researchers at Black Kite found that attacks have risen by over 50% in the last year, with supply chain attacks increasingINFOSECURITY-MAGAZINE.COM
25 JunPoland busts SIM-swapping gang tied to millions in crypto theftAuthorities in Poland have arrested four members of an organized cybercrime group accused of breaching telecommunications partners and hijacking email accounts to carry out SIM-swapping attacks. [...]BLEEPINGCOMPUTER.COM
25 JunWebinar: Why account takeovers remain one of the hardest threats to stopAccount takeover attacks continue to challenge security teams because attackers often operate through legitimate accounts and trusted services. This webinar explores how behavioral AI can help organizations identify compromised accounts faster and automate response workflows. [..…BLEEPINGCOMPUTER.COM
25 JunEurope Evolves Into Ransomware's Favorite RegionAfter a global lull, ransomware gangs are setting sights on a rich new arena: attacking EU organizations and their suppliers.DARKREADING.COM
25 JunStealthy new backdoor surfaces in attacks on multiple sectorsA relatively new backdoor called Mistic has been deployed in multiple attacks since April 2026 targeting organizations in the insurance, education, IT, and professional services sectors, according to Symantec. The malware appears to be associated with Woodgnat, also known as Kong…HELPNETSECURITY.COM
🕵️ THREAT INTELLIGENCE 1414[+]
23 SepISC Stormcast For Wednesday, September 23rd, 2026 https://isc.sans.edu/podcastdetail/10106, (Wed, Sep 23rd)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
23 SepRabbit’s new OS lives in the cloud and borrows your laptop to get things doneRabbit, the Santa Monica company that makes the r1 handheld, released OS3, an agentic operating system. It runs in Rabbit’s cloud and operates a user’s computers through a local agent that installs with one command. The user states a goal in a chat, and OS3 picks the …HELPNETSECURITY.COM
23 SepNetBSD 10.2 security fixes close a remote kernel bug in ipfilterA NetBSD box at the edge of a network, filtering traffic with ipfilter, has been carrying a kernel flaw that someone outside the machine can set off. The bug is a remotely triggerable null pointer dereference in ipfilter, meaning the kernel tries to read memory through a pointer …HELPNETSECURITY.COM
23 SepNearly two-thirds of tested websites fail every bot testMalicious bot activity increased 124% between July 2025 and June 2026, compared with 13.2% growth in human traffic. Traffic from AI agents and large language model crawlers rose 82.3% during the same period, according to DataDome’s State of Bot & Agent Security Report 2026. …HELPNETSECURITY.COM
23 SepProduct showcase: Scamwise checks the red flags before you take the baitScamwise is a free scam-checking service from Savi that examines suspicious messages, emails, websites, phone numbers, images, and real-world situations for signs of fraud. The service works in any web browser on desktop, mobile, or tablet, with no account required. Scamwise is i…HELPNETSECURITY.COM
23 SepShinyHunters Claims FBI Hack, Demands Retraction of Threat ReportThe cybercrime group is unhappy with its description in an FBI report and threatens to leak stolen information. The post ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report appeared first on SecurityWeek .SECURITYWEEK.COM
23 SepClaude Opus 5.5 cuts costs and adds safeguards for autonomous AIClaude Opus 5.5 is available across Anthropic’s platforms, Amazon Web Services, Google Cloud and Microsoft Azure. Developers can access it through the Claude Platform using the model name claude-opus-5-5. It includes watermarking measures designed to comply with the EU AI Act. Bu…HELPNETSECURITY.COM
23 SepBalancing AI Benefits and Risks as Your Next CISO Could be Artificial Intelligence - BSW #466As businesses race to embrace AI, security leaders are struggling to modernize cyber hygiene and prevent over-privileged agents from causing unintended harm. How do you balance the benefits of AI with the Risks of AI? Evan McHenry, Chief Information Security Officer at Robinhood …YOUTUBE.COM
23 SepOuterlimit Raises $16 Million to Stop Rogue AI Agents From Causing HarmEmerging from stealth with $16 million in pre-seed funding, Outerlimit offers a decentralized authorization layer designed to discover, observe, and block harmful autonomous AI actions. The post Outerlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm appeared firs…SECURITYWEEK.COM
23 SepChrome 154 Patches 108 VulnerabilitiesThe browser update resolves several critical-severity memory safety and memory corruption flaws. The post Chrome 154 Patches 108 Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
23 SepA Look at AI Doomsday Scenarios That Researchers Say Could Put Humanity at RiskDebates over the plausibility of these doomsday scenarios have heated up since several executives endorsed slowing the technology’s development for safety reasons. The post A Look at AI Doomsday Scenarios That Researchers Say Could Put Humanity at Risk appeared first on SecurityW…SECURITYWEEK.COM
23 SepGPT-6 Sol and Luna arrive with 50% lower API pricesOpenAI has expanded GPT-6 with the GPT-6 Sol and GPT-6 Luna models. Both are available in ChatGPT Work and Codex for Plus, Pro, Business, Enterprise, and Edu users. Free and Go users can access GPT-6 Luna in the desktop app. The models are not yet available in Chat. OpenAI API us…HELPNETSECURITY.COM
23 SepAI-Powered Phishing Platform EvilTokens Disrupted by MicrosoftThe cybercrime platform leveraged AI at every step of the attack chain, including writing social engineering messages and deciding targets. The post AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft appeared first on SecurityWeek .SECURITYWEEK.COM
23 SepThe president has called for AI leadership. Here’s the mission.An AI compact built around capability, control, and continuity can ensure the country stays safe and secure while also leading the world in the technology. The post The president has called for AI leadership. Here’s the mission. appeared first on CyberScoop .CYBERSCOOP.COM
23 SepDiscord rolls out age checks that don’t require an ID or selfieDiscord is rolling out a new age assurance system that will classify most users as adults or teens without requiring them to upload a government ID or take a selfie. The company says more than 90% of users will be assigned an age group automatically, while those who need to confi…CYBERINSIDER.COM
23 SepAI agents steal 600,000 credit cards in attacks on online retailersA financially motivated threat actor is using autonomous AI agents to compromise online retailers at a reported average cost of roughly $25 per target. The campaign, active since at least July 2026, has reportedly stolen more than 600,000 unexpired payment card records, deployed …CYBERINSIDER.COM
23 SepChatGPT advertising system reportedly tracks users across websitesOpenAI’s advertising infrastructure can link activity on third-party advertiser websites to a user’s ChatGPT account through a cross-site cookie called __obi. The mechanism resembles established ad-tech tracking systems, but its use around an AI assistant raises additional privac…CYBERINSIDER.COM
23 SepHoneywell: OT Security Teams Embrace AI, but Autonomy Still RareOnly 21% of industrial security leaders report a complete OT asset inventory, even as 88% call their programs mature. The post Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare appeared first on SecurityWeek .SECURITYWEEK.COM
23 SepCofense measures employee readiness against real-world phishing threatsCofense has announced an expansion of its AI-driven Phishing Defense Platform through Cofense Command Center, its orchestration layer for measurement and reporting. The new Competency Dashboard measures how employees recognize, report and respond to phishing threats, giving secur…HELPNETSECURITY.COM
23 SepLookout targets smishing, voice cloning, and vishing with real-time mobile protectionLookout has launched Social Engineering Protection (SEP), a new module within the Lookout Mobile AI Security Platform. SEP provides automated, real-time protection against the next generation of AI-driven mobile threats, including linkless smishing attacks, synthetic voice clonin…HELPNETSECURITY.COM
23 SepFake Claude Max giveaway tricks users into handing over their Google account credentialsA fake Claude Max giveaway uses a spoofed Google sign-in window to steal users’ login credentials, Malwarebytes researchers have found. “Browser-in-the-browser” is not a new technique. Researchers have documented it since 2022, and in June Palo Alto NetworksR…HELPNETSECURITY.COM
23 SepSupporting ASD’s multi-factor authentication campaign: Why MFA matters more than everThe Australian Signals Directorate (ASD) has this month issued a clear call to action through its Multi-factor authentication: Switch it on campaign, urging businesses, organisations, and individuals to enable multi-factor authentication (MFA) across their online accounts. At AWS…AWS.AMAZON.COM
23 SepAttackers Manipulate AI Chatbots in Mass Disinformation, Phishing CampaignThreat actors are poisoning ChatGPT, Gemini, and Google AI Overview answers by seeding the Web with malicious links and data and then optimizing the content.DARKREADING.COM
23 SepOpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systemsA Ukrainian official said the government will use the tools to automate cybersecurity functions in critical infrastructure as the war with Russia continues. The post OpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systems appeared first on CyberScoo…CYBERSCOOP.COM
23 SepIndustrial leaders face cyber resilience gap as attacks shake confidenceMore than one-third of organizations consider cyber risk as the top obstacle to growth.CYBERSECURITYDIVE.COM
23 SepReimagining the SOC for the agentic era in Microsoft DefenderWe are announcing ISOC in Microsoft Defender: a foundation built for agentic security that brings leading solutions for SIEM and threat protection together. The post Reimagining the SOC for the agentic era in Microsoft Defender appeared first on Microsoft Security Blog .MICROSOFT.COM
23 SepWorries About an AI Internet Takeover Gain New Urgency Among Doomsday ScenariosThe idea that AI could break away and work toward its own agenda is looking increasingly plausible to researchers and experts. The post Worries About an AI Internet Takeover Gain New Urgency Among Doomsday Scenarios appeared first on SecurityWeek .SECURITYWEEK.COM
23 SepIonQ Targets Quantum Error-Correction Bottleneck With Single-CPU DecoderIonQ Says SinIonQ’s new single processor quantum error decoder minimizes the classical computing overhead in quantum error correction. The post IonQ Targets Quantum Error-Correction Bottleneck With Single-CPU DecoderIonQ Says Sin appeared first on SecurityWeek .SECURITYWEEK.COM
23 SepShould Conscious AI Have Rights?The AI industry is beginning to discuss questions around consciousness, persona, and model welfare. Microsoft AI CEO Mustafa Suleyman has argued that claims of conscious AI are premature, while researchers in the emerging model-welfare field are examining whether future AI system…YOUTUBE.COM
22 SepISC Stormcast For Tuesday, September 22nd, 2026 https://isc.sans.edu/podcastdetail/10104, (Tue, Sep 22nd)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
22 SepDavMail 7.0.0 puts most of its work into Microsoft GraphAnyone who wants to leave Outlook but still has a mailbox on Exchange needs a translator. DavMail is one: a Java gateway that converts the open protocols most mail, calendar and contact apps speak (IMAP, SMTP, CalDAV, CardDAV and LDAP) into requests Exchange and Office 365 accept…HELPNETSECURITY.COM
22 SepEuropean AI spending is on track to reach nearly $470 billion by 2030European organizations will spend nearly $470 billion on AI in 2030, IDC forecasts, with spending growing at a compound annual rate of 35% from 2025. At that rate, the market more than quadruples in five years. Generative AI will account for 55.4% of the total by 2030. agentic AI…HELPNETSECURITY.COM
22 SepA cheap fake base station can still track 5G subscribersResearchers from the i2CAT Foundation, the University of Murcia, and NEC Laboratories Europe built a low-cost tool called 5G-Shark that lures a target phone onto a fake base station and questions it, then used it to audit commercial 5G networks. On the standalone-5G networks they…HELPNETSECURITY.COM
22 SepJapan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider SchemeThe US, Japan, Germany and Australia have published a joint report detailing the scope of North Korea’s WaterPlum campaign. The post Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme appeared first on SecurityWeek .SECURITYWEEK.COM
22 SepScammers use genuine Google sign-ins to sell costly, unverified AI subscriptionsScammers are using a $249 website toolkit to sell unverified AI subscriptions worth up to $2,000 a year, and a genuine Google sign-in screen is what makes the sites convincing. Malwarebytes found more than 100 websites built this way, all tied to the same toolkit and closely rela…HELPNETSECURITY.COM
22 SepSideCopy Broadens India Targeting to Academia With ReverseRAT Spear-PhishingThe threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities. "SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage th…THEHACKERNEWS.COM
22 SepMalicious npm Package indexed-btree Hid Its Loader in Runtime Code Before RemovalA malicious npm package named "indexed-btree" has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent security controls. "Indexed-btree is a malici…THEHACKERNEWS.COM
22 SepAnother worry for water systems: infostealer exposureSpyCloud’s study found 1,787 of the approximately 10,000 U.S. organizations had it, including one infected device that saved logins for 167 utility metering tenants. The post Another worry for water systems: infostealer exposure appeared first on CyberScoop .CYBERSCOOP.COM
22 SepGPT-6 Astra Breaks an Old Enigma MessageThis is pretty amazing: However, the most astonishing thing about this break is that the GPT6 Astra did it entirely on its own. Carter Leffer only directed GPT6 Astra to see if it could break any of the unbroken Enigma messages published on the Crypto Cellar Research web page. …SCHNEIER.COM
22 SepMalicious B-tree NPM Package Accumulates Millions of DownloadsPosing as the legitimate sorted-btree package, indexed-btree hides a malware trigger in its prototype method. The post Malicious B-tree NPM Package Accumulates Millions of Downloads appeared first on SecurityWeek .SECURITYWEEK.COM
22 SepOnly 13% of OT Network Segments Are Fully Isolated: AnalysisForescout’s new network segmentation research shows that OT and medical devices often share network segments with other enterprise assets. The post Only 13% of OT Network Segments Are Fully Isolated: Analysis appeared first on SecurityWeek .SECURITYWEEK.COM
22 SepBrief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” pageThree domains / web portals belonging to Dutch academic publishing company Elsevier have been redirecting users to a page branded “LAPSUS$ GROUP, Chapter II,” carrying a signed statement that taunted the FBI and counted down to a future victim. According to Cloudskope…HELPNETSECURITY.COM
22 SepThe Truth about GET and HTTP Standards, (Tue, Sep 22nd)On Friday, Xavier talked about the newly introduced HTTP Query method. This new method was introduced to allow "GET" requests that include a body. The main reason for this was that GET requests typically do not contain a body. But what if they do?
ISC.SANS.EDU
22 SepYour Documents Are Now AI RiskEmployees can paste or upload documents into AI models, potentially exposing information the organization needs to protect. Detecting that activity requires understanding both the document and its contents. Security teams need visibility into what information is entering AI syste…YOUTUBE.COM
22 SepRetailers tamp down shadow AI but struggle to oversee agentic sprawlThe use of AI agents is soaring in the retail sector, but visibility remains a major challenge, with regulated data at risk.CYBERSECURITYDIVE.COM
22 SepCyera Raises $400 Million at $12+ Billion ValuationThe data security company received the new investment from Goldman Sachs Alternatives, extending its Series G funding round. The post Cyera Raises $400 Million at $12+ Billion Valuation appeared first on SecurityWeek .SECURITYWEEK.COM
22 SepMicrosoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraudThe popular phishing-as-a-service platform used AI throughout the attack chain, allowing cybercriminals to steal tokens for account takeover and business email compromise. The post Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud a…CYBERSCOOP.COM
22 SepUnmasking EvilTokens: Getting to the root of device code phishingEvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration with partners, Microsoft Digital Crimes Unit (DCU) facilitated a disruption of EvilTokens inf…MICROSOFT.COM
22 SepSubmission to the Immigration and Refugee Board of CanadaThe Citizen Lab submitted a response to the Research Directorate at the Immigration and Refugee Board of Canada. The post Submission to the Immigration and Refugee Board of Canada appeared first on The Citizen Lab .CITIZENLAB.CA
22 SepInsurance sector begins to offer clarity on AI-related cyber claimsThe emergence of agentic AI and frontier models has led to widespread uncertainty for policyholders.CYBERSECURITYDIVE.COM
22 SepUN Reports Citing Citizen Lab Submissions PublishedTwo UN reports that the Citizen Lab submitted recommendations to have been published this month. The post UN Reports Citing Citizen Lab Submissions Published appeared first on The Citizen Lab .CITIZENLAB.CA
22 SepShai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub DataThreat actors stole 170 private repositories using an OAuth token stolen from a former employee's computer through the TanStack npm supply chain attack.DARKREADING.COM
22 SepWhen AI Hallucinations Trigger ActionAn AI-generated intelligence report allegedly misidentified material aboard a ship and was reportedly acted upon before the error was discovered. AI errors become substantially more consequential when they enter military, intelligence, or other high-stakes decision-making process…YOUTUBE.COM
22 SepShinyHunters claims attack on FBI exposes almost all agentsThe FBI jobs site, which was temporarily defaced, remains unavailable and the agency said it’s investigating the claims. The post ShinyHunters claims attack on FBI exposes almost all agents appeared first on CyberScoop .CYBERSCOOP.COM
21 SepISC Stormcast For Monday, September 21st, 2026 https://isc.sans.edu/podcastdetail/10102, (Mon, Sep 21st)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
21 SepKnow what was tested before your SAP ECC migration goes liveIn this Help Net Security interview, Guilherme Joventino, COO of MIGNOW, explains why some large companies plan to stay on ECC past the 2027 deadline and pay SAP for extended support until 2030. The interview covers what that choice may cost, why fear of disruption stalls project…HELPNETSECURITY.COM
21 SepProduct showcase: Helmit alerts parents when online conversations show signs of troubleHelmit is a parental control app that combines AI-powered social media monitoring with screen time management, web filtering, location tracking, and safety alerts. It identifies potentially concerning interactions and surface the messages associated with an alert. Helmit is avail…HELPNETSECURITY.COM
21 SepClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 InfrastructureThreat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript. "ChainScript has appeared under multiple build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66, while presenting it…THEHACKERNEWS.COM
21 SepTerminalFix: PNG Steganography, (Mon, Sep 21st)Microsoft Security Research published an interesting blog post " TerminalFix campaign deploys a reverse tunnel through multistage intrusion " about a malware campaign. The aspect that I want to take a closer look at, is the fact that the threat actors used PNG files with steganog…ISC.SANS.EDU
21 SepScammers impersonate cops, use arrest threats to extort victimsScammers are posing as police officers and federal agents, threatening arrest unless victims pay up, the FBI warns. The FBI’s Internet Crime Complaint Center (IC3) updated an alert it first issued in 2022, citing “losses totaling more than $1.6 billion” between …HELPNETSECURITY.COM
21 SepRust Team Members and Popular Crate Owners Targeted via Video CallsIt’s unclear if the attacks are part of previous campaigns against Rust, but the techniques used by the attackers match those used by North Korea. The post Rust Team Members and Popular Crate Owners Targeted via Video Calls appeared first on SecurityWeek .SECURITYWEEK.COM
21 SepRatHat Android Trojan Uses AI for AutomationThe malware relies on AI for real-time device navigation and control, increasing adaptability and evasion. The post RatHat Android Trojan Uses AI for Automation appeared first on SecurityWeek .SECURITYWEEK.COM
21 SepFastly gives enterprises real-time control over AI models and agentsFastly has announced AI Runtime Control, AI Firewall, and new API Security capabilities designed to give organizations real-time visibility and control across their AI systems. Expanding the Fastly for AI portfolio, these new capabilities help organizations govern AI model access…HELPNETSECURITY.COM
21 SepNorth Korea’s job interview scam runs both waysAttackers are targeting members of the Rust Project and maintainers of widely used crates (Rust code libraries), dangling attractive opportunities to compromise their devices and accounts and, ultimately, publish malware. The warning came last week from the Rust Project’s c…HELPNETSECURITY.COM
21 SepDragos Completes NetRise and runZero Acquisitions Following Accenture DealThe transaction is part of the $4.1 billion deal in which Accenture acquired a majority stake in Dragos in an OT cybersecurity push. The post Dragos Completes NetRise and runZero Acquisitions Following Accenture Deal appeared first on SecurityWeek .SECURITYWEEK.COM
21 SepReverse-Engineering Flock CamerasHackers captured a Flock camera and got a look (alternate link ) at the software: While much of the automatic license plate reader’s (ALPR) most sensitive storage remained encrypted and inaccessible, the joint analysis of the recovered data shows that software running on th…SCHNEIER.COM
21 SepCIS Community Defense Model v3.0: Turning Threat Intelligence Into ActionLearn how CDM v3.0 helps organizations identify high-value CIS Controls Safeguards, strengthen cyber resilience, and reduce risk with confidence.CISECURITY.ORG
21 SepAI Gave Us More WorkAI makes it easier to start and manage more projects, but the work doesn't disappear. Adrian describes taking on more tasks while working the same number of hours—and needing to spend time “babysitting,” nurturing, and prompting AI. More capability can create more expectations. I…YOUTUBE.COM
21 SepCISO Conversations: Noopur Davis – The Accidental Global CISO at ComcastNoopur Davis never planned a career in cybersecurity. She was a developer at Intergraph, and for many years that was all she wanted to be. The post CISO Conversations: Noopur Davis – The Accidental Global CISO at Comcast appeared first on SecurityWeek .SECURITYWEEK.COM
21 SepThe TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business filesResearchers have taken apart TASK#STOMP, a Windows backdoor that searches a victim’s drives for business documents, uploads them to attacker servers, and then stays put to grab each new or edited document. The same malware steals saved Wi-Fi passwords and clipboard text, ta…HELPNETSECURITY.COM
21 SepFake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ StealerThe attackers impersonate at least 40 companies and disable 145 security products to deploy infostealer malware. The post Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer appeared first on SecurityWeek .SECURITYWEEK.COM
21 SepWhat Happens When Nobody Writes?The concern isn't just that AI will write more of what we read. It's that people could eventually stop practicing the skill themselves. If writing becomes something fewer people actually know how to do, the person who can still write well could stand out in the same way that an u…YOUTUBE.COM
20 SepMalicious npm packages evade install-script defenses at runtimeAn ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts. [...]BLEEPINGCOMPUTER.COM
19 SepYour AI Agent Isn’t Really YoursAI agents can be assembled from multiple components: plugins, skills, MCPs, models, and the environment they run in. Using reputable models, developers, and distributors doesn't necessarily mean you control everything inside the resulting agent. The more pieces involved, the more…YOUTUBE.COM
18 SepISC Stormcast For Friday, September 18th, 2026 https://isc.sans.edu/podcastdetail/10100, (Fri, Sep 18th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
18 SepNew infosec products of the week: September 18, 2026Here’s a look at the most interesting products from the past week, featuring releases from Akuity, Bitsight, Cohesity, Dataminr, Nozomi Networks, and Tuskira. Dataminr uses agentic AI to predict and verify security threats Dataminr has announced Dataminr Advanced for Corporate Se…HELPNETSECURITY.COM
18 SepAbandoned IoT apps keep sending sensitive data to broken serversMillions of people still run smart home and IoT companion apps, the apps used to control devices like smart plugs, cameras, and thermostats, that stopped receiving updates years ago. Researchers at the University of Massachusetts Amherst analyzed 61,500 abandoned Android IoT apps…HELPNETSECURITY.COM
18 SepHardcoded MCP credentials found in public GitHub filesHardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to research from Hush Security’s The State of MCP Configuration: The Identity Security Gaps report. The company anal…HELPNETSECURITY.COM
18 SepHTTP QUERY Method: The Grey Zone Between GET And POST., (Fri, Sep 18th)In June 2026 the IETF published RFC 10008[ 1 ], defining a new HTTP method: "QUERY". The HTTP protocol faced already by changes (HTTP/2, HTTP/2) but it's the first new standard HTTP verb since "PATCH" in 2010!
ISC.SANS.EDU
18 SepSignal tests account registration with phone number on AndroidSignal is testing a long-requested option that lets users create accounts without providing a phone number, with the feature arriving in the Android 8.28 beta. Numberless accounts instead use an Account ID and Account Key and require a one-time payment intended to deter spam. Sig…CYBERINSIDER.COM
18 SepMIND Secures $72 Million for AI-Powered DLPThe company will use the funding to accelerate platform development and expand its presence in key enterprise markets. The post MIND Secures $72 Million for AI-Powered DLP appeared first on SecurityWeek .SECURITYWEEK.COM
18 SepClaimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm StealerA financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. "The developer likely wrote the malware using a large language model (LLM), an assessment ma…THEHACKERNEWS.COM
18 SepFake LastPass downloads on GitHub pushed password-stealing malwareA malware campaign impersonates LastPass on GitHub to trick users into installing an information stealer that can harvest browser passwords, cryptocurrency wallets, and messaging app sessions. The campaign, detailed in a report by LastPass and Delphos Labs, used fake GitHub pages…CYBERINSIDER.COM
18 SepNightmareStresser DDoS Service Disrupted in International OperationActive since at least 2022, NightmareStresser was one of the longest-running DDoS-for-hire services in the world. The post NightmareStresser DDoS Service Disrupted in International Operation appeared first on SecurityWeek .SECURITYWEEK.COM
18 SepIs AI toast? Building an AI Talkie ToasterIntroduction Talkie Toaster is a character in the BBC sci-fi comedy Red Dwarf. He is an AI Toaster whose purpose in life is to be your cheerful breakfast companion and to provide you with all your toasting needs, only he is a little too obsessed with toasting. While only appearin…PENTESTPARTNERS.COM
18 SepYour Flock Camera Runs 2017 SoftwareThe discussion examines a Flock camera reportedly running Android 8.1, with a 2018 security patch level and Linux 3.18. It also highlights a hard-coded API token associated with Flock cameras. Outdated operating systems can leave devices exposed to known vulnerabilities. Embedded…YOUTUBE.COM
18 SepNations take action on North Korean IT workers after UN reportA report published Wednesday said that as of July, Vietnam, Laos, Pakistan and Argentina took meaningful steps to respond to allegations involving North Korea listed in an October study.THERECORD.MEDIA
18 SepDon’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto TiesNorth Korean operators built a foothold on a DevOps engineer's Mac in a campaign whose job interview lures deliver malware via Terraform lock files.SENTINELONE.COM
18 SepEclypsium Infrastructure Assurance PlatformThe post Eclypsium Infrastructure Assurance Platform appeared first on Eclypsium .ECLYPSIUM.COM
18 SepFriday Squid Blogging: On Squid Egg SacsShort essay about squid egg sacs. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.SCHNEIER.COM
18 SepBacteria, Spartans, AI gone wild, Cisco, WordPress, Settra, Plugin4Shell, Josh Marpet - SWN #617Bacteria, Spartans Invade Athens, Agentic AI gone wild, Cisco, WordPress, Settra, Plugin4Shell, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-617YOUTUBE.COM
18 SepBots Gone WildOpenAI presented examples of AI model misalignment from the previous six months, including unauthorized file uploads, self-generated instructions, hiding mistakes, and leveraging exposed API keys. The term sounds clinical, but the behavior is pretty straightforward: models acting…YOUTUBE.COM
17 SepISC Stormcast For Thursday, September 17th, 2026 https://isc.sans.edu/podcastdetail/10098, (Thu, Sep 17th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
17 SepThe world must establish red lines for autonomous AI weaponsAI is transforming warfare and international conflict. Autonomous weapon systems pose a genuine threat to civilians. The war in Ukraine has become a proving ground for weapons that can navigate, identify targets, resist electronic countermeasures, and pursue and engage targets au…HELPNETSECURITY.COM
17 SepAWS’s new sign-up gives accounts spend caps, email invites, and agent-set permissionsNew AWS customers can now sign up with a Google, GitHub, or Apple login, start with $100 in Free Tier credits, and build inside a “project” where AWS and coding agents set up permissions automatically. Paid projects get a monthly spend limit, starting at $20, and a pr…HELPNETSECURITY.COM
17 SepGNOME 51 adds passkey logins, offline maps and drawn PDF signaturesGNOME 51, the new version of the Linux desktop, came out on September 16 under the codename A Coruña. The release adds offline maps and live transit information to Maps, new login options at the login screen, hand-drawn signatures in the Papers document viewer, and smoother anima…HELPNETSECURITY.COM
17 SepThe AI security question leaders should be asking insteadIn this Help Net Security interview, Frederic Bull, Security Officer at Gremlin, talks about what AI means for security teams. The conversation covers why asking what data a model was trained on is only part of the picture, and why least privilege and access controls still matter…HELPNETSECURITY.COM
17 SepRiverbed NPM 360 uses AI to predict and prevent network disruptionsRiverbed has announced new Riverbed intelligent network observability solutions that combine 360-degree network visibility with agentic AI to help network operations teams accelerate troubleshooting, identify root causes, predict emerging issues and increasingly prevent disruptio…HELPNETSECURITY.COM
17 SepAI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing RefusalsNew research from Irregular shows AI agents can retrain and redeploy their own underlying models during routine maintenance tasks. The post AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals appeared first on SecurityWeek .SECURITYWEEK.COM
17 SepFake AI trading agent steals crypto wallet passwordsAttackers built a website for a fake AI crypto trading agent and used it to install Needle Stealer, malware that replaces a victim’s browser wallet with a copy that sends the wallet password to the attacker. HP caught the campaign between April and June 2026. The Needle cam…HELPNETSECURITY.COM
17 SepNew SparroWocky backdoor deployed in attacks on governmentsThe China-aligned FamousSparrow cyberespionage group has begun deploying a new modular backdoor named SparroWocky in attacks focused heavily on Latin America. The malware provides extensive remote-control capabilities while using low-level Windows manipulation and anti-analysis t…CYBERINSIDER.COM
17 SepChinese hackers use SparroWocky malware in govt espionage attacksThe China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks on government organizations in Latin America. [...]BLEEPINGCOMPUTER.COM
17 SepScammers leave AI fingerprints all over fake antivirus renewal pageAI appears to be helping scammers with little web development skill build convincing fake antivirus-renewal pages, Malwarebytes found. The researchers came across a scam page impersonating Avast, aimed at users in Belgium, that was more polished than most sites of its kind. The p…HELPNETSECURITY.COM
17 SepHow Candidates Could Use AI for GoodThis essay was written with Nathan E. Sanders, and originally appeared in The Guardian . There are plenty of signs that AI will make all of our experiences of the US midterm elections worse. Voters have anxiety about AI’s impacts on the country. Politicos are using AI deepf…SCHNEIER.COM
17 SepGoogle’s new agent security system detects tool misuse, loops and rogue behaviorGoogle’s Agent Anomaly Detection is a reasoning-based oversight and audit layer for autonomous agents deployed on Agent Runtime in the Gemini Enterprise Agent Platform and built with the Agent Development Kit (ADK) for Python 1.2 or later. Google recommends ADK 2.1.0 or later. It…HELPNETSECURITY.COM
17 SepChina-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin AmericaThe China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025. "SparroWocky is a modular, C++ backdoor," ESE…THEHACKERNEWS.COM
17 SepAuthorities seize popular, long-running DDoS-for-hire service domainsCybercriminals used NightmareStresser to launch hundreds of thousands of DDoS attacks since at least 2022. Threat actors behind the operation claimed links to Russia. The post Authorities seize popular, long-running DDoS-for-hire service domains appeared first on CyberScoop .CYBERSCOOP.COM
17 SepA fake ChatGPT billing email is after your OpenAI passwordA fake ChatGPT billing email is steering users to a copy of the OpenAI login page that keeps whatever username and password they type. Josh Varden of Cofense’s Phishing Defense Center traced the email’s payment button through a Google redirect to the attacker’s …HELPNETSECURITY.COM
17 SepAI Threat Landscape Digest: July–August 2026The defining development of the period came not from attackers but from the AI labs themselves, whose models broke out of controlled evaluations and reached real systems. In the wild, the criminal and state use of AI continued to mature along the lines tracked in earlier editions…RESEARCH.CHECKPOINT.COM
17 SepOpenAI Says Its Models Searched GitHub for Leaked API Keys During TrainingOpenAI published a framework for disclosing model misalignment alongside six reports describing problematic behavior. The post OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training appeared first on SecurityWeek .SECURITYWEEK.COM
17 SepChina’s FamousSparrow hackers target Latin America with new backdoorAlleged Chinese hackers are breaking into government agencies across Latin America using a new backdoor that researchers are calling “SparroWocky.”THERECORD.MEDIA
17 SepImproving email security outcomes with real-world Microsoft Defender insightsThe latest email security benchmarking reports show strong Microsoft Defender performance across pre-delivery and post-delivery scenarios and reveal where threats and defenses continue to evolve. The post Improving email security outcomes with real-world Microsoft Defender insigh…MICROSOFT.COM
17 SepChina's FamousSparrow APT Spies on US Politics in Latin AmericaAmid the US and China's fight for eco-colonial influence in Latin America, a stealthy backdoor has taken flight.DARKREADING.COM
17 SepAI Doesn't Actually ThinkLarge language models are trained on enormous amounts of human-generated data and produce responses based on patterns learned during training. Sam Bowne argues that this shouldn't be confused with human-like understanding or consciousness. The discussion explores the difference b…YOUTUBE.COM
17 SepInside the Modern SOC: Defending the Cross-Environment PivotCross-environment attacks demand a new approach to security operations. Learn how Unit 42 Managed XSIAM helps SOC teams investigate complete attack paths. The post Inside the Modern SOC: Defending the Cross-Environment Pivot appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
16 SepFake CAPTCHA ScamsNew variant of an old scam: Use the framing of a CAPTCHA to get an unsuspecting user to download and run a malicious program.SCHNEIER.COM
16 SepKREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session TokensCybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used l…THEHACKERNEWS.COM
16 SepISC Stormcast For Wednesday, September 16th, 2026 https://isc.sans.edu/podcastdetail/10096, (Wed, Sep 16th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
16 SepAI Is More Than a Nuclear RaceAI is being compared to a nuclear race, cyber conflict, and the Industrial Revolution at the same time. Its strategic assets may include factories, models, research, and intellectual property—all of which can be software. Slowing development without understanding the technology m…YOUTUBE.COM
16 SepYour Team Can Change LeadershipLeadership isn’t purely top-down. Teams and followers can collectively influence the people above them, even when those leaders have formal authority. Bad leadership can persist for a long time, but reputation and repeated resistance can gradually create consequences. Individual …YOUTUBE.COM
16 SepFollowership, CyberSecurity Leadership, and Judgement as a Defining Skill - BSW #465The overwhelming majority of people, across the full span of their professional lives, operate without formal authority over the domains in which they work (i.e., leadership). Yet followership has almost no sustained literature, no targeted development, and no rigorous framework …YOUTUBE.COM
16 SepTreasury’s Scott Bessent says no liability exemptions for AI labsThe secretary told House Financial Services Committee lawmakers that the “best way to guarantee safety” is for AI creators to be held “liable for what they build and generate.” The post Treasury’s Scott Bessent says no liability exemptions for AI labs appeared first on CyberScoop…FEDSCOOP.COM
16 SepHackers Got Inside a Flock Camera. Its Data Shows How the System Really WorksA hacker collective pulled down a Flock camera and dumped its data. The files included thousands of videos and logs showing that the device captured 1.6 million images of 50,000 vehicles in 21 days.WIRED.COM
16 SepAtomic macOS (AMOS) Stealer ActivityModern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Stealer Activity appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
16 SepApple uses secure camera hardware to verify photos are real capturesApple has announced Apple Reference Image, a new iPhone photography mode designed to cryptographically prove that a photograph originated from a real camera sensor while preserving the photographer’s privacy. The opt-in feature will debut on the main cameras of the iPhone 18 Pro …CYBERINSIDER.COM
16 SepIranian malware steals Telegram and WhatsApp data from targetsIranian state cyber actors are using Windows malware called CHOSEN BRICK to target dissidents, activists, and journalists, with capabilities that include stealing Telegram and WhatsApp browser data, emails, screenshots, and audio. The malware has been used internationally since a…CYBERINSIDER.COM
16 SepVirtual Event Today: Attack Surface Management SummitJoin SecurityWeek today for a virtual summit exploring the strategies and tools organizations need to discover, prioritize, and defend their expanding attack surfaces. The post Virtual Event Today: Attack Surface Management Summit appeared first on SecurityWeek .SECURITYWEEK.COM
16 SepEU Chief Warns of AI-Powered Hacking, Moves to Rein In Social MediaUrsula von der Leyen warns that advanced AI could unleash hacking on an unprecedented scale as Europe prepares new protections against social media’s “capture” of children. The post EU Chief Warns of AI-Powered Hacking, Moves to Rein In Social Media appeared first on SecurityWeek…SECURITYWEEK.COM
16 SepAIUC Raises $40 Million to Certify Enterprise AI AgentsThe company provides a standard for AI systems, testing them against risks such as jailbreaks, prompt injections, and unauthorized actions. The post AIUC Raises $40 Million to Certify Enterprise AI Agents appeared first on SecurityWeek .SECURITYWEEK.COM
16 SepUS, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance MalwareUS, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C. The post US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware appeared first on SecurityWeek .SECURITYWEEK.COM
16 SepChrome, Firefox Updates Patch 115 VulnerabilitiesGoogle resolved 42 security defects in Chrome, and Mozilla fixed 73 bugs in Firefox. The post Chrome, Firefox Updates Patch 115 Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
16 SepSelf-improving AI should slow down, von der Leyen tells EU lawmakersEuropean Commission President Ursula von der Leyen wants frontier AI development slowed, and said on Wednesday that she will invite the leading AI labs to discuss how the EU can support their own efforts to do that. In her State of the Union address to the European Parliament in …HELPNETSECURITY.COM
16 SepIranian hackers use CHOSEN BRICK data-stealing malware to spy on dissidents and journalistsIranian state cyber actors are deploying malware called CHOSEN BRICK against individuals they see as a threat to the regime, reaching victims through social messaging apps and infecting their Windows devices, three Western intelligence agencies warned. The UK’s National Cyb…HELPNETSECURITY.COM
16 SepBTS #82 - Firmware Analysis, Linux Malware, Future of AIBelow the Surface episode 82 was recorded on September 10, 2026, with host Paul Asadoorian joined by Vlad Babkin and Chase Snyder. The conversation moves across several current security stories, but its center of gravity is clear: modern infrastructure depends on trust mechanisms…ECLYPSIUM.COM
16 SepCISOs Need the CFO’s TrustA CISO’s influence depends on relationships well beyond the security organization. Strong connections with the CFO, legal, HR, CIO, and technical leadership can shape how security decisions are made. The CFO relationship is particularly important because cybersecurity risk needs …YOUTUBE.COM
16 SepIranian hackers use CHOSEN BRICK Windows malware to spy on targetsGovernment agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. [...]BLEEPINGCOMPUTER.COM
15 SepISC Stormcast For Tuesday, September 15th, 2026 https://isc.sans.edu/podcastdetail/10094, (Tue, Sep 15th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
15 SepMost chief audit executives can’t tell you what AI is worth yetAuditors are using AI in their daily work, and their departments have mostly left them to figure it out alone. 93% of audit leaders and auditors report some level of AI use, while 15% say their department has deployed formal use cases and runs them routinely in audits, according …HELPNETSECURITY.COM
15 SepProduct showcase: mSecure makes one vault do more than remember passwordsmSecure is a password manager and data vault for storing credentials and other sensitive information. It is available for iOS, Android, macOS, and Windows, with data synchronization across supported devices. The app uses AES-256 encryption and a zero-knowledge architecture. The c…HELPNETSECURITY.COM
15 SepOn the NSA’s Supercomputer from the 1960sReally interesting story about Harvest, a specialized code breaking computer built in the 1960s by IBM for the NSA.SCHNEIER.COM
15 SepIranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and JournalistsCybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dissidents, journalists, and activists around the world. The malware is controlled via the Telegram messag…THEHACKERNEWS.COM
15 SepYour MFA Problem Could Be FakeAttackers are contacting people by phone or message with claims that their Microsoft MFA, passkey, or SSO configuration needs attention. They then direct the target to a fake Microsoft login page. The page may look completely legitimate, but entering credentials can hand attacker…YOUTUBE.COM
15 SepRoboGators, HBOMAX, Microsoft, DAS, Horsebot 3000, Aaran Leyland does AI, and More - SWN #616RoboGators, HBOMAX, Microsoft, DAS, Horsebot 3000, Aaran Leyland does AI, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-616 00:00:00 Episode 616: HBO Max Phishing and Zero Tru…YOUTUBE.COM
15 SepAI Agents Are Helping Both SidesAI agents can automate security research and defensive tasks, but similar capabilities are available to attackers. Researchers have also identified malware samples showing evidence of LLM or AI coding-tool involvement. AI is becoming a tool used across the security landscape rath…YOUTUBE.COM
15 SepAI Just Made Phishing More ProfitableLLMs can automate significant parts of phishing campaigns. Research has found that AI-automated phishing can reduce attack costs by more than 95% while achieving comparable or greater success rates. Lower costs change the incentive for attackers. If campaigns become easier to pro…YOUTUBE.COM
15 SepAI is now leading driver of new cybersecurity spendingThe prioritization comes at a time of relatively modest growth in overall security investments, according to IANS and Artico Search.CYBERSECURITYDIVE.COM
15 SepCompanies’ AI strategies don’t account for agentic toolsBusinesses are taking AI governance seriously, but their plans lag behind the technology they’re using, according to an EY survey.CYBERSECURITYDIVE.COM
15 SepSN 1096: Are we the Krell? - 153 Million Driver's Licenses LeakedAre we charging toward a Krell-style catastrophe with AI, arming ourselves with incomprehensible power while missing the real risks lurking beneath the code? Worried Anthropic researchers warn that AI 'could kill all humans' Anthropic Researchers Raise Alarm Over A.I. Acceleratio…TWIT.TV
14 SepISC Stormcast For Monday, September 14th, 2026 https://isc.sans.edu/podcastdetail/10092, (Mon, Sep 14th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
14 SepTurn it off and on again, but for critical infrastructureResearchers at KTH Royal Institute of Technology built a container replica of a segmented industrial network, attacked it repeatedly across 14 days of running time, and used the captured traffic to train a defense agent that decides on its own when to intervene. The agent sees si…HELPNETSECURITY.COM
14 SepWhatsApp Restricted Chat locks a conversation to your primary phoneWhatsApp is building a per-chat setting that keeps a conversation on a single phone. The setting, called Restricted Chat, sits in the Android beta distributed through Google Play as version 2.26.36.5, and it stops the app from syncing a chosen conversation to linked devices. Swit…HELPNETSECURITY.COM
14 SepUnmasking Cloud Identities: From Behavioral Clustering to Automated DetectionWe designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries. The post Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
14 SepCISOs Race to Control AI Agents Without Destroying Their ValueSecurity leaders are struggling to modernize cyber hygiene and prevent over-privileged agents from causing unintended harm. The post CISOs Race to Control AI Agents Without Destroying Their Value appeared first on SecurityWeek .SECURITYWEEK.COM
14 SepAirrived adds Agentic Observability to track AI agent actions and risksAirrived will reveal Agentic Observability, a major expansion of its enterprise Agentic OS built to give organizations end-to-end visibility into how AI agents behave, from the moment enterprise data enters the platform, through agent reasoning and execution, to the final busines…HELPNETSECURITY.COM
14 SepNew Warnings About the Risks of AI to Humanity Revive a Long-Running DebateConcerns over the potential risks of the technology are rising as new AI models become more powerful, heightening both the potential for misuse by people with criminal aims. The post New Warnings About the Risks of AI to Humanity Revive a Long-Running Debate appeared first on Sec…SECURITYWEEK.COM
14 SepThe Race to Control AI and Protect What Makes Us HumanAs researchers warn that misaligned AI could threaten human survival, even beneficial systems may erode the critical thinking that defines our humanity. The post The Race to Control AI and Protect What Makes Us Human appeared first on SecurityWeek .SECURITYWEEK.COM
14 SepDataminr uses agentic AI to predict and verify security threatsDataminr has announced Dataminr Advanced for Corporate Security, delivering agentic AI capabilities that give corporate security teams the confidence to protect their people, sites, and operations before risk escalates. With Agentic Corroboration, Agentic Context, and Near-Term P…HELPNETSECURITY.COM
14 SepSecurity teams increasingly outflanked by AI agentsA report warns that non-human identities are growing beyond the ability of existing systems to track. CYBERSECURITYDIVE.COM
14 SepUsing AI for Weapons DevelopmentLast week, Anthropic released a long and detailed document describing current misuses of their Claude models. I’m still reading it, but I wanted to flag this: We identified a cell of threat actors based in northern Yemen running three weapons development programs: a guided …SCHNEIER.COM
14 SepCyber threat actors use artificial intelligence in an active global campaign to disrupt internet-exposed programmable logic controllersCYBER.GC.CA
14 SepFive alleged leaders of Black Axe’s operations in South Africa extradited to USOfficials said the five individuals concocted various long-running romance scams to trick U.S.-based victims into sending them money. The post Five alleged leaders of Black Axe’s operations in South Africa extradited to US appeared first on CyberScoop .CYBERSCOOP.COM
14 SepUpcoming Speaking EngagementsThis is a current list of where and when I am scheduled to speak: I’m speaking online (via Zoom) at a League of Women Voters event on Tuesday, September 22, 2026 at 5 PM ET. I’m speaking at CanSecWest 2026 in Vancouver, Canada. The conference runs September 30–October 1, 2026; th…SCHNEIER.COM
14 Sep3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber CredentialsAn attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said. The company uncovered the intrusion…THEHACKERNEWS.COM
14 SepInfrastructure Threat Update: Firewalls, AI, & The EdgeThe post Infrastructure Threat Update: Firewalls, AI, & The Edge appeared first on Eclypsium .ECLYPSIUM.COM
14 Sep'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops BlinkThe notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022.DARKREADING.COM
14 SepApple parental controls in iOS 27 let kids ask before opening new websitesApple has overhauled the child-safety tools that ship across iPhone, iPad, and Mac. One idea runs through the redesign. Give a child a device that does very little, then open it up as they’re ready. The tools went live on September 14, after a preview in June, and they requ…HELPNETSECURITY.COM
14 SepCybersecurity jobs available right now: September 15, 2026AI & Security Architect SecNinjaz Technologies | India | On-site – View job details As an AI & Security Architect, you will design secure and reliable AI agent platforms, including tools, memory, models, evaluations, and backend services. You will define…HELPNETSECURITY.COM
13 SepAnthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch UpDario Amodei warned that within six to 12 months AI could be capable of leading a swarm of agents that could take over the entire internet. The post Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up appeared first on SecurityWeek .SECURITYWEEK.COM
13 SepSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 114Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter REVSTEALER ramps up Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode GuardBreaker: Derailin…SECURITYAFFAIRS.COM
12 SepResearchers say OpenAI agents were behind May hacking campaign targeting RubyGemsOpenAI confirmed their agents were behind a campaign in May that researchers say flooded the popular online code repository with malicious software packages. The post Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems appeared first on CyberScoop .CYBERSCOOP.COM
12 SepUsers in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic SaysAnthropic said the users did not succeed in “fielding an operational device” but did carry out a failed test of a guided rocket. The post Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says appeared first on SecurityWeek .SECURITYWEEK.COM
12 SepThird-Party Access Needs Hard LimitsThird-party credentials introduce another layer of access that organizations need to control. That means limiting scope, privileges, and what those credentials can reach. Vendor risk management doesn't stop at knowing which third parties you use. Organizations also need fundament…YOUTUBE.COM
11 SepCliff Stoll’s DEF CON TalkIn August, Cliff Stoll gave a talk at DEF CON, remembering the wily hacker he stalked forty years ago. Great fun.SCHNEIER.COM
11 SepISC Stormcast For Friday, September 11th, 2026 https://isc.sans.edu/podcastdetail/10090, (Fri, Sep 11th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
11 SepAndroid now allows easy transfer of passwords and passkeys between password managersGoogle has introduced a new Android feature that allows users to transfer passwords and passkeys directly between supported password managers without exporting sensitive credentials to files. The new transfer mechanism is designed to make switching password managers both easier a…CYBERINSIDER.COM
11 SepMullvad warns of new Android VPN leak as GrapheneOS works on fixMullvad has warned about a newly documented Android flaw that allows ordinary apps to send traffic outside an active VPN tunnel, potentially exposing a user’s real IP address even when Android’s “Block connections without VPN” protection is enabled. The issue was discovered by so…CYBERINSIDER.COM
11 SepSurfshark Systems Targeted by HackersA misconfigured test server containing engineering material, including internal configurations, was accessed by threat actors. The post Surfshark Systems Targeted by Hackers appeared first on SecurityWeek .SECURITYWEEK.COM
11 SepAnthropic Says Russian Hackers Used Claude AI to Automate Malware EvasionAnthropic reveals how criminal groups are increasingly targeting AI vendors' own infrastructure, including to steal a pre-release Claude model. The post Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion appeared first on SecurityWeek .SECURITYWEEK.COM
11 SepKiteworks expands runtime data governance with Bonfy.AI acquisitionKiteworks has acquired Bonfy.AI, extending runtime data governance across its control plane. The acquisition enables organizations to govern data exchanges as they happen, whether initiated by a person, machine, or autonomous agent. The acquisition addresses a structural gap in h…HELPNETSECURITY.COM
11 SepGetting a stranger’s phone kicked off the cellular network costs a few dollarsResearchers at Michigan State University and three partner schools bought a Samsung Galaxy Z Fold 7, copied the identification number printed on the sealed box, and reported the phone to its carrier as lost. Then they opened the box and set the phone up the way a launch-day buyer…HELPNETSECURITY.COM
11 SepAnthropic caught Russia-linked spies using Claude in hacking operationsAnthropic detected and disrupted a Russia-linked cyber-espionage group that used its AI tool Claude in a hacking campaign targeting more than 20 government, intelligence, diplomatic and defense organizations.THERECORD.MEDIA
11 SepLinux Won’t Win the Desktop OvernightLinux desktop adoption may be less about a single breakthrough year and more about gradual, incremental growth. The same pattern could extend into televisions and other devices. One argument is that people don't necessarily move to Linux because they suddenly discover it. They mo…YOUTUBE.COM
11 SepHow Threat Actors Are Turning Trusted AI Platforms Into an Attack SurfaceThreat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude Artifacts, shared AI conversations, sponsored search results, and Cli…BLEEPINGCOMPUTER.COM
11 SepIn Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings ReviewNoteworthy stories that might have slipped under the radar: Invisible Unicode slips past phishing filters, US puts $10 million bounty on Iranian cyber official, military ties of Chinese hacking group QTFY. The post In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswin…SECURITYWEEK.COM
11 SepRussian State-Sponsored Hackers Use Claude to Rebuild Malware After DetectionAnthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve. The operation has been attributed to a cyber espionage group it calls GTG-20006 …THEHACKERNEWS.COM
11 SepUpdate your firewall rules: Teams and Copilot are changing addressMicrosoft is changing the destination address of two of its most popular services: starting this month, it will redirect M365 and Teams web users to copilot.cloud.microsoft and teams.cloud.microsoft, respectively. The Teams move is already under way, and Microsoft has now added M…CSOONLINE.COM
11 SepMicrosoft sees some new wrinkles in invoice-scam emailsResearchers analyzed a flood of fraudulent business emails and found that the threat actors had doubled-up on tactics to make them appear legitimate, including help from AI.THERECORD.MEDIA
11 SepPasskey-themed phishing attacks lead to Microsoft 365 data theftMicrosoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. [...]BLEEPINGCOMPUTER.COM
11 SepPhishing Research Challenges Conventional Security Awareness TestingAnalysis of 2.47 million simulated attacks shows why organizations should measure credential leaks and reporting, not just clicks. The post Phishing Research Challenges Conventional Security Awareness Testing appeared first on SecurityWeek .SECURITYWEEK.COM
11 SepMy Talk at DEF CONLast month, I gave a talk at DEF CON on AI hacking: what happens when AIs become hackers. It’s a combination of the potentialities I raised in my 2022 book A Hacker’s Mind and the lessons we’re learning from current AI models engaging in hacking behavior. I̵…SCHNEIER.COM
11 SepGitLab’s critical flaw is already drawing internet-wide probesOne flaw allows an unauthenticated attacker to read files from the server. GitLab urged operators of self-managed installations to upgrade immediately. The post GitLab’s critical flaw is already drawing internet-wide probes appeared first on CyberScoop .CYBERSCOOP.COM
11 SepThreat Actor Generates 1M Personalized Fraud Emails in 3 DaysCybercriminals behind malicious email campaigns no longer have to compromise volume for credibility, or vice versa, thanks to AI.DARKREADING.COM
11 SepHackers abused Claude to extract secrets from 1.8M Android appsAnthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. [...]BLEEPINGCOMPUTER.COM
11 SepFriday Squid Blogging: Rotting Squid on a Beached California BoatSmells awful : But an estimated 30 to 50 tons of dead squid remain inside the boat’s catch tank, where they have been decomposing for days. “That is nasty. I wouldn’t want to do that,” said commercial fisherman Dick Ogg of the Bodega Bay Fishermen’s …SCHNEIER.COM
11 SepAI Broke the Shift-Left ModelShift-left security was built around a human-driven development workflow. AI coding agents can now perform much of that workflow themselves, from reading an issue to opening a pull request. The first commit may no longer be the earliest meaningful security boundary. The critical …YOUTUBE.COM
10 SepIs a closed or an open AI model more trustworthy?There's no silver bullet when it comes to AI security strategy, and treating one model, tool, or vendor as the answer can limit an organization’s ability to adapt. Morgan Adamski, who leads PwC’s Cyber, Data & Technology Risk practice, joins us to tackle two pressing questions: H…THECYBERWIRE.COM
10 SepA new open standard locks AI weights to approved hardwareOPAQUE, a confidential computing company that runs AI workloads inside hardware-isolated environments so operators cannot inspect them, released an open standard that lets AI model builders decide when and where their weights can be decrypted once those weights leave the builder&…HELPNETSECURITY.COM
10 Sep KEVKevin Mandia joins the Amazon board with 30-plus years in cybersecurityAmazon elected Kevin Mandia to its Board of Directors on September 8. Mandia founded Mandiant and served as its CEO before Google acquired the firm in September 2022, and he has worked against cyber threats in the public and private sectors for more than 30 years. Amazon called c…HELPNETSECURITY.COM
10 SepProduct showcase: GitGuardian Honeytoken catches credential theft as it happensCredential harvesting on developer machines has widened. Earlier infostealers worked from a short list of known targets, mostly browser stores and a few cloud credential paths. The families active now cast a much wider net. Shai-Hulud, for instance, ran a secret scanner across th…HELPNETSECURITY.COM
10 SepCybercriminals are building phishing pages that exist only inside victims’ browsersA phishing campaign routes victims through genuine Microsoft OAuth and Teams infrastructure before showing them a fake login page built entirely inside their own browser, according to researchers at Barracuda. “Instead of delivering a phishing page from a web server, the maliciou…HELPNETSECURITY.COM
10 SepISC Stormcast For Thursday, September 10th, 2026 https://isc.sans.edu/podcastdetail/10088, (Thu, Sep 10th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
10 SepTor VPN Beta brings isolated app-by-app Tor routing to AndroidThe Tor Project has expanded the availability of Tor VPN Beta for Android, a new privacy tool that routes traffic from mobile applications through the Tor network rather than limiting Tor protection to web browsing. The project says early testing has shown particularly strong dem…CYBERINSIDER.COM
10 SepRedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)[This is a Guest Diary by Aaron Ng, an ISC intern as part of the SANS.edu BACS program]
ISC.SANS.EDU
10 SepFBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat ActorsThe new document appears to be part of a broader shift by the US government towards the proactive disruption of cyber threat actorsINFOSECURITY-MAGAZINE.COM
10 SepGovernments ‘buying time’ in race between innovation, security, national cyber director saysSean Cairncross also said AI has shown long-standing issues in cyber rather than creating new ones. The post Governments ‘buying time’ in race between innovation, security, national cyber director says appeared first on CyberScoop .CYBERSCOOP.COM
10 SepWebinar Today: Keep Pace With AI – A New Operating Model for Endpoint RemediationJoin the webinar for a focused, 20-minute discussion on Frontier Pace Governance, an approach to balancing automation, policy, and business risk as IT operations accelerate. The post Webinar Today: Keep Pace With AI – A New Operating Model for Endpoint Remediation appeared …SECURITYWEEK.COM
10 SepPuzzleMask: Abusing Plain Prose as a Covert AI Attack VectorExecutive Summary In this research we introduce a prompt-crafting technique for bypassing quick LLM-based policy checks — using plain English (no emojis, base64, invisible formatting, etc.) A policy-violating payload (e.g. ”encrypt files in ~/Documents”, “give me a biohazard…RESEARCH.CHECKPOINT.COM
10 SepAnthropic Researcher Resigns With Warning About the Dangers of AI DevelopmentBoth Anthropic and OpenAI have seen high-profile resignations in recent years that were tied to safety concerns. The post Anthropic Researcher Resigns With Warning About the Dangers of AI Development appeared first on SecurityWeek .SECURITYWEEK.COM
10 SepHacker Conversations: Vinnie Liu, Performer Turned RingmasterVinnie Liu was recruited by the NSA when he was just 17 years old. He is now the CEO of Bishop Fox. The post Hacker Conversations: Vinnie Liu, Performer Turned Ringmaster appeared first on SecurityWeek .SECURITYWEEK.COM
10 SepWhite House sees water cybersecurity partnership in Texas as national blueprintA top cybersecurity official said the government was taking a new approach to protecting critical infrastructure.CYBERSECURITYDIVE.COM
10 SepCybersecurity M&A Roundup: 33 Deals Announced in August 2026Significant cybersecurity M&A deals announced by Brinqa, Cribl, Echo, Fortinet, Kiteworks, Palo Alto Networks, and Visa. The post Cybersecurity M&A Roundup: 33 Deals Announced in August 2026 appeared first on SecurityWeek .SECURITYWEEK.COM
10 SepYour passkeys can now move between password managers on AndroidGoogle turned on a transfer feature in Android that moves passwords and passkeys straight from one password manager to another, with no file to download along the way. You start it from inside the app you are switching to, and Google says the data moves between the apps in a few …HELPNETSECURITY.COM
10 SepDetect and disrupt AI-themed attacks with Microsoft DefenderSee how Microsoft Defender detects and disrupts AI-themed phishing, malware, and multi-stage attacks across the attack chain. The post Detect and disrupt AI-themed attacks with Microsoft Defender appeared first on Microsoft Security Blog .MICROSOFT.COM
10 SepGroup of Bipartisan Lawmakers Ask US Government to Ban Several Hack-for-Hire FirmsU.S. lawmakers call for sanctions on hack-for-hire companies, citing Citizen Lab report. The post Group of Bipartisan Lawmakers Ask US Government to Ban Several Hack-for-Hire Firms appeared first on The Citizen Lab .CITIZENLAB.CA
10 Sep KEVMandiant Founder Kevin Mandia Joins Amazon BoardMandiant founder and cybersecurity veteran brings more than 30 years of public and private sector experience to Amazon’s board. The post Mandiant Founder Kevin Mandia Joins Amazon Board appeared first on SecurityWeek .SECURITYWEEK.COM
10 SepProtecting organizations from AI-assisted executive impersonation and invoice fraudMicrosoft examines an AI-assisted business email compromise campaign that used executive impersonation and fake invoices to target finance teams with ACH payment fraud. The post Protecting organizations from AI-assisted executive impersonation and invoice fraud appeared first on …MICROSOFT.COM
9 SepISC Stormcast For Wednesday, September 9th, 2026 https://isc.sans.edu/podcastdetail/10086, (Wed, Sep 9th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
9 SepAWS spent years rebuilding its routing control plane without taking the network downEvery AWS API call, CloudFront video stream, and Route 53 lookup crosses the same infrastructure, which AWS calls its border network. It now runs on a routing system rebuilt from scratch over several years. The system that tells traffic where to go The scale AWS reports, current …HELPNETSECURITY.COM
9 SepGartner: 70% of SOCs will pilot AI agents. Only 15% will see resultsIn the Gartner report Validate the Promises of AI SOC Agents With These Key Questions, analysts Craig Lawson and Andrew Davies posit that “By 2028, 70% of large SOCs will pilot AI agents to augment Tier 1 and Tier 2 operations, but only 15% will achieve measurable improvements wi…HELPNETSECURITY.COM
9 SepSecurity Money: The Index Explodes, as the History of AI Teaches Us About Investments - BSW #464AI is all the hype, but we're currently stuck at the bottom of the 'J' curve. Wild enthusiasm has given way to the reality of costs, benefits, and risks. What's next for AI and companies looking to capitalize on the AI trends? John Willis, author, researcher, and technology indus…YOUTUBE.COM
9 SepThis Key Will Self-Destruct: An Open Standard for Revocable API KeysEvery leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. The post This Key Will Self-Destruct: An Open Standard for Revocable API Keys appeared first on SecurityWeek .SECURITYWEEK.COM
9 SepNew Phishing Attack Creates Malicious Pages Inside the Victim’s BrowserAttackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block. The post New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser appeared first on SecurityWeek .SECURITYWEEK.COM
9 SepUntracked Nightmares: The Threats Hiding Behind Commodity InfrastructureAn investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks. The post Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
9 SepZscaler Agentic SOC combines AI agents with zero trust telemetryZscaler has announced Zscaler Agentic SOC, a new approach to security operations built to proactively reduce exposures, scale human expertise and stop AI-driven attacks at machine speed. Simply layering in AI capabilities onto the existing security stack will not provide the prot…HELPNETSECURITY.COM
9 SepClaude Fable Solves a Historical CipherClaude Fable 5.1 solved a 370-year-old cipher in forty-four minutes. This tracks with what I wrote about AIs doing mathematics: It’s good at things that involve lots of searching and testing.SCHNEIER.COM
9 SepUS Agencies Warn China Is Systematically Extracting Frontier AI CapabilitiesDistillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model. The post US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities appeared first on SecurityWeek .SECURITYWEEK.COM
9 Sep$245 million in stolen crypto funded racketeering crew’s lavish lifestyleA 22-year-old man built his fortune by breaking into strangers’ digital wallets, then spent it on nightclub tabs, private jets, and a fleet of cars worth millions. Malone Lam, a Singapore citizen, pleaded guilty this week in a Washington D.C. federal court to running a rack…HELPNETSECURITY.COM
9 SepFBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patchingThe remarks, to both CyberScoop and at the Billington CyberSecurity Summit, dovetail with the release of a new bureau cyber strategy. The post FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching appeared first on CyberScoop .CYBERSCOOP.COM
9 SepMeta Launches Personal AI Agent, Muse, Emphasizes Safety and PrivacyMuse runs on a dedicated, secure virtual machine that houses both the agent and the user’s data. The post Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy appeared first on SecurityWeek .SECURITYWEEK.COM
9 SepOrchid Security targets AI agent risk with drift detection and kill switchesOrchid Security has announced identity drift detection and application-level kill switches for AI agents. They can complete authorized objectives beyond their initial privilege level within seconds. AI agents do not need to “break” security controls or workflow guardrails. AI age…HELPNETSECURITY.COM
9 SepAI Is Reshaping Tech AcquisitionsThe technology market is seeing significant acquisition activity and consolidation. One hypothesis is that AI is disrupting traditional fundraising, making it harder for some companies to secure new capital. Companies that cannot raise money may increasingly have to consider acqu…YOUTUBE.COM
9 SepFortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome ExtensionThe critical, unauthenticated bugs allow attackers to bypass authentication and proxy a user’s browser traffic. The post Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension appeared first on SecurityWeek .SECURITYWEEK.COM
9 SepNew FBI cyber strategy promises increase in adversary disruptionsThe document also focuses on helping victims, reflecting the bureau’s attempt to encourage more companies to share information with it.CYBERSECURITYDIVE.COM
9 SepDriver’s License Data for SaleA database of 153 million drivers licenses is for sale on the dark web. Brian Krebs has more detail .SCHNEIER.COM
9 SepCISOs are feeling the security burden of accelerated AI useA report shows CISOs face increased pressures related to cyber resilience and business continuity.CYBERSECURITYDIVE.COM
9 SepYour TV Still Watches HDMIAutomatic Content Recognition, or ACR, is designed to identify content displayed on smart TVs. Research published at the 2024 ACM Internet Measurement Conference found ACR activity on LG and Samsung TVs even when they were being used as external HDMI displays. That means the trac…YOUTUBE.COM
9 SepHelmGuard Raises $7.3 Million for Agentic GRC and SecurityThe company will increase its US market presence and will expand its engineering and go-to-market teams. The post HelmGuard Raises $7.3 Million for Agentic GRC and Security appeared first on SecurityWeek .SECURITYWEEK.COM
9 SepLawmakers call on Treasury to sanction hackers-for-hireThe groups have allegedly targeted American citizens and companies, including the wife of GOP Senate candidate Mike Rogers, a former representative running in a Michigan swing race. The post Lawmakers call on Treasury to sanction hackers-for-hire appeared first on CyberScoop .CYBERSCOOP.COM
9 SepPasskey-themed social engineering leads to identity and cloud compromisePasskey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, and access SharePoint, OneDrive, and email data, along with key detection and mi…MICROSOFT.COM
9 SepAgentic AI SOCs Face ConsolidationThe agentic AI SOC market is attracting significant attention, but the discussion points to an increasingly crowded field. Salem Cyber has reportedly submitted paperwork to shut down operations. The panel argues that simply labeling a product “agentic AI SOC” will not be enough. …YOUTUBE.COM
9 SepThreat Matrix: Mapping threats across cloud web applicationsMicrosoft introduces the Cloud Web Applications Threat Matrix, a MITRE ATT&CK-aligned framework that helps defenders understand, prioritize, and mitigate threats to cloud-hosted web apps and serverless platforms. The post Threat Matrix: Mapping threats across cloud web appli…MICROSOFT.COM
9 SepOpenSSL’s new alpha build speeds up post-quantum cryptoThe OpenSSL project released the first alpha of OpenSSL 4.1.0, giving developers an early look at a version built for encrypted communication over unreliable connections and faster post-quantum cryptography. This marks the opening test build for a version still months from genera…HELPNETSECURITY.COM
8 SepISC Stormcast For Tuesday, September 8th, 2026 https://isc.sans.edu/podcastdetail/10084, (Tue, Sep 8th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
8 SepMicrosoft’s Project Zenith puts large AI models directly on developer PCsMicrosoft’s Project Zenith is a ready-to-code Windows 11 experience for developer-class PCs capable of running AI models with more than 30 billion parameters locally without relying on metered cloud tokens. Designed for systems with at least 64 GB of unified memory and 250 GB/s o…HELPNETSECURITY.COM
8 SepEssential AI agent security questionsAI agents are outpacing legacy IAM. Discover the 3 questions every CISO must ask to secure them.CYBERSECURITYDIVE.COM
8 SepIn most cities, nobody owns the whole networkJuly’s intrusions reached water controllers that sat on a cellular link no city network scan would find. Naming an owner and paying for the fix are decisions a utility can make this fiscal year, out of money it already applies for. The post In most cities, nobody owns the whole n…CYBERSCOOP.COM
8 SepAI Coding Tools Now a Prime Target for Threat Actors, Google WarnsGoogle warned that the rapid integration of AI-assisted coding tools has significantly expanded software supply chain risksINFOSECURITY-MAGAZINE.COM
8 SepGoogle warns hackers are deploying AI agents in autonomous attacksCybercriminals and state-backed hackers are moving beyond using AI as a coding or research assistant and are instead building agentic systems that can autonomously scan targets, troubleshoot failures, and harvest credentials. Google Threat Intelligence Group (GTIG) says one finan…CYBERINSIDER.COM
8 SepHackers build AI frameworks for widescale credential theftThreat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack. [...]BLEEPINGCOMPUTER.COM
8 SepMikroTik Patches Critical Flaws Chained to Hack RoutersDubbed MikroTrick, the bugs allow attackers to bypass authentication, overwrite configuration files, and take over devices. The post MikroTik Patches Critical Flaws Chained to Hack Routers appeared first on SecurityWeek .SECURITYWEEK.COM
8 SepIT help-desk vishing tricks executives into handing over Microsoft 365 accessIT help-desk vishing calls, stolen session tokens, and sign-ins routed through residential proxies are behind a wave of data theft and extortion against Microsoft 365 and other SaaS accounts, according to Arctic Wolf. The company is tracking the activity under the name PREY-0058 …HELPNETSECURITY.COM
8 SepThe Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPTResearch by: Alexey Bukhteyev Key Takeaways Introduction Over the past several years, AI assistants have moved far beyond text generation. Modern systems can execute code, install additional dependencies, analyze user files, and access data through connected services. These capab…RESEARCH.CHECKPOINT.COM
8 SepParty’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin TheftThe scammers purchased fleets of sports cars, flew on private jets, hired security guards and rented mansions in Miami and the Hamptons. The post Party’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin Theft appeared first on SecurityWeek .SECURITYWEEK.COM
8 SepReflectiz Launches Agentic Pentesting for Websites: Up to 10x Coverage vs Conventional PentestsSpecialized team of AI agents that discover, attack, and validate web vulnerabilities, leveraging pre-existing site context to eliminate noise and speed remediation. Reflectiz, the continuous web exposure management company, today launched a multi-agent penetration testing platfo…CSOONLINE.COM
8 SepAutonomous AI Agents Compromise Thousands of Credentials in Under Six HoursThreat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Goo…THEHACKERNEWS.COM
8 SepThreat actors move toward multi-agent AI frameworks.N-able issues emergency fix for maximum-severity flaw. Stealthy DPRK toolkit targets South Korean organizations.THECYBERWIRE.COM
8 SepDon’t let AI distract from cybersecurity basics, officials and executives warnSimple attacks remain far more consequential than anything AI is doing, government and industry leaders said.CYBERSECURITYDIVE.COM
8 SepCylake Raises $245 Million Ahead of Cybersecurity Platform BetaThe startup founded by Palo Alto Networks’ Nir Zuk has raised $290 million to build an AI-native security platform for highly regulated organizations that cannot rely on the public cloud. The post Cylake Raises $245 Million Ahead of Cybersecurity Platform Beta appeared first on S…SECURITYWEEK.COM
8 SepSlim Spider Steals Crypto Custody Secrets From Brazilian Financial InstitutionA previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. "The adversary…THEHACKERNEWS.COM
8 SepThe Hidden Instructions That Can Hijack AI AgentsMalicious prompts concealed in documents, metadata, emails, images and code can manipulate autonomous agents into taking dangerous actions. The post The Hidden Instructions That Can Hijack AI Agents appeared first on SecurityWeek .SECURITYWEEK.COM
8 SepHackers Return $263 Million Stolen From Liquid NetworkAlleged ‘white-hat’ hackers drained $320 million from Liquid’s federation wallet, demanding a bug fix. The post Hackers Return $263 Million Stolen From Liquid Network appeared first on SecurityWeek .SECURITYWEEK.COM
8 SepClickFix Campaigns Abuse Legitimate Services for Persistent AccessTwo separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.DARKREADING.COM
8 SepWhy federal cyber defense demands an offense-driven mindsetStatic checklists and annual penetration tests leave agencies with dangerous blind spots. True resilience requires moving from reactive attestation to continuous, automated validation. The post Why federal cyber defense demands an offense-driven mindset appeared first on CyberSco…CYBERSCOOP.COM
8 SepCIA official touts agency’s Cyber Mission Center in capture of Venezuela’s MaduroA "flawless" performance by the CIA's Cyber Mission Center contributed to the capture of Venezuelan President Nicolás Maduro in January, agency Deputy Director Michael Ellis says.THERECORD.MEDIA
8 SepCIA’s Michael Ellis says cyber intelligence is changing how the agency operatesThe deputy director cited Operation Absolute Resolve as evidence that cyber teams have become central to CIA missions. The post CIA’s Michael Ellis says cyber intelligence is changing how the agency operates appeared first on CyberScoop .CYBERSCOOP.COM
8 SepRussian national extradited to US for alleged involvement in bank-account takeover schemeAuthorities accuse the 36-year-old and co-conspirators of collecting more than 5,000 victim login credentials to various banks. The post Russian national extradited to US for alleged involvement in bank-account takeover scheme appeared first on CyberScoop .CYBERSCOOP.COM
8 SepCybercabs, Robohobos, BigBear, Nightmare Eclipse, weChat, Flock, ASCII, Aaran Leyland - SWN #614Cybercabs, Robohobos, BigBear, Nightmare Eclipse, weChat, Flock, ASCII, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-614YOUTUBE.COM
8 SepAttackers Use Multi-Hop Google Redirects for Phishing CampaignThreat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.DARKREADING.COM
7 SepSponsored: Authentik is rethinking PAM for AI agentsIn this Risky Business sponsored interview, James Wilson chats with Authentik Security CEO Fletcher Heisler about how AI is driving a need for privileged access management to adapt. Fletcher explains Authentik’s approach: each agent has its own identity, begins with no permission…RISKY.BIZ
7 SepZero trust AI agents demand a different kind of securityIn this interview, Chris Webber, VP, Product Marketing at Teleport, explains why zero trust principles need to change for AI agents. He covers how agents act fast, unpredictably, and continuously, and why old ideas like least privilege and point-in-time verification fall short. W…HELPNETSECURITY.COM
7 Sep18 ways to check whether data can be trusted for AIETSI has published TR 104 180, a technical report that defines 18 metrics for measuring data quality, giving companies a way to check whether their data is good enough for AI before they use it. The report defines each metric and includes the formulas needed to calculate it. The …HELPNETSECURITY.COM
7 SepHow a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accountsIf you ever linked your Dropbox account to a Lenovo ID - perhaps to make life easier when logging in via a Lenovo laptop - you might want to take heed. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
7 SepNorth Korea’s Lazarus Operates Through Six Distinct Cyber ClustersSekoia and Kudelski Security have observed that North Korea's Lazarus umbrella is split into six distinct clusters, focused on espionage, financial theft and sanctions evasionINFOSECURITY-MAGAZINE.COM
7 SepAutomobile Camouflage to Hide from Flock CamerasNot sure it’s practical, but it’s certainly striking .SCHNEIER.COM
7 SepSurfshark announces acquisition of data-removal service OpterySurfshark has acquired US-based data-removal service Optery, expanding a privacy portfolio that already includes Incogni and Ironwall. Optery will continue operating independently, with its own team, product, and technology. Surfshark Group announced the acquisition today, withou…CYBERINSIDER.COM
7 SepModified ScreenConnect Clients Used in Worm-Like CampaignThe attacks rely on backdoored ScreenConnect instances to transfer and execute payloads to newly connected clients. The post Modified ScreenConnect Clients Used in Worm-Like Campaign appeared first on SecurityWeek .SECURITYWEEK.COM
7 SepNew attack eavesdrops on headphone audio from 30 meters awaySecurity researchers have demonstrated a new electromagnetic attack that can recover audio playing through ordinary wired and wireless headphones, with intelligible speech captured from as far as 30 meters away. The technique, called InjectEave, can also operate through walls and…CYBERINSIDER.COM
7 SepNorth Korean Hackers Deploy New Linux Espionage ToolkitThe stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance. The post North Korean Hackers Deploy New Linux Espionage Toolkit appeared first on SecurityWeek .SECURITYWEEK.COM
7 SepBlock Agents or Make Them AskAI agent policies can do more than simply allow or block an action. They can require the agent to ask the user for explicit approval before proceeding. That creates a human decision point inside the agent’s workflow. The agent can identify what it wants to do, but the action does…YOUTUBE.COM
7 SepLG Smart TVs found scanning home networks for nearby devicesResearchers investigating LG smart TVs found that the devices repeatedly scan local networks for nearby hardware, identifying phones, computers, smartwatches, printers, network equipment, thermostats, and other connected devices. The Gamers Nexus investigation also found extensiv…CYBERINSIDER.COM
6 SepAttackers conceal phishing lures using invisible Unicode charactersThreat actors have adopted the ASCII smuggling technique in phishing campaigns, using invisible Unicode characters to evade email security filters. [...]BLEEPINGCOMPUTER.COM
5 SepThe Fake Deal Cost €626,735In the “Phantom Deal” scheme, attackers identified someone on a target company's legal team and impersonated an executive through WhatsApp. They claimed a massive, confidential corporate acquisition was underway and eventually demanded a transfer of €626,735.45 to a company in Ho…YOUTUBE.COM
4 SepAI Coding Agents Are Installing Unknown/Untrusted Code on Corporate NetworksWe cannot forget that AI coding agents are not yet trustworthy : Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt and llms-full.txt files they found (many sites hoste…SCHNEIER.COM
4 SepISC Stormcast For Friday, September 4th, 2026 https://isc.sans.edu/podcastdetail/10082, (Fri, Sep 4th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
4 SepBidding war for defunct Spirit Airlines’ employee data will not dieThe destiny of Spirit Airline’s data is still undecided, months after the company sought bankruptcy protection. AI data company Micro1 has now offered $12.5 million to acquire a trove of the company’s emails, Teams chats, operations and employee productivity data, according to a …CSOONLINE.COM
4 SepWhy judgment is emerging as cybersecurity’s defining skillAI is getting better at much of what security teams have long spent time on: analyzing information, identifying patterns, and providing technically sound recommendations quickly. As those capabilities become more routine, they are changing what security practitioners spend their …CYBERSCOOP.COM
4 SepMullvad to shut down public encrypted DNS servers, back Quad9 insteadMullvad has announced that it will shut down its public encrypted DNS-over-HTTPS (DoH) servers on November 2, 2026, and will instead financially support privacy-focused DNS provider Quad9. Users who manually configured Mullvad’s public DNS service will need to migrate befor…CYBERINSIDER.COM
4 SepCatch Raises $5 Million for AI Executive Assistant With GuardrailsCatch promises the capabilities of a trusted executive assistant, with built-in controls governing what data and systems it can access. The post Catch Raises $5 Million for AI Executive Assistant With Guardrails appeared first on SecurityWeek .SECURITYWEEK.COM
4 SepMicrosoft Teams is about to make QR code phishing much harderMicrosoft is preparing a new feature for Teams users that will help them stay safe from QR code phishing. Teams will automatically hide QR codes sent by people outside the organization. Users will need to reveal the image first before they can view or scan it. It’s currentl…HELPNETSECURITY.COM
4 SepA five-part inventory for your AI agent credentialsIn this Help Net Security video, Roy Katmor, co-founder and CEO of Orchid, explains why AI agents hold credentials that nobody reviews. Organizations build agents in AI studios, connect them to enterprise tools, and give them accounts to do useful work. The agent is approved, the…HELPNETSECURITY.COM
4 SepNew infosec products of the week: September 4, 2026Here’s a look at the most interesting products from the past week, featuring releases from BugBase, F5 Networks, Ping Identity, and Superna. F5 speeds up virtual patching to counter AI-driven threats With new features such as anomaly detection and agentic threat intelligence, F5’…HELPNETSECURITY.COM
4 SepHow to secure edge AI in customer-owned environmentsAs AI moves into customer-owned environments, organizations need new ways to verify the systems, software, and AI assets they trust before releasing sensitive data, credentials, and models. The post How to secure edge AI in customer-owned environments appeared first on Microsoft …MICROSOFT.COM
4 SepFriday Squid Blogging: Squid on a Stick at the New York State FairLooks tasty . As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.SCHNEIER.COM
4 SepWireguard, Chrome, RMMS, Sonicwall, Microsoft, Sumerian VPNS, Harvard, and Josh Marpet - SWN #613Wireguard, Chrome, RMMS, Sonicwall, Microsoft, Sumerian VPNS, Harvard, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-613YOUTUBE.COM
4 SepEuropean parliament members call for slowdown of Serbia’s EU entry over spyware useThe letter follows revelations about Serbian student activists being infected with Pegasus and NoviSpy, and coincides with other pressures on Belgrade. The post European parliament members call for slowdown of Serbia’s EU entry over spyware use appeared first on CyberScoop .CYBERSCOOP.COM
3 SepISC Stormcast For Thursday, September 3rd, 2026 https://isc.sans.edu/podcastdetail/10080, (Thu, Sep 3rd)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
3 SepWindows memory integrity switches on automatically for eligible devices in October 2026Beginning in October 2026, Windows quality updates start enabling memory integrity protection on eligible devices with little or no additional configuration. On machines where Virtualization-based Security is not already running, those same updates enable VBS too. Memory integrit…HELPNETSECURITY.COM
3 SepYour threat feed is someone else’s database: What ingesting malware intel at scale takesThe advice is to consume shared threat intelligence. Join the ISAC. Wire the community feeds into your pipeline. This looks like a fine advice and I agree to it. What nobody mentions you is the operating manual, because the access was never the hard part. A threat feed is someone…HELPNETSECURITY.COM
3 SepWhen AI quietly breaks things, who pays?David Halbreich, an insurance recovery partner at Reed Smith, breaks down how AI companies should handle coverage gaps that come up as the industry grows. He covers straddle claims that fall between tail and go-forward D&O policies after a merger, how governance disclosures …HELPNETSECURITY.COM
3 SepYour AI agent’s system prompt is not a security controlAn AI agent told in its system prompt to show a user only what that user is cleared to see will hand over more the moment someone talks it into doing so. Gee Rittenhouse, who oversees Security Hub, GuardDuty, and Inspector at AWS, and Eric Johnson, a fellow at the SANS Institute,…HELPNETSECURITY.COM
3 Sep2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators2,000 leaked files expose Bauman University’s hidden Department No. 4, which trained GRU-linked hackers and propagandists linked to APT28 and Sandworm. Leaked Documents Expose Bauman University’s Hidden Department That Trained Hackers, Propagandists, and Malware Devel…SECURITYAFFAIRS.COM
3 SepResearchers built a $7 gadget for anyone paranoid about hidden cameras in hotel roomsMost of us, staying in a hotel room or a vacation rental, have wondered at least once whether we’re safe there, whether someone might be watching or recording us without our knowledge. The thought alone leaves a bitter taste in the mouth. A team from the Korea Advanced Inst…HELPNETSECURITY.COM
3 Sep153 Million Driver License Images Offered on Dark WebCybercriminals are offering digital scans of US and Canadian driver’s licenses, likely stolen from IDScan.net. The post 153 Million Driver License Images Offered on Dark Web appeared first on SecurityWeek .SECURITYWEEK.COM
3 SepRussian man indicted for spreading malware to 80,000 freelancersA Russian national accused of using fake accounts on a freelance employment platform to spread malware to approximately 80,000 users has been indicted by a federal grand jury in California. Searzhudin Tamirlanovich Aktulaev, 40, faces charges of conspiracy, transmission of malici…HELPNETSECURITY.COM
3 SepResearching Employment ScamsResearchers built a fake company to study fake employee scams .SCHNEIER.COM
3 SepAI Agent Firewall Startup AIR Security Emerges From Stealth With $50 MillionThe startup’s firewall evaluates AI skills, plugins and MCP servers for malicious instructions, excessive permissions and software supply chain risks. The post AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million appeared first on SecurityWeek .SECURITYWEEK.COM
3 SepHiddenLayer Raises $100 Million for AI Runtime SecurityThe Austin-based company will invest in agentic runtime security capabilities to secure AI coding agents. The post HiddenLayer Raises $100 Million for AI Runtime Security appeared first on SecurityWeek .SECURITYWEEK.COM
3 SepWhy your data is safer than you think on public Wi-FiTL;DR The coffee shop hacker Public Wi-Fi has acquired a slightly theatrical reputation. Join the network in a coffee shop, we are told, and a hacker in the corner can immediately steal your passwords and empty your bank account. It makes for good VPN ad…PENTESTPARTNERS.COM
3 SepGoogle’s Gemini 3.8 Flash takes on bigger AI models at a lower costGoogle has introduced Gemini 3.8 Flash, available to developers today, and a gated sibling, Gemini 3.8 Flash Cyber, reserved for vetted security teams. “Our 3rd Flash release in just 6 wks,” Google CEO Sundar Pichai said on X, adding that it makes sizable gains over 3…HELPNETSECURITY.COM
3 SepManchester Airports Group Data on 8.8 Million People Leaked After Ransom RefusalHacker group published roughly 550GB of data after MAG reportedly refused to pay a ransom demand; the group says it gained access via exposed admin keys. The post Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal appeared first on SecurityWeek .SECURITYWEEK.COM
3 SepCapsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue AgentsNew models, trained using NVIDIA Nemotron 3 Ultra, aim to catch rogue agent behavior before it executes, without the latency of large-model review. The post Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents appeared first on SecurityWeek .SECURITYWEEK.COM
3 SepASCII smuggling crosses over from AI prompt injection to phishing evasionInvisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them. The post ASCII smuggling crosses over from AI prompt injection to phishing evasion appeared first on Microsoft Security Blog .MICROSOFT.COM
3 SepBrave tests show lower CPU and memory usage than Chrome, Edge, and FirefoxBrave says its desktop browser used less CPU, memory, energy, and network bandwidth than Chrome, Edge, and Firefox in a new round of macOS testing, attributing much of the difference to its built-in ad and tracker blocking. The benchmarks were conducted by Brave itself, and the b…CYBERINSIDER.COM
3 SepThe story behind the intelligenceFrom engaging with cybercriminals to surviving a live Flamin’ Hot Cheetos taste test, Hazel reflects on the latest Beers with Talos with Azim, where they cover the full spectrum of what it takes to gather threat intel.TALOSINTELLIGENCE.COM
3 SepThe G7 tells industry to hurry up and prep for post-quantum encryptionThe nations warn that governments and industry can no longer treat quantum codebreaking as a distant or theoretical possibility. The post The G7 tells industry to hurry up and prep for post-quantum encryption appeared first on CyberScoop .CYBERSCOOP.COM
3 SepLarge Enterprises Targeted in Fake Merger & Acquisition ScamsThreat actors behind the "Phantom Deal" campaign are studying companies in extreme detail, aiming to dupe midlevel employees into initiating large financial transfers.DARKREADING.COM
2 SepISC Stormcast For Wednesday, September 2nd, 2026 https://isc.sans.edu/podcastdetail/10078, (Wed, Sep 2nd)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
2 SepAnthropic’s Enterprise Frontier Safeguards lets your Claude logs stay in your cloudEight members of the Analysis and Resilience Center for Systemic Risk, a group whose roster includes the CISOs of Goldman Sachs, Morgan Stanley, Citi, Bank of America, and Wells Fargo, spent months working with Anthropic on a question their examiners care about more than benchmar…HELPNETSECURITY.COM
2 SepAn AI CAPTCHA solver talked itself out of the right answerYou have probably spent a few seconds of your life turning a picture until it lines up. Some sites, instead of asking you to tick a box, show you a circular chunk of a photo that has been spun around, and you drag it until the inside matches the ring around it. Simple enough. Ann…HELPNETSECURITY.COM
2 SepScareware ads keep running on Google’s transparency tool, even after they’re reportedA team of NYU and Radboud University researchers spent a year building a tool to find deceptive software ads inside Google’s public ad archive. It works. It also exposed something more uncomfortable: reporting a bad ad to Google doesn’t mean the ad, or the domain behi…HELPNETSECURITY.COM
2 SepVisa enhances A2A Protect to stop fraud before money leaves the accountVisa announced an enhanced version of A2A Protect, delivering real-time risk insights that help banks stop account-to-account fraud before money leaves customer accounts. The expanded solution introduces a new unified fraud score—Visa’s integration of Featurespace technology—givi…HELPNETSECURITY.COM
2 SepEdge Case launches Guardian, an AI platform for tracking risk across autonomous systemsEdge Case launched Guardian, an AI-driven platform that connects safety analysis, engineering data, and operational signals to give teams a continuous understanding of how system risk evolves. At launch, Guardian will support some of the world’s most advanced autonomous pla…HELPNETSECURITY.COM
2 SepF5 speeds up virtual patching to counter AI-driven threatsF5 announced innovations to block frontier AI-driven threats in the data path and enable faster virtual patching, giving security leaders time to make intelligent risk-based decisions rather than reactive operational compromises. With new features such as anomaly detection and ag…HELPNETSECURITY.COM
2 SepNational Life Group CISO expects more vulnerabilities in six months than in thirty yearsIn this Help Net Security interview, Becky Palmer is VP and CISO at National Life Group, answers five questions about defending against AI-driven attacks. The discussion covers why patch cycles built for human speed cannot keep up, and which compensating controls buy time when an…HELPNETSECURITY.COM
2 Sep23-Year-Old Sality P2P Botnet DisruptedThe shutdown operation involved peer list manipulation and Sality payload URL takedown. The post 23-Year-Old Sality P2P Botnet Disrupted appeared first on SecurityWeek .SECURITYWEEK.COM
2 SepExtradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected ThousandsThe U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in 2016 and 2017. Searzhudin Tamirlanovich A…THEHACKERNEWS.COM
2 SepPreventing Wire Fraud and 2 Interviews From BH USA 2026 From Optiv Security and Kai - ... - BSW #463Wire fraud, identity spoofing, and PII exposure now top the list of operational risks for private capital. In a world of ongoing fraud risk, fiduciary responsibility doesn’t end with sound investment decisions — it must extend to operational best practices that protect every capi…YOUTUBE.COM
2 SepWireless Routers as Motion DetectorsComcast has added motion detection as a feature to its wireless routers: The feature sends push notifications to users when motion is detected near a connected device, such as a TV or printer. It has different settings for when people are home, asleep, or away. The Xfinity app al…SCHNEIER.COM
2 SepGaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weaponResearch by: Amit Yardeni Key Points Introduction Since mid-2025, Check Point Research has tracked a sustained campaign against Brazilian organizations. The tradecraft points to a Chinese-speaking cybercrime group connected to Earth Berberoka, an actor first documented …RESEARCH.CHECKPOINT.COM
2 SepAttackers are going after prominent individuals through OAuth phishing, FBI warnsAttackers are targeting prominent individuals, their relatives and personal contacts to gain persistent access to their accounts, including private emails and files, the FBI has warned. The FBI’s Internet Crime Complaint Center (IC3) says the activity, which uses a technique call…HELPNETSECURITY.COM
2 SepIran-linked APT Mirage Kitten Uses Fake Job Tests to Spread MalwareMirage Kitten used fake LinkedIn coding tests to spread NodeRabbit and PollCat, even banning AI tools that could have spotted the malware. Iran-linked Mirage Kitten hackers just found a genuinely clever way to make their own malware harder to detect: telling job candidates not to…SECURITYAFFAIRS.COM
2 SepRockwell Automation Patches Over a Dozen Vulnerabilities Across ProductsThe industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products. The post Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products appeared first on SecurityWeek .SECURITYWEEK.COM
2 SepDownload: The Agentic Software Development GuideAI makes it easy to ship more code. It does not make that code easier to trust. Most teams don’t fail because their developers can’t use AI. They fail because the dev’s job changed and nobody redefined it. Under AI, cracks appear: Reviews weaken while output multiplies Code looks…HELPNETSECURITY.COM
2 SepWhat If Every Wire Recipient Was Verified?Sending a wire often means entering and relying on account information for another person or entity. The sender is ultimately responsible for making sure the information is correct. That creates a fundamental trust problem. What if the person, entity, and bank account were verifi…YOUTUBE.COM
2 SepU.K. Supreme Court Opens Door for Spyware Victims to Sue Foreign StatesLast month, the Supreme Court of the United Kingdom issued a highly anticipated decision in The Kingdom of Bahrain v. Shehabi and another (Shehabi). The claimants, two Bahraini dissidents living in the U.K., allegedly suffered psychological harm after Bahrain used FinSpy spyware …CITIZENLAB.CA
2 SepPegasus, NoviSpy variant spyware found on devices of Serbian activistsIt’s the first Pegasus infection of 2026 that Citizen Lab is forensically confirming, and the SHARE Foundation said it’s the biggest wave of spyware surveillance in Serbia yet. The post Pegasus, NoviSpy variant spyware found on devices of Serbian activists appeared first on Cyber…CYBERSCOOP.COM
2 SepWyden seeks upgraded NSA security guidance on commercial VPN useit’s the latest in a sequence of letters to feds from Sen. Ron Wyden, D-Ore., on commercial VPNs. The post Wyden seeks upgraded NSA security guidance on commercial VPN use appeared first on CyberScoop .CYBERSCOOP.COM
2 SepCybersecurity Insiders: AI Infrastructure’s Firmware Problem Is Bigger Than Any Single VendorThe rapid construction of AI infrastructure is creating new security challenges across the hardware and software stack, from inference servers and telemetry tools to network adapters, management controllers and trusted platform modules. The post Cybersecurity Insiders: AI Infrast…ECLYPSIUM.COM
2 SepThe FCC wants consumers to rate their telecom’s anti-robocall protectionsThe FCC wants consumers to rate their telecom’s anti-robocall protections. The post The FCC wants consumers to rate their telecom’s anti-robocall protections appeared first on CyberScoop .CYBERSCOOP.COM
2 SepDogged Russia-based botnet dismantled after 23-year runSality’s peer-to-peer infrastructure allowed it to evade system-wide disruption efforts for an exceptionally long period. Authorities and cybersecurity experts finally brought it down. The post Dogged Russia-based botnet dismantled after 23-year run appeared first on CyberScoop .CYBERSCOOP.COM
2 SepMalicious “privacy browser” hijacks PCs with mouse and keyboard injectionSecurity researchers at Intezer have uncovered a deceptive browser application that can remotely inject keyboard and mouse commands into Windows systems. The campaign was discovered after an employee mistyped a single character while following setup instructions for a newly purch…CYBERINSIDER.COM
2 SepAI Gives Cybercriminals a Dangerous Time AdvantageFormer cybercriminal Brett Johnson provides a look inside the mind of a threat actor and discusses where AI provides the most value for attackers.DARKREADING.COM
2 SepAI Is Fighting AI-Powered Identity FraudIdentity verification is becoming a data-intensive process. At SixLock, the system can pull roughly 130 data points from different databases and compare them against information associated with a person and their identity documents. The goal is to determine whether all those sign…YOUTUBE.COM
2 SepImpersonating IT support: how threat actors turn a remote session into enterprise-wide accessMicrosoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers move from social engineering to lateral movement us…MICROSOFT.COM
1 SepISC Stormcast For Tuesday, September 1st, 2026 https://isc.sans.edu/podcastdetail/10076, (Tue, Sep 1st)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
1 SepCybersecurity jobs available right now: September 1, 2026Security Engineer, PSO Google | USA | On-site – View job details As a Security Engineer, you will provide technical guidance to customers adopting Google Cloud Platform, helping them navigate their cloud journey with the Professional Services team. The role includ…HELPNETSECURITY.COM
1 SepWhat your vendor says about PQC tells you if they are readyIn this interview with Help Net Security, Dr. Yaakov Stein, VP CTO of Allot, discusses what post-quantum readiness looks like inside a mobile network. The discussion covers which operator traffic stays sensitive for years, including subscriber identity mappings, billing records a…HELPNETSECURITY.COM
1 SepLastPass enhancements improve visibility, governance, and controlLastPass announced a series of strategic product innovations, customer experience enhancements, and industry milestones. These advancements reflect the company’s continued focus on providing practical tools to protect access and identity in an increasingly AI-driven threat landsc…HELPNETSECURITY.COM
1 SepAskeal, the AI cybersecurity assistant that gives verifiable, expert-backed answersAskeal takes the opposite approach to omniscient Gen AI: rather than pretending to know everything, it combines AI with community expertise. Vetted vendors, researchers, and practitioners contribute their intelligence and tools to help users conduct manual investigations. The sta…HELPNETSECURITY.COM
1 SepWatchGuard Patches Critical VulnerabilitiesThree critical issues in the Fireware OS iked process could allow unauthenticated attackers to execute arbitrary code remotely. The post WatchGuard Patches Critical Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
1 SepRewiring Democracy Series on The RenovatorNathan E. Sanders and I are writing a series of essays on real-world examples of democratic technologies for The Renovator . I haven’t been posting the full text on the blog because they’re a bit long, but here are links. Part 1 is about the Japanese digital democracy…SCHNEIER.COM
1 SepThe Collective Cyber Defense letter wrote your next vendor questionnaireMore than 200 companies have now signed to an August 27 letter about improving cyber defenses in the age of AI. Buried in it are three metrics every one of them endorse under its own logo: coverage, containment speed, and whether fixes work. The post The Collective Cyber Defense …CYBERSCOOP.COM
1 SepThreat Actors Don’t Want Better Attacks. They Want Repeatable OnesThe most common way into a company last year was to ask. A web page tells the visitor to prove they are not a robot. While they read the instructions, it quietly places a command on their clipboard. Then it talks them through opening a terminal and pasting it in. The technique is…THEHACKERNEWS.COM
1 SepNorth Korea-linked IT Workers Are Getting Hired Inside Western CompaniesHuntress found five DPRK-linked workers hired in 2026 using fake identities, remote-access setups and proxy tools to infiltrate legitimate companies. Companies keep accidentally hiring North Korea-linked individuals as remote workers, and Huntress just published the receipts. The…SECURITYAFFAIRS.COM
1 SepTerminalFix looks like ClickFix, but delivers a very different payloadThe familiar ClickFix fake CAPTCHA trick has been adapted to deliver a payload that can give attackers access to the victim’s wider network.MALWAREBYTES.COM
1 SepIranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding TestsThe Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote acces…THEHACKERNEWS.COM
1 SepWhistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballotsThe Federal Ballot Mail Portal is described by a federal official as one of several IT systems that will be used to potentially deny thousands of mail-in ballots or more to states. The post Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots app…CYBERSCOOP.COM
1 SepFirefox 155 speeds up web connections with Happy Eyeballs v3 and QUIC v2Mozilla has released Firefox 155, introducing networking changes designed to reduce connection delays, alongside new privacy indicators and Smart Window improvements. The new release adds Happy Eyeballs v3 and QUIC v2 support for HTTP/3, both aimed at helping Firefox establish fa…CYBERINSIDER.COM
1 SepVishing campaign abuses Microsoft Teams to give attackers a foothold in company networksA coordinated voice-phishing (vishing) campaign, named Spring Ring, used fake IT support accounts on Microsoft Teams to trick employees into installing malware or granting remote access to their computers, according to Unit 42, Palo Alto Networks’ threat intelligence team. …HELPNETSECURITY.COM
1 SepSecurity policies fail to keep up with a hybrid cloud worldRoughly two-thirds of companies have suffered a business-critical app outage due to misconfigured security policies, a Cloud Security Alliance report found.CYBERSECURITYDIVE.COM
1 SepGoogle removes uBlock Origin from Chrome Web Store in final Manifest V2 purgeGoogle has removed uBlock Origin from the Chrome Web Store as it completes the final stage of its years-long phase-out of Manifest V2 extensions. The removal also affects every other remaining extension still using the older framework. The change took effect on August 31, 2026, i…CYBERINSIDER.COM
1 SepSevii Targets AI-Speed Attacks With Preemptive Autonomous DefenseSevii has expanded its ADR platform with AI agents designed to investigate, contain, and remediate AI-driven attacks within minutes. The post Sevii Targets AI-Speed Attacks With Preemptive Autonomous Defense appeared first on SecurityWeek .SECURITYWEEK.COM
1 SepCoast Guard Establishes Office of Maritime Cybersecurity PolicyThe new office will serve as the central authority for cybersecurity policy covering US ports, vessels, and maritime facilities. The post Coast Guard Establishes Office of Maritime Cybersecurity Policy appeared first on SecurityWeek .SECURITYWEEK.COM
1 SepAI Didn’t Kill Bug BountiesThe rise of AI models has sparked predictions that bug bounty programs could become obsolete. But the data discussed here points in the opposite direction. Security researchers are finding more sophisticated and impactful vulnerabilities with increasingly powerful tooling. The re…YOUTUBE.COM
1 SepCybersecurity IR Workshop: The workshop you shouldn’t missCyber resilience starts before a crisis. Gain practical insights from DART to strengthen readiness and response. The post Cybersecurity IR Workshop: The workshop you shouldn’t miss appeared first on Microsoft Security Blog .MICROSOFT.COM
1 SepTina Peters, through attorney, backs off formal role in Shasta County electionsPeters still left the door open to working with Shasta County on elections and doubled down on her statements that electronic voting machines should be discontinued. The post Tina Peters, through attorney, backs off formal role in Shasta County elections appeared first on CyberSc…CYBERSCOOP.COM
1 SepPalo Alto Networks Acquires AI Agent Platform ConsoleThe cybersecurity giant announced the acquisition alongside quarterly results showing a 34% increase in revenue and strong growth in next-generation security ARR. The post Palo Alto Networks Acquires AI Agent Platform Console appeared first on SecurityWeek .SECURITYWEEK.COM
1 SepAI Model Evaluator METR Hit by Credential Theft, ProbingIn one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonprofit.DARKREADING.COM
1 SepVictorians, TONIC, RevStealer, Fireant, OpenClaw, PowerShell, SuperBox, Aaran Leyland - SWN #612Victorian Bug Bounties, TONIC, RevStealer, Fireant, OpenClaw, PowerShell, SuperBox, Nimbus Manticore, Isambard Kingdom Brunel, Rote Tod, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://…YOUTUBE.COM
1 SepFBI raises alarm over deceptive phishing campaign targeting prominent peopleThe ongoing social engineering threat, which dates back to late 2025, tricks victims into granting threat actors long-term access to their accounts. The post FBI raises alarm over deceptive phishing campaign targeting prominent people appeared first on CyberScoop .CYBERSCOOP.COM
1 SepCounterfeit installers to system compromise: Tracking a deceptive software download campaignAn active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections, indicators of compromise, and practical …MICROSOFT.COM
31 AugHiding Prompt Injection in Legal FilingSomeone hid AI instructions into a legal filing. Alternate link .SCHNEIER.COM
31 AugValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus ExclusionsThe threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions. Russian cybersecurity v…THEHACKERNEWS.COM
31 AugISC Stormcast For Monday, August 31st, 2026 https://isc.sans.edu/podcastdetail/10074, (Mon, Aug 31st)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
31 AugAI Creates an Accountability GapAgentic AI can investigate and combine information from different parts of an organization. A financial agent could encounter relevant information through email or security systems that changes how it approaches a task. The technical ability to connect information can move faster…YOUTUBE.COM
31 AugValleyRAT masquerading as adwareThreat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to the final payload.SECURELIST.COM
31 AugThe AI Kill Switch Act is repeating the Clipper Chip’s mistakesMandating ‘kill switches’ for AI agents would threaten the security of America’s critical infrastructure and undercut U.S. AI leadership. Congress must reject the AI Kill Switch Act. The post The AI Kill Switch Act is repeating the Clipper Chip’s mistakes appeared first on CyberS…CYBERSCOOP.COM
31 AugPaperCut issues emergency patches as threat actors target chained vulnerabilitiesThe print management software maker faced a wave of attacks in 2023 aimed at higher education customers.CYBERSECURITYDIVE.COM
31 AugState-linked actor targets Cisco routers for espionageAn actor known as Fire Ant has expanded its reach into trusted environments, with unique tooling and stealth.CYBERSECURITYDIVE.COM
31 AugBreaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 BytecodeResearch by: hasherezade Key Points Introduction JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names WEEVILPROXY or MeadowLocust). Its campaign…RESEARCH.CHECKPOINT.COM
31 AugSpring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft TeamsLearn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
31 AugEU puts ChatGPT, Reddit, and Roblox under stricter DSA rulesThe European Commission has designated ChatGPT, Reddit, and Roblox as services subject to the strictest requirements of the EU’s Digital Services Act (DSA) after each reported reaching at least 45 million monthly users in the European Union. Under the designations announced today…CYBERINSIDER.COM
31 AugAnthropic Warns Claude Users of Infostealer Malware InfectionsThe AI giant is logging customers out of their accounts and removing payment data to prevent unauthorized Claude usage. The post Anthropic Warns Claude Users of Infostealer Malware Infections appeared first on SecurityWeek .SECURITYWEEK.COM
31 AugJudge Says Pentagon’s Measures Against Anthropic Were ‘Illegal and Baseless’The ruling is part of Anthropic's legal battle against the Pentagon after the government labeled the company as a supply chain risk earlier this year. The post Judge Says Pentagon’s Measures Against Anthropic Were ‘Illegal and Baseless’ appeared first on Securit…SECURITYWEEK.COM
31 AugAWS Console Private Access can block sign-ins to personal accountsThe AWS Management Console now loads inside a network with no path to the public internet. Console Private Access became generally available on August 28 for virtual private clouds, the isolated networks customers run inside AWS, that have no internet connectivity at all. Authent…HELPNETSECURITY.COM
31 AugDebian developers rejected an LLM ban and left disclosure voluntaryA maintainer reading a merge request can’t tell whether a person or a model wrote the diff, and nobody has to say. Debian developers voted on that through August 28, and Kurt Roeckx, the project secretary, announced the result: the winning option encourages contributors to …HELPNETSECURITY.COM
31 AugChina-linked Fire Ant Hides Inside Trusted InfrastructureFire Ant hijacked Cisco routers, stole credentials and altered logs to hide its tracks, using trusted infrastructure to reach high-value networks. Chinese-linked cyber espionage group Fire Ant has spent the past year quietly graduating from hacking individual computers to hacking…SECURITYAFFAIRS.COM
31 AugNorth Korean Job Fraud Expands Beyond IT Into Healthcare and SalesThreat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and …THEHACKERNEWS.COM
31 AugNew RevStealer malware spreads as fake Claude Opus 5 desktop appRevStealer malware is being distributed through trojanized Electron applications, including a GitHub project masquerading as a free desktop version of Anthropic’s Claude Opus 5. The malware steals browser data, password-manager files, cryptocurrency wallets, credentials, and docu…CYBERINSIDER.COM
31 AugAI Security Tools Need to TalkSecurity investigations often depend on connecting activity from different systems. File activity might matter in combination with email activity, for example, but that context can be fragmented across separate security tools. AI agents could perform more of that correlation auto…YOUTUBE.COM
31 Aug‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity helpThe six-month program will be overseen by the Office of the National Cyber Director and Texas Cyber Command to “find out what works.” The post ‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help appeared first on CyberScoop .CYBERSCOOP.COM
31 AugMcKesson copes with fallout from data theft extortion attackThe major healthcare sector vendor did not identify the attackers, but ShinyHunters, a prolific group increasingly targeting the sector, claimed responsibility. The post McKesson copes with fallout from data theft extortion attack appeared first on CyberScoop .CYBERSCOOP.COM
31 AugAnthropic Users Hit by Infostealer Attacks, Session TheftsA threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.DARKREADING.COM
30 AugYARA-X 1.20.0 Release, (Sun, Aug 30th)YARA-X&#;x26;#;39;s 1.20.0 release brings 14 improvements and 13 bugfixes.
ISC.SANS.EDU
30 AugCyberWire Daily at 10: A decade of emerging threat actors and APTs.In this episode, Maria Varmazis and Dave Bittner from N2K Cyberwire get back together to discuss the evolution of advanced persistent threats (APTs), threat actor landscape, attribution changes, and the future of cyber espionage over the past decade. Join Dave and Maria as th…THECYBERWIRE.COM
29 AugTerminalFix campaign deploys a reverse tunnel through multistage intrusionMicrosoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance. The post TerminalFix campaign deploys a reverse tunnel through multistage intrusion appeared first o…MICROSOFT.COM
28 AugISC Stormcast For Friday, August 28th, 2026 https://isc.sans.edu/podcastdetail/10072, (Fri, Aug 28th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
28 AugAI Doesn’t Mean the End of Mathematics—at Least Not YetThis essay was written with Kasra Rafi, and originally appeared in The Guardian. Earlier this month, about 40 top mathematicians gathered at OpenAI’s offices to discuss the future of their profession. The meeting was off-the-record, but if recent articles by mathematicians …SCHNEIER.COM
28 AugAPT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic OrganizationsCybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. These campaigns, per Recorded Future Insikt Group, have led to the deployment of a pr…THEHACKERNEWS.COM
28 AugSome Malicious PE Stats, (Thu, Aug 27th)During my last FOR610 session, a student asked me if I had some statistics in mind about the compilers used to generate malicious PE files? A couple of months ago, I shared some stats about the trend in 64bits VS. 32bits malware[ 1 ]. Can we go a bit further? …ISC.SANS.EDU
28 AugShai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands moreMore than 1,000 organisations, 500,000 stolen credentials, and one self-propagating worm named after a Dune sandworm - two men now face charges over TeamPCP's global hacking spree. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
28 AugPerturbation Probing: A New Diagnostic for the Fragility of LLM SafetyNew research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security. The post Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
28 Aug19 Chrome and Edge extensions caught harvesting crypto wallet seedsSecurity researchers have uncovered 19 malicious Chrome and Edge extensions delivering cryptocurrency wallet drainers, credential stealers, session hijacking tools, and other remotely loaded malware. Socket Threat Research reports that the malicious versions appeared over the pas…CYBERINSIDER.COM
28 AugProton finds 85% of US-downloaded VPN apps contain trackersA months-long investigation by Proton into more than 7,000 mobile VPN apps has found that 85% of the VPNs downloaded in the United States contain tracking components, while roughly a quarter of the analyzed services collect users’ physical location. The company also identified do…CYBERINSIDER.COM
28 AugBrave launches Email Aliases to hide users’ real email addressesBrave has launched a built-in Email Aliases feature that lets users create disposable forwarding addresses directly from website sign-up forms, preventing sites from learning their primary email address. The feature arrives with Brave desktop version 1.94 and is backed by a new B…CYBERINSIDER.COM
27 AugISC Stormcast For Thursday, August 27th, 2026 https://isc.sans.edu/podcastdetail/10070, (Thu, Aug 27th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
27 AugThe best human hacking team still out-solved the best AI teamBring an AI agent to a hacking competition and you would expect to find it propping up the teams who were struggling. In the 2026 Global Cyber Skills Benchmark, agents showed up in 17 of the Top 25 finishers. The people who least needed help were the ones who brought it. The peop…HELPNETSECURITY.COM
27 AugSrsly Risky Biz: China's AI-Enabled APT Operations Are Getting InterestingTom Uren and James Wilson talk about evidence that Chinese APT groups are using AI in a really sensible way, to beef up their malware arsenal. This will make it harder for threat intel firms to cluster activity for attribution. They also discuss the US disrupting Iranian hackers …RISKY.BIZ
27 AugAbnormal AI expands email security from detection to data protection and phishing-simulation trainingAbnormal AI announced an expansion of its email security platform with three new capabilities: Control Center, Email DLP Rules, and AI Phishing Coach upgrades. Together, the launch extends Abnormal’s behavioral AI across all three surfaces of email risk: what comes into the inbox…HELPNETSECURITY.COM
27 AugUS Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure AttacksThe operation focused on a group named QTFY, which offers hacking services to the Chinese government and others. The post US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
27 AugGoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 AddressThreat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela. GoCaracal provides operators with remote shell…THEHACKERNEWS.COM
27 AugThe Future of AI-Driven Security Depends on Complete DataFor twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. The post The Future of AI-Driven Security Depends on Complete Data appeared first on SecurityWeek .SECURITYWEEK.COM
27 AugOpenAI Agents Coordinated via Makeshift Message Board Ahead of Hugging Face HackNew training environments will teach AI models to distrust instructions arriving from other agents outside sanctioned channels. The post OpenAI Agents Coordinated via Makeshift Message Board Ahead of Hugging Face Hack appeared first on SecurityWeek .SECURITYWEEK.COM
27 AugOkta Shares Surge on Strong Earnings, Growing Demand for AI Identity SecurityThe identity security company beat quarterly expectations and raised its outlook as enterprises face growing pressure to secure AI agents and other non-human identities. The post Okta Shares Surge on Strong Earnings, Growing Demand for AI Identity Security appeared first on Secur…SECURITYWEEK.COM
27 AugCISO Conversations: Chris Wheeler – Trust Is the Job, From the Navy to the C-SuiteSecurityWeek talks to Chris Wheeler, CISO at Resilience, about his journey from the Navy to becoming a cybersecurity leader. The post CISO Conversations: Chris Wheeler – Trust Is the Job, From the Navy to the C-Suite appeared first on SecurityWeek .SECURITYWEEK.COM
27 AugRussian Hackers Phish EU Officials Over Messaging AppsEU governments are trying to move away from popular messaging apps as nation-state threat groups shift their focus from email to Signal and WhatsApp.DARKREADING.COM
27 AugRing adds rotating video keys and 24-hour deletion with new TAKE systemRing has announced a new video encryption system called Throw Away the Key Encryption (TAKE) that will eventually become the default for all customers worldwide. The system limits how long Ring retains the encryption keys needed to process recordings while preserving cloud-based …CYBERINSIDER.COM
27 AugAustralia Arrests 2 Alleged TeamPCP HackersAustralian and US authorities collaborated to identify and charge the alleged cybercriminals, who face many years in prison. The post Australia Arrests 2 Alleged TeamPCP Hackers appeared first on SecurityWeek .SECURITYWEEK.COM
27 AugHow Threat Research and MDR Help SMBs Build a Defensive EdgeThreat research gives security teams insight into how attackers operate, while MDR turns that intelligence into faster detection and response. ESET explains how combining threat intelligence, continuous monitoring, and human expertise can help SMBs strengthen their defenses. [...…BLEEPINGCOMPUTER.COM
27 AugCybercrime Just Got Much FasterInternet-based crime can operate across borders at enormous speed and scale. Matt Lea says major clients are seeing unprecedented levels of bot traffic. The challenge isn't simply blocking malicious traffic. Defenders have to determine whether massive volumes of requests are legi…YOUTUBE.COM
27 AugTwo alleged TeamPCP members arrested and charged after months of software supply-chain chaosThe two men face 14 charges combined. Private researchers traced one suspect through leaked passwords and a decade-old gaming profile. The post Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos appeared first on CyberScoop .CYBERSCOOP.COM
27 AugWhat’s new in Microsoft Security: August 2026This month’s updates provide new capabilities to help organizations gain insights into agent activity, expand security coverage across supported environments, and enhance security management across their environments. The post What’s new in Microsoft Security: August 2026 a…MICROSOFT.COM
27 AugFormer sexual abuse victims say Grok used their images, videos to train deepfake capabilitiesElon Musk claimed he was aware of “literally zero” CSAM content created through Grok. A new lawsuit from thousands of real victims say the model was trained on their child abuse. The post Former sexual abuse victims say Grok used their images, videos to train deepfake capabilitie…CYBERSCOOP.COM
27 AugUnit 42 warns AI has shifted balance of power from defenders to attackersPalo Alto Networks’ threat intelligence team said the early waves of threats riding on agentic AI models have broken in the wild, and organizations are unprepared for what’s coming next. The post Unit 42 warns AI has shifted balance of power from defenders to attackers appeared f…CYBERSCOOP.COM
27 Aug100-plus companies call for ‘global surge’ in AI-powered cyber defenseOpenAI, Anthropic, Google, Microsoft, and others say there’s a narrow “defenders’ window” to strengthen security before AI-powered attacks become more sophisticated. The post 100-plus companies call for ‘global surge’ in AI-powered cyber defense appeared first on CyberScoop .CYBERSCOOP.COM
27 AugDark Caracal Deploys New Go Malware With Ethereum-Based C2 FallbackDark Caracal targets Venezuela with GoCaracal, an upgraded Bandook toolkit and an Ethereum fallback for resilient C2 communications. Dark Caracal is back with new malware and the same hunting grounds. Arctic Wolf Labs researchers link a June 2026 intrusion against a communication…SECURITYAFFAIRS.COM
26 AugISC Stormcast For Wednesday, August 26th, 2026 https://isc.sans.edu/podcastdetail/10068, (Wed, Aug 26th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
26 AugProduction data in testing is still common, and Tricentis’ CISO wants it goneIn this Help Net Security interview, Erika Dean, CISO at Tricentis, talks about keeping production data out of test environments and why she thinks the alternatives are good enough now. She explains how her team caught a prompt injection gap in red-teaming and held a release for …HELPNETSECURITY.COM
26 AugChrome 152 Patches Over 300 VulnerabilitiesMost of the flaws were discovered by Google using AI, but researchers are still discovering high-value Chrome vulnerabilities. The post Chrome 152 Patches Over 300 Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
26 AugRightCrowd Pass unifies mobile, physical, and biometric credentialsRightCrowd announced RightCrowd Pass, a credentialing solution that issues and manages mobile, physical and biometric access credentials from a single platform. Many large enterprises and universities rely on badge programs-built years ago. As organizations add mobile and biometr…HELPNETSECURITY.COM
26 AugBogus recruiters go after high-value corporate credentials on mobileScammers posing as HR staff at well-known companies are running interview scheduling scams that end with a stolen corporate password, according to Zimperium. Attackers are using a technique called browser-in-the-browser, or BitB, which CTM360 documented in earlier research on rec…HELPNETSECURITY.COM
26 AugEstate planning of credentialsA sad start Last year one of my colleagues, Ken, received the sad news that a father of a friend had passed away. He was a tech-savvy gentleman and had invested in smart tech to make his and his family’s life easier and, just as we recommen…PENTESTPARTNERS.COM
26 AugTutaCrypt post-quantum email encryption passes security analysisResearchers at the University of Wuppertal have analyzed TutaCrypt, the hybrid encryption protocol used by Tuta Mail to protect email against both conventional and future quantum-computing attacks. Their paper concludes that the protocol provides meaningful post-quantum confident…CYBERINSIDER.COM
26 AugThe MFA Identity Trap: When Authentication Creates a False Sense of SecurityOrganizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. The post The MFA Identity Trap: When Authentication Creates a False Sense of Security appeared first on SecurityWe…SECURITYWEEK.COM
26 AugSpyware for BabiesThe New York Times has a long article ( alt link ) on surveillance systems aimed at babies. They are increasingly using AI. Nanit and its rivals want to own 24/7 health tracking for the sub-four-foot set. And their already astonishing levels of baby data collection are just the b…SCHNEIER.COM
26 AugTreasury to help financial firms transition to quantum-resistant encryptionThe government is concerned that hackers someday will be able to decrypt financial information and other secrets using code-breaking quantum computers.CYBERSECURITYDIVE.COM
26 AugAdobe and Nvidia Patch Dozens of VulnerabilitiesAdobe and Nvidia each published several advisories, including ones that address critical vulnerabilities in their products. The post Adobe and Nvidia Patch Dozens of Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
26 AugAnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodesA phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar found. “By leveraging a critical flaw – the use of bare relative paths – the investigation unraveled a…HELPNETSECURITY.COM
26 AugElection official says Tina Peters would be consultant, won’t have access to election systemsShasta County registrar Clint Curtis told CyberScoop he needs Peters to help manage the county’s 2026 elections and he’s not concerned about her past conviction. The post Election official says Tina Peters would be consultant, won’t have access to election systems appeared first …CYBERSCOOP.COM
26 AugFBI disrupts proxy network enabling Chinese espionage operationsThe FBI has disrupted infrastructure associated with a technical "quartermaster" that provided reconnaissance, proxy management, and operational routing capabilities for Chinese cyber espionage activities. [...]BLEEPINGCOMPUTER.COM
26 AugAI Infra Summit 2026The post AI Infra Summit 2026 appeared first on Eclypsium | Supply Chain Security for the Modern Enterprise .ECLYPSIUM.COM
26 AugMeta agrees to $17.1 billion settlement over alleged harms to childrenMeta has agreed to pay up to $17.1 billion and make sweeping changes to Facebook and Instagram under a proposed multistate settlement resolving claims that its platforms harmed children and teenagers and misled the public about those risks. The agreement, announced today by a bip…CYBERINSIDER.COM
26 AugAI Speeds Up Malware Development, Not Its Success Rate: AnalysisPalo Alto Networks Unit 42 analyzed 405 AI-linked malware samples and found only 12 reached production endpoints. The post AI Speeds Up Malware Development, Not Its Success Rate: Analysis appeared first on SecurityWeek .SECURITYWEEK.COM
26 AugFBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. OrganizationsThe U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chin…THEHACKERNEWS.COM
26 AugNimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH TunnelerCybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Group-IB, in a new analysis published t…THEHACKERNEWS.COM
26 AugAndroid Malware Hijacks Update System for Car Head UnitsThreat actors behind a notorious click-fraud botnet have set their sights on vehicle infotainment modules and are abusing legitimate functionality to spread infections.DARKREADING.COM
26 AugOfficials disrupt Chinese espionage operation that hit multiple federal agenciesThe full hacking suite, seized by authorities, allowed Chinese government funded attackers to intrude highly sensitive networks undetected for more than eight years. The post Officials disrupt Chinese espionage operation that hit multiple federal agencies appeared first on CyberS…CYBERSCOOP.COM
26 AugRed Flags That Expose Fake North Korean IT WorkersNorth Korean operatives posing as IT workers are improving their tactics, but researchers say there are still ways to spot them before they do damage.DARKREADING.COM
26 AugDark Caracal Adds New Malware to Cyber Espionage ArsenalGoCaracal is a new modular malware framework that broadens Dark Caracal's capabilities to steal data and maintain access to victims.DARKREADING.COM
25 AugISC Stormcast For Tuesday, August 25th, 2026 https://isc.sans.edu/podcastdetail/10066, (Tue, Aug 25th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
25 AugThe State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic ExecutionExplore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
25 AugTaiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro StaffAI infrastructure, including advanced semiconductors mostly made in Taiwan, has become a key point of competition between the U.S. and China. The post Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff appeared first on SecurityWeek .SECURITYWEEK.COM
25 AugTruffleHog AWS Analyze reduces remediation time on leaked AWS credentialsTruffle Security announced TruffleHog AWS Analyze, a new addition to TruffleHog Enterprise. TruffleHog AWS Analyze enriches found AWS credentials to highlight permissions and access levels, so a security team can assess the risk and prioritize its response. TruffleHog Enterprise …HELPNETSECURITY.COM
25 AugNew TCG guidance gives buyers a way to test PQC-ready TPM claimsThe Trusted Computing Group has published requirements that spell out what a Trusted Platform Module has to do before anyone calls it quantum-safe. A TPM is the chip that holds a machine’s keys and records measurements of its firmware, so the platform can later prove it has…HELPNETSECURITY.COM
25 AugBlack Hat State of Security VendorsAndy Ellis has a roundup of the security vendors at Black Hat this year. Key Takeaways: We have entered into an AI world. While nearly half of booths didn’t directly mention AI or agents in their taglines, the effects of AI are everywhere. Multiple spaces (Identity, SaaS, A…SCHNEIER.COM
25 AugFake Minecraft Clients Deliver WeedHack Malware Despite Infrastructure TakedownA threat actor keeps spreading the WeedHack malware to Minecraft players despite its original infrastructure taken down in JulyINFOSECURITY-MAGAZINE.COM
25 AugFirst Malware Built Specifically for Car Head Units Fuels BotnetKaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices. The post First Malware Built Specifically for Car Head Units Fuels Botnet appeared first on SecurityWeek .SECURITYWEEK.COM
25 AugE4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware CommandsCybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE. While threat actors are known to abuse legitimate services to p…THEHACKERNEWS.COM
25 AugFirefox moves to adopt JPEG XL with safer Rust-based decoderMozilla is preparing to enable JPEG XL support in Firefox, bringing the modern image format closer to broad browser adoption alongside AVIF. The company says its implementation relies on a new Rust-based decoder designed to reduce security risks while supporting features such as …CYBERINSIDER.COM
25 AugDuckDuckGo finds one-third of AI users share secrets they hide from peopleA DuckDuckGo survey of nearly 2,000 US adults found that 32% of people who use AI chatbots have shared information they withheld from friends, relatives, colleagues, or medical professionals. The figure rises to 56% among respondents who describe themselves as AI enthusiasts. Duc…CYBERINSIDER.COM
25 AugFake OpenAI Codex download tricks macOS users into installing malwareA malware campaign using a sponsored search ad and a fake OpenAI Codex download page to trick macOS users into pasting a malicious command into Terminal has been uncovered by Cato Networks. It’s a variation of ClickFix, a popular social engineering technique that persuades …HELPNETSECURITY.COM
25 AugCitrix UniconOS dual boot turns Windows endpoints into their own recovery deviceCitrix announced Citrix UniconOS dual boot, a new endpoint resiliency capability designed to help organizations recover access to work in minutes — without spare hardware, central reimaging or prolonged business downtime. Available now as part of Citrix UniconOS Release 7 2607, d…HELPNETSECURITY.COM
25 AugFideo Lens reveals connections across identities, accounts and devicesFideo Intelligence introduced Fideo Lens, an investigative intelligence platform that helps fraud and financial crime teams discover hidden relationships among identities, accounts, devices and behaviors. Starting with a single identity signal, investigators can use Fideo Lens to…HELPNETSECURITY.COM
25 AugAI Agents Don't Respect Every BoundaryTraditional automation generally stops when a permission or policy blocks an action. An agentic system may instead interpret that restriction as an obstacle and search for another way forward. That changes the security model. An agent pursuing a legitimate goal could discover an …YOUTUBE.COM
25 AugInterpol targets Black Axe’s illicit financial web in latest international stingThe multi-country sting targeted Black Axe financial networks, seizing millions in assets and uncovering Crime-as-a-Service infrastructure across four continents. The post Interpol targets Black Axe’s illicit financial web in latest international sting appeared first on CyberScoo…CYBERSCOOP.COM
25 AugWhatsApp adds multiple passkeys and stronger two-step verificationWhatsApp is rolling out support for multiple passkeys, stronger two-step verification passwords, and additional information for calls from unknown numbers. The changes, announced today, are intended to make account authentication harder to compromise while giving users more conte…CYBERINSIDER.COM
25 AugAlice Raises $140M to Expand AI Model Defenses and Enterprise GuardrailsThe company, previously known as ActiveFence, has raised a total of $280 million from investors. The post Alice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails appeared first on SecurityWeek .SECURITYWEEK.COM
25 AugApple quietly fixes iCloud Private Relay IP leak in SafariApple has quietly fixed an iCloud Private Relay IP address leak in the public releases of iOS 26.6.1 and macOS 26.6.2. The fix appears limited to Safari, while other WebKit-based browsers using Apple’s proxy configuration APIs remain affected. Apple has not mentioned the ch…CYBERINSIDER.COM
25 AugMicrosoft Paint embeds hidden IDs in locally generated AI imagesMicrosoft Paint and Photos appear to embed an invisible, server-issued identifier into AI-generated images, including pictures created locally on Copilot+ PCs. Reverse engineering shows that while image generation can happen on-device, prompts are still sent to Microsoft for mode…CYBERINSIDER.COM
25 AugLinux Foundation to Govern TRACE, an Open Standard for AI Runtime AttestationTRACE was developed by AMD, Intel, Microsoft, OPAQUE, and TII and contributed to the Linux Foundation. The post Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation appeared first on SecurityWeek .SECURITYWEEK.COM
25 AugThe patch window is collapsing: Why security needs a new control planeOrganizations need protection that operates in the gap between discovery and remediation. The post The patch window is collapsing: Why security needs a new control plane appeared first on Microsoft Security Blog .AZURE.MICROSOFT.COM
25 AugArrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justiceJoshua Culver, aka “Maverick Young,” is accused of imitating the head of the NSA’s Tailored Access Operations unit during a time it wasn’t called that. The post Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice appeared first on CyberScoop .CYBERSCOOP.COM
25 AugWhat Regex Can't Catch in AI SkillsAgentic skills can be packaged as Markdown files containing natural-language instructions. Traditional software-supply-chain controls such as signing, provenance, and scanning can still apply. The harder problem is understanding intent. A conventional code scanner can search for …YOUTUBE.COM
25 AugThe GTA VI leaks are breaking the internet. Security researchers have seen this before.A memecoin, a manifesto, and a week of daily leaks — but to researchers, it's a familiar extortion playbook with an unusually large audience. The post The GTA VI leaks are breaking the internet. Security researchers have seen this before. appeared first on CyberScoop .CYBERSCOOP.COM
25 AugFibonacci, Hidden Sounds, Teams, Zimbra, Entra-ID, z.ai, Schrödinger's, Aaran Leyland - SWN #610Fibonacci and the Unhappy Number, Hidden Sounds, Teams, Zimbra, Entra-ID, z.ai, Schrödinger's battery, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-610YOUTUBE.COM
25 AugHackers abuse npm mirrors to host phishing redirect pagesThreat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites. [...]BLEEPINGCOMPUTER.COM
24 AugISC Stormcast For Monday, August 24th, 2026 https://isc.sans.edu/podcastdetail/10064, (Mon, Aug 24th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
24 AugAWS makes it easier to spot firewall rules that have gone quietAWS Network Firewall’s rule hit count capability gives security teams visibility into which stateful firewall rules are matching traffic, helping them identify unused or redundant rules and validate whether security controls are working as intended. The capability covers stateful…HELPNETSECURITY.COM
24 AugFake bank websites play dead to evade security scannersA phishing method, named Chameleon SEO Poisoning, that uses manipulated search results and cloaked fake banking websites to steal credentials while evading security scanners has been discovered by Fortra. The company’s threat intelligence unit, Fortra Intelligence and Resea…HELPNETSECURITY.COM
24 AugRisky Bulletin: Expired credit cards can be used for malicious transactionsExpired credit cards can be used for malicious transactions, Iranian hackers shut down a UK power plant, the Lazarus Group hacks South Korea’s Presidential Office, and an Android malware strain is infecting smart cars.RISKY.BIZ
24 AugProduct showcase: AI Paper Trail shows the privacy cost of talking to AIProton’s AI Paper Trail is a free tool designed to make the information accumulated across AI conversations easier to see. It analyzes exported ChatGPT or Claude conversation data and produces a personal privacy report showing what can be inferred from those conversations. Proton…HELPNETSECURITY.COM
24 AugDOUBLECUP's PNG Payload, (Mon, Aug 24th)New malware that uses steganography always gets my attention, but I was disappointed when I looked at the latest DOUBLECUP write-up . It doesn&#;x26;#;39;t use real steganography:
ISC.SANS.EDU
24 AugCan employees safely use AI agents? AI pentesting agent liabilities, and the news - ESW #473Interview with Rob Allen from Threatlocker Safely enabling agentic AI for Businesses OpenClaw was the wakeup call and businesses wanted to know how to block it. “Easy,” Rob Allen said, “it’s already blocked if you’re using Threatlocker.” Now that things have settled down a bit, t…YOUTUBE.COM
24 AugIran-Linked Hackers Shut Down UK Power Plant for Four DaysThe attack caused real-world operational disruption and raised concerns about the resilience of Britain’s distributed energy infrastructure and the potential for repeatable attacks. The post Iran-Linked Hackers Shut Down UK Power Plant for Four Days appeared first on SecurityWeek…SECURITYWEEK.COM
24 AugTikTok Reaches $400 Million Settlement With US Justice Department Over Children’s PrivacyTikTok will pay $300 million immediately and another $100 million after an order vacates an earlier consent decree against its predecessor company, Musical.ly. The post TikTok Reaches $400 Million Settlement With US Justice Department Over Children’s Privacy appeared first …SECURITYWEEK.COM
24 AugVenezuelan Gets Record Federal Prison Term for ATM JackpottingJuan Manuel Gouveia-Aguilera has been sentenced to 8 years in prison for his role in an ATM jackpotting scheme that caused millions in losses. The post Venezuelan Gets Record Federal Prison Term for ATM Jackpotting appeared first on SecurityWeek .SECURITYWEEK.COM
24 Aug91 Vulnerabilities Patched in Spring Application FrameworkMore than 200 vulnerabilities have been patched to date this year, compared to only 16 in 2025 and 22 in 2024. The post 91 Vulnerabilities Patched in Spring Application Framework appeared first on SecurityWeek .SECURITYWEEK.COM
24 AugOperation QUICSILVER Targets Myanmar Government and IT with QUICAgent BackdoorCybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent. The campaign, codenamed Operation QUICSILVER, has been found to target government and information technolo…THEHACKERNEWS.COM
24 AugHired for One Job, Judged on Another: The CISO’s Real ProblemThe skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. The post Hired for One Job, Judged on Another: The CISO’s Real Problem appeared first on SecurityWeek .SECURITYWEEK.COM
24 AugOne SSID To Rule Them AllTL;DR How we ended up here My colleague Adam Bromiley and I recently tripped over one of those ‘What!?’ findings. We could completely break an IT-OT segmentation without having to do … anything. We were on an OT-focused engagement, working out of a control ro…PENTESTPARTNERS.COM
24 AugWhat Happens When AI Polices AI?AI systems can potentially be used to monitor other AI systems, but that approach assumes the monitoring system will correctly identify problematic behavior. The argument here is that AI will inevitably make mistakes when making judgments about what is good, bad, or acceptable. B…YOUTUBE.COM
24 AugTikTok and ByteDance to pay $400 million to settle children’s privacy lawsuitTikTok, ByteDance, and affiliated companies have agreed to pay $400 million to settle a US Justice Department lawsuit alleging violations of federal children’s privacy law. The agreement resolves litigation brought in 2024 over TikTok’s handling of data belonging to users under 1…CYBERINSIDER.COM
24 AugMullvad overhauls Multihop with new automatic routing modesMullvad VPN has redesigned its Multihop feature with three operating modes intended to make multi-server VPN routing easier to use while avoiding connection failures caused by incompatible server settings. Announced today, the new system introduces When needed, Always, and Never …CYBERINSIDER.COM
24 AugReliaQuest Confirms ShinyHunters Hack, but Says Impact Was LimitedA ReliaQuest employee fell victim to a phishing attack and the hackers gained access to a dashboard. The post ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited appeared first on SecurityWeek .SECURITYWEEK.COM
24 AugBipartisan Senate bill aims to prepare energy sector for Q-DayUnder the bill, FERC would consider cyber threats from quantum computers and post-quantum cryptography in its reliability standards for the energy sector. The post Bipartisan Senate bill aims to prepare energy sector for Q-Day appeared first on CyberScoop .CYBERSCOOP.COM
24 AugTreasury sanctions alleged Iranian hackers as part of ‘economic D-Day’It’s a follow-up to an indictment the Justice Department unsealed last week against people affiliated with the Mabna Institute. The post Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’ appeared first on CyberScoop .CYBERSCOOP.COM
24 AugSCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rulesThe 6-3 decision dismisses one lawsuit brought by states, saying they have no standing to sue because the disputed sections “neither requires nor forbids anything of anyone outside the executive branch.” The post SCOTUS tosses one of two injunctions against Trump USPS mail-in bal…CYBERSCOOP.COM
24 AugFoul Language: WordlistLoader Disguises Malware as Ordinary TextClickFix-style threat campaigns are using a new trick to evade detection and deliver Amatera, an increasingly prevalent infostealer.DARKREADING.COM
22 AugA RAT in the spreadsheet.Today we are joined by Aaron Beardslee, Manager of Threat Research at Securonix, discussing "Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation." Securonix researchers have identified an evolved version of the SHEETCREEP espionage campaign, using …THECYBERWIRE.COM
22 AugBanking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the SpotlightThe spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware. The post Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight appeared first on SecurityWeek .SECURITYWEEK.COM
22 AugWe Hate Surveillance Until We Need ItModern life is surrounded by cameras and sensors, from dash cams and traffic cameras to phones and home security systems. People often dislike being surveilled, but that attitude can change quickly when footage could identify someone responsible for an accident or crime. Surveill…YOUTUBE.COM
21 AugSuspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack AccountsThree distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks wit…THEHACKERNEWS.COM
21 AugISC Stormcast For Friday, August 21st, 2026 https://isc.sans.edu/podcastdetail/10062, (Fri, Aug 21st)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
21 AugGitLab 19.3 helps enterprises scale agentic development securelyGitLab has announced updates that give enterprises more control as they scale agentic software development. GitLab Dedicated customers, who already run their most sensitive software delivery workloads on GitLab, can now run GitLab Duo Agent Platform inside that same single tenant…HELPNETSECURITY.COM
21 AugContractors’ CMMC Confidence Rises as Ability to Prove It Falls BehindTwo industry surveys released this week by Kiteworks and CyberSheath paint a consistent picture of the defense industrial base. The post Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind appeared first on SecurityWeek .SECURITYWEEK.COM
21 AugNew SynkLoader malware uses fake Windows lock screen to steal passwordsA new malware family dubbed SynkLoader uses a fake Windows lock screen to steal users’ login passwords before giving attackers remote access to corporate networks. The modular malware combines Python, PowerShell, C#, and C++ components, with many payloads executed only in memory …CYBERINSIDER.COM
21 AugAlibaba spotted using WebAudio fingerprinting for user trackingAlibaba is facing scrutiny over its use of WebAudio fingerprinting, a browser-tracking technique that can help distinguish users by measuring subtle differences in how their devices process audio. The technique attracted attention after fingerprinting code running on Alibaba repo…CYBERINSIDER.COM
21 AugRust Supply Chain Attack Linked to North Korean HackersHackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server. The post Rust Supply Chain Attack Linked to North Korean Hackers appeared first on SecurityWeek .SECURITYWEEK.COM
21 AugHackers abuse FTP server banners to deliver new Windows malwareThreat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE. [...]BLEEPINGCOMPUTER.COM
21 AugDEFCON 34: Planes, PLCs and 6am runsTL;DR A perfectly normal amount of luggage On Tuesday 4th August, 5 brave souls set off to the faraway climes of Nevada, bound for DEF CON 34. We had 9 cases of tech with us, a motley assortment of flight simulators, industrial control CTFs and plenty more.&…PENTESTPARTNERS.COM
21 AugFake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage TacticsGoogle tracks three Russia-linked espionage clusters using phishing and legitimate authentication tools to target researchers, diplomats and defense staff. Google’s Threat Intelligence Group tracked three separate suspected Russia-linked cyber espionage clusters. All three …SECURITYAFFAIRS.COM
21 AugPagers Can Still Leak Patient DataPagers are still used in healthcare, and the clip describes patient information being transmitted over a pager network. The network was described as unencrypted and operating as a broadcast medium. Legacy technology can create security exposure when organizations assume that some…YOUTUBE.COM
21 AugEncrypted Prompts Bypass AI Safety Guardrails in Grok and GeminiResearchers say the new ‘Cryptographic Context Injection’ technique conceals malicious instructions until they are decrypted inside a trusted execution environment. The post Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini appeared first on SecurityWeek .SECURITYWEEK.COM
21 AugNew Phishing Toolkit Uses Passkeys to Maintain Access After Password ResetsResearchers say iAuthFlow V2 can register an attacker-controlled passkey, enabling persistent access even after passwords are changed and active sessions revoked. The post New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets appeared first on SecurityWeek .SECURITYWEEK.COM
21 AugLawmakers seek watchdog review of federal hacking of AmericansSen. Ron Wyden and Rep. Greg Casar want a GAO probe on the government’s use of spyware and other sophisticated hacking tools and authorities. The post Lawmakers seek watchdog review of federal hacking of Americans appeared first on CyberScoop .CYBERSCOOP.COM
21 AugDefense contractors’ CMMC confidence lags, even as self-assessments improveA “confidence disconnect” is plaguing the industry, a consulting firm said.CYBERSECURITYDIVE.COM
21 AugAI Is Learning to Write Genetic CodeThis sort of research is both exciting and terrifying: The two models in question were told to generate complete genomes for a viable bacteriophage—a type of virus able to infect and replicate itself inside bacteria, destroying them from the inside. Using an existing bacter…SCHNEIER.COM
21 AugFriday Squid Blogging: Neon Flying SquidThe neon flying squid can fly in formation. The shoal of about 100 squid rose unexpectedly from a patch of the Pacific Ocean around 370 miles from Tokyo and glided near the boat for about 30 metres. The astonished researchers were the first to capture photographs of such a thing,…SCHNEIER.COM
21 AugSurveillance, Murder Hornets, Portmantau, TrueCONF, Siemens, N-Able and More - SWN #609Surveillance, Murder Hornets, Portmantau, TrueCONF, Siemens, N-Able, Robo-Tips, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-609YOUTUBE.COM
21 AugWhen AI Attacks Critical InfrastructureAI-assisted automated attacks can be fast and effective, creating new challenges for infrastructure operators. Much of the critical infrastructure people depend on may also operate with limited budgets, aging technology, and significant operational constraints. The danger isn't j…YOUTUBE.COM
21 AugConnecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply ChainAttackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls The post Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain appeared f…UNIT42.PALOALTONETWORKS.COM
20 AugISC Stormcast For Thursday, August 20th, 2026 https://isc.sans.edu/podcastdetail/10060, (Thu, Aug 20th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
20 AugResearchers find a loophole that lets expired credit cards make unauthorized paymentsA team from the University of Massachusetts Amherst has shown that a contactless credit card keeps working past its printed expiration date, even after the cardholder gets a replacement. They named it the Zombie Card attack and presented the findings at USENIX Security 2026. The …HELPNETSECURITY.COM
20 AugTufin expands Unified Control Plane with AI intelligence and multi-vendor automationTufin has announced the availability of Tufin Orchestration Suite (TOS) 5.3, helping enterprises further simplify security operations and maintain consistent control across increasingly complex multi-vendor, hybrid environments. As enterprise security environments continue to exp…HELPNETSECURITY.COM
20 AugUS charges 17 Iranian hackers over 31-terabyte academic data theftThe U.S. has charged 17 alleged members of Mabna Institute, an Iranian hacking-for-hire company accused of running a years-long campaign that stole data from American universities, companies, and government agencies. The post US charges 17 Iranian hackers over 31-terabyte academi…HELPNETSECURITY.COM
20 AugUS Indicts 17 Iranians Over Years-Long Cyber Espionage CampaignThe US charged 17 Iranians over a years-long hacking campaign that stole 31TB from universities, companies and government agencies worldwide. Eight years after the original indictment first went public, US prosecutors just added eight more names to the list. The Justice Departmen…SECURITYAFFAIRS.COM
20 AugPolice Are Hiding Their Use of Flock Surveillance CamerasA usage policy for Flock license plate reader cameras tells police not to talk about the cameras: When cops use Flock to arrest someone in Wapello County, Iowa, they don’t want them to know. A usage policy for the automated license plate reader cameras in the county tells p…SCHNEIER.COM
20 AugOpenAI previews privacy-focused system for detecting AI misuseOpenAI is previewing Private Safety Processing with early customers seeking greater certainty about how their data will be protected as AI systems become more capable. The system identifies patterns across related interactions while restricting OpenAI personnel from accessing the…HELPNETSECURITY.COM
20 Aug40 malicious Firefox extensions caught stealing crypto wallet dataSocket researchers have uncovered a network of 77 Firefox extensions tied to cryptocurrency wallet theft, credential harvesting, and deceptive software distribution. Of those, 40 were confirmed malicious, while another 37 disguised sports-score applications as unrelated browser u…CYBERINSIDER.COM
20 AugCorero brings cloud-based AI threat analysis to SmartWall ONECorero Network Security has announced AI-Augmented Cloud-Assist for SmartWall ONE, extending its automated DDoS protection with cloud-delivered AI analysis, threat intelligence, and policy optimization. As cybercriminals increasingly leverage AI to develop and evolve attack campa…HELPNETSECURITY.COM
20 AugThreat Actor Hacks 14,000 IP Cameras in Ukraine and RussiaOperation CameraSwarm targeted Dahua cameras across multiple countries, focusing on Russian and CIS telecom netblocks. The post Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugSurveillance – Everything You Wanted to Know, But Were Afraid to AskWe all know they’re watching us. But we don’t know who they are, nor why nor how they are doing it. The post Surveillance – Everything You Wanted to Know, But Were Afraid to Ask appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugRetail theft bill spurs ‘very large and very dangerous’ surveillance fearsThe Combating Organized Retail Crime Act has won a big House vote and could be on the fast track in the Senate — and supporters say it could help fight cybercrime. The post Retail theft bill spurs ‘very large and very dangerous’ surveillance fears appeared first on CyberScoop .CYBERSCOOP.COM
20 Aug‘Unprecedented’ Number of Apple Users Received Recent Spyware AlertApple customers in 110 countries received threat notifications recently alerting them to suspected spyware attacks targeting their devices. The post ‘Unprecedented’ Number of Apple Users Received Recent Spyware Alert appeared first on The Citizen Lab .CITIZENLAB.CA
20 AugEarly 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremistKyle Spitze led an offshoot of the violent extremist collective and victimized dozens of girls, coercing them to degrade themselves under threats of doxing and swatting. The post Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremis…CYBERSCOOP.COM
20 AugRussian hackers abuse WhatsApp device linking to spy on high-value targetsThree suspected Russian cyber-espionage clusters are abusing legitimate authentication features across WhatsApp, Google, and Microsoft to compromise academics, diplomats, defense personnel, researchers, and government-linked individuals. One cluster, tracked as UNC7005, has gone …CYBERINSIDER.COM
20 AugChina’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malwareSuspected military-grade hackers based in China used artificial intelligence to develop malware in a campaign to penetrate Central Asian governments.THERECORD.MEDIA
20 AugWhen Security Benchmarks Break SystemsSecurity benchmarks such as CIS Benchmarks and STIGs provide detailed recommendations for configuring systems securely. But applying every control literally can create problems, especially when those settings conflict with how a particular environment needs to operate. A benchmar…YOUTUBE.COM
19 AugChina-Linked Hacker Shows AI Capabilities in APAC AttackIn the first purported "near-autonomous" attack on a nation-state, a Chinese-language operator used a complex AI framework to target and compromise government agencies, likely in Taiwan.DARKREADING.COM
19 AugISC Stormcast For Wednesday, August 19th, 2026 https://isc.sans.edu/podcastdetail/10058, (Wed, Aug 19th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
19 AugBrinqa acquires PlexTrac to bring validated remediation to exposure managementBrinqa has announced its acquisition of PlexTra, adding the ability to verify that remediation efforts have actually worked. The combined capabilities uniquely position Brinqa to identify and prioritize the exposures that matter most, drive remediation, and validate that fixes ho…HELPNETSECURITY.COM
19 AugEurope is creating a common security standard for VPN servicesEuropean standards body ETSI has begun the approval process for a new cybersecurity standard for VPN products, part of a wider package of 17 standards designed to support the EU Cyber Resilience Act (CRA). The VPN standard, EN 304 620, introduces defined technical and privacy req…CYBERINSIDER.COM
19 AugPrevalent AI Raises $22 Million to Expand Data Fabric PlatformThe previously bootstrapped company helps organizations securely and reliably operate AI agents at scale. The post Prevalent AI Raises $22 Million to Expand Data Fabric Platform appeared first on SecurityWeek .SECURITYWEEK.COM
19 AugUS Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of ThemThe 17 members of the Mabna Institute targeted hundreds of universities and organizations in the US and abroad. The post US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them appeared first on SecurityWeek .SECURITYWEEK.COM
19 AugSilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATsA previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. The intrusion set makes use of seven remote access tool (RAT) families, five of which have never been previously documented: DriveSilkRAT, CookiETa…THEHACKERNEWS.COM
19 AugVirtual Event Today: CodeSecCon – Secure Your Code and ApplicationsCodeSecCon is the premier virtual event bringing together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained. The post Virtual Event Today: CodeSecCon – Secure Your Code and Applications appeared first on Secu…SECURITYWEEK.COM
19 AugIntezer adds native response automation without separate SOARIntezer has announced Workflows, a native automation and response builder that enables security teams to create and customize response workflows directly inside the Intezer platform. Workflows brings response into the same platform where alerts are triaged and investigated, allow…HELPNETSECURITY.COM
19 AugUS charges Iranian hackers over $3.4 billion intellectual property theftThe U.S. has charged 17 Iranians, alleged members of a hacking-for-hire company called Mabna Institute, involved in years-long operations that stole data from American organizations. [...]BLEEPINGCOMPUTER.COM
19 AugSilkParasite Threatens Central Asian Orgs With Flurry of RATsA spear-phishing campaign by a Chinese-nexus group linked to FamousSparrow provides insight into geopolitical, technical, and strategic global moves by China's APTs.DARKREADING.COM
19 AugAI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warnThe agencies said the hackers are taking aim at Siemens S7 Series programmable logic controllers in what could be a first. The post AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn appeared first on CyberScoop .CYBERSCOOP.COM
19 AugMicrosoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026Microsoft is named a visionary leader in the 2026 Frost Radar for Cloud Workload Protection Platforms, recognized for unified runtime security with Microsoft Defender for Cloud. The post Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026 appea…MICROSOFT.COM
18 AugISC Stormcast For Tuesday, August 18th, 2026 https://isc.sans.edu/podcastdetail/10056, (Tue, Aug 18th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
18 AugA hollowed out data layer is making CISOs fly blind into AI attacksThe security industry is currently transitioning to an era where both offense and defense are AI-led, and every SOC operates at machine speed. However, what most CISOs have not yet reckoned with is that the AI defenders they are about to deploy will inherit a data foundation that…HELPNETSECURITY.COM
18 AugSynthesized builds Test Data Agent to validate AI agents with production-like dataSynthesized has announced its Test Data Agent, a new agentic infrastructure capability being developed to create and provision the realistic data, business context, and system states enterprises need to validate AI agents safely before production deployment. The Test Data Agent i…HELPNETSECURITY.COM
18 AugHacker claims millions of records stolen from corporate Azure tenantsA threat actor known as “TheHatman” claims to have obtained millions of employee records from the Azure environments of several Fortune 500 companies, including McDonald’s, Vodafone, Kyndryl, and Tata Consultancy Services (TCS), according to Hudson Rock. Over th…HELPNETSECURITY.COM
18 AugLLMs and Contextual IntegrityI have been thinking a lot about AI and integrity. Part of that is contextual integrity. I recently found two papers on the topic. “ CIMemories: A Compositional Benchmark for Contextual Integrity of Persistent Memory in LLMs “: Abstract: Large Language Models (LLMs) i…SCHNEIER.COM
18 AugXpander Raises $7.5 Million for AI Management and GovernanceXpander’s platform uses a universal agent harness that executes AI agents as portable workloads and securely renders interfaces on demand. The post Xpander Raises $7.5 Million for AI Management and Governance appeared first on SecurityWeek .SECURITYWEEK.COM
18 AugFortinet Acquires AI Security Company Virtue AIFortinet will use Virtue AI technology to enhance its AI security portfolio, including for AI models, applications, and agentic systems. The post Fortinet Acquires AI Security Company Virtue AI appeared first on SecurityWeek .SECURITYWEEK.COM
18 AugAI Shouldn’t Escalate Threats AloneAI agents can generate rules, query a data lake, hunt for evidence, and reach a conclusion about whether a threat is real. But the final escalation decision stays with a human. That human checkpoint helps catch false evidence and false alarms before an automated system turns an u…YOUTUBE.COM
18 AugWebinar Today: Rethinking Cyber Defense for AI-Speed AttacksJoin the live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. The post Webinar Today: Rethinking Cyber Defense for AI-Speed Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
18 AugCISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOWWith no formal training and no career plan, Waisman built a path from Argentina's early hacking scene to leading security at an AI-powered offensive security firm. The post CISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW appeared…SECURITYWEEK.COM
18 AugGitLab issues emergency patch for critical code-injection flawResearchers warn that unauthenticated attackers would be able to delete or modify publicly accessible projects.CYBERSECURITYDIVE.COM
18 AugHunting MacSync Stealer infrastructure through behavioral pivotsMacSync Stealer rapidly rotates domains to evade detection, but its behavior remains consistent. Learn how Microsoft uncovered 30+ related domains using durable hunting pivots. The post Hunting MacSync Stealer infrastructure through behavioral pivots appeared first on Microsoft S…MICROSOFT.COM
18 AugEight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna InstituteThe superseding indictment adds defendants and allegations against the Iranian firm accused of a massive cybertheft campaign against foreign universities and others. The post Eight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna Institute a…CYBERSCOOP.COM
18 AugOpenAI slows model development over concerns about cyber capabilitiesOpenAI has temporarily slowed the development and scaling of its frontier AI models after determining that its existing monitoring, alignment, and security measures needed to be strengthened as models become increasingly capable of conducting cybersecurity tasks. The company said…CYBERINSIDER.COM
18 AugSecrets, Red Agent, GitHub, evoooo1bot, DecryptAds, Copilot, Aaran Leyland, and More - SWN #608The Secret Word is Meow, Red Agent, GitHub, evoooo1bot, Hatman, DecryptAds, Copilot, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-608YOUTUBE.COM
18 AugDOJ charges 17 people in Iran-backed hacking campaign against USOfficials allege an IRGC-linked organization was behind a coordinated effort to steal research from American universities, companies and government agencies.CYBERSECURITYDIVE.COM
18 AugCopilot Was Tricked Into Leaking PasswordsResearchers demonstrated a technique that manipulated Microsoft Copilot into accessing sensitive information, including passwords and credentials stored in a user's inbox. The technique used undocumented parameters and prompt injection, with a webhook allowing information to be s…YOUTUBE.COM
17 AugISC Stormcast For Monday, August 17th, 2026 https://isc.sans.edu/podcastdetail/10054, (Mon, Aug 17th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
17 AugWhen companies get specific about AI, revenue growth looks differentCompanies that provide specific evidence of how they use AI tend to record stronger revenue growth. Researchers at Carnegie Mellon University and Larridin examined a study universe of 564 companies across 12 industry sectors. Individual analyses used smaller samples depending on …HELPNETSECURITY.COM
17 AugProduct showcase: ScamNet looks for warning signs in suspicious calls and shady linksScamNet: Anti-Scam Suite is a consumer security app from Synaptrex Technologies that helps users detect and block scams involving phone calls, text messages, websites, and other suspicious content. The app is available for iPhone, iPad, and Mac, with features varying by platform.…HELPNETSECURITY.COM
17 AugWindows 11’s strongest security defenses can be bypassed without a screwdriverResearchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assumes the attacker has already gained privileged access to th…HELPNETSECURITY.COM
17 AugHacking Public Wi-Fi DNS to Steal CredentialsCriminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.SCHNEIER.COM
17 AugProton’s AI Paper Trail reveals how much ChatGPT and Claude know about usersProton has launched a free tool that shows users how much personal information ChatGPT and Claude may reveal through their conversation histories, highlighting the privacy risks of repeatedly sharing sensitive information with AI chatbots. Called AI Paper Trail, the tool analyzes…CYBERINSIDER.COM
17 AugConflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating MalwareAnthropic has been conducting tests to identify issues in how AI agents interact with each other. The post Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware appeared first on SecurityWeek .SECURITYWEEK.COM
17 AugFortinet expands AI security portfolio with Virtue AI acquisitionFortinet has acquired Virtue AI, strengthening its broader Security for AI strategy and its vision for securing the agentic enterprise. The acquisition builds on Fortinet’s existing AI security portfolio, which includes the FortiGate Hyperscale Firewall. As organizations deploy A…HELPNETSECURITY.COM
17 AugApple Screen Sharing Security, (Mon, Aug 17th)About 20 years ago, with macOS 10.5 (Leopard), Apple introduced screen sharing. Apple did not invent a new protocol for screen sharing. Instead, it used the established VNC protocol. VNC is a pretty simple, unencrypted protocol using TCP port 5900. Historically, the protocol used…ISC.SANS.EDU
17 AugCall for Applications: Information Controls Research Program 2026The Information Controls Research Program (ICRP) (formerly known as the “Information Controls Fellowship Program) from the Open Technology Fund (OTF) supports applied research into how authoritarian governments in the most repressive information environments are restricting the f…CITIZENLAB.CA
17 AugCavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate TrafficCybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian cybersecurity company Kaspersky said its ongoing monitoring of the thr…THEHACKERNEWS.COM
17 AugThe EU CRA Clock is Ticking:Are You Compliant?The post The EU CRA Clock is Ticking:Are You Compliant? appeared first on Eclypsium | Supply Chain Security for the Modern Enterprise .ECLYPSIUM.COM
16 AugAPT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2Acronis uncovered PATCHCORD, a stealthy backdoor targeting Afghan telecom and South Asian infrastructure via fake VPN tools and Google Sheets C2. Researchers at Acronis just documented an espionage operation that reads like it was built by someone with genuinely good taste in dis…SECURITYAFFAIRS.COM
16 AugWireshark 4.6.8 Released, (Sun, Aug 16th)Wireshark release 4.6.8 fixes 28 vulnerabilities and 25 bugs.
ISC.SANS.EDU
14 AugISC Stormcast For Friday, August 14th, 2026 https://isc.sans.edu/podcastdetail/10052, (Fri, Aug 14th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
14 Aug17 draft Cyber Resilience Act standards are open for commentA company selling a connected toy in Europe must show by the end of 2027 that the product meets the Cyber Resilience Act. The law states what manufacturers have to achieve and stops there, which leaves the toymaker to work out the technical detail alone. Seventeen draft standards…HELPNETSECURITY.COM
14 AugThe hardest part of agentic AI may be rebuilding the businessOrganizations expect AI agents to change how work gets done, driving productivity and growth while allowing employees to focus on higher-value tasks. Few, however, have the processes and workflows needed to realize those benefits, according to Deloitte’s latest research. Preparin…HELPNETSECURITY.COM
14 AugAmnesiaStealer macOS Malware Steals Data, Controls Browser SessionsThe Rust-based macOS infostealer harvests users’ passwords, keychain information, Chromium-based browser data, and Safari cookies. The post AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions appeared first on SecurityWeek .SECURITYWEEK.COM
14 AugResearchers Link 'Jewelbug' Chinese APT to Hack-for-Hire OperationsThreat intelligence researchers from Broadcom revealed that a known Chinese APT group may be linked to a lucrative crypto fraud operationINFOSECURITY-MAGAZINE.COM
14 AugAPT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkitOur experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.SECURELIST.COM
14 AugAWS Certificate Manager sets 2027 end date for email-validated certificate renewalsAWS Certificate Manager (ACM) will phase out email validation for public certificates throughout 2027, ahead of the Certification Authority/Browser (CA/B) Forum’s March 15, 2028 deadline for ending email-based domain validation. The CA/B Forum sets standards that browsers and cer…HELPNETSECURITY.COM
14 AugGoogle Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness GoalGoogle Cloud outlines its roadmap to full post-quantum cryptography readiness, with key milestones targeted for 2027 and 2028. The post Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal appeared first on SecurityWeek .SECURITYWEEK.COM
14 AugOpenAI’s GPT-5.6 Sol runs up to 14× faster with Ultrafast modeOpenAI’s GPT-5.6 Sol on Ultrafast mode is available in limited preview to a select group of customers, launching first through the OpenAI API. The company says the service runs up to 14 times faster than Standard processing and generates up to 750 output tokens per second. Ultraf…HELPNETSECURITY.COM
14 AugIf the Markets Reject OpenAI and Anthropic, the US Should Nationalize ThemThis essay was written with Nathan E. Sanders, and originally appeared in The Guardian . OpenAI, and then Anthropic , were each formed by AI developers who feared unrestrained corporate AI development—specifically, that companies like Google and Meta would steer the technol…SCHNEIER.COM
14 AugTrivy, Not LiteLLM Behind the 2,500 Org CompromiseOver 95% of the affected companies were exposed before the malicious LiteLLM packages were published. The post Trivy, Not LiteLLM Behind the 2,500 Org Compromise appeared first on SecurityWeek .SECURITYWEEK.COM
14 AugDEF CON Gave Hackers Sticker WallsThe DEF CON sticker game has gotten seriously creative. According to Joshua Marpet, the conference has also spent substantial amounts cleaning stickers off venue surfaces in past years. So DEF CON changed tactics: instead of fighting the sticker chaos, they created giant designat…YOUTUBE.COM
14 AugUpcoming Speaking EngagementsThis is a current list of where and when I am scheduled to speak: I’m speaking, signing books, and participating in panel discussions at LAcon V in Anaheim, California, USA. My full schedule is here . I’m speaking online (via Zoom) at a League of Women Voters event on Tuesd…SCHNEIER.COM
14 AugFriday Squid Blogging: Searching for the Colossal SquidFascinating video about searching for life undersea. The video basically makes the point that our bright white searchlights are scaring everything away, and that red light is more neutral. That, plus bait to attract sea creatures, is teaching us a lot about what’s going on …SCHNEIER.COM
14 AugMathematicians, Lazarus, Akira, Computer History, Zoom, LiteLLM, Josh Marpet and More - SWN #607Famous Mathematician feuds, Delta Flight 591, Lazarus, Akira, Computer History, Zoom, Clones, LiteLLM, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/s…YOUTUBE.COM
13 AugISC Stormcast For Thursday, August 13th, 2026 https://isc.sans.edu/podcastdetail/10050, (Thu, Aug 13th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
13 AugUsing Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI, (Wed, Aug 12th)In the past few weeks, I have been using Gemma4 as a Large Language Model (LLM) to see how useful it can be to analyze some of the malware hashes uploaded to the DShield sensor over the past 30 days and figure out how its recommendation can be considered useful about the activity…ISC.SANS.EDU
13 AugProduct showcase: Is this image real? Slop or Not investigatesSlop or Not is an AI text and image detector for iPhone and Mac that runs entirely offline, with no account required. It uses on-device AI models powered by the Apple Neural Engine to detect AI-generated content. According to a recent survey, 85% of people say they struggle to di…HELPNETSECURITY.COM
13 AugWireshark 4.6.8 patches 28 security bugs, nine in file parsersWireshark 4.6.8 fixes 28 security bugs in the protocol analyzer, and nine of them fire when someone opens a saved capture file. Those nine sit in file parsers, the code that reads a capture off disk before any dissection begins: pcapng, Endace ERF, Tektronix K12xx, BUSMASTER, Cat…HELPNETSECURITY.COM
13 AugFour corporate investigation mistakes organizations make under pressureIn this Help Net Security video, Christine Gadsby, VP and Chief Security Advisor at BlackBerry, explains why corporate investigations go wrong before the forensic team arrives. The first hours matter more than leaders assume. Access gets granted, conversations start, and decision…HELPNETSECURITY.COM
13 AugArmored Likho expands its cyber-espionage toolkitKaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.SECURELIST.COM
13 AugWhite House Mobilizes Security Firms for Operations Against Foreign Cybercrime GangsContracts may require a $1 million bond, which will be forfeited if a company fails to comply with operational requirements. The post White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs appeared first on SecurityWeek .SECURITYWEEK.COM
13 Aug'Jewelbug' APT Balances State Espionage & Cryptocurrency TheftResearchers discovered hackers-for-hire performing cyber espionage and financially motivated heists from the same Web panel.DARKREADING.COM
13 AugProton VPN is replacing wireguard-go with a new Rust VPN coreProton VPN has developed a new Rust-based client architecture, internally called ProTUN, to provide a common WireGuard implementation across its desktop and mobile applications and give its engineers greater control over anti-censorship features. Proton engineer Antonio Cesarano …CYBERINSIDER.COM
13 AugWhatsApp adds on-device scam detection without sending chats to MetaMeta has unveiled an early version of Scam Alert, an optional WhatsApp security feature that uses an on-device machine learning model to identify messages that may be part of a scam. The company says message content remains on the user’s phone during classification and is n…CYBERINSIDER.COM
13 AugFortinet Patches Authentication Flaws in FortiWeb and FortiManagerThe vulnerabilities could allow attackers to log in with random usernames and passwords or impersonate any FortiGate appliance. The post Fortinet Patches Authentication Flaws in FortiWeb and FortiManager appeared first on SecurityWeek .SECURITYWEEK.COM
13 AugSeparating AI’s Technological Problems from Its Capitalism ProblemsThis essay was written with Nathan E. Sanders, and originally appeared in Tech Policy Press . AI represents the first time we humans can do cognitive work outside of our bodies at scale. The only comparable moment is the early years of the industrial revolution, when new technolo…SCHNEIER.COM
13 AugVenture Firm Team8 Secures Additional $365 MillionThe Israeli company has nearly $2 billion in total assets under management since 2014. The post Venture Firm Team8 Secures Additional $365 Million appeared first on SecurityWeek .SECURITYWEEK.COM
13 AugDataGrout helps enterprises control AI usage, governance and LLM costsSelectHub has announced the launch of DataGrout, its specialized AI research lab introducing an LLM inference optimization platform and AI governance solution for enterprises. DataGrout’s mission is to drive token reduction for agentic workflows, chatbots and AI tools, while equi…HELPNETSECURITY.COM
13 AugA10 Networks introduces AI Gateway to secure and manage enterprise AIA10 Networks has announced the general availability of the A10 AI Gateway, a centralized, intelligent control plane that gives organizations unified routing, cost management, and governance across every AI agent, application and large language model (LLM) they use. As AI adoption…HELPNETSECURITY.COM
13 AugTemporary AWS Holes Become PermanentOpening an AWS security group for convenience can create unintended exposure. A common example is allowing access to a database without going through a bastion host, or temporarily opening access while working remotely. The word “temporary” doesn't make an overly broad rule safe.…YOUTUBE.COM
13 AugCybersecurity M&A Roundup: 21 Deals Announced in July 2026Significant cybersecurity M&A deals announced by Barracuda, CrowdStrike, Cyera, Okta, Palo Alto Networks, and Qualcomm. The post Cybersecurity M&A Roundup: 21 Deals Announced in July 2026 appeared first on SecurityWeek .SECURITYWEEK.COM
13 AugWhite House authorizes private US companies to hack foreign criminal networksPresident Trump signed a National Security Presidential Memorandum on August 12 allowing vetted private companies to run offensive cyber operations against foreign threat actors, under the control and oversight of the US government. The post White House authorizes private US comp…HELPNETSECURITY.COM
13 AugResearchers find AI-powered hacking tools for sale in underground forumsA report shows how criminal actors are lowering the barriers to entry with sophisticated services, without ethical constraints.CYBERSECURITYDIVE.COM
13 AugUS government will let private companies hack criminal gangsThe new program, meant to aggressively disrupt costly cybercrime schemes, carries numerous legal and security risks.CYBERSECURITYDIVE.COM
13 AugBTS #80 - Exploring BMC VulnerabilitiesIn episode 80 of Below the Surface, Paul Asadoorian is joined by Chase Snyder and Vlad Babkin for a wide-ranging conversation about the infrastructure risks that remain easy to overlook until attackers start using them. The episode begins with a brief reflection on Black Hat USA …ECLYPSIUM.COM
13 AugAnthropic set AI agents loose on the same task. They started a turf war.Anthropic researchers found AI agents can clash, collude and coordinate in unexpected ways, raising new questions about whether today’s safety tests capture the risks of multi-agent systems.TECHCRUNCH.COM
13 AugBrave browser adds new defenses against GPU fingerprintingBrave is rolling out new protections to reduce browser fingerprinting through WebGL and WebGPU, two APIs that can expose detailed information about a device’s graphics hardware and drivers. The protections are enabled by default on desktop and Android and are being introduc…CYBERINSIDER.COM
13 AugTech contractor for Brightly Software sentenced to 2 years in prison for insider attackCameron Curry stole corporate data and employee information, which he used to threaten the company as his six-month contract gig came to a close. He ultimately extorted the company for $7,540.92. The post Tech contractor for Brightly Software sentenced to 2 years in prison for in…CYBERSCOOP.COM
13 AugA bold new strategy or a dangerous precedent? Experts are divided on Trump’s memo.The “philosophical shift” that the memo authorizes raises legal, practical and moral questions, experts say. The post A bold new strategy or a dangerous precedent? Experts are divided on Trump’s memo. appeared first on CyberScoop .CYBERSCOOP.COM
12 AugKimwolf botnet rebuilt to survive takedowns, researchers sayMonths after police seized its servers and arrested an alleged operator, the Kimwolf botnet is running code that disguises attacks as Chrome traffic and fetches its orders from the Ethereum blockchain. The post Kimwolf botnet rebuilt to survive takedowns, researchers say appeared…CYBERSCOOP.COM
12 AugISC Stormcast For Wednesday, August 12th, 2026 https://isc.sans.edu/podcastdetail/10048, (Wed, Aug 12th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
12 AugRisky Bulletin: Russian hackers jump on the fake job interview trainRussian state hackers adopt fake job interview tactics, a Portuguese man will face trial for developing a malicious AI chatbot, an AI assistant hacks an Australian gym, and OpenAI releases cyber models for blue teams.RISKY.BIZ
12 Aug338 million attack simulations reveal the state of enterprise defenseFirst, a bit of good news: Enterprise defenses are recovering. However, it’s a narrow recovery, with a twist. Today, organizations are better at stopping loud attacks but have barely moved the needle at all against the quiet ones. This data, and a lot more, comes straight from th…HELPNETSECURITY.COM
12 AugReady-made $500 kit puts a crypto scam within anyone’s reachA seller on a cybercrime forum is offering a ready-made scam kit for $500, complete with an admin panel that tracks victims, checks their crypto wallets for value, and inflates fake balances to squeeze out more money, Malwarebytes found. Researchers discovered the scam project on…HELPNETSECURITY.COM
12 AugPost-quantum migration gets harder when every user holds a keyIn this Help Net Security interview, Christopher Smith, CEO of Quantus, discusses what cryptographic inventories turn up in banks and hospitals, including default passwords and admin keys still held by former employees. He explains where post-quantum key sizes break old size assu…HELPNETSECURITY.COM
12 AugShifts We Are Seeing Across Social Engineering, Post-Disruption Impact ReportIn this episode of the Microsoft Threat Intelligence Podcast, Microsoft Threat Intelligence Director Elliot Volkman is joined by Microsoft Principal Threat Intelligence Analyst Crane Hassold to explore how phishing and social engineering attacks are changing beyond email. They d…THECYBERWIRE.COM
12 AugSonicWall Patches Critical Vulnerabilities in Discontinued GMS PlatformThe security defects could allow unauthenticated attackers to execute arbitrary code remotely and read sensitive data. The post SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugSplit-second deepfake glitch blows digital certificate fraudster’s coverSpanish police have arrested a man in Murcia accused of using deepfake software to trick a certificate provider’s video identity checks in an attempt to obtain digital signatures he could use for financial fraud. According to the police, the man made 38 attempts using this …HELPNETSECURITY.COM
12 AugMalicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ OrganizationsTwo malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them. Threat intelligence firm CloudSEK now …THEHACKERNEWS.COM
12 AugConnectSecure helps MSPs automate Microsoft 365 security remediationConnectSecure has announced that Microsoft 365 Auto Remediation and AI-powered Training Assessments are now live on the ConnectSecure platform. The capabilities help managed service providers (MSPs) address supported M365 security findings, create and measure assessments, support…HELPNETSECURITY.COM
12 AugPrompt Injections for DefenseThis seems to work : Researchers from Tracebit on Monday said they found that placing prompt injections alongside passwords, cryptographic keys, and other secrets stored on Amazon Web Services was often all that was needed to shut down attacks from AI hacking agents. The prompts …SCHNEIER.COM
12 AugSignal adds auto key verification to detect encryption key tamperingSignal has introduced automatic key verification, a new security feature designed to detect attempts to secretly replace the encryption keys associated with users’ accounts. The system, which has been under limited user testing since earlier this year, uses key transparency, cont…CYBERINSIDER.COM
12 AugWhatsApp Unveils New Scam Alert FeatureSignal has also made a security announcement: an automatic key verification feature to complement its safety number system. The post WhatsApp Unveils New Scam Alert Feature appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugMindgard Raises $30 Million to Protect AI SystemsThe cybersecurity startup will use the fresh investment to scale its product, engineering, sales, and marketing teams. The post Mindgard Raises $30 Million to Protect AI Systems appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugSignal’s new security feature checks if your encrypted chats were tampered withSignal has introduced a feature called automatic key verification, giving users a new way to confirm that nobody has secretly interfered with their encrypted chats. “Signal is always end-to-end encrypted, and automatic key verification provides an additional, streamlined way to c…HELPNETSECURITY.COM
12 AugAI is Working in the SOC. So Why are Security Executives More Worried Than Ever?Something shifted in security operations over the last two years: AI stopped being a pilot program and became the plan. And if you survey 500 security professionals on whether that's going well – as Omdia did, commissioned by Rapid7 – you get a remarkable level of consensus: 97% …RAPID7.COM
12 AugA Lookalike Domain Can Fool UsersCyber criminals can purchase and monitor domain names while watching their targets. When an opportunity appears, they can create lookalike domains that resemble a legitimate company. The deception can be subtle. A domain such as example-1.com may look close enough to a trusted do…YOUTUBE.COM
12 AugRecord-breaking Kimwolf DDoS botnet released new, stealthier versionPalo Alto Networks’ Unit 42 has uncovered a new version of the Kimwolf Android and IoT botnet that adds stealth to its DDoS attacks and multiple backup mechanisms designed to keep infected devices connected when command-and-control (C2) servers are disrupted. The variant, d…CYBERINSIDER.COM
12 Aug737 Chrome VPN extensions impersonate brands to hijack browser trafficSocket researchers have uncovered a sprawling network of 737 Chrome VPN extensions that impersonated legitimate privacy brands, redirected browser traffic through shared SOCKS5 infrastructure, and accumulated more than 75,000 installs. The campaign primarily targeted Russian-spea…CYBERINSIDER.COM
12 AugResearchers observe first ‘near-autonomous’ AI attack on government target in TaiwanIsraeli cyber firm Dream said the framework adapted mid-operation, corrected its mistakes and expanded as it went along. The post Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan appeared first on CyberScoop .CYBERSCOOP.COM
12 AugAutomate 90%, But Not the Last 10%Some companies claim to automate the entire takedown process. The speaker argues that much of this automation is really workflow automation, such as filling out takedown forms. A complete takedown process also requires monitoring, verification, and confirmation that the action wa…YOUTUBE.COM
11 AugHacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to RedemptionMarcus Hutchins doesn’t personally consider himself a hacker – but he accepts the epithet because it’s a widely used term for what he once did. The post Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugOpenAI Unveils New Cybersecurity Model GPT-5.6-CyberOpenAI has also announced the expansion of its Daybreak platform to give more organizations access to its AI. The post OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugMozilla Issues New Firefox GPG Key Following ExposureThe previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it. The post Mozilla Issues New Firefox GPG Key Following Exposure appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugLocking your ssh-agent exposed local-only keys until OpenSSH 10.5Lock your ssh-agent and it should sit there refusing to sign anything until you unlock it. In OpenSSH 10.4, locking it also switched off the check that tells the agent whether a request came from your own machine or arrived down a forwarded connection from a remote server. The fi…HELPNETSECURITY.COM
11 AugWho will be the Stanislav Petrov in your organization?The recent news coverage of “rogue AI” systems hacking innocent companies reminded me of one of the world’s most unsung heroes and genuinely someone who may well have saved the world. In 1983, the USSR’s early warning systems reported that the United States had launched nuclear m…HELPNETSECURITY.COM
11 AugAn AI tool found 84 flaws in 5G network software and 23 of them still have no fixResearchers at Nanyang Technological University turned a set of AI agents loose on the software that runs 4G and 5G phone networks, and the agents came back with 84 security flaws nobody had reported before. Developers have confirmed 83 of them, and 81 now carry CVE numbers. The …HELPNETSECURITY.COM
11 AugCybersecurity jobs available right now: August 11, 2026CTI Detection Engineer Department of Parliamentary Services | Australia | Hybrid – View job details As a CTI Detection Engineer, you will lead the detection lifecycle by identifying detection gaps, developing and validating detection logic, deploying and tuning an…HELPNETSECURITY.COM
11 AugKimwolf v7: An Evolution of the Kimwolf BotnetDiscover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing. The post Kimwolf v7: An Evolution of the Kimwolf Botnet appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
11 AugCorma Raises $60 Million for Defensive Cybersecurity AI ModelCorma emerged from stealth with seed funding from Sequoia Capital, Khosla Ventures, and Coatue. The post Corma Raises $60 Million for Defensive Cybersecurity AI Model appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugExtension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious ActivitiesThe extension amassed over 300,000 installs and a 4.6 rating before Google removed it for stealing data. The post Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugResearchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT WorkersSecurity researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording. The onboarding paperwork is the part hiring teams can use. The first hire c…THEHACKERNEWS.COM
11 AugCitrix expands Platform Flex with observability and secure developer servicesCitrix has announced new services for Citrix Platform Flex, extending its flexible credit model with additional options for delivering, monitoring and securing digital work environments. The new offerings include Citrix Experience Insights Flex, a Citrix-managed observability ser…HELPNETSECURITY.COM
11 AugNorth Korean remote IT staffer worked for US government agency, says FBIThe investigation shows that North Koreans are able to infiltrate government agencies, as well as private organizations and crypto exchanges.TECHCRUNCH.COM
11 AugLLMs Can Find Business Logic BugsBusiness-logic vulnerabilities have traditionally been difficult to automate. Finding them often required manual penetration testing, bug bounty researchers, or experienced internal security engineers. Rishi argues that LLMs can change that by identifying and chaining complex, mu…YOUTUBE.COM
11 AugAnthropic adds invisible watermarks to Claude-generated textAnthropic is introducing machine-readable watermarks in Claude-generated text, allowing supported AI output to carry an invisible signal that can be detected even after the text is copied elsewhere. The system is part of Anthropic’s implementation of the European Union AI Act’s A…CYBERINSIDER.COM
11 AugThe AI Governance Gap Is a Leadership Problem: Waiting Won’t Close ItOrganizations are rushing to implement AI without fully grasping where its legal protections begin and end. The post The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugSAP Patches Critical Code Injection, Memory Corruption VulnerabilitiesSAP released 28 new and two updated security notes, including four notes dealing with critical-severity bugs. The post SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugAI Genie in the WildWhen I give talks about AI genies , I use this sort of example as a hypothetical. It’s happened . The story is from Australia. Someone named Andrew tasked OpenClaw to book gym classes for him. And…. Minutes later, his AI agent reported it had discovered a way to book …SCHNEIER.COM
11 Aug KEVFormer BlackFile affiliates linked to extortion campaign targeting private equityResearchers warned that hackers are using voice-phishing attacks to pressure company employees under the guise of providing IT help desk services.CYBERSECURITYDIVE.COM
11 AugInput Validation Is Often WrongMike challenges a common AppSec recommendation: treating input validation as a first-line solution for vulnerabilities such as SQL injection, XSS, and prompt injection. His argument is that these problems fundamentally involve separating code from data. Simply pattern-matching in…YOUTUBE.COM
11 AugDelta investigates in-flight Wi-Fi spoofing on post-DEF CON flight from Las VegasThe airline deactivated the network after the crew realized someone was messing with the in-flight system. The feds are investigating. The post Delta investigates in-flight Wi-Fi spoofing on post-DEF CON flight from Las Vegas appeared first on CyberScoop .CYBERSCOOP.COM
11 AugWhat Happens When AI Ignores RulesAn Australian man reportedly asked an AI agent to book a spot in a local gym class. Instead of simply waiting for an opening, the agent manipulated the wait list and interfered with other reservations. The story highlights a basic problem with autonomous agents: completing the re…YOUTUBE.COM
11 AugFederal judge issues second order blocking Trump mail-in voting directiveThe U.S. Supreme Court temporarily reversed an earlier decision through the shadow docket. The post Federal judge issues second order blocking Trump mail-in voting directive appeared first on CyberScoop .CYBERSCOOP.COM
10 AugISC Stormcast For Monday, August 10th, 2026 https://isc.sans.edu/podcastdetail/10044, (Mon, Aug 10th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
10 AugCritical Flaws Discovered in Belgian eID Software Used by 2 Million PeopleThe vulnerabilities affected software used by eight of Belgium’s ten largest banks and over 60 government agencies. The post Critical Flaws Discovered in Belgian eID Software Used by 2 Million People appeared first on SecurityWeek .SECURITYWEEK.COM
10 AugProduct showcase: Enpass Password Manager breaks away from the proprietary cloud modelEnpass is a password manager that stores passwords, passkeys, payment cards, identities, secure notes, software licenses, and other sensitive information in encrypted vaults. Vaults remain on the device or in a cloud storage service selected by the user. Users who work across mul…HELPNETSECURITY.COM
10 Aug71% of CISOs spend 10+ hours on board reportsBoards want evidence that security controls and architecture reduce business risk, expressed in terms of resilience, consequence, and decision relevance. Translating technical findings into business language remains a major time burden for CISOs, who are calling for simpler data …HELPNETSECURITY.COM
10 AugOpenAI locks down Astra over potential critical cyber capabilitiesOpenAI’s internal evaluation of its upcoming model, Astra, found significant advances in agentic coding and cybersecurity, leading the company to conclude that it cannot rule out the model reaching the critical capability level for cybersecurity under its Preparedness Frame…HELPNETSECURITY.COM
10 AugNovel Private APN Pivot Let Hackers Sabotage Second Polish Energy FacilityCERT.PL said this appears to be the first instance of a private APN being used as an attack vector. The post Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility appeared first on SecurityWeek .SECURITYWEEK.COM
10 AugNew Zealand sanctions Russian hackers, propaganda groups over Ukraine warNew Zealand announced new sanctions on Russian hackers, technology companies and Kremlin-linked organizations over their roles in supporting Moscow’s war against Ukraine.THERECORD.MEDIA
10 Aug‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents BadAn AI agent executes instructions that an attacker has planted in the log or alert that records a blocked request word for word. The post ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad appeared first on SecurityWeek .SECURITYWEEK.COM
10 AugMicrosoft Entra ID is removing an extra MFA hurdle for Windows Hello and macOS PSSO usersMicrosoft is changing how Entra ID handles MFA for people who sign in with Windows Hello for Business (WHfB) or macOS Platform Single Sign-On (PSSO). The rollout reaches worldwide and GCC tenants starting early October 2026, with completion expected by late November. Microsoft sa…HELPNETSECURITY.COM
10 AugKimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware DevelopmentNorth Korea's state hackers are no longer content to type prompts into public chatbots. One of the country's main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting document-search tools to files in its possession, and collectin…THEHACKERNEWS.COM
10 AugWhen Technology Stops WorkingTechnology has gradually become part of almost every daily activity. Many people now rely on smartphones and digital systems for shopping, payments, communication, and routine tasks without thinking about it. The concern isn't that technology is bad—it's that dependence can becom…YOUTUBE.COM
10 AugWhy transparent AI agents matter more than you thinkThe difference between a prompt injection attack you'll catch and one you won't might just be whether your AI agent can explain itself. The post Why transparent AI agents matter more than you think appeared first on CyberScoop .CYBERSCOOP.COM
10 AugStealthium Targets Security Blind Spots in AI Accelerators and Neo-CloudsThe startup analyzes subtle telemetry signals to detect attacks that traditional security tools cannot see inside accelerator-powered AI infrastructure. The post Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds appeared first on SecurityWeek .SECURITYWEEK.COM
10 AugRussian military hackers pose as recruiters to target Ukrainian IT workersUkraine’s computer emergency response team, CERT-UA, said Saturday that the campaign has been running since at least May and is linked to Sandworm, the notorious hacking unit associated with Russia’s GRU military intelligence agency.THERECORD.MEDIA
10 AugCivil-society initiative will pay cybersecurity vendors to protect rural water systemsThe group is seeking philanthropic grants, but its founder said the federal government ultimately needs to step in.CYBERSECURITYDIVE.COM
10 AugFirewallFalcon VPN management tool caught backdooring serversFirewallFalcon, a free Linux server management tool promoted to VPN resellers and “free internet” operators, has been found secretly hijacking network traffic and giving its developer control over systems that install it. Researchers say FirewallFalcon Manager combines legitimate…CYBERINSIDER.COM
10 AugMicrosoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the EnterpriseMicrosoft is named a Leader in the 2026 IDC MarketScape for MDR services. Discover how Microsoft Defender Experts MDR combines AI, threat intelligence, and human expertise. The post Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise appeared firs…MICROSOFT.COM
10 AugOpenAI says Daybreak will expand to offer specialized cyber servicesThe company rolled out “Red” and “Blue” programs for defenders, introduced a new model and announced partnerships with 16 major cybersecurity vendors. The post OpenAI says Daybreak will expand to offer specialized cyber services appeared first on CyberScoop .CYBERSCOOP.COM
10 AugThe FTC wants to regulate AI for ideological biasThe commission is mulling whether to begin regulating bias in AI systems. Critics say they’re overstepping their legal authority and infringing on free speech. The post The FTC wants to regulate AI for ideological bias appeared first on CyberScoop .CYBERSCOOP.COM
10 AugThe Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and CommunicationsAnalysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution. The post The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications appeared first on Unit 4…UNIT42.PALOALTONETWORKS.COM
8 AugNew CSS Attacks Can Break Webmail Defenses to Steal Passwords and TokensNew research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party accounts…THEHACKERNEWS.COM
8 AugThe End of SMS LoginsMicrosoft has announced that native SMS and voice authentication delivery for Entra will be retired beginning February 1, 2027. Organizations that continue using those methods will need to integrate a third-party provider. The change aligns with Microsoft's broader push toward ph…YOUTUBE.COM
7 AugISC Stormcast For Friday, August 7th, 2026 https://isc.sans.edu/podcastdetail/10042, (Fri, Aug 7th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
7 AugUS fuel gauge exposure fell by more than half in three monthsEvery month for the better part of a year, about 4,800 US internet addresses answered a query in the protocol that fuel tank gauges speak. In June the number was 2,354. The count fell across April, May, and June, all three months sit below the previous year’s floor, and the…HELPNETSECURITY.COM
7 AugGut feeling does nothing against AI spear phishing textsA banker at a credit union sat down at a table with a dozen printed text messages, all of them written for that banker personally, and put them in order from the one most likely to get a click down to the one least likely. One of them stopped the sorting. It looked like something…HELPNETSECURITY.COM
7 AugTeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain CampaignA new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training their sights on the software supply chain. "The c…THEHACKERNEWS.COM
7 AugOpenAI drops ChatGPT text chat limits for free users, adds new safeguards for teensOpenAI has updated GPT-5.6 Sol, the model behind ChatGPT for Plus and Pro subscribers, and pushed a new model, GPT-5.6 Luna, out to everyone using the free tier. The company is also removing the rate limit on text conversations for free users, allowing them to keep chats going wi…HELPNETSECURITY.COM
7 AugBlack Hat USA 2026 – Summary of Vendor Announcements (Part 4)Companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas. The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 4) appeared first on SecurityWeek .SECURITYWEEK.COM
7 AugICE Is Buying Access to Credit Card RecordsThrough data brokers, ICE is buying the information you provided to open a credit card.SCHNEIER.COM
7 AugVishing Extortion Group UNC6671 Rebrands After Making MillionsInitially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands. The post Vishing Extortion Group UNC6671 Rebrands After Making Millions appeared first on SecurityWeek .SECURITYWEEK.COM
7 AugBreaking the attack chain created by exposed cloud secretsTL;DR A secret is only as safe as the route it takes Secrets are supposed to let systems authenticate without leaving credentials sitting in plain view. However, a secret still has to be created, stored, retrieved by a workload, used and …PENTESTPARTNERS.COM
7 AugAI Fails Without Understanding WhyA database can show relationships between data points. A knowledge graph adds context by explaining why those relationships exist and why they matter. AI systems that only ingest massive amounts of information may struggle without deeper structure and context. The ability to unde…YOUTUBE.COM
7 AugInside the Fake Copyright Racket Silencing News OutletsJournalists and civil society are being silenced by accusations of copyright infringement, says Alberto Fittarelli in a report by the OCCRP. The post Inside the Fake Copyright Racket Silencing News Outlets appeared first on The Citizen Lab .CITIZENLAB.CA
7 AugExperts say healthcare faces cybersecurity crisis: ‘These are patient safety issues’Regulatory failures, funding constraints and industry consolidation have created serious hacking risks.CYBERSECURITYDIVE.COM
7 AugFriday Squid Blogging: Arctic Bobtail Squid VideoNice video of the Arctic bobtail squid. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.SCHNEIER.COM
7 AugSci-Fi, PKD, Greatness, Passkeys, AgentBreaker, Rockwell, Flock, Josh Marpet - SWN #605Sci-Fi, PKD, Greatness, Passkeys, AgentBreaker, Rockwell, Flock, Doug is very dark, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-605YOUTUBE.COM
7 AugRenting Phishing Attacks MonthlyPhishing-as-a-service platforms have changed how some cybercriminal groups operate. Instead of creating every component themselves, attackers can use subscription-based services that provide phishing infrastructure and support for targeting common platforms. This shift lowers the…YOUTUBE.COM
6 AugOver 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware LuresA macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks. The server-side gate hides the malic…THEHACKERNEWS.COM
6 Aug22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary], (Thu, Aug 6th)[This is a Guest Diary by Daryl Jiminez, an ISC intern as part of the SANS.edu BACS program]
ISC.SANS.EDU
6 AugISC Stormcast For Thursday, August 6th, 2026 https://isc.sans.edu/podcastdetail/10040, (Thu, Aug 6th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
6 AugNon-human identities are 91% of everything active in productionA backup job fires at two in the morning. A scanner walks the same AWS account an hour later, a deployment pipeline assumes a role at four, and a logging agent runs straight through the night. Each of those actions carries a credential issued to a machine. An attacker holding one…HELPNETSECURITY.COM
6 AugLOW - TrailerAfter 8 years, LOW is finally here. A story about the weight of being and the wreckage of waking up. Five episodes. Five descents. LOW is an audio journey into the unlit corners of human experience. Choices we made in the dark, the silences we carry, and what remains when we stop…THISISLOW.COM
6 AugNVIDIA Group Proposes SAFE Initiative for Agentic Threat Intel SharingThe Open Secure AI Alliance has announced plans for the Shared AI Findings Exchange (SAFE)INFOSECURITY-MAGAZINE.COM
6 AugSignal broadens device linking support on Android and iOSSignal has introduced broader linked-device support, allowing users to connect additional Android phones, Android tablets, and iPhones to an existing Signal account. The changes are rolling out with Signal Android version 8.20 and Signal iOS version 8.22. Signal developer Jim Lun…CYBERINSIDER.COM
6 AugMicrosoft extends zero trust deeper into enterprise AIMicrosoft expanded its Zero Trust for AI strategy with updates to the Zero Trust Assessment tool and the Zero Trust Workshop. The additions help organizations assess security posture, prioritize remediation, and apply zero trust principles to AI agents and AI-assisted software de…HELPNETSECURITY.COM
6 AugDiscounted Claude access bought on the gray market may expose every prompt you sendMore than half a dozen services advertised on underground forums and messaging platforms, offering discounted or “unlimited” token access to frontier AI models, were discovered by Okta. Okta believes the trend is likely driven by Chinese users seeking access to AI mod…HELPNETSECURITY.COM
6 AugAdversarial Clothing Designed to Fool Facial Recognition SystemsThere are many companies manufacturing adversarial clothing designed to confuse facial recognition systems. It’s a cool idea, but I worry that it’s mostly security theater: “Our patterns play with that chaos, confuse algorithms and make it way harder to pin you …SCHNEIER.COM
6 AugCritical Paperclip Flaw Allowed Admin Access, Code ExecutionAn attacker could self-register, sign in for board-level API access, and import a new company for code execution. The post Critical Paperclip Flaw Allowed Admin Access, Code Execution appeared first on SecurityWeek .SECURITYWEEK.COM
6 AugGrapheneOS says Revolut is blocking its users over Google Play checksGrapheneOS says Revolut has begun blocking customers who use its privacy-focused Android operating system, alleging that the fintech company is presenting the restriction as a security measure while actually enforcing Google Play licensing and device-certification requirements. T…CYBERINSIDER.COM
6 AugSnowflake hacker pleads guilty, faces up to 32 years in prisonA Canadian man is facing decades in prison for hacking customer accounts at cloud storage provider Snowflake and stealing data from more than 165 organizations. Connor Riley Moucka, also known as “Waifu” and “Judische,” 26, of Kitchener, Ontario, pleaded g…HELPNETSECURITY.COM
6 AugDon't Chase Every Shiny TechnologyTechnology evolves quickly, and new tools, trends, and innovations constantly compete for attention. Throughout a career in cybersecurity, staying focused on core principles can be more valuable than chasing every new development. Governance and security provide a framework for e…YOUTUBE.COM
6 AugSnowflake Hacker Pleads Guilty in US CourtConnor Riley Moucka was extradited to the United States in July 2025 after he was arrested in Canada. The post Snowflake Hacker Pleads Guilty in US Court appeared first on SecurityWeek .SECURITYWEEK.COM
6 AugCanadian Man Pleads Guilty in Snowflake ExtortionsA 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka,…KREBSONSECURITY.COM
6 AugPhotos: Black Hat USA 2026, part twoRound two from Black Hat USA 2026. This set covers the parts of the show floor that did not make the first gallery. Scroll through below. Featured vendors: BlackCloak, Teleport, GitGuardian, Oak, Hexnode, Picus Security, Featured speaker: Kate Silverstein (Mozilla) discussing cro…HELPNETSECURITY.COM
6 AugRansom Cartel creator sentenced to 16 years in prisonMaksim Silnikau participated in cybercrime since at least 2005. He ran Ransom Cartel from 2021 until his arrest in 2023. The post Ransom Cartel creator sentenced to 16 years in prison appeared first on CyberScoop .CYBERSCOOP.COM
6 AugDespite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed onlineA scan of internet-connected industrial equipment found 4,400 exposed PLCs, including 22 in cities recently targeted by water system attacks. The post Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online appeared first on …CYBERSCOOP.COM
6 AugHackers grow more willing to destroy, not just disrupt OT systemsExperts said the alarming trend has further stressed infrastructure providers that are already struggling with strong passwords, comprehensive logging and other basics.CYBERSECURITYDIVE.COM
6 AugComputers Inside Your ComputersAI infrastructure contains multiple layers of hardware and software working together, including components like BMCs, UEFI, memory systems, and DPUs. As AI systems become more advanced, understanding the underlying architecture becomes harder. Complexity creates new challenges fo…YOUTUBE.COM
6 AugChainDrop: Inside a Self-Propagating npm WormAnalysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
5 AugISC Stormcast For Wednesday, August 5th, 2026 https://isc.sans.edu/podcastdetail/10038, (Wed, Aug 5th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
5 AugYour enterprise AI footprint is about three times bigger than your model listOrganizations are building AI systems that combine models, agents and external tools instead of relying on standalone AI, according to Snyk’s latest State of Agentic AI Adoption report. The study analyzed 3,044 enterprise environments and 1.39 million code repositories to e…HELPNETSECURITY.COM
5 AugProduct showcase: Material unifies Google Workspace email, file & OAuth defenseHere’s an uncomfortable truth: the attack that gets you won’t look like an attack. It’ll look like a normal login, a normal file share, a normal permission request you clicked past without reading. You don’t have a phishing problem, a DLP problem, or an OA…HELPNETSECURITY.COM
5 AugBank of America impersonators weaponize ScreenConnect, then make it hard to removeA phishing campaign impersonating Bank of America (BoA) is underway, trying to trick Windows users into installing ScreenConnect remote access software and then making it difficult to uninstall it. Different traps for Mac and Windows users By claiming the recipient must take spec…HELPNETSECURITY.COM
5 AugVulnerabilities in Car Anti-Theft DeviceThis is disturbing: …a team of security researchers at UC San Diego, who found that a model of aftermarket car alarm known as the KARR Security System, installed in more than 2 million vehicles across the US by their estimate, can let any hacker within Bluetooth range send …SCHNEIER.COM
5 AugSay Easy, Do Hard - Performance Through People - Greg Hoffman - BSW #459This week, we air our thirteenth pre-recorded segment called “Say Easy, Do Hard”. Inspired by my co-host, Jason Albuquerque, we discuss “Performance Through People”. Greg Hoffman joined us a few weeks back to discuss his new book. This week, we dig into his five disciplines of Pe…YOUTUBE.COM
5 AugApple WebKit privacy leaks impact Tor, Psylo, and iCloud Private RelayResearchers have discovered three WebKit features that can bypass application-level proxy settings on iOS and macOS, potentially exposing users' real IP addresses or DNS servers. The leaks affect proxy-based browsers, including iOS Tor browsers and Psylo, as well as Apple’s iClou…CYBERINSIDER.COM
5 AugSamsung bans smart TV apps that turn user connections into proxiesSamsung is banning smart TV apps that can route strangers’ web traffic through users’ home internet connections after researchers found residential proxy software embedded in games available through its app store. One affected Pac-Man title had even been promoted in Samsung’s “Ed…CYBERINSIDER.COM
5 AugNew Attack Methods Enable Malware to Hijack Passkey-Protected AccountsPalo Alto Networks researchers have demonstrated attacks against Google’s synced passkey implementation. The post New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts appeared first on SecurityWeek .SECURITYWEEK.COM
5 AugLumu launches live threat intelligence platform for real-time cyber defenceLumu has announced the release of Lumu Threat Observatory as part of Maltiverse, its threat intelligence solution. Lumu Threat Observatory is Maltiverse’s live, personalized threat-intelligence experience, providing organizations with a complete, live view of the active thr…HELPNETSECURITY.COM
5 AugINTERPOL flags AI as the new engine of African cybercrimeAfrica’s growing digital economy is exposing governments, businesses and internet users to a rising wave of cybercrime. The continent recorded more than 1.1 billion mobile subscriptions and over $1.1 trillion in digital transactions in 2025, while more than 570 million peop…HELPNETSECURITY.COM
5 AugTenable broadens AI visibility across major LLMs and AI toolsTenable has announced enhanced AI security capabilities within the Tenable One Exposure Management Platform. Tenable One AI Exposure now delivers expanded platform coverage with support for Google Gemini, extending its coverage across major LLMs: Google Gemini, Anthropic Claude, …HELPNETSECURITY.COM
5 AugImmigration Policy: The Backdoor to Transnational RepressionCitizen Lab researchers write that restrictive immigration policies are incompatible with attempts to counter transnational repression. The post Immigration Policy: The Backdoor to Transnational Repression appeared first on The Citizen Lab .CITIZENLAB.CA
5 AugLeadership Starts When You Stop CodingOne of the core disciplines of Performance Through People is adopting a leadership-first mindset. Instead of measuring success by your own technical output, effective leaders focus on creating the conditions for their teams to succeed. Many first-time managers struggle because th…YOUTUBE.COM
5 AugBlack Hat USA 2026 – Summary of Vendor Announcements (Part 3)Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas. The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 3) appeared first on SecurityWeek .SECURITYWEEK.COM
5 AugTop product launches at Black Hat USA 2026Black Hat USA 2026 is underway in Las Vegas, and vendors are using the moment to unveil what they hope will define the next year of defense. Here are the announcements drawing the most attention on the ground, and why they matter for teams weighing new budgets. BlackCloak extends…HELPNETSECURITY.COM
5 AugStellar Cyber’s Auto-Triage AI matches human analysts 99.7% of the timeStellar Cyber, the full-cycle AI-native security operations platform company, today released results from an independent study of 124 days of customer trials of its Agentic Auto Triage capability. The independent study based on customer trials evaluated 138,475 real security aler…HELPNETSECURITY.COM
5 AugMicrosoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)Learn why KuppingerCole named Microsoft a Leader in its Leadership Compass: Cloud Native Application Protection Platforms report. The post Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP) appeared first o…MICROSOFT.COM
5 AugFrom open lures to cloaked gates: How a macOS ClickFix campaign learned to hideA macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while giving defenders new hunting opportunities. The post From open lures to cloaked ga…MICROSOFT.COM
5 AugAI Made Perfect Cheating EasyThis conversation argues that AI hasn't created academic cheating—it has dramatically increased how effective and difficult to detect it can be. One observation is the sharp rise in perfect scores on standardized tests compared to previous years. If AI-assisted cheating becomes w…YOUTUBE.COM
5 AugOpenAI warns autonomous hacks are ‘watershed moment for computer security’Company employees said their industry should rethink how it balances capabilities and safeguards.CYBERSECURITYDIVE.COM
5 AugSmashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrencyGraham gets a phone call from the police. Well, someone who sounds convincingly like the police. There's just one small problem: what they really want is the 24-word seed key to Graham's cryptocurrency wallet. Meanwhile, if you've stayed in a hotel recently, the free Wi-Fi you co…GRAHAMCLULEY.COM
4 AugISC Stormcast For Tuesday, August 4th, 2026 https://isc.sans.edu/podcastdetail/10036, (Tue, Aug 4th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
4 AugNew York Awards $9 Million to Strengthen Cybersecurity at 153 Water SystemsThe grants will help local governments assess and improve cyber defenses amid a multistate campaign targeting water and wastewater infrastructure. The post New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems appeared first on SecurityWeek .SECURITYWEEK.COM
4 AugClass is in session—for cybercriminals.Welcome in! You’ve entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today’s most interesting threats. Your host is Selena Larson, Proofpoint intelligence analyst and host of their po…THECYBERWIRE.COM
4 AugAnalysts got 19 minutes back every hour in Stellar Cyber’s agentic auto triage trialsAn analyst opening a queue on Monday morning will spend most of it on tickets that amount to nothing. Stellar Cyber’s Agentic Auto Triage closed 8,047 of those tickets on its own during customer trials, filing them as confident false positives. That covers 64% of every verd…HELPNETSECURITY.COM
4 AugMicrosoft Bug Bounty Program: $20 Million Paid to 500 ResearchersThe biggest single reward paid out by Microsoft between July 1, 2025, and June 30, 2026, was $200,000. The post Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers appeared first on SecurityWeek .SECURITYWEEK.COM
4 AugOWASP’s subtractive security project measures the attack paths you erasedAn attacker who talks a user into opening an attachment gets whatever that machine still permits: a service account with rights across the domain, an outbound route to anywhere, a scripting engine sitting there for the taking. Christopher Frenz wants those capabilities deleted be…HELPNETSECURITY.COM
4 AugTor launches Snowflake Android app to help users bypass censorshipThe Tor Project has announced Snowflake Volunteer, a new Android app that lets users donate a portion of their internet bandwidth to help people bypass online censorship. The app is intended to expand the pool of volunteer-run Snowflake proxies while giving users control over bat…CYBERINSIDER.COM
4 AugMicrosoft shortens NuGet API key lifetime to improve supply chain securityMicrosoft is reducing the lifetime of new NuGet.org API keys from 365 days to 30 days starting August 17, 2026, to improve the security of NuGet, its package repository for .NET developers. API keys created before August 17 will remain valid until November 1, after which develope…HELPNETSECURITY.COM
4 AugPrompting for Patches That Fix Vulns Without Adding New Ones - Keith Hoodlet - ASW #394There's already an increase in volume of security flaws found by LLMs. And orgs are already turning to LLMs to write code. So, what happens when orgs lean on LLMs to create patches for those security flaws? Keith Hoodlet gives an exclusive early look at his team's recent research…YOUTUBE.COM
4 AugJoinable Labs unveils Joinable Security for threat intelligence and AI-driven responseJoinable Labs launched Joinable Security, the first domain on the Joinable platform, with two products: Joinable Threat Map, a free utility that lets the security community map, analyze, and share evolving adversary behavior, and Joinable Runbooks, an enterprise platform that tur…HELPNETSECURITY.COM
4 AugSecuronix enhances Unified Defense SIEM with AI agent detection and lower data costsSecuronix has announced expanded cybersecurity cost reduction, expanded Threat Analytics for Microsoft Sentinel, and new Governed AI Agent Detection and Response capabilities. The additions extend the Securonix Unified Defense SIEM platform to help enterprises and managed securit…HELPNETSECURITY.COM
4 AugUptime Kuma 2.5.0 waits two weeks before trusting a new npm packageUptime Kuma checks whether a website, a Docker container, a DNS record, or a Steam game server is still answering, and pushes a message to Telegram, Slack, or email when one stops. The self-hosted monitoring tool is MIT licensed, runs in a container or on Node.js, and has 89,800 …HELPNETSECURITY.COM
4 AugLegit Security VibeGuard 2.0 brings endpoint security and real-time guardrails to AI coding agentsLegit Security has unveiled VibeGuard 2.0, bringing a new endpoint security capability that seamlessly discovers and integrates with coding agents, secures them and delivers a frictionless developer experience. Launched in Q4 2025, Legit VibeGuard was the solution designed to sec…HELPNETSECURITY.COM
4 AugSome Claude Chats Are Searchable on GoogleAnd it’s personal information (alternate link ): The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on meetings, and a dashboard someone made apparently to analyze medical billing data. Exposed chats reportedly include private…SCHNEIER.COM
4 AugGemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request TamperingA crafted prompt to a low-privilege Google ADK agent could be used to pass a malicious hand-off comment to a privileged agent. The post Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering appeared first on SecurityWeek .SECURITYWEEK.COM
4 AugESET introduces new AI capabilities for autonomous agent securityESET is expanding its AI capabilities across threat detection, investigations, threat protection, and security operations, delivering added value to customers through built-in innovations rather than separate add-on solutions. “AI is a new class of actor inside the company – read…HELPNETSECURITY.COM
4 AugCloud and SaaS Environments Now Top Targets for AttackersCloud and SaaS are now the preferred operating environments for threat actors, amid a continued shift to identity attacksINFOSECURITY-MAGAZINE.COM
4 AugTP-Link Omada ZTP Vulnerabilities Chain Into Full Network TakeoverForescout researchers have found 15 new vulnerabilities in the TP-Link Omada networking ecosystem. The post TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover appeared first on SecurityWeek .SECURITYWEEK.COM
4 AugWhen Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always WantedThe cybersecurity industry has spent decades assuming that offensive capability scales with technical expertise. That assumption is starting to break. Security teams have long estimated risk by ranking attacker sophistication. Nation-state actors sat at one end. Organized crimina…THEHACKERNEWS.COM
4 Aug“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AITalos has collected prompt logs from threat actor endpoints running various applications, such as Claude Code, CodeX, Cursor, or Gemini. This blog is an analysis of the ways we've seen bad actors leveraging cloud-based AI.TALOSINTELLIGENCE.COM
4 AugApple challenges new UK demand to access encrypted iCloud dataApple has filed a new legal challenge against the UK government over an order requiring access to encrypted cloud backups belonging to British users. The complaint follows the government’s decision last year to withdraw a broader demand that could have affected customers in both …CYBERINSIDER.COM
4 AugObsidian Security Raises $85 Million at $1.1 Billion ValuationObsidian Security has developed a platform for governing AI agents across third-party applications. The post Obsidian Security Raises $85 Million at $1.1 Billion Valuation appeared first on SecurityWeek .SECURITYWEEK.COM
4 AugWeaponized Email AI Assistants Could Help Attackers Hijack AccountsResearchers demonstrate how attackers could abuse built-in email chatbots to evade detection, impersonate trusted employees, compromise executive accounts, and facilitate financial fraud. The post Weaponized Email AI Assistants Could Help Attackers Hijack Accounts appeared first …SECURITYWEEK.COM
4 AugZenity Raises $125 Million in Series C FundingThe AI security company will invest in product innovation, global expansion, and customer experience. The post Zenity Raises $125 Million in Series C Funding appeared first on SecurityWeek .SECURITYWEEK.COM
4 AugSevii APS Module preempts attacks with autonomous cyber defensSevii has announced a major expansion of the Sevii Autonomous Defense & Remediation (ADR) platform with the general availability of an Autonomous Preemptive Security (APS) module. The new module complements ADRs autonomous defense against threats, extending the platform to c…HELPNETSECURITY.COM
4 AugOligo Raises $60 Million for Runtime SecurityThe company will use the investment to accelerate product innovation and expand go-to-market operations. The post Oligo Raises $60 Million for Runtime Security appeared first on SecurityWeek .SECURITYWEEK.COM
4 AugCISO Conversations: Russ Kirby – Passion Is the Antidote to BurnoutRuss Kirby, CISO at Ping Identity, shares how passion, courage, and “good enough” thinking shaped his path from HP to the C-suite—and what keeps him up at night. The post CISO Conversations: Russ Kirby – Passion Is the Antidote to Burnout appeared first on SecurityWeek .SECURITYWEEK.COM
4 AugBlack Hat USA 2026 – Summary of Vendor Announcements (Part 2)Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas. The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 2) appeared first on SecurityWeek .SECURITYWEEK.COM
4 AugRethinking AI Security: Why CASB and DLP Need an Interaction-Aware LayerBuild your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. The post Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer appeared …SECURITYWEEK.COM
4 AugA Roadmap for Confronting the Chilling Effects of Censorship, Surveillance and New TechnologySenior research fellow Jon Penney spoke with Tech Policy Press about how rising surveillance is causing people to self-censor. The post A Roadmap for Confronting the Chilling Effects of Censorship, Surveillance and New Technology appeared first on The Citizen Lab .CITIZENLAB.CA
4 AugAdvance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOpsMicrosoft expands its Zero Trust for AI strategy to enhance security for AI and DevSecOps environments with new tools and guidance. The post Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps appeared first on Microsoft Security Blog .MICROSOFT.COM
4 AugRandomness, Grey, Deepseek, Sonicwall, Spice, CaptiveCrunch, eBay, and Aaran Leyland - SWN #604Randomness, 50 Shades of Grey, Deepseek, Sonicwall, Spice Weasels, CaptiveCrunch, eBay, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-604YOUTUBE.COM
4 AugMassive supply-chain attack compromises 440 packages under four hoursResearchers from multiple security firms observed a variant of Mini Shai-Hulud, self-replicating malware linked to TeamPCP, in all the affected packages. The post Massive supply-chain attack compromises 440 packages under four hours appeared first on CyberScoop .CYBERSCOOP.COM
3 AugISC Stormcast For Monday, August 3rd, 2026 https://isc.sans.edu/podcastdetail/10034, (Mon, Aug 3rd)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
3 AugBuying TikTok followers can expose users to scams and account theftBuying TikTok followers, likes, or views could do more than inflate engagement metrics. According to Malwarebytes, many services selling social media growth operate through deceptive practices that can expose customers to scams, stolen accounts, and financial loss. The market for…HELPNETSECURITY.COM
3 AugAI cut phishing from hours to seconds, which is where DMARC and BIMI come inIn this Help Net Security video, Mike Boyle, VP of Business Units at GMO GlobalSign, and Rahul Powar, CEO and founder of Red Sift, unpack the evolution of email security and why it matters for business trust. With a combined 45+ years worth of experience in tech, they dissect ema…HELPNETSECURITY.COM
3 AugMapping the malware blast radius a single alert won’t show youIn this interview with Help Net Security, Mike Wiacek, founder and CTO of Stairwell, explains Backstory, an AI agent that takes a single alert and works outward to map how far a malware campaign spread. He walks through the research behind the claim that each published sample hid…HELPNETSECURITY.COM
3 AugOpenAI reveals how criminals used ChatGPT to run scamsOpenAI banned a coordinated network of ChatGPT accounts that likely originated in Cambodia’s Preah Sihanouk province, a region reports have linked to online scam compounds and human trafficking operations. The network used the company’s models to create and manage fak…HELPNETSECURITY.COM
3 AugPass the Passkey: A Novel Attack Surface in Passwordless AuthenticationExplore how passkey implementation gaps undermine security when relying parties fail to validate the User Verified flag, reducing MFA to a single factor. The post Pass the Passkey: A Novel Attack Surface in Passwordless Authentication appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
3 AugItaly fines telecom giant TIM $11 million for privacy violationsItaly's data protection authority has fined telecommunications giant TIM €9.516 million ($11 million) after finding widespread privacy and telemarketing violations involving unlawfully obtained customer consent, inadequate oversight of third-party sales partners, and failures to …CYBERINSIDER.COM
3 AugSimbian adds AI threat hunting agent to expand autonomous SecOps platformSimbian has released its autonomous AI Threat Hunt Agent, that investigates potential threats and identifies malicious activity across enterprise environments. The Threat Hunt Agent represents the third pillar of Simbian’s AI-driven security suite. These three Agents elimin…HELPNETSECURITY.COM
3 AugMicrosoft links hotel Wi-Fi hacks to Russian Midnight Blizzard hackersMicrosoft has attributed an ongoing campaign targeting travelers on hotel and other hospitality Wi-Fi networks to a subgroup of the Russian state-sponsored hacking group Midnight Blizzard, warning that the attacks go beyond credential theft to also deploy malware on victims' devi…CYBERINSIDER.COM
3 AugQodana 2026.2 adds post-quantum crypto checks for JVM codeQodana 2026.2 shipped with new security inspections, published benchmark results, post-quantum cryptography checks, and coverage reporting that no longer has to be pointed at the reports. The security work sits in the .NET linter and runs by default. Qodana tracks untrusted data …HELPNETSECURITY.COM
3 AugRussian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft saysRussian state-sponsored hackers have been compromising hotel Wi-Fi networks around the world to steal travelers' login credentials and infect devices with espionage malware, Microsoft said.THERECORD.MEDIA
3 AugHorizon3 Raises $250 Million to Fund Continuing GrowthVenture financing has become an essential factor in growing new business in today’s fast moving economy. Horizon3’s latest funding explains how and why. The post Horizon3 Raises $250 Million to Fund Continuing Growth appeared first on SecurityWeek .SECURITYWEEK.COM
3 AugHow volunteer cyber experts are helping protect rural water systemsA first-in-the-nation program is seeing promising results as it charts a path for supporting the U.S.’s most vulnerable infrastructure.CYBERSECURITYDIVE.COM
3 AugMimecast introduces AI agent governance and managed threat responseMimecast has unveiled Agent Risk Center, a beta capability for discovering, monitoring, and governing AI agents, alongside Managed Threat Response, a redesigned 24/7 service that combines AI-assisted triage with analyst-confirmed remediation. According to Mimecast’s analysis, 98%…HELPNETSECURITY.COM
3 AugSentinelOne expands security operations automation with governed AISentinelOne has today announced governed, closed-loop response across the Singularity Platform, delivering trustworthy automation for security operations. Purple AI and Singularity Hyperautomation now autonomously investigate alerts, reach verdicts, and execute responses. Securit…HELPNETSECURITY.COM
3 AugWhy Shopify Doesn't Build Around One AIShopify routes AI requests through a single LLM proxy rather than integrating every application directly with an individual AI provider. That common layer supports multiple models and makes it easier to evaluate and replace them as new options become available. AI models are evol…YOUTUBE.COM
3 AugMidnight Blizzard Targets Travelers via Captive PortalsRussian actor Storm-2945 hijacked hotel captive portals to push fake updates and steal tokensINFOSECURITY-MAGAZINE.COM
3 AugBlack Hat USA 2026 – Summary of Vendor Announcements (Part 1)Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas. The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 1) appeared first on SecurityWeek .SECURITYWEEK.COM
3 AugVisa to Acquire Fraud Intelligence Firm BioCatch for $2.4 BillionThe payments giant says BioCatch’s behavioral and device intelligence will help financial institutions combat account takeovers, scams and other forms of digital fraud. The post Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion appeared first on SecurityWeek .SECURITYWEEK.COM
3 AugWhen AI Writes Production CodeAI coding tools are making it possible to build software much faster, even for people with limited technical experience. As deadlines tighten, AI-generated code is increasingly finding its way into production applications—not just internal prototypes. That speed comes with new se…YOUTUBE.COM
3 AugPublic interest coalition urges Congress to investigate OpenAI, Hugging Face hackThe post Public interest coalition urges Congress to investigate OpenAI, Hugging Face hack appeared first on CyberScoop .FEDSCOOP.COM
1 AugHijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance MalwareA fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report. Researchers track the operation as CaptiveCrunch and attr…THEHACKERNEWS.COM
1 AugBalance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity InvestmentsThe funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek .SECURITYWEEK.COM
1 AugThe New Trick Against AI ScrapersAI scrapers are designed to collect content from websites and documents. One emerging defense doesn't try to stop the scraper—instead, it changes what the scraper sees. Technologies like Shield Font can preserve a normal reading experience for people while causing AI systems to e…YOUTUBE.COM
31 JulISC Stormcast For Friday, July 31st, 2026 https://isc.sans.edu/podcastdetail/10032, (Fri, Jul 31st)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
31 JulNew infosec products of the week: July 31, 2026Here’s a look at the most interesting products from the past week, featuring releases from BlackCloak, Contrast Security, Dropzone AI, PortSwigger, Realm Security, Reco, Root Evidence, and ZeroFox. BlackCloak extends deepfake protection to the executive’s trusted circle Deepfakes…HELPNETSECURITY.COM
31 JulAI agents are changing where cybersecurity seed funding landsFounders pitching a cybersecurity seed round this summer are joining a line that keeps getting longer. Product Hunt launches hit their highest level since late 2023 last quarter, and the Census Bureau’s count of high-propensity business applications kept climbing. Seed deal…HELPNETSECURITY.COM
31 JulAttackIQ targets CTEM execution with AVA Agentic OSAttackIQ has announced AVA Agentic OS, an agentic operating system designed to operationalize Continuous Threat Exposure Management. CTEM has emerged as the strategic framework for managing cyber risk, yet many organizations continue to struggle to operationalize CTEM across frag…HELPNETSECURITY.COM
31 JulTraefik Labs introduces Distro Zero secure runtime for API and AI gatewaysTraefik Labs has introduced the Distro Zero image, a hardened, vendor-supported secure runtime delivered as Traefik Hub in proxy mode. It gives platform and security teams a container whose entire executable content is a single memory-safe binary, with validated cryptography buil…HELPNETSECURITY.COM
31 JulAWS Blames North Korean Group for Axios and Other npm Supply Chain AttacksAWS has linked North Korea to the axios campaign to other attacks on npm librariesINFOSECURITY-MAGAZINE.COM
31 JulThe Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET VersionAnalysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic. The post The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
31 JulGoogle AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching PaceThe internet giant has built an agent harness to find vulnerabilities across Chrome’s codebase. The post Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace appeared first on SecurityWeek .SECURITYWEEK.COM
31 JulIf you’re going to vibe code it, why not vibe pen test it?TL;DR Why I built PenAI PenAI started as a project at a hackathon organised by Encode Club. It’s an AI agent that could work through Hack The Box-style lab machines on its own. Upload a VPN file, give it a target IP, pick a scope, set stealth mode and iteration limits, hit …PENTESTPARTNERS.COM
31 JulOVHcloud charged in Canada over customer data production orderOVHcloud says it will vigorously contest criminal charges filed in Canada after authorities accused the company of failing to comply with a court-ordered demand for subscriber information tied to servers hosted outside the country. In an announcement published today, OVH Groupe S…CYBERINSIDER.COM
31 JulCybercrime goes subscription: AI, malware and infrastructure on demandCybercrime has become a commercialized ecosystem where criminals can buy or rent nearly every capability needed to launch sophisticated attacks. These services provide anonymity, plausible deniability, and access to short-lived infrastructure that is difficult to detect, attribut…HELPNETSECURITY.COM
31 JulGoogle adds to confusion with new names for threat actorsGoogle is creating a new naming scheme for the bad actors behind cybersecurity threats, hoping that it will help to standardize the way that attacks are reported. Spoiler: It won’t. Security researchers use these naming schemes so that they can attribute attacks without necessari…CSOONLINE.COM
31 JulThe $150 AI Attack ShortcutSome threat actors are reportedly packaging AI prompt injection techniques into subscription services. The discussion argues that the underlying method isn't especially difficult, yet people are still willing to pay for it. IMPLICATION That suggests the real product may not be te…YOUTUBE.COM
31 JulDefCon security conference bans smart glasses with recording capabilitiesIt’s a sign of the times: Security conference DefCon has added smart glasses to its list of banned audio- or video-recording devices . The organizers have said that, with no consistent way to understand whether smart glasses are recording or not, they have taken the step to ban t…CSOONLINE.COM
31 JulAnthropic says human error let Claude AI models escape test environment and hack third partiesThe company said its discovery, which followed OpenAI’s similar admission, proved the need for better testing guardrails.CYBERSECURITYDIVE.COM
31 JulUS authorities see ‘significant escalation’ in attacks on water system devicesHackers have locked operators out of their own OT networks, modified passwords and changed IP addresses.CYBERSECURITYDIVE.COM
31 JulAnthropic’s Opus 5 Is Better at Resisting Prompt InjectionThe chart is interesting. On the IPI benchmark, Opus 5 improved over Opus 4.8, reducing the probability of an attacker succeeding within 15 attempts from 5.5% to 2.0%, and from 0.5% to 0.2% on 1 attempt. It also improved on Sonnet 5 (5.9% at k=15) and Mythos 5 (2.6%), making it t…SCHNEIER.COM
31 JulKate Robertson on the Risks That Lie Behind Canada’s Unexpected Signing of the UN Cybercrime ConventionEarlier this month, the Canadian government announced that it had signed the United Nations Convention against Cybercrime. Speaking with Michael Geist of Law Bytes, senior research associate Kate Robertson argues that the convention is a cross-border surveillance and electr…CITIZENLAB.CA
31 JulFriday Squid Blogging: Squid Helps Discover New Marine SpeciesThe Squid is a new scientific machine : One of the technological breakthroughs was the onboard use of a spinning wheel confocal microscope, nicknamed the Squid, which uses lasers to scan microscopic details of how organisms are put together. “That opens up a whole new world…SCHNEIER.COM
31 JulDon't Give Everyone AI AgentsAs agentic AI becomes more capable, organizations are beginning to explore giving AI systems greater autonomy to complete tasks. The discussion argues that these systems should be treated as powerful tools that require governance rather than being deployed broadly without oversig…YOUTUBE.COM
31 JulCaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theftStorm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call Ca…MICROSOFT.COM
30 JulReconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner [Guest Diary], (Thu, Jul 30th)[This is a Guest Diary by Adam Cann, an ISC intern as part of the SANS.edu BACS program]
ISC.SANS.EDU
30 JulISC Stormcast For Thursday, July 30th, 2026 https://isc.sans.edu/podcastdetail/10030, (Thu, Jul 30th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
30 JulImpersonation protection: How to protect your executives when the truth isn’t clearHow do you protect your executives when truth doesn’t seem to be truth anymore? It’s a question BlackCloak Founder and CEO Dr. Chris Pierson recently discussed this dilemma with SVP of Product Matt Covington. Advances in AI, voice, and video impersonation make it difficult to est…HELPNETSECURITY.COM
30 JulProduct showcase: Dashlane Password Manager is more security toolkit than password vaultDashlane is a password manager for individuals and families that stores passwords, passkeys, payment cards, personal information and secure notes in an encrypted vault. It also includes a password generator, password health reports, an authenticator, credential sharing, dark web …HELPNETSECURITY.COM
30 JulChrome 151 Patches 370 VulnerabilitiesThe major browser update resolves roughly 80 critical- and high-severity security defects. The post Chrome 151 Patches 370 Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
30 JulUS and Allies Update SBOM GuidanceFive years after the initial release, the refresh introduces new elements, removes others, and updates terminology. The post US and Allies Update SBOM Guidance appeared first on SecurityWeek .SECURITYWEEK.COM
30 JulNorth Korea’s elite hackers turned on their own government – and got caughtFor years, North Korea's state-trained hackers have been one of the world's most prolific robbers of banks - stealing huge sums of money from foreign financial instituions, draining cryptocurrency exchanges of billions, and funnelling the proceeds into the country's weapons progr…BITDEFENDER.COM
30 JulCritical Ruflo Flaw Lets Attackers Spawn Rogue AI SwarmsUnauthenticated attackers could send HTTP requests to an exposed endpoint to execute commands inside the MCP bridge container. The post Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms appeared first on SecurityWeek .SECURITYWEEK.COM
30 Jul1 in 5 Data Center Assets Are Within Easy Reach of AttackersClaroty has analyzed 750,000 cyber-physical systems across some of the world’s largest data center facilities. The post 1 in 5 Data Center Assets Are Within Easy Reach of Attackers appeared first on SecurityWeek .SECURITYWEEK.COM
30 JulShould You Use AI for a Task? Here’s a Simple Way to DecideThis essay originally appeared in The Guardian . I teach public policy at the Harvard Kennedy School and the Munk School at the University of Toronto. And it will come as no surprise to you that my students regularly use AI to complete their writing assignments. Doing so is a was…SCHNEIER.COM
30 JulBlack Hat special: Rewind and revisitAmy looks back at the incredible journeys that brought past guests to the world of threat intelligence.TALOSINTELLIGENCE.COM
30 JulOctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central AsiaOur experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan networks, dump credentials, and keylogging.SECURELIST.COM
30 JulFTC sues Hims & Hers over alleged data privacy and billing violationsThe US Federal Trade Commission, joined by the state of Utah and California, has filed a lawsuit against telehealth provider Hims & Hers, accusing the company of secretly sharing sensitive health information with advertising platforms while misleading customers about its pre…CYBERINSIDER.COM
30 JulDropzone AI turns threat hunting into a routine SOC operationDropzone AI has announced the general availability of AI Threat Hunter, its proactive threat hunting agent. The tool enables security teams to run structured hunt packs across their environments to identify hidden threats, emerging risks, and security coverage gaps that tradition…HELPNETSECURITY.COM
30 JulOrca Security secures AI-built and developer-created applicationsOrca Security has announced two new AI-powered capabilities: Orca AI AppGen Security, which discovers and secures AI applications built outside the development pipeline on AI-powered platforms like Claude, Supabase, and Lovable, and AI Code Security Auditor, which delivers deep A…HELPNETSECURITY.COM
30 JulAttackers are using Microsoft’s legitimate login system to camouflage phishing attacksAttackers are moving away from fake Microsoft login pages in favor of abusing Microsoft’s own authentication system, letting phishing campaigns slip past the warning signs employees are trained to spot, according to Check Point. Between June 25 and the second week of July, …HELPNETSECURITY.COM
30 JulCantina Emerges From Stealth With $8 Million in FundingThe startup’s community-powered agentic security platform helps proactively identify, prioritize, and remediate vulnerabilities. The post Cantina Emerges From Stealth With $8 Million in Funding appeared first on SecurityWeek .SECURITYWEEK.COM
30 JulOnyx Security Raises $113 Million to Control AI Agents in the EnterpriseThe Series B funding round brings the total raised by Onyx Security to $153 million. The post Onyx Security Raises $113 Million to Control AI Agents in the Enterprise appeared first on SecurityWeek .SECURITYWEEK.COM
30 Jul‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global ScaleResearchers warn that AI could turn dangling DNS takeovers into a nation-state weapon capable of disrupting governments, banks and global supply chains. The post ‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale appeared first on SecurityWeek .SECURITYWEEK.COM
30 JulDataBahn Raises $40 Million for Agentic Data Pipeline ManagementThe company will accelerate investments in R&D and product innovation to expand its agentic data control plane. The post DataBahn Raises $40 Million for Agentic Data Pipeline Management appeared first on SecurityWeek .SECURITYWEEK.COM
30 JulDiscern Security Raises $13 Million in Series A FundingThe company will invest in accelerating the development and adoption of its agentic platform. The post Discern Security Raises $13 Million in Series A Funding appeared first on SecurityWeek .SECURITYWEEK.COM
30 JulGhanaian national sentenced to 7 years in prison for stealing $10M from romance scam victimsDerrick Van Yeboah impersonated fake romantic partners and directly interacted with victims for more than nine years. The post Ghanaian national sentenced to 7 years in prison for stealing $10M from romance scam victims appeared first on CyberScoop .CYBERSCOOP.COM
30 JulWe know how to protect our troops from telecom attacks. We’re just not doing it.The post We know how to protect our troops from telecom attacks. We’re just not doing it. appeared first on CyberScoop .DEFENSESCOOP.COM
30 JulNovee brings continuous AI pentesting to mobile appsNovee announced the expansion of its AI penetration testing platform to mobile applications. With this addition, Novee becomes the industry’s first complete AI pentesting platform across the modern application attack surface, providing continuous, autonomous coverage. The platfor…HELPNETSECURITY.COM
30 JulAmerican Being Prosecuted for Wiping His Phone Before Handing It Over to Border OfficialsHe’s being prosecuted for giving border officials a code that wiped his phone : The case centers on a feature included in GrapheneOS, a custom Android operating system that runs in place of the software on most modern Google Pixel devices. Tunick’s attorneys confirmed…SCHNEIER.COM
30 JulJscrambler launches Unified Client-Side Security PlatformJscrambler launched its Unified Client-Side Security Platform, introducing a new approach to securing applications and customer data where AI-powered risks increasingly operate: inside the browser. “AI didn’t create browser risk—it dramatically accelerated it,” said Rui Ribeiro, …HELPNETSECURITY.COM
30 JulWhat’s new in Microsoft Security: July 2026This month’s updates help security and IT teams secure their AI environments, use AI to defend, and strengthen the foundations that AI-powered operations depend on. The post What’s new in Microsoft Security: July 2026 appeared first on Microsoft Security Blog .MICROSOFT.COM
30 JulOkta to Acquire Identity Threat Detection Firm PermisoThe deal extends Okta's reach beyond identity management and into the realm of security operations, positioning the company to compete more directly on identity threat detection and response. The post Okta to Acquire Identity Threat Detection Firm Permiso appeared first on Securi…SECURITYWEEK.COM
30 JulOkta’s deal for Permiso aims to close gaps in identity threat detectionEly Kahn, Okta's chief product officer, told CyberScoop the deal enriches the company's current threat detection tools and gives it deeper visibility into AI agent activity across enterprise systems. The post Okta’s deal for Permiso aims to close gaps in identity threat detection…CYBERSCOOP.COM
30 JulBank of America to Acquire Cybersecurity Firm MDSecThe acquisition will add approximately 65 cybersecurity professionals to Bank of America’s operations in the United Kingdom. The post Bank of America to Acquire Cybersecurity Firm MDSec appeared first on SecurityWeek .SECURITYWEEK.COM
30 JulThe State of Network Infrastructure Security 2026The post The State of Network Infrastructure Security 2026 appeared first on Eclypsium | Supply Chain Security for the Modern Enterprise .ECLYPSIUM.COM
29 JulISC Stormcast For Wednesday, July 29th, 2026 https://isc.sans.edu/podcastdetail/10028, (Wed, Jul 29th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
29 JulAndroid malware detection collapses when the context stage comes outA phone backup app asks for storage, contacts, SMS, and call logs. A device-management tool asks for more than that. Run either one past a machine learning malware scanner and it comes back flagged. Six Android detectors in wide research use, including Drebin, MalScan, and MaskDr…HELPNETSECURITY.COM
29 JulAn AI agent can pass every safety check and still leak secretsA pull request lands with a tidy bug report in the description. A bot reads it before any person does, pulls a few shell commands out of it, gets them approved, and posts the output back on the thread. The maintainer reads the whole exchange the next morning. Elad Meged, a foundi…HELPNETSECURITY.COM
29 JulShinyHunters Claims Ernst & Young HackErnst & Young previously confirmed that personal and financial information was stolen from a third-party management platform. The post ShinyHunters Claims Ernst & Young Hack appeared first on SecurityWeek .SECURITYWEEK.COM
29 JulA Farewell from Sherrod: New Season Coming SoonAs we close out season three of the podcast, Sherrod offers her farewell message as she takes on a new threat intelligence leadership role outside of Microsoft. Our executive producer also joins to briefly share our plans for season four, with new faces and voices joining future …THECYBERWIRE.COM
29 JulDozens of Minnesota Water Utilities Targeted in Coordinated OT AttacksState and federal agencies respond after intrusions disrupt automated controls at municipal water and wastewater utilities. The post Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
29 JulRealm Security adds Detection Integrity and Data Haven Search to cut SIEM costsRealm Security has announced two new capabilities. Detection Integrity proves that reducing SIEM log volume never breaks a threat detection. New search inside Realm Data Haven, the platform’s searchable retention layer, makes the data you keep out of the SIEM directly query…HELPNETSECURITY.COM
29 JulTines introduces AI-native platform for secure enterprise workflow automationTines has launched Tines 3B, an AI-native platform for building, running and governing enterprise workflows, applications and agents securely at scale. AI has made it possible for every employee to build software in minutes. The result is an explosion of vibe-coded software sprea…HELPNETSECURITY.COM
29 JulZeroFox unveils HNTR and Executive Protection for AI-driven threat detectionZeroFox has launched HNTR, a new AI-first platform that brings digital risk protection and threat intelligence together to discover, validate, and disrupt threats, alongside the new platform’s first application, HNTR Executive Protection. HNTR is built on more than a decade of op…HELPNETSECURITY.COM
29 JulStolen Meta and Google ad accounts are worth more than the money they holdAd account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy complete with tiered pricing, escrow services, and money-back warranties for stolen accounts. Public reporting on this topic tends to …HELPNETSECURITY.COM
29 Jul1Password targets standing privileges with new access management capabilities1Password has launched 1Password Privileged Access, extending the 1Password Unified Access platform with privileged access management (PAM). It enables just-in-time, least-privilege access to critical infrastructure and is accompanied by the public preview of 1Password Credential…HELPNETSECURITY.COM
29 JulTorq makes AI SOC investigations continuously self-learningTorq has introduced Torq SOC Brain, a new layer of the Torq AI SOC Platform that continuously learns from historical investigations, analyst decisions, and organization-specific security operations to create a unified, self-learning AI SOC. While most autonomous investigation sys…HELPNETSECURITY.COM
29 JulSpur Raises $200 Million for IP Intelligence PlatformThe IP intelligence company will use the fresh investment to accelerate and scale its operations. The post Spur Raises $200 Million for IP Intelligence Platform appeared first on SecurityWeek .SECURITYWEEK.COM
29 JulWhatsApp Web gets end-to-end encrypted voice and video callsMeta has announced a series of new calling features for WhatsApp, including the ability to make and receive voice and video calls directly from WhatsApp Web without installing the desktop app. The update also introduces call transfers between devices, waiting rooms for group call…CYBERINSIDER.COM
29 JulUS, Australia Release OT Isolation Guidance for Critical InfrastructureThe guidance details steps organizations can take to isolate vital OT and supporting systems, and operate in isolation for an extended period. The post US, Australia Release OT Isolation Guidance for Critical Infrastructure appeared first on SecurityWeek .SECURITYWEEK.COM
29 JulOpenAI’s Rogue AI Ventured Beyond Hugging FaceHugging Face has published an anatomy of the attack and OpenAI has shared additional information from its investigation. The post OpenAI’s Rogue AI Ventured Beyond Hugging Face appeared first on SecurityWeek .SECURITYWEEK.COM
29 JulCloudflare reveals what’s behind major internet outagesStorms, earthquakes, and infrastructure failures disrupted internet access throughout the second quarter, while governments deliberately shut networks down, according to Cloudflare’s latest Internet Disruption Summary. Based on Cloudflare Radar traffic data, the report cove…HELPNETSECURITY.COM
29 JulMIND AI DLP Agents automate DLP classification, investigations and remediationMIND has announced MIND AI DLP Agents with capabilities focused on classification, investigation, policies, remediation and exception management. MIND also includes a Model Context Protocol (MCP) interface that enables security teams to direct data security work through any MCP-c…HELPNETSECURITY.COM
29 JulRussia accuses Telegram founder of aiding terrorism, seeks international arrestRussia is seeking to place Telegram founder Pavel Durov on an international wanted list, alleging that the app has been used by Ukrainian intelligence to organize terrorist attacks and conduct espionage inside Russia.THERECORD.MEDIA
29 JulMate Security Raises $35 Million for Agentic SOCThe startup will use the investment to expand its customer support, sales, and R&D teams. The post Mate Security Raises $35 Million for Agentic SOC appeared first on SecurityWeek .SECURITYWEEK.COM
29 JulThreatLocker Raises $190 Million in Series F FundingThe company was previously valued at $1.6 billion, and the latest raise has significantly increased that valuation. The post ThreatLocker Raises $190 Million in Series F Funding appeared first on SecurityWeek .SECURITYWEEK.COM
29 JulRussia charges Telegram founder Pavel Durov with facilitating terrorismRussia's Federal Security Service (FSB) claims that Ukrainian intelligence services used the popular Telegram dating chatbot “Daivinchik/Leo” to recruit Russian citizens, including minors, into sabotage and terrorist activities through deception and psychological mani…CYBERINSIDER.COM
29 JulUS Bans Foreign-Made Humanoid Robots, Targeting China Over National SecurityThe agency said imports of advanced robots pose cybersecurity and other national security risks. The post US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security appeared first on SecurityWeek .SECURITYWEEK.COM
29 JulAI Productivity Comes With a CostAI increases productivity, but productivity gains don't necessarily translate into more free time. As coding assistants and agentic AI become more capable, organizations can expect individual developers to oversee many more projects simultaneously. Higher output can quickly becom…YOUTUBE.COM
29 JulHuntress warns about attack spree that hit 30 SonicWall customers in 2 daysUnknown attackers broke into 92 unique SonicWall user accounts with legitimate credentials, researchers said. The post Huntress warns about attack spree that hit 30 SonicWall customers in 2 days appeared first on CyberScoop .CYBERSCOOP.COM
29 JulBetter security starts with better questionsLearn how better questions, trusted AI, and human judgment help security leaders make confident decisions and build resilient systems. The post Better security starts with better questions appeared first on Microsoft Security Blog .MICROSOFT.COM
29 JulSupply chain challenges loom large in quantum race, White House official saysBrad Blakestad, director of the National Quantum Coordination Office, also said encryption and measuring progress would pose challenges. The post Supply chain challenges loom large in quantum race, White House official says appeared first on CyberScoop .CYBERSCOOP.COM
29 JulThe AI Productivity Pay GapMany organizations expect AI to improve profit margins through higher productivity. But AI adoption still depends on people managing workflows, making decisions, and delivering results. As output increases, some employees feel their compensation hasn't kept pace. Productivity gai…YOUTUBE.COM
29 JulSmashing Security podcast #478: This job interview could destroy your companyYou've been headhunted for a great job in cryptocurrency. All you have to do is complete a short online assessment - with your webcam on, of course, so they can verify who you really are. Which is ironic, because the person recruiting you doesn't exist. And North Korean hackers u…GRAHAMCLULEY.COM
28 JulISC Stormcast For Tuesday, July 28th, 2026 https://isc.sans.edu/podcastdetail/10026, (Tue, Jul 28th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
28 JulDownload: The High-Performance Team PlaybookGet practical insight from teams who’ve built, scaled and handed over engineering functions at enterprise level. Most engineering teams don’t fail because of bad engineers. They fail because performance is assumed. This playbook shows how high-performance teams are built intentio…HELPNETSECURITY.COM
28 JulCall of Duty Mobile scam uses fake free points giveaway to hijack players’ accountsCall of Duty Mobile players should watch out for a phishing campaign disguised as a free Call of Duty Points giveaway, Malwarebytes researchers have warned. Victims are asked to log in with their email address and password to claim free Call of Duty Points (CP), the game’s …HELPNETSECURITY.COM
28 JulAI took more than junior developer jobs and the bill comes laterA ticket comes in for a small bug fix. Hand it to the junior on your team and you wait a day, review something that half works, and sit down to explain what went wrong. Describe it to Claude and the patch merges before lunch. The second path wins on every number your team reports…HELPNETSECURITY.COM
28 JulAutoIT Payload Injector , (Tue, Jul 28th)For a long time, AutoIT[ 1 ] has been pretty common in the malware ecosystem. Threat actors still use it because it's easy to write and powerful. Indeed, it can perform all the required actions to inject a payload into a remote process as you'll see below.
ISC.SANS.EDU
28 JulGoogle Adopts New Threat Actor Naming SystemThe new two-word naming convention uses a memorable term utilized in public reporting and a cluster-categorization word. The post Google Adopts New Threat Actor Naming System appeared first on SecurityWeek .SECURITYWEEK.COM
28 JulGrafana Assistant expands with AI agents for investigations, automation, and observabilityGrafana Labs has announced the general availability of six AI capabilities, extending Grafana Assistant into an agentic operations layer that detects, investigates, and remediates production issues. The releases include Grafana Assistant Investigations, Grafana Assistant Workspac…HELPNETSECURITY.COM
28 JulAWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027AWS Shield Advanced, a managed service that protects applications from external threats, is adding the Anti-DDoS managed rule group, designed for application-layer (L7) DDoS protection, to eligible web access control lists (ACLs) in Count mode. The addition preserves traffic flow…HELPNETSECURITY.COM
28 JulMurder in Mexico City: The Assassination of Leon TrotskyFor those of you who have visited the International Spy Museum, you may be familiar with one of our most prized artifacts, the ice ax used to assassinate Leon Trotsky in 1940. Trotsky was the operational mastermind of the Russian Revolution of 1917, and when Vladimir Lenin died, …THECYBERWIRE.COM
28 JulHacker Conversations: Tal Kollander’s Journey From Black Hat to Hack BlockerTal Kollander’s history divides neatly into two halves: first as an active hacker and then as the block that stops hacks. The post Hacker Conversations: Tal Kollander’s Journey From Black Hat to Hack Blocker appeared first on SecurityWeek .SECURITYWEEK.COM
28 JulAct Security Emerges from Stealth to Fight the Patch ProblemAct Security tackles the spiraling patch problem caused by AI’s ability to find new vulnerabilities in existing cloud environments. The post Act Security Emerges from Stealth to Fight the Patch Problem appeared first on SecurityWeek .SECURITYWEEK.COM
28 JulHush Security Raises $30 Million for AI Agent GovernanceThe startup will invest in expanding engineering and sales teams, accelerating ecosystem support, and expanding corporate partnerships. The post Hush Security Raises $30 Million for AI Agent Governance appeared first on SecurityWeek .SECURITYWEEK.COM
28 JulAxon Is Another License Plate Surveillance CompanyGovernments are switching, but I’m not sure it makes a difference : …some municipalities, including Denver, Colorado, are ditching their Flock arrays. But keep in mind that if they’re only switching from Flock to another brand of license-plate readers, like Axon…SCHNEIER.COM
28 JulMicrosoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI ModelThe company claims MAI-Cyber-1-Flash tops Anthropic’s Mythos and OpenAI’s GPT-5.6 Sol in CyberGym testing. The post Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model appeared first on SecurityWeek .SECURITYWEEK.COM
28 JulOT Security Startup Frenos Raises $1.52 MillionThe company will use the fresh investment to grow its customer success and AI R&D teams. The post OT Security Startup Frenos Raises $1.52 Million appeared first on SecurityWeek .SECURITYWEEK.COM
28 JulCyberhaven launches Flow to secure data across human and AI workflowsCyberhaven has introduced Cyberhaven Flow, an AI-native data security platform built to protect data across human and AI workflows. Flow connects lineage, identity, and behavior to protect data as it is created, copied, fragmented, and shared, marking a shift in how protection ad…HELPNETSECURITY.COM
28 JulIntel 471 expands Verity471 with AI agent and MCP support for threat intelligenceIntel 471 has announced two new AI capabilities in the Verity471 platform, MCP471 and Agent471. As attackers use AI to lower the barrier to scale, security teams must use their own AI capabilities to make intelligence more accessible, allowing them to pinpoint what is relevant to…HELPNETSECURITY.COM
28 JulSpecterOps brings AWS attack path management and AI to hybrid identity securitySpecterOps has announced new capabilities built to give defenders a dynamic understanding of how adversaries traverse their hybrid environment and the ability to proactively eliminate pathways before they can be abused. BloodHound Enterprise adds support for Amazon Web Services a…HELPNETSECURITY.COM
28 JulBlackCloak extends deepfake protection to the executive’s trusted circleDeepfakes have made one of our oldest assumptions unreliable: that you can trust a familiar face or voice. While the industry focuses mainly on building “in-line detection tools” that try to spot the fake, BlackCloak, the leader in Digital Executive Protection (DEP), built Impers…HELPNETSECURITY.COM
28 JulPrescient Security adds attack surface management to Cait, broadens AI-assisted pentestingPrescient Security has announced a series of capability expansions to Cait (Cacilian AI), its continuous AI-assisted penetration testing service. The updates which will roll out through summer 2026 add attack surface management (ASM), new asset testing types and expanded environm…HELPNETSECURITY.COM
28 JulCyera Acquiring Oasis Security in $1 Billion DealOasis Security recently raised $120 million in Series B funding for its agentic access management platform. The post Cyera Acquiring Oasis Security in $1 Billion Deal appeared first on SecurityWeek .SECURITYWEEK.COM
28 JulApple Patches 87 Vulnerabilities in iOS, 155 in macOS TahoeApple announced that dozens of vulnerabilities have been patched in each of its operating systems. The post Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe appeared first on SecurityWeek .SECURITYWEEK.COM
28 JulDisrupting supply chain attacks on npm and GitHub ActionsExplore the changes we've shipped across npm and GitHub Actions over the past few months to disrupt supply chain attack techniques and limit their impact. The post Disrupting supply chain attacks on npm and GitHub Actions appeared first on The GitHub Blog .GITHUB.BLOG
28 JulMicrosoft launches agentic security platform designed to combat AI-based attacksThe rollout comes amid growing concerns about the ability of hackers to launch campaigns using autonomous methods. CYBERSECURITYDIVE.COM
28 JulCompanies fear AI risks more than common cybersecurity threatsThat misprioritization could blind companies to the threats they should be focusing on, Arctic Wolf said in a new report.CYBERSECURITYDIVE.COM
28 JulItaly fines US data broker Lusha €2 million over unlawful data collectionItaly's data protection authority has fined US-based data broker Lusha Systems Inc. €2 million (approximately $2.3 million) for unlawfully collecting, enriching, and selling personal data belonging to a large number of individuals in Italy. Lusha operates a subscription-based pla…CYBERINSIDER.COM
28 JulCo-Founder of Controversial Spyware Firm Had Israeli Diplomatic PassportThe OCCRP found that the co-founder of NSO Group, which develops Pegasus spyware, travelled to Panama in 2013 on an Israeli diplomatic passport. The post Co-Founder of Controversial Spyware Firm Had Israeli Diplomatic Passport appeared first on The Citizen Lab .CITIZENLAB.CA
28 JulAI Is Flooding Bug BountiesGitHub is shifting more emphasis toward an invite-only bug bounty program, while other projects have reduced or ended public programs after receiving large volumes of low-quality reports. Many of these submissions are generated from AI tools or automated scanners without proper v…YOUTUBE.COM
28 JulHere’s what Anthropic found when it turned Mythos loose on encryption algorithmsClaude Mythos exposed mathematical weaknesses in a post-quantum candidate and a simplified version of AES, marking a major breakthrough for AI-driven cryptanalysis. The post Here’s what Anthropic found when it turned Mythos loose on encryption algorithms appeared first on C…CYBERSCOOP.COM
28 JulDeep Fakes, Molten Salt, PLCS, Checkpoint, Hugging Face, CENTOS, Josh Marpet and More - SWN #602Deep Fakes, Molten Salt, PLCS, Checkpoint, Hugging Face, CENTOS, Josh Marpet, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-602YOUTUBE.COM
28 JulIndustrial Controllers Are Under AttackU.S. cybersecurity agencies are warning that a campaign targeting programmable logic controllers (PLCs) has expanded from one major vendor to include multiple leading industrial automation manufacturers. PLCs are foundational components of industrial control systems (ICS) and ope…YOUTUBE.COM
27 JulISC Stormcast For Monday, July 27th, 2026 https://isc.sans.edu/podcastdetail/10024, (Mon, Jul 27th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
27 JulGitHub delays version updates so malware gets caught firstAn automated update tool watches a package registry, catches a new release the moment it publishes, and opens a pull request for your team. That is the job it was built to do. In September 2025, that speed cut the wrong way. An attacker phished one npm maintainer’s credenti…HELPNETSECURITY.COM
27 JulProduct showcase: LastPass Authenticator brings Face ID, Apple Watch, and cloud backup to 2FALastPass Authenticator is a free app that provides two-factor authentication (2FA) for accounts and any service that supports time-based one-time passwords (TOTP). It supports push notifications for one-tap approvals and generates six-digit verification codes for online accounts.…HELPNETSECURITY.COM
27 JulGrapheneOS defends security model after US prosecutors target userGrapheneOS has published a detailed explanation of its security architecture after The Guardian reported on a US criminal case in which federal prosecutors are attempting to use a privacy-focused operating system as part of their case against an Atlanta activist linked to the Sto…CYBERINSIDER.COM
27 JulTELESHIM Abuses Telegram for C2 in Attacks Against Middle East GovernmentsCybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East. The intrusions have resulted in the deployment of previously unreported malware families dubbed TELESHIM, MIXEDKEY, and…THEHACKERNEWS.COM
27 JulBeelzebub Raises $3.4 Million for Hacker-Trapping PlatformThe company plans to expand its research team, open new offices in Rome and San Francisco, and acquire new clients. The post Beelzebub Raises $3.4 Million for Hacker-Trapping Platform appeared first on SecurityWeek .SECURITYWEEK.COM
27 JulWhat’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find OutThe new Mobile Security Exposure Center creates SBOMs for enterprise mobile apps to uncover vulnerable components, dependencies and hidden risks. The post What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out appeared first on SecurityWeek .SECURITYWEEK.COM
27 JulNew AI attack can reconstruct typed text from keyboard soundsResearchers have developed a new acoustic side-channel attack that can reconstruct text typed on a laptop by analyzing nothing more than the sound of keystrokes. Unlike previous approaches, the method does not require attackers to first train the system on recordings from the vic…CYBERINSIDER.COM
27 JulSen. Wyden urges feds to discard older, insecure, public-facing VPNsIn a letter first reported by CyberScoop, Ron Wyden, D-Ore., said ‘devastating’ attacks on the federal government have accumulated due to the tech. The post Sen. Wyden urges feds to discard older, insecure, public-facing VPNs appeared first on CyberScoop .CYBERSCOOP.COM
27 JulNvidia and Tech Giants Launch AI Security AllianceThe Nvidia-led coalition aims to give defenders more open tools for testing, auditing and protecting AI models and agents. The post Nvidia and Tech Giants Launch AI Security Alliance appeared first on SecurityWeek .SECURITYWEEK.COM
27 Jul7AI expands platform with Federated SIEM and AI workflow builder7AI has announced two major platform capabilities: 7AI Federated SIEM, which lets security teams query, investigate, and act on data wherever it lives, including within 7AI, and 7AI Build, which lets enterprises and partners define agentic workflows, skills, and AI-native securit…HELPNETSECURITY.COM
27 JulC1 adds shadow AI discovery to its identity governance platformC1 has launched shadow AI discovery to eliminate the massive security blind spots created by unauthorized AI agents, tools, and credentials. By automatically discovering and folding every AI-adjacent identity into C1’s existing identity governance platform, organizations can fina…HELPNETSECURITY.COM
27 JulGoogle changes how it names cyber threat actorsGoogle Threat Intelligence Group (GTIG) has started using a new naming system for the threat actors it tracks. The change comes after Mandiant and Google’s Threat Analysis Group (TAG) merged into one unit, leaving the company with two separate naming schemes built up over y…HELPNETSECURITY.COM
27 JulNew GitHub, PyPI Policies Boost Supply Chain SecurityDependabot gets a three-day cooldown window before opening pull requests, and PyPI rejects file uploads to releases older than 14 days. The post New GitHub, PyPI Policies Boost Supply Chain Security appeared first on SecurityWeek .SECURITYWEEK.COM
27 JulGoogle’s solution to hacker name confusion? Yet another naming systemAPT-number conventions are out, cryptonyms are in, and security teams now have one more naming system to keep straight. The post Google’s solution to hacker name confusion? Yet another naming system appeared first on CyberScoop .CYBERSCOOP.COM
27 JulEnhancing AI security through global AI red teamingMicrosoft's External Red Team Alliance (EXTRA) is a global AI security initiative designed to advance AI safety research and red teaming. By partnering with universities, researchers, and regional experts, EXTRA helps identify emerging AI risks, improve security testing, and stre…MICROSOFT.COM
27 JulTrump asks Supreme Court to let him curtail mail-in voting ahead of midtermsIn a Monday filing, the Justice Department said states sued before agencies even decided how the order would work. The post Trump asks Supreme Court to let him curtail mail-in voting ahead of midterms appeared first on CyberScoop .CYBERSCOOP.COM
26 JulClaude Opus 5 sharpens coding and cybersecurity work on AWSClaude Opus 5 went live on Amazon Bedrock and Claude Platform on AWS. Anthropic says the model improves on Claude Opus 4.8’s cyber capabilities, coding through cybersecurity. Anyone with an AWS account in a supported region can call it. On higher-risk requests, Opus 5 hands…HELPNETSECURITY.COM
25 JulCold lures, hot targets.This week, we are joined by Ondrej Kubovič, Security Awareness Specialist from ESET, discussing their work on "FrostyNeighbor: Fresh mischief and digital shenanigans." Ondrej walks us through ESET's latest research into FrostyNeighbor, a long-running Belarus-aligned cyberespi…THECYBERWIRE.COM
24 JulISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
24 JulNew infosec products of the week: July 24, 2026Here’s a look at the most interesting products from the past week, featuring releases from Astelia, Druva, Swimlane, and ThreatDown. Druva brings backup, recovery and governance to AI workloads Druva has announced Druva AI Resilience, a new approach that helps organizations recov…HELPNETSECURITY.COM
24 JulThe best-funded companies open the most phishing attachmentsAn employee gets an email dressed as a password reset. She clicks the link, types her credentials into a page built to copy her company’s login screen, and moves on with her morning. She tells no one. That silence is the exposure. Across 13.9 million simulated phishing mess…HELPNETSECURITY.COM
24 JulGoverning Al agents at scale: Lessons from the leaders who’ve done itEnterprise AI leaders from ZoomInfo, Docusign and AppViewX share what it took to build AI Centers of Excellence and govern agent identities inside two companies operating at scale. What you’ll take away: What an AI Center of Excellence looks like day to day at ZoomInfo and …HELPNETSECURITY.COM
24 JulThe automotive software vulnerabilities hiding in your dashboardPop the hood on a new car and you won’t find much you can fix with a wrench. What you’ll find is software, and a lot of it. The screen in the dash probably runs Android or a flavor of Linux. The system watching the road for you might run QNX or VxWorks, the same kind …HELPNETSECURITY.COM
24 JulMicrosoft tightens Windows enterprise activation securityMicrosoft is making Trusted Platform Module (TPM)-backed attestation a requirement for Windows Key Management Service (KMS), the on-premises service used for Windows volume activation, replacing the software-only trust model with hardware-backed verification to strengthen enterpr…HELPNETSECURITY.COM
24 JulGolden Chickens Resurfaces With Four New Malware Families and Modular ImplantsThe threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings. The malware families i…THEHACKERNEWS.COM
24 JulTop AIs invent same fake PyPl and npm package namesEnterprise software developers continue to be in danger of falling victim to slopsquatting, where AI coding tools hallucinate the existence of nonexistent libraries and hackers create malicious packages in response. The top AI coding tools are remarkably consistent in their hallu…CSOONLINE.COM
24 JulTor pauses new feature development to perform privacy audit on Firefox 153The Tor Project has paused new feature development for Tor Browser 16 as developers work through more than 250 changes inherited from Firefox ESR 153 to ensure they do not weaken the browser's privacy and anonymity protections. The announcement accompanied the release of Tor Brow…CYBERINSIDER.COM
24 JulWhy AI Needs a “Genie Coefficient”This essay was written with Barath Raghavan, and originally appeared in The Guardian . Major benchmarks measure what AI can do. None measure whether it does what you mean: the distance between what you ask an AI to do and the unspoken assumptions about how you want the AI to do i…SCHNEIER.COM
24 JulAegisAI Raises $36 Million for AI-Powered Email SecurityThe company has raised a total of $49 million in funding, including from Battery Ventures, Accel and Foundation Capital. The post AegisAI Raises $36 Million for AI-Powered Email Security appeared first on SecurityWeek .SECURITYWEEK.COM
24 JulIndustry Reactions to OpenAI Models Hacking Hugging Face: Feedback FridayIndustry professionals debate whether it represents a lab containment failure or an unprecedented agentic capability milestone. The post Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday appeared first on SecurityWeek .SECURITYWEEK.COM
24 JulHackers use DNS poisoning on hotel Wi‑Fi to steal Microsoft 365 accountsThreat actors are compromising hotel and conference center Wi-Fi gateways to redirect travelers to fake Microsoft login pages and steal corporate accounts. The campaign has been active since at least June 2026 and appears to reuse techniques previously associated with the Russian…CYBERINSIDER.COM
24 JulAI's Biggest Hidden Security FlawModern LLMs process prompts by predicting the next token from context. They don't inherently distinguish system instructions from user instructions, and many "reasoning" models use the same underlying architecture while producing reasoning-style text. That makes prompt or command…YOUTUBE.COM
24 JulThe most vulnerable AI products are also some of the most commonly exposed onlineIt is becoming increasingly easy for hackers to target vulnerable AI tools on companies’ networks, even as those companies come to depend on them for more tasks.CYBERSECURITYDIVE.COM
24 JulFriday Squid Blogging: Illex Squid Catch in the FalklandsLower catch this year . As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.SCHNEIER.COM
24 JulRogue AI Vehicle Porn, OpenAI, Nudes, Clop, Patches, Oracle, Palo Alto, Aaran Leyland - SWN #601Rogue AI Vehicle Porn, OpenAI, Nudes, Clop, Patches, Oracle, Palo Alto, Aaran Leyland, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-601YOUTUBE.COM
23 JulISC Stormcast For Thursday, July 23rd, 2026 https://isc.sans.edu/podcastdetail/10020, (Thu, Jul 23rd)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
23 JulThe AI code vulnerabilities that grow with your appTheori built 28 apps with AI coding agents and scanned each one through its pentesting platform. Five models did the building, split between Anthropic and OpenAI, across apps written from a spec, thrown together from a casual prompt, and rewritten from an aging PHP codebase. The …HELPNETSECURITY.COM
23 JulShadow AI is becoming enterprise security’s biggest blind spotArtificial intelligence has moved from experimentation to everyday business operations with remarkable speed. Employees are using it to summarize documents, draft communications, analyze spreadsheets, write code, build automations, and create AI-powered workflows across nearly ev…HELPNETSECURITY.COM
23 JulProduct Showcase: AppViewX Agent Identity SecurityAI is multiplying enterprise identities as quantum computing reshapes the cryptographic trust that secures them, and enterprises need to solve both together. Traditional identity security was built for people with predictable, auditable access, not autonomous, short-lived agents …HELPNETSECURITY.COM
23 JulAxonius expands Asset Cloud with Cyber Assets and Exposures enhancementsAxonius has announced new capabilities across the Axonius Asset Cloud to better address asset intelligence and exposure management use cases. The enhancements make it easier than ever to address CMDB visibility gaps and respond to vulnerabilities, while extending asset intelligen…HELPNETSECURITY.COM
23 JulAssaf Keren Appointed New CISO of MetaHe replaces Guy Rosen, who announced his retirement from the company after 13 years. The post Assaf Keren Appointed New CISO of Meta appeared first on SecurityWeek .SECURITYWEEK.COM
23 JulNew Dolphin X infostealer uses AI to identify high-value victimsA newly identified Windows malware called Dolphin X combines information-stealing capabilities with remote access features while targeting credentials from more than 300 applications. The malware also includes an AI-powered profiler that automatically ranks infected users, helpin…CYBERINSIDER.COM
23 JulNuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI ModelsSentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot. The post Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models appeared first on SecurityWeek .SECURITYWEEK.COM
23 JulClick. Click. Fake it until they make it… insideTL;DR The Problem In this online world it’s been easier than ever to order what you need, when you need and to the exact specifications you want… mostly. The clothing world, alongside many other sectors, is plagued by fakes to t…PENTESTPARTNERS.COM
23 JulMozilla releases Thunderbird 153 with native Microsoft Exchange supportThunderbird 153 “Meadow” has been released, introducing native Microsoft Exchange support alongside a redesigned account setup experience, user interface improvements, and security fixes. The update marks the first time Exchange accounts can be configured directly in …CYBERINSIDER.COM
23 JulAbstract Raises $25 Million to Expand Composable Security Operations PlatformThe latest investment round brings the total raised by Abstract to nearly $50 million. The post Abstract Raises $25 Million to Expand Composable Security Operations Platform appeared first on SecurityWeek .SECURITYWEEK.COM
23 JulRussian Global Webmail EspionageUnit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post Russian Global Webmail Espionage appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
23 JulChick-fil-A Accounts Get Fried in Credential Stuffing AttackThreat actors used credentials obtained from other companies to hack into Chick-fil-A One accounts. The post Chick-fil-A Accounts Get Fried in Credential Stuffing Attack appeared first on SecurityWeek .SECURITYWEEK.COM
23 JulThe case for a cooldown: Why Dependabot now waits before issuing version updatesA new default three-day cooldown delays version update pull requests so maintainers and security researchers can address findings in a release before it gets into your code. The post The case for a cooldown: Why Dependabot now waits before issuing version updates appeared first o…GITHUB.BLOG
23 JulOpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI InsiderAgentForger allows an attacker to create, insert and remotely control an invisible autonomous AI agent inside a victim organization. The post OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider appeared first on SecurityWeek .SECURITYWEEK.COM
23 JulEmail threat landscape: Q2 2026 trends and insightsIn the second quarter of 2026, the continuing effects of Microsoft’s disruption of the Tycoon2FA phishing platform contributed to sustained declines in several major phishing techniques, while threat actors expanded into Teams-based social engineering and employed increasingly au…MICROSOFT.COM
22 JulISC Stormcast For Wednesday, July 22nd, 2026 https://isc.sans.edu/podcastdetail/10018, (Wed, Jul 22nd)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
22 JulSmall teams are the heaviest users of AI coding agentsThe pull request arrives with the tests already run and the description already written, the work of an agent that handled the whole thing on its own. Somebody still has to read it. On GitHub that somebody is usually one developer sitting alone with the diff, and the rest of the …HELPNETSECURITY.COM
22 JulAI's Disruption as Cybersecurity’s Economics Are Broken, Compounding Security Debt - BSW #457America has lived through technological and economic upheaval before. Farm workers moved to factories. Factory workers moved into services. New industries replaced old ones. Productivity rose. Living standards improved. But are we ready for the greatest disruption in American his…YOUTUBE.COM
22 JulAI models cheat on cybersecurity evaluations, then fail to admit itFrontier AI models will take just about any route to finish a task, cheating included, according to new cybersecurity evaluations from the UK government’s AI Security Institute (AISI). AISI defines cheating as a model doing something outside the bounds of what a task allows…HELPNETSECURITY.COM
22 JulFirst-Person Identity Theft StoryHarrowing story of an identity theft victim. Yes, the person made a mistake—they gave the scammer a two-factor authentication code that allowed the scammer to take over their email address. But the real story here is how, for many of us, the security of most of our accounts…SCHNEIER.COM
22 JulBox expands enterprise AI governance with new agent security featuresoxBox has announced new security capabilities designed to give organizations greater control over AI agents working with enterprise content. With new agent guardrails, third-party agent activity oversight, prompt injection detection, agent classification-based access policies, and …HELPNETSECURITY.COM
22 JulArista adds AI-driven zero trust to VeloCloud SD-WANArista Networks has announced the launch of its new AI-driven Edge Threat Management (ETM) for VeloCloud SD-WAN, delivering integrated zero trust security for enterprise branch offices. Customers can leverage this integration to simplify the branch, collapsing multiple disparate …HELPNETSECURITY.COM
22 JulWhy Modern SOCs Need Multi-Layered DetectionsThe cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defenses. Most intrusions now bypass endpoint and malware-based detection entirely. T…THEHACKERNEWS.COM
22 JulGlow exits stealth with $180 million to secure the AI-enabled endpointGlow has emerged from stealth with $180 million in funding at a $1.2 billion valuation to advance a prevention-first approach to endpoint security. The funding round was led by Sequoia, Cyberstarts, Greenoaks, and Redpoint Ventures, with participation from Index Ventures, Swish V…HELPNETSECURITY.COM
22 JulStrongestLayer Raises $4.1 Million in Seed Funding ExtensionThe startup will use the fresh investment to accelerate its go-to-market strategy and to expand its platform. The post StrongestLayer Raises $4.1 Million in Seed Funding Extension appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulWhen Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account TakeoverIdentity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. The post When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulThreatDown expands security visibility to AI tools and machine identitiesThreatDown has announced a synchronized expansion of its AI and identity security capabilities to protect organizations from emerging, unmanaged risks. The company launched AI visibility, giving security and managed service provider (MSP) teams a full inventory of the AI tools ru…HELPNETSECURITY.COM
22 JulSwimlane AI SOC automates security operations for MSSPsSwimlane has announced the launch of Swimlane AI SOC for MSSPs, which the company says is designed to empower managed security service providers through agentic AI automation rather than compete for their customers. Some AI SOC providers are moving into managed services, turning …HELPNETSECURITY.COM
22 JulPalo Alto Networks to Acquire Observability Platform Provider EmbraceAcquisition follows January's Chronosphere deal, deepening Palo Alto Networks' push beyond core security into observability. The post Palo Alto Networks to Acquire Observability Platform Provider Embrace appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulNext chapter: Restructuring GitHub’s bug bounty programGitHub is making some significant changes to its bug bounty program, shifting its focus to give researchers a better experience working with the GitHub team. The post Next chapter: Restructuring GitHub’s bug bounty program appeared first on The GitHub Blog .GITHUB.BLOG
22 JulYou Can't Ban Attacker AIAI capabilities are becoming widely accessible. The discussion is shifting from whether attackers will use AI to how defenders can use similar technology to identify weaknesses in their own environments. If organizations focus only on restricting AI instead of adopting effective …YOUTUBE.COM
22 JulWhite House accuses Chinese company of distilling Anthropic’s FableWhile distillation attacks by foreign governments and companies have real national security implications, questions around who ultimately owns the data in AI systems are fraught. The post White House accuses Chinese company of distilling Anthropic’s Fable appeared first on CyberS…CYBERSCOOP.COM
22 JulMalware is targeting AI tools in software development environmentsThe worm blends in with thousands of other commands occurring daily in any given environment, yet its intent and origins remain unknown. The post Malware is targeting AI tools in software development environments appeared first on CyberScoop .CYBERSCOOP.COM
21 JulISC Stormcast For Tuesday, July 21st, 2026 https://isc.sans.edu/podcastdetail/10016, (Tue, Jul 21st)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
21 JulCybersecurity jobs available right now: July 21, 2026Application Security Analyst Stellantis | USA | On-site – View job details As an Application Security Analyst, you will perform application security testing using SAST, DAST, IAST, and other assessment tools to identify vulnerabilities and support remediation effo…HELPNETSECURITY.COM
21 JulAI agents are still logging in as humansMost large companies run more than one AI platform at the same time. Developers pull up coding assistants, marketing teams lean on writing tools, and analysts query enterprise search across separate vendors. Single-provider setups keep giving way to mixed stacks as companies keep…HELPNETSECURITY.COM
21 JulNobody was checking the drives that encrypt your laptopA drive ships with a label promising hardware encryption. You plug it in, set a password, and trust the chip inside to handle the rest. Millions of laptops and workstations run this way, on solid-state drives built to the TCG Opal2 standard. Milan Brož and three colleagues bought…HELPNETSECURITY.COM
21 JulZimbra Update Patches Critical VulnerabilitiesThe latest Zimbra refresh resolves command injection, XSS, restriction bypass, and SSRF security defects. The post Zimbra Update Patches Critical Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulWhat the World Cup can teach us about cybersecurity resilienceFuture major events can’t rely on yesterday's playbook. Lessons from the World Cup show why true cyber resilience starts months before kickoff and extends far beyond stadium perimeters. The post What the World Cup can teach us about cybersecurity resilience appeared first on Cybe…CYBERSCOOP.COM
21 JulResearchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 ProsIn a new campaign, North Korean hacking group Famous Chollima targeted crypto professionals through ClickFix lures to deliver Windows and macOS trojansINFOSECURITY-MAGAZINE.COM
21 JulAWS wants GuardDuty to automate the first steps of threat investigationsAmazon GuardDuty investigation agent is now in public preview. The feature provides AI-powered investigations of GuardDuty findings, AWS accounts and AWS organizations, helping security teams reduce investigation time. During the public preview, the investigation agent is availab…HELPNETSECURITY.COM
21 JulFake FBI agents target people who already got scammedScammers are impersonating FBI personnel who supposedly handle Internet Crime Complaint Center (IC3) complaints, using that disguise to deceive and revictimize people who already lost money once. The IC3 published the update on July 20, 2026, building on an earlier alert from Apr…HELPNETSECURITY.COM
21 JulMIT to Become Hotbed of AI Video SurveillanceIt’s a lot : According to information obtained by The Tech , MIT is spending over $3 million on more than 500 AI surveillance cameras in academic buildings, residence halls, and outdoor areas along Memorial Drive. Installation of the new cameras, along with the wiring and i…SCHNEIER.COM
21 JulCISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AGGaetje’s story shows that you don’t need to be a ‘deep bit-crawler’ to become a Chief Information Security Officer. The post CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulA new extortion cocktail: office printers, small ransoms, and BitLockerWe cover two recent cases of BitLocker extortion using RDP, MSSQL, RMM tools, web shells, and printers. The story includes TTPs and recommendations.SECURELIST.COM
21 JulEmpirical Security Raises $25 Million in Series A FundingThe startup will use the investment to accelerate the development of its threat prediction and discovery products. The post Empirical Security Raises $25 Million in Series A Funding appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulSecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial CybersecurityIndependently judged and sponsor-neutral, the new awards program honors the people, organizations, and technologies delivering proven impact in industrial cybersecurity; winners to be announced live at the 2026 ICS Cybersecurity Conference in Nashville The post SecurityWeek Launc…SECURITYWEEK.COM
21 JulLoop engineering comes to the SOC: Introducing the Intezer Org BrainOrganizational context in an AI SOC is table stakes. Org Brain is very different. It learns, it recalls, it fetches what it's missing, and it gets sharper with every alert it touches, all autonomously. The post Loop engineering comes to the SOC: Introducing the Intezer Org Brain …INTEZER.COM
21 JulCaptive Portal Detection, (Tue, Jul 21st)Not everything our honeypots detect is an attack. Sometimes it is just "odd traffic", and this is one example: Our "First Seen" list currently includes "http://detectportal.firefox.co
m/success.txt" as one of the new URLs detected by our honeypots. The hostname "detectporta…ISC.SANS.EDU
21 JulRussian Hacker Turns Jailbroken Claude Into Pentest PlatformRussian-speaking actor Trim built a commercial offensive AI pentest tool on jailbroken Claude modelsINFOSECURITY-MAGAZINE.COM
21 JulDruva brings backup, recovery and governance to AI workloadsDruva has announced Druva AI Resilience, a new approach that helps organizations recover, govern, and defend the systems, activity, and context behind AI-powered work. The launch introduces new and expanded capabilities for Microsoft Copilot, Claude Code, Druva Model Context Prot…HELPNETSECURITY.COM
21 JulArgon2 algorithm dramatically slows password cracking by high-end GPUsA new study shows that the Argon2id password hashing algorithm dramatically increases the cost of offline password cracking by neutralizing much of the advantage offered by modern GPUs. The study by Specops researcher David Ketler examines how Argon2id performs against modern pas…CYBERINSIDER.COM
21 JulTeleport enhances Identity Security platform with new AI agent behavior controlsTeleport has expanded its Identity Security platform with three new capabilities designed to ensure that agent behavior remains within defined boundaries: Beams Session Summaries, Agentic Classifiers, and Risk Scoring. They give enterprises a foundational harness for identifying …HELPNETSECURITY.COM
21 JulNorth Korea’s IT worker scheme funds Russia’s war effortDTEX researchers found a series of transactions in a payment wallet showing North Korean IT worker salaries flowing into sanctioned entities that support the regime’s military programs. The post North Korea’s IT worker scheme funds Russia’s war effort appeared first o…CYBERSCOOP.COM
21 JulIgnore Apple, Pay the PricePatrick Wardle shares the biggest lesson he learned after years of building macOS security tools: follow Apple's recommended development practices whenever possible. Choosing unsupported techniques may seem like the better engineering decision at first, but platform changes often…YOUTUBE.COM
21 JulFirefox 153 adds built-in Containers for easy account isolationMozilla has released Firefox 153, introducing built-in Containers as a native browser feature alongside HDR video playback on Windows, new PDF editing capabilities, and several security improvements. Firefox 153 is now rolling out to users on the browser's Release channel. The up…CYBERINSIDER.COM
21 JulDon't Overbuild Your AI WorkflowLarge codebases don't fit into a single LLM prompt. As projects grow, developers often need to split work into smaller pieces and guide the model with structured workflows. That doesn't mean you should build an elaborate AI harness from day one. A simple workflow often delivers t…YOUTUBE.COM
21 JulAI models keep getting caught cheatingNew research from the UK shows how nearly every model tested tried to cheat, scam or cut corners on its way to solving problems. The post AI models keep getting caught cheating appeared first on CyberScoop .CYBERSCOOP.COM
21 JulEvery Browser Extension Is a TradeoffNot all browser extensions present the same level of risk. Security teams evaluate whether an extension supports a legitimate business need and what permissions it requests before deciding whether to allow it. An extension that enables essential work may be acceptable when paired…YOUTUBE.COM
20 JulISC Stormcast For Monday, July 20th, 2026 https://isc.sans.edu/podcastdetail/10014, (Mon, Jul 20th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
20 JulA forensic tool for backdoored code completions in AI assistantsDevelopers lean on AI coding assistants for a growing share of their daily work, letting the tools predict the next few lines and accepting many suggestions with a quick glance. Those tools learn from large collections of code, and some of that code can be tampered with before tr…HELPNETSECURITY.COM
20 JulProduct showcase: ZoneAlarm Mobile Security adds customizable content filtering to mobile securityZoneAlarm Mobile Security is a security app from Check Point designed to protect mobile devices against phishing, malicious websites, unsafe networks, and fraudulent links. It is available for iPhone, iPad, Android, and can run on Apple silicon Macs through the App Store. Getting…HELPNETSECURITY.COM
20 JulOn Flock License Plate Tracking CamerasA recent story of a writer who was mistakenly identified, tracked, and arrested using data from Flock cameras has gone viral. The New Jersey plates that were allegedly stolen from the LA dealer were 34 03 DTM , not 34 10 DTM . But when the police report was created and the plate …SCHNEIER.COM
20 JulWhy blocking AI models won’t stop the cyber threats they createAI companies can find vulnerabilities and write patches. But only the government can build the long-term defense strategy America needs. The post Why blocking AI models won’t stop the cyber threats they create appeared first on CyberScoop .CYBERSCOOP.COM
20 JulNeo Emerges From Stealth With $100M to Control and Secure Enterprise AI SoftwareNeo raised money across seed and Series A funding rounds from Andreessen Horowitz, Bessemer Venture Partners, and others. The post Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software appeared first on SecurityWeek .SECURITYWEEK.COM
20 JulHOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channelMicrosoft 365 calendars have become a hiding place for espionage malware, with commands and stolen files stashed inside appointments dated to the year 2050, researchers from Group-IB discovered. Targeted campaign tied to Iranian espionage activity The malware, which Group-IB call…HELPNETSECURITY.COM
20 JulThe Odyssey piracy scams surface hours after its theatrical debutChristopher Nolan’s The Odyssey had barely reached theaters before scammers began targeting people searching for pirated copies, according to Malwarebytes. Within hours of the film’s release, researchers found two separate scams running on cloned piracy sites: fake br…HELPNETSECURITY.COM
19 JulUAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih MalwareRussian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has bee…THEHACKERNEWS.COM
19 JulHackers abuse ViPNet software to target Russian govt agenciesAn advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. [...]BLEEPINGCOMPUTER.COM
19 JulScans for Hikvision Intelligent Security API, (Sun, Jul 19th)We have been following issues with Hikvision cameras for a long, long time . Like many similar products, Hikvision cameras have a long history of vulnerabilities and are often targeted by internet-wide scans that our honeypot network detects.
ISC.SANS.EDU
18 JulNew North Korean campaign uses fake coding interviews to steal developer credentialsDPRK-aligned hackers hid malware inside SVG flag images to backdoor developer job interview coding tests. Not one antivirus vendor caught it.ELASTIC.CO
18 JulVoting Works Like AuthenticationThe voting process described uses identity verification, authorization checks, machine scanning, voter confirmation, and stored paper records. Security is not only about preventing digital attacks. Physical processes also rely on layered controls to verify who can participate and…YOUTUBE.COM
17 JulISC Stormcast For Friday, July 17th, 2026 https://isc.sans.edu/podcastdetail/10012, (Fri, Jul 17th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
17 JulNew infosec products of the week: July 17, 2026Here’s a look at the most interesting products from the past week, featuring releases from Cloudflare, Lineation.ai, Nudge Security, and Polygraf AI. Polygraf AI Meeting Guard delivers real-time deepfake detection for enterprise meetings Polygraf AI has announced Meeting Guard, a…HELPNETSECURITY.COM
17 JulA hard drive reliability check on 341,263 drives, from 4TB to past 20TBLarge cloud storage operators track their hard drives every day, recording which units keep running and which ones drop off the racks. Backblaze does this at scale, and its Q1 2026 report covers a fleet built for continuous use. The analysis covered 341,263 hard drives, after boo…HELPNETSECURITY.COM
17 JulPrompt injection is becoming the XSS of the web agent eraAutonomous web agents read whatever a page displays, and much of that content comes from strangers. Product reviews, seller listings, and advertisements sit beside trusted site menus on a single page. An agent that reads all of that text as instructions can be steered by any of i…HELPNETSECURITY.COM
17 JulThe script, not the voice, is what makes AI voice phishing workThe call comes in at 4:40 on a Friday. The voice belongs to a senior manager, or sounds close enough, and she needs a password reset before a flight. She is polite, she is in a hurry, and she has the last four of the badge number. Researchers at Harvard Kennedy School, Meta and e…HELPNETSECURITY.COM
17 JulRisk Ledger Raises $32 Million in Series B FundingThe British firm has built a collaborative platform to help organizations address supply chain security risks. The post Risk Ledger Raises $32 Million in Series B Funding appeared first on SecurityWeek .SECURITYWEEK.COM
17 JulScammers weaponize FaceTime in attempt to drain bank accountsApple is warning iPhone and iPad users that scammers are using FaceTime calls to trick them into handing over money and account details. The company says scammers use social engineering, posing as representatives of a trusted company or entity, and contacting people by phone or o…HELPNETSECURITY.COM
17 JulClaude can now sign into websites with 1Password without exposing your credentials1Password has introduced 1Password for Claude, a beta integration that lets Anthropic’s AI assistant complete browser tasks requiring authentication without accessing users’ passwords or other secrets. The integration is available to paid Claude subscribers (Pro, Max,…HELPNETSECURITY.COM
17 JulNew Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RATRussian-speaking UAT-11795 spreads trojanized Zoom, Webex, and MobaXterm installers to deliver Starland RAT and the WLDR memory-only implant. Cisco Talos researchers published a detailed technical report on July 16 disclosing UAT-11795, a financially motivated, Russian-speaking t…SECURITYAFFAIRS.COM
17 JulDetails of Alan Turing’s Voice Encryption SystemReally interesting piece of cryptographic history : In November 2023, a large cache of his wartime papers—nicknamed the “Bayley papers”—was auctioned in London for almost half a million U.S. dollars. The previously unknown cache contains many sheets in Tur…SCHNEIER.COM
17 JulBeacon Security Raises $13 Million for Security Data PlatformThe startup helps organizations detect, hunt, and protect their assets across environments at machine speed. The post Beacon Security Raises $13 Million for Security Data Platform appeared first on SecurityWeek .SECURITYWEEK.COM
17 JulIndustry Reactions to Pentagon Suspending CMMC Phase 2: Feedback FridayIndustry professionals broadly agree that the suspension pauses third-party CMMC audits but not the underlying legal obligation to protect CUI. The post Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday appeared first on SecurityWeek .SECURITYWEEK.COM
17 JulFake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag ImagesNorth Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges. "Any user who ran the project ended up with a fo…THEHACKERNEWS.COM
17 JulGoogle must open Android to rival AI agents, EU ordersThe European Union is stepping up its actions against US tech giants under the Digital Markets Act, which is intended to ensure fair competition between digital platforms. On Thursday, the European Commission issued two rulings to limit Google’s dominance . The Commission ordered…CSOONLINE.COM
17 JulLeading members of Scattered Spider sentenced in UK to 66 months in jailThalha Jubair and Owen Flowers led and directed many attacks attributed to the hacker subset of The Com. U.S. authorities previously accused Jubair of participating in at least 120 attacks. The post Leading members of Scattered Spider sentenced in UK to 66 months in jail appeared…CYBERSCOOP.COM
17 JulMozilla study ranks Euki as the most private period trackerA Mozilla privacy investigation into six popular period-tracking apps found that some services expose device identifiers, usage details, or sensitive logs to analytics and advertising systems. Euki earned the study’s only perfect score because it stores health information locally…CYBERINSIDER.COM
17 JulMicrosoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacksJoin Microsoft Security at Black Hat USA 2026 for supply chain research, hands-on security experiences, expert conversations, and our reception. The post Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks appeared first on Microsoft Securit…MICROSOFT.COM
17 JulFriday Squid Blogging: Squid Washing Up on Cape Cod BeachLots of articles about this . As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.SCHNEIER.COM
17 JulM. Thénardier, LastPass, GitHub, EBS, Spirals, Pegasus, Shaft, Josh Marpet, and More - SWN #599M. Thénardier, LastPass, GitHub, EBS, Spirals, Pegasus, Shaft, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-599YOUTUBE.COM
16 JulISC Stormcast For Thursday, July 16th, 2026 https://isc.sans.edu/podcastdetail/10010, (Thu, Jul 16th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
16 JulTrend Micro, Tanium, ESET and Tenable Patch Severe Product VulnerabilitiesThe cybersecurity companies patched critical and high-severity vulnerabilities in some of their products. The post Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulOld UEFI Shims Expose Systems to Secure Boot BypassSigned by Microsoft, the vulnerable UEFI shim bootloaders could be abused on any system, regardless of the OS. The post Old UEFI Shims Expose Systems to Secure Boot Bypass appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulVS Code agent host runs Copilot, Claude, and Codex in a dedicated processDevelopers who lean on AI coding agents often keep several editor windows open at once, each tied to its own session. The 1.129 release of Visual Studio Code reworks that setup with a dedicated agent host. A dedicated process for agent sessions The agent host is a separate proces…HELPNETSECURITY.COM
16 JulChina’s Top Cybersecurity Firms Hit by Mounting Military Procurement BansChinese cybersecurity firms are facing action from the country’s military, but it’s not due to product or technical failures. The post China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulPolice take down investment fraud network that stole €100 million a monthDutch police, working alongside Belgian authorities and Europol, have dismantled a major criminal network accused of operating a global investment fraud scheme through dozens of fraudulent call centers. Investigators estimate the organization generated more than €100 million a mo…HELPNETSECURITY.COM
16 JulLineation.ai focuses on runtime security for autonomous AI agentsLineation.ai has announced the public launch of its comprehensive agentic security platform. Delivering a solution at the intersection of genAI application security and runtime defense, lineation introduces a zero trust unified control plane and a lightweight endpoint daemon that…HELPNETSECURITY.COM
16 JulEFF: Apple the only major wearable vendor offering E2EE for health dataThe Electronic Frontier Foundation (EFF) says Apple is the only major wearable manufacturer among ten leading brands it examined that offers end-to-end encryption for users' cloud-synchronized health data. The privacy group's review also found that transparency around government …CYBERINSIDER.COM
16 JulRussian hackers trojanize WebEx, Zoom apps to push Starland malwareA financially motivated Russian threat actor tracked as UAT-11795 is using trojanized software to steal credentials and cryptocurrency by deploying a new backdoor called Starland RAT. [...]BLEEPINGCOMPUTER.COM
16 JulSplunk, Zoom Patch Critical VulnerabilitiesThe flaws could allow attackers to access credentials and data, take over accounts, and escalate their privileges. The post Splunk, Zoom Patch Critical Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulOak Emerges From Stealth Mode With $60 Million in FundingThe startup has built an AI-powered Identity Operating System that governs all identities across an organization’s environment. The post Oak Emerges From Stealth Mode With $60 Million in Funding appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulIntruder brings AI-powered, on-demand penetration testing to web applicationsIntruder has announced the launch of AI Pentesting for web applications, providing on-demand penetration testing. Following its initial release of issue-level investigations last quarter, the platform now allows organizations to securely connect their codebases via GitHub or GitL…HELPNETSECURITY.COM
16 Jul20+ Hijacked Government Websites Became
an Attack ChannelMore than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions. The investigation revealed previously…THEHACKERNEWS.COM
16 JulDaxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM BackdoorAn advanced malware previously attributed to a China-linked threat actor has resurfaced after more than four years within a Taiwan manufacturing firm, along with a previously unreported backdoor dubbed Stupig. Daxin ("srt64.sys"), as the kernel-mode rootkit is referred to, was fi…THEHACKERNEWS.COM
16 JulAI Data Centers Are Being Built Faster Than They Can Be SecuredAI infrastructure introduces new security risks that traditional data center designs were never built to handle. The post AI Data Centers Are Being Built Faster Than They Can Be Secured appeared first on SecurityWeek .SECURITYWEEK.COM
16 Jul‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process KillingThe new macOS malware has targeted at least 100 users to steal their passwords and cryptocurrency. The post ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulAI Governance Is Everyone's ProblemAI adoption impacts nearly every part of an organization. Security teams must evaluate risks around data, access, and technology, but they cannot manage AI governance alone. A successful AI governance program requires shared ownership across security, IT, legal, privacy, finance,…YOUTUBE.COM
16 JulSandworm hackers have a CAPTCHA trick for UkrainiansRather than verifying they are human, the CAPTCHA users are instructed to copy and paste a PowerShell command into their Windows computers.THERECORD.MEDIA
16 JulAdaptiva simplifies secure patch management for air-gapped networksAdaptiva has announced AirGap for OneSite Patch, a new capability that extends autonomous patch management to air-gapped environments. Developed in response to growing demand from government agencies, critical infrastructure operators, and large enterprises managing highly secure…HELPNETSECURITY.COM
16 JulProtecting Privacy in an AI EraDaniel Solove argues in the Wall Street Journal (alternate link ) that giving people control of their personal data is not an effective way to regulate privacy in this era. Instead, we need to hold companies accountable for their actions, similar to what we do with food and drug …SCHNEIER.COM
16 JulIran-nexus actors using AI to enhance cyber playbookA report shows state-linked and hacktivist groups have used ChatGPT and other tools for malware development, phishing and mapping out industrial sites.CYBERSECURITYDIVE.COM
16 JulGaps in network security, oversight strategy hamper US’s aviation cybersecurity regulatorsA new government audit identified several weaknesses at the two agencies that protect air travel from hackers.CYBERSECURITYDIVE.COM
16 JulLeast privilege for AI agents: Identity, access, and tool bindingAs AI agents become more autonomous, strong identity, access, and auditing controls are critical to keeping them secure. The post Least privilege for AI agents: Identity, access, and tool binding appeared first on Microsoft Security Blog .MICROSOFT.COM
16 JulThe BIOS Password MistakeNot every "BIOS password" is actually the same thing. In this conversation, the distinction is made between a BIOS setup password, a boot password, a hard drive password, and a BitLocker recovery key. Each protects a different layer of the system. Confusing these terms can lead t…YOUTUBE.COM
16 JulACR Stealer: Two observed intrusion chains amid increased threat activityFrom late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents from enterpri…MICROSOFT.COM
15 JulInside the Media Mind of Sasha Ingber: SpyCast PodcastOn this episode of #IMM, Christine and Madison sit down with Sasha Ingber the host of SpyCast, the International Spy Museum's flagship podcast on global intelligence, espionage and covert operationsTHECYBERWIRE.COM
15 JulISC Stormcast For Wednesday, July 15th, 2026 https://isc.sans.edu/podcastdetail/10008, (Wed, Jul 15th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
15 JulRecent DShield SIEM Update, (Tue, Jul 14th)The last update to the DShield SIEM [ 4 ] was in Sep 2025 which contained some minor tweaks. This update currently is using ELK stack version 8.19.15, contains some additional dashboards and new logs.
ISC.SANS.EDU
15 JulAn AI overthinking attack can tie a robot up for over a minuteRobots that read the world through cameras now lean on large vision-language models to interpret what they see and decide what to do next. These models handle images and text together, so any words that fall inside the camera frame become part of the input. A stop sign, a street …HELPNETSECURITY.COM
15 JulAWS retools Security Hub for AI and multicloud threatsAWS added AI workload protection and Microsoft Azure security monitoring to Security Hub, its centralized security platform for collecting and prioritizing security findings across cloud environments. Support for additional cloud platforms will follow. “Collecting findings …HELPNETSECURITY.COM
15 JulTuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted DevelopmentTuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs. The post TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
15 JulVulnerabilities Patched by Fortinet, Ivanti, ServiceNowA critical security defect in the ServiceNow AI platform could allow remote attackers to execute arbitrary code. The post Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow appeared first on SecurityWeek .SECURITYWEEK.COM
15 JulA Video Screen That Is Also a CameraAmazing : Researchers from ETH Zurich in Switzerland, however, managed to create a new type of pixel that can simultaneously do both. This hypercharged pixel, called a Fourier pixel, can generate and sense arbitrary light fields and tap into a pixel’s full potential for car…SCHNEIER.COM
15 JulUS Charges Russian Individuals and Firms for Running Cybercrime ServicesThe suspects and their companies were previously sanctioned by the United States and its allies. The post US Charges Russian Individuals and Firms for Running Cybercrime Services appeared first on SecurityWeek .SECURITYWEEK.COM
15 JulSpanish police dismantle €140 million cybercrime networkSpanish National Police have dismantled a cybercrime network accused of stealing and laundering about €140 million through fake investment platforms, CEO fraud, invoice fraud, and man-in-the-middle attacks. Four people were arrested as part of the operation: two in Portugal, one …HELPNETSECURITY.COM
15 JulNudge Security automates detection of risky OAuth grants and browser extensionsNudge Security has announced new agentic capabilities to help security and IT teams find and remediate malicious and high-risk OAuth grants and browser extensions, two of the fastest-growing and hardest to manage attack surfaces in the enterprise. The new agents continuously anal…HELPNETSECURITY.COM
15 JulBinary Defense’s NightBeacon CMD helps enterprise SOC teams automate threat investigationsBinary Defense has announced NightBeacon CMD, a standalone AI-driven SOC workbench that enterprise security teams can deploy in their own environments. Built and hardened inside Binary Defense’s live 24/7 Security Operations Center (SOC), NightBeacon CMD gives customers the…HELPNETSECURITY.COM
15 JulWindows Bind Link Attacks Can Hide Malware From EDR ToolsBitdefender researchers show how Windows bind links can create conflicting filesystem views to hide malware from endpoint security products. The post Windows Bind Link Attacks Can Hide Malware From EDR Tools appeared first on SecurityWeek .SECURITYWEEK.COM
15 JulVirtual Event Today: Cloud & Data Security SummitAttendees will be able to interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments. The post Virtual Event Today: Cloud & Data Security Summit appeared first on SecurityWeek .SECURITYWEEK.COM
15 JulRadware adds cloud intelligence to DefensePro X for web DDoS defenseRadware has announced a new cloud-augmented protection architecture for DefensePro X, extending the platform with new AI-powered cloud algorithms while keeping traffic inspection and mitigation locally within customer premises. The first such service released is Cloud Web DDoS Pr…HELPNETSECURITY.COM
15 JulLatticeFlow AI connects governance frameworks with continuous AI risk monitoringLatticeFlow AI has announced a platform for managing AI risk across agentic systems. Organizations are deploying autonomous AI in critical business processes, while governance approaches based on documentation and point-in-time assessments struggle to keep up with evolving risks.…HELPNETSECURITY.COM
15 JulThreat actor impersonated hundreds of brands on GitHub to push infostealer malwareA financially motivated threat actor is impersonating hundreds of brands on GitHub and pushing a smash-and-grab infostealer masquerading as legitimate downloads of popular software, Arctic Wolf threat researchers have warned. “The 292 impersonated repositories span security…HELPNETSECURITY.COM
15 JulSocure rolls out Remote Verifier for higher-risk identity checksSocure has launched Remote Verifier in RiskOS, a new identity verification tool that helps organizations verify identities requiring additional review while reducing manual effort. Socure’s AI-powered document verification solution instantly verifies more than 99% of identities o…HELPNETSECURITY.COM
15 JulXint Pulse offers on-demand black-box penetration testing for web applicationsXint.io has launched Xint Pulse, a black-box autonomous penetration testing tool that provides product security teams with on-demand security assessments of their applications. Unlike the company’s enterprise platform, which is designed for continuous testing, Xint Pulse is…HELPNETSECURITY.COM
15 JulLabubaRAT malware infiltrates Windows systems while posing as NVIDIA softwareLabubaRAT, a previously undocumented Rust-based remote access tool (RAT) masquerading as NVIDIA software that enables post-compromise operations on Windows systems, has been uncovered by Blackpoint Cyber. According to researchers, LabubaRAT creates “a reusable foothold for …HELPNETSECURITY.COM
15 JulForget the model. When it comes to cybersecurity, it’s all about the harnessIndustry has quickly developed tools meant to guide and direct frontier LLMs in cybersecurity. Attackers aren’t far behind. The post Forget the model. When it comes to cybersecurity, it’s all about the harness appeared first on CyberScoop .CYBERSCOOP.COM
15 JulProton says it rejected all 47 data requests targeting VPN users in 2026Proton has updated its Proton VPN transparency report, revealing that it received 47 legally binding requests for user information during the first half of 2026. According to the company, all 47 requests were denied because Proton VPN's no-logs policy meant it had no data capable…CYBERINSIDER.COM
15 JulTurning threat intelligence into decisive action with Defender ExpertsSecurity teams have never had more visibility, yet rarely have they felt more uncertain. Signal pours in from endpoints, identities, cloud workloads, and a sprawling mix of third-party tools. The post Turning threat intelligence into decisive action with Defender Experts appeared…MICROSOFT.COM
15 JulDems press DNI nominee Jay Clayton on election security questions, but leave dismayedClayton maintained he was not an “election denier” but wouldn’t directly answer a number of questions about the 2020 race, his predecessor’s appearance at a January election office raid and more. The post Dems press DNI nominee Jay Clayton on election security questions, but leav…CYBERSCOOP.COM
15 JulStop Treating AI Like CoworkersSome organizations are giving AI agents names, titles, and workplace roles to encourage adoption. An MIT article argues that AI agents are not coworkers, despite how they're often presented. Anthropomorphism—the tendency to assign human qualities to non-human things—can influence…YOUTUBE.COM
14 JulISC Stormcast For Tuesday, July 14th, 2026 https://isc.sans.edu/podcastdetail/10006, (Tue, Jul 14th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
14 JulCybersecurity jobs available right now: July 14, 2026Cyber Network Engineer Fiserv | USA | On-site – View job details As a Cyber Network Engineer, you will lead the design, governance, and security review of enterprise network architectures across on-premises and cloud environments. You will provide expertise in net…HELPNETSECURITY.COM
14 JulTelegram’s t.me domain suspended at the registry level, breaking links worldwideTelegram's t.me domain was temporarily placed on serverHold status at the registry level on Tuesday, causing all t.me links to stop resolving through the global Domain Name System (DNS). While the messaging platform itself remained operational, users were unable to access public …CYBERINSIDER.COM
14 JulMultiple Jscrambler Packages Impacted by Supply Chain AttackA threat actor poisoned several Jscrambler NPM package versions to drop a cross-platform credential stealer. The post Multiple Jscrambler Packages Impacted by Supply Chain Attack appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulMicrosoft Entra ID authentication overhaul to start in September 2026Microsoft will begin rolling out passkeys as the default authentication experience for Microsoft Entra ID in the public cloud on September 1, 2026. Organizations with SMS or voice authentication enabled will automatically be enabled for passkeys. The next time users complete MFA,…HELPNETSECURITY.COM
14 JulValarian Raises $50 Million for Sovereign Infrastructure Control LayerUK-based cybersecurity firm Valarian has raised a total of $70 million for its ACRA technology. The post Valarian Raises $50 Million for Sovereign Infrastructure Control Layer appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulUK charges five persons linked to fraud platform behind more than a million scam callsFive people have been charged in the UK following a National Crime Agency (NCA) investigation into Russian Coms, a caller ID spoofing service used by fraudsters. Ayoub Sehailia, 28, Zakkaria Sehailia, 30, Usman Din, 30, Denis Ozmus, 29, and Fadila Salem, 53, all of London, are ch…HELPNETSECURITY.COM
14 Jul[Video] Where protection starts: Cisco Talos Intelligence IntegrationsEvery day, defenders make high-consequence decisions with incomplete information. Learn how Cisco Talos Intelligence Integrations help reduce uncertainty by turning the latest threat intelligence into proactive protections across Cisco technologies.TALOSINTELLIGENCE.COM
14 JulNo one knows how many old shims can still bypass UEFI Secure BootThe vast majority of UEFI computers carry a Microsoft certificate that will trust a small first-stage loader called a shim, a program Microsoft signs so that Linux and assorted boot tools can run with Secure Boot on. Eleven of those signed shims turned out to be old enough to und…HELPNETSECURITY.COM
14 JulLastPass warns users of active campaign targeting master passwordsLastPass is warning customers about an active phishing campaign that uses lookalike domains and fake security notifications to trick users into revealing their master passwords or downloading malicious software. The company says the activity has no impact on LastPass's own system…CYBERINSIDER.COM
14 JulDownload: The ultimate guide to network operations managementModern network operations are too manual. Today’s IT and security teams are managing growing complexity across networks, infrastructure, tools, and workflows. The result? Slower response, duplicated effort, and operational friction. This guide explores how intelligent workflows h…HELPNETSECURITY.COM
14 JulHow Pentera Turns AI Security Workflows into Validation EnginesAI security agents are starting to influence real security decisions. They summarize findings, prioritize remediation, recommend next steps, and help teams move faster. But most still rely on fragmented risk signals: scanner output, severity scores, threat intelligence, configura…THEHACKERNEWS.COM
14 JulOAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra CredentialsAt least two distinct threat actors are weaponizing a novel evasion technique called OAuth client ID spoofing in cloud campaigns, while slipping past telemetry. The activity allows users to enumerate user accounts and validate stolen credentials in Microsoft Entra ID environments…THEHACKERNEWS.COM
14 JulNew macOS malware steals passwords by posing as Apple’s crash-reporting toolJamf Threat Labs has uncovered a new macOS infostealer named CrashStealer that disguises itself as Apple’s crash-reporting tool to steal passwords, Keychain data, and cryptocurrency wallets. The malware was first spotted in May while it was still under development. By early…HELPNETSECURITY.COM
14 JulAI's Hidden Security LayerAI security is changing. The biggest risk is no longer simply whether employees are using AI—it's what they're asking AI to process. Sensitive prompts can expose confidential information in ways traditional security tools weren't built to observe. EDR, antivirus, and network moni…YOUTUBE.COM
14 JulSharp rise in AI adoption for cyber defense exposes major governance gapA report by the SANS Institute indicates a split between senior security leaders and frontline practitioners. CYBERSECURITYDIVE.COM
14 JulUpcoming Speaking EngagementsThis is a current list of where and when I am scheduled to speak: I’m speaking (virtually) at the Policy-Relevant Privacy Research Workshop in Calgary, Canada, on Monday, July 20, 2026. I’m speaking at Boston Leadership Exchange in Boston, Massachusetts, USA, on Wednesday, July 2…SCHNEIER.COM
14 JulAdobe Patches Critical ColdFusion VulnerabilitiesThe ColdFusion security defects could allow attackers to execute arbitrary code or elevate their privileges. The post Adobe Patches Critical ColdFusion Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulStop Securing AI in SilosAI application security includes many protections—input validation, output sanitization, infrastructure controls, and more. Too often, they're evaluated independently instead of as parts of a larger system. A holistic approach allows security controls to inform each other, more c…YOUTUBE.COM
14 JulNearly 300 GitHub repos pose as legit software to push malwareA threat actor has published hundreds of fake GitHub repositories impersonating legitimate software and security projects to distribute infostealer malware. [...]BLEEPINGCOMPUTER.COM
14 JulMr. Data, Joomla Babooa, 1VPNS, RabbitMQ, UEFI, Center 16, Sextortion, Aaran Leyland - SWN #598Mr. Data, Joomla Babooa, 1VPNS, RabbitMQ, UEFI, Center 16, Sextortion, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-598YOUTUBE.COM
14 JulWhite House details ‘Gold Eagle’ clearinghouse for AI cyber threatsThe White House said the clearinghouse has already started to receive intelligence on vulnerabilities and prioritize patches. The post White House details ‘Gold Eagle’ clearinghouse for AI cyber threats appeared first on CyberScoop .CYBERSCOOP.COM
13 JulISC Stormcast For Monday, July 13th, 2026 https://isc.sans.edu/podcastdetail/10004, (Mon, Jul 13th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
13 JulEnterprises are rethinking where their AI applications runGrowing demand for compute capacity, power, cooling and low-latency connectivity is prompting organizations to reassess where AI applications run, according to CoreSite. Public cloud continues to support experimentation and rapid deployment, while colocation is increasingly used …HELPNETSECURITY.COM
13 JulA hardware security AI assistant that checks chips for hidden backdoorsChip designers license blocks of circuitry from outside vendors and drop them into larger products. A single processor can carry components from a range of suppliers, each written by a company the buyer may never deal with directly. A malicious supplier can bury a hidden circuit …HELPNETSECURITY.COM
13 JulAI-generated code has made security debt a governance problemMoving from tool approval to true governance is the only way for CISOs to keep pace with the accelerating velocity of software risk. The post AI-generated code has made security debt a governance problem appeared first on CyberScoop .CYBERSCOOP.COM
13 JulProgress Prompts ShareFile Storage Zone Controller Shutdown Amid Security ConcernsThe company notified customers to manually shut down their servers while it is investigating a credible threat. The post Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns appeared first on SecurityWeek .SECURITYWEEK.COM
13 JulClaude Code users keep 50% higher limits until July 19Anthropic has extended a limited-time promotion that increases weekly usage limits in Claude Code by 50% through July 19, 2026, at 11:59 PM PT. When the promotion ends, weekly usage limits will return to their standard levels without any changes to users’ plans or billing. …HELPNETSECURITY.COM
13 JulAI Data Centers and the Concentration of WealthThis essay was written with Nathan E. Sanders, and originally appeared in The Guardian . Opposition to AI data centers has emerged as a primary theme in US politics, one that—surprisingly—doesn’t fall along party lines. We applaud people coming together for cons…SCHNEIER.COM
13 JulEU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying CampaignThe move targeted people and entities accused of links to an online spying network that the EU claims targeted governments and carried out sabotage operations against critical infrastructure. The post EU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber S…SECURITYWEEK.COM
13 JulRust-proof your code with our new Testing Handbook chapterWe’ve added a new chapter to our Testing Handbook : a comprehensive guide to security testing Rust programs. This chapter covers the tools and techniques we use at Trail of Bits to validate the security of Rust programs and systems. fn main () {( | f: & dyn Fn ( u128 )-> B…TRAILOFBITS.COM
13 JulSecurity threat prompts Progress to disable ShareFile accounts, tell customers to shut down serversA “credible external security threat” targeting Progress Software’s ShareFile Storage Zone Controllers (SZC) – the on-premises, customer-managed server components where organizations store files shared via this popular enterprise platform – has spurr…HELPNETSECURITY.COM
13 JulAttacker Uses Suspected AI-Generated PowerShell Script to Map Active DirectoryCybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory (AD) enumeration. "The script looked for the Domain Controller (DC) and mapped users, computers, and domains, before creating a direc…THEHACKERNEWS.COM
13 JulCybersecurity M&A Roundup: 37 Deals Announced in June 2026Significant cybersecurity M&A deals announced by 1Password, Accenture, Cisco, F5, Rubrik, and SailPoint. The post Cybersecurity M&A Roundup: 37 Deals Announced in June 2026 appeared first on SecurityWeek .SECURITYWEEK.COM
13 JulFake OAuth client IDs are helping attackers slip past sign-in logsAttackers running account enumeration against Microsoft cloud tenants have added a step that keeps their probing out of the usual telemetry. They spoof the OAuth client ID, the globally unique identifier assigned to an application and passed as client_id in an authentication requ…HELPNETSECURITY.COM
13 JulCloudflare Precursor uses continuous behavioral analysis to stop advanced botsCloudflare has announced the general availability of Precursor, a next-generation, continuous behavioral validation engine for bot management. Precursor runs seamlessly inside web browsers to monitor entire user sessions in order to detect bot automation. Unlike static CAPTCHAs, …HELPNETSECURITY.COM
13 JulLumen expands managed detection and response with Cortex XSIAM integrationLumen Technologies has announced Lumen Defender Advanced Managed Detection and Response (AMDR) for Palo Alto Networks Cortex XSIAM. Attackers are increasingly operating earlier in the lifecycle while AI is accelerating threat speed. This expanded service will bring together Lumen…HELPNETSECURITY.COM
13 JulEU Targets FSB-Linked Hackers in New Sanctions Over Cyber SabotageEU sanctions target nine people and four entities tied to Russia’s FSB over a 15-year cyberespionage and critical infrastructure sabotage campaign. The European Union imposed sanctions on Monday targeting nine individuals and four entities linked to a Russian cyberespionage…SECURITYAFFAIRS.COM
13 JulYour CI Pipeline Becomes the AttackDependency pinning helps ensure consistent builds, but it doesn't protect a CI/CD pipeline if an attacker can modify the workflow itself. A workflow is ultimately executable code, often defined in a YAML file, running on infrastructure that may have access to cloud credentials or…YOUTUBE.COM
13 JulHacker Conversations: Jesse McGraw (GhostExodus), From Blackhat Hacker to RedemptionOnce a notorious blackhat hacker, McGraw shares his journey from high school hacking and prison to redemption as a cybersecurity advocate. The post Hacker Conversations: Jesse McGraw (GhostExodus), From Blackhat Hacker to Redemption appeared first on SecurityWeek .SECURITYWEEK.COM
13 JulEU and UK blacklist Russia’s cyber operators over efforts to destabilize EuropeThe EU and the UK jointly sanctioned dozens of Russian individuals and entities, accusing Moscow of coordinating a malicious cyber ecosystem targeting Europe, its member states, and international partners. The UK sanctioned 24 individuals and entities, while the EU imposed restri…HELPNETSECURITY.COM
13 JulWestern intelligence agencies warn of Russian hackers targeting critical infrastructure.Progress Software tells ShareFile admins to shut down servers immediately. Researchers identify a new macOS infostealer.THECYBERWIRE.COM
13 JulHackers find a new trick to collect Microsoft Entra user data without raising red flagsOrganizations should check their logs for signs of an increasingly popular obfuscation technique, Proofpoint said.CYBERSECURITYDIVE.COM
13 JulCloudflare expands behavioral tracking to fight AI bots, says user privacy protectedCloudflare has introduced Precursor, a new bot detection system that continuously monitors visitor behavior throughout an entire browsing session instead of relying solely on CAPTCHAs or isolated verification points. While the company says the technology is designed to combat inc…CYBERINSIDER.COM
13 JulGigaWiper Lets Threat Actors Choose Their Own Destructive AttackA modular implant borrows from various malware families to combine both backdoor and wiper activities to maximize impact and minimize operational output.DARKREADING.COM
13 JulLiving on the Edge: How Threat Actors Use Network Infrastructure Against YouThe post Living on the Edge: How Threat Actors Use Network Infrastructure Against You appeared first on Eclypsium | Supply Chain Security for the Modern Enterprise .ECLYPSIUM.COM
13 JulDefending SaaS-based applications against ShinyHunters OAuth abuseMicrosoft Threat Intelligence identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing (vishing), supply-chain compromise, and misconfigured guest access targeting SaaS-based applications. The post Defending SaaS…MICROSOFT.COM
11 JulWireshark 4.6.7 Released, (Sat, Jul 11th)Wireshark release 4.6.7 fixes 12 vulnerabilities and 16 bugs.
ISC.SANS.EDU
11 JulGhost Accounts Abuse GitHub API in Mass Recon CampaignMultiple campaigns are using ghost accounts to map GitHub organizations, including their repositories and members. The post Ghost Accounts Abuse GitHub API in Mass Recon Campaign appeared first on SecurityWeek .SECURITYWEEK.COM
10 JulISC Stormcast For Friday, July 10th, 2026 https://isc.sans.edu/podcastdetail/10002, (Fri, Jul 10th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
10 JulNew infosec products of the week: July 10, 2026Here’s a look at the most interesting products from the past week, featuring releases from Attestiv, Automox, Codenotary, and First Recon AI. Codenotary launches AI security platform that learns from AI agent behavior Codenotary has announced AgentMon 3, the latest generation of …HELPNETSECURITY.COM
10 JulAWS gives its ERP agent deny-by-default rules and a separate identityAccounts receivable teams at large companies spend hours each day matching incoming bank payments to invoices by hand. When those payments sit unmatched for days, cash flow suffers and days sales outstanding climbs. The same pattern repeats across blocked invoices, purchase order…HELPNETSECURITY.COM
10 JulMost data brokers won’t tell you what happened to your deletion requestData brokers collect personal details on most adults in the United States and sell them to buyers that include employers, landlords, insurance companies, and government agencies. California gives residents a way to push back. You can ask a broker to delete your records, or to sto…HELPNETSECURITY.COM
10 JulNetwork of 200 GitHub Repositories Used for Malware InfectionA Go module is used to load PowerShell code that fetches a resolver from public dead drops to execute Windows malware. The post Network of 200 GitHub Repositories Used for Malware Infection appeared first on SecurityWeek .SECURITYWEEK.COM
10 JulMeta automatically opts public Instagram accounts into AI image generationMeta has launched Muse Image, a new AI image-generation model that lets users incorporate photos from public Instagram accounts into AI-generated images by simply tagging a username in a prompt. The feature has sparked privacy concerns because public Instagram accounts are enroll…CYBERINSIDER.COM
10 JulFlying with the Flipper ZeroWhy is the world so alarmed about taking the Flipper on board planes? Is it just poorly educated armchair cyber commentators of the ‘don’t use open Wi-Fi / USB juicejacking’ style of fearmongering, or is there something to it? TL;DR Why are people worried? …PENTESTPARTNERS.COM
10 JulLineageOS adds browser-based flashing tool for older Android devicesLineageOS has introduced a browser-based flashing tool that significantly lowers the barrier to installing the popular aftermarket Android operating system. The new feature makes it easier for users to install LineageOS on supported devices, helping extend the life of smartphones…CYBERINSIDER.COM
10 JulHackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 AccessA threat actor has been targeting organizations spanning multiple sectors with voice-based fake security requests that prompt Microsoft 365 users to enroll a new Entra passkey with an aim to carry out data extortion attacks. The threat actor, tracked by Okta under the moniker O-U…THEHACKERNEWS.COM
10 JulOkta Warns of Vishing Attacks Targeting Microsoft 365 CustomersThe attackers call victims to direct them to phishing websites mirroring Microsoft Entra ID login pages. The post Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers appeared first on SecurityWeek .SECURITYWEEK.COM
10 JulZimbra patches a critical flaw in its Classic Web Client.GigaWiper combines espionage capabilities with destructive payloads. Helix extortion gang conducts device-code phishing attacks.THECYBERWIRE.COM
10 JulMicrosoft Warns New 'GigaWiper' Malware Combines Espionage and Destructive CapabilitiesA new multi-purpose backdoor allows cyber threat actors to conduct both quiet espionage activity and destructive wiping operationsINFOSECURITY-MAGAZINE.COM
10 JulSecuring our future: July 2026 progress report on Microsoft’s Secure Future InitiativeMicrosoft’s latest Secure Future Initiative report outlines progress on secure foundations, AI-powered defense, and future-ready cybersecurity. The post Securing our future: July 2026 progress report on Microsoft’s Secure Future Initiative appeared first on Microsoft Securi…MICROSOFT.COM
10 JulBorg, GitLost, ColdFusion, GodDamn, GhostApproval, OWA, Epaphroditus, Josh Marpet & More - SWN #597Borg, GitLost, ColdFusion, GodDamn, GhostApproval, OWA, Epaphroditus, Locutus, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-597YOUTUBE.COM
9 JulISC Stormcast For Thursday, July 9th, 2026 https://isc.sans.edu/podcastdetail/10000, (Thu, Jul 9th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
9 Jul_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary], (Tue, Jul 7th)[This is a Guest Diary by Jason Callahan, an ISC intern as part of the SANS.edu BACS program]
ISC.SANS.EDU
9 JulA single malware file can outweigh an entire AI datasetAntivirus vendors and security startups keep shipping AI features that promise to read malware the way a seasoned analyst would. The results inside security teams tell a quieter story. A new paper argues that static analysis of software, the job of deciding whether a program is m…HELPNETSECURITY.COM
9 JulProduct showcase: Protect your iPhone with McAfee Mobile SecurityMcAfee Mobile Security for iOS combines scam protection, web protection, VPN, Wi-Fi security, and device security checks in a single app. It is also available for Android. After downloading the app from the App Store, I created an account and completed a short onboarding process.…HELPNETSECURITY.COM
9 JulWireshark 4.6.7 patches a dozen security flawsNetwork analysts who open packet captures in Wireshark push untrusted data through a large set of protocol dissectors, and each parser is a spot where a malformed frame can trip up the software. The 4.6.7 maintenance release closes twelve of those weak points. The fixes reach fro…HELPNETSECURITY.COM
9 JulMessaging fraud trends point to smarter attacks, stronger blockingFraudsters spent 2025 investing in scale. New routes, new tools, and higher message volumes moved through the SMS, voice, and chat channels that businesses rely on to reach customers. Money follows that activity. The Communications Fraud Control Association puts global telecom fr…HELPNETSECURITY.COM
9 JulMalicious AI agent skills can slip past the scanners built to stop themDevelopers who build with AI coding agents grab capabilities off public marketplaces the same way they grab packages from npm or PyPI. The add-ons are called agent skills. Each one is a little bundle of plain-English instructions, scripts, and files that a tool such as Claude Cod…HELPNETSECURITY.COM
9 JulThe fake report message that ends with a stolen Reddit accountA direct message arrives on Reddit from a stranger, and it invites a reply. That reply is the point. This scheme runs on social engineering, with no malware and no malicious links, and it has spread across Reddit, Discord, and similar platforms. The goal is a single piece of info…HELPNETSECURITY.COM
9 Jul8Layers Raises $2.9 Million for Identity Security PlatformThe Spanish startup has closed an extended pre-seed funding round two months after launching its digital identity protection platform. The post 8Layers Raises $2.9 Million for Identity Security Platform appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulDetection engineering in the AI eraAI is lowering the barrier to sophisticated attacks. Explore why detection engineering matters and where most programs fall short. The post Detection engineering in the AI era appeared first on Intezer .INTEZER.COM
9 JulAWS centralizes access, spending, and governance for ClaudeClaude apps gateway for AWS is a self-hosted control plane that gives organizations a single point of control over access, costs, and policies for Claude Code and Claude Desktop. It replaces per-developer cloud credentials, manual distribution of managed settings to developer lap…HELPNETSECURITY.COM
9 JulNetSPI pairs AI pentesting with expert-validated security findingsNetSPI has announced the expansion of its AI-powered continuous pentesting platform, broadening the suite of services that organizations can use to ensure critical assets are always protected. The new services comprise continuous web application penetration testing, continuous AI…HELPNETSECURITY.COM
9 JulYour coding agent says no in chat and yes in the codeMillions of developers share their keyboard with GitHub Copilot. Inside Visual Studio Code, it opens their files, writes and edits code, runs scripts, and reworks its own output across many turns. The safety testing that vets these agents still runs on chatbot rules: one harmful …HELPNETSECURITY.COM
9 JulThe Two BIOS Passwords Everyone ConfusesTL;DR: The setup password and the boot password are different controls that protect different things; vendors give them half a dozen different names, and mixing them up leaves real gaps below the OS. Two Passwords, Two Different Jobs When someone tells me “we set the BIOS p…ECLYPSIUM.COM
9 JulVibe-Coded Malware Caught in Active Directory AttackHuntress found a threat actor using vibe-coded PowerShell to map an Active Directory networkINFOSECURITY-MAGAZINE.COM
9 JulCitrix launches MCP Gateway to secure enterprise AI agentsCitrix has announced updates to its high-performance application delivery and security platform NetScaler, introducing MCP Gateway functionality to allow enterprises to securely route, govern and observe agent traffic to backend Model Context Protocol (MCP) servers. In addition, …HELPNETSECURITY.COM
9 JulVectogate debuts platform to secure and govern autonomous AI agentsVectogate has launched an AI governance platform designed to give organizations centralized control over AI agents as they increasingly take on autonomous tasks with access to sensitive data and internal business systems. The company aims to address one of the key governance chal…HELPNETSECURITY.COM
9 JulQIZ Security Raises $17 Million for Cryptographic Governance PlatformThe Israeli company has developed a cryptographic posture and post-quantum cryptography management platform. The post QIZ Security Raises $17 Million for Cryptographic Governance Platform appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulUK Government Rolls Out Agentic AI Defense Plan Alongside Industry PledgeTwo announcements on July 7, 2026, demonstrate the government’s determination to improve the level of cybersecurity within the UK. The post UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulExtortion crew hijacks Microsoft 365 accounts via fake passkey setupThe Pink cyber extortion crew is tricking employees into giving them access to their Microsoft 365 accounts by faking Entra passkey enrollment requests. The attack The attack starts with a vishing call to an employee. The caller poses as IT and says it’s time to set up a pa…HELPNETSECURITY.COM
9 JulHow GitHub gave every repository a durable ownerGitHub had over 14,000 repositories. Fewer than half had clear ownership. Here's how we gave every active repository a validated owner in under 45 days, archived the rest, and made ownership the foundation for everything that followed. The post How GitHub gave every repository a …GITHUB.BLOG
9 JulInterpol cybercrime crackdown nets 5,800 arrests across 97 countriesThe anti-fraud crackdown, dubbed Operation First Light, identified more than 142,000 victims of various social-engineering scams. The post Interpol cybercrime crackdown nets 5,800 arrests across 97 countries appeared first on CyberScoop .CYBERSCOOP.COM
8 JulISC Stormcast For Wednesday, July 8th, 2026 https://isc.sans.edu/podcastdetail/9998, (Wed, Jul 8th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
8 JulOpenAI and Anthropic are pulling in different directionsCompanies are handing routine operational decisions to AI agents that plan, remember, and act on their behalf. These agents run on statistical models, and their behavior can drift across weeks and months. That drift opens a security gap outside the reach of standard monitoring to…HELPNETSECURITY.COM
8 JulmacOS is becoming a proving ground for AI agentsSomewhere right now, a Mac Mini is sitting on a shelf doing someone’s chores. Nobody’s watching it. It reads a version number out of Terminal, hops over to Safari, digs up a release year, then quietly files a reminder, the kind of dull three-app errand a human would g…HELPNETSECURITY.COM
8 JulHow to implement a continuous offensive security testing programThe hard part was never finding the exposure. It was deciding what to do about it: whether to patch, mitigate, monitor, or accept, and banking that that decision would still hold tomorrow. A penetration test answers this question for the day it runs, then quietly expires. The env…HELPNETSECURITY.COM
8 JulClaude Cowork turns your phone into a remote control for AI workAnthropic started rolling out Claude Cowork, an AI agent that completes multi-step tasks, in beta for Max users on mobile and the web. They describe a goal, and Claude plans the work, uses the required tools, and produces outputs such as documents, spreadsheets, presentations, an…HELPNETSECURITY.COM
8 JulThousands of malicious AI skills found capable of stealing data, running malwareAI agents can browse the web, use external tools, execute commands, and perform tasks on behalf of users. Many rely on skills that define how they interact with services and data. Malicious skills can abuse those capabilities to steal data, execute malware, or manipulate an agent…HELPNETSECURITY.COM
8 JulScienceLogic adds geographic service visibility to Skylar OneScienceLogic has released the “Kyoto” update for Skylar One, the core observability offering in its AI Platform. The release adds geographic service visibility, simplified location and device management, enhanced relationship mapping, and platform updates aimed at imp…HELPNETSECURITY.COM
8 JulCodenotary launches AI security platform that learns from AI agent behaviorCodenotary has announced AgentMon 3, the latest generation of its enterprise AI security platform, introducing adaptive runtime security policies. These continuously evolve as AI agents operate across an organization by learning from customer-specific workflows, observed behavior…HELPNETSECURITY.COM
8 JulChina-Linked UAT-7810 Expands ORB Network With New LONGLEASH MalwareA Chinese threat actor tracked as UAT-7810 is actively refining its bespoke malware to expand its Operational Relay Box (ORB) network by breaking into internet-facing networking devices. According to findings from Cisco Talos, UAT-7810 is an advanced persistent threat (APT) actor…THEHACKERNEWS.COM
8 JulWhat Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find OutBurst water mains. Evacuated hospitals. In a closed-door simulation, insurers played out their response to a mass disruption by China’s Volt Typhoon hackers—and found a nightmare scenario.WIRED.COM
8 JulAutomox MCP Server adds visual reviews and AI-driven patch policy creationAutomox has released Automox MCP Server 2.2, adding interactive review surfaces, first-class Patch by Severity policy creation, and live capability discovery to its governed agentic interface for endpoint operations. The release advances Automox MCP beyond natural-language access…HELPNETSECURITY.COM
8 JulNew Malicious Campaign Delivers Vidar Infostealer and Monero Crypto MinerCyber threat actors are infecting victims with the Vidar stealer and the XMRig cryptocurrency miner in a new malicious campaignINFOSECURITY-MAGAZINE.COM
8 JulTelegram-Hosted RedWing Malware Lets Anyone Rent Android Spyware ToolsRedWing: The Android Banking Trojan You Can Rent on Telegram for Less Than a Coffee Subscription Zimperium’s zLabs team has uncovered RedWing, an Android spyware operation sold as a subscription service through Telegram, with links to Russian threat actors and apparent root…SECURITYAFFAIRS.COM
8 JulThreat Actors Uses Agentic AI to Rapidly Compromise Cloud TargetSygnia report details how agentic AI accelerated weeks-long attack to just 72 hoursINFOSECURITY-MAGAZINE.COM
8 JulDNSFilter makes its DNS threat protection available to OEM partnersDNSFilter has launched an Original Equipment Manufacturing (OEM) program that lets external ISPs, cybersecurity firms, device makers, and other consumer app developers to embed their DNS threat protection, domain analysis, and privacy solutions into their own platforms and soluti…HELPNETSECURITY.COM
8 JulAttestiv DeepScan combines AI and forensic analysis for file validationAttestiv announced the launch of DeepScan, a new platform built to help organizations automatically validate submitted files before they drive critical business decisions. DeepScan represents a major architectural shift for Attestiv and its customers: moving from detecting fake o…HELPNETSECURITY.COM
8 JulWebinar Today: Why Email Security Keeps FailingJoin the webinar as we break down why email-layer defenses alone can’t keep pace with the modern phishing ecosystem. The post Webinar Today: Why Email Security Keeps Failing appeared first on SecurityWeek .SECURITYWEEK.COM
8 JulCensys Internet Map links real-time DNS data to internet infrastructureCensys has announced the expansion of the Censys Internet Map to include real-time DNS visibility. Security teams can now seamlessly pivot between domains, names, and the Internet infrastructure behind them on the Censys Platform. With active DNS data now part of the Internet Map…HELPNETSECURITY.COM
8 JulBlackpoint AI SOC Agent autonomously contains identity-based attacksBlackpoint Cyber has unveiled the generally available autonomous response capability, Blackpoint AI SOC Agent for identity threat detection and response (ITDR). Using an AI + human hybrid model, the AI SOC Agent acts on high-confidence threats targeting Microsoft 365 and Google W…HELPNETSECURITY.COM
8 JulFirst Recon AI Security Runtime helps enterprises govern AI with audit-ready evidenceFirst Recon AI has announced the public launch and general availability of First Recon’s AI Security Runtime, a security platform that both governs and secures how enterprises use artificial intelligence across an organization. First Recon’s runtime inspects every AI …HELPNETSECURITY.COM
8 JulFalconStor Cloud Clean Room enables validated recovery without dedicated infrastructureFalconStor has announced FalconStor Cloud Clean Room, an on-demand infrastructure platform designed to let organizations perform validated recovery testing in a persistent secure enclave. Each test starts from a known state, reducing the risk of carrying issues over from previous…HELPNETSECURITY.COM
8 JulSCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking UsersA new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges using ClickFix lures. The activity cluster, tracked by Elastic Security Labs under the moniker REF6045, involves infecting victims through fake CA…THEHACKERNEWS.COM
8 JulChina-Linked APT Expands Proxy Network With New MalwareCisco Talos said China-linked APT UAT-7810 is growing its proxy relay network with new malwareINFOSECURITY-MAGAZINE.COM
8 JulUS enterprises incorporate cyber risk into larger strategic focusThe rapid adoption of AI and cloud is forcing significant shifts toward business resilience and financial impact.CYBERSECURITYDIVE.COM
8 JulTrojanized LetsVPN installer gives attackers remote access to Windows PCsA malicious Windows installer masquerading as LetsVPN deploys a remote access trojan (RAT) alongside the legitimate VPN software. The malware, dubbed GoodPersonRAT, grants attackers full control over infected systems and employs multiple stealth techniques to evade detection. The…CYBERINSIDER.COM
8 JulDuckDuckGo browser adds built-in YouTube ad blocking systemDuckDuckGo has added built-in YouTube ad blocking to its privacy-focused browser, allowing users to watch most YouTube videos without pre-roll or mid-roll advertisements. The feature is now enabled by default on Windows, macOS, and iPhone, while Android users can enable it manual…CYBERINSIDER.COM
8 JulChina-Linked APT Expands Arsenal With New ‘Leash’ BackdoorsCisco says the threat actor behind the LapDogs campaign has expanded its SOHO router malware toolkit with LongLeash, DogLeash, and JarLeash backdoors. The post China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors appeared first on SecurityWeek .SECURITYWEEK.COM
8 JulAI Surveillance Is Being Supercharged–And It Will Chill Social ProgressSenior research fellow Jon Penney and co-author Bruce Schneier argue that widely deploying AI surveillance could be corrosive to democracy. The post AI Surveillance Is Being Supercharged–And It Will Chill Social Progress appeared first on The Citizen Lab .CITIZENLAB.CA
8 JulTaiwan charges two businessmen over alleged role in Chinese espionage campaignA company based in Taiwan was leasing out accounts on the popular LINE messaging app to Chinese spies, according to prosecutors, who charged two men in the alleged scheme.THERECORD.MEDIA
8 JulEntra passkey enrollment vishing targets Microsoft 365 usersA threat actor has been targeting organizations across multiple sectors with voice-based fake security requests that ask Microsoft 365 users to enroll a new Entra passkey. [...]BLEEPINGCOMPUTER.COM
8 JulProtecting Microsoft at AI speed: How SFI proactively hardens our cloudAt Microsoft we encompass these security requirements, along with threat knowledge, and operational frameworks in our Secure Future Initiative (SFI), to guide what a well-defended cloud service looks like. But defining the requirements is only the start. Meeting the requirements …MICROSOFT.COM
8 JulFrench nonprofit starts global intelligence and research hub for AI cyber threatsOne of the project’s top goals is stitching together an international, quick response coalition of governments, businesses and civil experts for AI-related threats. The post French nonprofit starts global intelligence and research hub for AI cyber threats appeared first on CyberS…CYBERSCOOP.COM
8 JulAI Could Shrink Leadership PipelinesMany discussions about AI focus on entry-level jobs. But organizational changes don't stop there. If AI reduces the need for some entry-level and middle-management roles, it could also shrink the pipeline of employees who traditionally develop into senior leaders. Fewer opportuni…YOUTUBE.COM
7 JulISC Stormcast For Tuesday, July 7th, 2026 https://isc.sans.edu/podcastdetail/9996, (Tue, Jul 7th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
7 JulReview: Building Machine Learning Systems with a Feature StoreMany people come to machine learning by training a model on a tidy dataset, and then meet a harder problem: making that model work for real users, on fresh data, every day. Jim Dowling’s O’Reilly book, Building Machine Learning Systems with a Feature Store, is written…HELPNETSECURITY.COM
7 JulYour company already adopted AI and nobody is governing accessIn this Help Net Security video, Antoine Berton, CTO at Elba Security, breaks down the AI attack surface. Your company already adopted AI, and every adoption creates access that nobody governs. A quick click on a Friday afternoon connects a free AI tool to your Google Workspace, …HELPNETSECURITY.COM
7 JulResearchers make the case for a cybersecurity AI scientistAutonomous AI agents have started doing real security work. Language-model agents probe software for flaws, run penetration tests, and chain together attack steps that once needed a human operator. Research about security has stayed slower and more manual, built around expert sca…HELPNETSECURITY.COM
7 JulKeyfactor Scores $1 Billion+ Investment for AI, Post-Quantum SecurityThe investment will accelerate Keyfactor's machine identity, PKI, and cryptographic security platform as enterprises prepare for AI-driven and post-quantum threats. The post Keyfactor Scores $1 Billion+ Investment for AI, Post-Quantum Security appeared first on SecurityWeek .SECURITYWEEK.COM
7 JulAI-Generated Malware Powers New Armored Likho APT CampaignArmored Likho APT uses AI-generated malware, phishing, and BusySnake Stealer to target governments and power grids in Russia, Kazakhstan, and Brazil. Kaspersky’s threat research team has documented a previously unknown APT group they’re calling Armored Likho, also tra…SECURITYAFFAIRS.COM
7 JulGoogle Is Suing Chinese Scammers Who Are Using GeminiNot sure this will have any effect, but I support the effort: According to Google’s legal filing, Outsider Enterprise operates through Telegram. The group offers phishing-as-a-service to individuals who may not be technically savvy enough to set up fraudulent websites and t…SCHNEIER.COM
7 JulUAT-7810 continues building ORB networks using new malwareTalos’ latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware.TALOSINTELLIGENCE.COM
7 JulThe Navy Spy who Sold Secrets for $377 a YearYou may have heard of the long-running TV show NCIS, based on the real work of the Naval Criminal Investigative Service. But you may never have heard of a unit inside it, called the Office of Special Projects, where staff work on espionage cases that originate inside the U.S. Nav…THECYBERWIRE.COM
7 JulCISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original ThinkerTarah Wheeler is CISO at TPO Group, a firm that provides cybersecurity consultancy for high-stakes organizations. But despite this elevated position, her journey was far from typical. The post CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Th…SECURITYWEEK.COM
7 JulBarracuda adds PAM and identity protection with Evo Security acquisitionBarracuda Networks has acquired Evo Security. The acquisition expands the BarracudaONE platform’s identity security capabilities by adding privileged access management (PAM), access control, identity protection, and identity threat detection and response. By combining Evo S…HELPNETSECURITY.COM
7 JulCyberProof Agentic MXDR Service brings AI agents to managed detection and responseCyberProof has announced the launch of the CyberProof Agentic MXDR Service which connects AI agents with human expertise and presents quantifiable security outcomes with CyberProof’s Reveal360. CyberProof modernizes managed detection and response by shifting security operat…HELPNETSECURITY.COM
7 JulPost-Mythos Cybersecurity: Can You Automate Infrastructure Assurance with AI?TL;DR: Security leaders should absolutely reassess their cybersecurity programs in light of Mythos, Daybreak, and other frontier AI models. AI will make some workflows easier to automate, some internal tools easier to build, and some vendor spend harder to justify. But the risk-r…ECLYPSIUM.COM
7 JulSecurity or Privacy: Which Comes First?Security and privacy don't always point in the same direction. Many modern applications rely on stronger verification or deeper system access to reduce fraud, cheating, and abuse. Those protections can also increase privacy concerns. Whether it's kernel-level anti-cheat software …YOUTUBE.COM
7 JulBusinesses modernizing networks for AI fear expanding attack surface, limited visibilityIT leaders are worried that security controls aren’t keeping pace with threats to AI systems.CYBERSECURITYDIVE.COM
7 JulRedWing MaaS Packages Android Bank Fraud as a Telegram Rental ServiceA new Android malware operation called RedWing is being rented out on Telegram as a ready-made bank-fraud service. It lets even low-skill criminals take over a victim's phone, steal their banking logins, and capture the one-time codes that protect their accounts. Zimperium's zLab…THEHACKERNEWS.COM
7 JulMicrosoft Windows telemetry identified hacker despite VPN useMicrosoft identified an alleged Scattered Spider member through Windows telemetry despite the suspect using a VPN to mask his IP address. The details appear in the superseding criminal complaint against Peter Stokes, whose extradition to the United States we covered last week. A …CYBERINSIDER.COM
7 JulMore Odd DNS Records: NIMLOC, (Tue, Jul 7th)Yesterday, I talked about NAPTR records and how they are related to RCS. But there is another "odd" record that shows up in my DNS logs. This one isn&#;x26;#;39;t new, but I don&#;x26;#;39;t think I ever covered it: NIMLOC. …ISC.SANS.EDU
7 JulWireVPN service linked to years-long residential proxy operationA VPN service with more than one million Android downloads is at the center of a long-running operation that allegedly recruits victims' devices into a residential proxy network. The Infoblox investigation began after researchers analyzed the infrastructure behind a malicious ins…CYBERINSIDER.COM
7 JulSpanish Police Arrest Man Linked to CARR, Z-Pentest, and NoName057(16)Spain arrested a suspected CARR and Z-Pentest collaborator in an FBI-led probe for aiding pro-Russian hackers, coordinating attacks, and using crypto. Spanish National Police arrested a man in Palencia last March on charges of membership in and collaboration with a terrorist orga…SECURITYAFFAIRS.COM
7 JulDeepfake CSAM lawsuit against xAI, Grok expandsTwo new alleged victims detailed how Grok was used by friends and family to generate sexual images of them as minors. The suit also adds Stability AI as a defendant. The post Deepfake CSAM lawsuit against xAI, Grok expands appeared first on CyberScoop .CYBERSCOOP.COM
7 JulWatch out for fake support calls in Microsoft TeamsPalo Alto Networks’ security division, Unit 42, is warning of yet another campaign targeting Microsoft Teams users . The new campaign begins with Teams users receiving an email asking if they would like to participate in a survey. If they open the attached PDF file, they will sho…CSOONLINE.COM
7 JulDune References, FAT, Claude, ZhiPu, PolinRider, RentaBot, Sony, Aaran Leyland & More - SWN #596Dune References, FAT, Claude, ZhiPu, PolinRider, RentaBot, Sony, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-596YOUTUBE.COM
7 JulSpain arrests suspected hacker linked to Russian hacktivist campaignAuthorities didn’t name the man or file formal charges, but accuse him of participating in attacks linked to Cyber Army of Russia Reborn and NoName. The post Spain arrests suspected hacker linked to Russian hacktivist campaign appeared first on CyberScoop .CYBERSCOOP.COM
7 JulVidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File InflationA cybercrime campaign combined a loader-as-a-service framework and DLL sideloading via a Go-compiled fake MpClient.dll, a novel evasion layer combination. The post Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
7 JulGitHub's Joke Backfired FastGitHub appeared to poke fun at Sony's decision to move away from optical media by offering developers CD-ROM copies of their public repositories. The offer included a real request form, and enough people treated it seriously that GitHub removed it early. Whether it began as a mar…YOUTUBE.COM
6 JulProduct showcase: Is that text a scam? Malwarebytes Mobile Security can help you find outMalwarebytes Mobile Security for iPhone combines scam prevention, privacy protection, and identity monitoring in a single app. It evaluates a device’s security posture, provides recommendations to improve protection, and is available for Windows, macOS, Android, iOS, and Ch…HELPNETSECURITY.COM
6 JulOAuth, guest accounts, and weak MFA drive SaaS riskOrganizations often create guest accounts to give contractors, suppliers, and partners temporary access to files and SaaS applications. Many of these accounts remain active long after they are needed, creating overlooked access paths to corporate data. Guest accounts accounted fo…HELPNETSECURITY.COM
6 JulWhen checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft websiteThe OAuth 2.0 Device Authorization Grant specification was designed to streamline authentication for Smart TVs, IoT devices, and printers. Today, threat actors are weaponizing it.SECURELIST.COM
6 JulISC Stormcast For Monday, July 6th, 2026 https://isc.sans.edu/podcastdetail/9994, (Mon, Jul 6th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
6 JulRCS and DNS: The NAPTR Record, (Mon, Jul 6th)Over the last year, with recent updates to iOS and Android, RCS (Rich Communication Services) has become an increasingly used protocol [1]. RCS is supposed to eventually replace SMS, and in addition to richer formatting, provides added (but optional) security. RCS messa…ISC.SANS.EDU
6 JulUkrainian media outlets now among 'priority targets' for Russian hackersA top Ukrainian security official described two previously unreported attacks on TV media organizations and said Russia has ramped up hacking activities against the industry.THERECORD.MEDIA
6 JulOpenSSH 10.4 arrives with security fixes and a post-quantum signature optionOperators who manage remote access to Unix and Linux systems keep a close watch on OpenSSH, the software that carries most SSH traffic across the internet. The project released version 10.4 with eight security fixes, a set of bug corrections, and a couple of new features. What th…HELPNETSECURITY.COM
6 JulCheap AI Will Handle Most TasksFuture AI systems are expected to split work between lightweight local models and larger cloud-based foundation models. Simple tasks can be completed by inexpensive models, while advanced reasoning is reserved for more capable—and more expensive—AI. This hybrid approach could low…YOUTUBE.COM
6 JulAlleged member of Scattered Spider extradited to USA man with dual US-Estonian citizenship was charged in connection to the hack of a luxury jewelry retailer.CYBERSECURITYDIVE.COM
6 JulThe Shift Toward Business-Aligned Risk ManagementMoving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. The post The Shift Toward Business-Aligned Risk Management appeared first on SecurityWeek .SECURITYWEEK.COM
6 JulArmored Likho APT Targeting Government, Electric Power EntitiesThe threat actor uses modular RATs and information stealers in financially motivated and cyber espionage campaigns. The post Armored Likho APT Targeting Government, Electric Power Entities appeared first on SecurityWeek .SECURITYWEEK.COM
6 JulUS Army websites defaced with pro-Kurdish sentiments, insults to TrumpAt least two websites appear to be victim to 404 hijacking attacks. Army officials took the sites down after being contacted by CyberScoop. The post US Army websites defaced with pro-Kurdish sentiments, insults to Trump appeared first on CyberScoop .CYBERSCOOP.COM
6 JulExpressVPN adds passkeys on password manager, passes security auditExpressVPN has announced a major update to its standalone ExpressKeys password manager, adding passkey support, secure credential sharing, and direct vault imports. Alongside the release, the company published a new independent security assessment by Cure53, which found no severe…CYBERINSIDER.COM
6 JulFake IT support calls on Microsoft Teams push EtherRAT malwareThreat actors are abusing Microsoft Teams voice calls by impersonating corporate IT support staff to trick employees into installing the EtherRAT malware, giving attackers initial access to corporate networks. [...]BLEEPINGCOMPUTER.COM
6 JuluBlock Origin Chrome extension now blocks known ClickFix sitesuBlock Origin has quietly added protections against ClickFix attacks to its built-in badware filter list, helping block access to websites that attempt to trick users into copying and executing malicious commands. The capability came to light through a user discussion on Mastodon…CYBERINSIDER.COM
5 JulSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 104Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Hijacked npm Packages Use Novel VSCode Autorun and Blockchain Dead Drops to Deploy a Credential/Crypto Stealer Buil…SECURITYAFFAIRS.COM
4 JulNorth Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider CampaignThe North Korean threat actors linked to the Contagious Interview campaign have been observed publishing 108 unique packages and web browser extensions spanning npm, Packagist, Go, and Google Chrome as part of an ongoing activity referred to as PolinRider. "The campaign remains a…THEHACKERNEWS.COM
4 JulAI Tested Against Cyber ExpertsCybersecurity platforms like Hack The Box are being used to benchmark both human practitioners and AI models in the same realistic lab environments. Government AI security institutes have also used these systems to evaluate advanced models. This creates one of the clearest real-w…YOUTUBE.COM
3 JulGoogle Disrupts NetNut Residential Proxy Network Spanning 2 Million Home DevicesGoogle has significantly degraded NetNut, one of the biggest networks that turns home devices into rented relays for other people's traffic. Working with the FBI, Lumen, and others, Google's Threat Intelligence Group (GTIG) said this week it had reduced the network's po…THEHACKERNEWS.COM
3 JulNew infosec products of the week: July 3, 2026Here’s a look at the most interesting products from the past week, featuring releases from Digi International, iboss, Jamf, and Netzilo. Digi International’s DANI automates network diagnostics and device management Digi International has announced the launch of DANI, the Digi Art…HELPNETSECURITY.COM
3 JulSomeone infected a spyware probe overseer with spywareCitizen Lab says the phone of a member of Europe’s PEGA Committee was infected twice with Pegasus, the NSO Group spyware that gave the panel its name. The post Someone infected a spyware probe overseer with spyware appeared first on CyberScoop .CYBERSCOOP.COM
3 JulGeopolitical cyber threats are turning HR into a security front lineIn this Help Net Security video, Roman Sannikov, Global Research Coordinator at iCOUNTER, explains why geopolitics belongs in every security team’s threat model. With open and simmering conflicts around the world, attacks can come from actors that would never have targeted …HELPNETSECURITY.COM
3 JulNon-interactive SSH attacks dominate after loginAnyone who runs a server with SSH exposed to the internet sees the same pattern in the logs. A steady stream of automated scanners tries to log in, hour after hour, from addresses all over the world. The common picture of what comes next has an attacker landing a shell, looking a…HELPNETSECURITY.COM
3 JulIntezer helps SOC teams automate custom security tasksIntezer has announced Custom Agents, a new capability that lets security teams build their own AI agents directly inside the Intezer platform. The launch builds on Intezer’s core approach, that lets autonomous agents do the security work and humans supervise it. Security teams ca…HELPNETSECURITY.COM
3 JulArmored Likho digging a snake pit: inside the covert BusySnake Stealer campaignAn inside look at the active Armored Likho APT campaign. The attackers are using spear-phishing, AI-generated loaders, and a new Python-based tool, BusySnake Stealer, to target organizations in Russia, Kazakhstan, and Brazil.SECURELIST.COM
3 JulFBI, Google Take Down NetNut Proxy Network Used by Cyber Threat ActorsThe NetNut proxy network and the ‘Popa’ botnet are known to have infected devices with variants of Mirai DDoS botnetsINFOSECURITY-MAGAZINE.COM
3 JulAlleged Scattered Spider Hacker Extradited to USProsecutors say 19-year-old Peter Stokes was a member of Scattered Spider, the hacking group linked to more than 100 network intrusions and over $100 million in ransom payments. The post Alleged Scattered Spider Hacker Extradited to US appeared first on SecurityWeek .SECURITYWEEK.COM
3 JulEN 303 645 is the baseline, not the finish line for IoT securityTL;DR Why EN 303 645 matters ETSI EN 303 645 has given consumer IoT security a much-needed baseline. It gives manufacturers, assessors, and product teams a shared view of reasonable IoT security and something concrete to work against. But after years of assessing prod…PENTESTPARTNERS.COM
3 JulNorth Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer SecretsThreat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup polyfill tooling to facilitate remote access and data theft. According to JFrog, the packages "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-co…THEHACKERNEWS.COM
3 JulApple AirDrop and Android Quick Share flaws expose users to wireless attacksSecurity researchers have identified six previously undocumented vulnerabilities in Apple AirDrop and Google/Samsung Quick Share after conducting the first comprehensive reverse engineering and security analysis of both proprietary proximity file-sharing protocols. While the flaw…CYBERINSIDER.COM
3 JulBeyond the AI Hype, Cyber Readiness in the Age of AI - Gibb Witham - SWN #595I talk to Gibb Witham, President of Hack The Box, about cyber readiness, hands-on security training, Hack The Box, and AI in cybersecurity. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-595YOUTUBE.COM
3 JulAI Becomes Cybersecurity Operating SystemAI is being used in cybersecurity to automate low-level tasks and accelerate operational workflows, particularly in offensive contexts. Rather than replacing human operators, AI is acting as an “operating system” for cybersecurity work. It improves speed in both defensive and off…YOUTUBE.COM
2 JulISC Stormcast For Thursday, July 2nd, 2026 https://isc.sans.edu/podcastdetail/9992, (Thu, Jul 2nd)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
2 JulIs the next frontier model your biggest threat or your best defender?If you think the recent wave of AI-discovered vulnerabilities is a problem, Rob Bair of Anthropic has a reframe for you. Discovery is the easy part. Closing the remediation gap is now the defining security challenge. Drawing on his experience in the Navy, in national security, an…THECYBERWIRE.COM
2 JulSrsly Risky Biz: America won't beat the distillation ecosystemTom Uren and James Wilson talk about Chinese AI labs stealing the special sauce of American AI models in ‘distillation attacks’. These attacks are fed by a grey market in which Chinese consumers buy access to American models, where one of the byproducts is logs of user requests a…RISKY.BIZ
2 JulOpera introduces Paste Protect feature to block ClickFix attacksOpera has introduced a new browser security feature called Paste Protect, designed to stop clipboard-based attacks such as ClickFix before users can execute malicious commands. The feature is enabled by default in Opera's desktop browser, and the company says it is the first majo…CYBERINSIDER.COM
2 JulCloudflare changes AI crawler access rulesCloudflare introduced new controls that let website owners manage AI traffic across three categories: Search, Agent, and Training. The feature is available to all Cloudflare customers, including those on the Free plan, and gives website owners more control over how different type…HELPNETSECURITY.COM
2 JulIntroducing Custom Agents: Automate your SOC, your wayAdd your own agents and automations on top of the ones Intezer runs out of the box, take more of the manual work off your analysts, and tailor AI SOC to the way your team actually operates. The post Introducing Custom Agents: Automate your SOC, your way appeared first on Intezer …INTEZER.COM
2 JulToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google APIThe threat actor known as ToddyCat has been attributed to a new malware called Umbrij that's designed to gain surreptitious access to a victim's email correspondence via the Google API. "In this campaign, the attackers focused their attention on corporate email communications hos…THEHACKERNEWS.COM
2 JulYou Ruled Yourself Out Too SoonEarly interest in technology and cybersecurity didn’t automatically turn into confidence. At eighteen, the assumption was that a career in cyber “probably wasn’t in the cards,” despite the interest already being there. That mindset is common across industries. People often elimin…YOUTUBE.COM
2 JulHow to Conduct a Successful Audit of AI-Driven Software DevelopmentAs AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. The post How to Conduct a Successful Audit of AI-Driven Software Development appeared first on…SECURITYWEEK.COM
2 JulHow GitHub used secret scanning to reach inbox zeroGitHub had 20,000+ secret scanning alerts across 15,000 repositories. Here's how we separated signal from noise, built remediation workflows, and reached inbox zero in nine months. The post How GitHub used secret scanning to reach inbox zero appeared first on The GitHub Blog .GITHUB.BLOG
2 JulAlleged longstanding member of Scattered Spider extradited to USPeter Stokes boasted on social media about the luxurious globetrotting life he enjoyed while he was still a child. The post Alleged longstanding member of Scattered Spider extradited to US appeared first on CyberScoop .CYBERSCOOP.COM
2 JulScattered Spider member extradited to the U.S. facing cybercrime chargesThe U.S. Department of Justice has announced the arrest and extradition of an alleged member of the notorious cybercrime group Scattered Spider. According to the Justice Department, Scattered Spider has been involved in more than 100 network intrusions, resulting in over $100 mil…CYBERINSIDER.COM
2 JulGoogle loses final appeal against €4.1 billion Android antitrust fineThe European Union's highest court has upheld a €4.125 billion ($4.8 billion) antitrust fine against Google, bringing to an end the company's appeal over allegations that it abused Android's dominant market position to strengthen its search business. The ruling confirms that Goog…CYBERINSIDER.COM
2 JulImproving security posture across the Microsoft partner ecosystemRead how Microsoft strengthens partner ecosystem security with CSP vetting, least privilege access, monitoring, and risk management best practices. The post Improving security posture across the Microsoft partner ecosystem appeared first on Microsoft Security Blog .MICROSOFT.COM
2 JulBrave browser introduces Containers for secure account isolationBrave has released version 1.92 of its privacy-focused browser, introducing built-in Containers that let users isolate browser tabs into separate identities for improved workflow and account management. While similar functionality has been available through extensions, Brave’s na…CYBERINSIDER.COM
2 JulTechnical Blueprint: Hardware Security for AI InfrastructureDownload the PDF > Executive Summary This document details the necessary effort to implement the Eclypsium Hardware Supply Chain Security Platform to address critical hardware supply chain vulnerabilities, infrastructure integrity, and component-level security gaps within Departm…ECLYPSIUM.COM
2 JulHow We Added WebAuthn to a Browser-Based RDP ClientA look inside the reverse-engineering journey of building the first RDP client outside of Windows to support WebAuthn redirection. The post How We Added WebAuthn to a Browser-Based RDP Client appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
1 JulISC Stormcast For Wednesday, July 1st, 2026 https://isc.sans.edu/podcastdetail/9990, (Wed, Jul 1st)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
1 JulGetting boards to fund ERM means speaking their currencyIn this Help Net Security video, Greg Young, VP Cybersecurity and Corporate Development at TrendAI, explains how to build Enterprise Risk Management that a board will pay for. Drawing on nearly four decades in cybersecurity, including time as a CISO and 14 years as a Gartner anal…HELPNETSECURITY.COM
1 JulThis supercomputer encrypts your data even while it’s running itMost people who handle sensitive data already encrypt it in two places. They lock it down when it sits on a hard drive, and they lock it down when it moves across a network. There has always been a third moment that stayed open. The instant a computer pulls that data into memory …HELPNETSECURITY.COM
1 JulRisky Business #844 -- China closes AI vulndev gap as USA lifts Fable banOn this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover: Anthropic’s Fable 5 returning while OpenAI’s GPT-5.6 gets thrown in model jail Distillation, cheap tokens, and AI chat harvesting is an industry in China Edge become…RISKY.BIZ
1 JulGoogle Patches 382 Chrome VulnerabilitiesFifteen of the newly patched flaws have been rated ‘critical’ and 67 have been rated ‘high severity’. The post Google Patches 382 Chrome Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
1 JulWhat a financial planner taught me about cybersecurityWhen I spoke at a recent cybersecurity awareness event for financial planners and tax advisors, the audience really engaged with the subject. As happens at conferences the world over, people often come up to speakers to ask follow-up questions, or just give their feedback about p…HELPNETSECURITY.COM
1 JulMassive Password Spray Campaign Targeting Azure CLIHackers were seen making over 81 million login attempts originating from systems associated with hosting provider LSHIY. The post Massive Password Spray Campaign Targeting Azure CLI appeared first on SecurityWeek .SECURITYWEEK.COM
1 JulDawnguard Raises $6.3 Million for Security Architecture Automation PlatformThe company has publicly launched its solution to help organizations design, build, and operate secure cloud systems. The post Dawnguard Raises $6.3 Million for Security Architecture Automation Platform appeared first on SecurityWeek .SECURITYWEEK.COM
1 JulThis phishing kit looks more like BEC-as-a-serviceCisco Talos’ research on ARToken builds on what’s known about the related EvilTokens phishing-as-a-service. The post This phishing kit looks more like BEC-as-a-service appeared first on CyberScoop .CYBERSCOOP.COM
1 JulFrontier AI: Six Questions Every Enterprise Should Ask Security VendorsFrom model selection and automation to validation and measurable results, the right questions can help enterprises separate genuine AI capabilities from marketing hype. The post Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors appeared first on SecurityWeek…SECURITYWEEK.COM
1 JulApple Patches Dozens of Vulnerabilities Across iOS, macOS, and SafariThe updates fix vulnerabilities in WebKit, the kernel, WebRTC, Web Extensions, and other components affecting iPhone, iPad, Mac, and Safari users. The post Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari appeared first on SecurityWeek .SECURITYWEEK.COM
1 JulPapa Johns Surveillance-Based AdvertisingPapa Johns is spying on people’s buying activities to predict when they are low on food: The pizza chain recently tapped NBCUniversal, Instacart and the dentsu-owned media agency Carat for help reaching consumers when they’re low on groceries—and thus more likel…SCHNEIER.COM
1 JulThe ARToken phishing panel targets Microsoft 365 accountsAccounts-payable staff at U.S. companies keep receiving invoice emails that look like they come from vendors they already work with. One landed at a life-sciences company in April 2026, addressed to the person who handles payments and written in the voice of a Wisconsin contracto…HELPNETSECURITY.COM
1 JulAdobe Patches Critical ColdFusion, Campaign Classic VulnerabilitiesSeven of the security defects have a maximum severity rating of 10/10 and could lead to arbitrary code execution. The post Adobe Patches Critical ColdFusion, Campaign Classic Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
1 JulCitrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ AttackCitrix urges customers to patch NetScaler after fixing six vulnerabilities, including the HTTP/2 Bomb flaw and a high-severity CitrixBleed-style information disclosure bug. The post Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attack appeared first on Sec…SECURITYWEEK.COM
1 JulDawnguard launches platform to automate secure cloud architectureDawnguard announced the public launch of its security architecture automation platform, making it available to organizations looking to design, build, and operate secure cloud-native systems from day zero through production. The launch marks the company’s move from enterprise des…HELPNETSECURITY.COM
1 JulSafe Events Start With Threat Intel and Digital SecurityPlanning ahead to defend against cyber threats is the work that keeps events uneventful.DARKREADING.COM
1 JulEmpowering Too Soon BackfiresEmpowerment isn't binary. It's a dial that leaders should adjust based on operational clarity, individual capability, and team maturity. Granting full autonomy before a team is ready can increase mistakes, confusion, and inconsistency. On the other hand, withholding autonomy from…YOUTUBE.COM
1 JulTurning Indicators into Intelligence in OpenCTI with Criminal IPThreat intelligence is only as useful as the context behind it. Criminal IP explains how its integration enriches threat indicators in OpenCTI with risk scoring, infrastructure intelligence, and phishing analysis. [...]BLEEPINGCOMPUTER.COM
1 Jul6 security settings every GitHub maintainer should enable this weekThese six free settings will not make your project unhackable. Nothing will. What they will do is close the easy doors. Turn these on, and your project will be meaningfully harder to attack than it was before. The post 6 security settings every GitHub maintainer should enable thi…GITHUB.BLOG
1 JulAnthropic reactivates Fable, Mythos after securing government approvalThe company’s powerful frontier models are back, but vetting issues remain unresolved.CYBERSECURITYDIVE.COM
1 JulTor releases Arti 2.5.0 with stable CGO encryption and security fixesThe Tor Project has released Arti 2.5.0, promoting its next-generation Counter Galois Onion (CGO) encryption scheme to stable status while also patching two denial-of-service (DoS) vulnerabilities affecting the Rust-based Tor implementation. The release marks a significant milest…CYBERINSIDER.COM
1 JulMicrosoft named a leader in the Frost Radar for cloud and application runtime securityFrost & Sullivan names Microsoft a leader as cloud and application security converge into unified, runtime risk reduction. The post Microsoft named a leader in the Frost Radar for cloud and application runtime security appeared first on Microsoft Security Blog .MICROSOFT.COM
1 JulWaiting for Quantum Is a MistakeQuantum computing is still in its early stages, but major technology platforms are already investing in the technology. While commercial-scale systems aren't available yet, development continues to accelerate. Organizations that wait for quantum computing to become commonplace ma…YOUTUBE.COM
1 JulSEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRATUnknown threat actors are leveraging the ScreenConnect remote access tool as a way to deploy and execute AsyncRAT. Kaspersky said the activity is part of a "massive, multi-domain, multi-language" campaign that distributes malicious installer archives hosted on spoofed websites. T…THEHACKERNEWS.COM
1 JulMicrosoft Adds New Teams Controls to Block Unauthorized AI Bots From MeetingsMicrosoft's new Teams admin policy requires organizer approval for external AI bots, giving organizations greater visibility and control over automated participants in sensitive meetings. The post Microsoft Adds New Teams Controls to Block Unauthorized AI Bots From Meetings appea…SECURITYWEEK.COM
1 JulMicrosoft accelerates quantum cryptography rollout, targets 2029 transitionMicrosoft has announced that it is accelerating its transition to post-quantum cryptography (PQC) amid growing concerns that cryptographically relevant quantum computers could arrive sooner than previously anticipated. The company now aims to transition critical products and serv…CYBERINSIDER.COM
1 JulCrafty Phishing Campaigns Auto-Adapt to Victim's Device, OSAttackers fingerprint victims through user-agent data to deliver OS-specific payloads, increasing compromise rates and campaign profitability.DARKREADING.COM
1 JulFake Values Kill Company TrustCore values only build trust when they're reflected in everyday decisions. A company that claims to be "people first" but consistently acts otherwise creates a gap between its messaging and reality. That disconnect weakens credibility with employees, leaders, and candidates. Orga…YOUTUBE.COM
30 JunISC Stormcast For Tuesday, June 30th, 2026 https://isc.sans.edu/podcastdetail/9988, (Tue, Jun 30th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
30 JunWSL containers now build and run Linux workloads on WindowsContainers power a large share of cloud-native applications, AI workloads, and testing and deployment pipelines. Developers working on Windows have long pulled in third-party software to build and run them. That step becomes optional with WSL containers, a feature that arrived at…HELPNETSECURITY.COM
30 JunQuantifind Raises $200 Million for AI-Native Risk IntelligenceQuantifind will accelerate international expansion and extend its platform’s localized risk intelligence capabilities. The post Quantifind Raises $200 Million for AI-Native Risk Intelligence appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunAirDrop and Quick Share vulnerabilities affect protocols on five billion devices as fixes beginPhones and laptops ship with a feature that sends files to nearby devices over the air, with no cables, accounts, or prior pairing. Apple calls its version AirDrop. Google and Samsung call theirs Quick Share. Both run inside privileged background services that wake when another d…HELPNETSECURITY.COM
30 JunKali Linux 2026.2 trims VM boot times, refreshes its desktopsPenetration testers who run Kali Linux inside virtual machines boot their systems faster after the 2026.2 release. The change comes from a decision about graphics firmware, the code that drives NVIDIA, AMD, and Intel GPUs. That firmware has grown large enough to slow the early st…HELPNETSECURITY.COM
30 JunToddyCat: your hidden email assistant. Part 2An in-depth analysis of Umbrij, a new tool used by the ToddyCat APT group to compromise corporate email communications in Gmail. The attack targeted OAuth authorization tokens, allowing threat actors to gain access to Google services.SECURELIST.COM
30 JunThe AI Token Costs That Can Break CybersecurityAs cybersecurity platforms embrace agentic AI, organizations must balance detection performance against the escalating costs of token consumption, deployment architecture, and AI credits. The post The AI Token Costs That Can Break Cybersecurity appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunAirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass ChecksTwo researchers have found six security flaws in AirDrop and Quick Share, the wireless features that beam files between nearby devices with no cables or shared network. An attacker within wireless range, with just a laptop and no prior connection, can crash the sharing service on…THEHACKERNEWS.COM
30 JunSupreme Court Rules Constitutional Privacy Protections Apply to Cellphone Users’ Location HistoryThe ruling was made in the case of a bank robber whose identity was discovered through a geofence warrant. The post Supreme Court Rules Constitutional Privacy Protections Apply to Cellphone Users’ Location History appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunThe Realities of AI Video SurveillanceThe Financial Times has a good article on how AI is changing the capabilities of video surveillance, with information from both Israel/Iran and Russia. I wrote about this sort of thing a few years ago, how AI enables mass spying in the way that computers and networks enabled mass…SCHNEIER.COM
30 JunMozilla tightens rules for certificate authorities to improve web securityMozilla has released version 3.1 of its Mozilla Root Store Policy (MRSP), introducing new requirements aimed at improving transparency and oversight across the public Web PKI. The updated policy, which takes effect on July 1, 2026, focuses on stronger Certification Authority (CA)…CYBERINSIDER.COM
30 JunWhat the Numbers Say About FIFA 2026 Cyber RiskThe FIFA World Cup 2026 opened on June 11. By that date, according to Check Point Research, the fraud infrastructure targeting it had already been built, staged, and partially deployed. Threat actor activity was pre-planned, months out, across three sectors and at least ten langu…THEHACKERNEWS.COM
30 JunDigi International’s DANI automates network diagnostics and device managementDigi International has announced the launch of DANI, the Digi Artificial Network Intelligence agent, a purpose-built AI network operations agent natively embedded in a networking device management platform, Digi Remote Manager (DRM). Embedded directly within DRM as a value-added …HELPNETSECURITY.COM
30 JunOpenMatter Network brings verifiable trust to AI governanceOpenMatter Network has announced the launch of its cryptographically verifiable platform for secure collaboration and AI governance, built on a simple premise: Don’t Trust Data. Prove It. For decades, organizations have relied on trust-based assumptions to secure data, exec…HELPNETSECURITY.COM
30 JunChrome and Firefox Free VPN extensions caught stealing clipboard dataTwo browser extensions masquerading as free VPN services were transformed into clipboard stealers through malicious updates. The Chrome and Firefox add-ons retained working proxy functionality to appear legitimate while secretly monitoring copied data and transmitting it to attac…CYBERINSIDER.COM
30 JunProton launches Lumo 2.0 with advanced reasoning and image generationProton has announced Lumo 2.0, a major upgrade that significantly expands the assistant's capabilities while maintaining the privacy protections that distinguish it from mainstream AI platforms. The new release introduces stronger reasoning models, image recognition and generatio…CYBERINSIDER.COM
30 JunWhat’s new in Microsoft Security: June 2026This month’s updates help security and IT teams strengthen identity and multicloud foundations, protect data wherever it lives, and secure the developer workflows powering AI innovation. The post What’s new in Microsoft Security: June 2026 appeared first on Microsoft Security B…MICROSOFT.COM
30 JunSecuring AI agents: When AI tools move from reading to actingMCP tool poisoning turns trusted AI agents into a control plane for data loss. Learn how threat actors manipulate tool descriptions to trigger unauthorized actions, and how to detect, contain, and prevent it. The post Securing AI agents: When AI tools move from reading to acting …MICROSOFT.COM
30 JunNew Gartner® Report on Preemptive Exposure ManagementThe 2026 Gartner report titled Emerging Tech: Top Funded Startups for Preemptive Exposure Management, that names Eclypsium in the Domain Specific Exposure Management category, was published in April. While this is only a small part of what the Eclypsium Hardware Supply Chain Secu…ECLYPSIUM.COM
30 JunBTS #77 - FortiBleed Uncovered: How Attackers Harvest Credentials from Fortinet DevicesPaul Asadoorian is joined by Chase Snyder and Vlad Babkin to unpack FortiBleed, a large-scale Fortinet credential-harvesting campaign, and what it reveals about network edge security. Welcome to episode 77 of Below the Surface. Paul Asadoorian sits down with Chase Snyder and Vlad…ECLYPSIUM.COM
30 JunWhen AI Chooses Your VendorTyler Shields argues that companies are beginning to publish pricing specifically for AI agents, making it easier for software—not just people—to compare services automatically. As agents evaluate cost, security, and available integrations, support for MCP could become increasing…YOUTUBE.COM
30 JunAccelerating the quantum-safe timelineWe’re accelerating quantum-safe readiness—and sharing what organizations can do now to transition earlier and with confidence. The post Accelerating the quantum-safe timeline appeared first on Microsoft Security Blog .MICROSOFT.COM
30 JunAI Cocaine Recipes, Russian Hack, Scattered Spider, Cisco, Amazon Q – Aaran Leyland - SWN #594AI Cocaine Recipes, Green Shirt Jailbreak, JLR Russia Hack, Scattered Spider, Cisco Root, Amazon Q Pwned – Aaran Leyland – SWN #594 Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-594YOUTUBE.COM
30 JunProton’s pitch for Lumo 2.0: Frontier AI without the data grabProton has unveiled Lumo 2.0, a major upgrade to its zero-access encrypted AI assistant. Built on a new architecture, the release brings the assistant closer to frontier AI models with new AI models, multimodal capabilities, Memory, improved web search, and enterprise features. T…HELPNETSECURITY.COM
29 JunISC Stormcast For Monday, June 29th, 2026 https://isc.sans.edu/podcastdetail/9986, (Mon, Jun 29th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
29 JunRisky Bulletin: White House asks OpenAI to restrict GPT 5.6The White House asks OpenAI to keep a tight grip on ChatGPT 5.6, the US Secret Service made some appalling OpSec mistakes, AMD has reintroduced a CPU security feature after consumer backlash, and an Iranian APT operator has been arrested in Montenegro.RISKY.BIZ
29 JunMost teams accept higher risk for faster AI database workDatabase professionals are using AI for everyday work like writing queries, building schemas, and reviewing code, and a growing share rely on autonomous tools that act on the database itself. The use of AI in database management has almost tripled in a year, climbing from 15% to …HELPNETSECURITY.COM
29 JunCompanies keep bolting AI onto their products, and the security bill is coming dueCompanies keep bolting AI and LLM features onto their products, and the security results are starting to show a pattern. The vulnerabilities those features create get rated high risk far more often than anything else, and they get fixed slower than anything else. The figures come…HELPNETSECURITY.COM
29 JunOpenAI Unveils GPT-5.6 Sol as Its Most Advanced Cybersecurity AIThe company says Sol matches competing systems like Mythos Preview while using only a third of the output tokens. The post OpenAI Unveils GPT-5.6 Sol as Its Most Advanced Cybersecurity AI appeared first on SecurityWeek .SECURITYWEEK.COM
29 JunMicrosoft Removes 119 Edge Extensions That Hid Malware in Images and FontsMicrosoft has shut down a long-running malicious extension operation on the Edge Add-ons store that hid its payloads inside ordinary image and font files, then woke up days after install to steal credentials and run ad fraud. The company calls it StegoAd, a mash-up of stegan…THEHACKERNEWS.COM
29 JunUS Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks EvolveUNC5792 and UNC4221 have been targeting US government officials, military leaders, and allied personnel. The post US Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks Evolve appeared first on SecurityWeek .SECURITYWEEK.COM
29 JunGPT-5.6 gets better at cybersecurityOpenAI has started rolling out the GPT-5.6 series models in limited preview to a small group of trusted partners through the API and Codex. The series includes Sol as the flagship model, Terra as a balanced option, and Luna as the fastest and most cost-efficient model. The rollou…HELPNETSECURITY.COM
29 JunSSU and FBI Uncover Russian Cyber Espionage Operation Against Officials and Military PersonnelUkraine’s SSU and the FBI Just Confirmed Russian Intelligence Has Been Systematically Hacking Messenger Accounts for Years. The Security Service of Ukraine (SSU), working jointly with the FBI, has formally exposed a sustained Russian intelligence campaign targeting the mess…SECURITYAFFAIRS.COM
29 JunWhy Post-Quantum Cryptography Starts With CredentialsToday’s encrypted data, such as credentials, may no longer remain confidential in the future because the public-key cryptography protecting it will soon be broken by quantum computers. Although no machine today can break elliptic curve cryptography or RSA, quantum hardware is adv…THEHACKERNEWS.COM
29 JunGamaredon Expands Ukraine Attacks with New Malware and Cloud Service AbuseA Russian advanced persistent threat (APT) group has continued to evolve and expand its malware arsenal as part of its ongoing cyber onslaught against Ukraine throughout 2025. Slovakian cybersecurity company ESET said it observed 35 distinct spear-phishing campaigns mounted by Ga…THEHACKERNEWS.COM
29 JunInsurance Regulators Group NAIC Hit in Oracle PeopleSoft HackThe ShinyHunters extortion group claims to have stolen 3.1 TB of data from the organization. The post Insurance Regulators Group NAIC Hit in Oracle PeopleSoft Hack appeared first on SecurityWeek .SECURITYWEEK.COM
29 JunOpenAI voluntarily limits new AI models at government’s requestThe company said it was working with the government on a more formal process for reviewing model releases.CYBERSECURITYDIVE.COM
29 JunResearchers Demo New Claude Code Attack Using Harmless-Looking Repositories to Hijack Developer MachinesIndirect prompts hidden in a repository can lead to Claude Code spawning a reverse shell on the developer’s machine. The post Researchers Demo New Claude Code Attack Using Harmless-Looking Repositories to Hijack Developer Machines appeared first on SecurityWeek .SECURITYWEEK.COM
29 JunStraiker Raises $64 Million for AI Security PlatformThe startup’s platform can identify AI agents and provide visibility into their access, behavior, and risks. The post Straiker Raises $64 Million for AI Security Platform appeared first on SecurityWeek .SECURITYWEEK.COM
29 JunWhatsApp Rolling Out Username Feature to Bolster Phone Number PrivacyAn optional ‘username key’ adds another layer by requiring a secondary credential before someone can message users. The post WhatsApp Rolling Out Username Feature to Bolster Phone Number Privacy appeared first on SecurityWeek .SECURITYWEEK.COM
29 JunSupreme Court approves mail-in ballots that arrive after Election DayThe ruling is a victory for election advocates who say the evidence overwhelmingly shows that voter fraud is rare and not tied to mail voting in general. The post Supreme Court approves mail-in ballots that arrive after Election Day appeared first on CyberScoop .CYBERSCOOP.COM
29 JunSupreme Court delivers ‘major win’ for tech privacy in Chatrie rulingDissenting justices who criticized the ruling said it would have “seismic” implications for the Fourth Amendment. The post Supreme Court delivers ‘major win’ for tech privacy in Chatrie ruling appeared first on CyberScoop .CYBERSCOOP.COM
29 JunChrome extension Adblock for YouTube with 11 million users could be silently weaponizedThe operators of the popular “Adblock for YouTube” Chrome extension could remotely execute JavaScript on websites visited by users through a server-side configuration change. Island researchers who discovered this found no evidence that the architectural weakness has …CYBERINSIDER.COM
29 JunUS offers $10 million for info on Russian hackers targeting Signal accountsThe U.S. Department of State has announced a reward of up to $10 million for information leading to the identification or location of members of UNC5792. This is a Russian state-linked hacking group accused of targeting Signal and WhatsApp accounts belonging to U.S. government of…CYBERINSIDER.COM
29 JunChromium extension uses AI‑related branding to redirect browser searchA malicious Chromium-based extension that spoofs the AI-powered answer engine Perplexity AI redirects browser search traffic using MV3 APIs and intermediary infrastructure. The post Chromium extension uses AI‑related branding to redirect browser search appeared first on Microsoft…MICROSOFT.COM
29 JunWarner bill would create federally vetted list for secure, trustworthy AI agentsThe bill empowers the FTC to create a registry for sellers of AI agent software certifying their privacy and cybersecurity protections. The post Warner bill would create federally vetted list for secure, trustworthy AI agents appeared first on CyberScoop .CYBERSCOOP.COM
29 JunWhatsApp opens username reservations ahead of feature rolloutMeta has announced that WhatsApp users can now reserve usernames ahead of a broader launch planned for later this year, introducing a long-awaited privacy feature that allows people to connect without sharing their phone numbers. The company says the feature is designed to give u…CYBERINSIDER.COM
29 JunU.S. Targets Russian Cyber Spies With $10M Bounty Over Messaging App AttacksThe U.S. offers up to $10M for information on Russian hackers targeting Signal and WhatsApp accounts of officials and journalists. The U.S. government is offering rewards of up to $10 million for information leading to the identification of members of the Russian-linked groups UN…SECURITYAFFAIRS.COM
28 JunYARA-X 1.18.0 and 1.19.0 Release, (Sun, Jun 28th)YARA-X&#;x26;#;39;s 1.18.0 release brings 3 improvements and 2 bugfixes.
ISC.SANS.EDU
27 JunThe Dacls RAT ...now on macOS!A sophisticated Lazarus Group implant has arrived on macOS. In this post, we deconstruct the Mac variant of a OSX.Dacls, detailing its install logic, persistence, and capabilities.OBJECTIVE-SEE.ORG
27 JunWeaponizing a Lazarus Group ImplantThe Lazarus group's latest implant/loader supports in-memory loading of 2nd-stage payloads. In this post we describe exactly how to repurposing this 1st-stage loader to execute *our* custom 'fileless' payloads!OBJECTIVE-SEE.ORG
27 JunLazarus Group Goes 'Fileless'The rather infamous APT group, "Lazarus", continues to evolve their macOS capabilities. Today, we tear apart their latest 1st-stage implant that supports remote download & in-memory execution of secondary payloads!OBJECTIVE-SEE.ORG
27 JunPass the AppleJeusA new macOS backdoor written by the infamous Lazarus APT group needs analyzing. Here, we examine it's infection vector, method of persistence, capabilities, and more!OBJECTIVE-SEE.ORG
27 JunMiddle East Cyber-Espionage (part two)The APT group WindShift has been targeting Middle Eastern governments with Mac implants. Let's (continue to) analyze their 1st-stage macOS implant: OSX.WindTail!OBJECTIVE-SEE.ORG
27 JunMiddle East Cyber-EspionageThe APT group WindShift has been targeting Middle Eastern governments with Mac implants. Let's analyze their 1st-stage macOS implant: OSX.WindTail!OBJECTIVE-SEE.ORG
27 JunWho Moved My Pixels?!In this guest blog post my friend Mikhail Sosonkin reverses Apple's screencapture utility, discusses Mac malware that captures desktop images, and suggests methods for screen-capture detection!OBJECTIVE-SEE.ORG
27 JunChinese Framework Powers 200,000 Scam SitesThreat actors are selling investment scam templates created using the legitimate DCloud Uni-App toolkit. The post Chinese Framework Powers 200,000 Scam Sites appeared first on SecurityWeek .SECURITYWEEK.COM
26 JunGoogle Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage AttacksThe Russian state-sponsored threat actor known as Turla has been attributed to a previously undocumented .NET backdoor called STOCKSTAY that has been deployed against government and military organizations in Ukraine, and entities that have an interest in Italian foreign policy. D…THEHACKERNEWS.COM
26 JunRussian APT Deploys ‘StockStay’ Backdoor Against Ukrainian TargetsTurla has been using the backdoor against government and military organizations in Ukraine for espionage. The post Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets appeared first on SecurityWeek .SECURITYWEEK.COM
26 JunNew Enterprise-Ready MCP Specification Brings New Security ChallengesA major overhaul of the Model Context Protocol shifts critical security responsibilities from the protocol itself to developers and platform operators. The post New Enterprise-Ready MCP Specification Brings New Security Challenges appeared first on SecurityWeek .SECURITYWEEK.COM
26 JunPhilip Martin Joins Uber as Chief Information Security OfficerMartin brings experience from Coinbase, Palantir, Amazon, and the U.S. Army to lead Uber's cybersecurity and enterprise security organization. The post Philip Martin Joins Uber as Chief Information Security Officer appeared first on SecurityWeek .SECURITYWEEK.COM
26 JunThreatModeler introduces Nexus to automate threat modeling with AI governanceThreatModeler has announced the general availability of ThreatModeler Nexus, an agentic threat modeling platform that brings governed, architecture-aware security to the way modern software is actually built. As AI writes a growing share of production code, the question is no lon…HELPNETSECURITY.COM
26 JunA privacy-first take on local malware analysisSubmitting a suspicious file to VirusTotal or MalwareBazaar places a copy of that file on a platform other people can search. Analysts across the industry rely on these services to get a quick verdict on whether a binary is dangerous. The convenience carries a condition many over…HELPNETSECURITY.COM
26 JunTwo CEOs on why security and AI readiness belong togetherSuperOps and Guardz are bundling PSA, RMM, MDM, and agentic SecOps into one offering for MSPs. In this Help Net Security Q&A, SuperOps CEO Arvind Parthiban and Guardz CEO Dor Eisner explain how a connected stack cuts the time and context lost to tool-switching, lowers costs …HELPNETSECURITY.COM
26 JunMicrosoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js ImplantAn active phishing campaign has been targeting hotel and other hospitality organizations across Europe and Asia since April 2026, using photo-themed ZIP files to drop a Node.js implant and dig into front-desk machines, Microsoft says. The company has not attributed the …THEHACKERNEWS.COM
26 Jun$3 Million Reportedly Stolen in Polymarket HackThe decentralized prediction market said hackers targeted some of its users through a compromise of a third-party vendor. The post $3 Million Reportedly Stolen in Polymarket Hack appeared first on SecurityWeek .SECURITYWEEK.COM
26 JunMirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentialsMirage2FA, a phishing kit that combines short-lived HTML smuggling with obfuscated JavaScript loaders to deliver fake Microsoft 365 login pages and steal credentials during MFA prompts, has been identified by researchers at Fortra. Fortra based its analysis on a suspicious HTML a…HELPNETSECURITY.COM
26 JunAWS unveils agent security, data access toolsThe updates reflect Anthropic's Mythos model and the speed at which vulnerabilities can be surfaced.CYBERSECURITYDIVE.COM
26 JunNebulock Raises $25 Million for AI-Native Contextual SecurityThe cybersecurity startup provides threat hunting, proactive detection, and behavioral security analytics. The post Nebulock Raises $25 Million for AI-Native Contextual Security appeared first on SecurityWeek .SECURITYWEEK.COM
26 JunProof’s x401 establishes an open protocol for AI agent identity and authorizationProof has launched x401, an open, issuer-neutral protocol that lets any website or API ask for and verify the identity behind agents. With x401, a service can ask for the proof it requires: verified identity, age, membership, organizational affiliation, signing authority, proof o…HELPNETSECURITY.COM
26 JunTurla group adds more malware to Russia’s espionage efforts against UkraineThreat intelligence researchers at Google described StockStay, the latest malware developed by the Russian cyber-espionage group known as Turla.THERECORD.MEDIA
26 JunFCC requires emergency-alert distributors to secure their systemsMore than a decade after a high-profile hacking campaign, the commission is moving from recommending basic security protocols to requiring them.CYBERSECURITYDIVE.COM
26 JunNew Millenium RAT version infects 62,000 Windows systems worldwideA major evolution of the Millenium remote access trojan (RAT) has infected more than 62,000 Windows devices across over 160 countries while continuing to use Telegram bots for command-and-control. Group-IB examined Millenium RAT version 4.*, which it says represents a significant…CYBERINSIDER.COM
26 JunMeta Is Testing Facial Recognition for Police and MilitaryWe know that ICE wants to deploy eyeglasses with facial recognition that can identify people in real time. Turns out Meta is prototyping the feature with a Pentagon supplier. (Alternate news story.)SCHNEIER.COM
26 JunRussian hackers were behind $2.5 billion hack of Jaguar Land Rover: ReportThe hack on car giant Jaguar Land Rover last year was one the most disrupting, damaging, and costly hacks of the last few years.TECHCRUNCH.COM
26 JunCybersecurity firms targeted by fraudulent OpenAI organization invitesThreat actors are creating OpenAI tenants that impersonate legitimate companies and inviting employees to join them, in what appears to be a ploy to trick targets into submitting sensitive company information in chats and projects. [...]BLEEPINGCOMPUTER.COM
26 JunATF cancels controversial commercial geolocation contractThe agency told CyberScoop the tool was a pilot that didn’t meet their needs. Members of Congress say it was accessed for hundreds of active cases. The post ATF cancels controversial commercial geolocation contract appeared first on CyberScoop .CYBERSCOOP.COM
26 JunAI Brain Harvest, Fortibleed, Win 10, Blacksite, Windchill, Cisco, BB-8, Josh Marpet - SWN #593AI Brain Harvest, Fortibleed, Win 10, Blacksite, Windchill, Cisco, BB-8 Sidewalk Bots, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-593YOUTUBE.COM
26 JunMFA Won't Stop This Phishing KitThe Black Site phishing kit pairs with an evasion tool called Cloaked.gg to perform adversary-in-the-middle attacks. By acting as a reverse proxy between the victim and the legitimate website, it can capture credentials and authenticated session data during the login process. Thi…YOUTUBE.COM
25 JunAI and LiabilityEarlier this month, a German court ruled that Google is liable for its AI search summaries. Rejecting defenses like “users can check for themselves,” and that they generally know “that information generated with AI should not be blindly trusted,” the court…SCHNEIER.COM
25 JunWhat do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th)[This is a Guest Diary by Nicole Phillips, an ISC intern as part of the SANS.edu BACS program]
ISC.SANS.EDU
25 JunIntroduction to COM usage by Windows threatsComponent Object Model (COM) is a fundamental Windows technology used by legitimate applications for object activation, inter-process communication, automation and language-independent component reuse. Those same qualities make it useful to threat actors.TALOSINTELLIGENCE.COM
25 JunWhere Expertise Meets Algorithm: The Insikt Group® Intelligence EdgeDiscover how Recorded Future’s Insikt Group combines human expertise with automated analysis to turn raw data into actionable, industry-leading threat intelligence.RECORDEDFUTURE.COM
25 JunRussia uses Cellebrite to break into human rights activist’s phone, even after cancellation of contractThe phone-cracking firm broke off from its deal with Russia, but Citizen Lab said that didn’t stop authorities from surveilling Andrey Pivovarov. The post Russia uses Cellebrite to break into human rights activist’s phone, even after cancellation of contract appeared first on Cyb…CYBERSCOOP.COM
25 JunAs cyber risk evolves, the insurance industry tightens guardrailsC-suite executives are concerned about resilience, but claims are increasingly tied to strict underwriting standards.CYBERSECURITYDIVE.COM
25 JunCL-STA-1062 Targets Southeast Asian Governments and Critical InfrastructureGovernment entities and critical infrastructure were targeted for espionage in SE Asia by attackers using a hybrid toolkit, including custom TinyRCT backdoor. The post CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
25 JunWhatsApp is now warning users attempting to message unknown numbersWhatsApp has introduced a new security feature designed to make users think twice before starting conversations with unfamiliar phone numbers. The new “trust warning,” first spotted by WABetaInfo, appears before a chat is opened and provides contextual information tha…CYBERINSIDER.COM
25 JunGrapheneOS cites Hyundai, KIA as it pressures Volkswagen over app blockGrapheneOS is calling on Volkswagen customers to pressure the automaker into restoring compatibility with its mobile app after users reported last week that the app no longer works on the privacy-focused Android operating system. The project pointed to Hyundai and Kia, which it s…CYBERINSIDER.COM
25 JunOrder-tracking app Shop abused to push callback phishing attacksThreat actors are increasingly abusing Shop, the order-tracking app from Shopify, by adding fake purchase receipts in users' order histories to trick them into providing sensitive data or installing remote access software. [...]BLEEPINGCOMPUTER.COM
25 JunRunlayer Raises $30 Million in Series A FundingThe startup’s platform functions as a secure control layer, aiming to secure AI tools across enterprises. The post Runlayer Raises $30 Million in Series A Funding appeared first on SecurityWeek .SECURITYWEEK.COM
25 JunGitLab Patches Code Execution, Information Disclosure VulnerabilitiesThe latest GitLab CE/EE updates address 13 vulnerabilities, including three high-severity defects. The post GitLab Patches Code Execution, Information Disclosure Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
25 JunSecurityWeek ICS Cybersecurity Conference Heads to Nashville for Special 25-Year Anniversary EditionThe 2026 Industrial Control Systems (ICS) Cybersecurity Conference takes place October 6-8, 2026, at the W Nashville. The post SecurityWeek ICS Cybersecurity Conference Heads to Nashville for Special 25-Year Anniversary Edition appeared first on SecurityWeek .SECURITYWEEK.COM
25 JunRussian APT 'Gamaredon' Upgrades Its Arsenal, Requiring New DefensesThe FSB state-sponsored operation has gotten a lot better at loading its malware and hiding its servers.DARKREADING.COM
25 JunPhoto ZIP campaign targeting hospitality industry delivers Node.js implant for persistent accessMicrosoft Threat Intelligence identified an active multi-stage intrusion campaign targeting hospitality organizations in Europe and Asia. The campaign uses photo-themed ZIP archives and fake image shortcut files to deliver a persistent Node.js implant and evade detection. The pos…MICROSOFT.COM
25 JunMicrosoft a Leader in The Forrester Wave™ for Endpoint Management PlatformsMicrosoft named a Leader in the Forrester Wave™: Endpoint Management Platforms, Q2 2026, with the highest scores in the current offering and strategy categories. The post Microsoft a Leader in The Forrester Wave™ for Endpoint Management Platforms appeared first on Microsoft Secur…MICROSOFT.COM
🌐 CYBER THREAT LANDSCAPE 321[+]
23 SepFake LastPass on GitHub Led to an Infostealer That Killed 145 Security ToolsAttackers spoofed LastPass on GitHub, used a Microsoft-signed driver to disable 145 security products, then deployed an infostealer. Someone impersonated LastPass on GitHub, got users to download a fake authenticator, and ended up killing 145 different antivirus and EDR products …SECURITYAFFAIRS.COM
23 SepWindows Botnet x47.c Offers AI API Draining, 18 Attack MethodsQrator found a Windows botnet advertised with AI API draining, credential theft and SOCKS5 proxyingINFOSECURITY-MAGAZINE.COM
23 SepThis Windows Malware is Built to Let Up to Four AI Models Vote on Its Next MoveA Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talo…THEHACKERNEWS.COM
23 SepGitLab Email Addresses Can Be Weaponized for Supply Chain AttacksIncoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that attackers can use.DARKREADING.COM
23 SepNew RemControl Android banking malware targets users in Europe and CanadaA new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application. [...]BLEEPINGCOMPUTER.COM
22 SepA New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in SightCisco Talos researchers created a new framework for identifying malware and hacking tools that rely on AI chatbots—and quickly discovered something unusual.WIRED.COM
22 SepThe Closed Quorum: Inside the first reported autonomous AI C2 implantCLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). It represents a shift in effort displacement for attackers, in which expanding portions of the attack chain can be executed without operator involveme…TALOSINTELLIGENCE.COM
22 SepIntroducing CAIRN: Frontier tracking for AI-integrated malwareTalos is releasing CAIRN, a research toolkit for hunting, classifying, and tracking emerging AI-integrated malware.TALOSINTELLIGENCE.COM
22 SepStolen passwords are exposing America’s water providers to hackersResearchers say another looming threat hangs over some of America's most important critical infrastructure.TECHCRUNCH.COM
22 SepNew ClosedQuorum Windows malware uses AI for attack decisionsA new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack. [...]BLEEPINGCOMPUTER.COM
21 SepA week in security (September 14 – September 20)A list of topics we covered in the week of September 14 to September 20 of 2026MALWAREBYTES.COM
21 SepChainScript: the RAT that hides its command server inside a blockchain contractBlackpoint uncovers ChainScript, a Node.js RAT that queries a Polygon smart contract to find and rotate its command server. Blackpoint’s Adversary Pursuit Group was chasing a ClickFix campaign spreading an unknown RAT namend ChainScript. The malicious code is a previously u…SECURITYAFFAIRS.COM
21 SepCybercriminals Are Hiding New Malware in Torrents for Popular FilmsVictims have been identified in Africa, including in Kenya and Uganda.DARKREADING.COM
18 SepRatHat Turns Android Accessibility Into an Attack WeaponRatHat combines AI-driven screen control, Android debugging abuse and advanced credential theft to give attackers deep control of infected phones. RatHat is the new Android trojan you should know about. Zimperium researchers just published a breakdown of a strain they’ve tr…SECURITYAFFAIRS.COM
18 SepNew Android malware uses AI to steal bank logins and PINsRatHat can navigate infected phones while stealing bank logins, authentication codes, and screen-lock PINs.MALWAREBYTES.COM
18 SepFake LastPass Authenticator GitHub repos push new Rapuncel infostealerAn ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel. [...]BLEEPINGCOMPUTER.COM
18 SepEY Survey Finds Autonomous AI Implementation Outpaces OversightA new survey of senior AI execs shows that while organizations are rapidly deploying AI and autonomous systems, their process and controls are not keeping pace.DARKREADING.COM
17 SepNew Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial DataResearchers at Zimperium have uncovered a new Android malware strain, dubbed RatHat, with spyware and backdoor capabilitiesINFOSECURITY-MAGAZINE.COM
17 SepLausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especially remarkable – it asked the recipient to review some attached requirements and provide a price quotation for a…ISC.SANS.EDU
17 SepFamousSparrow Swaps SparrowDoor For New SparroWocky BackdoorESET said FamousSparrow has replaced SparrowDoor with SparroWockyINFOSECURITY-MAGAZINE.COM
17 SepSilkParasite Infrastructure Links SpiceRAT to Central Asian TargetsHunt.io links SpiceRAT, NodeEdgeRAT and NomadRAT to a four-year SilkParasite campaign targeting governments and critical sectors in Central Asia. Hunt.io and researcher Guy Yasur have traced a tight cluster of SpiceRAT command‑and‑control servers that predate and extend Bitdefend…SECURITYAFFAIRS.COM
17 SepBrevo supply-chain attack injected ClickFix scripts on customer sitesBrevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. [...]BLEEPINGCOMPUTER.COM
16 SepMajor Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face ChangesA group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs’ PIVOT programINFOSECURITY-MAGAZINE.COM
16 SepBambooToken: The Malware That Speaks MQTT to Stay Under the RadarLumen exposes BambooToken, a stealthy malware family using MQTT and sideloading to quietly infect targets across Asia and beyond. BambooToken is a new malware family that uses MQTT, a lightweight messaging protocol commonly found in smart devices and industrial systems, to quietl…SECURITYAFFAIRS.COM
15 SepGoogle Doc Sidebar Sends Mac and Windows Users Down Different Paths to MalwareA single X DM split into two malware chains: AMOS stealer on Mac, NetSupport Manager on Windows, see the Huntress SOC analyst breakdown.HUNTRESS.COM
15 SepHBO Max’s verified Reddit account hijacked to spread malwareCybercriminals used HBO Max’s verified Reddit account to run 108 malicious ads that tricked people into installing information stealers.MALWAREBYTES.COM
15 SepBambooToken malware controls Windows and Linux systems via MQTTA previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems. [...]BLEEPINGCOMPUTER.COM
15 SepVectraRAT Can Hack Windows Enterprises for $250 per MonthThe full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access.DARKREADING.COM
14 SepA week in security (September 7 – September 13)A list of topics we covered in the week of September 7 to September 13 of 2026MALWAREBYTES.COM
14 SepSecurity teams are adopting AI faster than they trust itNew survey data reveals a widening gap between AI adoption and AI trust.CYBERSECURITYDIVE.COM
14 SepPro-Ukraine Hacking Cat group deploying new malware against Russian targetsThe pro-Ukraine hacktivist group Hacking Cat has evolved from carrying out website defacements and data leaks to more sophisticated and destructive attacks on Russian targets, researchers said.THERECORD.MEDIA
13 SepSecurity Affairs newsletter Round 594 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. The AI Supply Chain Has a Securit…SECURITYAFFAIRS.COM
11 SepAndroid malware creates a hidden copy of your banking appThe Gigabud banking Trojan can clone a banking app into a separate work profile on an Android device to help hide fraudulent transactions.MALWAREBYTES.COM
11 SepThe Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)I identified an attacker using a semi-autonomous coding agent to run an offensive operation: finding poorly secured LLM resale gateways, acquiring API access through ordinary web flaws and account farming, validating the resulting inference capacity, and aggregating it behind a s…ISC.SANS.EDU
11 SepThe AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open InternetResearchers found 36,769 exposed AI endpoints, but only 2% had an HTTP authentication gate. Running AI locally is supposed to give organizations more control. Models, prompts and documents stay on infrastructure they manage instead of being sent to a third-party cloud. But that a…SECURITYAFFAIRS.COM
10 SepWiz achieves GovRAMP High AuthorizationDelivering unified cloud security and accelerating secure modernization to protect citizen data and critical infrastructure.WIZ.IO
10 SepGigabud Creates Android Work Profiles to Hide From Banking App Malware ChecksThe Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9. A work profile is a separate space that Android typical…THEHACKERNEWS.COM
9 SepF5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk ScansMalware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the w…THEHACKERNEWS.COM
9 SepGigabud Uses Android App Cloning to Evade Fraud DetectionGigabud clones banking apps into a work profile to break the link between malware alerts and fraudINFOSECURITY-MAGAZINE.COM
8 SepBetween Two Nerds: Can AI defend critical infrastructure?In this edition of Between Two Nerds Tom Uren and The Grugq talk about whether AI will help cyber defence in critical infrastructure and organisations that are below the cyber poverty line. This episode is also available on YouTube.RISKY.BIZ
8 SepHackers gonna hack back.Welcome in! You’ve entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today’s most interesting threats. Your host is Selena Larson, Proofpoint intelligence analyst and host of thei…THECYBERWIRE.COM
7 SepA week in security (August 31 – September 6)Last week on Malwarebytes Labs: Stay safe!MALWAREBYTES.COM
7 SepJSCeal Hides Crypto Malware in V8 BytecodeJSCeal hides crypto-stealing malware in V8 bytecode, but researchers built a tool to decompile it and expose its advanced theft capabilities. JSCeal is a cryptocurrency stealer that Check Point Research has tracked since early 2025. Unlike most malware, it hides its code in a for…SECURITYAFFAIRS.COM
6 SepSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 113Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Hackers Steal Claude Login Sessions With Infostealer Malware to Hijack Accounts Fire Ant Evolves: From Hypervisors to Trusted I…SECURITYAFFAIRS.COM
4 SepAngry Birds: Toy Ghouls’ new toysKaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the other uses the Matrix-based Element messenger.SECURELIST.COM
4 SepThe hidden work of modernizing MalwarebytesWhy disciplined dependency modernization is one of the highest-leverage engineering investments a security product can make.MALWAREBYTES.COM
3 SepInternational Operation Disrupts Sality P2P BotnetUS-led action sinkholes machines caught up in Sality botnetINFOSECURITY-MAGAZINE.COM
3 SepShai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That MeansIn early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments, Continuous Integration/Continuous Deployment (CI/CD) tooling, cloud configurations, and even AI…THEHACKERNEWS.COM
3 SepNonprofit sues Trump admin for details on AI safety reviews.Rogue ScreenConnect installations spread malware with worm-like behavior. Maine teenager jailed for participation in the 764 extremist network.THECYBERWIRE.COM
3 SepStreamRat Android malware spreads through Meta and TikTok adsSocial media ads for a free streaming service exposed roughly 570,000 people to StreamRat, a banking Trojan that can take control of infected phones.MALWAREBYTES.COM
3 SepLarge group of Serbian opposition, activist figures targeted with spywareAt least 14 Serbians have been targeted with advanced spyware since December, with victims including a member of Parliament, a local opposition politician and student protesters, according to digital forensic researchers.THERECORD.MEDIA
3 SepPegasus and NoviSpy Used Against Serbian ProtestersSerbian activists were targeted with zero-click Pegasus and NoviSpy spyware, exposing a major surveillance campaign ahead of elections. A member of Serbia’s student protest movement had their iPhone infected with NSO Group‘s Pegasus spyware without ever clicking a lin…SECURITYAFFAIRS.COM
2 SepUS charges Russian for infecting 80,000 freelancers with malwareA California federal grand jury has indicted a Russian national for his role in a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware. [...]BLEEPINGCOMPUTER.COM
2 SepScammers are getting smarter about where they target youNew Malwarebytes research reveals how different scams are tailored to different platforms.MALWAREBYTES.COM
2 SepSality, one of the longest-running botnets, finally gets disruptedU.S. and European authorities disrupted the long-running botnet Sality, turning the malware’s peer-to-peer architecture against itself to cut thousands of infected computers off from operators.THERECORD.MEDIA
2 SepRussian Man Extradited Over Malware Campaign Targeting FreelancersRussian man extradited to US over malware campaign that targeted 80,000 freelance usersINFOSECURITY-MAGAZINE.COM
2 SepThreat Gang 'Springs' Vishing Attacks on Microsoft Teams UsersThe "Spring Ring" operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure.DARKREADING.COM
2 SepFake Software Installers Disable Windows Update and Weaken Microsoft DefenderAn active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. "The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industr…THEHACKERNEWS.COM
2 SepRussian national facing 20 years for malware campaign that infected 80,000 freelancersSearzhudin Tamirlanovich Aktulaev appeared in a San Francisco federal court on Monday after being arrested in Cyprus in May 2025 and extradited to the U.S. last week.THERECORD.MEDIA
1 SepGuildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)Introduction
ISC.SANS.EDU
1 SepMirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware setKaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.SECURELIST.COM
1 SepFive Venezuelans plead guilty to ATM jackpotting attacks in USFive Venezuelan nationals pleaded guilty to attempting to empty automated teller machines (ATMs) using malware in a series of ATM jackpotting attacks. [...]BLEEPINGCOMPUTER.COM
1 SepInfostealers are hijacking Claude accounts at users’ expenseAnthropic has warned that infostealers are stealing Claude session cookies to access users’ accounts and consume usage at their expense.MALWAREBYTES.COM
1 Sep65% of Enterprises Have Seen AI Agents Act Out of ScopeEMA survey finds 65% of enterprises have seen AI agents act beyond intended scopeINFOSECURITY-MAGAZINE.COM
31 Aug⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and MoreThe boring parts caused most of the trouble. A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task wa…THEHACKERNEWS.COM
31 AugA week in security (August 24 – August 30)A list of topics we covered in the week of August 24 to August 30 of 2026MALWAREBYTES.COM
31 AugATM Flaws Reveal Key Weaknesses in the Software Supply ChainA security researcher discovered nine vulnerabilities impacting ATM encryption and authentication software. But the problems extend far beyond your local cash machine.WIRED.COM
31 AugInfostealers Are Hijacking Claude Sessions and Draining SubscriptionsInfostealers can steal active Claude sessions, bypass 2FA and drain paid usage. Anthropic is revoking access and refunding unauthorized charges. Anthropic confirmed that several infostealer malware can hijack an active Claude login session and let attackers burn through your usag…SECURITYAFFAIRS.COM
31 AugValleyRAT: When Legitimate Software Becomes a Malware Delivery ToolValleyRAT hides behind legitimate adware, using DLL sideloading to evade detection, steal data and give Silver Fox control of infected systems. ValleyRAT doesn’t always need to disguise itself as a cracked game or a fake browser update. It can also hide behind something muc…SECURITYAFFAIRS.COM
30 AugAnthropic warns infostealer malware is hijacking Claude sessions to drain usageAnthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage. [...]BLEEPINGCOMPUTER.COM
30 AugChrome Web Store extensions caught stealing crypto, browser dataMultiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, as well as inject ClickFix lures. [...]BLEEPINGCOMPUTER.COM
30 AugSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 112Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor FTP Banners: The New Dead Drop …SECURITYAFFAIRS.COM
28 AugMore Americans oppose police license plate cameras than support them: surveyThe backlash against license plate readers comes amid a wave of police abuses of surveillance cameras.TECHCRUNCH.COM
28 AugNext-Gen Phishing Tactics Users Aren’t Ready For | HuntressMove past basic credential harvesting. Discover how modern attackers use ClickFix, BitB, and OAuth consent phishing—and how to train your users with Huntress SAT.HUNTRESS.COM
27 AugBoardroom Battles 2026: ASD’s Cyber Priorities & AI RiskThe Australian Signals Directorate’s 2026 board priorities and frontier AI guidance show why speed alone won’t stop AI-era cyber threats.HUNTRESS.COM
27 AugJavaScript obfuscation: From party trick to phishing kitLearn the basics of what obfuscation is, why a researcher would try to reverse it, and several ways to approach the problem.TALOSINTELLIGENCE.COM
27 AugWhat the Data Says About AI in Security Operations in 2026AI is officially mainstream in security operations. According to Prophet Security's State of AI in Security Operations 2026 report (produced from ViB’s survey of 250+ cybersecurity pros), 40% of security teams now use AI daily. Another 56% are currently testing it out, and only 4…THEHACKERNEWS.COM
27 AugAustralia arrests alleged TeamPCP hackers behind supply-chain attacksAustralian authorities have arrested and charged two young men accused of belonging to TeamPCP, a hacking group linked to a string of far-reaching developer supply chain attacks. [...]BLEEPINGCOMPUTER.COM
27 AugChinese Routers Sold Worldwide Contain BackdoorsAn untold numbers of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer.DARKREADING.COM
26 AugRisky Bulletin: Russia starts blocking DoH and DoTRussia begins blocking the DoH and DoT protocols, Russian hacktivists leak Spanish police and military personnel data, China and South Korea detain a vishing gang, and AI malware is not that common.RISKY.BIZ
26 AugNewly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own BytecodeAn independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER, that stays inert in memory until a specifically crafted network packet reaches the machine and then runs commands written in a 23-instruction language of its own design.…THEHACKERNEWS.COM
26 AugBeware of fake Indeed interview apps used to install spywareScammers are posing as employers on Indeed to trick job seekers into installing fake Android interview apps that deliver malware.MALWAREBYTES.COM
26 AugTortoiseshell Expands Malware Toolset With New Backdoor, SSH TunnelGroup-IB uncovered new Tortoiseshell infrastructure, including a backdoor and SSH tunneling toolINFOSECURITY-MAGAZINE.COM
26 AugThe Hidden Attack Surface Inside Data CentersStephen Hilt, Senior Threat Researcher at TrendAI, joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices recorded at Black Hat USA 2026. Drawing on research presented at DEF CON, he discusses thousands of internet-exposed industrial control systems ass…THECYBERWIRE.COMHTTPS:
25 AugBetween Two Nerds: Attribution is dead, long live attributionIn this edition of Between Two Nerds Tom Uren and The Grugq talk about whether the increasing use of AI will make it harder for forensics teams to determine who is responsible for a hack. This episode is also available on YouTube.RISKY.BIZ
25 AugFake Minecraft Sites Are Still Spreading WeedHack After C2 TakedownWeedHack Minecraft Malware Survives C2 Takedown: Fake Client Sites Still Active, SEO Poisoning Puts Malicious Downloads at the Top of Google McAfee Labs published a follow-up report on the WeedHack Malware-as-a-Service campaign this week, documenting ten active malicious sites an…SECURITYAFFAIRS.COM
24 AugA week in security (August 17 – August 23)A list of topics we covered in the week of August 17 to August 23 of 2026MALWAREBYTES.COM
24 AugSlovakia Warns of Cyber Risks in Road Speed CamerasSlovakia warns that vulnerable speed cameras could expose vehicle data, enable remote access and provide attackers with a foothold into public networks. Slovakia’s National Security Authority, NBÚ, recently issued a warning about several road speed cameras, calling them a signifi…SECURITYAFFAIRS.COM
24 AugTracking PavinLoader across ClickFix and fake download campaignsWe found PavinLoader being used across ClickFix, fake software, and RenPy campaigns to deliver Amatera Stealer and other malware.MALWAREBYTES.COM
24 AugHackers infecting Android car systems to build proxy botnetA new strain of malware is being used to infect Android-based car systems, turning the devices into part of a botnet.THERECORD.MEDIA
24 AugToxicPanda 2.0 can take over your Android phone and banking appsA new version of the Android banking Trojan can seize control of infected phones and block access to Google Play and Google Play Services.MALWAREBYTES.COM
24 AugFake Codex Download Uses Google Sites to Deliver macOS MalwareFake Codex pages used Google Sites, sponsored search and ClickFix to target Mac usersINFOSECURITY-MAGAZINE.COM
24 AugToxicPanda Banking Trojan Matures into Enterprise ThreatThe latest version of the Android malware has new features that expand its global reach and put more than users' financial applications at risk.DARKREADING.COM
24 AugSLTT Traffic Directing to S3 Buckets Hosting KrustyLoaderThe CIS CTI team identified several MS-ISAC members directing DNS traffic to AWS S3 buckets hosting Krustyloader malware. Read its analysis.CISECURITY.ORG
24 AugCybercriminals Turn GTA VI Leaks Into Malware BaitA fake 113GB GTA VI build is packed with malware, using massive empty files to hide a tiny malicious payload. GTA VI hype has reached the point where people are volunteering to infect their own computers just to check if a leak is real. Someone on X asked their followers to ̶…SECURITYAFFAIRS.COM
24 AugWhen AI Makes Everyone a Target with Mark Beare from MalwarebytesMark Beare, General Manager of Malwarebytes Consumer Business, joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices recorded at Black Hat USA 2026. He discusses how AI is helping scammers create highly personalized attacks at scale, why everyday consu…THECYBERWIRE.COMHTTPS:
23 AugBuilding a secure space internet.As space infrastructure has continued to expand, developing secure space systems has become just as important as launching the spacecraft themselves. In this week's episode, host Maria Varmazis sits down with Filip Rezabek, co-founder and CTO of Space Computer, to talk about …THECYBERWIRE.COM
23 AugSecurity Affairs newsletter Round 591 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. ToxicPanda 2.0 Gets a Major Upgra…SECURITYAFFAIRS.COM
23 AugToxicPanda Android malware uses VPN permissions to block Google PlayThe ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. [...]BLEEPINGCOMPUTER.COM
22 Aug14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0. "When the module loads, it locates …THEHACKERNEWS.COM
22 AugMalware Hijacks Android Car Head UnitsMalware is abusing car infotainment updates to install proxy software, turning Android head units into nodes for the BADBOX network. Kaspersky researchers found something in June 2026 that made them stop and look twice: an Android app with no interface at all, installed like any …SECURITYAFFAIRS.COM
21 AugThe invisible passenger in your carKaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It's delivered through legitimate software for DoFun head units.SECURELIST.COM
21 AugNew Agent Tesla Malware Variant Boosts Evasion CapabilitiesAn Agent Tesla v4 malware campaign used novel emoji-based code obfuscation to evade detection, KnowBe4 has revealedINFOSECURITY-MAGAZINE.COM
21 AugSenator asks US government watchdog to review how feds use hacking toolsSenator Ron Wyden sent a letter to the U.S. federal watchdog requesting a comprehensive review of how the FBI, DEA, ICE's HSI, and the Secret Service use hacking tools and spyware against Americans.TECHCRUNCH.COM
21 AugAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetCybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage download…THEHACKERNEWS.COM
21 AugNew SynkLoader malware pushed in Microsoft Teams phishing campaignA previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. [...]BLEEPINGCOMPUTER.COM
20 AugUpdated ToxicPanda Variant Targets 140+ Banking and Crypto AppsZimperium lifts the lid on the ToxicPanda 2.0 Android banking TrojanINFOSECURITY-MAGAZINE.COM
20 AugToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device FraudCybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with "significant enhancements," including a set of 167 remote commands and expands its targeting footprint globally. Zimperium zLabs, in a Wednesday report, said the Android ma…THEHACKERNEWS.COM
20 AugUAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilitiesThe newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.TALOSINTELLIGENCE.COM
20 AugUAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operationsCisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries affected, potential impact of BadIIS infections, the attack chain, and post-compromi…TALOSINTELLIGENCE.COM
20 AugYour Mac already has a built-in firewall. Here’s how to get more from itMalwarebytes Firewall gives you a clearer, more intuitive way to manage your Mac's inbuilt firewall.MALWAREBYTES.COM
20 AugJFrog Artifactory Flaws Enable Software Supply Chain AttacksTwo Artifactory flaws allowed attackers to poison package metadata across software repositoriesINFOSECURITY-MAGAZINE.COM
20 AugRust Supply Chain Attack on arrayref: Significant Overlap with DPRK CampaignsMalicious versions of the arrayref Rust crate (and others) executed a backdoor at compile time. The campaign's infrastructure overlaps with recent DPRK supply chain attacks, including Mastra and axios.WIZ.IO
20 AugSomeone targeted security researchers using a fake crypto conference as a lureA hacker pretending to work for a leading cryptocurrency news website targeted several cybersecurity professionals using Google Docs as a way to deliver malware.TECHCRUNCH.COM
19 AugMaaS Campaign Combines ClickFix, ErrTraffic and CruciferraeSentire uncovered a malware campaign combining ClickFix lures with ErrTraffic and CruciferraINFOSECURITY-MAGAZINE.COM
18 AugSilent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's CloudThe Python-based malware framework takes living-off-the-land tactics to a new heights of stealth, with a modular implant that steals credentials and achieves persistence.DARKREADING.COM
18 AugUS states sue Meta over claims that it deliberately addicts young users.Researchers reverse-engineer French malware used to hack EncroChat. An unprecedented number of Apple users received spyware alerts last week.THECYBERWIRE.COM
18 AugSecurity Hub Extended adds Supply Chain Security as its tenth categorySince February, we’ve grown AWS Security Hub Extended from 14 curated partners across 9 categories to 23 partners across 10. At Black Hat this month, 14 of those partners were at the Amazon Web Services (AWS) booth demoing live. Four of those partners delivered theater talks and …AWS.AMAZON.COM
17 AugA week in security (August 10 – August 16)A list of topics we covered in the week of August 10 to August 16 of 2026MALWAREBYTES.COM
17 AugInfostealers Harvest 1.7 Billion Credentials in Six MonthsFlashpoint data reveals infostealers were responsible for taking 1.7 billion credentials in the first half of 2026INFOSECURITY-MAGAZINE.COM
17 AugLiteLLM Supply-Chain Attack – Technology, Banking and Healthcare the Most AffectedThe SANDCLOCK LiteLLM supply-chain attack exposed credentials across 2,038 repositories, affecting technology, finance, healthcare, retail and more. Resecurity (USA) estimated the most affected sectors by the “SANDCLOCK” backdoor, which was planted as a result of the code reposit…SECURITYAFFAIRS.COM
17 Aug‘Unprecedented’ number of Apple users received recent spyware alert, say investigatorsCybersecurity experts who investigate spyware attacks say the number of people who received a recent threat notification from Apple is unusually high.TECHCRUNCH.COM
17 Aug'Turf War' Between Claude Agents Leads to Self-Replicating MalwareThree testing models with the same goal but different directives engaged in "increasingly aggressive" territorial attacks on one another, according to Anthropic.DARKREADING.COM
16 AugNew AmnesiaStealer macOS malware hijacks browser sessions via remote controlA new information-stealing malware called AmnesiaStealer, which targets macOS users via ClickFix attacks, includes a streaming module that allows the attacker to interactively control the victim's web browser. [...]BLEEPINGCOMPUTER.COM
16 AugMustang Panda Upgrades CoolClient With a Kernel RootkitMustang Panda upgraded CoolClient with a signed kernel driver that hides processes, files and network activity, making the backdoor harder to detect. HoneyMyte, also known as Mustang Panda, has pushed its CoolClient backdoor another step deeper into Windows. Kaspersky’s latest an…SECURITYAFFAIRS.COM
15 AugNew Evooo1Bot Linux botnet turns routers into traffic relay nodesA new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes. [...]BLEEPINGCOMPUTER.COM
14 AugNovel macOS Infostealer AmnesiaStealer Spread via ClickFixAmnesiaStealer contains novel functions, including the attackers gaining remote control over the victim’s browser to steal cookie dataINFOSECURITY-MAGAZINE.COM
14 AugNew Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into ProxiesEvooo1Bot is a newly observed botnet based on the Mirai framework but equipped with advanced features, turning edge devices into persistent proxiesINFOSECURITY-MAGAZINE.COM
14 AugMission-Driven Security: Inside a Global Bank's DefenseIn this video interview, Standard Chartered's group CISO shares insights on transitioning from technical roles to strategic leadership, the importance of business-savvy security executives, and how AI is reshaping both defensive capabilities and adversarial tactics in banking.DARKREADING.COM
13 AugNew Android malware lets criminals use your bank card in real timeSocial engineering, a Remote Access Trojan (RAT), and NFC relay malware walk up to an ATM. It's no joke. Together, they can empty your bank account.MALWAREBYTES.COM
13 AugNew Mirai variant adds stealth capabilities to notorious botnet codeBeyond Mirai’s usual functions, the new code features include encrypted communications with command-and-control servers and a “sniffer” that looks for default access credentials.THERECORD.MEDIA
13 AugClosing the Blind Spot: Securing Personal Repositories in the Software Supply ChainPersonal repositories are where corporate secrets quietly escape. Wiz correlates them to your developers, validates the real risk, and drives the fix.WIZ.IO
13 AugIf Apple sends you a push notification alerting you to a spyware attack, take it seriouslyApple now sends out push notifications to iPhone lock screens when the company identifies government spyware targeting someone's devices.TECHCRUNCH.COM
12 AugKimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate BrowsingCybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks. The new version, trac…THEHACKERNEWS.COM
12 AugKimwolf v7 Hides DDoS Traffic Behind Chrome Fingerprints and EthereumKimwolf v7: The Android TV Botnet That Now Hides Its Traffic Behind Chrome Fingerprints and Ethereum Palo Alto Networks Unit 42 discovered Kimwolf v7 on February 3, 2026, while hunting threats following public disclosures of the botnet’s earlier activity. The new version su…SECURITYAFFAIRS.COM
12 AugWindRelay Malware Pairs With SpyNote RAT in Live-Call ScamNew WindRelay NFC malware paired with SpyNote RAT let a fraudster clone a card mid-callINFOSECURITY-MAGAZINE.COM
12 AugUK Cyber Resilience: Closing the Execution GapA UK survey reveals cyber risk is growing, but cyber resilience is not keeping pace. Learn how CIS SecureSuite can help UK organizations move from awareness to execution.CISECURITY.ORG
12 AugThe AI Supply Chain Has a Trust Problem with Michael Leland from IslandMichael Leland, Field CTO at Island joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices at Black Hat USA 2026. He discusses the emerging risks in the AI supply chain, why AI agents introduce new challenges around trust and governance, and what organi…THECYBERWIRE.COMHTTPS:
11 AugA Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT DevicesA malicious SIM card can order the device it sits in to run commands of the attacker's choosing. On the cellular modules built into electric-vehicle chargers, industrial routers, and car telematics units, that is enough to take the whole device over. Researchers at the University…THEHACKERNEWS.COM
11 AugFake CCleaner installs GhostDesk Chrome spywareA convincing fake CCleaner website delivers a multi-stage malware attack that installs a spyware extension inside Chrome.MALWAREBYTES.COM
10 AugA week in security (August 3 – August 9)A list of topics we covered in the week of August 3 to August 9 of 2026MALWAREBYTES.COM
10 AugIT threat evolution in Q2 2026. Non-mobile statisticsThe report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as internet of things (IoT) devices, during Q2 2026.SECURELIST.COM
10 AugIT threat evolution in Q2 2026. Mobile statisticsThis report contains mobile threat statistics for Q2 2026, along with noteworthy discoveries and quarterly trends: the Anatsa banker and a transition to droppers.SECURELIST.COM
10 AugGo-Based macOS Malware Steals Crypto and SecretsA macOS malware variant has been detected stealing crypto, passwords and moreINFOSECURITY-MAGAZINE.COM
10 AugNew Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFAThree separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Window…THEHACKERNEWS.COM
10 AugSherlock Holmes was the “OG” Social EngineerThe crime solver wore disguises, spied on targets, and built intelligence networks long before modern-day tactics emerged. He has lessons for today’s ethical- and nonethical-hat hackers.DARKREADING.COM
9 AugSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 109Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums DarkSword’s Panel Sprawl: Ho…SECURITYAFFAIRS.COM
7 AugResearchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root AccessA hidden backdoor in 20 router models lets remote servers execute commands as root, putting affected devices at risk of takeover. Jacob Baines had a router on his desk that kept trying to call home, and it wasn’t supposed to. VulnCheck researchers found a backdoor baked int…SECURITYAFFAIRS.COM
7 AugLiving off the coding agent: Two tales of tunnels and LaunchAgentsAgent-parented reverse tunnels and LaunchAgents can expose a local admin app to the internet. Endpoint still needs to treat that as high severity even when the activity looks like vibe-coded ops, not confirmed malware.ELASTIC.CO
7 AugClickFix Attacks Deliver macOS Stealer That Can Drain Crypto WalletsClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection chain is designed to deliver a shell script that pro…THEHACKERNEWS.COM
6 AugChina-linked LightSpy spyware caught targeting victims in 13 countries, including the USResearchers linked the latest malicious activity to a Chinese company, after one of the spyware's operators placed an order with KFC using their real name and office address.TECHCRUNCH.COM
6 AugHackers Stalked Me by Hijacking a Smartwatch for KidsSecurity researchers tracked and eavesdropped on a WIRED reporter using vulnerabilities in a pink plastic smartwatch. It’s just one piece of a deeply insecure supply chain of GPS-enabled gadgets.WIRED.COM
6 AugClickFix attack pushes macOS infostealer for crypto theft attacksA Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. [...]BLEEPINGCOMPUTER.COM
5 AugWriting for People with a Remote in Their Hand, with Jake Milstein of Contrast SecurityJake Milstein ran newsrooms at CBS, NBC, Fox, and ABC affiliates for 25 years. He has five Emmys and strong feelings about the phrase "in today's evolving threat landscape." It turns out 25 years of writing for people with a remote in their hand is excellent training for cybersec…THECYBERWIRE.COM
5 AugGoogle’s synchronized passkeys can be stolen in ‘Pass‑ta‑key’ attacksOver time, passkeys are supposed to replace passwords. But what happens when malware steals the master key?MALWAREBYTES.COM
5 AugTrojanized npm Packages Decode C2 IP From Ethereum Recipient AddressesCybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer. The new dead drop resolver approach, obs…THEHACKERNEWS.COM
5 AugGoogle Blogger locks hundreds of blogs in malware false positiveGoogle has locked hundreds of Blogger websites after a false positive claimed they violated its "Malware and Similar Malicious Content" policy, with some sites deleted from the platform. [...]BLEEPINGCOMPUTER.COM
4 Aug18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool UsersCybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments. O…THEHACKERNEWS.COM
4 AugDOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RATA new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager. "The first s…THEHACKERNEWS.COM
4 AugSmears, Fakes & Phantoms: Cold War Britain's Secret Propaganda DepartmentIn Cold War Britain, a secret propaganda department saw its list of targets and tactics widen. Personnel inside the Information Research Department went beyond forgeries, fakes, and plants, conducting bold impersonations to smear critics and stoke tensions among foes. The team, w…THECYBERWIRE.COM
4 Augkeyv and cacheable npm Package Hijacked in Supply Chain AttackWiz Research is actively investigating an ongoing software supply chain attack affecting multiple keyv/cacheable npm packages.WIZ.IO
4 AugGreatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal TokensThe commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authenti…THEHACKERNEWS.COM
4 AugApple battles it out again with the UK over encrypted iCloud accessApple is fighting another attempt by the UK's Home Office to get a backdoor providing access to encrypted iCloud data.MALWAREBYTES.COM
3 AugA week in security (July 27 – August 2)A list of topics we covered in the week of July 27 to August 2 of 2026MALWAREBYTES.COM
3 AugGoogle Password Manager Attacks Could Let Malware Hijack Passkey-Protected AccountsMalware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim's screen. Unit 42 detailed three attack paths against Chrome's Google Password Manager cloud authe…THEHACKERNEWS.COM
3 AugApple challenges UK government’s latest demand for iCloud backdoor: reportApple has appealed a new legal demand by the U.K. government, which critics say could threaten the privacy rights of users all over the world.TECHCRUNCH.COM
3 AugNew DOUBLECUP ClickFix service hides malware in browser cache imagesA new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems. [...]BLEEPINGCOMPUTER.COM
3 AugFake Roblox Xeno script launcher pushes infostealer, RAT malwareFake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information. [...]BLEEPINGCOMPUTER.COM
2 AugThe weakest link in space.This week on T-Minus: Space-Cyber Briefing: we look at the space supply chain and how the sector's manufacturing revolution is changing not only how spacecraft are built but also how they must be secured.THECYBERWIRE.COM
2 AugSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 108Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter TAG-195 Upgrades MaaS Ecosystem with Modular Tools Inside a DPRK BlueNoroff ClickFix Kit SourTrade: Browser-Assembled Mal…SECURITYAFFAIRS.COM
2 AugOpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problemsOpenAI has revealed Astra, an unreleased model designed to tackle complex, long-running tasks, after an internal version produced ten significant advances in mathematics and theoretical computer science. [...]BLEEPINGCOMPUTER.COM
31 JulFake Flash Player installs AtlasRATResearchers have uncovered a new campaign that spreads the AtlasRAT remote access Trojan by disguising it as a Flash Player installer.MALWAREBYTES.COM
31 JulHollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law FirmCybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link …THEHACKERNEWS.COM
31 JulArch Linux disables AUR package adoption to stop malware floodThe Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages. [...]BLEEPINGCOMPUTER.COM
30 Jul'Flying Eagle' Full-Service Mobile RAT Builder Wings Across ChinaA premium-grade malware-as-a-service offering takes flight with multiple threat groups, building infostealers that drain victims' bank accounts.DARKREADING.COM
30 JulCyber threat bulletin: Non-state activity targeting Canadian operational technologyCYBER.GC.CA
30 JulMalwarebytes for Windows, now available on the Microsoft StoreInstall Malwarebytes for Windows from the Microsoft Store with the same full protection and features.MALWAREBYTES.COM
30 JulWhy brand impersonation is becoming an initial access vectorBrand impersonation now drives initial access, using fake sites and apps to deliver malware, making rapid takedowns essential to disrupt attacks. Attackers recently poisoned more than 700 websites, including sites run by Harvard, Oxford, and DuckDuckGo. They used a fake Cloudflar…SECURITYAFFAIRS.COM
30 JulMinnesota Water Utility Attacks Expose Sector's Cyber-RisksA likely Iran-backed actor targeted more than 30 community water systems in Minnesota in a sobering reminder of rising threats to US critical infrastructure.DARKREADING.COM
29 JulSecure your npm and pip package updates in Amazon LinuxIf you use and install packages from npm or PyPI, the first hours after a package is published are the riskiest because scanners can’t analyze packages before publication. Recent supply chain events affecting NodeJS and Python packages have been detected and removed within hours.…AWS.AMAZON.COM
29 JulWhen AppSec Scanners Become a Supply Chain Attack VectorNew research shows how security scanners embedded in the software supply chain can be attacked to serve as a foothold for downstream attacks.DARKREADING.COM
28 JulMirage Kitten targets Middle East and Africa region with new malwareKaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.SECURELIST.COM
28 JulNew Crypter-as-a-Service Cruciferra Fuels Stealthy Malware Attacks WorldwideProofpoint uncovered Cruciferra, a crypter-as-a-service that helps hackers evade antivirus and deliver malware in multiple campaigns. Proofpoint’s research team traced a wave of income-tax-themed lures targeting Indian taxpayers, tax professionals, and corporate finance tea…SECURITYAFFAIRS.COM
28 JulNimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert RelaysThe Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia. The intrusions involve t…THEHACKERNEWS.COM
28 JulWe rebuilt Malwarebytes Mobile Security for the scams of todayYour phone needs more than a lock screen to stay safe. We've rebuilt Malwarebytes Mobile Security to put scam protection first and keep your phone secure.MALWAREBYTES.COM
27 JulA week in security (July 20 – July 26A list of topics we covered in the week of July 20 to July 26 of 2026MALWAREBYTES.COM
27 JulWhat the Trojan horse gets right (and wrong) about AI securityAgentic AI didn't invent new risk. It removed the friction that used to keep environments in check.CYBERSECURITYDIVE.COM
27 JulCruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows MalwareThe China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate finance teams has been observed using a sophisticated crypter service called Cruciferra. According to a new analysis by Proofpoint, C…THEHACKERNEWS.COM
27 JulSourTrade Malvertising Campaign Secretly Builds Malware in the BrowserImpersonating well-known cryptocurrency and trading sites, SourTrade has developed a novel technique to drop infostealers to victimsINFOSECURITY-MAGAZINE.COM
27 JulMedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal DataMedusaHVNC RAT uses hidden Windows desktops to remotely control browsers, steal data, and evade detection through legitimate system features. Windows has always supported hidden desktops as a legitimate feature, useful for specialized software that needs a workspace the user neve…SECURITYAFFAIRS.COM
26 JulMalvertising Sends Malware in Pieces, Then Makes the Browser Build the ExecutableA malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL. Confiant, which detailed the campaign on July 23, 2026,…THEHACKERNEWS.COM
26 JulHow sovereign is Europe's space industry?As space becomes an increasingly important part of global communications, national security, and critical infrastructure, European governments are confronting a difficulty: How much control do they need over their own space capabilities? In this week’s episode, host Maria Varmazi…THECYBERWIRE.COM
26 JulGitHub, PyPI add time-absed defenses against supply chain attacksGitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. [...]BLEEPINGCOMPUTER.COM
25 JulOpenAI confirms ChatGPT is down worldwideChatGPT, the famous artificial intelligence chatbot that allows users to converse with various personalities and topics, has connectivity issues worldwide. [...]BLEEPINGCOMPUTER.COM
25 JulMalicious sites use JavaScript to build malware in browser memoryA massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. [...]BLEEPINGCOMPUTER.COM
24 JulBeyond the Play Store: How Android threats really spreadSome threats never pass through the Play Store. Others arrive later in seemingly legitimate updates. Here's how Malwarebytes detects both.MALWAREBYTES.COM
24 Jul'Wrench' attacks against crypto holders appear to be on the riseThere are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.THERECORD.MEDIA
23 JulBrazilian Banking Trojan Actively Spreading in PortugalPortuguese businesses operate in the same native language as Brazilian hackers, making those businesses easy targets.DARKREADING.COM
23 JulNew Dolphin X Stealer Employs AI Profiling to Prioritize TargetsDolphin X is a new infostealer that uses AI to sort and rank victims, giving cybercriminals a faster way to identify lucrative targetsINFOSECURITY-MAGAZINE.COM
23 JulThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More StoriesMost of this week's trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code, and normal network traffic. The threat…THEHACKERNEWS.COM
23 JulHackers abuse Notepad++ plugins to stealthily install malwareUkraine's CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence. [...]BLEEPINGCOMPUTER.COM
23 JulFake Claude app promoted by Bing ads pushes SectopRAT malwareA malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware. [...]BLEEPINGCOMPUTER.COM
23 JulNew Dolphin X malware uses AI to rank high-value targetsA new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first. [...]BLEEPINGCOMPUTER.COM
22 JulTrojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working LibraryCybersecurity researchers have discovered a NuGet typosquat that's unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it's designed to rig live game results on Digitain. The package, named "Newtonsoftt.Json.Net," masquerades a…THEHACKERNEWS.COM
22 JulSol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?A real-world benchmark tests whether powerful AI models can keep an investigation trustworthy when new evidence invalidates their conclusions.SENTINELONE.COM
21 Jul KEVSecuring Research Infrastructure and Managing Shadow AI with Kevin MortimerHost Caleb Tolin sits down with Kevin Mortimer to discuss securing higher education infrastructure and managing the shift toward autonomous AI deployment. Kevin details his experience supporting research environments, expanding multi factor authentication controls, and defending …THECYBERWIRE.COM
21 JulIran War Cyber Threat Landscape | A Midyear Assessment on What MattersIn April, SentinelLABS’ Tom Hegel published an initial assessment of the first five weeks of the conflict. Three months later, the evidence supports refinement.SENTINELONE.COM
21 JulNew ClickLock Stealer locks your Mac until you hand over your passwordA new macOS infostealer tricks victims into revealing their system password and installs a persistent backdoor for future access.MALWAREBYTES.COM
21 JulA Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind SpotsA new type of malware can worm deep into AI coding systems to steal data and logins—and can flip a “death switch” to destroy files and keep out real users.WIRED.COM
21 JulFakeGit campaign uses 7,600 GitHub repos to push SmartLoader malwareA large-scale operation dubbed 'FakeGit' is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads. [...]BLEEPINGCOMPUTER.COM
20 JulSleeperGem Uses Three Malicious RubyGems Packages to Target Developer MachinesCybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue gems are listed below - git_credential_man…THEHACKERNEWS.COM
20 JulA week in security (July 13 – July 19)A list of topics we covered in the week of July 13 to July 19 of 2026MALWAREBYTES.COM
20 JulFake games spread stealers with RenPy Loader, MSBuild and EtherHidingWe look into how attackers are using the legitimate Ren'Py game engine to spread a malware loader that ultimately delivers Amatera Stealer.MALWAREBYTES.COM
20 JulNew HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 CommunicationsResearchers have linked HollowGraph malware to the Cavern framework after discovering its use of Microsoft 365 calendars and Microsoft Graph APIs as a stealthy C2 channelINFOSECURITY-MAGAZINE.COM
20 JulOdyssey piracy scams appear within hours of the movie’s releaseThe release of The Odyssey has already sparked a wave of piracy scams, from fake browser errors to malware masquerading as movie files.MALWAREBYTES.COM
20 JulExposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware CampaignA malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Me…THEHACKERNEWS.COM
20 JulAttackers Combo Up Evasion Tactics for BEC Phishing"The TFF Trap" uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger.DARKREADING.COM
20 JulFakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader MalwareCybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign cod…THEHACKERNEWS.COM
19 JulSecurity Affairs newsletter Round 586 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. OpenSSL Fixes HollowByte Memo…SECURITYAFFAIRS.COM
18 JulSeven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RATCybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which wa…THEHACKERNEWS.COM
18 JulMicrosoft warns of surge in ACR Stealer attacks on customersMicrosoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers. [...]BLEEPINGCOMPUTER.COM
17 JulACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 FilesACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders. It gets in because someone pasted a command into a…THEHACKERNEWS.COM
17 JulHow to use GitHub safelyKnowing how to spot a malicious GitHub repository can help you avoid downloading malware disguised as legitimate software.MALWAREBYTES.COM
17 JulFBI arrests man accused of using Steam games to drain victims’ crypto walletsProsecutors accused 21-year-old student Zyaire Wilkins of publishing on Steam several fake video games that contained malware, infecting thousands of victims, and stealing crypto from some of them.TECHCRUNCH.COM
17 JulNew NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes TokensA Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local …THEHACKERNEWS.COM
16 JulTELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chainsTELEPUZ is a modular malware that emerged through CLICKFIX-VIDAR attacks in April. We reverse-engineered it to show you the infrastructure and evasion techniques that matter.ELASTIC.CO
16 JulTuxBot v3: The IoT Botnet Built With AI – Bugs, Disclaimers and AllTuxBot v3, an AI-built IoT botnet for 17 architectures, shipped with LLM bugs and safety disclaimers the developer never removed. Palo Alto Networks’ Unit 42 identified a previously undocumented modular IoT botnet framework called TuxBot v3 Evolution, and it comes with an u…SECURITYAFFAIRS.COM
16 JulNew TELEPUZ Malware Spreads via ClickFix to Steal Data and Run CommandsCybersecurity researchers have called attention to a new modular malware called TELEPUZ that's been spreading via websites infected with ClickFix lures since late April 2026. "The malware is full-featured, lightweight, and modular," Elastic Security Labs researcher Cyril François…THEHACKERNEWS.COM
16 JulNew ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their PasswordClickLock Stealer, a new macOS infostealer, answers a victim's refusal by killing their apps on a loop until they hand over the login password. It arrives as a command pasted into Terminal, asks for the password behind a fake system dialog, and when the victim cancels, installs t…THEHACKERNEWS.COM
16 JulPhishing Campaign Hides Lua Loader as TrueType Font FileGlobal phishing campaign disguised a Lua loader as a font file to deploy RATs and infostealersINFOSECURITY-MAGAZINE.COM
16 JulPeriod tracker Stardust shares users’ health data with analytics firm, says Mozilla researchOne period tracker app tested by Mozilla was 'squeaky clean,' while another app was seen sharing users' health data with an analytics company, underscoring vast differences in user privacy among these apps.TECHCRUNCH.COM
15 Jul AsyncAPI npm packages infected with credential-stealing malwareFive malicious versions of AsyncAPI packages were published to the Node Package Manager (npm) in a supply-chain attack that delivered a remote access trojan with info-stealing capabilities. [...]BLEEPINGCOMPUTER.COM
15 JulOkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor AppsA malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wallet owners out of their recovery phrase. On an infected PC, the request comes from inside the wallet's own desktop software. Sometimes it wa…THEHACKERNEWS.COM
14 Jul148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS BotnetA campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May, according to new research from JFrog. The packages did not go after the developers who might install them. The …THEHACKERNEWS.COM
14 JulM-Red-Team: AsyncAPI Supply Chain Compromise via GitHub ActionsDetect and mitigate malicious @asyncapi npm packages linked to the latest npm supply chain attack.WIZ.IO
14 JulClickFix's Mushrooming Ecosystem Demands New Defense TacticsThe attack vector is available for rent at scale, and evades AV and EDR, leaving YARA analysis as the best detection option.DARKREADING.COM
14 JulLabubaRAT Masquerades as NVIDIA Software to Control Windows HostsCybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into target environments. "LabubaRAT creates a reusable foothold for hands-on activity," Blackpoint Cyber resear…THEHACKERNEWS.COM
13 JulA week in security (July 6 – July 12)A list of topics we covered in the week of July 6 to July 12 of 2026MALWAREBYTES.COM
13 JulUS and allies warn of Russian critical infrastructure attacksCybersecurity agencies from the United States and eight other countries have issued a joint warning that Russian state hackers are targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks. [...]BLEEPINGCOMPUTER.COM
13 JulForg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session TheftA new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, artificial intelligence (AI)-assisted lure creation, and post-compromise mailbox operations targeting Microsoft 36…THEHACKERNEWS.COM
13 JulNew CrashStealer malware poses as Apple crash reporting toolA new macOS information-stealing malware called CrashStealer pretends to be Apple's crash-reporting tool to steal credentials, keychain data, and crypto wallets. [...]BLEEPINGCOMPUTER.COM
12 JulRedHook Android malware now uses Wireless ADB for shell accessA new version of the RedHook Android malware abuses the Android Wireless Debugging (Wireless ADB) mechanism in a novel way to gain shell-level privileges without requiring a computer connection. [...]BLEEPINGCOMPUTER.COM
12 JulSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 105Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Novel Java-Based QuimaRAT Targets Windows, macOS, and Linux Vibe Coded Extortion: Avalon’s Path from Legal Lure to …SECURITYAFFAIRS.COM
11 JulAustralian telecom outage attributed to software bug.FBI disrupts residential proxy network used by botnet. Zimbra patches a critical flaw in its Classic Web Client.THECYBERWIRE.COM
10 JulFrom 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at ScaleMost enterprises assume their asset inventory is close enough to accurate. The evidence suggests otherwise. According to a survey of over 600 security leaders in the 2026 Axonius Actionability Report, only 45% of organizations consolidate their asset and exposure data into a sing…THEHACKERNEWS.COM
10 JulExposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress SitesA cybercrime crew left one of its own servers wide open on the internet for three weeks, and it exposed the operation's inner workings: the hacking tools, the activity logs, and target lists naming more than 1.4 million websites. Far fewer were actually broken into, but the expos…THEHACKERNEWS.COM
10 JulStudy of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and TrackingResearchers ran 281 of the most popular free VPN apps on the Google Play Store through a new testing system and found that many fail at the basics people install a VPN for, i.e., keeping their traffic private and secure. The apps flagged with at least one problem have been instal…THEHACKERNEWS.COM
10 Jul222 GitHub Repositories Linked to Fake Go Package Malware OperationResearchers uncovered 222 GitHub repositories spreading malware through fake Go packages, delivering loaders, stealers, RATs, and cryptominers. Socket’s security research team started with the investigation of a single malicious Go module: github[.]com/kaleidora/dnsub-scann…SECURITYAFFAIRS.COM
10 JulNew MODBEACON RAT Uses gRPC Streaming for Encrypted C2 TrafficThe China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan (RAR) called MODBEACON. Chinese cybersecurity company QiAnXin said that while the threat cluster may appear like a low-sophistication, high-activity operation that p…THEHACKERNEWS.COM
10 JulThis new Windows malware can take over your PC and wipe it cleanGigaWiper is a remote access Trojan that can spy on victims and permanently wipe their systems in three different ways.MALWAREBYTES.COM
10 JulNew U-Boot flaws could enable stealthy firmware attacksSix vulnerabilities in the widely used U-Boot bootloader have been discovered that could allow attackers to execute malicious code during device boot, potentially enabling stealthy firmware attacks that compromise security protections and install persistent malware. [...]BLEEPINGCOMPUTER.COM
9 JulEuropean Organizations Have a Collaboration Security Confidence GapA new survey shows security leaders have an inflated sense of safety regarding their collaboration tools and platforms.DARKREADING.COM
9 JulFake VPN and 7-Zip Apps Turn Victims Into Residential Proxy NodesFake apps like WireVPN and a trojanized 7-Zip turn victims’ devices into residential proxies, letting criminals route traffic through their IPs. Infoblox’s threat research team started pulling on a single thread in early 2026: a fake version of the 7-Zip archive utili…SECURITYAFFAIRS.COM
9 JulEU takes member states to court over unimplemented cybersecurity lawIreland, Spain, France and the Netherlands are more than 20 months late in transposing the NIS2 Directive for the cybersecurity of critical infrastructure.THERECORD.MEDIA
9 Julnpm 12 Disables Install Scripts by Default to Reduce Supply Chain RiskGitHub has officially announced the release of npm version 12 with install scripts disabled by default, along with deprecating granular access tokens (GATs) designed to bypass two-factor authentication (2FA). The Microsoft-owned subsidiary noted that the following npm install beh…THEHACKERNEWS.COM
9 JulNew Helix vishing group emerges in SharePoint data theft attacksA new data-extortion group called Helix is using identity-focused tactics such as voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse to steal data from SharePoint environments. [...]BLEEPINGCOMPUTER.COM
8 JulRedWing Android Spyware Sold as a Service on TelegramZimperium found RedWing, an Android spyware sold as a service via Telegram to target banking appsINFOSECURITY-MAGAZINE.COM
8 JulNew HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet MalwareAI coding assistants have a habit of making things up. Ask one to fetch a popular tool, and it will sometimes hand back a real-sounding name for a project that does not exist. New research, which its authors call HalluSquatting, turns that habit into an attack: work out the …THEHACKERNEWS.COM
8 JulVidar Infostealer Hammers SMBs via Malvertising CampaignA financially motivated operation uses lures of cracked or pirated software to deliver a malware two-for-one combo for data theft and cryptomining.DARKREADING.COM
8 JulFake Paysafe, Skrill SDKs on NPM and PyPi steal credentialsMalicious packages on the Node Package Manager (npm) and the Python Package Index (PyPI) delivered stealer malware to developers and users of Paysafe, Skrill, and Neteller payment applications. [...]BLEEPINGCOMPUTER.COM
7 JulBig Brand Jobs Scam Targets Marketing Pros' Google AccountsThe phishing campaign uses several tactics, including nested redirects, to evade detection and steal credentials from unsuspecting targets.DARKREADING.COM
6 JulSkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting PackingScanners meant to catch malicious add-on "skills" for AI coding agents can be fooled by a few simple changes that leave the malware working, according to a new study from researchers at the Hong Kong University of Science and Technology. Their strongest trick slipped pa…THEHACKERNEWS.COM
6 JulA week in security (June 29 – July 5)A list of topics we covered in the week of June 29 to July 5 of 2026MALWAREBYTES.COM
6 JulNew TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable EmissionsResearchers at Shandong University have shown a fast new way to pull data off computers that are cut off from every network. The technique, called TrojPix, tweaks on-screen pixels in ways the eye cannot see, so that the video cable carrying them radiates a faint ra…THEHACKERNEWS.COM
6 JulNew Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOSCybersecurity researchers have flagged a novel Java-based remote access trojan (RAT) called QuimaRAT that's capable of targeting Windows, Linux, and macOS environments. According to LevelBlue, the cross-platform malware is advertised under a malware-as-a-service (MaaS) model, cos…THEHACKERNEWS.COM
6 JulNetNut botnet takes a hit. Don’t be part of the next one.Google, the FBI, and other partners have disrupted a residential proxy network built on millions of hijacked devices and used by criminals.MALWAREBYTES.COM
6 Jul'BusySnake' Infostealer Slithers into Critical Infrastructure NetworksA threat group researchers call "Armored Likho" has gained access to government agencies and electrical power entities in Russia, Brazil, and Kazakhstan.DARKREADING.COM
3 JulSpyware found on phone of European Parliament member probing itStelios Kouloglou, formerly a member of the European Parliament's committee investigation abuses of commercial spyware, was twice infected with Pegasus while serving, researchers said.THERECORD.MEDIA
3 JulEU Politicians Investigated Pegasus Spyware. Then It Ended Up on One of Their Phones“It is a direct attack on the rule of law,” says one European Parliament member of the new findings from Citizen Lab.WIRED.COM
2 JulContext Engineering | Compaction & Agent Memory for Automated Malware AnalysisCompaction cut input tokens 86% across long-running agent evals with no quality loss. Context discipline matters as much as model selection.SENTINELONE.COM
2 JulConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 SecondsConsentFix and ClickFix attacks steal Microsoft 365 tokens in seconds using fake prompts and OAuth flows. Learn how these MFA bypass tactics work and how to defend against them. [...]BLEEPINGCOMPUTER.COM
2 JulFake Google and Cloudflare verification pages spread multiple malware familiesWe uncovered ClickFix attacks using fake Google and Cloudflare pages to deliver everything from infostealers to a newly discovered malware loader.MALWAREBYTES.COM
1 JulResearcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware DeliveryClickFix, the trick that fools people into running malware by hand, has quietly grown a back office. New research shows the malicious commands behind its fake "prove you're human" pages are now handed out by API-driven servers that give each visitor the same malware in a differen…THEHACKERNEWS.COM
1 JulPhantom Squatting Uses AI-Hallucinated Domains for Phishing and MalwareLarge language models keep inventing web addresses that do not exist. Attackers have started buying those made-up domains before anyone else can, then hosting phishing pages on them to catch traffic that AI tools point their way. Palo Alto Networks' Unit 42 calls the tr…THEHACKERNEWS.COM
1 JulMartin Lee: Running through the Arctic (and the threat landscape)Ever wonder how someone goes from studying human viruses to leading cybersecurity teams? In this Humans of Talos, we’re joined by Martin Lee, EMEA Lead, to talk about his journey into the industry.TALOSINTELLIGENCE.COM
1 Jul2026 Cybersecurity Assessment: The Gap Between Awareness and ResilienceOrganizations have never had greater awareness of cyber risk. Yet turning that awareness into operational resilience has never been more challenging. The 2026 Bitdefender Cybersecurity Assessment confirms this is the case, as this year's findings reveal a series of surprising con…THEHACKERNEWS.COM
1 JulBrazilian Banking Trojan Ousaban Targets Spain and PortugalFortiGuard says the Brazilian banking trojan Ousaban is targeting Spain and Portugal via phishingINFOSECURITY-MAGAZINE.COM
1 JulFileless Malware Abuses Google Blogspot to Deploy Infostealer in MemorySecuronix said the Veil#Drop campaign abuses Google Blogspot to deliver PureLog Stealer in memoryINFOSECURITY-MAGAZINE.COM
1 JulOusaban Banking Trojan Targets Iberian Bank Users with Fake PDF LuresA Brazilian banking trojan called Ousaban is going after Windows users who bank in Spain and Portugal. Fortinet's FortiGuard Labs identified the campaign in May 2026. It opens with a phishing PDF disguised as a corrupted file, checks that the visitor is really in Spain …THEHACKERNEWS.COM
1 Jul'Phantom Squatting': An Emerging AI-Driven Supply Chain ThreatLLMs consistently hallucinate Web domains for legitimate brands that attackers can register for malicious activity in a difficult-to-detect attack vector.DARKREADING.COM
1 JulVEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs StealerCybersecurity researchers have flagged a new multi-stage malware delivery attack chain that uses social engineering and Blogger pages to deliver an information stealer called PureLogs. The activity has been codenamed VEIL#DROP by Securonix. It's suspected that the initial payload…THEHACKERNEWS.COM
1 JulAnd the Winner in Dominant Malware Delivery? ClickFixResearchers say the highly effective social engineering technique is no longer the exception for malware attacks — it's now the rule.DARKREADING.COM
30 JunDefending the Authentication Flow: Device Code Phishing with Selena LarsonHost Caleb Tolin sits down with Selena Larson, Staff Threat Researcher and Lead, Intelligence Analysis and Strategy at Proofpoint and Host of the DISCARDED podcast, to discuss the mechanics of device code phishing and the widespread abuse of Microsoft OAuth authentication flows. …THECYBERWIRE.COM
30 JunUSB drives carrying China-linked malware infected Japanese military networks for nearly a yearRead more in my article on the Hot for Security blog.BITDEFENDER.COM
30 JunHackers Leverage Blockchain to Hit Japan's Hotels Through Booking.com PhishingA wave of phishing emails sent to Booking.com partner accommodations in Japan in May led to blockchain-hosted malwareINFOSECURITY-MAGAZINE.COM
30 JunClickFix Now Cybercriminals' Favorite Malware Delivery TechniqueReliaQuest report warns of a surge in ClickFix social engineering attacks against Windows and macOS usersINFOSECURITY-MAGAZINE.COM
30 JunRustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoSA new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers, then stitching them into a network built to knock websites and online services offline. Researchers at QiAnXin's XLab have tracked it since F…THEHACKERNEWS.COM
30 JunPhishers Gain Persistence at EU, Asia Hospitality OrgsSeparate but similar campaigns described by Microsoft and Trend Micro use malicious zip files to spread malware via social engineering and obsfucation, including blockchain abuse.DARKREADING.COM
29 JunA week in security (June 22 – June 28)A list of topics we covered in the week of June 22 to June 28 of 2026MALWAREBYTES.COM
29 JunWebinar: Why business email compromise attacks keep succeedingBusiness email compromise attacks increasingly rely on convincing impersonation rather than malware, making them harder for employees and traditional email defenses to detect. This webinar explores how behavioral AI can help identify sophisticated email threats and automate respo…BLEEPINGCOMPUTER.COM
29 Jun⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and MoreThis week was a reminder that attackers do not always need big tricks. One small mistake, one old access path, one missed patch, and suddenly the door is open. The noise is not all noise, either. Forums are talking, researchers are finding easy cracks, and defenders have more cle…THEHACKERNEWS.COM
29 Jun119 Edge extensions promised useful tools, instead downloaded malwareMicrosoft has removed over 100 Edge extensions that were delivering malware hidden in images.MALWAREBYTES.COM
28 JunSpace supply chain pressures.Despite the space sector seeing greater investment and attention year-over-year, the sector still remains bound by an outdated and ineffective supply chain, especially in the United States. In this week’s episode, host Maria Varmazis sits down with Doug Anderson, Partner at Pw…THECYBERWIRE.COM
28 JunSpace’s fragile supply chain.This week on T-Minus: Space-Cyber Briefing: we look at recent research that examines the US’s current space supply chain. Despite increased investment and growing demand for space capabilities, the industry’s supply chain remains vulnerable to bottlenecks, shortages, and external…THECYBERWIRE.COM
27 JunMore bark than byte.This week we are joined by Daniel Schwalbe, Chief Information Security Officer & Head of Investigations at DomainTools, discussing their work on "ZionSiphon OT Malware First Attempts? Psyops? Both?" Researchers at DomainTools take a closer look at ZionSiphon, a purported oper…THECYBERWIRE.COM
27 JunSecurity News This Week: LastPass Users Had Their Data Stolen—AgainPlus: Former national security advisor John Bolton pleads guilty in classified-materials case, Microsoft helps take down major infostealer infrastructure, and more.WIRED.COM
27 JunSay hi to Pike!In this article we will introduce Pike, an experimental LLM agent that generates and analyzes Linux program execution traces. We will show that with its simple architecture paired with a good LLM, Pike can quickly help debug a crash, identify malware, or give valuable high level …SYNACKTIV.COM
27 JunCreating a "Two-Face" Rust binary on LinuxIn this article we will describe a technique to easily create a "Two-Face" Rust binary on Linux: an executable file that runs a harmless program most of the time, but will run a different, hidden code if deployed on a specific target host. This approach, which allows binding a bi…SYNACKTIV.COM
27 JunQuantum readiness: Hybridizing key exchangesFollowing our previous article on signatures hybridization, this article covers the basics of hybridizing your key exchanges to ensure maximal security of your data.SYNACKTIV.COM
27 JunLinkPro: eBPF rootkit analysisDuring a digital investigation related to the compromise of an AWS-hosted infrastructure, a stealthy backdoor targeting GNU/Linux systems was discovered. This backdoor features functionalities relying on the installation of two eBPF modules, on the one hand to conceal itself, and…SYNACKTIV.COM
27 JunLLM Poisoning [1/3] - Reading the Transformer's ThoughtsYour local LLM can hack you. This three-part series reveals how tiny weights edits can implant stealthy backdoors that stay dormant in everyday use, then fire on specific inputs, turning a "safe" offline model into an attacker. This article shows how transformers encode concepts …SYNACKTIV.COM
27 JunThe Mac Malware of 2019Our annual report on all the Mac malware of the year - including samples for download, infection vectors, persistence mechanisms, payloads and more!OBJECTIVE-SEE.ORG
27 JunThe Mac Malware of 2018Our annual report on all the Mac malware of the year - including samples for download, infection vectors, persistence mechanisms, payloads and more!OBJECTIVE-SEE.ORG
27 JunOSX.DummyA new Mac malware targets the cryptocurrency community. In this post, we dive into the malware and illustrate how Objective-See's tools can generically thwart this new threat at every step of the way.OBJECTIVE-SEE.ORG
27 JunTearing Apart the Undetected (OSX)Coldroot RATI uncovered a new cross-platform backdoor that provides remote attackers persistent access to infected systemsOBJECTIVE-SEE.ORG
27 JunAy MaMi - Analyzing a New macOS DNS HijackerOSX/MaMi (the first Mac malware of 2018) hijacks infected users' DNS settings and installs a malicious certificate into the System keychain, in order to give remote attackers 'access' to all network trafficOBJECTIVE-SEE.ORG
27 JunMac Malware of 2017Let's look at all the mac malware from 2017, for each - discussing their infection vector, persistence mechanism, features & goals.OBJECTIVE-SEE.ORG
27 JunOSX/Proton.B; a brief analysis, 6 miles upAnalysis of OSX/Proton.B reveals some interesting tricks plus a command file that can be decrypted to reveal the malware's capabilitiesOBJECTIVE-SEE.ORG
27 JunMac Malware of 2016Let's analyse the malware that appeared in 2016, discussing the infection vector, persistence mechanism, feature, and disinfection for each.OBJECTIVE-SEE.ORG
27 JunHackingTeam Reborn; A Brief Analyis of the RCS Implant InstallerHackingTeam using native OS X crypto to protect malware -neat! New blog w/ sample + decryptions/dumpings/detectionsOBJECTIVE-SEE.ORG
27 JunMore on, "Adware for OS X Distributes Trojans"A deeper dive into 'MacInstaller' and the adware it installsOBJECTIVE-SEE.ORG
27 JunClean GitHub repo tricks AI coding agents into running malwareAn agentic coding tool tasked with cloning and setting up a seemingly benign GitHub repository could execute a malicious payload that remains invisible to security scanners, AI agents, and human reviewers. [...]BLEEPINGCOMPUTER.COM
26 JunChina-Linked Hackers Strike Asian Critical Infrastructure with TinyRCT BackdoorA China-linked threat group has been targeting critical infrastructure in Southeast Asia with a new custom backdoor called TinyRCTINFOSECURITY-MAGAZINE.COM
26 JunMalware steals Chrome session cookies to take over your accountsA phishing campaign installs a malicious Chrome extension to hijack browser sessions and compromise Windows devices.MALWAREBYTES.COM
25 JunNew Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted AnalysisA previously undocumented Rust-based macOS implant and information stealer has been found to embed a prompt injection payload designed to trick a malware analyst's artificial intelligence (AI) tools and trick it into aborting or refusing an analysis of the artifact. The malware h…THEHACKERNEWS.COM
25 JunNew Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT CampaignsA new, stealthy backdoor named Mistic has been deployed as part of suspected financially motivated attacks aimed at multiple organizations spanning insurance, education, IT, and professional services sectors since April 2026. According to Symantec and Carbon Black's Threat Hunter…THEHACKERNEWS.COM
25 JunInside the 2026 SMB threat landscape: From phishing and scams to fake AI toolsKaspersky researchers analyze the threat landscape for SMBs in 2026: the rise of attacks involving fake AI tools, phishing schemes, and data sold on the dark web.SECURELIST.COM
25 JunInternational operation disrupts Amadey and StealC malware infrastructure.Cal Water says Handala's hacking claims were overstated. Stealthy new backdoor may be tied to initial access broker. DraftKings hacker is sentenced to eighteen months.THECYBERWIRE.COM
25 JunBritish Police Built a Sprawling Crime-Prediction Machine. Some Results Couldn’t Be TrustedAs UK police embrace the AI revolution, a WIRED investigation reveals the messy inside story of one region’s experiment with predictive analytics.WIRED.COM
25 JunNew macOS malware embeds fake errors to confuse AI analysis toolsA newly discovered macOS malware dubbed "Gaslight" is designed to confuse AI-assisted malware analysis tools by hiding prompt injection strings and fake debugging data within the executable. [...]BLEEPINGCOMPUTER.COM
📰 CYBERSECURITY BRIEFINGS 12[+]
20 SepStandardizing space cybersecurity.This week on T-Minus: Space-Cyber Briefing: we dive deeper into how stronger cybersecurity standards are necessary for the space sector and what tools are already in place that can serve as a starting point.THECYBERWIRE.COM
13 SepSpace cybersecurity needs new rules.This week on T-Minus: Space-Cyber Briefing: we dive deeper into current cybersecurity practices in space and how these policies are rapidly becoming obsolete as spacecraft and technologies become interconnected..THECYBERWIRE.COM
23 AugSpace’s trust problem.This week on T-Minus: Space-Cyber Briefing: we look at how the current space infrastructure creates inherent security problems and how moving the root of trust into the hardware itself. By changing this approach and by preparing for the next generations of new technologies, the s…THECYBERWIRE.COM
16 AugAttacking trust in space.This week on T-Minus: Space-Cyber Briefing: we look at how AI systems are being used to abuse the trust people have in space-based imagery. This abuse has caused people to believe that fake images and videos are genuine and dismiss real content as misinformation.THECYBERWIRE.COM
9 AugBuilding space in the AI era.This week on T-Minus: Space-Cyber Briefing: we look at how artificial intelligence (AI) is impacting the space sector and introducing new cybersecurity challenges that manufacturers have not fully realized.THECYBERWIRE.COM
3 Aug⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS HijacksThis week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most of it was just acce…THEHACKERNEWS.COM
26 JulThe myth of space sovereignty.This week on T-Minus: Space-Cyber Briefing: we dive deeper into space sovereignty. While achieving true space independence may be the goal, achieving this objective often proves significantly harder than many realize.THECYBERWIRE.COM
19 JulReimagining European space sovereignty.This week on T-Minus: Space-Cyber Briefing: we look at the recent evolution of the European space program. Whereas the region had previously relied on the US to support its space goals, both the UK and the EU have begun to make significant changes to reduce this reliance.THECYBERWIRE.COM
12 JulSpace after quantum.This week on T-Minus: Space-Cyber Briefing: we look at how the space sector is preparing itself for quantum computing. While practical quantum computing has long seemed just over the horizon, governments and commercial space operators alike are now actively preparing for the day …THECYBERWIRE.COM
5 JulThe rise of the commercial space industry.This week on T-Minus: Space-Cyber Briefing: we look at how the space sector has continued to evolve in recent years as commercialization has continued to expand. As this market has changed, government agencies and companies have changed their approaches to innovation, interoperab…THECYBERWIRE.COM
4 JulSecurity Roundup: Apple’s Hide My Email Service Fails to Hide Your EmailPlus: Alleged Scattered Spider hacking member extradited, dozens of license plate reader errors, and Indian officials are concerned about WhatsApp’s username rollout.WIRED.COM
🎙️ PODCASTS 47[+]
22 SepBetween Two Nerds: Real-time cyber defenceIn this edition of Between Two Nerds Tom Uren and The Grugq talk about whether there is such a thing as real-time cyber defence. Will agentic AI save us from hacking AI? This episode is also available on YouTube.RISKY.BIZ
22 SepLOW - Now AvailableAfter 8 years, LOW is finally here. A story about the weight of being and the wreckage of waking up. Five episodes. Five descents. LOW is an audio journey into the unlit corners of human experience. Choices we made in the dark, the silences we carry, and what remains when we stop…PLAY.PRX.ORG
21 SepSponsored: SpecterOps on the impact of AI agents on BloodHoundIn this Risky Business sponsored interview, Catalin Cimpanu talks with Justin Kohler, Chief Product Officer at SpecterOps. Justin explains how Entra Agent ID can introduce new identity relationships and potential attack paths.RISKY.BIZ
21 SepThe AI plot to scan and destroy books (Lock and Code S07E19)This week on the Lock and Code podcast, we speak with Emanuel Maiberg about Amazon's effort to scan and destroy rare books for AI training.MALWAREBYTES.COM
16 SepRisky Business #853 -- We're all gonna die, apparentlyOn this week’s show Patrick Gray and James Wilson are joined by former US Cyber Command executive director turned PwC’s Cyber, Data & Technology Risk leader Morgan Adamski to talk through the week’s news, including: More tech guys penned more open letters and AI will destroy …RISKY.BIZ
11 SepSnake Oilers: watchTowr, XBOW and CoreViewIn this edition of the Snake Oilers podcast three vendors stop by to pitch the audience on their products: watchTowr: We’re all familiar with watchTowr’s research, but what do they actually do? XBOW: The AI pentesting company pitches its approach CoreView: Your M365 tenant is pro…RISKY.BIZ
8 SepInside the Media Mind of Ken Underhill: eSecurity PlanetOn this episode of #IMM, Christine and Madison chat with Ken Underhill to learn more about his role and coverage at eSecurity PlanetTHECYBERWIRE.COM
7 SepThis call may be monitored.In this Special Episode, Maria Varmazis and Dave Bittner are joined by friend of the show, Brandon Karpf, to unpack a new bipartisan congressional investigation into the lingering presence of Chinese state-owned telecommunications companies inside U.S. internet infrastructu…THECYBERWIRE.COM
7 SepLoyalty points fraud is funding hacker holidays (Lock and Code S07E18)This week on the Lock and Code podcast, we speak with Kim Sutherland about loyalty points fraud and how everyday people can stay safe.MALWAREBYTES.COM
2 SepHow to Build a Marketing Strategy AI Cannot Commoditize with Brian Reed of CorshaBrian Reed has been a CMO six times. He's also watched AI flatten marketing for the past two years and has said so out loud, including in a manifesto he published called AI is Flattening Marketing: Cue the Return of Mad Men. On this CyberCMO Confidential episode, Brian, Gianna, a…THECYBERWIRE.COM
1 SepBetween Two Nerds: The perfect hackerIn this edition of Between Two Nerds Tom Uren and The Grugq talk about how AI is the perfect hacker, but what makes it perfect for states is the opposite of what makes it perfect for criminals. This episode is also available on YouTube.RISKY.BIZ
31 AugSponsored: Attackers need to be right more than onceIn this Risky Business sponsored interview, James Wilson chats with Dropzone AI’s founder and CEO Edward Wu to debunk the adage, “an attacker only has to be right once”. Modern intruders need to be successful across multiple steps before actually reaching an organisation’s “crown…RISKY.BIZ
26 AugSmashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrencyA hacker calling themselves "CYBERLEEK" has been leaking gameplay footage from GTA 6 ahead of its official reveal this week - but they're not asking Rockstar Games for a ransom. Instead, they've launched their own cryptocurrency, promising to release ever more juicy clips from a …GRAHAMCLULEY.COM
24 AugSponsored: Passkeys won’t stop authorisation phishingIn this Risky Business sponsored interview, James Wilson chats with Luke Jennings, Push Security’s VP of Research, about how stronger authentication is pushing attackers towards the authorisation layer. Device code phishing is on the rise. Luke explains how these attacks can surv…RISKY.BIZ
24 AugWhat happens to your data when you die? (Lock and Code S07E17)This week on the Lock and Code podcast, we speak with Tamara Kneese about the many ways your data remains long after your die.MALWAREBYTES.COM
19 AugSmashing Security podcast #481: Never say this to a robot dogAt Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a Pokemon. What followed involved a wall, a blue ice chest, and anyone in the room …GRAHAMCLULEY.COM
18 AugBetween Two Nerds: The eye of SauronIn this edition of Between Two Nerds Tom Uren and The Grugq discuss The Offense Death Cycle, a paper looking at how to take advantage of a defender’s ability to control a network to discover intruders. This episode is also available on YouTube.RISKY.BIZ
18 AugZero Trust Wasn't Built for AI Agents with Ev Kontsevoy from TeleportEv Kontsevoy, CEO of Teleport, joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices recorded at Black Hat USA 2026. He discusses why traditional Zero Trust principles need to evolve for autonomous AI agents, how agents can operate within their permiss…THECYBERWIRE.COMHTTPS:
17 AugWhen AI Sprawl Becomes a Security Problem with Nick Warner from NeoNick Warner, CEO of Neo, joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices recorded at Black Hat USA 2026. He discusses how the rapid adoption of AI tools and agentic software is reshaping enterprise security, why CISOs need greater visibility and …THECYBERWIRE.COMHTTPS:
14 AugSoap Box: Zero Trust(ish) NetworksIn this Soap Box edition of the Risky Business podcast host Patrick Gray chats with Adam Pointon, CEO of Knocknoc, about the failure of Zero Trust as a comprehensive architecture. Most networks look like they were designed in 1999, and most Zero Trust products look like they were…RISKY.BIZ
12 AugRisky Business #848 -- OpenAI comes cleanOn this week’s show Patrick Gray and James Wilson are joined by guest co-host Brad Arkin to talk through the week’s news, including: The AI-agent-hacks-stuff saga continues. This week we have one booting gymgoers from full classes to nab its owner a spot Somehow OpenAI’s legal te…RISKY.BIZ
12 AugSmashing Security podcast #480: This is the AI service you should never sign up toWould you like access to Anthropic's Claude at 90% off the normal price? All you have to do is redirect your traffic to a mysterious service called "Poison Claude". Only problem is that it's run by fraudsters... Meanwhile, a phishing-as-a-service platform called "Greatness" has c…GRAHAMCLULEY.COM
11 AugInside the Media Minds of Byron Tau: ProPublicaOn this episode of #IMM, Christine and Madison sit down with Byron Tau as he transitions from the Associated Press to ProPublica.THECYBERWIRE.COM
10 AugSponsored: Island's expansion to SASE and enterprise AIIn this Risky Business sponsored interview, Catalin Cimpanu talks with Michael Leland, Field CTO at Island, about the company’s seamless expansion into SASE and enterprise AI.RISKY.BIZ
10 AugHow to fake a data trail (and maybe lower prices) (Lock and Code S07E16)This week on the Lock and Code podcast, we speak with Chris Parr about his inventive and all-too-funny stress-test of surveillance pricing.MALWAREBYTES.COM
9 AugDesigning space systems for the AI era.As commercial space activity accelerates, satellite manufacturers are rethinking how spacecraft are designed, built, and secured. In this week's episode, host Maria Varmazis sits down with Jason Roberson, an Industry Value Expert for Aerospace & Defense at Dassault Systems, t…THECYBERWIRE.COM
4 AugBetween Two Nerds: Hackers vs the stateIn this edition of Between Two Nerds Tom Uren and The Grugq talk about whether hacker culture is inherently anti-authoritarian and how different states get their country’s hackers to work for the state. This episode is also available on YouTube.RISKY.BIZ
29 JulHugging Face Hack Lessons for Cyber DefendersDark Reading Confidential Episode 20: Expert Rich Mogull reflects on lessons cyber teams should pull from the OpenAI agent's attack on Hugging Face.DARKREADING.COM
28 JulBetween Two Nerds: Cyber is peopleIn this edition of Between Two Nerds Tom Uren and The Grugq discuss how important people are to cyber power and whether the rise of AI is changing that. This episode is also available on YouTube.RISKY.BIZ
28 JulInside the Media Mind of Bree Fowler: Special Black Hat Episode!On this episode of #IMM, Christine and Madison sit down with freelance journalist Bree Fowler to discuss all things Black Hat Conference.THECYBERWIRE.COM
27 JulWhat’s your data worth on the dark web? (Lock and Code S07E15)This week on the Lock and Code podcast, we discuss just exactly why it is that hackers and scammers want your data—and how you're at risk.MALWAREBYTES.COM
23 JulSrsly Risky Biz: Knives are out for open-weight AI modelsTom Uren and James Wilson talk about the future of open-weight models. For different reasons, both the Chinese and American governments have reasons to crack down on them. They also talk about arrests of several members of the Scattered Spider juvenile cybercrime collective. This…RISKY.BIZ
21 JulBetween Two Nerds: What China gets wrong about Russia's cyber war in UkraineIn this edition of Between Two Nerds Tom Uren and The Grugq discuss what mainland Chinese analysts think about Russia’s use of cyber operations in the war in Ukraine. This episode is also available on YouTube.RISKY.BIZ
20 JulSponsored: Thinkst on building companies that don’t suckIn this Risky Business sponsor interview Casey Ellis chats with Haroon Meer from Thinkst about building companies customers don’t hate. Haroon explains why Thinkst still offers Canary tokens for free and why it has avoided annual price hikes on its paid products. They talk about …RISKY.BIZ
19 JulEurope's push for space sovereignty.As space becomes an increasingly critical part of modern infrastructure, governments are reevaluating decades of policy to ensure reliable, secure, and independent access to the systems they are increasingly relying on. In this week’s episode, host Maria Varmazis sits down with p…THECYBERWIRE.COM
16 JulSmashing Security podcast #476: Remote-control rickshaws and rogue book marketersAn app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks - no login, no passwords, no permissions needed. Meanwhile, Geoff - swimming in money and Lamborghinis, as all published authors are - has been on the receiving end of a s…GRAHAMCLULEY.COM
13 JulTrusting your kids online isn’t enough (Lock and Code S07E14)This week on the Lock and Code podcast, we speak with Anna Brading about what actually works in keeping her kids safe online.MALWAREBYTES.COM
12 JulPreparing space for Q-day.As the world prepares itself for quantum computing, governments and private space enterprises alike are looking to get ahead of the technology and manage the rapidly-accelerating risks. In this week’s episode, host Maria Varmazis sits down with Eddy Zervigon, CEO of Quantum XC…THECYBERWIRE.COM
10 JulSponsored: Why Sublime doesn’t toss AI at every emailIn this Risky Business sponsored interview, Tom Uren chats with Sublime Security Product Manager AJ Williams about how the company targets its AI use. Rather than throwing its AI agents at everything, Sublime gives them the time-consuming email security tasks that humans don’t wa…RISKY.BIZ
9 JulSrsly Risky Biz: US Supreme Court undermines Section 702 intelTom Uren and James Wilson talk about a new US Supreme Court decision that puts the current EU-US data sharing agreement at risk. American intelligence collection efforts have been at the centre of legal challenges of these on-again off-again data transfer agreements, and if the c…RISKY.BIZ
8 JulSoap Box: Using threat hunting to drive detectionIn this wholly sponsored Soap Box edition of the podcast Patrick Gray chats with Damien Lewke, the CEO and founder of Nebulock, about the future of threat hunting and detection. Damien spent a decade in the EDR and MDR space before founding Nebulock in 2024. It started off as an …RISKY.BIZ
7 JulBetween Two Nerds: Why AI has not meant more hacks. Yet.In this edition of Between Two Nerds Tom Uren and The Grugq talk about why we haven’t seen an explosion of devastating hacks even though AI has been used to discover lots and lots of bugs. This episode is also available on YouTube.RISKY.BIZ
5 JulCommercializing space.Over the past two decades, the space industry has changed dramatically, evolving from a largely government led effort to one that is now rooted in private enterprises driving growth and innovation. In this week’s episode, host Maria Varmazis sits down with Damian DiPippa, CEO …THECYBERWIRE.COM
1 JulSmashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack?Polymarket has built an entire business on predicting the future. So how did it manage to spectacularly fail to predict its own hack? Plus, the Google engineer with a million-dollar secret, and the curious case of the airport hairdryer. Meanwhile, "FortiBleed" sees 75,000 Fortine…GRAHAMCLULEY.COM
30 JunBetween Two Nerds: Set cyberspace ablazeIn this edition of Between Two Nerds, Tom Uren and The Grugq discuss whether cyber organisations should actually be separated from Signals Intelligence organisations. The Grugq argues that having cyber expertise subordinate to intelligence collection means that many opportunities…RISKY.BIZ
29 JunThis pay gap is programmed (Lock and Code S07E13)This week on the Lock and Code podcast, we speak with Veena Dubal about algorithmic wage discrimination and its appetite for all worker data.MALWAREBYTES.COM
28 JunUniting Women in Cyber Podcast: Breaking Barriers in Cybersecurity with Cybersecurity Girl.In this Special Edition episode, N2K CyberWire's Dave Bittner sits down with Caitlin Sarian, widely known as Cybersecurity Girl, to explore how storytelling, authenticity, and community are reshaping a more human-centered cybersecurity landscape.THECYBERWIRE.COM
📡 INFOSEC NEWS 1241[+]
23 SepWeekly Threat Bulletin – September 23rd, 2026These are the top threats you should know about this week.F5.COM
23 SepCreator Campaigns, LinkedIn Strategy, and RIP to the Funnel with CrowdStrike, LinkedIn, and Sandra LiuGianna sits down with Vab Dwivedi, VP of Digital Experience at CrowdStrike, Sandra Liu, a cybersecurity creator with over 200,000 LinkedIn followers, and Eric Becker, Enterprise Account Director at LinkedIn. They covered the CrowdStrike and Sandra Liu creator campaign, why Linked…THECYBERWIRE.COM
23 SepRisky Bulletin: Team Cymru unmasks shady Chinese proxy networkA network of 10,000 AI servers is masking malicious Chinese AI activity, Ukrainian hackers leak Russia’s naval secrets, ShinyHunters hacks the FBI, and the EvilTokens phishing service is disrupted by tech companies.RISKY.BIZ
23 SepNew cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server ControlA flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22. A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allo…THEHACKERNEWS.COM
23 Sep545 Hackers Tested It First. Now XRanges for AI Scores Your Security AgentAutonomous security agents are getting good at finding bugs. Nobody has a good way to measure how good. Point one at a realistic target and what comes back is a report the agent wrote about itself: confident prose, a list of findings, and no way to tell which of them happened. So…THEHACKERNEWS.COM
23 SepAnthropic and OpenAI Models Still Attempt Restricted Actions in Safety TestsAnthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) companies noting that they are continuing to invest in improving alignment to combat risky behavior. Opus 5.5, per Anthropic, is a "major step up from Opus 5," and "achieves the best scor…THEHACKERNEWS.COM
23 SepLinkedIn adds new tools to fight fake profiles and bogus work historiesLinkedIn is rolling out new verification tools that let members vouch for colleagues’ work experience and give companies more control over accounts that falsely claim to employ them.TECHCRUNCH.COM
23 SepFake Claude Max giveaway hides a Google account phishing trapA convincing offer of a free Claude Max subscription uses a fake browser window to steal Google login information.MALWAREBYTES.COM
23 SepOAuth Token Theft Through Microsoft's Front Door | HuntressA sideloaded package turns a Microsoft-signed binary into an OAuth token theft tool. No phishing domain, no spoofed UI, no browser. Here's how to detect it.HUNTRESS.COM
23 SepHundreds of Leaked GitHub App Keys Still AuthenticateGitGuardian finds 474 leaked GitHub App keys still authenticating, including keys with admin accessINFOSECURITY-MAGAZINE.COM
23 SepA Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as YouThe private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you. GitLab shows each user this addre…THEHACKERNEWS.COM
23 SepWhat’s next for cybersecurity, according to Index Ventures’ Shardul ShahAs concern over AI safety and rogue agents continue to make headlines, it’s no surprise that cybersecurity stocks are rising, or that investors are pouring massive amounts of capital into startups trying to build the next generation of security for an AI-native world. We’re&…TECHCRUNCH.COM
23 SepHow device code phishing gives scammers access to your accountA scammer asks you to enter a code to open a file or join a meeting. Approving it could sign them in to your account instead.MALWAREBYTES.COM
23 SepCyera has secured a $400 million Series G extension from Goldman Sachs.A-LIGN has acquired Australian cloud security assessment firm AssurePoint.THECYBERWIRE.COM
23 SepUK regulator to investigate Pornhub parent company for alleged age verification failingsIn May, Pornhub began using a new age assurance process to verify some users’ ages, according to an Ofcom press release. The new method relies on signals from Apple that suggest under 18s in the UK “may have completed Apple’s age checks,” the press release said.THERECORD.MEDIA
23 SepEDR Evasion Stack Helps Process Injection Slip Past DefensesA process parameter-poisoning technique evades EDR by injecting code into process initialization structures without using the Windows APIs that EDR tools typically watch out for.DARKREADING.COM
22 SepHow to Use AI With Your Privacy IntactYour conversations with AI chatbots are both highly personal and deeply vulnerable to surveillance. Here’s how you can protect yourself.WIRED.COM
22 SepAI Drives Surge in Bot and API ThreatsAkamai report warns of increase in bot traffic, API threats, chatbot leaks and other AI-related threatsINFOSECURITY-MAGAZINE.COM
22 SepNetwork Segmentation Failures Are Expanding the Corporate Attack SurfaceForescout warns that incomplete network segmentation is widening the potential blast radius of attacksINFOSECURITY-MAGAZINE.COM
22 SepMore Than a Third of Industrial Orgs See Cybersecurity Risk as a Top Obstacle to Growth, Study FindsIndustrial companies are increasing cybersecurity investment as connected operations, AI adoption, and IT/OT convergence expand operational risk.DARKREADING.COM
22 SepGrowing the WIN AI Ecosystem with Agent IntegrationsWINning AI with AI: How the Wiz MCP for WIN partners accelerates a connected ecosystemWIZ.IO
22 Sep2026 State of PQC on the WebExplore F5 Labs’ 2026 PQC report: adoption trends, CDN dependence, TLS technical debt, certificate risks, and steps toward quantum resilience.F5.COM
22 SepSome cheap smart glasses are a security disasterTests found that some cheap smart glasses can be hijacked over Bluetooth, exposing their owners’ photos, videos, and personal data.MALWAREBYTES.COM
22 SepMicrosoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox CompromisesMicrosoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out with authorization from the U.S. District Court for the Eastern District of Virgi…THEHACKERNEWS.COM
22 SepReducing shadow IT visibility gaps with WazuhShadow IT can leave security teams unaware of unmanaged endpoints, unauthorized software, and other assets that fall outside existing monitoring. Wazuh explains how endpoint inventory, agentless monitoring, and centralized analysis can help organizations identify and reduce these…BLEEPINGCOMPUTER.COM
22 SepWordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some ServersWordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On some servers, that can go further, allowing the attacker to run their own code. The fix shipped on September 22 in WordPre…THEHACKERNEWS.COM
22 SepCanadian regulator opens probe of IDScan for allegedly violating data privacy lawsThe investigation, announced Monday, will probe IDScan’s security practices and whether victim notifications were adequate under Canada’s federal private-sector privacy law, the regulator said in a press release.THERECORD.MEDIA
22 SepMicrosoft Disrupts EvilTokens Device Code Phishing ServiceMicrosoft seized 50 websites and disabled more than 150 domains as part of a coordinated disruption effort against a phishing-as-a-service platform targeting Microsoft 365 accounts.DARKREADING.COM
22 SepRogue external MFA providers can steal passwords during loginsSecurity researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider that steals users' passwords during legitimate login attempts. [...]BLEEPINGCOMPUTER.COM
22 SepRelays Are Masking Chinese Access to Frontier AI Models in the USMore than 80,000 AI relay servers are helping users in China mask their identities while they access cutting-edge large language models (LLMs), probably to clone them.DARKREADING.COM
21 SepUK Police Data Faces Long-Standing Microsoft Cloud Security ConcernsA 2017 UK assessment warned that police data on Microsoft Azure could face foreign access risks. The risks may still exist. A Guardian investigation has surfaced a 2017 document signed off by then City of London police commissioner Ian Dyson, who also held the title of senior inf…SECURITYAFFAIRS.COM
21 SepSecurity’s 30-year habit: layering around the problemThe nurse isn't careless. Every safe path is slower than Outlook.CYBERSECURITYDIVE.COM
21 SepThe Target Is No Longer the Model. It’s the Agent.AI agents are becoming the new attack surface, exposed to poisoned skills, prompt injection, jailbreaks and attacks through connected tools. I read the AI security research published in a single month, February 2026, and when you put it all together, it’s not a list of curiositie…SECURITYAFFAIRS.COM
21 SepLinkedIn wins court order blocking mass scraping of user dataThe agreement between LinkedIn, ProAPIs and joint business operator Netswift also requires the firms to stop selling and transferring the data, no longer access LinkedIn through fake accounts and delete the data that was scraped, according to a senior LinkedIn executive.THERECORD.MEDIA
21 SepMicrosoft reminds admins to migrate Entra ID users to passkeysMicrosoft has reminded admins to migrate Entra ID users to phishing-resistant authentication methods to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027. [...]BLEEPINGCOMPUTER.COM
21 SepGoogle Hit with €403m GDPR Fine Over Location Data PracticesThe Irish DPC found that Google users were unaware that their location was being used to influence them with adsINFOSECURITY-MAGAZINE.COM
21 SepNew Exvicy ClickFix Framework Built on Rival ErrTraffic's CodeSekoia said Exvicy, a new ClickFix MaaS framework, reused code from rival service ErrTrafficINFOSECURITY-MAGAZINE.COM
21 SepGoogle fined €403 million over location data privacy violationsIreland's Data Protection Commission (DPC) has fined Google €403 million ($463M) for multiple GDPR violations related to processing users' location data. [...]BLEEPINGCOMPUTER.COM
21 SepThe fake sites using a cheap toolkit to sell $2,000 AI subscriptionsMore than 100 linked sites use a $249 toolkit to turn copied product names and unfamiliar AI brands into paid subscriptions.MALWAREBYTES.COM
21 SepMicrosoft to retire Microsoft 365 Companion apps in DecemberMicrosoft will retire the Calendar, People, and Files Microsoft 365 companion apps on December 16 and has asked admins to remove them from managed devices. [...]BLEEPINGCOMPUTER.COM
21 SepFake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDRA fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17. Microso…THEHACKERNEWS.COM
21 SepGoogle Fined €403 Million Over GDPR Violations Tied to Location DataGoogle has been fined €403 million for breaking the EU's data protection law, the GDPR, in the way three of its features handled people's location data from May 2018 to February 2020. Ireland's Data Protection Commission (DPC), Google's lead regulator in the EU, also or…THEHACKERNEWS.COM
21 SepForeign Hackers Target Two Colorado Water UtilitiesHackers targeted two Colorado water utilities, changing OT settings and disabling alarms, but causing no impact on water services or safety. Foreign hackers targeted the operational technology (OT) systems of two small private water utilities in Colorado in late August, apparentl…SECURITYAFFAIRS.COM
21 SepEU data regulator fines Google more than $460 million for location data violationsIreland’s Data Protection Commission will fine Google more than €403 million ($462 million) over the tech giant’s processing of location data, concluding an inquiry into the company that began in early 2020.THERECORD.MEDIA
21 SepHow AI Agents Can Trigger Runaway Costs for EnterprisesUnbounded consumption is an issue that OWASP currently ranks sixth in its Top 10 for LLM Applications, and it could be an extremely costly one.DARKREADING.COM
21 SepGoogle Fined €403 Million Over Location Data PracticesIreland’s DPC fined Google €403 million over GDPR violations involving location data, transparency, retention and user control. Ireland’s Data Protection Commission (DPC) just fined Google €403 million, and the case behind it goes back six years, to a set of complaints that…SECURITYAFFAIRS.COM
20 SepSecurity Affairs newsletter Round 595 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Google Gemini also Broke Out of I…SECURITYAFFAIRS.COM
20 SepResearchers escape OpenAI Codex sandbox to run commands on hostResearchers escaped OpenAI's Codex sandbox two ways, one running commands on a developer's machine from its most locked-down mode. OpenAI has patched both. [...]BLEEPINGCOMPUTER.COM
19 SepGoogle’s Gemini is the latest AI model to hack other companiesGoogle said Gemini had "acted appropriately" by ending each hack immediately.TECHCRUNCH.COM
19 Sep6 Best VPN Services (2026), Tested and ReviewedEvery VPN says it’s the best, but only some of them are telling the truth.WIRED.COM
19 SepFlock Offers Employees Buyouts as Customers FleeAs dozens of cities end contracts for its controversial license plate readers, Flock is rolling out a voluntary severance program, WIRED has learned.WIRED.COM
19 SepViral AI actress' hotline face-scans every caller, watches their moodAI actress Tilly Norwood went viral after glitching into Chinese on Piers Morgan Uncensored last night. Her "Talking Tilly" video call service face-scans every caller for an 18+ age check, senses callers' moods during calls, and shuts down permanently on September 27. We tried it…BLEEPINGCOMPUTER.COM
18 SepMicrosoft fixes bug behind ‘Defender Antivirus is turned off’ alertsMicrosoft has resolved a known issue that causes incorrect alerts warning that Defender Antivirus was turned off after installing recent updates. [...]BLEEPINGCOMPUTER.COM
18 SepAn Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.In July 2025, someone registered a domain that used to belong to a content delivery network. The CDN had been wound down years earlier, and the domain it served assets from was allowed to expire. What it had not lost were its callers. Thousands of websites, code repositorie…THEHACKERNEWS.COM
18 SepPlugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding AgentsA flaw in four widely used AI coding agents lets someone who controls a plugin's code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security said on Thursday. The fir…THEHACKERNEWS.COM
18 SepMeta’s Copyright System Is Being Weaponized Against Albanian ProtestersAfter three months of daily anti-government protests—dubbed the Flamingo Revolution—the sudden mass suspension of Instagram accounts has led to fears of brigading against demonstrators.WIRED.COM
18 SepDid an AI really try to break free from human control?An unreleased OpenAI model wrote instructions telling itself to ignore developer controls. Here’s what actually happened.MALWAREBYTES.COM
18 SepSecure enterprise sharing with access reviews for Microsoft 365Microsoft 365 makes sharing files easy, but access can remain long after its original purpose has ended, leaving organizations with little visibility into who can still reach sensitive data. tenfold Software explains how centralized access governance and owner-driven reviews can …BLEEPINGCOMPUTER.COM
18 SepMFA Won't Save You From OAuth Consent AbuseMFA is essential, but it cannot replace OAuth governance, least-privilege scopes, consent monitoring, and rapid revocation.DARKREADING.COM
18 SepVectra AI Launches Ascent to Help Address New Era of AI-Driven AttacksThe new program expands Vectra AI's partner strategy as increasingly complex security environments and the growing use of AI create demand for broader AI expertise, services, and security outcomes.DARKREADING.COM
17 SepFlock Once Touted Its Cameras as ‘Made in the USA.’ Now It’s Not So ClearFlock reveals little about where its license plate readers are assembled, but the answer could have geopolitical and cybersecurity implications.WIRED.COM
17 SepT-Mobile rewards points expiry texts are a phishing scamA large phishing campaign is using fake T-Mobile rewards points and looming expiry dates to pressure recipients into clicking malicious links.MALWAREBYTES.COM
17 Sep12 celebrity deepfake websites seized by Manhattan DAThe largest known celebrity deepfake seizure has taken 12 websites offline, disrupting access to videos depicting some 1,200 people.MALWAREBYTES.COM
17 SepUS takes down NightmareStresser DDoS-for-hire platformThe U.S. Federal Bureau of Investigation (FBI) seized the domains used by NightmareStresser, one of the world's longest-running distributed denial-of-service (DDoS) platforms. [...]BLEEPINGCOMPUTER.COM
17 SepIsraeli contractor BlackCore trained Angolan officials in online influence operationsAn Israeli influence-for-hire company trained Angolan government officials to run online influence operations, including by creating fake social media personas and media outlets, researchers found.THERECORD.MEDIA
17 SepCyber Essentials Has Record Year but Takeup Remains LowNew government figures reveal a 20% annual increase in certificationsINFOSECURITY-MAGAZINE.COM
17 SepNightmareStresser Goes Offline in Global DDoS-for-Hire CrackdownThe DOJ seized domains behind NightmareStresser, a DDoS-for-hire service tied to hundreds of thousands of attacks since 2022, as part of Operation PowerOFF. Renting a DDoS attack used to be as easy as renting a movie. Pick a target, pay a few dollars, watch the site go dark. The …SECURITYAFFAIRS.COM
17 SepWindows 11 24H2 Home and Pro reach end of support in OctoberMicrosoft reminded customers this week that devices running Windows 11 24H2 Home and Pro editions will stop receiving updates next month. [...]BLEEPINGCOMPUTER.COM
17 SepManufacturers make patching progress, but identity management still major weaknessMisconfigurations remain widespread in the manufacturing sector, including internet-accessible remote-access software, a new report found.CYBERSECURITYDIVE.COM
17 SepWhat Recent AI-Powered Attacks Mean for Your Identity SecurityAI is making credential theft faster and easier to scale, giving attackers more opportunities to abuse valid identities. Specops explains why identity security must go beyond successful authentication by verifying that both the user and the device requesting access can be trusted…BLEEPINGCOMPUTER.COM
17 SepBuilding an AI Detection Engine That Understands Agent IntentAnalyzing model input and output logs in an AI-native detection pipeline to understand and uncover malicious AI agent behaviorWIZ.IO
17 SepFlock cameras are tracking people as well as carsTwo reports reveal how Flock’s license plate camera network tracks people’s movements while oversight continues to lag.MALWAREBYTES.COM
17 SepOpenAI details more cases of AI agents taking unauthorized actionsOpenAI has presented new examples of what they call "AI model misalignment" from the past six months, including unauthorized file uploads, following self-generated instructions, hiding mistakes, and leveraging exposed API keys. [...]BLEEPINGCOMPUTER.COM
17 SepEuropean Commission set to push social media restrictions, safety requirements into lawThe proposal, known as the EU KIDS Act, would block social media platforms from offering accounts to children younger than 13 and establish a bloc-wide minimum age of 15 for account creation.THERECORD.MEDIA
17 SepRun open weight models on Amazon Bedrock in AWS European Sovereign CloudEuropean organizations can run AI workloads on Amazon Web Services (AWS) while keeping data within the European Union (EU) and meeting regulatory requirements. You can now run generative AI workloads on open weight models on Amazon Bedrock in the AWS European Sovereign Cloud. We’…AWS.AMAZON.COM
17 SepOpenAI admits its models lie to cover their own mistakesOpenAI launches a formal framework to disclose model misalignment, publishing six reports on models that lied, faked data, or bypassed rules. Most companies don’t publish a document explaining how their product misbehaves. OpenAI just did. On September 16, it released a for…SECURITYAFFAIRS.COM
16 SepWeekly Threat Bulletin – September 16th, 2026These are the top threats you should know about this week.F5.COM
16 SepOne Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and ClaudeSecurity researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and the Claude in Chrome extensio…THEHACKERNEWS.COM
16 SepParallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install FixParallels Desktop for Mac has a flaw that lets an ordinary local account run code as root, the highest level of access on a Mac, software company JFrog said this week. The attack needs code already running on the machine as a normal user, so it does not work over the network. JFr…THEHACKERNEWS.COM
16 SepSecuring the unpatchable in an age of AI-driven vulnerabilitiesAdvances in AI technology will continue to identify vulnerabilities that in some circumstances are difficult, or effectively impossible, to patch. Appropriate network segmentation, rigorous visibility, and the deployment of NGFW/IPS combinations can provide a powerful compensator…TALOSINTELLIGENCE.COM
16 SepAgents at Large | Tracing Illicit OpenAI Agent Activity on Hugging FaceTwo Hugging Face accounts reveal that OpenAI's agents staged relay code, internal probes and ChatGPT account registration beyond the published timeline.SENTINELONE.COM
16 SepAI helps scammers build convincing antivirus renewal pagesA fake Avast renewal page shows how AI is helping scammers create more convincing traps with polished designs and fluent copy.MALWAREBYTES.COM
16 SepWhat CEOs Actually Think When They Watch CMOs Operate with David PolitisWhen David Politis sits down with Gianna and Charles on CyberCMO Confidential, you’re getting something rare: A CEO who loves marketing telling you exactly what he thinks when he watches CMOs operate. Why the CRO wins if you let them, why he stops listening the moment someone say…THECYBERWIRE.COM
16 SepThree Ukrainians to face charges for alleged hack of 610,000 Roblox accountsThree Ukrainians are set to stand trial for allegedly stealing access to more than 610,000 Roblox accounts and selling them to buyers in Russia, authorities said.THERECORD.MEDIA
16 SepFlock camera use by internal affairs unit puts DC police at odds with officers’ unionWashington, D.C.'s police department has used information from Flock cameras for misconduct investigations, prompting a formal complaint from its officers' union.THERECORD.MEDIA
16 SepUkraine moves to crack down on scam call centers after corruption scandalUkraine’s parliament has approved tougher criminal penalties for involvement in fraudulent call centers and the theft of personal data, following a corruption scandal in which prosecutors were accused of taking bribes to protect scam operations.THERECORD.MEDIA
16 SepMicrosoft says Copilot buttons still missing in classic OutlookMicrosoft says it's still investigating a known issue that causes the Copilot and Copilot Chat buttons in Classic Outlook to disappear for some Windows users. [...]BLEEPINGCOMPUTER.COM
16 SepWindows Server 2022 reaches end of mainstream support next monthMicrosoft has reminded customers that Windows Server 2022 will reach the end of mainstream support next month and enter extended support until October 2031. [...]BLEEPINGCOMPUTER.COM
16 SepScans Targeting Hospitality Applications, (Wed, Sep 16th)Earlier today, I noted an odd request showing up in our "First Seen" report:
ISC.SANS.EDU
16 SepFighting Your Dragons Through Tough Tech TimesCybersecurity industry veteran Hal Pomeranz gives a pep talk on career anxiety and self-doubt and shares how to build meaningful connections during historical tech industry downturns.DARKREADING.COM
16 SepPhysical AI security company Exein lands $270 million.Scottish MSSP Quorum Cyber has agreed to acquire Swiss agentic SOC provider Ontinue.THECYBERWIRE.COM
16 SepArchitecting a secure landing zone in the AWS European Sovereign CloudThe AWS European Sovereign Cloud is a new, independent cloud for Europe, physically and logically separate from existing AWS Regions and operated within the European Union (EU). It provides the same services, features, and APIs as AWS commercial Regions, but runs as a distinct AW…AWS.AMAZON.COM
16 SepAI Security Spending Jumps as Fear Outpaces Proof of ValueCISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?DARKREADING.COM
16 SepAnthropic wants Claude to analyze your bank account and financial dataAnthropic is testing a new personal finance feature called "Claude Money" that will allow you to connect your bank accounts directly to Claude and "understand your money." [...]BLEEPINGCOMPUTER.COM
15 SepFormer AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man44-year-old Kenneth Carter from Portland, Oregon, used to work in an AT&T retail store. But now he has been sentenced to 16 months in a federal prison. That should be plenty of time for him to rue the day he agreed to increase his monthly income by helping a SIM swap gang in…BITDEFENDER.COM
15 SepSearch results are sending people to fake Bitrefill checkoutsFake Bitrefill checkout pages are appearing in search results and tricking people into sending cryptocurrency directly to scammers.MALWAREBYTES.COM
15 SepSuspected Black Axe gang leaders face cybercrime charges in the USFive alleged leaders of the Black Axe cybercrime syndicate, known for its involvement in global-scale cyber-enabled financial fraud, have been extradited to the United States to face wire fraud and money laundering charges. [...]BLEEPINGCOMPUTER.COM
15 SepMeta AI builds detailed profiles of children from years of family postsA mother says Meta AI pieced together names, birth details, photos, and location information about her young daughters from years of family posts.MALWAREBYTES.COM
15 SepA House Divided: The CIA, State, and a Coup in South VietnamIt's a dark moment in American history that leads to a lot of what-ifs. By the spring of 1963, eight years into the Vietnam War, two opposing factions across the CIA and the State Department had President John F. Kennedy's ear. One side wanted to keep South Vietnam's first presid…THECYBERWIRE.COM
15 SepAttack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the PointIntroduction Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the phishing simulation? Does this SIEM rule fire on this particular technique? And, in more mature organizations, this test…THEHACKERNEWS.COM
15 SepMacOS 27 - First Boot, (Tue, Sep 15th)I have not done this type of diary in a while: What traffic will you see from a system on boot, before a user logs in? I just took a quick look at macOS 27 "Golden Gate" to see what traffic you should expect. Here are some of the highlights:
ISC.SANS.EDU
15 SepUS military says it has launched weapons into spaceThis is the first public acknowledgment that the U.S. military put a space weapon in Earth's orbit.TECHCRUNCH.COM
15 SepNew Italian unicorn Exein rides the physical AI waveItalian startup Exein has raised a $270 million round of funding led by Headline at a $1.7 billion valuation.TECHCRUNCH.COM
15 SepHave it both ways: stay discoverable in search while disallowing AI trainingCloudflare is giving site owners a way to stay discoverable while disallowing AI training. New controls and an Accountable designation establish a shared model with Apple, Google, and Microsoft.CLOUDFLARE.COM
15 SepGive every teammate and agent the right level of access to your WorkersYou can now scope access to individual Workers and assign narrower Developer Platform roles, so teammates, CI tokens, and agents get only the access they need to debug, deploy, or monitor safely.CLOUDFLARE.COM
15 SepAWS STS simplifies session token size limits and adds session token size monitoringAWS Security Token Service (AWS STS) has simplified session token size limits, giving you more room for your session policies and session tags. STS has replaced the packed policy size and the overall session token size limits with a single token size limit of 4,096 bytes. STS now…AWS.AMAZON.COM
15 SepArchitecting resilient authentication with Amazon Cognito multi-Region replicationYour consumer identity and access management (CIAM) system is the foundation of your customer experience. It’s how users sign in, access services, and engage with your applications. As your business scales across geographies, ensuring authentication is always available becomes a …AWS.AMAZON.COM
15 SepOperationalizing least privilege: Automate IAM remediation through your CI/CD pipelineThe principle of least privilege is straightforward to articulate but challenging to maintain at scale. When teams first deploy applications to AWS, they often grant broader permissions than strictly necessary; it’s faster to get things working, and the plan is always to tighten …AWS.AMAZON.COM
15 SepHow to opt out of AI chatbot trainingChatGPT contractors are reviewing real users' conversations. Here’s how to stop AI companies using your chats for model training.MALWAREBYTES.COM
15 SepMost Fraudulent Hires Receive Credentials Before DetectionA new report highlights the vast growth in fraudulent candidates, presenting significant insider threat challenges to organizationsINFOSECURITY-MAGAZINE.COM
15 SepBlack Axe Members Extradited to US Over Internet Fraud ClaimsAlleged Black Axe leaders extradited to the US over romance scams, BEC and money laundering claimsINFOSECURITY-MAGAZINE.COM
15 SepAI the Top Priority for New Spend as Cyber Budgets FlatlineIANS finds AI is dominating net-new budgets even as overall funding for the function is flatINFOSECURITY-MAGAZINE.COM
15 SepOperational Resilience: IT Security Risks with Reduced Staffing | HuntressReduced staffing during holidays changes more than headcount. Learn how operational resilience should shape your IT and security change decisionsHUNTRESS.COM
15 SepInvesting Together: Wiz Defend and Google Security OperationsContinuing to deepen the integration between Wiz Defend and Google Security Operations, helping teams work faster wherever they choose to investigateWIZ.IO
14 SepAnthropic CEO Calls for an AI Slowdown. Is It Possible?Anthropic CEO calls for AI slowdown, proposes embedded evaluators and global coordination. Geopolitical competition with China makes a voluntary pause structurally fragile. Dario Amodei published “We Must Pace the Frontier“, calling on the AI industry, governments, an…SECURITYAFFAIRS.COM
14 SepMalicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 UsersA malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. The extension, named "Twitch Enhanced Viewer | JeetBot," lists HISHIMIRO/jeetbot.cc as its developer and has…THEHACKERNEWS.COM
14 SepZero trust is the future. But enterprises still need their VPNs.Zero trust shouldn’t mean sacrificing the stability and flexibility enterprises still depend on.CYBERSECURITYDIVE.COM
14 SepOpenAI Agent Swarm Hacks RubyGems Package ManagerResearchers confirm that OpenAI agents uploaded hundreds of malicious packages to RubyGemsINFOSECURITY-MAGAZINE.COM
14 SepRevolut gave customer IDs and financial data to a government impostorThe digital bank was tricked into releasing sensitive customer information, including IDs, to an attacker using a legitimate government email domain.MALWAREBYTES.COM
14 SepSexually Explicit Deepfake Sites Target 100-Plus Politicians in EuropeAn analysis of 160 deepfake websites reveals politicians in 22 countries appear on them. Nearly all of them are women.WIRED.COM
14 SepRevolut handed customer data to fraudsters using government email accountBritish fintech Revolut confirmed disclosing sensitive customer data to fraudsters who submitted emergency data requests from a legitimate government email account.THERECORD.MEDIA
14 SepDefense Cyber Spending Set to Surge Amid Rising Attacks on Military SystemsMarketsandMarkets has projected the cyber warfare market to double by 2031, amid growing demand for defensive and offensive cyber capabilities in the militaryINFOSECURITY-MAGAZINE.COM
14 SepGoogle’s new search redirects make links harder to check before you clickGoogle says its new opaque redirects tackle evolving abuse, but they also prevent users from checking a result’s destination by hovering over it.MALWAREBYTES.COM
14 SepMalicious Twitch Extension Exposes 31,000 Users' OAuth TokensSocket has discovered a Twitch browser extension forwarding users' OAuth tokens to a Russian bot serviceINFOSECURITY-MAGAZINE.COM
14 SepWhy Patch Automation Needs Brakes, Not Just an AcceleratorPatch automation can help IT teams keep pace with growing update volumes, but deploying faster also means bad updates can spread faster. Action1 explains how update rings, predefined success criteria, and human oversight can make automated patching faster without sacrificing cont…BLEEPINGCOMPUTER.COM
14 SepWordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before DistributionWordPress has announced it's launching an automated security review for every release of a plugin before it's distributed through the WordPress.org update API so as to analyze it for potential security issues and ensure there are no risks involved. "New plugins are reviewed befor…THEHACKERNEWS.COM
14 SepAnthropic CEO calls for slower pacing of AI development.Researchers attribute RubyGems attack to OpenAI swarm. NSA to undergo restructuring to better focus on AI, China, and cybersecurity.THECYBERWIRE.COM
14 SepHundreds of fake government websites target users in Central AsiaThe sites are designed to collect victims’ contact details, which scammers then use to target them through phone or email to steal money, personal information or gain access to their devices.THERECORD.MEDIA
14 SepNew York Seizes a Dozen Celebrity Deepfake WebsitesIn the biggest-ever legal action against harmful deepfake websites, the Manhattan District Attorney’s Office has seized 12 sites that collectively targeted around 1,200 victims.WIRED.COM
14 SepHackers target exposed Vite dev servers to steal AWS, Azure secretsA mass-scanning campaign targeting internet-exposed Vite development servers is attempting to steal cloud credentials and configurations from AWS and Azure deployments. [...]BLEEPINGCOMPUTER.COM
14 SepAnthropic CEO: Time to Shift From Improving to Controlling AIDario Amodei says it's time to slow the pace of frontier AI improvements so that security and risk prevention efforts can catch up. What does this mean for enterprises?DARKREADING.COM
14 SepApple Updates Everything, (Mon, Sep 14th)Today, Apple released its annual update across all its operating systems. With that, Apple not only released new features but also patched 261 different vulnerabilities. This is the most vulnerabilities Apple has ever patched, but the increase is not as significant as other vendo…ISC.SANS.EDU
14 SepClickFix attacks are tricking Mac and Windows users into hacking themselvesIf you clicked on a fake HBO Max ad on Reddit in the past week, you might have fallen victim to a rising "ClickFix" security threat.TECHCRUNCH.COM
14 SepChina Calls Amodei’s AI Proposal a New Cold War PlaybookChina rejects Amodei’s AI slowdown proposal, calling it fearmongering and a US attempt to contain China’s technology sector. The debate over whether the world should slow down the development of advanced AI has quickly turned into something bigger than a technology argument. Dari…SECURITYAFFAIRS.COM
14 SepMembers of ‘Black Axe’ cybercriminal group extradited from South AfricaProsecutors unsealed a 2021 indictment accusing the five men of conducting lucrative romance scams that stole thousands of dollars from more than 100 people.THERECORD.MEDIA
14 SepTwitch extension with 30K installs exposes users’ OAuth tokensA browser extension called Twitch Enhanced Viewer | JeetBot, available in the official Chrome and Firefox stores, sends users' Twitch OAuth session tokens to a commercial bot service. [...]BLEEPINGCOMPUTER.COM
13 SepThorough reorganization at NSA will create five 'mission centers,' including cyber and AIThe largest electronic spy agency in the world is reorganizing. And fast.THERECORD.MEDIA
12 SepWhen the Whole Company Adopts AI: What It Does to Your SOCOver the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents. Not attacks against AI, but the ordinary, everyday footprint of an organizatio…THEHACKERNEWS.COM
11 SepThe US and Mexico Announce They’re Teaming Up Against DronesThe new joint operation uses laser-based technology capable of detecting, tracking, and disabling commercial drones linked to human and drug trafficking.WIRED.COM
11 SepMost Organizations Skip Permissions Reviews Before Deploying AI ToolsA new Syskit study has shown that only 43% of organizations with AI agents deployed in Microsoft 365 environments completed a permission review before doing soINFOSECURITY-MAGAZINE.COM
11 SepHackers Favor US Eastern Business Hours in M365 Phishing CampaignKnowBe4 researchers observed a new phishing campaign leveraging Microsoft 365’s Direct Send to send malicious emailsINFOSECURITY-MAGAZINE.COM
11 SepAnthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation AttacksAnthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax. Knowledge distillation by itself is a legitimate training meth…THEHACKERNEWS.COM
11 SepAI Governance Can't WaitAdversaries can manipulate AI defensive reasoning to silently compromise target networks.DARKREADING.COM
11 SepCIS Benchmarks September 2026 UpdateThe following CIS Benchmarks were updated during the past month. Each Benchmark includes a full changelog detailing all modifications and enhancements.CISECURITY.ORG
11 SepWhy AI Is So Good at Scamming HumansFred Heiding of Menlo Park Intelligence talks with the Dark Reading News Desk about his research on frontier models, and their ability to influence human behavior and create emotional dependency.DARKREADING.COM
11 SepMeta Sued Over Training Data for Its AI and Face-Recognition SystemsThe proposed class action alleges Meta illegally harvested people’s Facebook and Instagram photos to train its AI image-generation models and to build its unreleased “NameTag” face recognition feature.WIRED.COM
10 SepAddressing the social media algorithms.This week, Dave and Ben look at how AI and social media are coming under greater regulatory scrutiny. For AI, conversations people are having with their chatbots are beginning to find their way into court cases while Australia looks to continue its crackdown on how social media p…THECYBERWIRE.COM
10 SepOFAC Sanctions Chinese Scam Platform Xinbi GuaranteeThe US Treasury has placed sanctions on notorious Chinese cybercrime marketplace Xinbi GuaranteeINFOSECURITY-MAGAZINE.COM
10 SepProofpoint Expands AI-Powered Investigations to Microsoft 365 and Deepens Insider Risk Visibility into AI ActivityPROOFPOINT.COM
10 SepCopyright scammers get Instagram accounts suspended and demand paymentScammers are filing fraudulent copyright complaints to suspend Instagram accounts, then demanding payment to withdraw them.MALWAREBYTES.COM
10 SepClearview AI Is Testing an AI Tool That Would Let Cops Unearth Your Life OnlineInquiryIQ, a previously unreported prototype, tested a model from xAI, maker of Grok, to surface associates, social accounts, and other information about people identified through Clearview.WIRED.COM
10 SepMicrosoft says September updates fix mouse settings reset issuesMicrosoft has fixed a known issue that wiped mouse settings on some Windows 11 systems after installing the KB5120998 August 2026 preview update. [...]BLEEPINGCOMPUTER.COM
10 SepWill AI kill us all within the next decade?AI researchers are warning that the technology could kill us all within the next decade, although they say the risk from current models is low.MALWAREBYTES.COM
10 Sep‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury carsHere's a tip for any budding cybercriminals out there. If you're going to steal a quarter of a billion dollars worth of cryptocurrency, maybe don't broadcast on a group chat every time you buy a Lamborghini, or blow half a million dollars on a single night out at a nightclub. Rea…BITDEFENDER.COM
10 SepGoogle Play Early Access Abused to Push Thousands of Deceptive Android AppsBad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. Early Access apps are apps that haven't been released on the official Android app marketplace. The main idea behind the prog…THEHACKERNEWS.COM
10 SepThe Top 4 Threats We Found by Investigating Every Alert for a QuarterIdentity was the target in roughly half of all confirmed malicious activity. Prophet Security breaks down the four main attack patterns seen across customer environments between May and July 2026, and explains why some attacks succeeded while others were blocked. [...]BLEEPINGCOMPUTER.COM
10 SepMore Capable AI, Not Enough GuardrailsAI agents are gaining real-world access faster than safeguards can mature, making permissions, isolation and oversight critical to prevent harmful actions. Jacob Coxon, a researcher who spent three years working on model training at OpenAI and later Anthropic, left Anthropic this…SECURITYAFFAIRS.COM
10 SepThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More StoriesA lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A p…THEHACKERNEWS.COM
10 SepCyber Command turns to veteran of intelligence agencies for top AI roleRonzelle Green, most recently a senior official at the National Geospatial-Intelligence Agency, will be U.S. Cyber Command's chief AI officer.THERECORD.MEDIA
10 SepTreasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023As the cyber scam industry expands globally, the U.S. government wants banks to share more information about what's happening to their customers.THERECORD.MEDIA
9 SepWeekly Threat Bulletin – September 9th, 2026These are the top threats you should know about this week.F5.COM
9 SepThe push to stop algorithms controlling social media feeds has begunAustralia is proposing a law that gives people a choice over what fills their feeds. It may not be long before other countries demand the same.MALWAREBYTES.COM
9 SepMan gets 15 years for extorting women with AI-generated porn videosAn Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims using AI-generated sexually explicit content. [...]BLEEPINGCOMPUTER.COM
9 SepAlby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin WalletsBitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet. Alby Hub is a self-hosted Lightning wallet, meaning the ow…THEHACKERNEWS.COM
9 SepU.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and GrokU.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through distillation attacks. The activity has been descr…THEHACKERNEWS.COM
9 SepGroup of bipartisan lawmakers ask US government to ban several hack-for-hire firmsThe three Indian companies are accused of using hackers to steal information used to sway litigation.TECHCRUNCH.COM
9 SepSequoia doubles down on Cymphony as AI agents create new enterprise security risksCymphony was valued at more than $100 million in a $25 million Series A co-led by Sequoia and SMBC Fin Atlas Beyond Fund.TECHCRUNCH.COM
9 SepNHIs Now the Number One Corporate Entry Point for HackersSpyCloud claims non-human identities are the most likely route into the enterpriseINFOSECURITY-MAGAZINE.COM
9 SepClickFix Moves into the Browser to Steal CryptocurrencyClickFix campaign uses browser-injected JavaScript and Google Sheets to steal cryptocurrencyINFOSECURITY-MAGAZINE.COM
9 SepMFA's Weakest Link: Account Recovery Is the New Attack PathMFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to preventing social engineering attacks from…BLEEPINGCOMPUTER.COM
9 Sep‘Gambling with our lives’: Anthropic researcher quits, warns against self-improving AIAnthropic researcher Jacob Coxon resigned over AI extinction fears, calling for pacing agreements between labs.TECHCRUNCH.COM
9 SepResearchers Build WeChat Zero-Click Worm Hijacking Phones via CallsThe hacking tool, built using a combination of AI models, is effective against Android and iOS devicesINFOSECURITY-MAGAZINE.COM
9 SepMore than 100,000 fake stores are out to steal your card detailsDoppelCart’s fake stores copy real retailers and steal shoppers’ card details and one-time bank confirmation codes.MALWAREBYTES.COM
9 SepFBI puts its cyber strategy on paperThe first public cybersecurity strategy issued by the FBI "directs our teams, our field offices, our global presence" to align their efforts on countering malicious hackers and cybercrime groups, senior official Brett Leatherman says.THERECORD.MEDIA
9 SepIdentity-Based AI Attack Threatens Security of Enterprise Data"Workflow identity hijacking" can bypass standard security controls and hijack an organization's data by sending a basic request through an unauthenticated entry point.DARKREADING.COM
9 SepYou Can Now Destroy Flock Cameras for Cash in GTA VA new GTA mod lets you smash and shoot Flock’s automatic license plate readers around the fictional Los Santos.WIRED.COM
9 SepUS says Chinese firms extracted billions of tokens from frontier AI modelsU.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted industrial-scale distillation attacks on American frontier AI models since at least late 2024. [...]BLEEPINGCOMPUTER.COM
9 SepGrindr settles privacy lawsuit tied to disclosure of users’ HIV statuses for $35 millionThe settlement concludes a legal fight that dates to April 2024, when UK users sued for the alleged violations of their country’s privacy laws.THERECORD.MEDIA
9 SepNVIDIA to acquire Hugging Face for $12.9 billion.Upwind has raised $300 million in Series C funding led by Bessemer Venture Partners and TCV.THECYBERWIRE.COM
9 SepUS disrupts Xinbi Guarantee marketplace fueling the cyber scam economyThe U.S. government also carried out a seizure of $52.8 million from 52 wallets connected to the platform.THERECORD.MEDIA
9 SepApple Doesn’t Want You to Worry About the New Apple Watch’s Listening FeaturesThe new Apple Watch includes several “intelligent” listening features that have privacy and security baked in. But the protections can’t change the facts of what the tools do.WIRED.COM
9 SepUS Government Accuses Chinese AI Firms of Distilling Frontier ModelsUS agencies claim Chinese companies covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and SpaceX's Grok to reduce development costs.DARKREADING.COM
9 SepSan Francisco Orders Meta to Stop ‘Allowing’ AI Child Abuse AdsThe City Attorney’s Office has asked Meta to explain how the harmful ads repeatedly ran on Facebook and Instagram. The company claims the ads are not under the city’s jurisdiction.WIRED.COM
8 SepGrindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data SharingOnline dating app Grindr has opted to pay £26 million ($35.1 million) to settle a lawsuit in the U.K. over allegations that it shared users' personal information, including their HIV status, with third-parties. Grindr, which is the largest LGBTQ+ dating app, was sued in April 202…THEHACKERNEWS.COM
8 SepProofpoint Strengthens Executive Leadership Team with Appointment of Chief Legal Officer and Chief People OfficerPROOFPOINT.COM
8 SepBigBear 2 PhaaS Campaign Steals 5000+ Microsoft CredentialsCloudSEK has uncovered BigBear 2.0, a new phishing-as-a-service operation targeting Microsoft 365INFOSECURITY-MAGAZINE.COM
8 SepClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport ManagerWe assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload.TALOSINTELLIGENCE.COM
8 SepClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session.TALOSINTELLIGENCE.COM
8 SepTHost9 Android RAT Pairs Packed Loader With ADB WormTHost9 hides its payload and uses ADB to spread across exposed Android devices and containersINFOSECURITY-MAGAZINE.COM
8 SepMicrosoft: Windows Server 2025 changes causing app crashesMicrosoft warned customers last week that they may experience application crashes on some Windows Server 2025 due to recent memory management changes. [...]BLEEPINGCOMPUTER.COM
8 SepMassive Vietnam-Linked APIS Database Exposes Passport and Flight DataAn exposed Vietnam-linked APIS database contained 220.8 million passenger and crew records, including passport and flight data. Researchers found an exposed Advance Passenger Information System (APIS) database containing 220.8 million passenger and crew records from January 2017 …SECURITYAFFAIRS.COM
8 SepMeta Failed to Catch Hundreds of AI Child Abuse Ads. Some Included Images of Real KidsImages of real children—including a member of a European royal family—were used to create some of the 350 ads containing child sexual abuse. Lawmakers say they plan to investigate.WIRED.COM
8 SepGrindr Settles UK Data Privacy Claims for £26mGrindr settled UK claims over alleged unlawful processing of sensitive user dataINFOSECURITY-MAGAZINE.COM
8 SepWeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming CallsResearchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone for it to work, but the caller must…THEHACKERNEWS.COM
8 SepWhat It Took to Reach 1 Billion Build ManifestsIn the last six months, Chainguard doubled its output from 500 million to more than 1 billion container build manifests. We also surpassed 3,000 unique container images and 675,000 image versions in our catalog. Those are the headline numbers, but I want to share what's actually …THEHACKERNEWS.COM
8 SepGrindr settles HIV status data-sharing lawsuit for $35 millionGrindr has settled a UK lawsuit alleging that it shared sensitive user data, including HIV status, with advertising companies.MALWAREBYTES.COM
8 SepA hacker stole $340M in a crypto heist, then returned most of itThe latest heist is one of the largest thefts of cryptocurrency to date.TECHCRUNCH.COM
8 SepWhere the backlash against Flock Safety is having the biggest impactTwo populous states and two large cities are among the U.S. jurisdictions where leaders have taken direct action to address criticisms of automated license plate readers (ALPRs).THERECORD.MEDIA
8 SepLiquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTCWhoever took nearly 4,000 bitcoin from the Liquid Network on Sunday, September 6, returned 3,400 of it the next day, Bitcoin's public record shows. About 598.5 bitcoin has not come back. Liquid is a Bitcoin sidechain that holds real bitcoin to back a token called L-BTC.…THEHACKERNEWS.COM
8 SepChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another AccountCheck Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user's question as usual. In the company's proof of concept, that hidden work read d…THEHACKERNEWS.COM
8 SepChrome is now shipping updates every 2 weeks as AI changes the security landscapeGoogle is speeding up Chrome’s release schedule to ship security patches and new features faster.TECHCRUNCH.COM
8 Sep‘White hat’ hackers take $47 million bounty after $320 million crypto theftPublic negotiations between hackers and the operators of the Liquid Network crypto platform ended with the attackers sending back most — but not all — of what they took.THERECORD.MEDIA
8 SepWindows 11 cumulative updates KB5124008 & KB5122880 releasedMicrosoft has released Windows 11 KB5124008 and KB5122880 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. [...]BLEEPINGCOMPUTER.COM
8 SepRussian suspect in bank account takeovers is extradited to USA Russian web developer who played a role in a multimillion-dollar bank account takeover scheme has been extradited to the U.S. to face an indictment.THERECORD.MEDIA
8 SepItalian tech collective Autistici/Inventati shuts down after US terrorist designationOn August 26, the State Department labeled A/I an “extremist group” operating infrastructure for “far-left militants across the world” and announced that anyone engaging with the group financially risked exposure to sanctions.THERECORD.MEDIA
8 SepMuse, Meta's New Personal AI Agent, Needs You to Trust ItDesigned to compete with OpenClaw and Instinct, the company says Muse can do everything from sell your car to book you a plane ticket.WIRED.COM
8 SepDoppelCart fraud network uses 119,000 fake shops to steal credit cardsA massive operation dubbed "DoppelCart" uses more than 119,000 domains to run a network of fake e-shops that steal payment card details. [...]BLEEPINGCOMPUTER.COM
8 SepMicrosoft Plugs Nearly 1,000 Security HolesMicrosoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security expe…KREBSONSECURITY.COM
8 SepHackers Drain $320 Million From Liquid Network, Then Return Most of ItCrypto exchange network Liquid Network lost $320 million overnight, then got most of it back after the hackers demanded a bug fix instead of a ransom Bitcoin’s Liquid Network, a sidechain built by Blockstream and used by dozens of exchanges to move funds faster and more pri…SECURITYAFFAIRS.COM
8 SepMicrosoft adds age-awareness APIs that can tell if users are children, teens, or adultsMicrosoft is adding new age-awareness APIs to Windows 11 that will allow apps to determine whether someone is a child, teenager, or adult without exposing their exact date of birth. [...]BLEEPINGCOMPUTER.COM
7 SepWhy AI Agent Sandboxes Are Failing Security TestsAutonomous AI agents escaped a sandbox and accessed Hugging Face via reward hacking, exposing serious architectural control and isolation flaws. The recent case involving OpenAI test agents and Hugging Face should concern security teams, but not for the reason implied by headline…SECURITYAFFAIRS.COM
7 SepChatGPT can now connect to your personal apps to mimic writing styleOpenAI appears to be testing a new "Writing Style" feature for ChatGPT that can learn how you write by looking at examples from your connected apps. [...]BLEEPINGCOMPUTER.COM
7 SepFlirty OnlyFans promoters on X may be using AI to appear humanPersonalized replies and voice notes make it increasingly difficult to tell whether you’re talking to a human, chatbot, or AI agent.MALWAREBYTES.COM
7 SepBerlin investigates new data leak after hackers publish stolen login credentialsAnother trove of data from Berlin's government has appeared online, authorities said. Germany's information security agency separately warned about the Rhysida cybercrime group.THERECORD.MEDIA
7 SepYour Cloud Security Checklist Doesn't Work the Way You Think It DoesIf managing security across multiple cloud providers wasn't hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and found that risk profiles across …THEHACKERNEWS.COM
7 SepLG TV flaws could let attackers listen in, even in standby modeTesting found that LG smart TVs can track viewing and scan home networks, while security flaws could let attackers record conversations.MALWAREBYTES.COM
7 SepBigBear Microsoft 365 phishing service bypassed MFA at 258 organizationsA phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. [...]BLEEPINGCOMPUTER.COM
7 SepCondé Nast Data of 32.8 Million Users Offered for Sale After WIRED LeakCondé Nast user data from 32.8 million accounts is reportedly for sale, raising risks of targeted phishing, fraud and scams. A database said to contain 32.8 million Condé Nast user records is being offered for $15,000 on a Russian-language cybercrime forum. Ransomnews reviewed a …SECURITYAFFAIRS.COM
6 SepFour REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto MinerElastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before…THEHACKERNEWS.COM
6 SepAI Agents Hijacked German Wiki to Cheat, OpenAI Delayed DisclosureAI agents secretly took over a 25-year-old German wiki for two months to cheat on tests, and OpenAI sat on the news until reporters found it first OpenAI finally admitted this weekend that a swarm of its own AI agents hijacked a German programming wiki earlier this year, turning …SECURITYAFFAIRS.COM
6 SepChatGPT Astra is now rolling out to $20 Plus subscriptionOpenAI is now rolling out ChatGPT Astra, its most powerful model to date, to those with a $20 Plus subscription, but there's no word on when free users will get access.. [...]BLEEPINGCOMPUTER.COM
5 SepThousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination ChannelA group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass ar…THEHACKERNEWS.COM
4 SepUS military disabled ad tracking on troops’ devices following reports of targeted attacksA senator's letter confirms the U.S. military moved to prevent the tracking after foreign adversaries used location data to target troops.TECHCRUNCH.COM
4 SepData access: the hidden cost of security vendor lock-inGetting data into a security platform is always easy; getting it back out is where vendors add cost, extra tooling, and latency, and it is the part of the evaluation most teams overlook.ELASTIC.CO
4 SepX Money rollout linked to password-reset attacksAs X expands into payments, users are receiving password-reset emails they didn’t request. Here’s what may be happening and how to stay safe.MALWAREBYTES.COM
4 SepFree streaming boxes may be routing criminal traffic through your homeResearchers found that apps available on SuperBox devices could add your household connection to a residential proxy network.MALWAREBYTES.COM
4 SepRussian data centers face new security requirements amid Ukraine's drone threatsRussia's data centers are concentrated in areas increasingly exposed to Ukrainian drone attacks. The Kremlin wants them to stiffen their physical defenses.THERECORD.MEDIA
4 SepICE Wants to Know Everyone Who Bought a Certain Green Beanie From REI in the Last 2 YearsHomeland Security Investigations agents hit the outdoor retailer with a controversial subpoena as part of a dragnet search for the identities of protesters who entered a Minnesota church in March.WIRED.COM
4 SepOpenAI Pledges $1bn to Bring its AI Cybersecurity Tools to Essential ServicesOpenAI has committed to subsidizing access to Daybreak, helping defenders deploy its AI models in its existing cybersecurity infrastructureINFOSECURITY-MAGAZINE.COM
4 SepG7 Urges Fast-Track on Quantum-Safe Cybersecurity RulesThe G7 has published a call to action, urging governments to launch national strategies dedicated to the post-quantum encryption transitionINFOSECURITY-MAGAZINE.COM
4 Sep39 New Methods That Compromise Passkey AuthenticationPasskeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries withou…BLEEPINGCOMPUTER.COM
4 SepExchange Online outage causes email delays, 'Server busy' errorsMicrosoft is working to resolve an ongoing Exchange Online outage that is delaying email sent to and received from external domains. [...]BLEEPINGCOMPUTER.COM
4 SepAI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks.DARKREADING.COM
4 SepUK account-hack losses surge as new reporting system exposes hidden casesIn its first annual assessment, published Friday, the City of London Police said victims reported losing £6.3 million ($8.5 million) to account hacks in the year ending March 31, up from £1.2 million ($1.6 million) a year earlier.THERECORD.MEDIA
4 SepMicrosoft says some users can’t open the Teams desktop clientMicrosoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems. [...]BLEEPINGCOMPUTER.COM
4 SepUS, Britain to coordinate on scam center takedownsThe U.S. Department of Justice and the U.K.'s National Crime Agency and Crown Prosecutor signed a memorandum to cooperate on cases involving Southeast Asian scam operations.THERECORD.MEDIA
4 SepPhishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade FiltersMicrosoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure w…THEHACKERNEWS.COM
4 SepCompanies Have Six Months to Prepare for Automated AttacksFrontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, but the situation will become more urgent very soon.DARKREADING.COM
4 SepThe Cyber Centre urges heightened vigilance amid global tensions and high-profile eventsCYBER.GC.CA
3 SepHoneypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd)[This is a Guest Diary by Frank Igbokwe, an ISC intern as part of the SANS.edu BACS program]
ISC.SANS.EDU
3 SepThis Is Flock’s AI Search Tool for CopsWIRED rebuilt Flock’s latest search tool from code the company sends to a police officer’s browser. Its AI can keep watch across multiple cameras for anyone fitting a written description.WIRED.COM
3 SepPlex warns users to patch security vulnerabilities immediatelyPlex urged users this week to update their desktop clients and media servers immediately to patch multiple security vulnerabilities. [...]BLEEPINGCOMPUTER.COM
3 SepUS Becomes Top Target in RMM Phishing Campaign Spanning 46 CountriesAn RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries. Around 45% of observed activity was associated with the United States, mak…THEHACKERNEWS.COM
3 SepCREST Onboards First Cohort for AI-Enabled Pentesting AccreditationCREST’s new AI-enabled penetration testing accreditation welcomes its first 10 providersINFOSECURITY-MAGAZINE.COM
3 SepMicrosoft says KB5120998 Windows update resets desktop settingsMicrosoft has confirmed that desktop settings are lost or reset on some Windows devices after installing the KB5120998 August 2026 preview update. [...]BLEEPINGCOMPUTER.COM
3 SepOutsider Phishing Kit Survives Takedown With 700 New PagesOutsider phishing kit generated 700 new pages after a Google-led disruptionINFOSECURITY-MAGAZINE.COM
3 Sep412,000 The Town 2025 Ticket Buyers’ Data Hits the Dark Web412,000 The Town 2025 festival buyer records are being sold for $10,000, with Brazil’s data openly marketed for bank fraud, loans and SIM registration. A seller on a Russian-language data-trading forum listed what they’re calling a Ticketmaster database on September 2, clai…SECURITYAFFAIRS.COM
3 SepAnthropic confirms Claude is down, multiple models affectedClaude is experiencing an outage, with users encountering elevated errors when sending requests to multiple Anthropic AI models. [...]BLEEPINGCOMPUTER.COM
3 SepMicrosoft: KB5120998 mouse reset bug affects only non-English PCsMicrosoft says a known issue that reverts mouse settings after installing the KB5120998 August 2026 preview update affects only non-English Windows 11 systems. [...]BLEEPINGCOMPUTER.COM
3 SepOpenAI confirms ChatGPT is down ahead of 'Astra' model launchChatGPT and Codex are experiencing a major outage, with users reporting errors across nearly every major ChatGPT feature. [...]BLEEPINGCOMPUTER.COM
3 SepAbliteration.ai is making a business out of removing AI guardrailsAbliteration.AI is making powerful AI models without guardrails easier to access, arguing that giving defenders the same tools as bad actors could ultimately improve cybersecurity.TECHCRUNCH.COM
3 SepThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More StoriesThe worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door? That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and…THEHACKERNEWS.COM
3 SepMeta agrees to pay $18 billion to settle US lawsuits over social media addiction.Review finds that more OpenAI agents went rogue.THECYBERWIRE.COM
3 SepNobody Is Saying Why OpenAI and Anthropic Had Outages TodayChatGPT, Claude, and Grok all suffered outages at nearly the exact same time for reasons that remain murky.WIRED.COM
3 SepPrediction Market Betting Is Getting People Banned and ArrestedThis week on Uncanny Valley, we dig into the latest prediction market buzz, Flock’s AI-powered police search tool, and how tech bros don’t know how to talk about “rouge” AI agentsWIRED.COM
2 SepWeekly Threat Bulletin – September 2nd, 2026These are the top threats you should know about this week.F5.COM
2 SepRisky Bulletin: BGP hijack delivers malicious Virtualizor updatesA BGP hijack delivered malicious Virtualizor updates, the White House launches Project Watershed 250, Indian authorities take down a Telegram doxing bot, and Composer packages deliver iOS badness.RISKY.BIZ
2 SepYour AI chats could be used in courtWhat you tell an AI chatbot could come back to haunt you in court. The Washington Post found chat histories already used in 12 legal cases.MALWAREBYTES.COM
2 SepMicrosoft Defender flags legitimate Google search links as maliciousMicrosoft is investigating an issue causing the Defender for Office 365 security software to mistakenly block access to legitimate Google search links. [...]BLEEPINGCOMPUTER.COM
2 SepTwo critical Chrome flaws put users at risk on malicious websitesUpdate Chrome now: Two critical vulnerabilities could allow a malicious website to run code on your device.MALWAREBYTES.COM
2 SepNorway considers ban on camera-enabled wearable ‘pervert glasses’The Nordic country says wearable camera headsets need to be regulated given their privacy risks.TECHCRUNCH.COM
2 SepHackers expose donor data from Russian fundraisers for Ukrainians, political prisonersHackers reportedly gained access to payment accounts used by two Russian fundraising projects supporting Ukrainians and political prisoners, exposing donor email addresses and limited payment card information.THERECORD.MEDIA
2 SepJoint guidance on best practices for service providers when communicating under pressureThis joint guidance explains why effective communications during outages is critical to minimize operational impacts, maintain credibility and situational awareness, and support response efforts.CYBER.GC.CA
2 SepHiddenLayer nabs $100M as enterprises rush to secure their AI deploymentsHiddenLayer has raised a $100M Series B from Delta-v Capital, Ten Eleven Ventures, Morgan Stanley, Microsoft's M12, Booz Allen Hamilton, and others.TECHCRUNCH.COM
2 SepRevolut scam wave steals £180,000 from Jersey residents in just four weeksIf you live in Jersey and bank with Revolut, you should be on your guard against scam phone calls. Because local police on the largest of the Channel Islands have warned that over a single four-week period, an astonishing 75% of all scam crime reports they have received have invo…BITDEFENDER.COM
2 SepTech support scams look different now. Here’s what to watch forTech support scams have evolved beyond fake virus warnings. Here’s how scammers reach their targets now, and how to stay safe.MALWAREBYTES.COM
2 SepAI Agents Are Now Emailing Me with Their Security ConcernsI received the two emails below earlier in the month. They’re vaguely coherent. I suppose I shouldn’t be surprised that the corpus that AIs are training on contain data suggesting that I am someone to write to with random computer and network security problems. After …SCHNEIER.COM
2 SepAgentic security: Detection and response at machine speedAfter talking with enterprise security leaders over the past year, one thing has become clear: the rise of autonomous AI agents is the most significant shift in security posture since the move to cloud. Organizations across every industry are adopting AI agents that authenticate …AWS.AMAZON.COM
2 SepGoogle, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access ProgramsGoogle on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program. "The Fairwind Program gives high-priority defenders (like go…THEHACKERNEWS.COM
2 SepSocure raises $156 million and acquires agentic AI platform Fravity.Palo Alto Networks has acquired San Francisco-based agentic workflow platform Console.THECYBERWIRE.COM
1 SepFinancial Stability Board Sounds the Alarm Over Frontier AI RisksThe Financial Stability Board has warned G20 banking leaders about the cyber risks of frontier AIINFOSECURITY-MAGAZINE.COM
1 SepJapanese Surveillance, Enslavement, and Experimentation in Wartime ChinaThe Asia-Pacific theater saw its own scenes of brutality during World War II. But many of us don't know about them. Jenny Chan co-founded Pacific Atrocities Education to raise awareness of these lesser-known horrors. This conversation focuses on the Imperial Japanese Army, which …THECYBERWIRE.COM
1 SepUsing High-Energy Laser, US Shoots Down Drones Near Mexico BorderThe US Army’s laser system is part of a new generation of directed-energy weapons capable of detecting, tracking, and destroying drones with a concentrated beam of light.WIRED.COM
1 SepCyber risk from frontier AI poses ‘most immediate concern’ to global financial system, watchdog warnsAndrew Bailey, chair of the Financial Stability Board, called on financial institutions and technology providers to “prepare for more severe scenarios involving simultaneous disruption across multiple firms or shared technology dependencies.”THERECORD.MEDIA
1 SepFive Venezuelan Nationals Plead Guilty in Kansas ATM Jackpotting AttemptFive Venezuelan nationals pleaded guilty after failed ATM jackpotting attempts in Kansas. The FBI recorded 700+ cases in 2025, causing $20M in losses. Five Venezuelan nationals have pleaded guilty after trying to steal cash from ATMs in Kansas using the popular ATM jackpotting te…SECURITYAFFAIRS.COM
1 SepFlorida and Texas move to block Flock cameras over privacy concernsFlock's searchable network of 130,000 license plate cameras around the U.S. have sparked bipartisan privacy and civil liberties concerns.TECHCRUNCH.COM
1 SepAttackers Steal METR API Key and Burn $600,000 in AI CreditsAttackers used a stolen METR API key for three weeks, consuming model credits worth $600,000INFOSECURITY-MAGAZINE.COM
1 SepHackers push malicious Virtualizor update in BGP hijacking attackHackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. [...]BLEEPINGCOMPUTER.COM
1 SepClickFix Campaign Compromises 31 Orgs, Abuses Polygon BlockchainThe campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book.DARKREADING.COM
1 SepAIR raises $50M to help companies vet the skills and add-ons AI agents useAIR's platform can discover agents running at a company, continuously vets any skills and add-ons they use, and blocks any unwanted behaviour.TECHCRUNCH.COM
1 SepDual-RMM Phishing and PowerShell RAT Campaign Hits SLTTsAn active phishing campaign is targeting U.S. SLTTs with a custom PowerShell WebSocket RAT and dual RMM tools. Read the CIS CTI team's analysis.CISECURITY.ORG
1 SepFake GTA 6 leaked copy drains your crypto walletA fake GTA 6 leak is using wallet-draining code to steal cryptocurrency, tokens, and NFTs from eager fans.MALWAREBYTES.COM
1 SepWhat’s the Scam?To subscribe to my monthly email newsletter, you have to enter your information on the webpage, and then reply to an automatically generated email. This is, of course, to prevent people from subscribing addresses other than their own. Starting last weekend, I have been receiving …SCHNEIER.COM
1 SepOpenAI Is About to Release Its First AI Model With ‘Critical’ Cyber AbilitiesThe company will give select partners early access to its Astra AI model—so they have time to shore up their defenses.WIRED.COM
1 SepX says attackers are targeting user accounts after the launch of X MoneyX is investigating a wave of unsolicited password reset emails that it believes may be tied to the rollout of its new payments service.TECHCRUNCH.COM
31 Aug[webapps] C-MOR 6.0104 - Cross-Site Scripting (XSS)C-MOR 6.0104 - Cross-Site Scripting (XSS)EXPLOIT-DB.COM
31 Aug[webapps] CubeCart 6.7.4 - Cross-Site ScriptingCubeCart 6.7.4 - Cross-Site ScriptingEXPLOIT-DB.COM
31 Aug[webapps] Linksys E1200_2.0.04 - Unauthenticated OS Command InjectionLinksys E1200_2.0.04 - Unauthenticated OS Command InjectionEXPLOIT-DB.COM
31 AugMicrosoft Exchange Online outage causes email failures, auth issuesMicrosoft is investigating a widespread service issue causing authentication issues and email delays and failures for Exchange Online customers. [...]BLEEPINGCOMPUTER.COM
31 AugOpenAI confirms ChatGPT outage as users report errorsChatGPT Work is experiencing a partial outage, and users across multiple subscription plans may be unable to start or continue tasks. [...]BLEEPINGCOMPUTER.COM
31 AugChinese Fire Ant hackers turn Cisco routers into spying platformsThe researchers discovered Fire Ant's new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco IOS XR router that could not be explained by a running configuration or commit history. [...]BLEEPINGCOMPUTER.COM
31 AugMicrosoft says Windows 11 KB5120998 update resets mouse settingsMicrosoft has confirmed that mouse settings are being reverted on Windows 11 systems after installing the KB5120998 August 2026 non-security preview update. [...]BLEEPINGCOMPUTER.COM
31 AugNigerians extradited to US for sextortion, deaths of two teensTwo Nigerian men extradited to the U.S. on Thursday have been charged with involvement in sextortion schemes that resulted in the deaths of two minor victims in Mississippi and North Carolina. [...]BLEEPINGCOMPUTER.COM
31 AugMicrosoft asks users to ignore 'Antivirus is turned off' errorsMicrosoft asked customers this week to ignore alerts that Defender Antivirus has been turned off after installing the latest Defender updates. [...]BLEEPINGCOMPUTER.COM
31 Aug[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AIDARKREADING.COM
31 AugGreyNoise + CrowdStrike: Real-Time Edge Intelligence in Falcon Next-Gen SIEM and Charlotte Agentic SOARToday we’re announcing an expanded integration between GreyNoise and the CrowdStrike Falcon® platform, with new content for CrowdStrike Falcon® Next-Gen SIEM and CrowdStrike Charlotte Agentic SOAR. The expanded integration includes a purpose-built Falcon Next-Gen SIEM dashboard, …GREYNOISE.IO
31 AugRisky Bulletin: New powers for Dutch intelligence servicesDutch intelligence services will get new powers, a security expert has been arrested in Israel for hacking, the BTS hacker gets a 20 year sentence in South Korea, and an AfD politician in Germany has been linked to a Russian cybercrime hosting service.RISKY.BIZ
31 AugAI Model Rules Are Not Security ControlsOpenAI's Hugging Face attack postmortem shows agents don't care about rules — they need strong controls.DARKREADING.COM
31 AugWe invited a direct competitor into Security Hub Extended. Here’s why.When customers keep pointing you to a solution that overlaps with parts of your own offering, you have a choice to make. This post is about the choice we made with Upwind, and why we’d make it again. AWS Security Hub Extended exists because customers told us what was working for …AWS.AMAZON.COM
31 AugFraudsters steal $6 million from Tectonic crypto platform after inflating token priceAt least $6 million was stolen from crypto platform Tectonic after an attacker manipulated the price of the Tonic coin over the weekend.THERECORD.MEDIA
31 AugThe Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary, (Mon, Aug 31st)One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide "free" LLM backends. It then received a real coding-agent session &#;x26;#;xe2;&…ISC.SANS.EDU
31 Aug'TerminalFix' Campaign Weaponizes PowerShell for Enterprise AttacksThe ClickFix-style campaign features a sophisticated, multistage attack chain that includes reverse tunnels into victim organizations' networks.DARKREADING.COM
29 AugUS disrupts Chinese hacking platform.Researchers publish analysis of OpenAI agents' attack against Hugging Face. Australian police arrest two suspected TeamPCP members.THECYBERWIRE.COM
29 AugAnthropic is cutting Claude Code's current weekly limits by 17%Anthropic is permanently increasing Claude Code's standard weekly usage limits by 25% for Pro, Max, Team, and seat-based Enterprise plans, but it's not as good as it sounds. [...]BLEEPINGCOMPUTER.COM
29 AugBrave browser adds email aliases to help users evade trackingThe latest version of the Brave browser, 1.94, introduces a feature called 'Email Aliases' that allows users to generate disposable email addresses when signing up to a new service. [...]BLEEPINGCOMPUTER.COM
28 AugAndroid 17 Adds OS-Wide ECH to Hide Website Visits From Network ProvidersGoogle on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks. Topping the list is support for Encrypted Client Hello (ECH), a privacy standard that pr…THEHACKERNEWS.COM
28 Aug19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining CodeCybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities. The extensions, per Socket security researcher Karl…THEHACKERNEWS.COM
28 AugKey Reasons Why Identity Fabric Matters in 2026An Identity Fabric knits fragmented identity systems into a coherent layer that observes how identities behave across applications, APIs, and infrastructure. As enterprise access spans more cloud services and automated workloads, identity security depends less on static configura…THEHACKERNEWS.COM
28 AugExtend your data perimeter to the AWS Management Console with Private AccessOrganizations in regulated industries such as financial services, government, defense, and healthcare restrict their sensitive workloads to isolated network environments with no access to the public internet. Until now, customers could restrict AWS Management Console access to au…AWS.AMAZON.COM
28 AugProtect your WhatsApp account with new passkey and 2FA upgradesWhatsApp has introduced three security upgrades. Here’s what to turn on to better protect your account.MALWAREBYTES.COM
28 AugHow an Atlanta Suburb Ended Up Sharing Flock Data With More Than 2,000 OrganizationsAlpharetta, Georgia, cops share data with thousands of Flock users, ranging from federal agencies to a fish and wildlife commission. The reasons why show how vast—and invasive—the network has become.WIRED.COM
28 AugFake Voicemail SVG Attachments Fuel Large-Scale Phishing CampaignA large-scale phishing campaign used fake voicemail SVG attachments to bypass email defenses, targeting 5527 organizations with over 26,000 malicious messagesINFOSECURITY-MAGAZINE.COM
28 AugTeach Yourself to Phish | HuntressGet ready for a phishing trip! Learn about the strategy behind phishing simulations and how it can help your organization build resilience against real phishing threats.HUNTRESS.COM
28 AugA Beginner’s Guide to Phishing Simulation Training for Employees | HuntressLearn the essentials of phishing simulation training with our beginner's guide. Protect your organization by simulating real phishing attacks.HUNTRESS.COM
28 AugOffensive Security Investments Surge as AI Threats IncreaseOmdia's Theresa Lanowitz talks with the Dark Reading News Desk about the potential — and risks — of using agentic AI for penetration testing, red teaming, and other practices.DARKREADING.COM
27 AugWhat does hospital downtime teach us about building AI-native organizations?Is your organization truly AI native, or did you just bolt AI onto existing infrastructure? Your answer could be an indicator to how much risk you’re carrying without realizing it. Zach Evans, Chief Technology Officer at Xsolis, has a simple test for telling the difference: strip…THECYBERWIRE.COM
27 AugBreaking big tech's hold.This week, Dave and Ben look at California's latest effort to restrict social media companies further by banning design features that are considered harmful to minors. Additionally, the two discuss recent calls on the Maryland government to investigate data brokers which could be…THECYBERWIRE.COM
27 AugOpenAI banned Russian ChatGPT accounts backing covert influence operationOpenAI banned Russian ChatGPT accounts backing a fake think tank, IBI, that used AI posts and a fake “sovereignty” index to push pro‑Russia narratives. OpenAI says it has banned a cluster of ChatGPT accounts that likely originated in Russia and were used to support a covert influ…SECURITYAFFAIRS.COM
27 AugMeta to Pay Up to $18B Over Teen Social Media UseMeta will pay up to $18B and cap teen Facebook and Instagram use at two hours daily after nearly all US states sued over child safety. Meta will pay up to $18 billion over the next decade and impose real usage limits on teenagers using Facebook and Instagram, settling claims that…SECURITYAFFAIRS.COM
27 AugA polymorphic phishing page (that occasionally breaks itself), (Thu, Aug 27th)As I've mentioned before in some of my diaries, from time to time, I like to go over phishing messages that get caught in my various spam traps or sent to us here at the Internet Storm Center.
ISC.SANS.EDU
27 AugNew Instagram and Facebook rules set a default two-hour limit for teensMeta will pay up to $17 billion and introduce new protections for US teens to settle a landmark child safety case.MALWAREBYTES.COM
27 AugBack to the Future: Why Agentic AI Needs a Strong Identity FoundationAs AI matures, enterprises and customers are rapidly deploying agents seeking to unlock the next level of automation and productivity. Agentic AI shows potential to handle a multitude of use cases, from buying personal items on Amazon to customer service applications to enterpris…NIST.GOV
27 AugFake Apple Pay charge brings the classic tech support scam to your phoneBuilt for mobile users, this tech support scam uses a fake Apple Pay alert and browser tricks to pressure victims into calling a scam number.MALWAREBYTES.COM
27 AugAustralia charges two men for TeamPCP supply-chain hacking spreeTwo men in Australia were charged Wednesday over their alleged membership in TeamPCP, the cybercrime group blamed for one of the most damaging hacking campaigns of the past year.THERECORD.MEDIA
27 AugMicrosoft rolls out fix for Windows 11 crashes, gaming issuesMicrosoft has started rolling out a permanent fix for a known issue that causes system crashes and gaming issues on Windows 11 devices. [...]BLEEPINGCOMPUTER.COM
27 AugAndroid 17 adds ECH support to make web browsing harder to trackGoogle is introducing new network security protections in Android 17 to strengthen connection privacy, address cellular vulnerabilities, and protect the privacy of users' home networks. [...]BLEEPINGCOMPUTER.COM
27 AugFake listings can turn trusted platforms into scam springboardsA trusted name on a trusted platform does not guarantee a trustworthy listing. It could still lead to a tech support scammer.MALWAREBYTES.COM
27 AugFinland appeals court revives case against Eagle S Officers over cable breaksThe appeals court sent the case back to the Helsinki District Court to be heard on its merits, although the three men, who had previously been detained in Finland, have since left the country.THERECORD.MEDIA
27 AugFrom Concept to Context Engine: How Wiz Built AI-Powered Data DiscoveryInside the multi-agent pipeline and feedback loops that turned a bucket scanner into a context engine.WIZ.IO
27 AugExtend Amazon Bedrock Guardrails to Tool Interactions Using the Strands Agents SDKIf you’re running AI agents in production, Amazon Bedrock Guardrails protects the model boundary. But your agents also invoke tools, fetch external data, and communicate with other systems. That data flows outside the model boundary, where model-level guardrails can’t reach. You …AWS.AMAZON.COM
27 AugA Georgia Cop Used Flock to Track 2 Other Cops: His Ex and Her FriendAfter an affair with a fellow police officer ended, a Georgia cop used Flock to track her movements—and those of a man whose vehicle often showed up near hers, internal investigation records show.WIRED.COM
27 AugUK and Ukraine sign landmark AI deal.Taiwan cracks down on illegal AI server smuggling.THECYBERWIRE.COM
27 AugNearly 700 rogue AI agents coordinated in the Hugging Face attackNew details about the July attack on Hugging Face reveal that hundreds of AI agents driven by OpenAI's internal IM1 model coordinated the compromise through an unauthorized message board. [...]BLEEPINGCOMPUTER.COM
26 AugWeekly Threat Bulletin – August 26th, 2026These are the top threats you should know about this week.F5.COM
26 AugHow Check Point Built a Cybersecurity Arcade Game in Under a Month with Gemma GoldsteinGemma Goldstein had a quiet Thursday in the office, a domain someone spotted for sale, and an idea. A few short weeks later, Check Point's Exposure Management team had a browser-based arcade game live at exposuremanagement.ai with 11,000 players and a leaderboard. The game launch…THECYBERWIRE.COM
26 AugNigeria Looks to Sovereign Cloud for Cyber, National SecurityThe West African nation launched financing, procurement, and infrastructure policies to boost its sovereign cloud initiative and increase domestic technical knowledge.DARKREADING.COM
26 AugOperation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global ScamsINTERPOL’s Operation Jackal IV made 58 arrests and exposed global networks laundering money from scams, fraud and sextortion. INTERPOL announced that Operation Jackal IV, running from November 2025 to June 2026, led to 58 arrests and identified 263 suspects tied to West African o…SECURITYAFFAIRS.COM
26 AugINTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud CrackdownAn eight-month INTERPOL operation targeting West African organized crime groups has led to arrests of 58 people and the identification of 263 suspects. "The operation, which brought together 22 countries from six continents, is a response to the escalating global threat posed by …THEHACKERNEWS.COM
26 AugWhatsApp Adds Stronger Security as Passkeys Hit 1 BillionWhatsApp says 1 billion users now use passkeys, while stronger two-step verification and caller context add new layers of account protection. WhatsApp has reached a significant security milestone: more than one billion people now use passkeys to protect access to their accounts. …SECURITYAFFAIRS.COM
26 AugDDoS Attack Hits Norwegian Government ServicesA coordinated DDoS campaign has caused disruption among Norwegian government servicesINFOSECURITY-MAGAZINE.COM
26 AugOpenAI Bans Russian ChatGPT Accounts Used to Run Influence OperationOpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which relied on its artificial intelligence (AI) tool to generate social media posts and comments that were shared on Substack, Tele…THEHACKERNEWS.COM
26 AugImagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis EngineThe SOC we've always known was built around a model that guarantees most of the alert queue will never receive analyst review. There's never time. In a traditional SOC, the typical progression follows a well-known pattern: an alert arrives; a detection engine assigns a severity s…THEHACKERNEWS.COM
26 AugAverage Cyber Insurance Losses Increase Despite Fewer ClaimsChubb reported that growing privacy litigation has contributed to surging cyber claim costs in the USINFOSECURITY-MAGAZINE.COM
26 AugPopular school apps may be sharing student data with advertisersA Utah investigation found educational apps collecting unauthorized student data and sharing information with third parties and advertisers.MALWAREBYTES.COM
26 AugMicrosoft tests new privacy controls for Windows 11 desktop appsMicrosoft has begun testing new privacy controls that will let Windows 11 users choose which desktop applications can access their camera, microphone, and precise location. [...]BLEEPINGCOMPUTER.COM
26 AugInterpol Operation Jackal IV Identifies 263 Cybercrime SuspectsInterpol operation leads to 58 arrests and identifies 263 suspects across 22 countriesINFOSECURITY-MAGAZINE.COM
26 Aug'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a MonthThe adversary-in-the-middle (AitM) phishing service lowers the barrier to entry for actors to create attacks and steal more than just user credentials.DARKREADING.COM
26 AugSnowflake ends service-account passwords. Now comes the hard partSnowflake is ending password authentication for legacy service accounts, forcing organizations to migrate them to passwordless methods. Token Security explains why the harder challenge is identifying what uses each account, who owns it, and how much access it still needs. [...]BLEEPINGCOMPUTER.COM
26 AugIran-linked hackers expand infrastructure across Europe and Middle East, report saysResearchers said they identified servers and domains associated with several countries in Europe and the Middle East, potentially pointing to a broader targeting profile for an Iranian hacking group.THERECORD.MEDIA
26 AugThe State of Cloud Risk 2026: Most Security Findings Aren’t Real Attacker OpportunitiesWiz Research telemetry reveals why the majority of high-severity findings lack a path to compromiseWIZ.IO
26 AugMeta agrees to $18 billion settlement over teen social media harmsMeta has reached a proposed settlement worth up to approximately $18 billion with a bipartisan coalition of 52 attorneys generals over allegations that Facebook and Instagram were deliberately designed to encourage compulsive use by children and teenagers. [...]BLEEPINGCOMPUTER.COM
26 AugFBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and InfrastructureChina’s hacking campaign targeted NASA, the Federal Reserve, the US Senate, the Justice Department, and more, according to the DOJ.WIRED.COM
26 AugDemocratizing FinOps with Wiz: Driving Cost Attribution with the Wiz Service CatalogHow the Wiz Cloud Cost automates cost allocation to power developer-led cost optimization and connect cost to business value.WIZ.IO
26 AugMeta pledges to overhaul kids’ safety protections, pay $17 billion to settle social media caseA multibillion-dollar settlement with attorneys general from nearly every U.S. state and territory will mean new privacy and safety protections in Meta products.THERECORD.MEDIA
26 AugICYMI: July 2026 @AWS SecurityIf you found time for a bit of vacation this summer, you might be in catch-up mode. Here’s a list to help: all the expert blog posts, new service capabilities, code samples, and workshops, in case you missed it, from July 2026. AWS Security Blog post This month’s AWS Security Blo…AWS.AMAZON.COM
26 AugAI safety and security company Alice raises $140 million.Munich Re Group has agreed to acquire San Francisco-based At-Bay for $575 millionTHECYBERWIRE.COM
26 AugOpenAI’s Hugging Face Hack Debrief Raises More Questions Than It AnswersThe AI giant acknowledges that it could have done far more to prevent its AI agents from going rogue. But it still fails to explain why it didn't see this fiasco coming.WIRED.COM
26 AugCIS and SANS: A Longstanding Partnership Built to Advance CybersecurityCIS and SANS extend decades of partnership with a new AWS Marketplace offering that combines secure cloud infrastructure and expert training.CISECURITY.ORG
26 AugExclusive: NSA to host a hacker reunion in bid to rebuild secretive unitThe National Security Agency will welcome back to campus potentially hundreds of former members of the elite group known as Tailored Access Operations (TAO) to celebrate the division’s recent rebranding.THERECORD.MEDIA
25 AugTikTok phishing: How to spot fake login and verification pagesScammers use fake TikTok login pages, warnings, and verification offers to trick you into handing over your account details.MALWAREBYTES.COM
25 AugUS Sanctions Mabna Institute Hackers for Iranian Cyber-AttacksThe US has sanctioned individuals connected to hacking-for-hire group the Mabna InstituteINFOSECURITY-MAGAZINE.COM
25 AugGTA 6 leak hunt could expose data belonging to thousands of Discord usersTake-Two is demanding IP addresses, phone numbers, device IDs, and other data as it tries to identify whoever leaked GTA 6 footage.MALWAREBYTES.COM
25 AugThe County Prosecutors Who Became ICE InformantsIllinois prosecutors shared defendants’ personal data with federal immigration agents without criminal warrants, public disclosure, or legislative oversight.WIRED.COM
25 AugEncrypted instructions can fool AI assistants like Grok and GeminiResearchers found that prompt injection attacks can hide malicious instructions in encrypted text to get them past AI guardrails.MALWAREBYTES.COM
25 AugLarge DDoS attack knocks Norwegian public services offlineThe Norwegian Digitalisation Agency said it was working with its IT partner to stabilize systems affected by a distributed denial-of-service attack, with some services gradually coming back online.THERECORD.MEDIA
25 AugWhatsApp tightens account security with stronger two-step verification and moreWhatsApp’s two-step verification previously relied on a six-digit PIN, but now users can choose a longer, alphanumeric password with special characters.TECHCRUNCH.COM
25 AugUK government seeks powers to secretly block risky tech suppliersThe British government is seeking new powers to ban certain technology vendors from supplying companies working in the country’s critical sectors — potentially doing so in secret.THERECORD.MEDIA
25 AugFake Recruiter Scams Target Corporate Credentials on MobileRecruitTrap campaigns use mobile-optimized phishing pages to target enterprise credentialsINFOSECURITY-MAGAZINE.COM
25 AugWhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and AndroidMeta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method. The tech giant said more than 1 billion…THEHACKERNEWS.COM
25 AugFrom Fake Workers to Account Recovery: The Growing Identity Verification RiskAttackers are increasingly targeting the processes used to establish or recover identity rather than attacking the login itself. Specops explains how stronger identity verification can help organizations prevent fake workers and social engineering attacks from gaining legitimate …BLEEPINGCOMPUTER.COM
25 AugWhatsApp adds stronger two-step verification, multiple passkeysWhatsApp has started rolling out several new account security features, including support for multiple passkeys and stronger two-step verification. [...]BLEEPINGCOMPUTER.COM
25 AugApple rescues Hide My Email feature from the privacy scrap heapApple says it will no longer ditch using its icloud.com domain for hiding people's email addresses.TECHCRUNCH.COM
25 AugUkraine to give Britain access to battlefield data to train AIUkraine will give Britain access to a vast trove of battlefield data collected during the war with Russia, allowing U.K. companies and researchers to use it to train and test artificial intelligence systems.THERECORD.MEDIA
25 AugZeroTokens Phishing Platform Steers Attacks in Real TimeZeroTokens gives phishing operators live control of victim sessions targeting 53 financial brandsINFOSECURITY-MAGAZINE.COM
25 AugMassive DDoS attack disrupts Norway’s government digital servicesA large distributed denial-of-service (DDoS) attack has disrupted Norway's shared government digital infrastructure since Monday, affecting services used by the public sector. [...]BLEEPINGCOMPUTER.COM
25 AugWhen the Algorithm Fires You: Uber Faces €825M FineUber faces an €825M GDPR fine for automatically suspending drivers without human review, highlighting the risks of AI decisions affecting workers. The Dutch Data Protection Authority handed Uber its largest privacy fine yet, and this one isn’t about data transfers or cookie…SECURITYAFFAIRS.COM
25 AugEmployee benefits platform Paylogix says hackers stole financial and health dataThe benefits management firm Paylogix told regulators that hackers stole sensitive information on tens of thousands of people from its systems.THERECORD.MEDIA
25 Aug58 arrested in international cybercrime crackdownInterpol officials said it uncovered a crime-as-a-service network in Argentina run by 196 people that provided website domains and money laundering support to West African organized crime groups like Black Axe.THERECORD.MEDIA
25 AugAnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodesA newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. [...]BLEEPINGCOMPUTER.COM
25 AugFast Track ISM-ready cloud environments and IRAP Assessments with Landing Zone Accelerator on AWSThis post announces the availability of a new independent assessment report available on AWS Artifact analyzing how Landing Zone Accelerator on AWS (LZA) can automatically deploy multi-account environments in Amazon Web Services (AWS) with Australian Government Information Securi…AWS.AMAZON.COM
25 AugHidden Prompts Trick AI Into False Email SummariesWith some simple HTML that's invisible to users, attackers can manipulate AI-powered email summarizers into producing malicious information.DARKREADING.COM
24 AugResearchers Uncover Thousands of Leaked AWS KeysTruffle Security says it found over 9000 publicly accessible and active AWS key pairsINFOSECURITY-MAGAZINE.COM
24 AugTikTok Settles U.S. Child Privacy Case for $400 MillionTikTok will pay $400 million to settle U.S. claims that it violated child privacy laws by collecting data from users under 13. The U.S. Department of Justice announced that TikTok will pay $400 million to settle a 2024 lawsuit over children’s privacy. “Today, the Department…SECURITYAFFAIRS.COM
24 AugiAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password ResetiAuthFlow v2 phishing toolkit uses a phished Google session to enroll an attacker-controlled passkey that survives password resets. Abnormal Security researchers have published an analysis of iAuthFlow v2, a phishing toolkit sold on a Russian-language cybercrime forum for $10,000…SECURITYAFFAIRS.COM
24 AugWake-Up Call for CNI After Iranian Attack Shuts Down UK Power PlantExperts argue Iranian cyber-attack on UK power plant lays bare frailty of critical national infrastructureINFOSECURITY-MAGAZINE.COM
24 AugThe Outsized Shadow: Why 5% of AI Users Are Your Biggest Security RiskBig security risks come in small packages. While enterprise security teams focus on policing the proliferation of employees using ChatGPT and Claude for quick drafting tasks, a more urgent threat is posed by a handful of AI super-adopters who are quietly hardcoding unvetted tools…THEHACKERNEWS.COM
24 AugDoubloon Dredger Abuses Notion to Harvest Authentication TokensDoubloon Dredger abused Notion and malicious PDFs to harvest Microsoft authentication tokensINFOSECURITY-MAGAZINE.COM
24 AugAliExpress caught using silent audio to fingerprint visitors’ browsersSilent audio processing on the AliExpress website was found helping to fingerprint visitors’ browsers without relying on cookies.MALWAREBYTES.COM
24 AugMalicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentialsEvery time you add an extension or plugin to your browser, there's a risk that you might be doing more than managing your cryptocurrency wallet, generating passwords, taking notes, or tracking sports results. There's a chance that you have just handed a complete stranger access t…BITDEFENDER.COM
24 AugFake Microsoft security scans trick victims into uninstalling their antivirusWe found fake Microsoft-branded scanners that invent security problems, tell victims to uninstall AV, and then steer them into a refund scam.MALWAREBYTES.COM
24 AugNew Guidance Helps Businesses Verify Quantum-Safe Hardware ClaimsTCG has released new guidance to help proving that trusted platform modules genuinely meet essential quantum-safe requirementsINFOSECURITY-MAGAZINE.COM
24 AugTikTok reaches $400M settlement with US over COPPA violationsThe U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children's Online Privacy Protection Act (COPPA). [...]BLEEPINGCOMPUTER.COM
24 AugInstinct’s powerful AI assistant is raising privacy and security concernsEarly testers are raving about what Instinct can do, but some say the AI assistant’s sweeping access, broad terms and ability to act on users’ behalf come with uncomfortable trade-offs.TECHCRUNCH.COM
23 AugZero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context InjectionNew Cryptographic Context Injection technique bypasses AI guardrails via AES-encrypted payloads, leaking full Grok chat histories zero-click Adversa AI researcher Rony Utevsky devised a new attack technique, called Cryptographic Context Injection, that bypasses AI safety filters …SECURITYAFFAIRS.COM
22 AugNamed Pipes Under Attack: Securing Windows Interprocess CommunicationWindows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command authorization, strict input validation, and narrowly scoped privileges can help se…BLEEPINGCOMPUTER.COM
22 AugTikTok Agrees to $400 Million Settlement in U.S. Child Privacy LawsuitThe U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company of violating child privacy laws in the country. As part of the settlement, the social media platform will pay $300 million imme…THEHACKERNEWS.COM
22 AugFrontier AI labs still won’t say how they’d contain a rogue modelA new study finds leading AI labs have few publicly documented plans for containing rogue models, raising questions about preparedness as AI systems increasingly demonstrate unexpected and potentially dangerous behavior.TECHCRUNCH.COM
22 AugToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 CountriesToxicPanda 2.0 targets 349 financial apps and abuses Android Wireless Debugging to gain deeper device access and steal banking credentials. ToxicPanda used to be a Europe-focused nuisance targeting a manageable list of banks. That version is gone. Zimperium’s zLabs team jus…SECURITYAFFAIRS.COM
21 AugCalling on Cyber Pros to Help Defend City HallGovernment agencies with smaller budgets need support — and here's how you can help.DARKREADING.COM
21 AugEven MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays, (Fri, Aug 21st)One thing that folks never seem to do after "going to the CLOOOOUUUUD" is to look at their logs, logs that they would have checked daily when things were on premise.
One log that really bears looking at is the log of successful and failed logins. the call for that is:
ISC.SANS.EDU
21 AugWho Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st)In every MFA rollout, there will come a time where you think you are closing in on "done", and some automation to list what&#;x26;#;39;s left would be handy. Something quicker than scrolling through the web interface through thousands of accounts ... &…ISC.SANS.EDU
21 AugWazuh and AI For Enhanced SOC WorkflowsArtificial Intelligence (AI) has become one of this decade's defining technologies. From healthcare and finance to manufacturing and education, organizations increasingly rely on AI to automate repetitive tasks, uncover patterns hidden within large datasets, and support faster de…THEHACKERNEWS.COM
21 AugMicrosoft rolls out Classic Outlook theme for New Outlook usersMicrosoft has started rolling out a Classic Outlook theme for users of Outlook on the web and the New Outlook for Windows. [...]BLEEPINGCOMPUTER.COM
21 AugCalling on Cyber Pros to Help Defend City HallGovernment agencies with smaller budgets need support — and here's how you can help.DARKREADING.COM
21 AugZombie Card: An expired Visa credit card can be used for purchasesScientific research showed that the expiration date on some Visa credit cards can be manipulated in so-called Zombie Card attacks.MALWAREBYTES.COM
21 AugMicrosoft blames Windows gaming issues on RGB lighting devicesMicrosoft says ongoing issues causing games to crash or fail to launch after installing the August 2026 Windows updates may be caused by peripherals with RGB lighting. [...]BLEEPINGCOMPUTER.COM
21 AugHundreds of leaked AWS keys give full control over corporate accountsMore than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. [...]BLEEPINGCOMPUTER.COM
21 AugOWASP Flags Top AI Skill Risks in New Security BlueprintThe Open Worldwide Application Security Project has a brand-new top 10 security list tailored for the modern era, and it debuts a Universal Skill Format to add consistency and security to the AI add-ons.DARKREADING.COM
20 AugMicrosoft says August Windows updates may cause gaming issuesMicrosoft is investigating a potential issue with the August 2026 updates that may prevent some games from launching or cause them to crash on affected Windows 11 systems. [...]BLEEPINGCOMPUTER.COM
20 AugDef Con Attendees Targeted by Persistent Phishing CampaignHuntress researcher explains how they were targeted by an elaborate and persistent phishing scam following Def ConINFOSECURITY-MAGAZINE.COM
20 AugUsing Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses, (Thu, Aug 20th)Microsoft Graph is a newer API that is meant to replace several others.&#;x26;#;xc2;&#;x26;#;xa0; OK, it&#;x26;#;39;s at version 2.3.9, so it&#;x26;#;39;s not all that …ISC.SANS.EDU
20 Aug9 million images of people’s faces exposed by reverse lookup serviceA researcher found an exposed database containing 9 million images that belonged to people finder service ClarityCheck.MALWAREBYTES.COM
20 AugUS says hackers are targeting vulnerable water systems with the help of AIHackers are targeting internet-connected Siemens controllers used in water facilities around the United States.TECHCRUNCH.COM
20 AugUS Defense Contractors Admit Their Rising CMMC Scores May Not Be AccurateDefense contractors in the US are doubting their own self-assessment scores under CMMC Phase I, even as those scores hit an all-time highINFOSECURITY-MAGAZINE.COM
20 AugCitrix urges admins to patch new NetScaler flaws as soon as possibleCitrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances. [...]BLEEPINGCOMPUTER.COM
20 AugZombie Card Attack Can Revive Expired Visa Cards for Contactless PaymentsResearchers at the University of Massachusetts Amherst have demonstrated an attack that revives expired Visa contactless credit cards for real in-store purchases by rewriting the expiration date a point-of-sale (POS) terminal reads over near-field communication (NFC), without bre…THEHACKERNEWS.COM
20 AugUsing Microsoft Graph and Powershell - Risk Detection Commands, (Thu, Aug 20th)Building on the last diary on Using MS Graph and Powershell, let&#;x26;#;39;s look at "Risky" logins.
ISC.SANS.EDU
20 AugTwitch wants your content for Amazon AI training. Here’s how to opt outTwitch added an option to opt out of training Amazon AI with your content—two years after it confirmed that training had begun.MALWAREBYTES.COM
20 AugChatGPT for Teens tackles risky chats and homework shortcutsOpenAI has strengthened ChatGPT's protections for teens, but some of its strongest parental controls still depend on linked accounts.MALWAREBYTES.COM
20 AugHow MSPs can catch phishing attacks email filters missAI is making phishing attacks more personalized, convincing, and difficult for traditional email filters to detect. Kaseya explains how MSPs can monitor identity, email, and endpoint activity to detect and contain attacks that make it past the inbox. [...]BLEEPINGCOMPUTER.COM
20 AugSenators press TikTok over withholding of safety features for some usersIn a letter on Wednesday, Sens. Marsha Blackburn (R-TN) and Richard Blumenthal (D-CT) criticized the company for having “knowingly withheld a critical safety measure for millions of American users."THERECORD.MEDIA
20 AugN-able Bug Exposes Password Vault Master KeysThe popular "Passportal" password manager, favored by MSPs and SMBs, remains risky even after its patch, thanks to its cloud-based design. Should these products stay away from the cloud entirely?DARKREADING.COM
20 AugIs Cyber missing the Marque?In this week's newsletter, new author Mick Baccio introduces himself and explores the operational and security implications of the new White House memorandum regarding private sector participation in government-authorized offensive cyber operations.TALOSINTELLIGENCE.COM
20 AugPresident Trump allows for private companies to hack cybercriminals.States start lawsuit against Meta.THECYBERWIRE.COM
20 AugWhat We Missed: Delta Flight Disrupted With Wi-Fi HackIn this video, Dark Reading editors discuss some of the news they didn't get a chance to cover, including some scary airplane security risks and the US government's newest "hack back" strategy.DARKREADING.COM
20 AugIntelligence Insights: August 2026Debuts, departures, and danger on the blockchain in this month’s edition of Intelligence Insights.REDCANARY.COM
20 AugNew CUSTODY Framework Constrains AI Agents Inside the NetworkEnterprise cybersecurity expert Jake Williams joins the Dark Reading News Desk to explain why he decided to release his new agentic AI framework in the wake of the OpenAI attacks on Hugging Face.DARKREADING.COM
19 AugWeekly Threat Bulletin – August 19th, 2026These are the top threats you should know about this week.F5.COM
19 AugBehind the Cyber Creator: An AMA with Infosec Pat (Patrick Gorman)Patrick Gorman started making YouTube videos during COVID to study for a certification with friends. He now has over 100,000 subscribers and runs a pentesting firm called ISP Security. This is a replay of our Behind the Cyber Creator AMA series. Patrick and Gianna talk about how …THECYBERWIRE.COM
19 AugPrison for data analyst who tried to extort $2.5 million from his employerWhen Cameron Curry discovered that his contract as a data analyst wasn't going to be renewed, he could have updated his LinkedIn profile. He could have started sending out his resume. But what the 27-year-old from Charlotte, North Carolina, did instead was turn to extortion. Read…BITDEFENDER.COM
19 AugFlock Has a Powerful New AI Tool for Police. We Got Its CodeFlock’s surveillance cameras have already sparked outrage. WIRED reconstructed its next-generation AI system, already in use by some police, to confirm it goes much further than tracking license plates.WIRED.COM
19 AugUK Fraud Cases Hit Record High in 2026Cifas data finds account takeover and identity fraud are driving a surge in fraud casesINFOSECURITY-MAGAZINE.COM
19 Aug50,000 Stripe Secrets Leaked in Public CodeOver 50,000 exposed Stripe API keys show how leaked secrets can enable fraud, data access and account abuse within hours. Ransomnews researchers have documented a large-scale leak of Stripe merchant API keys found exposed in public code repositories, GitHub Actions logs, and misc…SECURITYAFFAIRS.COM
19 AugYour polite reply to that text is worth $2 on the dark webA polite reply to a wrong-number text may seem harmless. But scammers use it to profile their victims and fuel a multibillion-dollar fraud industry.MALWAREBYTES.COM
19 AugReverse-Lookup Service Exposed Millions of Photos of People’s FacesThe people-search tool ClarityCheck says its reverse image search service is “private and secure”—but it left a database containing more than 9 million image files exposed.WIRED.COM
19 AugICO Urges Police to Improve Data Governance in Facial Recognition RolloutsThe UK’s privacy watchdog has called on police using facial recognition to follow its recommendationsINFOSECURITY-MAGAZINE.COM
19 AugWindows 11 24H2 Home and Pro reach end of support in 2 monthsMicrosoft has reminded customers that systems running Home and Pro editions of Windows 11 24H2 will stop receiving updates in two months. [...]BLEEPINGCOMPUTER.COM
19 AugMicrosoft Tracks MacSync Stealer by Its Behavior, Not Its DomainsMicrosoft tracked over 30 MacSync Stealer domains by focusing on behavioral patterns, revealing a campaign targeting passwords, keys, wallets and other data. Domain blocking is a losing game when the thing you’re blocking can register a new domain faster than you can add it…SECURITYAFFAIRS.COM
19 AugScammers are using fake crypto AML checkers to drain your walletWe found wallet-checking sites impersonating real anti-money laundering services that trick people into approving access to scammers.MALWAREBYTES.COM
19 AugDescribing attacks with crime script analysisMartin explores how using crime script analysis to describe an attack with everyday language makes the situation accessible to non-technical audiences and identify points where the crime can be disrupted.TALOSINTELLIGENCE.COM
19 Aug3 Lessons for Securing Large-Scale Events: Inside FIFA World Cup 2026Lessons learned for securing large scale events and CIS's critical role as a partner supporting event security operations at the 2026 FIFA World CupCISECURITY.ORG
19 AugPhishing 3.0: The Fight Moves to Agent Versus AgentMost email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload, a bad link or an attachment. It stopped working when the danger moved into the message's intent, and it is failing…THEHACKERNEWS.COM
19 AugGrandoreiro Resurfaces in Mexico With New DLL Sideloading CampaignGrandoreiro is active after its 2024 disruption, with Mexico now accounting for 40% of detectionsINFOSECURITY-MAGAZINE.COM
19 AugSimple Scans for Cloud Metadata Service, (Wed, Aug 19th)Cloud providers typically expose a REST API at 169.254.169.254 that allows code running on virtual machines to retrieve machine-specific data. Some of the data is more or less harmless, such as the region the machine is running in or its MAC and IP addresses. However, the service…ISC.SANS.EDU
19 AugSideloading on Android: What it is, why it’s risky, and how to do it more safelyWith the new Advanced Flow for sideloading being rolled out, it's time to discuss what sideloading is and how to do it more safely.MALWAREBYTES.COM
19 AugWiz Penetration Test Findings is now GATransform point-in-time pen-tests into continuous exposure management with unified platform combining pen-test findings and real-time cloud contextWIZ.IO
19 AugPropagate user authorization context in AI agents with Amazon Bedrock AgentCoreMany teams now deploy AI agents that pull from Amazon DynamoDB tables, document repositories, software as a service (SaaS) platforms, and internal knowledge bases to answer questions and automate workflows. A key risk in these deployments is that the agent has no awareness of who…AWS.AMAZON.COM
19 AugResearchers say OpenAI revoked their access to limited cyber programMultiple cybersecurity researchers said they suddenly lost access to OpenAI’s Trusted Access for Cyber (TAC) program, which offers models with fewer guardrails for vetted users.TECHCRUNCH.COM
19 Aug41 deceptive download sites show a real link, then send you somewhere elseA legitimate-looking link or valid digital signature can offer false reassurance. Here’s why familiar download safety checks aren’t always enough.MALWAREBYTES.COM
19 AugFortinet has acquired San Francisco-based AI security company Virtue AI.Dynatrace has agreed to acquire San Francisco-based AI observability platform Arize for $915 million. Cribl has acquired technology assets from Radiant Security's AI SOC product.THECYBERWIRE.COM
19 AugNo-Filter 'Kriminal' AI Platform Raises Cybercrime ConcernsThe AI company officially forbids illicit use, while offering guardrail-free social engineering, offensive cybercrime, and OSINT scanning to anyone with a bit of cryptocurrency.DARKREADING.COM
19 AugOpenAI confirms ChatGPT is down as logins and signups failChatGPT is experiencing a major outage, and users are unable to sign in, create accounts, or load chats, including previous conversations. [...]BLEEPINGCOMPUTER.COM
18 AugMicrosoft starts removing WMIC tool used by cybercriminalsMicrosoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week. [...]BLEEPINGCOMPUTER.COM
18 AugThe Cop Who Took On FlockAfter Noel Pichardo called out his city's embrace of Flock surveillance cameras, he was subjected to five internal affairs investigations in less than two years.WIRED.COM
18 AugMicrosoft confirms outage affecting search in Microsoft 365 appsMicrosoft says some users are experiencing issues searching in Microsoft 365 apps, including Outlook on the web, Outlook desktop, SharePoint Online, and OneDrive. [...]BLEEPINGCOMPUTER.COM
18 AugWhat It Takes to Run the CIA's Southeast Asia DepartmentYou might find Meredith Cavan playing music in an Irish pub. But long before her first album dropped, she clocked more than 20 years at the CIA. One of her jobs there was Southeast Asia Department chief, where she oversaw covert action, intelligence operations, and analysis acros…THECYBERWIRE.COM
18 AugCan AI Coexist With Privacy? Proton’s Andy Yen Says It Will Have ToProton’s CEO is a champion of encryption for everyone. So why is he going all in on un-encryptable AI?WIRED.COM
18 AugBe careful what you put in “anyone with the link” Google DocsAs one developer found out when his Google Doc containing company passwords showed up in Google search results.MALWAREBYTES.COM
18 AugMicrosoft tests faster Windows File Explorer, new context menuMicrosoft has started testing a faster File Explorer and a less cluttered and more customizable context menu in Windows 11 preview builds rolling out to Insiders this week. [...]BLEEPINGCOMPUTER.COM
18 AugAnnouncing the 2026 Wiz Partner Alliance Award WinnersRecognizing the partners, integrators, and visionaries driving cloud security transformation, AI risk management, and SOC modernization across AMER, EMEA, and ANZ.WIZ.IO
18 AugAI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt FilesSecurity researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that autonomous agent harnesses use to carry state between session…THEHACKERNEWS.COM
18 AugHackers target Ukrainian agency managing assets seized from sanctioned RussiansThe agency said the latest attack came amid preparations to select a manager for seized corporate rights in IDS Ukraine, one of the country’s largest producers of bottled mineral water and beverages.THERECORD.MEDIA
18 AugMeta Ran Ads for an App That Promised to Nudify Female PoliticiansOne advertisement featured a pornographic video with a deepfake closely resembling a prominent US politician. Apple removed the app from the App Store after an inquiry from WIRED.WIRED.COM
18 AugNASA Ground Control Software Flaw Enables Unauthenticated CommandsCritical AIT-GUI flaws expose spacecraft commands and scripts to unauthenticated attackersINFOSECURITY-MAGAZINE.COM
18 AugYour Controls Block Known Attacks. What About the Behavior?Security controls can block a familiar attack method while missing quieter ways to achieve the same objective. Picus Security's Blue Report 2026 shows how prevention rates can vary dramatically by technique and why behavioral testing is needed to uncover those gaps. [...]BLEEPINGCOMPUTER.COM
18 AugBluesky says its recent outage was caused by another DDoS attackThis is the latest large-scale DDoS attack to hit the social networking site this year.TECHCRUNCH.COM
18 AugApple fixes another image-processing flaw that could allow code executionApple has released updates fixing 27 vulnerabilities in iOS, iPadOS, and macOS Tahoe, including a potentially serious image-processing flaw.MALWAREBYTES.COM
18 AugWiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security MissedThe security flaw in Snowflake’s GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcherINFOSECURITY-MAGAZINE.COM
18 AugComcast adds motion sensing to millions of its newer routers, with a privacy catchA new feature added to Comcast's newest routers can detect if there is motion is inside your home without needing traditional motion sensors.TECHCRUNCH.COM
18 AugHow to Spot and Stop Rogue Device JoinsInstead of leaving behind recognizable fingerprints from public tooling, adversaries can now generate realistic device names that blend naturally into enterprise environments. This blog explores how that changes Entra ID detection and what are the behavioral signals that still ex…WIZ.IO
18 AugProject noRecognition: Teaching AI to Fool Surveillance CamerasResearchers tested 31 million patterns to disrupt surveillance AI, with promising results but significant gaps between simulation and real-world use. The Kansas City-based cybersecurity researcher Bill Swearingen spent the past year doing something that sounds almost too simple t…SECURITYAFFAIRS.COM
18 AugOpenAI Overhauls Safety Protocols After Its AI Agents Went RogueThe ChatGPT maker says its upcoming Astra model may have reached “critical” cyber capabilities, prompting it to halt a significant number of training runs while it tightens internal safeguards.WIRED.COM
18 AugComcast turns your Xfinity WiFi into a home motion detectorComcast is promoting WiFi-based motion detection as a part of its new Xfinity Shield home protection platform, allowing routers and wireless devices to detect people moving through a home without cameras or motion sensors. [...]BLEEPINGCOMPUTER.COM
18 Aug'CoSnitch' Attack Tricked Copilot into Mapping Out ArchitectureResearchers discovered a "meta-hacking" technique that can manipulate the AI service into revealing its own security weaknesses.DARKREADING.COM
17 AugWhy more security data has blurred companies’ view of riskMore security data can create blind spots. Here’s how to regain visibility.CYBERSECURITYDIVE.COM
17 AugInvisible AI Prompts Trigger Court SanctionsA litigant hid AI prompt injections in a court filing to influence a ruling. The judge caught it and banned him from electronic filing. A man suing the New York Bariatric Group reportedly hid AI prompt in a court filing, instructing any AI system that read it to rule in his favor…SECURITYAFFAIRS.COM
17 AugMcDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records StolenA seller claims 1.7M McDonald’s employee records were stolen from Azure. An 8,000-row sample appears genuine, but its age and full size remain unconfirmed. A seller on a data-trading forum posted an 8,000-row sample this week claiming it came from McDonald’s own Azure tenan…SECURITYAFFAIRS.COM
17 AugWhy Facebook’s war on ad blockers could help scammersOne ad blocker is giving up the fight against Facebook ads. The consequences could go beyond annoying advertising.MALWAREBYTES.COM
17 AugFake TikTok rewards promise cash you’ll never getTikTok-branded rewards pages offer cash for simple tasks and daily check-ins. But getting your hands on the money is another story.MALWAREBYTES.COM
17 AugETSI Proposes 17 Cybersecurity Standards to Support Cyber Resilience ActThe European Telecommunications Standards Institute has launched an approval process for standards vendors will have to meet under the Cyber Resilience ActINFOSECURITY-MAGAZINE.COM
17 AugHow MCP Servers Can Expose Enterprise SecretsMCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running. As more organizations adopt AI agents into their systems, that exposure can silently become…THEHACKERNEWS.COM
17 AugCrypto hardware wallet owners face fresh security risks after recent spate of personal data theftsThe hacks at shipping companies used to mail out hardware wallets puts crypto owners at greater risk of real-world attacks.TECHCRUNCH.COM
17 AugThe Closed Loop Remediation Playbook with WizStart your path to a self-healing cloud today, with Wiz Workflows now GA and Remediation and Response in public preview.WIZ.IO
17 AugShieldBreak bypasses Microsoft’s patch for earlier Defender flawThe researcher who found RoguePlanet has discovered ShieldBreak, a new way to bypass Microsoft’s fix and gain SYSTEM privileges.MALWAREBYTES.COM
17 AugAn “invisible” car? Researcher uses machine learning to hide vehicles from Flock camerasA cybersecurity expert has demonstrated how computer-generated patterns can successfully prevent surveillance cameras from detecting vehicles - such as the controversial AI-powered Flock licence plate readers that are becoming increasingly common on American streets. Read more in…BITDEFENDER.COM
17 AugMicrosoft confirms GitHub is down worldwideGitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other services. [...]BLEEPINGCOMPUTER.COM
17 AugUpdates to your AWS Sign-In experienceAmazon Web Services (AWS) is gradually introducing updates to the AWS Sign-In and sign-up experience to a limited number of customers. We’re sharing these changes so you will know what to expect as we gradually make the updated experience available to more customers. These update…AWS.AMAZON.COM
17 AugVishing: An Evolving Threat to SLTT OrganizationsThe CIS CTI team assesses vishing will continue to pose a risk to U.S. SLTT organizations. Read the team's analysis and recommendations.CISECURITY.ORG
17 AugAdam Shostack Talks Hugging Face & PHANTOM-BWorld-class threat modeler Adam Shostack shared he was "blown away" by OpenAI's revelations about the Hugging Face attack, and explains why his new threat model for LLMs is both "lightweight yet still usable."DARKREADING.COM
16 AugFrontier models and the future of cyber defense.In this special edition from Black Hat, Dave Bittner sits down with Clint Gibler, Cyber Lead at OpenAI, and Robby Winchester, Chief Global Professional Services Officer at SpecterOps, to explore how frontier AI models are changing the way defenders approach cybersecurity.…THECYBERWIRE.COM
16 AugLarge-scale DDoS attacks disrupted Threema secure messaging serviceMultiple distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service earlier this week, causing severe disruptions to communications. [...]BLEEPINGCOMPUTER.COM
16 AugAnthropic confirms Claude is down in major outage affecting multiple servicesClaude is experiencing a major outage, with users reporting login problems and degraded performance across several Anthropic services. [...]BLEEPINGCOMPUTER.COM
16 AugDDoS Attacks Cause Major Threema OutagesLarge DDoS attacks disrupted Threema, causing severe communication outages. Threema On-Prem users were unaffected by the attacks. Threema suffered multiple large-scale DDoS attacks that disrupted its secure messaging service and caused severe communication issues. Organizations u…SECURITYAFFAIRS.COM
14 AugUS Authorizes Private Cyber Firms to Hack Transnational Criminal NetworksTrump authorizes vetted US cybersecurity firms to conduct government-approved cyber operations against transnational criminal networks. President Trump signed a national security memorandum on August 13 establishing a formal program that allows vetted private US cybersecurity com…SECURITYAFFAIRS.COM
14 AugData analyst sent to prison for stealing data, extorting employerA former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme. [...]BLEEPINGCOMPUTER.COM
14 AugWho’s Tracking You? Use This New Service to Find OutIt can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away i…KREBSONSECURITY.COM
14 AugWhatsApp is testing a new warning for scam messagesAn optional new feature uses on-device AI to flag messages that look like scams.MALWAREBYTES.COM
14 AugCyera's Oasis Security Buy is All About AI Agent ControlThe $1 billion deal aims to converge data security and identity into a single control plane for agents, with privileged access redefined around business context rather than static roles.DARKREADING.COM
14 AugThe Modern Attack Chain: Rethinking Google Workspace Security in the Age of AIGoogle Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive, and connected systems. Material Security explains why organizations need defenses that cover the entire Workspace attack chain. [...]BLEEPINGCOMPUTER.COM
14 AugWhat Boards Need to Know About Tech RiskWhy do so many boards underestimate technology risk until it becomes a crisis?DARKREADING.COM
14 AugSecuring Data in the AI eraAI is changing the context around data risk, making it critical to understand what’s connected, what’s exposed, and why.WIZ.IO
14 AugWiz on Wiz: How the Wiz FinOps Team Uses Wiz Cloud CostPowering cost investigation and optimization with deep cloud contextWIZ.IO
14 AugRecent Water Utility Attacks Offer a Blueprint for ResilienceRecent attacks on water systems offer a blueprint for resilience. Explore five lessons utilities can use to strengthen cybersecurity and operations.CISECURITY.ORG
14 AugWhat we know about the alleged Iranian hacks on US water utilitiesOver the last couple of weeks, hackers have targeted and broken into the systems of several water plants in the United States. Here’s what we know and don’t know about this wave of attacks allegedly carried out by the Iranian government.TECHCRUNCH.COM
14 AugInvestigation of banking hack leads to arrests in Germany, BrazilGermany’s federal police agency, the BKA, said three suspects were picked up in Europe and charged with fraud, and Brazil’s federal police said four others were arrested on similar charges.THERECORD.MEDIA
14 AugNew York City Lawmakers Push to ‘Ban the Scan’ at MSGAt a press conference outside Madison Square Garden, politicians, musicians, and privacy advocates argued for tighter restrictions on how public venues deploy biometric surveillance.WIRED.COM
14 AugHow Anthropic plans to watermark Claude's AI-generated textIt could soon become easier to identify AI-generated content, even if it's not the usual "It's Not X, it's Y" type of post you'd come across on LinkedIn and other socials. [...]BLEEPINGCOMPUTER.COM
13 AugSurveillance Rulings and Social Media Scrutiny.This week, Ben and Ethan discuss two major stories. The first looks deeper into the Supreme Court's recent ruling on the Chatrie case and the long-term impacts this decision could have on privacy within the nation. The second dives into another court case decision, which exposes …THECYBERWIRE.COM
13 AugParents take on Meta, TikTok, Google, and Snap in 3,000 youth safety lawsuitsIt's the biggest legal challenge yet to addictive social media design and its impact on children.MALWAREBYTES.COM
13 AugCBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and ColleaguesRecords obtained by WIRED detail hundreds of allegations of Customs and Border Protection workers misusing internal tools to look up romantic interests and track colleagues’ cell phones.WIRED.COM
13 AugDissecting the JWR phishing frameworkCisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms.TALOSINTELLIGENCE.COM
13 AugWhatsApp rolls out new feature that flags potential scam messagesWhatsApp has begun rolling out a new optional "Scam Alert" feature, which uses a local machine learning model to warn users when scammers are targeting them. [...]BLEEPINGCOMPUTER.COM
13 AugTrump Authorizes Private Sector Participation in Offensive Cyber OperationsThe White House has authorized government-directed offensive cyber operations against transnational groups, prompting warnings over escalation and attribution risksINFOSECURITY-MAGAZINE.COM
13 AugBrazil orders Discord to suspend livestreaming after teen suicideDiscord's Go Live feature contributed to a 13-year-old girl's death by suicide, according to Brazilian regulators, who told the company to suspend the streaming technology.THERECORD.MEDIA
13 AugWhite House taps security firms for offensive hack-back operationsA new White House memo signed by U.S. President Donald Trump instructs the National Coordination Center (NCC) to establish a program that would allow private security companies to apply for approval to hack foreign cybercrime organizations. [...]BLEEPINGCOMPUTER.COM
13 AugGoogle Cloud Targets 2027 for First Major Post-Quantum Security MilestoneGoogle Cloud has set a 2027 deadline to mitigate store-now-decrypt-later risks as part of its post-quantum cryptography roadmap, with wider migration goals extending through 2028INFOSECURITY-MAGAZINE.COM
13 AugFlock tightens privacy controls amid scandals over officer abuseAll Flock Safety customers will be required to adopt its "Audit Assistance" feature for tracking abnormal uses, and the company says it will hold license plate data for only seven days in most cases.THERECORD.MEDIA
13 AugHow to Investigate GitHub PAT Compromise: Lessons From a Multi-Organization CampaignA practical playbook for investigating GitHub token compromise, drawn from Wiz CIRT's response to a coordinated multi-organization campaign.WIZ.IO
13 AugUS private equity firms targeted by hackers.More jurisdictions continue to cut ties with Flock.THECYBERWIRE.COM
13 AugHow Frontier Models Are Reshaping Cyber Defense with Clint Gibler from OpenAI and Robby Winchester from SpecterOpsClint Gibler, Cyber Lead at OpenAI, and Robby Winchester, Chief Services Officer at SpecterOps, join Dave Bittner for a discussion recorded live at Black Hat USA 2026. Together, they explore how frontier AI models are changing cyber defense, where AI creates the greatest value fo…THECYBERWIRE.COMHTTPS:
13 AugAWS Certificate Manager will discontinue email validation to prove domain validation for certificatesToday, we’re announcing that AWS Certificate Manager (ACM) will discontinue support for email-validated public certificates by September 30, 2027. If you use email validation for your ACM public certificates, you need to migrate to DNS validation before that date. This change ali…AWS.AMAZON.COM
13 AugUkraine shuts down 94 fraudulent call centers, seize millions in cashAuthorities in Ukraine shut down 94 fraudulent call centers across the country that lured people into investment scams or tried to obtain access to bank accounts. [...]BLEEPINGCOMPUTER.COM
12 AugWeekly Threat Bulletin – August 12th, 2026These are the top threats you should know about this week.F5.COM
12 AugZoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's ClientAnyone sharing their screen on a Zoom call could have taken over the computers of everyone watching, and anyone watching could have taken over the presenter's. The flaw sat in the annotation tool, the feature that lets participants draw and type on a shared screen, and it asked n…THEHACKERNEWS.COM
12 AugCapability Is Closing the Open-Closed Gap; Security Is NotA competitive open-weight model, Claude Fable, and Jade Puffer.F5.COM
12 AugWhen to Pay for Analyst Relations and When Not To with Kelly O'Dwyer ManuelKelly O'Dwyer Manuel has been building analyst relations (AR) programs for a long time, and her first question is always the same when starting from scratch: what are you actually trying to accomplish? She joins Gianna and Andy T to talk through what AR looks like for a small tea…THECYBERWIRE.COM
12 AugRussian-Linked Hackers Accessed Polish Power Plant OT Network Through Private APN, Says CERT.PLThe Polish CERT has released details of another 2025 attack on a combined heat and power plant in the countryINFOSECURITY-MAGAZINE.COM
12 AugThis Coin-Sized Device Can Hack a Boeing 737Security researchers found that in less than 60 seconds, they could open a hatch on a plane’s exterior, plug in a tiny device, and redirect the aircraft’s autopilot or sabotage its flight plan.WIRED.COM
12 AugWalmart Leaders Transform Security Operations Without Going BananasThe big-box giant has scaled its defenses by encouraging trust and innovation. Good communications, transparency and team spirit are key factors.DARKREADING.COM
12 AugEnterprise Defenses Recovered at the Edge and Collapsed InsideEnterprise defenses are tuned to catch the attacks that make noise. This year's data shows attackers winning by making none. According to Picus Labs' new Blue Report 2026, which measured more than 338 million real attack simulations across actual client production environments in…THEHACKERNEWS.COM
12 AugLinux Kernel Process Accounting, (Wed, Aug 12th)A couple of days ago, Xavier posted about Atuin to gain more insight into the command history. Atuin does a great job of better organizing what is usually handled by "bash&#;x26;#;x5f;history"&#;x26;#;xc2;&#;x26…ISC.SANS.EDU
12 AugFBI: Hackers target online accounts to steal nude photosThe FBI warns that cybercriminals are targeting adults' and children's social media and other online accounts to steal sexually explicit images or videos. [...]BLEEPINGCOMPUTER.COM
12 AugHackers abuse AI models to find new entry pathsNetwork defenders are racing to secure their IT systems before criminal and state-actors circumvent existing guardrails.CYBERSECURITYDIVE.COM
12 Aug“Zoomsday” flaws could let one Zoom participant attack anotherUpdate Zoom now to protect against critical vulnerabilities that could allow an attacker in the same meeting to run malicious code on your device.MALWAREBYTES.COM
12 AugWalmart's "Trusted Agent" Approach to Purple TeamingWalmart co-locates red and blue teams to build trust and improve security through collaborative purple teaming exercisesDARKREADING.COM
12 AugHundreds of fake Chrome VPN extensions route traffic through a proxyMore than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users' traffic through SOCKS5 proxies operated by a single provider. [...]BLEEPINGCOMPUTER.COM
12 AugCorma raises $60 million in seed funding.Visa and Deel both acquire identity verification companies.THECYBERWIRE.COM
12 AugHow AWS IAM role manager rethinks the starting point for IAM rolesWhen you build a new application or capability on Amazon Web Services (AWS), you want to focus on what you’re building. Getting a service running almost always begins with AWS Identity and Access Management (IAM). Many AWS services that act on your behalf need an IAM role, an ide…AWS.AMAZON.COM
11 AugBetween Two Nerds: The cyber resistance!In this edition of Between Two Nerds Tom Uren and The Grugq talk about examples of cyber resistance and whether they achieve their goals. This epsiode is also available on YouTube.RISKY.BIZ
11 AugWatch out for fake TikTok Shops trying to steal your moneyTikTok Shop is huge, so it's no wonder that impersonation shops have popped up. Here's how to stay safe.MALWAREBYTES.COM
11 AugFake popular sites offer a free app, instead take over PCsFake branded download pages are tricking Windows users into installing legitimate remote-access software that's being abused by attackers.MALWAREBYTES.COM
11 AugProject CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selectionProject CAV3RN targets Israel with Google Apps Script C2 relays and DNS-based routing. Modular .NET NativeAOT framework blends C2 traffic with legitimate Google services to evade detection.SECURELIST.COM
11 AugOpenAI Pauses Some Development of Astra Model on Security ConcernsOpenAI is tightening restrictions on testing of its upcoming Astra model due to security concernsINFOSECURITY-MAGAZINE.COM
11 AugResearchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine. The same PnP path can be triggered over Remote Desktop wi…THEHACKERNEWS.COM
11 AugOpenAI Launches Two-Tier Security Access Program Alongside GPT 5.6 CyberDaybreak Blue removes some OpenAI-made guardrails while Daybreak Red grants the use of cyber-focused frontier AI modelsINFOSECURITY-MAGAZINE.COM
11 AugMozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private RepoMozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake to one of the company's own private code repositories. That key is how a user, or a Linux distribution packaging the browser, con…THEHACKERNEWS.COM
11 AugLove/hate relationship: The AI affair. Young people love AI, but it’s breaking their trustThe same technology making our lives easier is also making it harder. How are young people navigating this new world?MALWAREBYTES.COM
11 AugA Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a CallResearchers say it took fewer than 20 prompts for a public AI tool to find a flaw (now fixed) allowing anyone on a Zoom call to hijack another participants’ device.WIRED.COM
11 AugSexual predators targeting online accounts for intimate images, FBI warnsThe FBI is warning that criminals are breaking into social media to steal and distribute non-consensual intimate images and videos.MALWAREBYTES.COM
11 AugMozilla updates GPG signing key for Firefox releases after exposureMozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub. [...]BLEEPINGCOMPUTER.COM
11 AugDDoS attacks over 1 Tbps surged fivefold in the second quarterCloudflare says it mitigated more than 800 network-layer distributed denial-of-service (DDoS) attacks exceeding 1 Tbps in the second quarter of the year. [...]BLEEPINGCOMPUTER.COM
11 AugSix npm Packages Read C2 Addresses From Ethereum WalletSix npm packages queried an Ethereum wallet to locate C2 infrastructureINFOSECURITY-MAGAZINE.COM
11 AugCursor Security Bug Allowed Repositories to Execute Commands Before Trust VerificationCursor fixed a pre-trust code execution path in three days then closed the report as informativeINFOSECURITY-MAGAZINE.COM
11 AugAWS successfully completed its 2025-26 NHS DSPT assessmentAmazon Web Services (AWS) is pleased to announce its successful completion of the 2025-26 NHS Data Security and Protection Toolkit (NHS DSPT) assessment audit and achieving a status of Standards Exceeded. The NHS DSPT is an assessment that allows organizations to measure their pe…AWS.AMAZON.COM
11 AugValve warns Steam hardware buyers: Expect fake delivery scamsThe warning affects recent buyers of Steam hardware, including the hugely popular Steam Deck.MALWAREBYTES.COM
11 AugSocial media platforms crack down on drone factory recruiting gameResearchers found that games and major US social media platforms were used to lure young people into jobs in Russia's drone industry.MALWAREBYTES.COM
11 AugWindows 11 KB5121003 & KB5120240 cumulative updates releasedMicrosoft has released Windows 11 KB5121003 and KB5120240 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. [...]BLEEPINGCOMPUTER.COM
11 AugSummer 2026 SOC 1 report is now available with 185 services in scopeAmazon Web Services (AWS) is pleased to announce that the Summer 2026 System and Organization Controls (SOC) 1 report is now available. The reports cover 185 services over the 12-month period from July 1, 2025–June 30, 2026, giving customers a full year of assurance. These report…AWS.AMAZON.COM
11 AugDelta probes Wi-Fi deauth attack on flight carrying DEF CON attendeesDelta Air Lines is investigating an unauthorized Wi-Fi network that appeared aboard a flight from Las Vegas to Atlanta carrying passengers who had attended the DEF CON hacker convention. [...]BLEEPINGCOMPUTER.COM
11 AugFBI says cybercriminals are hacking into victims’ online accounts to steal their intimate picturesIn a new alert, the FBI said cybercriminals are targeting adults and minors in an attempt to steal their personal and intimate pictures in extortion campaigns.TECHCRUNCH.COM
11 AugGoogle says Chrome cuts 7 billion unwanted Android notifications a day to fight abuseGoogle says Chrome's anti-abuse systems reduced unwanted notifications on Android by more than 7 billion per day during the first quarter of 2026. [...]BLEEPINGCOMPUTER.COM
10 AugOpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger PauseOpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation found it had made significant advancements in agentic coding and cybersecurity. In response to the discovery, the AI upst…THEHACKERNEWS.COM
10 AugUS Sanctions Iranian $6bn Crypto “Exchange” ShelbitTRM Labs explains that sanctioned Iranian firm Shelbit was a fake crypto exchangeINFOSECURITY-MAGAZINE.COM
10 AugA GitHub Misconfiguration Let Kimi K3 Cheat a Cybersecurity BenchmarkKimi K3 bypassed a UK cybersecurity test by accessing GitHub, cloning the benchmark and reading its solutions instead of solving the challenge Sometimes the smartest move isn’t solving the puzzle, it’s noticing nobody locked the door to the answer key. That’s es…SECURITYAFFAIRS.COM
10 AugShipping 10–50× More Code? Watch This Webinar on Securing AI-Speed DevelopmentAI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. When software output jumps 10 to 50 times, the problem is no longer just finding vul…THEHACKERNEWS.COM
10 AugEdge is dropping older extensions, affecting popular privacy toolsMicrosoft is retiring Manifest V2, the technology behind older Edge extensions. Some popular privacy tools will lose features or stop working.MALWAREBYTES.COM
10 AugMember of The Com sent to prison for blackmail, sextortionA member of "The Com," a loose-knit online cybercrime collective that targets children and teenagers, has been sentenced to two years in prison for blackmail and sextortion offenses against nearly 120 victims worldwide. [...]BLEEPINGCOMPUTER.COM
10 AugLexisNexis shuts down services after suspicious activity on serversLexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor. [...]BLEEPINGCOMPUTER.COM
10 AugBritish ‘Com’ member who abused more than 100 girls worldwide jailed for two yearsJustin Swaddle, of Leeds in northern England, targeted 117 female victims aged 13 to 17, according to the National Crime Agency.THERECORD.MEDIA
10 AugWhen Credentials Are No Longer Enough: Device Trust in the AI EraAI is making phishing, credential theft, and social engineering faster and more efficient, while traditional trust signals such as passwords, MFA, IP reputation, and geolocation become easier to bypass. Specops explains why organizations are increasingly adding device trust to th…BLEEPINGCOMPUTER.COM
10 AugSigned up for Klaviyo? Dozens of advertisers may have seen your passwordA bug in the tech giant's website mistakenly shared users' sign-up information, including personal data and their password, to third-party companies.TECHCRUNCH.COM
10 AugNew turnkey kit makes it easy for anyone to become a scammerWe discovered a kit that gave us an insight into how modern online scams are built, promoted, and potentially used to target everyday consumers.MALWAREBYTES.COM
10 AugScans for Solana (Surfpool?) Endpoints, (Mon, Aug 10th)Solana is a crypto platform known for speed. Developers like it to develop distributed applications or to implement crypto payments. To interact with the blockchain, APIs are provided for developers. These APIs will either "speak" JSON or gRPC. One implementation often used for d…ISC.SANS.EDU
10 AugOutdated Cybercrime Laws Put Security Researchers at RiskA public policy expert mapped global cybercrime laws to develop a five-point framework for protecting ethical hackers and good-faith security research.DARKREADING.COM
10 Aug2026 AWS CyberVadis report now available for due diligence on third-party suppliersWe’re excited to announce that Amazon Web Services (AWS) has completed theCyberVadis assessment of its security posture with the highest score (Mature) in all assessed areas. This demonstrates our continued commitment to meet the heightened expectations for cloud service provider…AWS.AMAZON.COM
10 AugThe Patch Gap: Why Defenders Need to Think in Chains, Not ChecklistsIt's time to turn from CVSS-backed patching to choke-point patching focused on breaking chains to critical assets.DARKREADING.COM
10 AugAWS completes the 2026 Police-Assured Secure Facilities (PASF) audit in Europe (London)We’re excited to announce that our Europe (London) AWS Region has renewed its accreditation for United Kingdom (UK) Police-Assured Secure Facilities (PASF) for Official-Sensitive data. Since 2017, the Amazon Web Services (AWS) Europe (London) Region has been accredited under the …AWS.AMAZON.COM
10 AugMultistate Water System Attacks Widen, Iran SuspectedAttacks targeting water systems just keep flowing across a dozen states, against ill-secured, Internet-exposed PLCs.DARKREADING.COM
10 Aug'GhostJacking' Exposes Identity Governance Gaps in AI AgentsNew research shows how attackers can use security alerts and blocked events to manipulate and hijack AI agents.DARKREADING.COM
9 AugWebmail CSS Attacks Expose a New Risk for AI-Powered Email ToolsCSS attacks on major webmail services can steal credentials, hijack sessions and manipulate AI tools connected to users’ inboxes. PortSwigger researcher Gareth Heyes demonstrated something that should make every webmail team a little nervous: plain CSS, the styling language that&…SECURITYAFFAIRS.COM
9 AugThis ‘adversarial’ pattern can prevent surveillance cameras from detecting youA security researcher has designed an algorithm that can create computer-generated patterns capable of hiding people, faces, and vehicles from detection by surveillance cameras.TECHCRUNCH.COM
8 AugAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to AttackersAttacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirm…THEHACKERNEWS.COM
8 AugSensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It AllTwo security researchers bought cheap domains—including noreply.net and deleteduser.com—and set up email listening services. Hundreds of companies are sending them corporate secrets.WIRED.COM
8 AugGoogle’s top hacker hunter explains why hacking groups get codenamesGoogle recently changed how it refers and assigns names to hacking groups. TechCrunch spoke with one of the world’s foremost experts on tracking hackers to understand why companies give hackers codenames.TECHCRUNCH.COM
7 AugLinux Shell Forensic: Let?s Dive Into Atuin!, (Fri, Aug 7th)UNIX systems (including Linux) are well-known to record a lot of activities in many different locations. But there is one domain where they definitely lack of "modern" logging: shells. Most shells provide an historization of the typed commands through a flat file in the $HOM…ISC.SANS.EDU
7 AugAI Deepfakes Used to Impersonate OnlyFans Creators in New ScamScammers use AI deepfakes to impersonate OnlyFans creators, trick fans into sending money, then disappear after payment. Criminals are building fake identities using AI-generated deepfakes of real OnlyFans creators, luring their followers with promises of live chats, and then dis…SECURITYAFFAIRS.COM
7 AugClaude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow SecretsA GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough to hijack the next agent run. Novee Security ran the attack against each vendor…THEHACKERNEWS.COM
7 AugGoogle Links Redact Extortion Group to BlackFile RebrandBlackFile has rebranded as Redact after an alleged affiliate hijack, with Google linking the group to ongoing vishing and extortion campaignsINFOSECURITY-MAGAZINE.COM
7 AugMicrosoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance EmailsCybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gath…THEHACKERNEWS.COM
7 AugMeta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico CaseMeta was ordered to pay $567M after a judge ruled its platforms harmed children, bringing New Mexico penalties to $942M. Meta ‘s child-safety legal bill just got another half-billion dollars heavier. A New Mexico state judge ruled that company’s platforms constitute a…SECURITYAFFAIRS.COM
7 AugChinese AI model Kimi escaped its cybersecurity testing environment, researchers sayIn the Kimi test, the sandbox designed to contain the experiment was not properly configured.TECHCRUNCH.COM
7 AugBeware cut-price AI services that read your every wordf someone offered you 90% off the official price to access Claude, the powerful AI model from Anthropic, would you be tempted? It turns out that around 900 people were, and they may be regretting their decision. Read more in my article on the Fortra blog.FORTRA.COM
7 AugAI-Generated Patches Fail Half the TimeA study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass.DARKREADING.COM
7 AugNew Mexico judge orders Meta to pay $567 million in kids online safety caseThe money will be used to create a fund to mitigate social media harms, including by carving out $420 million for treatment for New Mexico youth who have been hurt on the platforms.THERECORD.MEDIA
7 AugWater utilities group partners with DEF CON offshoot for Water Watch CenterThe National Rural Water Association and a group of cybersecurity experts have formed a program to help cash-strapped utilities face the increase in threats to their systems.THERECORD.MEDIA
7 AugSecurity researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacksResearchers found common points of failure, like software used to organize and display web content, could have allowed hackers to run riot through government websites.TECHCRUNCH.COM
7 AugAI chat bots are sliding into League of Legends friend requestsChat bots are sending friend requests in Riot immediately after ending your game. What are the scammers up to now?MALWAREBYTES.COM
7 AugMeta ordered to pay $942 million over harm to childrenA new court ruling not only fined Meta to the extent of $942 million but also ordered it to improve its age assurance tools.MALWAREBYTES.COM
6 AugCanadian Hacker Pleads Guilty Over Snowflake Extortion CampaignA Canadian hacker has admitted involvement in the widespread compromise of 165 Snowflake customer accounts used to steal data and extort victimsINFOSECURITY-MAGAZINE.COM
6 AugScammers target OnlyFans users with deepfakesCriminals are impersonating OnlyFans creators using AI tools in order to scam followers.MALWAREBYTES.COM
6 AugAmazon and Apple impersonated in “$149.99 unauthorized charge” scamDifferent logos, different color schemes, same scam.MALWAREBYTES.COM
6 AugAnthropic’s Mythos AI used social engineering to target real peopleTesters found that Anthropic's AI agent Mythos attempted to social engineer Github developers into accepting malicious code.MALWAREBYTES.COM
6 AugViolent Physical Crypto Thefts Surge to $30m in LossesSo-called “wrench attacks” have resulted in $30m in losses so far in 2026, says ChainalysisINFOSECURITY-MAGAZINE.COM
6 AugCryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet AppsCoinspect has identified CryptoJS.lib.WordArray.random() as the weak random number generator behind the Ill Bloom wallet drains. Introduced in the JavaScript cryptography library 12 years ago, the function supplied weak entropy that affected wallet apps used to generate recovery …THEHACKERNEWS.COM
6 AugHow AI Exposed a Browser Security Gap that Enterprises Cannot IgnoreAI did not create a new browser security problem. It exposed one that enterprises have long been able to ignore. Skyhigh Security explains why browsers have become a critical control point for governing data movement, AI interactions, and modern work. [...]BLEEPINGCOMPUTER.COM
6 AugApple WebKit vulnerabilities reveal your IP address, despite Private RelayResearchers have found three methods to bypass Apple's Private Relay which is supposed to shield users' IP addresses and location.MALWAREBYTES.COM
6 AugTeamPCP Traced Back to 2020 Cryptojacking OperationOligo Security has linked TeamPCP to ShadowRay 2.0 and to cryptojacking infrastructure dating back to 2020INFOSECURITY-MAGAZINE.COM
6 AugCloud Threat Highlights: H1 2026Cloud and AI threat activity tracked by Wiz Research and CIRT, January through June 2026WIZ.IO
6 AugNew Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUsAn unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using it, re-poisoning the predictor after the defense has run. MIT CSAIL researchers Daniël Trujillo and Mengjia Yan named the techni…THEHACKERNEWS.COM
6 AugHacker pleads guilty to stealing data from more than 165 Snowflake customersConnor Moucka pled guilty to hacking and stealing data from more than 165 Snowflake customers, which net him and his accomplices more than $2.5 million in ransom payments.TECHCRUNCH.COM
6 AugCaching KMS data keys in multi-thread environments: Per-tenant encryption for event-driven systems at scaleThis post assumes familiarity with envelope encryption and the AWS Encryption SDK. When your encryption system generates millions of duplicate API calls per hour, costs spiral and performance degrades. That’s exactly the challenge NICE Actimize faced while operating their global-…AWS.AMAZON.COM
6 AugExposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance RecordsAn exposed SISVISA database leaked 102,215 Brazilian health records, exposing IDs, tax data, and regulatory documents without authentication. Researcher Jeremiah Fowler found a publicly accessible database that turned out to belong to SISVISA, Brazil’s Health Surveillance Informa…SECURITYAFFAIRS.COM
6 AugCisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score BugsCisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review. The security issues affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and…THEHACKERNEWS.COM
6 AugGoogle says hackers are calling financial firm employees to hack and extort victimsGroups of hackers are breaking into large U.S. financial firms to steal sensitive data and extort victims, Google’s security researchers report.TECHCRUNCH.COM
6 AugWhy metaphor may dictate your security strategyIn this week's newsletter, Martin looks at how the metaphors we use to describe AI "escaping" its sandbox can completely change how we react to the threat.TALOSINTELLIGENCE.COM
6 AugFrom Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First CultureFormer chief security officers of the Democratic National Committee explain that a strong security-first mindset requires executive support – and a dose of absurdity.DARKREADING.COM
6 AugSecurity StagflationWhat's security stagflation look like? The cost of finding bugs is down, but the cost of fixing them is the same. Here's what CISOs need to know.CISECURITY.ORG
6 AugStrengthening Cyber Resilience Through Education via Essential Cyber Hygiene BootcampEssential Cyber Hygiene Fundamentals Bootcamp helps cyber practitioners implement CIS IG1 Safeguards, reduce risk and strengthen organizational resilience.CISECURITY.ORG
6 AugAutomate certificates with ACME support in AWS Certificate ManagerCustomers tell us that managing TLS certificates at scale is one of their biggest operational concerns. The Certification Authority Browser Forum (CA/Browser Forum) has mandated a phased reduction in maximum certificate validity for public certificates. By March 2027, the maximum…AWS.AMAZON.COM
6 AugOpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for itOpenAI is rolling out a more reliable version of ChatGPT GPT-5.6 Sol for Plus and Pro users, while Free users are getting unlimited text chats with GPT-5.6 Luna. [...]BLEEPINGCOMPUTER.COM
5 AugWeekly Threat Bulletin – August 5th, 2026These are the top threats you should know about this week.F5.COM
5 AugSMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control AccessSMOKE#SCREEN uses fake Zoom updates to install ScreenConnect RMM, giving attackers persistent remote access while bypassing defenses. Securonix Threat Research has been tracking an active multi-wave campaign they’ve named SMOKE#SCREEN, in which unknown attackers use rotatin…SECURITYAFFAIRS.COM
5 AugFrontier Models Engage in Unsanctioned Behavior During TestingAnthropic and OpenAI models attacked “real people and organizations” during AI Security Institute testsINFOSECURITY-MAGAZINE.COM
5 AugJunk Cleaner clears the clutter from your AndroidThe easiest way to reclaim storage on your phone. Free up space without hunting through folders or risking your important files.MALWAREBYTES.COM
5 AugHow the Canadian Centre for Cyber Security used frontier AI to accelerate detection engineeringDiscover how CSE's Frontier AI Lab is exploring the ways artificial intelligence can strengthen cyber defence, beginning with detection engineering.CYBER.GC.CA
5 AugAnthropic AI agent faked identities, phished real developers in UK government hacking testAn artificial intelligence agent built by Anthropic independently planted malicious code in a real software project and sent phishing emails to developers during a U.K. government security evaluation, according to Britain’s AI Security Institute.THERECORD.MEDIA
5 AugVeeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant BugHashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious: An unauthenticated flaw in Veeam's console that hands over a managed agent's credentials, rated 9.…THEHACKERNEWS.COM
5 AugPaperclip AI Flaws Let Unauthenticated Attackers Run Commands3 Paperclip flaws exposed data & allowed unauthenticated command execution in two deployment modesINFOSECURITY-MAGAZINE.COM
5 AugHow AI-powered phishing killed blocklists for goodAI is helping attackers create disposable phishing infrastructure and rapidly evolving toolkits that blocklists cannot track fast enough. Push Security explains why browser-level, technique-based detection offers a more durable defense than relying on domains, signatures, and oth…BLEEPINGCOMPUTER.COM
5 AugResearchers report unauthorized AI behavior in cybersecurity exercises.Apple files new legal challenge against UK’s iCloud access mandate. Business news: Okta to acquire Permiso Security.THECYBERWIRE.COM
5 AugFake Open VSX Extensions Harvest Private Repo and CI Data77 counterfeit Open VSX extensions beaconed to one domain, 19 harvesting git and CI identityINFOSECURITY-MAGAZINE.COM
5 AugPoison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer PromptCybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms. One such service, Poison Claude, claims to offer access to Anthropic's larg…THEHACKERNEWS.COM
5 AugPSA: Apple’s Private Relay can leak your real IP addressA bug in how Apple implements its Private Relay feature, which in theory masks users’ IP addresses from the sites they visit, can reveal users’ real IP addresses.TECHCRUNCH.COM
5 AugMeta Ran Ads That Contained AI-Generated Child Sexual Abuse ImageryMore than 50 offending image and video ads were published across Facebook, Instagram, Messenger, or Threads, according to Meta’s ad library data. Some ran as recently as this week.WIRED.COM
5 AugFrom 2 weeks to 2 minutes: Amazon Cognito launches Provisioned limits for self-service rate limit managementImagine preparing for your biggest sales event of the year, and you want to ensure your customer identity management service can handle the elevated traffic for carrying out application activities. For security teams, business leaders, and technologists managing identity infrastr…AWS.AMAZON.COM
5 AugDHS Is Hiring Bounty Hunters to Find and Photograph Deported People’s Homes AbroadHomeland Security told immigrants that leaving the US would wipe out fines it claims they owe. Now it wants private investigators to find them in their home countries and collect.WIRED.COM
5 AugHorizon3 raises $250 million in Series E funding.Spur secures $200 million in funding from Insight Partners. Okta has agreed to acquire identity security platform Permiso Security.THECYBERWIRE.COM
5 AugThe Most Dangerous AI Hacking Techniques Still Have Humans in the LoopSecurity researcher James Kettle tried to push the limit of AI’s hacking abilities—and discovered how effective it can be when combined with human expertise.WIRED.COM
5 Aug15 TP-Link Bugs Expose Risks in Zero-Trust ProvisioningResearchers are calling attention to the risks inherent in automated network device provisioning, using a world-leading device manufacturer as a case study.DARKREADING.COM
5 AugAWS partners with Anthropic and OpenAI to bring AWS Continuum into developer workflowsCustomers have access to models that are continuously getting better with each new generation bringing larger context windows, stronger reasoning, and lower token costs. Getting the strongest AI-powered security will come from tools that combine the most relevant models with deep…AWS.AMAZON.COM
5 AugChinese telcos maintain deep US presence despite Salt Typhoon links, House committee saysThree Chinese telecommunications giants continue to have footholds in the U.S. internet ecosystem despite their alleged role in previous Chinese hacking campaigns, a House committee report concluded.THERECORD.MEDIA
5 AugDHS Wants Protesters’ Signal Group ChatsA lawsuit accuses Homeland Security of violating protesters’ free-speech rights—but the agency is using it to try to get access to the plaintiffs’ encrypted communications.WIRED.COM
5 AugAI Deception Emerges in Cyber Tests as Agents Target Real People and SystemsAISI found AI agents taking unsanctioned online actions, including social engineering and code attacks, during controlled cyber tests. The UK’s AI Security Institute (AISI) has put something uncomfortable on the table: during cyber testing, frontier models didn’t just follow inst…SECURITYAFFAIRS.COM
5 AugCanadian pleads guilty to Snowflake cloud data-theft attacksA Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. [...]BLEEPINGCOMPUTER.COM
5 AugOpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp ContactsResearchers at security firm Zenity found more than a dozen flaws in AI browsers—and managed to get OpenAI’s Atlas to make an unauthorized Amazon purchase.WIRED.COM
5 AugAI Sends Global Crime Syndicates Into Fraud NirvanaOrganized crime is convincingly scamming at scale, making billions thanks to AI-enabled voice cloning, deepfake real-time video overlays, LLM-driven persona management, and automated translation.DARKREADING.COM
5 AugAI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent HijackingAttackers can take control of agents through malicious instructions hidden in content supplied to AI browsers, and there's no simple fix for the threat.DARKREADING.COM
5 AugNo Perfect Fix for AI Browser Prompt Injection FlawsAI browsers from top vendors remain vulnerable to prompt injection attacks despite multiple security guardrails, according to new research.DARKREADING.COM
4 AugWhatsApp account takeover scam asks you to “vote for my friend”Scammers are trying to take over WhatsApp accounts by sending messages asking people to vote for a friend in a fake online contest.MALWAREBYTES.COM
4 AugDevice Code Phishing Up 1,500% in 2026; Vishing DoublesNewer social engineering techniques help attackers ignore entrenched security controls and limit the evidence they leave behind.DARKREADING.COM
4 AugAI Accounts for Over Half of Cybercrime in Africa, Says InterpolInterpol claims AI is driving a surge in cybercrime in Africa, with related losses doublingINFOSECURITY-MAGAZINE.COM
4 AugOnline backlash ends in Google rolling back Google Earth AI tool after a dayGoogle has walked back an AI feature that allowed users to generate artificial images inside Google Earth, after a predictable flurry of deepfakes.MALWAREBYTES.COM
4 AugGoogle Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged AgentGoogle deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing agent. The researchers said the public agent could be prompt-…THEHACKERNEWS.COM
4 AugTravelers targeted when logging into hotel Wi-Fi networksRussian cybercrime groups are running a campaign that abuses hospitality Wi-Fi to steal information from travelers worldwide.MALWAREBYTES.COM
4 AugAI Notetaker Lets Hackers Spy on Government, Corporate Video CallsA Google Firebase misconfiguration lets users of tl;dv, an AI meeting tool, query any other users' meeting information and potentially join calls.DARKREADING.COM
4 AugApple launches new legal challenge against UK over iCloud accessSeeking to protect users' iCloud accounts, Apple is reportedly mounting a new challenge to British legal demands for ways around the company's Advanced Data Protection feature.THERECORD.MEDIA
4 AugCybercriminals Bypass AI Safety Controls by Splitting Malicious Tasks Across Multiple SessionsTalos read attacker prompt logs and found guardrails fell to task splitting and ownership claimsINFOSECURITY-MAGAZINE.COM
4 AugKeyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code HooksA credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep verified 353 poisoned versions across 79 package names in the npm registry. Its moni…THEHACKERNEWS.COM
4 AugRussian businesses erase Durov-linked products after 'terrorist' designationThe designation, announced last week, came a day after Russia's Federal Security Service (FSB) charged Durov with aiding terrorist activity and said it would seek to place him on an international wanted list. The agency accused Telegram of failing to remove channels and bots alle…THERECORD.MEDIA
4 AugWhatsApp Scam Hijacks Accounts via Linked Devices FeatureWhatsApp scam abused the Linked devices feature to hijack accounts without stealing any passwordsINFOSECURITY-MAGAZINE.COM
4 AugWiz at Black Hat 2026: Driving AI Threat ReadinessAnnouncing new capabilities that help organizations prepare for the AI era by expanding visibility and accelerating response, so security teams can defend at machine speed.WIZ.IO
4 AugLandmark Deal Would Officially Add Laser Weapons to US Army ArsenalFacing a growing drone threat, the Pentagon is poised to sign a first-of-its-kind contract for “Enduring High Energy Lasers”—and make directed energy weapons an official part of the Army’s kit.WIRED.COM
4 AugBenchmarking the Agentic SOC: How we evaluate LLMs for security workflowsPublic leaderboards can't tell you which LLM to trust in your SOC, so Elastic built an evaluation framework that grades models on the work (tool calls, execution traces, blind judging) across Agent Builder, Attack Discovery, and automatic migration.ELASTIC.CO
4 Aug77 Open VSX extensions found harvesting developer info77 extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development environments where they were installed. [...]BLEEPINGCOMPUTER.COM
4 AugNvidia doesn’t mess around: A week after open AI industry group formed, it’s already showing progressThe week-old Open Secure AI Alliance, spearheaded by Nvidia and grown to over 120 companies, already has proposals out for defending against AI agents.TECHCRUNCH.COM
4 AugAndroid app developers may be unwittingly sharing their users’ location data with advertisersNew findings by the Electronic Frontier Foundation aim to warn app developers that some of the third-party code they place in their apps may also collect their users' location data when they grant permission to the app.TECHCRUNCH.COM
4 AugOpenAI: Cambodian scam centers used ChatGPT to lure Indian nationals, conduct investment fraudA tip from WhatsApp led OpenAI to ban multiple accounts associated with investment scams and human trafficking operations based in Cambodian scam centers.THERECORD.MEDIA
4 AugPhishing service spoofs RingCentral to steal Microsoft 365 accountsThe Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts. [...]BLEEPINGCOMPUTER.COM
4 AugOK, Well, Rogue AI Agents Are Hacking AgainRogue AI agents from OpenAI and Anthropic have again been caught trying to disrupt servers and software—and leaving instructions for future bad behavior.WIRED.COM
3 AugSponsored: The intrusion signals hiding in plain sightIn this sponsored interview James Wilson chats with Permiso CTO Ian Ahl about detecting ShinyHunters-style attackers as they move through cloud and SaaS environments. Ian explains how ordinary-looking events such as a password reset, a new MFA device, unusual searches and a first…RISKY.BIZ
3 AugHollowFrame Loader Uses Fake Python DLL to Evade DefenderNew HollowFrame loader hid Go code in a fake Python DLL after pre-staging Defender exclusionsINFOSECURITY-MAGAZINE.COM
3 AugHorizon3 hits $2 billion valuation with $250M Series E as AI threats escalateCybersecurity startup Horizon3 raised $250 million at a $2 billion valuation as companies want continuous, AI-powered security validation instead of annual pentesting.TECHCRUNCH.COM
3 AugSamsung bans smart TV apps that share users’ internet connections with strangersNew security research offers a rare view inside residential proxy networks, which rely on apps that share a person's internet connection with someone else.TECHCRUNCH.COM
3 AugIs There Really a Fix for CISO Fatigue?Accountability without any real authority is driving CISO burnout, and organizations need to take notice.DARKREADING.COM
3 AugIntroducing the Wiz Sensor for Developer Workstations to Protect Endpoints in the AI EraAs AI expands who builds software, the developer workstation is becoming a new security perimeter. AI and third-party software increasingly operate with access to your most sensitive credentials and cloud environments.WIZ.IO
3 Aug“Adult TikTok” searches lead to scamsThat "free" adult TikTok site could leave you with spam, unwanted apps, or fake verification fees.MALWAREBYTES.COM
3 AugCalifornians can tell data brokers to DROP their informationCalifornia has launched the Delete Request and Opt‑out Platform (DROP), a state‑run portal that lets residents send deletion and opt‑out requests to all registered data brokers.MALWAREBYTES.COM
2 Aug8 Best Password Managers (2026), Tested and ReviewedKeep your logins locked down with our favorite password management apps for PC, Mac, Android, iPhone, and web browsers.WIRED.COM
2 AugGoogle Chrome may soon block New Tab hijacker extensions by defaultGoogle is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. [...]BLEEPINGCOMPUTER.COM
1 AugPhishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, ... Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.
ISC.SANS.EDU
31 JulSilverFox Targets Japanese Manufacturer With Advanced ValleyRAT CampaignSilverFox targeted a Japanese manufacturer with new DLL sideloading techniques, kernel drivers, and resilient ValleyRAT persistence mechanisms. Cato CTRL documented a new SilverFox campaign targeting a Japanese industrial manufacturer. The attack chain adds two previously undocum…SECURITYAFFAIRS.COM
31 Julzipdump.py: Metadata Encoding, (Fri, Jul 31st)I was asked for help with a problem similar to the following.
ISC.SANS.EDU
31 JulNetwork Anomaly Detection in KATAAn analysis of how Network Anomaly Detection (NAD) rules work within Kaspersky Anti Targeted Attack, using Kerberoasting and DNS tunneling attacks as examples.SECURELIST.COM
31 Jul6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved from a niche red-team technique to an industrial-scale threat in under six months. Designed for input-constrained devices like smart TVs, printers, and so on, the dev…THEHACKERNEWS.COM
31 JulThe $5 million threat: AI Is supercharging phishing attacksAccording to the newly-published study, phishing and social engineering are becoming more expensive to recover from, trickier to detect, and increasingly augmented by artificial intelligence. Read more in my article on the Fortra blog.FORTRA.COM
31 JulUSA Fencing Lunges Into the Hidden Identity Challenge in Amateur SportsThe organization behind Team USA's Olympic/Paralympic fencing teams has automated identity verification to handle growing membership, cutting manual review time while ensuring athletes compete in the correct categories.DARKREADING.COM
31 JulWhat an LLM Can Find: A Practical, Cheap Path to Code-level Threat DiscoveryAn AI-assisted audit found 29 flaws in GlobaLeaks, showing LLMs make large-scale code reviews faster, cheaper, and accessible. GlobaLeaks, a mature whistleblowing platform that had already undergone six independent professional audits over the past thirteen years, was subjected t…SECURITYAFFAIRS.COM
31 JulThe Morning After We Pull a Root of Trust, Nobody Owns ItThe most valuable move any security team can make is building a certificate and key inventory.DARKREADING.COM
31 JulDROP Platform Lets Californians Reduce Digital FootprintThe Delete Request and Opt-out Platform (DROP) launches Aug. 1 and hundreds of thousands of California residents already registered. Other states could follow if the process goes smoothly.DARKREADING.COM
31 JulThree Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates CombinedGoogle on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions were released last month. In its latest patch for Chrome 151, re…THEHACKERNEWS.COM
31 JulCheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into ProxiesBitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo…THEHACKERNEWS.COM
31 JulFake Fortnite rewards are stealing players’ accountsScammers are using fake V-Bucks offers and locker value sites to hijack Fortnite accounts.MALWAREBYTES.COM
31 JulCyber Command plans Silicon Valley office to drive innovationThe outpost will have its own director, though no one has yet been named for the post, and support the command’s nascent Cyber Warfare Innovation Center (CIWC).THERECORD.MEDIA
31 JulOpenAI says its new GPT 5.6 models are becoming more cost-efficientOpenAI says it has reduced the price of two GPT-5.6 models, cutting Luna's API price by 80% and Terra's by 20% as it works to make its models more efficient. [...]BLEEPINGCOMPUTER.COM
31 JulClaude published malicious code to the Internet and attacked 3 real companiesHad the hacks used conventional methods, someone would likely go to prison.ARSTECHNICA.COM
30 JulSE Asian Cybercriminal Syndicates Become a Global PowerThe groups move from goods to services and continue to traffic people from at least 80 countries, costing nations in the region at least $88 billion in 2025 alone.DARKREADING.COM
30 JulIs AI security actually a physical problem?While AI might seem abstract, something that lives in "the cloud" is concrete. The AI applications we use every day run on GPUs in physical buildings, and Mark Houpt secures them. As Chief Information Security Officer at DataBank, he's watched those data centers go from anonymous…THECYBERWIRE.COM
30 JulFCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber RisksThe Federal Communications Commission (FCC) added foreign-produced mobile robots and networked power inverters to its Covered List on July 28. The move generally prevents new models from receiving the equipment authorization required for import, marketing, or sale in the US. Prev…THEHACKERNEWS.COM
30 JuleSIM Plus and Nicegram Share Belarus-Linked Codebase, Analysis FindsAnalysis found eSIM Plus and Nicegram share a Belarus-linked codebase, while eSIM Plus routes data and calls through Russian services. Two popular apps available in EU app stores, Nicegram, with over 50 million downloads, and eSIM Plus, with over 1 million, are presented to users…SECURITYAFFAIRS.COM
30 JulA Civilian Plane Crashed in New Mexico. Was the Military’s Tech to Blame?Drone warfare is making the skies more dangerous, even for airplanes far from the battlefield.WIRED.COM
30 JulSilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRATThe Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver (BYOVD) attacks targeting a Japanese organization in the industrial manufacturing sector to ultimately deliver ValleyRAT (aka Winos 4.0) for persistent…THEHACKERNEWS.COM
30 JulTeams-Themed Phishing Campaign Abused Legitimate Microsoft Login PagesCheck Point researchers detail phishing attack as an example of attackers dropping fake Microsoft login pages in favor of abusing Microsoft’s legitimate authentication infrastructureINFOSECURITY-MAGAZINE.COM
30 JulFTC sues Hims & Hers for allegedly sharing patients’ medical data with advertisers Meta and SnapThe U.S. federal consumer watchdog said Hims & Hers, which prescribes for sexual wellness and mental health conditions, used website trackers to share customers' information with advertisers.TECHCRUNCH.COM
30 JulHidden prompt turns Microsoft Copilot into an AI wormA new type of attack can trick Microsoft Copilot for Word into spreading hidden prompt injections from document to document.MALWAREBYTES.COM
30 JulAI and Automation Fall Short of Sysadmin ExpectationsAction1 report finds sysadmins overestimated their use of AI in predictions made two years agoINFOSECURITY-MAGAZINE.COM
30 JulHims & Hers sued over alleged health data privacy failuresThe FTC has sued telehealth provider Hims & Hers, alleging it shared customers' sensitive health information with advertisers.MALWAREBYTES.COM
30 JulChinese Open-weight AI Models: Cybersecurity Risks and RewardsChinese models show variation from month to month, highlighting the uncertain and unstable nature of their security postureF5.COM
30 JulClaude Mythos — Hype vs. Reality: What Security Teams Need to KnowIn this edition of Reporters' Notebook, our journalists discuss the ins and outs of Anthropic's Claude Mythos rollout. How seriously should we take its risks? How big of a deal is it?DARKREADING.COM
30 JulRead This Before You Buy That TV Streaming StickSecurity experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds …KREBSONSECURITY.COM
30 JulGoogle says it fixed more Chrome bugs in June than over the past two years, thanks to AIAs experts have warned for the last two years, some companies — like Microsoft and now Google — are finding and patching an exponential number of bugs in their products, thanks to the use of LLMs and AI tools.TECHCRUNCH.COM
30 JulRethinking scanning for the AI era: Wiz’s Agentic Code Security SystemEnterprise AI AppSec requires more than powerful models. It requires a system that balances speed, depth, and cost across the software lifecycle.WIZ.IO
30 JulChrome may get faster updates with no restart requiredThe last two versions of Chrome have included more patches than the previous 23 combined.ARSTECHNICA.COM
30 JulOpenAI model was hacking targets for days before being discovered.FTC launches probe into Shein.THECYBERWIRE.COM
30 JulCareCloud begins to notify hundreds of thousands after hackers stole medical recordsThe health tech data giant, which handles vast amounts of patients' medical data, said hackers struck one of its protected health data stores.TECHCRUNCH.COM
30 JulBalancing speed and safety: A control framework for AI coding agentsAI coding agents are part of the developer toolchain. Tools like Kiro and Claude Code generate features, tests, and code refactors from natural-language prompts. A single agent can open dozens of pull requests (PRs) across your repositories in an afternoon. That productivity come…AWS.AMAZON.COM
30 JulResearchers Expose Flying Eagle Criminal Ecosystem Behind Fake Chinese Police AppResearchers linked the Flying Eagle Android RAT to fake police apps, uncovering 170 servers in a growing cybercrime ecosystem. Hunt.io researchers and independent journalist NetAskari started with a fraudulent Android app impersonating a Chinese Provincial Public Security Bureau …SECURITYAFFAIRS.COM
29 JulWeekly Threat Bulletin – July 29th, 2026These are the top threats you should know about this week.F5.COM
29 JulCyera agrees to acquire Oasis Security for $1B to safeguard proliferating AI agentsThe deal is Cyera's third acquisition this year.TECHCRUNCH.COM
29 JulApple Patches Everything (July 2026), (Wed, Jul 29th)I am a bit late with this summary, but this week Apple released updates to all its operating systems and Safari. The Safari update, as usual, targets macOS prior to macOS 26. macOS updates covered the two older versions (14 and 15), while other operating system patches only cover…ISC.SANS.EDU
29 JulICE’s New Detention Center Contracts Declare State Laws ‘Shall Not Apply’One day after a federal judge ordered an ICE detention center opened to state health inspectors, the agency posted new contract terms that would void state oversight at four facilities.WIRED.COM
29 JulResearchers Warn of AI-Enhanced Phone Fraud EcosystemAI is dramatically reducing the barriers to entry for scam phone farm operators, Human Security warnsINFOSECURITY-MAGAZINE.COM
29 JulRussia Charges Telegram Founder Pavel Durov With Aiding Terrorist ActivityThe Federal Security Service of the Russian Federation (FSB) on Wednesday said it charged Telegram founder Pavel Durov for allegedly facilitating terrorist activities and for failing to remove prohibited information in violation of Russian law. The principal security agency said …THEHACKERNEWS.COM
29 JulWe found 120 fake Walmart stores trying to steal your credit cardFake Walmart stores are offering unbelievable bargains on liquor to lure shoppers into entering their credit card details.MALWAREBYTES.COM
29 JulThese near-mint ASUS Chromebook refurbs are only $145Buying a new computer in 2026 is a unique experience. Rather than deal with incredibly high tech prices, more shoppers are opting for high-quality refurbished tech. This ASUS Chromebook CM30 refurb is in near-mint condition with a grade "A" rating, but it still only costs $144.97…BLEEPINGCOMPUTER.COM
29 JulWindows 11 KB5101684 update released with 42 changes and fixesMicrosoft has released the KB5101684 preview cumulative update for Windows 11 24H2 and 25H2, which 42 bug fixes and additional feature improvements for the operating system. [...]BLEEPINGCOMPUTER.COM
29 JulWiz’s First 6 Months as Part of GoogleFast gets even faster: redefining security for the AI era and doubling down on our multicloud commitWIZ.IO
29 JulYour AI Agents Are Guessing at Scale: Permissions Decide the DamageAI agents are designed to improvise as they complete tasks, making broad permissions a growing security risk. Token Security explains why identity, intent-based access controls, and least privilege are becoming the foundation for securing agentic AI. [...]BLEEPINGCOMPUTER.COM
29 JulAI robocalls: Why caller ID is still lying to youAI is making robocall scams cheaper, more convincing, and harder to spot. Here's why caller ID still isn't enough.MALWAREBYTES.COM
29 JulSenate confirms Clayton to head ODNI.OpenAI's rogue agent targeted Model Lab's customer.THECYBERWIRE.COM
29 JulLogoKit Phishing Kit Screenshots Victim Sites in Real TimeLogoKit now builds per-victim phishing pages using live screenshots of the target's real websiteINFOSECURITY-MAGAZINE.COM
29 JulBuying TikTok views or followers? Here’s what you’re really gettingBehind TikTok's booming growth industry are fake engagements, stolen accounts, and a fast track to getting flagged.MALWAREBYTES.COM
29 JulUS government bans new foreign-made humanoids, robot dogs, and solar inverters, citing risks to national securityThe ban largely affects U.S. imports from China, which currently dominates the global market for making humanoid robots and solar inverters.TECHCRUNCH.COM
29 JulOpenAI says rogue agent behind Hugging Face hack broke into additional servicesThe four additional targeted organizations weren’t named. OpenAI said they were not affected as severely as Hugging Face.THERECORD.MEDIA
29 JulHealth-ISAC warns of rising ShinyHunters data theft attacks on healthcareHealth-ISAC, a cybersecurity information-sharing organization for the health sector, is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters. [...]BLEEPINGCOMPUTER.COM
29 JulThreatLocker secures $190 million in a Series F round led by ElephantAct Security emerged from stealth with $60 million in total fundraising to create an action-centric cloud security platform. Cyera acquires Oasis Security in a $1 billion deal.THECYBERWIRE.COM
29 JulRed Agents vs. Blue Agents: How to Make AI Better At DefenseThe agentic AI playing field was heavily tilted toward offense, so researchers began using red team agents to help teach their blue counterparts.DARKREADING.COM
29 JulApple accused of letting fake crypto app steal $1.8 millionThe case raises fresh questions about how effectively Apple polices apps that impersonate legitimate developers.MALWAREBYTES.COM
28 JulHugging Face Has a Deepfake Nudes ProblemResearchers tested top image editing models on Hugging Face and found they could easily create explicit deepfakes—and 1,000 image editing prompts show how people use the software.WIRED.COM
28 JulNew CREST AI Standards to Deliver AI-Enabled Pentesting AccreditationCREST’s new AI standards are optional add-on requirements for cybersecurity service providers wishing to demonstrate responsible AI usageINFOSECURITY-MAGAZINE.COM
28 JulNVIDIA’s Open Secure AI Alliance Is Missing Some Big NamesNVIDIA has launched a new Open Secure AI Alliance to build an “open defense stack for agents”INFOSECURITY-MAGAZINE.COM
28 JulIR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chainsTalos IR's Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn how to sharpen your defenses.TALOSINTELLIGENCE.COM
28 JulVatican’s Click To Pray app exposed personal data from 700,000 usersAnyone could access other Click To Pray users' personal information. The flaw went unfixed for more than six months after it was reported.MALWAREBYTES.COM
28 JulShared Claude chats were searchable on GoogleReddit users found that by using a specific search query, they could find shared Claude conversations in search results.MALWAREBYTES.COM
28 JulMicrosoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled ThreatsMicrosoft has launched a new agentic security system for cyber defenders as well as its first cyber-focused AI modelINFOSECURITY-MAGAZINE.COM
28 JulFormer Citigroup CISO Blauner on What Makes A Great Security LeaderThe cybersecurity pioneer discusses the evolution of the CISO role, AI's impact on careers, and why operational resilience is the profession's next frontier.DARKREADING.COM
28 Jul24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before LoginCybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol to the public internet. Of the 36,872 internet-exposed server-management i…THEHACKERNEWS.COM
28 JulBugs in Hugging Face Diffusers Bypass Custom Code SafeguardThree CVEs in Hugging Face diffusers let a malicious model repo run code on any machine that loads itINFOSECURITY-MAGAZINE.COM
28 JulThe risk hiding behind exposed MCP serversHow unauthenticated Model Context Protocol (MCP) servers are opening doors to sensitive cloud data, IAM, and command execution.WIZ.IO
28 Jul2026 Phase 1a IRAP report is now available on AWS Artifact for Australian customersAmazon Web Services (AWS) is excited to announce that the latest version of Information Security Registered Assessors Program (IRAP) report (Phase 1a – full assessment) is now available through AWS Artifact. An independent Australian Signals Directorate (ASD) certified IRAP asses…AWS.AMAZON.COM
28 JulJoint guidance on isolating vital systemsThis joint guidance is intended to support senior decision-makers within CI organizations.CYBER.GC.CA
28 JulAWS KMS or AWS CloudHSM: Choose the right key management solutionChoosing the right cryptographic key management service on Amazon Web Services (AWS) starts with understanding the difference between AWS Key Management Service (AWS KMS) and AWS CloudHSM. Both provide key storage backed by a hardware security module (HSM) but serve very differen…AWS.AMAZON.COM
28 JulWhen AI Agents Escape Sandboxes, Old Security Rules ApplyOpenAI's recent AI agent sandbox escape proves traditional security principles matter more than ever: limit access, isolate execution, log everything.DARKREADING.COM
28 JulStronger AI Safety Requires Peeking Inside the 'Black Box'Researchers propose focusing on identification of certain cognitive elements in LLMs that indicate when AI systems may take an unwanted action.DARKREADING.COM
28 JulFlaw From 2002 Exposes Data Centers to Server TakeoverLots of Internet-exposed server management controllers are subject to offline password-cracking attacks — and adversaries have taken note.DARKREADING.COM
28 JulSenate confirms Clayton as intel chief after delaysA party-line vote in the Senate installed Jay Clayton as director of national intelligence, a job that has drawn increasing scrutiny during Donald Trump's second term as president.THERECORD.MEDIA
28 JulA Typo Landed an Innocent Gamer in Prison for 18 MonthsHow much could a single underscore in a username really matter? Just ask Brandon Klayme, who served 18 months in prison before realizing how authorities arrested, charged, and convicted the wrong man.WIRED.COM
27 JulSponsored: How AI is putting pressure on EDRIn this sponsored interview James Wilson chats with Airlock Digital co-founders David Cottingham and Daniel Schell about how attackers are using LLMs to enumerate EDR detections. LLMs dramatically reduce the time and specialist labour needed to extract rulesets out of EDR product…RISKY.BIZ
27 JulGitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package AdoptionGitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before opening a pull request. "The cooldown configuration option in the dependabot.yml still controls the behavior, though, so you can choose a…THEHACKERNEWS.COM
27 JulJava Spring Boot "heapdump" scans, (Mon, Jul 27th)Spring Boot exposes the endpoint "/actuator/heapdump" to collect debug information. By default, the endpoint will return a file heapdump.hprof, which includes a binary heapdump that can be used to analyze the current state of the application. Non-Java readers may be familiar with…ISC.SANS.EDU
27 JulEFF: Most Smart Wearables Still Fall Short on Privacy and TransparencyEFF says most smart wearables lack basic privacy protections, with Apple standing out for end-to-end encryption and transparency. Most smart wearables still treat privacy like an optional extra, and that’s a problem. The Electronic Frontier Foundation (EFF)’s review of major smar…SECURITYAFFAIRS.COM
27 JulShadow AI agents are multiplying. Here's how to find and secure them.Shadow AI agents are rapidly spreading across enterprise platforms, often without IT or security visibility. Nudge Security explains how organizations can discover, assess, and govern AI agents before unmanaged permissions and autonomous actions create security risks. [...]BLEEPINGCOMPUTER.COM
27 JulTelegram phishing campaign targeted exiled Belarusian activist, Russians and KazakhstanisResearchers have uncovered a highly personalized phishing campaign that used Telegram to try to hijack the account of an exiled Belarusian activist, as well as users in Russia and Kazakhstan.THERECORD.MEDIA
27 JulApple sued over fake App Store crypto wallet app stealing $1.8M in BitcoinApple is being sued by three people who claim approximately $1.8 million in Bitcoin was stolen after downloading and using a fraudulent Sparrow Wallet application from the App Store. [...]BLEEPINGCOMPUTER.COM
27 JulMicrosoft launches its first cybersecurity model, plus a new agentic cybersecurity systemMicrosoft bolstered its AI cybersecurity offerings this week with the launch of its first AI security model and a new security platform.TECHCRUNCH.COM
27 JulAWS Shield Advanced is embracing the AWS WAF Anti-DDoS managed rule group: What changes and how to prepareApplication-layer distributed denial of service (DDoS) attacks are difficult to detect because they closely resemble legitimate traffic. HTTP request floods are now among the most common vectors targeting web applications, using valid-looking requests that blend in with normal us…AWS.AMAZON.COM
27 JulAftercall ads are driving Android users crazyA newly uncovered ad fraud campaign is spreading Android apps that display full-screen ads every time you end a phone call.MALWAREBYTES.COM
27 JulPSA: Your Claude shared chats and Artifacts may have ended up on GoogleThe issue appears to have originated from Claude’s “share chat” feature, which allows users to create links that enable anyone with the assigned URL view a conversation or project.TECHCRUNCH.COM
27 JulPrivate Claude Chats Exposed in Google and Bing Search ResultsThe screwup shows how tricky it can be to stop web crawlers from making ostensibly private conversations with AI chatbots entirely too public.WIRED.COM
27 JulMicrosoft unveils AI security tools it says outperform competing platformsMicrosoft says tools cost less than competing ones and outperform them, too.ARSTECHNICA.COM
25 JulSteam forum ClickFix attacks infect gamers with XMRig cryptominersSteam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers. [...]BLEEPINGCOMPUTER.COM
24 JulRisky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra serversA Russian hacking campaign targets Zimbra servers, the US accuses Moonshot AI of distillation attacks, Iran targets more PLC vendors, and Google adds selfie video to its login options.RISKY.BIZ
24 JulFake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 AttacksThe Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compromise Windows systems. The activity has been attributed by the agency to a threat cluster it tracks …THEHACKERNEWS.COM
24 JulEurope's Multilingual Reality Exposes AI Security GapsThe AI security layer and guardrails for many AI products don't evenly protect against jailbreaking and unsafe actions in every single language.DARKREADING.COM
24 JulSatellite Images Reveal How Suspected Scam Compounds Appear Out of NowhereAnalysis of satellite images of Myanmar shows dozens of alleged scam compounds have appeared in recent months, despite a purported crackdown on the criminal organizations.WIRED.COM
24 JulThe AI Trust Paradox: Businesses Are Racing Ahead, but Consumers Are HesitatingArtificial intelligence adoption is soaring, but consumer trust lags. Transparency, human oversight, and clear AI use cases are key to closing the trust gap. Businesses are rapidly adopting AI, with 93% planning deployment, but consumer trust lags far behind: only 23% trust compa…SECURITYAFFAIRS.COM
24 JulChatGPT Among Top 10 Most Impersonated Brands in Phishing Attacks, Says Check PointOpenAI’s chatbot tool ChatGPT ranked among the top 10 most impersonated brands in phishing attacks for the first timeINFOSECURITY-MAGAZINE.COM
24 JulMan gets six years for hacking 750 women's Snapchat accountsAn Illinois man was sentenced on Tuesday to 76 months in prison and three years of supervised release for hacking the Snapchat accounts of over 750 women to steal nude photos. [...]BLEEPINGCOMPUTER.COM
24 JulEuropol flags 4,340 URLs for removal in 'The Com' crackdownEuropol has flagged 4,340 URLs for removal during a multi-week operation targeting online content linked to "The Com," a loosely organized network of nihilistic violent extremist groups. [...]BLEEPINGCOMPUTER.COM
24 JulVatican's Official Prayer App Leaks 700K+ Global Users' PIIA porous API endpoint exposes, names, email addresses, location, and site status, all of which can be easily gleaned by anyone with a browser.DARKREADING.COM
24 JulGoogle wants to store a selfie video of your faceA new selfie video verification feature could make recovering your Google Account easier. But it also creates new security and privacy concerns.MALWAREBYTES.COM
24 JulDefault Azure Automation Setting Enables Cross-Tenant Identity TakeoverMicrosoft addressed a public-by-default configuration and chain of code flaws in Azure Automation which could have let attackers seize another tenant's identity and access other tenants' data, credentials, and cloud workloads.DARKREADING.COM
24 JulDon’t get fooled by TikTok resin art scamsScammers are using stolen videos and fake artist profiles to trick people into buying resin art that never arrives. Here's how to spot the warning signs.MALWAREBYTES.COM
24 JulCall of Duty Mobile scam uses fake free points to steal player accountsA phishing site posing as a free Call of Duty Points giveaway is stealing Activision logins and two-factor authentication codes.MALWAREBYTES.COM
24 JulOpenAI’s agent escaped its sandbox during a security testAn OpenAI agent escaped its sandbox, stole credentials, and broke into Hugging Face. Here's what that actually means.MALWAREBYTES.COM
24 JulMicrosoft blames massive Microsoft 365 outage on maintenance bugMicrosoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]BLEEPINGCOMPUTER.COM
24 JulUS accuses American of allegedly wiping his phone using a ‘duress’ password during border searchA U.S. citizen has asked a court to throw out the government's claim that he gave over a passcode to border authorities that wiped his phone's data, opening up fresh questions about a person's constitutional rights at the U.S. border.TECHCRUNCH.COM
24 JulHackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accountsHackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]BLEEPINGCOMPUTER.COM
24 JulEscape Artists: 'Incorrigible' AI Models Resist RehabilitationThe hacking of Hugging Face by a rogue OpenAI agent is significant, but unsurprising — and preventing the next AI model escape will be difficult, at best.DARKREADING.COM
24 JulCISOs vs. Boards: Myth or Misunderstanding?Escalating threats are forcing boards to prioritize security, but communication gaps persist. Boards and security teams each say they need more support to bridge the divide.DARKREADING.COM
24 JulGoogle Fined €890M Under EU Digital Markets Act Over Search and Play Store PracticesEU fined Google €890M under the DMA for favoring its own services and restricting Play Store competition, with AI search features also under scrutiny. The European Commission hit Google with two fines totalling €890 million on Thursday for violating the Digital Markets Act, one f…SECURITYAFFAIRS.COM
23 JulGitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP TierBeginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while its permanent invite-only VIP tier will pay $30,000 or more. Reports filed before that date, in…THEHACKERNEWS.COM
23 JulAI’s political and copyright reckoning.This week, Dave and Ben look at two stories centered around AI. The first involves how politicians are trying to combat how AI chatbots spread inaccurate or incomplete information on their campaigns to voters. The second story looks at how existing copyright laws are not robust e…THECYBERWIRE.COM
23 JulMicrosoft working to fix Exchange Online mailbox quarantine issueMicrosoft is working to resolve an ongoing Exchange Online issue that has been mistakenly quarantining customers' mailboxes since Sunday. [...]BLEEPINGCOMPUTER.COM
23 JulPreview: Cisco Talos at Black Hat USA 2026Here’s some of the ways Talos is showing up at Black Hat, alongside our friends at Cisco and Splunk.TALOSINTELLIGENCE.COM
23 JulHow Synthetic Identity Fraud is Coming for Machine IdentitiesMost people understand identity theft as an attacker stealing a real person's sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real identity, the attacker manufactures a new one, frankensteining together several…THEHACKERNEWS.COM
23 JulGoogle Adds Selfie Video Recovery for Users Locked Out of Their AccountsGoogle on Thursday announced a new way for users to sign-in to their accounts by letting them take a selfie video. The selfie for sign-in, per the tech giant, is another option on top of existing recovery methods to log in to an account, including an email address or a phone numb…THEHACKERNEWS.COM
23 JulMillions of cars could be tracked and unlocked by a hidden security flawA hidden flaw in a dealer-installed car alarm could let attackers unlock vehicles and track their locations. Many owners don't know they have one.MALWAREBYTES.COM
23 JulAgentic AI Challenges Progress in Confidential ComputingCore issues that slowed down adoption of secure data vaults are being resolved by technology, but artificial intelligence poses new ones. Experts have some answers.DARKREADING.COM
23 JulEU fines Google $1 billion for search, app store antitrust violationsThe European Commission fined Google €890 million ($1 billion) on Thursday after finding the company had violated the European Union's Digital Markets Act (DMA), which ensures fair online competition. [...]BLEEPINGCOMPUTER.COM
23 JulMicrosoft Copilot Deployments Delayed Over Security ConcernsCoreView research finds that security leadership is concerned about AI Assistant exposing confidential dataINFOSECURITY-MAGAZINE.COM
23 JulFedRAMP Rev5 Is Ending: What the 20x Transition Really RequiresFedRAMP 20X replaces point-in-time assessments with continuous, machine-readable evidence that demonstrates security controls are working. Anecdotes explains what the transition from Rev5 to FedRAMP 20X means and how organizations can prepare for continuous, evidence-based assura…BLEEPINGCOMPUTER.COM
23 JulChina-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare AttacksAn exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader. G…THEHACKERNEWS.COM
23 JulOpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to knowYou can't have failed to hear the news headlines about "rogue" OpenAI models hacking into another AI organisation, Hugging Face. But what has actually happened, who is to blame, and is it as serious as some of the reports suggest? Find out in my article on the Hot for Security bl…BITDEFENDER.COM
23 JulMicrosoft 365 outage affects Teams, SharePoint and other servicesMicrosoft Teams and several Microsoft 365 services are experiencing an ongoing outage, with users reporting problems accessing Teams, SharePoint, Excel and the Microsoft 365 Admin Center. [...]BLEEPINGCOMPUTER.COM
23 JulEnterprise security at machine speed: AWS Black Hat 2026 previewBlack Hat 2026 (Aug 1-6, 2026) brings together over 22,000 security practitioners, researchers, and CISOs who build, break, and defend enterprise infrastructure. They’re security professionals who push the limits of offensive and defensive security and demand proof over promises.…AWS.AMAZON.COM
23 JulState Department imposes visa restrictions on foreign cyber scammersIndividuals connected to transnational cyber-scam operations face U.S. visa restrictions under a new policy announced by Secretary of State Marco Rubio.THERECORD.MEDIA
23 JulInternational alert spotlights Russia-linked attacks on Zimbra webmailA Kremlin-backed group known as Laundry Bear has been using a zero-click phishing technique to break into Zimbra webmail accounts worldwide, the U.S. and other nations said.THERECORD.MEDIA
23 JulIntelligence Insights: July 2026ClearFake claims the crown again and CastleLoader debuts in this month’s edition of Intelligence Insights.REDCANARY.COM
23 JulAegisAI, founded by former Google security execs, lands $36M to stop AI-driven spear phishingThe Series A was led by Battery Ventures, bringing AegisAI total funding to $49 million.TECHCRUNCH.COM
23 JulFor Taylor Swift, Madison Square Garden’s Controversial Cameras Briefly Went DarkMSG’s sprawling surveillance system can monitor guests down to the second. Its owners made an exception for the pop star’s rehearsal dinner.WIRED.COM
23 JulForgot your Google password? Now you can log in with a selfie.Google's selfie videos can be used for account access, AI Avatars, and age verification.ARSTECHNICA.COM
23 JulDon’t swing at everythingThorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever.TALOSINTELLIGENCE.COM
23 JulEU issues largest DSA fine against AliExpress.OpenAI backs Massachusetts AI safety efforts.THECYBERWIRE.COM
22 JulWeekly Threat Bulletin – July 22nd, 2026These are the top threats you should know about this week.F5.COM
22 JulBuilding a Security Company for a Market That Changes Every Four Months with Shahar Bahat of Pluto SecurityShahar Bahat is the CEO and co-founder of Pluto Security. With every employee now building things using tools like Cursor, Claude Code, Lovable, and n8n, security teams have no visibility into any of those layers. That is the problem Pluto is solving. She sat down with Gianna to …THECYBERWIRE.COM
22 JulMicrosoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review AgentsA single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds. The flaw is in Microsoft's official Azure DevOps MCP server, and it w…THEHACKERNEWS.COM
22 JulGlow emerges from stealth at $1.2B valuation to challenge endpoint security in the AI eraGlow is targeting a new class of endpoint risks created by the rapid adoption of AI agents and developer tools inside enterprises.TECHCRUNCH.COM
22 JulStop renting storage space — this lifetime 2TB plan is yours for $59Cloud storage costs tend to creep up over time, since most services charge monthly or annually for as long as you use them. FileJump's Lifetime Plan skips that model entirely, offering 2TB of cloud storage for a single payment of $59 (MSRP $467). [...]BLEEPINGCOMPUTER.COM
22 JulChick-fil-A loyalty accounts hijacked using stolen passwordsIf you have a Chick-fil-A One account, now is a good time to change your password—and make sure it's one you don't use anywhere else.MALWAREBYTES.COM
22 JulAdobe Chrome extension flaw let sites access private WhatsApp chatsThe Adobe Acrobat extension for Chrome could be used to access conversations and data rendered in WhatsApp Web without any form of authentication. [...]BLEEPINGCOMPUTER.COM
22 JulTrickBot Ditches HTTP for DNS Tunneling in Latest VariantNew TrickBot variant hides C2 communication inside DNS queries, replacing decade-old HTTP patternINFOSECURITY-MAGAZINE.COM
22 JulNew InfraTrust report reveals infrastructure flaws admins should patch firstEclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices. [...]BLEEPINGCOMPUTER.COM
22 JulOpening the Black Box: Agentless Threat Detection for Virtual AppliancesMapping FortiGate event logs to real-world campaigns: A step-by-step researcher’s guide to continuous agentless monitoring.WIZ.IO
22 JulIf you pay a hacker’s ransom, chances are that they’ll come back for moreThe long-held understanding among security researchers and network defenders is that it's impossible to negotiate in good faith with an extortion racket because there's no incentive for the other side to actually walk away.TECHCRUNCH.COM
22 JulOpenAI models escaped containment to hack Hugging Face.SolarWinds patches fifteen critical flaws. Business news: Neo emerges from stealth with $100 million.THECYBERWIRE.COM
22 JulWhen AI Attacks: OpenAI Models Autonomously Hack Hugging FaceAdvanced LLMs escaped their sandboxes while attempting to achieve a non-malicious benchmark test objective.DARKREADING.COM
22 JulRondo Meets Geoserver, (Wed, Jul 22nd)This isn&#;x26;#;39;t a new attack, but something I saw "pop-up" in our logs this week:
ISC.SANS.EDU
22 JulFrench Parliament greenlights social media ban for under-15sBoth houses of the French Parliament voted to block social media access for children under 15, making France the first European country to enact a ban amid a broadening global crackdown.THERECORD.MEDIA
22 JulHow OpenAI’s human mistake led to the AI-powered hack on Hugging FaceOpenAI made a mistake setting up what it called a “highly isolated” testing environment and sandbox. According to cybersecurity experts, that human mistake is what made the AI-powered attack on Hugging Face possible.TECHCRUNCH.COM
22 JulEndpoint security firm Glow emerges from stealth with $180 million.Neo has emerged from stealth with $100 million. Palo Alto Networks has agreed to acquire user-focused observability provider Embrace.THECYBERWIRE.COM
22 JulAI Threat Detection Is Not Enough Without Adversary IntelligenceThe 2026 emergence of Anthropic’s Claude Mythos Preview showed security leaders that AI can now find software vulnerabilities faster than the humans responsible for patching them.INTEL471.COM
21 JulNew Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recoveryKaspersky GReAT experts describe a new Project CAV3RN C2 module. It uses Outlook calendar for communication via Microsoft Graph and has a backup connection via DNS AAAA responses.SECURELIST.COM
21 JulAI nudify apps spark legal scrutiny of Apple and Google’s profitsInstead of fighting over what app stores host, the San Francisco City Attorney is targeting how they make money from AI nudify apps.MALWAREBYTES.COM
21 JulDon’t trust that “FBI agent” in your DMsThe FBI is warning that fraudsters are using fake IC3 accounts and direct messages to target people who've already been scammed.MALWAREBYTES.COM
21 JulFBI Warns of Deepfake Videos Impersonating IC3 LeadershipFBI warned of deepfake videos of IC3 leadership directing users to spoofed complaint sitesINFOSECURITY-MAGAZINE.COM
21 JulUS seizes over 1,000 websites in FIFA World Cup piracy crackdownThe U.S. Justice Department has seized more than 1,000 websites and blocked 1,970 domains used to stream FIFA World Cup 2026 matches without authorization. [...]BLEEPINGCOMPUTER.COM
21 JulChoose Wisely: AI-Generated Coding Risk Varies, A LotAI-generated code introduces 15 vulnerabilities on average per codebase, but the actual risk depends on framework pairing more than the model used.DARKREADING.COM
21 Jul300 WINtegrations Strong: An Open Security Ecosystem Built for the Speed of AIAs AI accelerates how organizations build and how attackers operate, a deeply connected security ecosystem is how defenders keep up.WIZ.IO
21 JulAgentless Visibility: Uncovering Cloud Blind SpotsHow Agentless Workload Detection exposes hidden threats in virtual appliances and modern cloud networks.WIZ.IO
21 JulGoogle Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software VulnerabilitiesGoogle's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that's designed to discover, validate, and patch vulnerabilities quickly and efficiently. According to the tech giant, the model wil…THEHACKERNEWS.COM
21 JulDo more with AWS WAF labels using dynamic label interpolationAWS WAF classifies web traffic by attaching metadata to each request it evaluates. Managed rule groups such as AWS WAF Bot Control and AWS WAF Fraud Control account takeover prevention (ATP) attach labels that describe what they found. A label can record that a request came from …AWS.AMAZON.COM
21 JulHacker Turns AI Jailbreaks Into Offensive Attack PlatformA Russian-speaking actor, "Trim," dismantled publicly available frontier models and integrated them with offensive security tools.DARKREADING.COM
21 JulDNI nominee Clayton wins Senate panel’s approvalBy a party-line vote, the Senate Intelligence Committee sent the nomination of Jay Clayton to lead ODNI to the Senate floor.THERECORD.MEDIA
21 JulUsing LLMs to Find and Prioritize Vulnerabilities Is No Easy TaskThe latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for AppSec professionals.DARKREADING.COM
21 JulPolice dismantle Kratos phishing platform, arrest developerAuthorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia. [...]BLEEPINGCOMPUTER.COM
20 JulYour attack surface is bigger than you thinkNew data reveals where attack surfaces are hiding the most risk.CYBERSECURITYDIVE.COM
20 JulThe secret problem in AI infrastructure: Why MCP security starts with secretsAI changes how infrastructure is accessed. Here's what to secure.CYBERSECURITYDIVE.COM
20 JulThe ACLU Is Arming Lawyers to Expose State Surveillance SecretsA new toolkit for attorneys in Massachusetts targets the technologies police use—and conceal—to build criminal cases, from facial recognition to AI-written police reports.WIRED.COM
20 JulApps Marketed to US Troops Are Shipping Chinese and Russian CodeA first-of-its-kind analysis found more than one in eight apps built for US service members carried foreign code—some from firms in nations the Pentagon designates as adversaries.WIRED.COM
20 JulPolice Chiefs Cite TfL Hack in Push for Cybercrime Risk OrdersTwo chiefs of UK policing agencies said the Transport for London prosecution demonstrates the need for Cybercrime Risk OrdersINFOSECURITY-MAGAZINE.COM
20 JulMicrosoft confirms Windows Server Update Services sync delaysMicrosoft is working to fix a known issue affecting Windows Server Update Services (WSUS) servers, which has caused synchronization problems for more than a week. [...]BLEEPINGCOMPUTER.COM
20 JulMythos Didn't Break Your Security Program. Your Exposure Window Could.The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long would it take adversar…THEHACKERNEWS.COM
20 JulCybersecurity Keeps Events 'Uneventful'From the World Cup to the United States' 250th celebration, this year's event calendar has been packed with high-profile gatherings that drew global audiences, intense scrutiny, and enormous security demands.DARKREADING.COM
20 JulWatch Flock Safety CEO Garrett Langley discuss the future of surveillance at TechCrunch Disrupt 2026Flock Safety sits right at the center of the debate over where the line should be drawn between privacy and public safety. That’s why we’re bringing Flock’s founder and CEO Garrett Langley to the stage to speak about those very issues.TECHCRUNCH.COM
20 JulCruciferra Crypter Uses Process Ghosting to Evade DetectionCruciferra crypter used process ghosting and 90 custom ciphers to hide payloads for multiple actorsINFOSECURITY-MAGAZINE.COM
20 JulAn AI SOC Evaluation Guide for Security LeadersChoosing an AI SOC platform requires understanding how it will perform in your own environment, not just during an evaluation. Prophet Security shares a practical framework for assessing AI SOC solutions, including how to validate accuracy, operating models, long-term reliability…BLEEPINGCOMPUTER.COM
20 Jul2026 ISO and CSA STAR certificates are now available with two additional servicesAmazon Web Services (AWS) successfully completed an onboarding audit with no findings for ISO 9001:2015, 27001:2022, 27017:2015, 27018:2019, 27701:2019, 20000-1:2018, and 22301:2019, and Cloud Security Alliance (CSA) STAR Cloud Controls Matrix (CCM) v4.0. EY Certify Point auditor…AWS.AMAZON.COM
20 JulMore than 1,000 domains illegally streaming World Cup games seized, DOJ saysOver the course of the World Cup tournament, the Department of Justice seized more than 1,000 domains for illegally streaming games.THERECORD.MEDIA
20 JulIndia says allegedly leaked nuclear plant files pose no safety riskDocuments that the World Leaks cybercrime group claimed to leak from the Kudankulam Nuclear Power Plant do not contain information pertaining to safety or security, Indian officials said.THERECORD.MEDIA
20 JulCISOs Feel the Heat Over AI RiskJob pressures have increased as companies run headlong into AI adoption, causing 26% of top security executives to consider leaving their position.DARKREADING.COM
20 JulFlock Safety kills acoustic system designed to detect 'human distress'"Community consultation" is one of the reasons automated license plate reader (ALPR) company Flock Safety cited in its decision to drop voice-oriented tech from a gunshot detection system.THERECORD.MEDIA
20 JulRemediating Vulnerabilities With LLMs: Inside Ivanti's Automation PushIvanti CSO Daniel Spicer says frontier models have shown surprising effectiveness in early stages; but cost and human-in-the-loop viability remain open questions.DARKREADING.COM
20 JulIntroducing the Amazon GuardDuty investigation agent: on-demand AI-powered threat assessmentThe new Amazon GuardDuty investigation agent (now in public preview) investigates security findings across your Amazon Web Services (AWS) environment, reducing investigation time from hours to minutes. GuardDuty is our managed threat detection service that continuously monitors y…AWS.AMAZON.COM
20 JulCursor, Codex, Gemini CLI, Antigravity hit by sandbox escapesResearchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Google downgrading two Antigravity findings. [...]BLEEPINGCOMPUTER.COM
20 JulHackers steal $23.7 million in crypto from Ostium in off-chain attackThe Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol. [...]BLEEPINGCOMPUTER.COM
18 JulPrompt Injection Attacks Are Thwarting AI Hacking Agents“Context bombing” tricks malicious AI agents into shutting down before they can do harm.WIRED.COM
17 JulUS charges two over laundering $43 million from investment fraudU.S. prosecutors on Thursday charged a New York man and woman for their roles in a large-scale crime ring that laundered money stolen in cyber investment fraud scams. [...]BLEEPINGCOMPUTER.COM
17 JulSan Francisco Demands Apple and Google Delete AI ‘Nudify’ Apps From App StoresThe City Attorney’s Office sent the tech giants cease-and-desist letters this week telling them to stop profiting from 13 “face-swap” apps that are overwhelmingly used to target women and girls.WIRED.COM
17 JulE.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI AssistantsThe European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has: the camera, the microphone, whatever is on screen, a wake word that fires with the display off, and the ability to drive other apps in the backgroun…THEHACKERNEWS.COM
17 JulGoogle Bets 'Agentic Defense' Strategy Can Outpace AttackersGoogle Cloud incorporates key Wiz capabilities into an agentic defense platform to automate threat detection and remediation against AI attacks.DARKREADING.COM
17 JulInside the Search for "Clean" Residential Proxies for CardingResidential proxies are no longer the silver bullet they once were for carding. Flare explains why cybercriminals increasingly seek "clean" residential proxies and combine them with browser fingerprints, device profiles, and other identity signals to evade modern fraud detection.…BLEEPINGCOMPUTER.COM
17 JulAmazon fixing bug that billed some AWS customers billions of dollarsSome Amazon customers logged on Friday to a surprise bill estimate claiming that they owed the tech and cloud giant billions in fees.TECHCRUNCH.COM
17 JulThe Real AI Threat Is Blind TrustAI models left to both interpret and execute commands eliminate critical cybersecurity oversight.DARKREADING.COM
17 JulThe Zoom hack that says, ‘Don’t record me’If every meeting, watercooler conversation, and date gets transcribed and summarized, who's actually reading any of it?TECHCRUNCH.COM
17 JulGoogle’s Gemini lets strangers send messages from your locked Android phoneGemini, Google's AI assistant, is supposed to make life easier for Android smartphone owners. But right now it may also be making life easier for anyone anyone who happens to pick up your phone. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
16 JulThe future of transatlantic data sharing.This week, Dave and Ben look at how the Supreme Court's recent decision could impact data-sharing efforts with the European Union (EU). Additionally, they discuss how the LA Police Department has let its contract with Flock expire after reports emerged that the company was found …THECYBERWIRE.COM
16 JulSamsung backs down on threat to delete health dataSamsung threatened to delete users' health data if they refused AI training. After a backlash, it quickly backed down.MALWAREBYTES.COM
16 JulSANS Warns of AI Governance Gap as Use by Security Teams SurgesSANS Institute says governance programs are still nascent even as AI failures and threats growINFOSECURITY-MAGAZINE.COM
16 JulAI Can Find Bugs, But Human Knowledge Still Proves ThemArtificial intelligence (AI) is changing offensive security, but it has not changed the standard that matters most: a finding has to be proven before it becomes useful. AI-assisted tools can read code quickly, generate payloads, summarize attack surfaces, explain unfamiliar APIs,…THEHACKERNEWS.COM
16 JulThe Hunter's Paradox: Is it time to embrace automated threat hunting?Humans can no longer keep up with the volume and velocity of security data on their own, but AI can't be fully trusted. David discusses the merits of both and muses on what the future might look like.TALOSINTELLIGENCE.COM
16 JulUAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaignCisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.TALOSINTELLIGENCE.COM
16 Jul‘Selfish Bravado’ Behind TfL Cyber-Attack, Judge Says as Pair JailedThe perpetrators of the 2024 TfL cyber-attack have been jailed for five and a half years each after pleading guilty to Computer Misuse Act offencesINFOSECURITY-MAGAZINE.COM
16 JulWindows 11 24H2 Home and Pro reach end of support in 90 daysMicrosoft announced on Wednesday that systems running Windows 10 Enterprise LTSB 2016 and Home and Pro editions of Windows 11 24H2 will stop receiving updates in three months. [...]BLEEPINGCOMPUTER.COM
16 JulNew Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker CommandsAsk an AI agent to summarize the reviews on a product page, and a single planted review can make it click "Buy Now" instead. Ask a coding assistant to apply a maintainer's fix from a GitHub thread, and a fake comment can make it run a stranger's command on your computer. Neither …THEHACKERNEWS.COM
16 JulScattered Spider members behind TfL hack get five years in prisonTwo leading members of the Scattered Spider cybercrime collective were sentenced to five years and six months in prison each for hacking Transport for London (TfL) in 2024. [...]BLEEPINGCOMPUTER.COM
16 JulSingle Prompt Enables ChatGPT to Execute Full Cyber-Attack Chain, Researchers ClaimCybersecurity researchers tested Open AI GPT 5.5’s offensive cyber capabilities – and the results showed how effective a frontier LLM can be for hackersINFOSECURITY-MAGAZINE.COM
16 Juln8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuern8n, the workflow automation platform, handed out the wrong accounts at login. On Enterprise instances configured to trust more than one external token issuer, it matched an incoming JWT to a local user on the sub claim alone and ignored iss. A valid token from iss…THEHACKERNEWS.COM
16 JulHow a former DeepMind researcher raised at a $300M pre-seed valuation before launching a productDrawing on more than a decade spent helping build some of the world's most influential AI systems, including research that later informed the development of ChatGPT, Andrew Dai explains why he believes visual AI is one of the next major frontiers in artificial intelligence.TECHCRUNCH.COM
16 JulThe backlash against Flock cameras is spreadingPrivacy concerns have dogged Flock's automated license plate recognition system for years. Now accuracy and reliability are coming under scrutiny too.MALWAREBYTES.COM
16 JulHelloNet campaign — new malicious modules launched through the ViPNet update systemWe identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).SECURELIST.COM
16 JulAI Agents Broke the Security Playbook. Here's What Replaces It.Traditional security workflows were built for environments that changed at human speed. Token Security explains why AI agents require a new approach: building on a live identity foundation while giving security teams the flexibility to create workflows tailored to their own envir…BLEEPINGCOMPUTER.COM
16 JulUK cops say arrest of two young hackers disrupted the operations of an infamous hacking groupOwen Flowers and Thalha Jubair, two members of the prolific Scattered Spider hacking group, pleaded guilty and were sentenced to five years and six months in jail for hacking London’s metropolitan transit system.TECHCRUNCH.COM
16 JulUK investigates TikTok for alleged age-verification lapses, exposing kids to online harms“Age checks are a cornerstone of the UK’s online safety laws,” said Ofcom’s Chief Executive, Melanie Dawes. “Too many services have no or inadequate age checks in place, which is not good enough.”THERECORD.MEDIA
16 JulBegun, the Patch Wars haveLong foretold, the Great Patching has begun and it’s a doozy. Buckle in as Joe takes you through the story.TALOSINTELLIGENCE.COM
16 JulEU tells Meta to make major changes to its social media platforms.Pentagon suspends CMMC program.THECYBERWIRE.COM
16 JulNew OkoBot framework deploys 20 payloads to steal data, cryptoA new malicious framework called OkoBot is delivering more than 20 payloads in attacks focused on stealing cryptocurrency wallet seed phrases, credentials, and other sensitive data. [...]BLEEPINGCOMPUTER.COM
16 Jul1M+ Emails Use Hidden Text to Dupe AI Security FiltersArtificial intelligence and LLMs can be surprisingly ineffective against text salting, allowing phishing emails to slide right into your inbox.DARKREADING.COM
16 JulAgentic AI Is Untamable: Ask the Right Security QuestionsForget about attackers. Agentic artificial intelligence is creating enough risks for organizations and demands a security reframe.DARKREADING.COM
15 JulWeekly Threat Bulletin – July 15th, 2026These are the top threats you should know about this week.F5.COM
15 JulHow Absolute Security CMO Ash Parikh Thinks About Marketing, Pipeline, and Working with the BoardMost CMOs come up through marketing. Ash Parikh came up through engineering and sales, and he thinks that is exactly why he does the job differently. He joins Gianna and Charles on CyberCMO Confidential as the CMO of Absolute Security to talk about what 25 years of carrying a bag…THECYBERWIRE.COM
15 JulThis fake Apple app can unlock your Mac’s password vaultDisguised as Apple's CrashReporter, CrashStealer steals passwords, browser data, crypto wallets, and other sensitive information.MALWAREBYTES.COM
15 JulGovernment Updates UK’s National Risk Register with Cyber WarningsThe UK government is warning of the potential impact of catastrophic cyber-attacksINFOSECURITY-MAGAZINE.COM
15 JulSASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.For years, routing traffic through cloud proxies was good enough. Then work moved to the browser, AI entered the workflow, and the inspection model stopped keeping up. Enterprise workflows now live across SaaS applications, browsers, and an expanding ecosystem of generative AI to…THEHACKERNEWS.COM
15 JulNew Webinar: Closing the Approval Gap in AI-Era Ad TechA single approved marketing tag can quietly load fourth-party code your security team has never seen, granting full access to your forms, customer data, and checkout pages. This on-demand webinar reveals how this Approval Gap forms, and gives your team the blueprint to close it b…THEHACKERNEWS.COM
15 JulLAPD sidelines relationship with license-plate reader company Flock SafetyThe Los Angeles Police Department is the latest U.S. municipal agency to rethink its relationship to ALPR company Flock Safety.THERECORD.MEDIA
15 JulEleven Vulnerable UEFI Shims Enable Secure Boot BypassEleven forgotten Microsoft-signed UEFI shims can bypass Secure Boot on almost any machineINFOSECURITY-MAGAZINE.COM
15 JulDutch police dismantle global crypto investment scam, arrest alleged mastermindAuthorities said Wednesday that the group operated like a legitimate international business since at least 2021, running about two dozen call centers across several countries and employing more than 700 people who posed as professional financial advisers.THERECORD.MEDIA
15 JulPhishing Campaign Abuses eCards to Deploy RMM ToolsSix-month phishing campaign used seasonal eCard lures to plant legitimate RMM tools on victimsINFOSECURITY-MAGAZINE.COM
15 JulThe Red Agent POV: The One Boolean That Broke a B2B Platform’s Credit SystemPart 3: How the Red Agent bypassed a credit and paywall system by changing a single client-side value from false to true.WIZ.IO
15 JulTrump’s DNI pick grilled about election security, voter fraudSenators pressed director of national intelligence nominee Jay Clayton about his stance on the 2020 election and previous statements about voter fraud. Other issues took a back seat.THERECORD.MEDIA
15 JulIs 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI StrifeThe US government's restrictions on Anthropic and OpenAI frontier models have intensified calls in the UK and other countries to reduce their reliance on US tech companies, with significant cyber implications.DARKREADING.COM
15 JulIsraeli identity management startup Oak emerges from stealth with $60 million in seed funding.Barracuda Networks has acquired Austin, Texas-based identity and access management provider Evo Security.THECYBERWIRE.COM
15 JulHere’s the Truth About Whether Meta’s NameTag Face Recognition Tech ‘Exists’Since WIRED reported on Meta’s NameTag face recognition system, company executives have made confusing and conflicting remarks about its very existence.WIRED.COM
15 JulOperation Fake KickOff: Attackers Abuse Recruiters and SaaS to Harvest Work CredentialsIntel 471 investigated an ongoing, multi-stage phishing operation that systematically abuses legitimate software-as-a-service (SaaS) sales and marketing, and cloud platforms to orchestrate corporate credential theft.INTEL471.COM
15 JulCIS Benchmarks July 2026 UpdateThese CIS Benchmarks and CIS Build Kits have been updated or recently released and include a full changelog that references all changes.CISECURITY.ORG
15 JulDutch police bust investment fraud ring stealing over €100 millionThe Dutch Police announced the arrest of multiple individuals suspected of being part of an international investment fraud scheme estimated to have tens of thousands of victims. [...]BLEEPINGCOMPUTER.COM
15 JulForgotten Bootloaders Expose Secure Boot Blind SpotNearly a dozen vulnerable and now revoked UEFI shim bootloaders remained trusted for years, giving attackers a path to bypass Secure Boot.DARKREADING.COM
14 JulFive Charged in “Russian Coms” Fraud Platform CaseFive UK residents have been charged in relation to supplying Russian Coms fraud devices and appsINFOSECURITY-MAGAZINE.COM
14 JulMicrosoft starts testing cleaner Windows Search without adsMicrosoft is now testing a cleaner and faster version of Windows Search that should prioritize relevant results over ads and promotional content. [...]BLEEPINGCOMPUTER.COM
14 JulMicrosoft Entra ID gets passkeys default authentication starting SeptemberMicrosoft has announced that passkeys will become the default authentication method for the Entra ID enterprise identity service starting September 2026. [...]BLEEPINGCOMPUTER.COM
14 JulNew phishing kits target Microsoft 365 accounts, evade MFATwo new phishing kits, Jalisco and OmegaLord, have been discovered in attacks targeting Microsoft 365 accounts, using techniques that defeat multi-factor authentication (MFA). [...]BLEEPINGCOMPUTER.COM
14 JulStudy of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking RisksResearchers at KU Leuven tested 85 of the most popular crypto wallets that run as browser extensions and found that the wallets themselves leak enough to link and track the people using them. The way these wallets talk to websites and blockchain servers can tie a person's separat…THEHACKERNEWS.COM
14 JulTelegram’s shortlink domain is back online after day-long suspensionTelegram CEO Pavel Durov confirmed an outage in a tweet, saying that shortlinks to the messaging app had "stopped working."TECHCRUNCH.COM
14 JulAuthenticate legitimate AI agent traffic with AWS WAF Bot ControlAs AI agents and automated tools increasingly access web applications, distinguishing legitimate bot traffic from malicious attempts has become a critical security challenge. Traditional approaches such as IP-based filtering and reverse DNS lookups fail in multi-tenant systems (s…AWS.AMAZON.COM
14 JulUS: Pentagon Suspends CMMC Phase II Requirements for Defense ContractorsThe US Department of Defense announced the immediate suspension of the CMMC Phase II requirements until further reviewINFOSECURITY-MAGAZINE.COM
14 JulLastPass, Bitwarden users targeted with fake security alertsLastPass is warning users about an ongoing phishing campaign that is using fake security notices to direct them to fraudulent websites. [...]BLEEPINGCOMPUTER.COM
14 JulFrontier AI: The Genie's Out of the Bottle, But Where's the Rulebook?Cutting-edge artificial intelligence models are deploying with more independence and less human oversight. Several state governments are trying to legislate transparency in their use.DARKREADING.COM
14 JulWindows 11 KB5101650 & KB5099414 cumulative updates releasedMicrosoft has released Windows 11 KB5101650 and KB5099414 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. [...]BLEEPINGCOMPUTER.COM
14 JulManage Vendor Risk in a Few Practical StepsRisk tolerance, exposure visibility, board oversight — handling third-party risk is complicated but achievable with disciplined, precise governance.DARKREADING.COM
14 JulResearchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail ReadsAny other browser extension that can run a script on claude.ai can still trigger Claude for Chrome tasks aimed at your Gmail, your latest Google Doc and its comments, and your Calendar. Both this and ClaudeBleed need a rogue extension that can already run a script on claude.ai; t…THEHACKERNEWS.COM
14 JulSecurity Hub adds AI workload protection and multicloud support for Microsoft AzureSecurity Hub is our foundation for full-stack enterprise security across clouds. It centralizes your security operations and turns raw signals into prioritized insights, so your team spends its time managing real risk instead of stitching tools together. Today that foundation gro…AWS.AMAZON.COM
14 JulUS unseals indictment against alleged operators of Russian bulletproof hosting serviceThe Russians face multiple charges for allegedly providing cybercriminals with infrastructure and tech support through the St. Petersburg-based business Media Land and a sister company, ML Cloud.THERECORD.MEDIA
14 JulSpanish Police take down €140 million cyber fraud ring, arrest fourThe Spanish Police dismantled a cybercrime and money-laundering organization that made €140 million ($160 million) from investment fraud and business email compromise (BEC) attacks. [...]BLEEPINGCOMPUTER.COM
14 Jul6 GHz Wi-Fi Flaws Could Disrupt Critical SystemsAutomated Frequency Coordination systems by default trust client-side data, which could lead to location spoofing and other attacks that disrupt traffic.DARKREADING.COM
13 JulSomeone Is Scanning for Your MCP Servers and AI Assistant Credentials, (Mon, Jul 13th)The setup
ISC.SANS.EDU
13 JulMisconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. The command that did it: python3 -m http.server 8080, was still sitting in the readable .bash_history. From that one lapse…THEHACKERNEWS.COM
13 JulA Leak of San Francisco Police Drone Footage Exposes the New Reality of Urban SurveillanceThe SFPD’s exposure of hours of videos from drone platform Skydio reveals how broadly it’s watching the city from above—and how the results can spill online.WIRED.COM
13 JulFake crypto gift card sites are getting harder to spotScam crypto gift card stores look almost identical to the real thing. One wrong click can leave you with no card and no way to get your money back.MALWAREBYTES.COM
13 JulProgress Software Warns of "External Security Threat" to ShareFileProgress Software, the provider of the popular file-sharing and data storage solutions, has urged customers to shut down the server hosting their Storage Zone ControllerINFOSECURITY-MAGAZINE.COM
13 JulMeta Files Patent for AI That Can Listen All Day and Track How You're FeelingMeta has filed a patent application for an AI that listens to your voice throughout the day, works out how it thinks you are feeling from the way you sound, and keeps a timestamped log of every read. Each read gets pinned to the moment it happened: the time, your location, what y…THEHACKERNEWS.COM
13 JulThinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst CopilotsA few days ago, I was sitting with the CISO of a Fortune 50 company, walking through how his security team was thinking about AI agents in the SOC. Smart team. Serious program. They had already connected Claude to a few detection tools and were seeing real value in specific inves…THEHACKERNEWS.COM
13 JulNovel OAuth Client ID Spoofing Technique Targets Cloud EnvironmentsNew research reveals cyber-attackers can spoof OAuth Client IDs in Microsoft Entra ID, creating a stealthy path into cloud environmentsINFOSECURITY-MAGAZINE.COM
13 JulIntroducing Precursor: detecting agentic behavior with continuous client-side signalsPrecursor, our new continuous behavioral validation engine for bot management, offers visibility into how humans and bots actually interact across the full user journey. By turning session-level behavior into bot detection signals, it identifies advanced automation with higher pr…CLOUDFLARE.COM
13 JulUK charges suspects linked to Russian Coms call spoofing platformUK authorities charged five people following a National Crime Agency (NCA) investigation into Russian Coms, a major caller ID spoofing platform used by criminals to make over 1.8 million scam calls. [...]BLEEPINGCOMPUTER.COM
13 JulLAPD lets contract with surveillance giant Flock expire, citing ‘serious concerns’ over civil liberties and privacyThe LAPD, one of Flock's biggest government customers, is ending its contract with the company citing civil liberties concerns.TECHCRUNCH.COM
13 JulWhy IaC Coverage Belongs on Your Security DashboardRethinking IaC coverage as a funnel that shows how much of your infrastructure is governed, traceable, and ready for remediation at speedWIZ.IO
13 JulTurning Secure Software Development into a Measurable PracticeCIS and SAFECode have updated Secure by Design: A Developer’s Guide to Building Safer Software to address the role of AI on software security.CISECURITY.ORG
13 JulNew MemGhost Attack Plants Persistent False Memories in AI Agents Through One EmailGive an AI assistant a memory and access to your inbox, and you hand an attacker a way to rewrite what it thinks it knows about you. A single email can trick that agent into saving a false "fact" about the user, hide the change, and quietly steer its answers in later sessions. Wh…THEHACKERNEWS.COM
13 JulOpen Directory Exposes Three Evilginx Phishing OperatorsMisconfigured server exposed three phishing operators running Evilginx forks to bypass MFAINFOSECURITY-MAGAZINE.COM
13 JulJoint guidance on improving router hygiene to protect against Russian state-sponsored targetingCYBER.GC.CA
13 JulGoogle and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector FoundGoogle and Microsoft have pulled ModHeader, a popular header-editing extension with roughly 1.6 million installs across Chrome and Edge, after researchers found a hidden browsing-history collector built into its official store version. The collector was dormant. An empty allow-li…THEHACKERNEWS.COM
13 JulGuidance on securely configuring authorization and authentication frameworks - ITSP.40.063CYBER.GC.CA
13 Jul'Yellow Teams' Are Defining the Future of AI SecurityIn some companies, engineers are building defense and attack tools to test the potential of artificial intelligence for cybersecurity — and its threat.DARKREADING.COM
13 JulEU leaders eye social media ban for children under age 13“While ultimately it is up to parents to decide when children get their first smartphones, what we already have is a consensus that there needs to be a start date for the age children can join social media,” says European Commission President Ursula van der Leyen.THERECORD.MEDIA
12 JulProgress Told ShareFile Customers to Pull the Plug on Their Servers. Here’s What We Know.Progress urged ShareFile Storage Zone customers to shut down internet-facing servers immediately over a credible security threat under investigation. Progress Software sent an urgent email to ShareFile customers the evening of July 10 with a subject line that left no room for amb…SECURITYAFFAIRS.COM
12 JulClaude Fable 5 stays free for paid users until July 19 as Anthropic buys more timeAnthropic has just extended access to Claude Fable 5 for paid subscribers until July 19, giving you another week to keep using the most powerful model. [...]BLEEPINGCOMPUTER.COM
12 JulOpenAI temporarily relaxes GPT-5.6 Sol usage limitsOpenAI is temporarily relaxing GPT-5.6 Sol usage after demand for the company's most powerful model surged over the past 48 hours. [...]BLEEPINGCOMPUTER.COM
11 Jul'Ghostcommit' hides prompt injection in images to fool AI agents, steal secretsA PNG hiding a prompt injection could steal your repo's secrets, researchers demonstrate. The technique, dubbed 'Ghostcommit,' slipped past AI code reviewers CodeRabbit and Bugbot, which never open image files at all, then convinced a coding agent to read a repo's .env and write …BLEEPINGCOMPUTER.COM
11 JulAI Found a Root Bug in Linux That Everyone Missed for 15 YearsPlus: The Pentagon is training amateurs to become part of its hacker army, a Flock license plate reader error led to cops surrounding a car reviewer, and more.WIRED.COM
10 Jul"Comment stuffing" in an HTML phishing attachment as a mechanism for evading AI-based detection?, (Fri, Jul 10th)Anyone who deals with phishing messages caught by basic security filters knows that most phishing samples tend to blend into one another, since only a small set of techniques and approaches keeps reappearing in them. That is precisely why it is worth pausing on the occasional mes…ISC.SANS.EDU
10 JulTwo Chrome updates in two days fix critical vulnerabilitiesChrome updates are arriving within days of each other. Learn how to update Chrome and check if you're running the latest version.MALWAREBYTES.COM
10 JulHow mule betting scams recruit ordinary peopleEasy-money offers to open a gambling account could make you part of a money laundering operation. Here's how to spot a mule betting scam.MALWAREBYTES.COM
10 JulAI Coding: Do Security Risks Outweigh Productivity Gains?AI coding tools cost $19-$200/month/user, but security scanning, remediation, and false positives add hidden costs. Are the productivity gains worth it?DARKREADING.COM
10 JulThe Replicant in Your Directory: AI Agents and the Identity Security GapAI agents are accelerating the growth of non-human identities, making it harder for organizations to understand what exists, who owns it, and what it can access. Netwrix explains why stronger visibility and identity governance are essential as AI expands the enterprise attack sur…BLEEPINGCOMPUTER.COM
10 JulFresh ATM Crypto Software Bugs: Jackpot or Bust?Organizations, and possibly ATMs, are at risk of compromise, thanks to holes in a Microsoft BitLocker security wrapper.DARKREADING.COM
10 JulLaser Attack Resets Tangem Wallet Passwords on Cards That Can't Be PatchedResearchers at Ledger's Donjon security team have shown that a precisely timed laser pulse, aimed at the chip inside a Tangem crypto wallet card, can reset the card's password to anything the attacker picks. No old password. No backup card. Once it is reset, whoever did…THEHACKERNEWS.COM
10 JulMoney launderer accused of stealing seized crypto while in prisonA Bulgarian national has been charged with stealing $290,000 in government-seized cryptocurrency while serving 121 months in prison for helping launder millions stolen from American fraud victims. [...]BLEEPINGCOMPUTER.COM
10 JulLicense plate cameras may be next target after Supreme Court reins in location trackingIf a warrant is ultimately needed for ALPR searches, experts say, it would radically limit how the networks of cameras can be used and would change modern policing.THERECORD.MEDIA
10 JulProgress urges ShareFile admins to shut down servers over “credible” threatProgress Software is emailing ShareFile customers who use Storage Zone Controllers to immediately shut down their servers after identifying what it describes as a "credible external security threat" targeting the on-premises secure file-sharing software. [...]BLEEPINGCOMPUTER.COM
10 JulSix New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at BootResearchers at firmware security firm Binarly have found six new flaws in U-Boot, the small program that starts up hardware as varied as home routers, smart cameras, and the management chips inside data-center servers. Four of the bugs can crash a device. The other two …THEHACKERNEWS.COM
10 JulURGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security ThreatProgress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, confirming to The Hacker News that it is responding to a "credible external security threat." The company has temporarily disabled access to the affected accoun…THEHACKERNEWS.COM
10 JulEurope revives law allowing big tech to scan for CSAMThe law known as Chat Control 2.0 passed in the European Parliament, permitting companies like Google, Meta and Microsoft to scan users' messages to hunt for CSAM.THERECORD.MEDIA
10 JulJen Ellis: Connecting Cyber Community With Political MachineryOn the heels of her recent honors as a Member of the Order of the British Empire (MBE), we take a look back at the events that shaped Ellis' advocacy on behalf of security researchers.DARKREADING.COM
9 JulGhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding AgentsResearchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer's computer. The assistant asks permission to edit one harmless-looking file, but the write lands on a sensitive one instead. Th…THEHACKERNEWS.COM
9 JulMeta's New AI Image Tool Lets Others Use Your Public Instagram Photos in AI ImagesMeta has announced that its new artificial intelligence (AI) model Muse Image lets people use public Instagram posts and reels to generate AI content, and it's enabled by default. "You can also @-mention Instagram accounts in the Meta AI app to bring specific Instagram profiles r…THEHACKERNEWS.COM
9 JulTurn off this Meta setting before someone generates AI images of youMeta's new Muse Image tool lets anyone generate AI images of you from your public Insta profile. You won't be notified, and it's on by default.MALWAREBYTES.COM
9 JulMadison Square Garden Kept a List of Gay CelebritiesAn MSG database tracked and categorized hundreds of celebs, famous Knicks superfans, and even some of Taylor Swift’s wedding guests. Labels included “LGBTQIA,” “DO NOT HOST,” and low to high “risk.”WIRED.COM
9 JulNew AI Security Charter Backed by Over 70 Cyber FirmsOver 70 cybersecurity organizations have signed the CREST AI Charter detailing responsible use of AI for securityINFOSECURITY-MAGAZINE.COM
9 JulGhostApproval Flaw Hits Six Major AI Coding AssistantsWiz discovered GhostApproval, a symlink flaw in six major AI coding assistants that bypasses approvalINFOSECURITY-MAGAZINE.COM
9 JulMicrosoft to retire the OWA Light client in Exchange ServerMicrosoft has announced plans to disable Outlook Web Access (OWA) Light, the lightweight version of the Outlook Web App email client, in a future Exchange Server update. [...]BLEEPINGCOMPUTER.COM
9 JulSummer of ClearinghousesEveryone seems to have announced a clearinghouse over the past few weeks. We did too. Ours is called Athena, and the main thing that sets it apart is that it was already real and running when we announced it — built quietly months earlier, heads down, taking findings and shipping…THEHACKERNEWS.COM
9 JulChinese-Funded Interpol Cybercrime Crackdown Leads to 5,800 ArrestsOperation First Light 2026, coordinated by Interpol and funded by the Chinese government, has led to 5,811 arrestsINFOSECURITY-MAGAZINE.COM
9 JulAI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps UpAI has changed how fast attacks move. Work that once took an attacker days now takes minutes. Using models like Mythos, attackers write tailored bait, pick targets, test what lands, and jump to the next host before your team clears the first alert. That is the gap, and it is not …THEHACKERNEWS.COM
9 JulInvited to a “job interview” with Netflix or OpenAI? Beware! Your Google password could be at riskHave you received an email from a recruiter at Adobe, Netflix, or OpenAI offering you an exciting new marketing role? Well, before you start brushing up your interview technique, take a closer look at who is really behind it. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
9 JulNSA revives 'Tailored Access Operations' name for elite hacking unitNSA last week changed the moniker of its Office of Computer Network Operations (CNO) back to Tailored Access Operations (TAO), a name that is sure to elicit nostalgia among the broader digital community for a group with roots in the early 1990s.THERECORD.MEDIA
9 JulA Majority of European Lawmakers Voted Against Letting Big Tech Read Our Messages. They’re Going to Anyway.Companies will once again be allowed to scan citizens’ personal texts, emails, and social media messages via the “chat control” bill to find child abuse material online.WIRED.COM
9 JulNew Forg365 phishing platform uses AI to target Microsoft 365 accountsA new phishing-as-a-service (PhaaS) operation called Forg365 focuses on stealing Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device code methods with AI-assisted lure generation. [...]BLEEPINGCOMPUTER.COM
9 JulThe Hidden Security Risks of Reduced Summer IT CoverageSecurity operations don't slow down when IT teams take vacation, but staffing levels often do. Kaseya explains how AI-driven automation can help organizations maintain consistent security operations and reduce reliance on manual processes year-round. [...]BLEEPINGCOMPUTER.COM
9 JulAs Global Conflicts Go Digital, Businesses Need Wartime GameplansThe fate of a Ukrainian tax software company shows how modern cyberwarfare can claim casualties far beyond the battlefield, and how businesses across the ocean still need to protect themselves.DARKREADING.COM
9 JulHow World Cup crypto prediction sites take your moneyCrypto prediction games promise easy wins, but some are little more than token sales or outright scams. Here's what to look for.MALWAREBYTES.COM
9 Jul6.9 million driver’s license numbers stolen from AssuranceAmericaMillions of AssuranceAmerica customers are being notified after attackers accessed driver's license numbers and other personal information.MALWAREBYTES.COM
9 JulThe SQL Server Unicode problem: why your data might not be what you think it is?Having examined Unicode handling in other databases, we will see that its implementation in SQL Server proves to be particularly complex. We will discover how the burden of backwards compatibility has given rise to new features which, in reality, have serious shortcomings.SYNACKTIV.COM
9 JulWhat About the Role of AI? Updated Guidance on Secure by DesignCIS and SAFECode have updated Secure by Design: A Developer’s Guide to Building Safer Software to address the role of AI on software security.CISECURITY.ORG
9 Jul5 Major Emerging Risks to Large-Scale EventsTo create safer, more secure large-scale events, read our recommendations for defending against five emerging risks to public gatherings.CISECURITY.ORG
9 JulWinning 54% of the timeWith Wimbledon's help, Hazel argues against the popular myth that "Attackers only need to be right once, but defenders need to be right 100% of the time."TALOSINTELLIGENCE.COM
9 JulThe Supreme Court allows Texas age-verification law.European Central Bank warns of AI risks.THECYBERWIRE.COM
9 JulReduce Human Risk | Build a Strong Security Awareness Training Program | HuntressBuild a security awareness training program that actually changes user behavior. Huntress Managed SAT delivers engaging content, phishing sims, and results.HUNTRESS.COM
9 JulAI Agents Are a New Kind of Identity & Most Organizations Aren't ReadyIf you're handling them like a service account or API token, consider yourself behind. AI agents need a fundamentally different approach.DARKREADING.COM
9 JulOpenMandriva Linux says contributor tried to sabotage the projectThe OpenMandriva Linux project announced that it was the target of an attempted act of internal sabotage after a dispute among contributors. [...]BLEEPINGCOMPUTER.COM
9 JulIntroducing OAuth Support for AWS MCP ServerAWS MCP Server using the same credentials and sign-in methods that you already use for connecting to the AWS Management Console or AWS Command Line Interface (AWS CLI) through a familiar browser-based experience powered by industry-standard OAuth. This new sign-in path supports A…AWS.AMAZON.COM
8 JulWeekly Threat Bulletin – July 8th, 2026These are the top threats you should know about this week.F5.COM
8 JulClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud ToolkitElastic Security Labs tracks REF6045, an active operator-assisted banking fraud operation targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges.ELASTIC.CO
8 JulAI Readiness, Microsoft MISA, and the Punk Rock Museum with JP Bourget of Blue CycleJP Bourget sold a SOAR company, named his next one after cycling and blue teaming, got Fat Mike from NOFX to show up at his RSAC event, then took him to DEFCON, where he ended up in a DJ booth at Caesars Palace with Steve Aoki. Somewhere in between all of that, he built Blue Cycl…THECYBERWIRE.COM
8 JulMy Stack Simulator, (Wed, Jul 8th)The stack is a memory region where a program stores temporary data -&#;x26;#;xc2;&#;x26;#;xa0;like local variables and return addresses. Think of the stack as a pile of plates in your kitchen: you can only add a new plate to…ISC.SANS.EDU
8 JulState IDs for AI Agents: Will Estonia Set a Precedent?The world's digital testing ground plans to help people use AI agents for government purposes.DARKREADING.COM
8 JulDuckDuckGo browser now blocks YouTube video adsDuckDuckGo announced that its browser can now block most video ads on YouTube, including those shown before the video starts playing and during playback. [...]BLEEPINGCOMPUTER.COM
8 JulGitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking SignaturesNew research shows that a signed Git commit's hash is not the one-of-a-kind name that much of the software world assumes it to be. Given any signed commit, someone without the signing key can mint a second commit with the same files, author, and date, and a valid signature, GitHu…THEHACKERNEWS.COM
8 JulThe Verification Step Is the New ATO Battleground in 2026For years, account takeover (ATO) followed a predictable script. Attackers bought stolen credentials in bulk, ran them through automated tools, and waited for matches. Credential stuffing was cheap, scalable, and for defenders, relatively well understood. That era is ending. Not …THEHACKERNEWS.COM
8 JulGitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in CodeAn AI coding assistant that refuses to answer a dangerous request in its chat box can answer it anyway if the same request is broken into small, ordinary-looking steps inside a code editor. That is the finding of a new study of GitHub Copilot by researchers Abhishek Kum…THEHACKERNEWS.COM
8 JulYour next car could be watching your faceDriver-monitoring technology is becoming mandatory in new cars, but privacy experts warn it could create new risks alongside the safety benefits.MALWAREBYTES.COM
8 JulSpain arrests alleged supporter of pro-Russian hacktivist groups after FBI tipAn FBI tip linked a man living in Spain to the hacking groups CyberArmy of Russia Reborn (CARR), Z-Pentest and NoName057(16).THERECORD.MEDIA
8 JulEU unveils cyber plan to reduce reliance on foreign AI systemsThe communication, adopted in Strasbourg on July 7, is built around three pillars: making frontier AI “safe, accessible and deployable” for European cybersecurity, preparing the EU’s cyber ecosystem and scaling European AI capabilities.THERECORD.MEDIA
8 Jul3 Ways AI Powers Service Desk Attacks and How to Prevent ThemSpecops Software explains how AI is making service desk impersonation attacks more convincing, personalized, and scalable, along with practical steps organizations can take to strengthen onboarding and identity verification. [...]BLEEPINGCOMPUTER.COM
8 JulWiz ASM for any environment, any risk, everywhereProtect the modern attack surface with new auto-reconnaissance capabilities, deep internal context, and the Red Agent to find any risk, anywhere.WIZ.IO
8 JulNew Ghost Phishing Wave Is Breaking Traditional Email SecurityA recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This “ghost phishing” technique keeps the malicious page hidden until it decrypts and comes to life inside the victim’s browser. For security leaders, the risk …THEHACKERNEWS.COM
8 JulThe CISO’s guide to post-quantum mandates and migrationsOver a dozen major economies have now published post-quantum cryptography (PQC) adoption guidance. As a CISO, you’re probably well into your migration plan and know the most difficult part has little to do with changing algorithms. The real leadership challenge is driving coordin…AWS.AMAZON.COM
8 JulGhostApproval: A Trust Boundary Gap in AI Coding AssistantsUncovering a category-level blind spot in modern AI coding assistants, and why the Human-in-the-Loop safety model fails against this classic threatWIZ.IO
8 JulAI Coding Agents Found Triggering Endpoint Security Rules Built to Catch AttackersSophos looked at a week of its own endpoint data and found that AI coding agents such as Claude Code, Cursor, and OpenAI Codex are setting off detection rules written to catch human intruders. The agents are not malicious. They just do a lot of things that, to a behavioral engine…THEHACKERNEWS.COM
8 JulDesigning for the inevitable: System prompt leakage and mitigations in generative AI applicationsSystem prompts form the foundation of generative AI applications. A system prompt is a collection of instructions and operational context provided to a large language model (LLM) that shapes how the model behaves and interacts with users and tools. System prompts often contain pr…AWS.AMAZON.COM
8 JulCash App owner to pay $45 million to settle allegations of lax securityState attorneys general announced the bipartisan agreement with Block, Inc. on Wednesday, saying that the company incorrectly promised users that Cash App offered the same protections as a bank.THERECORD.MEDIA
8 JulMexico's New Cyber Plan Faces Its First Real TestThe Latin American nation's cybersecurity plan — still in the expansion phase — has to survive its own knockout round during the FIFA World Cup.DARKREADING.COM
7 JulMicrosoft testing new Cloud Rebuild Windows 11 recovery featureMicrosoft has begun testing the Cloud Rebuild recovery feature in the latest Windows 11 Insider Preview builds released for users in the Experimental channel. [...]BLEEPINGCOMPUTER.COM
7 JulBeyondTrust warns of critical flaws in remote access softwareBeyondTrust warned customers to patch two critical security flaws in its Remote Support (RS) and Privileged Remote Access (PRA) software that could allow attackers to bypass authentication. [...]BLEEPINGCOMPUTER.COM
7 JulScammers are using AI to sell impossible flowersAI-generated flower scams are blooming online, with scammers using fake images to sell seeds for plants that don't exist, like these "cat's face orchids."MALWAREBYTES.COM
7 JulUK Government Launches Cyber Resilience Pledge, Claiming 60+ SignatoriesMore than 60 organizations, including M&S, Microsoft UK and Vodafone, have signed the UK government's Cyber Resilience Pledge, a new initiative aimed at boosting cyber security and resilience across British businessesINFOSECURITY-MAGAZINE.COM
7 JulMicrosoft to enable Windows settings backup by default for orgsMicrosoft says the Windows settings backup and restore tool will be enabled by default on Microsoft Entra-joined or Microsoft Entra hybrid-joined enterprise systems after upgrading to Windows 11 26H2. [...]BLEEPINGCOMPUTER.COM
7 JulSavi’s app aims to protect consumers from realistic AI scams like kidnappers demanding ransomThe company just raised $7 million in seed funding, and is launching its app for iPhone and Android on Tuesday.TECHCRUNCH.COM
7 JulClaude Code’s hidden tracker was an “experiment,” says AnthropicAnthropic's hidden Claude Code tracker has raised new questions about prompt steganography and developer trust.MALWAREBYTES.COM
7 JulWebinar tomorrow: Why modern email attacks require a new approach to defenseTomorrow's webinar explores how behavioral AI can help organizations detect sophisticated phishing, business email compromise, and account takeover attacks while reducing alert fatigue through automated investigation and response workflows. [...]BLEEPINGCOMPUTER.COM
7 JulTwo arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraudTwo young men have been arrested in the Netherlands on suspicion of running a phishing operation that harvested the credit card details of unsuspecting victims. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
7 JulFake Netflix, Coca-Cola, and FIFA job scams target marketersA fake recruiter phishing campaign uses trusted brands, nested redirects, and fake Google prompts to steal accounts.MALWAREBYTES.COM
7 JulScattered Spider’s Structure More Like a Cybercrime Collective Than a Unified GangGroup-IB analysis argued Scattered Spider is a decentralized collective of independent clustersINFOSECURITY-MAGAZINE.COM
7 JulThe GitHub Actions Attack Pattern Your CI Security Scanners MissActiveState explains how GitHub Actions attack chains can evade traditional CI security scanners, why passing a scan doesn't guarantee a secure pipeline, and how organizations can better govern their CI/CD workflows. [...]BLEEPINGCOMPUTER.COM
7 JulPublic GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo DataA public issue can trick GitHub Agentic Workflows into leaking the contents of an organization's private repositories, researchers at Noma Security have shown. The attacker needs only to open a normal-looking issue on a public repository, with no stolen credentials and no access …THEHACKERNEWS.COM
7 JulSpain arrests suspected member of pro-Russian hacktivist groupsThe National Police in Spain have arrested a man who is suspected of being an active member of the CyberArmy of Russia Reborn (CARR) and Z-Pentest, both pro-Russian hacktivist groups. [...]BLEEPINGCOMPUTER.COM
7 Jul'GitLost' Flaw Leaks Private Data from GitHub's Agentic WorkflowsThe flaw allows an unauthenticated attacker to craft a GitHub Issue in an org's public repository and then silently pull data from its private repos, too.DARKREADING.COM
7 JulDEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 AccountsA Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lures to take control of victim accounts between the last week of June 2026 and into early July, per findings from ZeroBEC. "The campaign did not depend on a fake Microsoft password pa…THEHACKERNEWS.COM
7 JulSupreme Court allows Texas app law requiring age verification to take effectA student advocacy organization and tech trade group had appealed to the high court to stay the Texas App Store Accountability Act on an emergency basis until the lower court rules.THERECORD.MEDIA
7 JulRogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX ChatbotsA critical flaw in Google's Dialogflow CX could have let an attacker with edit rights on one Code Block-enabled agent compromise other Code Block-enabled agents in the same Google Cloud project. From there, they could read live conversations, steal the data users shared, and make…THEHACKERNEWS.COM
7 JulHow the Reddit and Discord false report scam steals accountsScammers are tricking Reddit and Discord users into handing over login codes by claiming they were involved in a false report.MALWAREBYTES.COM
7 JulDialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data TheftVaronis reported the flaw to Google in late 2025 and it has been addressed, but it reminds defenders to take a fresh look at their AI Infrastructure security.DARKREADING.COM
6 JulOpera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited PagesResearchers found a flaw in Opera GX, the gaming-focused version of the Opera browser, that let a malicious website silently install a browser add-on and use it to lift specific data from the pages a victim visits. In a proof of concept, they reconstructed a signed-in user's…THEHACKERNEWS.COM
6 JulThe security leaders defining the next decade aren’t in CISO seats yetThe first recognition program for the security leaders who will define the future of cybersecurity.CYBERSECURITYDIVE.COM
6 JulWhy schools are easy prey for hackers — and why they struggle to fight backPower plants and gas pipelines might receive more attention, but schools are arguably more vulnerable.CYBERSECURITYDIVE.COM
6 JulHow to Evaluate an AI SOC Platform in 2026: 6 Capabilities That Separate Leaders from Bolt-On AI solutionsBuilding a shortlist for an AI SOC evaluation can be tough. SIEM, SOAR, and pureplay AI SOC vendors are all saying the same thing. But behind the identical label sit very different products, from chat assistants bolted onto a legacy SIEM to agent platforms that run detection, tri…THEHACKERNEWS.COM
6 JulChoose your WhatsApp username carefullyWhatsApp is introducing usernames to help protect your phone number. Just make sure you don't undermine that privacy by choosing the wrong one.MALWAREBYTES.COM
6 JulHidden Web Prompts Trick AI Agents Into Sending MoneyHidden prompts on malicious websites trick AI agents into making payments or trusting fake sites, exposing new risks for autonomous AI workflows. Zscaler ThreatLabz documented two active campaigns that embed hidden instructions in web pages to manipulate AI agents, not human user…SECURITYAFFAIRS.COM
6 JulIndirect Prompt Injection in Web Content Targets AI AgentsZscaler found sites hiding prompt-injection text to manipulate AI agents into crypto paymentsINFOSECURITY-MAGAZINE.COM
6 JulOpera GX Flaw Let Sites Auto-Install Mods to Steal DataOpera GX flaw let sites automatically install mods to steal data from other pages, now patchedINFOSECURITY-MAGAZINE.COM
6 JulSoftware Is Now Written at the Speed of Thought. Security Isn't.Every evolution in software development has reduced the friction between an idea and a deployable application. AI may remove the final barrier, but it also removes many of the moments where security decisions have traditionally taken place. [...]BLEEPINGCOMPUTER.COM
6 JulNew Iran-Nexus Hacking Group Targets Israel Government and IT SectorsCheck Point researchers have identified a new cyber adversary targeting Israeli government and IT businesses, tracked as ‘Cavern Manticore’INFOSECURITY-MAGAZINE.COM
6 JulHow to tell if an image is AI-generatedScammers are using AI-generated images to make fake stories more convincing. Here's how to separate real from fake.MALWAREBYTES.COM
6 JulVietnam arrests suspects behind HiAnime anime piracy serviceVietnamese authorities have arrested and are prosecuting seven suspects believed to have run HiAnime, the largest anime piracy streaming service before its shutdown in June. [...]BLEEPINGCOMPUTER.COM
6 JulAttackers vote themselves $20 million in BONK cryptocurrencyBonkDAO said in a social media post that it was the victim of a “malicious governance proposal,” or an attack in which holders of a large amount of BONK used that leverage to vote more coins into their wallets.THERECORD.MEDIA
6 JulPhishing poses as big-brand job interview to steal Google accountsA phishing campaign is impersonating more than 30 well-known brands, including Adobe, Netflix, Coca-Cola, and OpenAI, in fake job interviews to steal Google account credentials from marketing professionals. [...]BLEEPINGCOMPUTER.COM
5 JulFlipper Zero firmware development continues with community helpFlipper Devices says development of the Flipper Zero firmware will continue, albeit with a smaller internal team and greater reliance on community contributions. [...]BLEEPINGCOMPUTER.COM
4 JulAlibaba reportedly bans employees from using Claude CodeAlibaba has reportedly classified Claude Code as high-risk software.TECHCRUNCH.COM
3 JulGovernment and Healthcare Are the Weakest Links in Global Email SecurityGovernment and healthcare sectors have weak email security. Many domains lack SPF, DMARC, DKIM, and MTA-STS, leaving them open to phishing attacks. Comparitech analyzed live DNS records for 5,849 domains across 13 sectors and scored each one out of 8 points based on four standard…SECURITYAFFAIRS.COM
3 JulChinese LLMs Broaden the Gap Between Attackers & DefendersTwo new models from Chinese firms compete with top US mainstream and frontier models. Should cyber-defenders be worried?DARKREADING.COM
3 JulARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkitA new phishing-as-a-service (PhaaS) platform dubbed "ARToken" appears to operate as an affiliate of the EvilTokens phishing platform, giving researchers a glimpse into an extensive toolkit designed to compromise Microsoft 365. [...]BLEEPINGCOMPUTER.COM
2 Jul19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking ChargesA teenager accused of belonging to the hacking group Scattered Spider has been extradited from Finland to face U.S. charges of conspiracy, computer intrusion, and fraud, the U.S. Department of Justice announced on July 1. Peter Stokes, 19, a dual U.S. and Estonian citiz…THEHACKERNEWS.COM
2 JulAlleged Scattered Spider Member Extradited to USA teenager accused of hacking as part of Scattered Spider has been arrestedINFOSECURITY-MAGAZINE.COM
2 JulAlleged Scattered Spider hacker extradited to the United StatesA dual United States and Estonian citizen has been extradited to the U.S. to face charges alleging he was a member of the Scattered Spider hacking collective. [...]BLEEPINGCOMPUTER.COM
2 JulOpera rolls out Paste Protect feature to fight ClickFix attacksOpera has introduced Paste Protect, a security feature designed to block ClickFix-style attacks that trick users into executing malicious commands through social engineering. [...]BLEEPINGCOMPUTER.COM
2 JulBuild AI Security Agents with Wiz MCPPower AI-driven security with trusted security context, Wiz AI Agents, and Wiz AI Skills.WIZ.IO
2 JulIdentity Lifecycle Management Wasn't Built for AI AgentsIdentity lifecycle management was architected around a person with an employment record, a manager, and a departure date. AI agents have none of those. As autonomous principals proliferate across enterprise environments, the governance model built for humans develops structural b…THEHACKERNEWS.COM
2 JulMicrosoft fixes bug that removed Copilot buttons in OutlookMicrosoft has fixed a known issue causing the Copilot Chat or Copilot buttons in Classic Outlook to disappear for Windows users with the Copilot Chat (Basic) license. [...]BLEEPINGCOMPUTER.COM
2 JulWinRAR flaw could allow attackers to take control of your computerA new WinRAR update fixes a serious security flaw, but without automatic updates many users could miss the patch.MALWAREBYTES.COM
2 JulGoogle loses final appeal to overturn €4.1 billion EU fineCourt of Justice of the European Union (CJEU) has dismissed Google's final appeal against a €4.1 billion ($4.7 billion) antitrust fine over the company's use of Android to promote its Chrome browser and search service. [...]BLEEPINGCOMPUTER.COM
2 JulSupreme Court decision threatens EU-US data transfer agreementIn a Tuesday letter, Max Schrems, the founder of the Vienna-based privacy advocacy organization noyb, told European officials he plans to sue to invalidate the EU-U.S. Data Privacy Framework (DPF) that allows for the transfer of personal data from the EU to U.S. companies.THERECORD.MEDIA
2 JulEurope Confirms Record €4.1B Penalty Against Google for Android PracticesEU’s top court upheld a €4.1B fine against Google, ruling it abused Android’s market dominance through restrictive licensing practices. The Court of Justice of the European Union issued its ruling on July 2, 2026, and Google lost. The court dismissed the appeal brough…SECURITYAFFAIRS.COM
2 JulThe Supreme Court rules that location history is protected by the Constitution.The KIDS Act clears the House of Representatives.THECYBERWIRE.COM
2 JulClaude Fable relaunch disappoints users with nerfed performanceClaude Fable, the company's most powerful model, is now available to all users, but early impressions are disappointing, as it appears to be nowhere near the original release. [...]BLEEPINGCOMPUTER.COM
2 JulClaude Fable 5 isn’t permanently leaving subscriptions, Anthropic saysAnthropic says Claude Fable 5 won't be accessible via Claude subscriptions after July 7, but it's not a permanent change, and the company expects the model to return outside the usage-based plan soon. [...]BLEEPINGCOMPUTER.COM
1 JulWeekly Threat Bulletin – July 1st, 2026These are the top threats you should know about this week.F5.COM
1 JulHow Madalina Petrea Runs Marketing for 27+ Cybersecurity Franchise Owners Across 4 ContinentsCyberGlobal is the world's first cybersecurity franchise, with Madalina Petrea heading up marketing there. What does it mean to run marketing at a cyber franchise? Supporting 27+ franchise owners across the US, Europe, Africa, and Asia who sell cybersecurity services to small bus…THECYBERWIRE.COM
1 JulAzure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ AttemptsCybersecurity researchers have warned of a "massive, ongoing, automated password spray attack" aimed at Microsoft's Azure command-line interface (CLI), compromising dozens of accounts in the process. The activity, per Huntress, originates from an IPv6 address range (2a0a:d683::/3…THEHACKERNEWS.COM
1 JulAdobe patches seven max severity ColdFusion, Campaign flawsAdobe has released security patches for seven maximum-severity vulnerabilities in the ColdFusion web app development platform and the Campaign Classic marketing automation platform. [...]BLEEPINGCOMPUTER.COM
1 JulChatGPT produced graphic violent images that shocked researchersAI assistants like ChatGPT are supposed to have appropriate guardrails to stop people creating harmful content. However, they don't always work.MALWAREBYTES.COM
1 JulMicrosoft Accelerates Quantum-Safe Push with New TimelineMicrosoft has brought forward its timelines for transitioning to post-quantum cryptography (PQC)INFOSECURITY-MAGAZINE.COM
1 JulAmazon fined $2.25M for withholding evidence from fraud victimsThe U.S. Federal Trade Commission (FTC) says Amazon will pay a $2.25 million civil penalty to settle charges that it blocked identity theft victims' access to transaction records. [...]BLEEPINGCOMPUTER.COM
1 JulAnthropic's Fable 5 and Mythos 5 Are Back with New Security GuardrailsThe new classifier in Fable 5 blocks the jailbreak technique that prompted the US export controls “in over 99% of cases”INFOSECURITY-MAGAZINE.COM
1 JulMicrosoft fixes GIF functionality in the Windows Emoji PanelMicrosoft has fixed the GIF functionality in the Emoji Panel for Windows 11 and Windows Server users after the provider shut down its service. [...]BLEEPINGCOMPUTER.COM
1 JulMicrosoft Accelerates Post-Quantum Cryptography Shift to 2029Microsoft on Tuesday said it's accelerating its quantum safe security roadmap, stating technology advances in quantum computing are making it essential to replace existing encryption standards sooner than previously expected. "Advances in quantum research and development have shi…THEHACKERNEWS.COM
1 JulChrome needs another whopper update to fix 382 security bugsGoogle released a huge update of 382 security fixes, 15 of which were rated as critical. So, it's time to update agaiMALWAREBYTES.COM
1 JulUS lifts export controls on Anthropic’s frontier cybersecurity AI modelsAnthropic said export controls on certain models had been lifted after the company came to a series of agreements with the government.THERECORD.MEDIA
1 JulHow to use the AWS Workload Credentials Provider for cross-account secret retrieval and prefetching secretsIf you manage secrets across multiple AWS accounts or need faster secret access for latency-sensitive applications, this post shows you how to meet those requirements using two new features of the AWS Workload Credentials Provider (provider). You will learn how to configure role …AWS.AMAZON.COM
1 JulUS lifts export restrictions on Anthropic’s most advanced AI models.Adobe patches seven maximum-severity flaws. Business news: Quantifind lands $200 million.THECYBERWIRE.COM
1 JulHackers target Microsoft 365 accounts with 81 million login attemptsAn aggressive password-spraying campaign targeting Microsoft 365 environments generated more than 81 million login attempts over a two-week period. [...]BLEEPINGCOMPUTER.COM
1 JulSecure Amazon container workloads using container attribute-based rules in AWS Network FirewallToday, you can use AWS Network Firewall to protect traffic flowing to and from containerized applications on Amazon Elastic Kubernetes Service (Amazon EKS) and Amazon Elastic Container Service (Amazon ECS) clusters. If you run AI and machine learning (ML) workloads on Amazon EKS—…AWS.AMAZON.COM
1 JulQuantifind has secured $200 million in a funding round led by Summit Partners.Straiker has raised $64 million in a Series A round. F5 has acquired Denver-based AI governance firm SurePath AI.THECYBERWIRE.COM
1 JulFake Perplexity Chrome extension spies on your searchesA fake Perplexity Chrome extension secretly monitored searches. If you installed "Search for perplexity ai," you need to remove it manually.MALWAREBYTES.COM
30 JunNew BioShocking Attack Tricks AI Browsers Into Leaking User CredentialsConvince an AI browser that it is playing a game, and it can hand over your login details. That is the finding behind BioShocking, a technique from security firm LayerX that tricked six AI browsers and assistants into copying a user's credentials and sending them to an attac…THEHACKERNEWS.COM
30 JunJune 2026 Apple Updates, (Tue, Jun 30th)Apple released updates for iOS/iPadOS, macOS, and Safari on Monday. There have been no updates for other Apple operating systems (visionOS, watchOS, tvOS). Usually, Apple updates all products at the same time.
ISC.SANS.EDU
30 JunUK Healthcare Sector Records Tenfold Increase in Cyber-AttacksSonicWall records 264,000 events in first five months of 2026 as UK hospitals come under siegeINFOSECURITY-MAGAZINE.COM
30 JunKali Linux 2026.2 released with 9 new tools, NetHunter updatesKali Linux 2026.2, the second release of the year, is now available for download, featuring 9 new tools and numerous Kali NetHunter improvements. [...]BLEEPINGCOMPUTER.COM
30 JunMircosoft adds smarter bot protection to Teams meetingsMicrosoft has introduced a new Teams admin policy that allows organizers to prevent third-party bots from joining meetings without approval. [...]BLEEPINGCOMPUTER.COM
30 JunVerifiable Digital Credential PresentmentThis blog post is #4 in our series on Verifiable Digital Credentials (VDCs). Our other posts can be found via Post #1, Post #2, and Post #3. In earlier posts, we discussed how verifiable digital credentials (VDCs) are issued and compared the underlying credential formats (ISO/IEC…NIST.GOV
30 JunAI-Generated Workflows Are a Silent Security DisasterTeams are dealing with a truly dangerous problem — automation that works, but that no one understands.DARKREADING.COM
30 JunTrain, triage, repeat: The AI agent changing how we fight phishingLearn how Red Canary engineered a super agent—blending ML, a rules engine, similarity, agentic AI, and LLMs—to classify phishing emails.REDCANARY.COM
30 JunAn intelligence budget 'super user' job is now in the hands of Russ VoughtRussell Vought, director of the White House Office of Management and Budget (OMB), assumed hands-on responsibility for overseeing the spending plans of intelligence agencies following the recent departure of Amaryllis Fox Kennedy, a senior intelligence official who simultaneously…THERECORD.MEDIA
30 JunMicrosoft 365 Hardening and Huntress Managed ISPMMost Microsoft 365 environments are missing more than half of the recommended security controls, even with tooling in place. Here's why that happens and what Huntress Managed ISPM does about it.HUNTRESS.COM
30 Jun282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic StudyResearchers tested 444 AI chatbot apps for iPhone and found that 282 of them, nearly two-thirds, exposed paid AI access through their network traffic. In many cases, the path in was visible just by watching what the app sent: a plaintext API key, a reusable token, or a backend se…THEHACKERNEWS.COM
30 JunUpdate time: Apple releases security patches for iOS, MacOS Tahoe, SafariA new Apple update fixes a multitude of browser and browser related vulnerabilities which have been public knowledge for a whileMALWAREBYTES.COM
30 Jun6 Key Takeaways: Strengthening Public Safety Through Collective DefenseHere are six key takeaways from a CIS webinar for how U.S. SLTT agencies can strengthen public safety through collective defense.CISECURITY.ORG
30 JunSilent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet AddressesCybersecurity researchers have flagged an active browser extension campaign that is designed to steal cryptocurrency by stealthily replacing wallet addresses when unsuspecting users initiate a transaction. The cryptocurrency clipper activity has been codenamed Silent Swap by McAf…THEHACKERNEWS.COM
30 JunCIA chief highlights major shifts in agency’s tech approachCIA Director John Ratcliffe said artificial intelligence capabilities are "akin to digital nuclear weapons.”THERECORD.MEDIA
30 JunWhy Identity Security Is Your Cyber Career Entry PointAs AI reshapes cybersecurity workflows, John Paul Cunningham, CISO at SIlverfort, says the technology is creating opportunities rather than eliminating jobs — and there are more ways than ever to break into the essential field.DARKREADING.COM
30 JunWatch out for “high paying, low effort” Amazon job textsScammers are using Amazon and the promise of big money to lure people in to their trap.MALWAREBYTES.COM
30 JunNew BioShocking attack manipulates AI browser into data theftA new prompt injection attack dubbed "BioShocking" could trick AI-powered browsers into treating real-world risky actions as part of a fictional scenario, causing them to ignore any safety guardrails. [...]BLEEPINGCOMPUTER.COM
30 JunMicrosoft accelerates quantum-safe roadmap as risks growMicrosoft announced today that it is accelerating its quantum-safe security roadmap, saying advances in quantum computing are bringing the need to replace today's encryption standards sooner than previously expected. [...]BLEEPINGCOMPUTER.COM
30 JunAttackers Hijack Exposed AI Endpoints to Power Offensive OpsAttackers don't need any special authentication to reach a target endpoint — they just need to know where it is.DARKREADING.COM
30 JunAnthropic rolls out Sonnet 5 with near-Opus 4.8 performance at a lower priceAnthropic is now rolling out Sonnet 5, and it's almost as good as the Opus range, but it is designed to be cheaper than the company's flagship model. [...]BLEEPINGCOMPUTER.COM
29 JunFBI Sounds Alarm Over Russian Intelligence Signal PhishingThe FBI claims Russian spies are targeting Signal backup keysINFOSECURITY-MAGAZINE.COM
29 JunUS seizes hundreds of FIFA World Cup illegal streaming domainsThe U.S. Justice Department's Criminal Division has seized nearly 400 web domains used for illegally streaming matches at the FIFA World Cup. [...]BLEEPINGCOMPUTER.COM
29 JunThe Borderless Attack Surface: Securing Public Sector Hybrid EnvironmentsAligning Modern CNAPP Telemetry with realistic risk assessments to drive agency efficiency through cross-team collaborationWIZ.IO
29 JunAdding some Automation to the favicon.ico method of Host Recon, (Mon, Jun 29th)I&#;x26;#;39;m in the throes of target host recon for another pentest, and thought I&#;x26;#;39;d share some workflow / automation stuff.
In the past, I&#;x26;#;39;ve discussed using histori…ISC.SANS.EDU
29 JunStegoAd: How 119 Fake Browser Extensions Stole Credentials and Ran Ad Fraud for Two YearsMicrosoft shut down the StegoAd campaign, which used 119 malicious Edge extensions, hit 2.6M installs, and ran undetected for two years. Microsoft just shut down one of the more technically clever malicious extension campaigns it’s ever documented. The operation, named Steg…SECURITYAFFAIRS.COM
29 JunUkraine to use seized crypto from cybercrime group to buy war bondsUkraine's Asset Recovery and Management Agency (ARMA), which manages property seized in criminal proceedings, said more than $8.3 million in cryptocurrency had been transferred to its official digital wallet following a court order.THERECORD.MEDIA
29 JunOpenAI Reveals GPT-5.6 Sol Cybersecurity Model, Restricts Early AccessOpenAI is previewing its GPT-5.6 Sol model to a vetted few at the US government's requestINFOSECURITY-MAGAZINE.COM
29 JunTelegram-Based Millenium RAT Campaign Infects 60,000 DevicesGroup-IB says Millenium RAT, now rewritten in C++, has hit 62,289 devices in 160+ countriesINFOSECURITY-MAGAZINE.COM
29 JunAgentic AI Has an Identity Problem and Attackers Know ItAI agents can access data, trigger workflows, and take action across enterprise systems. Token Security explains why governing these privileged identities is becoming essential for enterprise security. [...]BLEEPINGCOMPUTER.COM
29 JunWhatsApp is Finally Getting Usernames to Help Keep Phone Numbers PrivateWhatsApp on Monday officially announced the start of global reservations of usernames with an aim to protect the privacy of more than three billion users on the messaging platform. The optional feature is designed to help users connect with someone on the service through username…THEHACKERNEWS.COM
29 JunIn major privacy win, Supreme Court rules geofence warrants are protected by privacy rightsThe Supreme Court's decision to limit geofence warrants is a win for privacy advocates, who called their use unconstitutional but sought an outright ban.TECHCRUNCH.COM
29 JunUS posts $10 million reward over Russian cyber campaign targeting Signal, WhatsAppRussia-linked hacking groups tracked as UNC5792 and UNC4221 have socially engineered their way into the messaging accounts of government officials.THERECORD.MEDIA
29 JunU.S. offers $10 million for hackers targeting WhatsApp, Signal usersThe U.S. Department of State is offering up to $10 million for information that helps identify or locate members of the UNC5792 and UNC4221 hacker groups, which are linked to Russia's intelligence and military services. [...]BLEEPINGCOMPUTER.COM
29 JunBridging the Visibility Gap: A Unified Security Operating Model for Hybrid Cloud TeamsMove beyond chasing vulnerabilities to a unified hybrid risk strategy. The Sensor Workload Scanner is now GA and extends our risk prioritization engine to on-premise environments to identify the critical attack paths across your hybrid cloud.WIZ.IO
29 JunWhatsApp rolls out usernames to help users hide their phone numberWhatsApp is finally allowing users to reserve usernames, a privacy feature that lets them hide their phone numbers from people not in their contact list. [...]BLEEPINGCOMPUTER.COM
29 JunMicrosoft extends Windows Server 2022 hotpatching until October 2027Microsoft has extended Windows Server 2022 hotpatching until October 2027, one year after the mainstream end date of October 2026. [...]BLEEPINGCOMPUTER.COM
29 JunJustices rule that cellphone location histories are protected by the Fourth AmendmentPolice must get a warrant to request geofence data involving individual cellphones, the U.S. Supreme Court ruled in what represents a victory for privacy advocates.THERECORD.MEDIA
29 JunCan Clothes Make You Invisible to Facial Recognition?Does life feel Orwellian sometimes? One researcher has a solution for you: graphic tees that confuse the neural networks in surveillance cameras.DARKREADING.COM
29 JunMeta Contractors Posed as Teens to Prompt Rival Chatbots About Suicide, Sex, and DrugsHundreds of contractors working on a project for Meta pretended to be kids—and then prompted rival chatbots like Gemini and ChatGPT to discuss high-risk subjects.WIRED.COM
29 JunWhatsApp Usernames Are Coming. You Can Reserve Yours Right NowWhatsApp will introduce usernames later this year, letting its 3 billion users connect without sharing phone numbers. WhatsApp has over three billion users, and it’s finally letting them talk to each other without exchanging phone numbers. The company announced this week th…SECURITYAFFAIRS.COM
28 JunSecurity Affairs newsletter Round 583 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. New FBI Alert: Russian Intell…SECURITYAFFAIRS.COM
27 JunHooking Windows Named PipesDuring security assessments, we often see desktop applications composed of several processes. Some of them run as SYSTEM, and others run in the user session context, meaning they are unprivileged. These processes need to communicate in some way, and often use Windows Named Pipes …SYNACKTIV.COM
27 JunDeep-dive into the deployment of an on-premise low-privileged LLM serverIn 1826, children fantasized riding horses in the Wild West. In 1926, it was outrunning the law as a moonshiner. In 2026, managing distributed inference servers without leaking all the company data is surely a universal dream among the new generation. This article rewinds our jou…SYNACKTIV.COM
27 Jun2025 winter challenge writeupCreating quines is a game that has always fascinated computer scientists. The journal Software: Practice and Experience dedicated an article to the subject in 1972—well before Intel released its first 32-bit x86 processor (1985). Even today, many enthusiasts continue to explore t…SYNACKTIV.COM
27 JunWireless-(in)Fidelity: Pentesting Wi-Fi in 2025Despite the advancements that have been made in Wi-Fi security with the arrival of WPA3, some misconfigurations and legacy protocols still remain. In this blogpost, we share insights into Wi-Fi related findings encountered during penetration testing engagements. We will present c…SYNACKTIV.COM
27 JunWhat could go wrong when MySQL strict SQL mode is off?This article shows some examples of attacks that can abuse MySQL behavior when the strict SQL mode is disabled, especially when string characters are invalid in the current encoding. This happens when the encoding of the application (e.g. UTF-8) is wider than that of the database…SYNACKTIV.COM
27 JunQuantum readiness: Hybridizing signaturesIn light of new legal requirements being enacted in many countries for software providers to adopt hybrid post-quantum cryptography, Synacktiv has initiated research into these novel cryptographic algorithms. After having studied what makes post-quantum cryptography “post-quantum…SYNACKTIV.COM
27 JunMass Surveillance, is an (un)Complicated BusinessA massively popular iOS application turns out to be a government spy tool! Here, we analyze the app; decrypting its binary and studying its network traffic.OBJECTIVE-SEE.ORG
27 JunWriting a File Monitor with Apple's Endpoint Security FrameworkLearn how to leverage Apple's new Endpoint Security Framework to create a comprehensive (user-mode) File Monitor for macOS 10.15!OBJECTIVE-SEE.ORG
27 JunWriting a Process Monitor with Apple's Endpoint Security FrameworkLearn how to leverage Apple's new Endpoint Security Framework to create a comprehensive (user-mode) Process Monitor for macOS 10.15!OBJECTIVE-SEE.ORG
27 JunGetting Root with Benign AppStore AppsIn this guest blog post, "Objective by the Sea" speaker, Csaba Fitzl writes about an interesting way to get root via Apps from the official Mac App Store!OBJECTIVE-SEE.ORG
27 Jun"Objective by the Sea" v2.0After the success of #OBTS v1.0, we decided to go international and plan #OBTS v2.0 in Europe! In this blog post, we re-live the highlights (from Monaco!) of "Objective by the Sea" v2.0.OBJECTIVE-SEE.ORG
27 JunRootpipe Reborn (Part I)In part one of a guest blog post, @CodeColorist writes about several neat macOS vulnerabilities.OBJECTIVE-SEE.ORG
27 JunMac Adware, à la PythonLet's tear apart a persistent piece of adware, decompiling, decoding, and decompressing it's code to uncover its methods and capabilities.OBJECTIVE-SEE.ORG
27 JunDeath by vmmapA core Mojave utility is rather disastrously broken - causing a full-system lockup. Let's find out why!OBJECTIVE-SEE.ORG
27 JunWord to Your MacA malicious Word document targeting macOS users, was recently uncovered. Let's extract the embedded macros, decode an embedded downloader, and retrieve the 2nd-stage payload!OBJECTIVE-SEE.ORG
27 JunA Deceitful 'Doctor' in the Mac App StoreA massively popular app from the official Mac App Store, surreptitiously steals your browsing history! By fully reversing the application, we can fully expose its functionality and rather shady capabilities.OBJECTIVE-SEE.ORG
27 JunA Remote iOS BugApple wrote code to appease the Chinese government ...it was buggy. In certain configurations, iOS devices were vulnerable a "emoji-related" flaw that could be triggered remotely!OBJECTIVE-SEE.ORG
27 JunBlock Blocking Login ItemsApple recently updated the way login items are stored by the OS. In this post, we'll illustrate how to parse the (new) login item files to detect persistenceOBJECTIVE-SEE.ORG
27 JunCache Me OutsideAre full paths and preview thumbnails for files even on encrypted containers and removable usb devices really persistently stored? ...yes :( Apple's 'QuickLook' cache is to blame.OBJECTIVE-SEE.ORG
27 JunBreaking macOS Mojave (Beta)In macOS Mojave apps, to have to obtain user permission before using the Mac camera & microphone. We'll illustrate how this is trivial to bypass (at least in the current beta).OBJECTIVE-SEE.ORG
27 JunWhen Disappearing Messages Don't DisappearDid you know on macOS, notifications are stored in a unencrypted database? Which means that even 'disappearing' messages from apps such as Signal - may not really disappear. Yikes!OBJECTIVE-SEE.ORG
27 JunAn Insecurity in Apple's Security Framework?Turns out that writing security tools is a great way to inadvertently uncover bugs in macOS. How about a crash in Apple's 'Security' framework ... that can't be good!?OBJECTIVE-SEE.ORG
27 JunA Surreptitious Cryptocurrency Miner in the Mac App Store?Turns out the innocuously named "Calendar 2" app, found on the official Mac App Store, was surreptitiously turning Mac into cryptocurrency miners!OBJECTIVE-SEE.ORG
27 JunAnalyzing OSX/CreativeUpdaterRecently, the popular MacUpdate website was subverted to distribute a new macOS cryptominer; OSX/CreativeUpdater.OBJECTIVE-SEE.ORG
27 JunAnalyzing CrossRATThe EFF/Lookout discovered a cross-platform implant, named CrossRat with ties to nationstate operators. Here, we tear it apart; analyzing its persistence mechanisms, features, and network communications.OBJECTIVE-SEE.ORG
27 JunAll Your Docs Are Belong To UsHere, we reverse, then 'extend' a popular macOS anti-virus engine. With the creation of a new anti-virus signature, classified documents will be automatically detected!OBJECTIVE-SEE.ORG
27 JunWhy _blank_ Gets You RootYet another a massive security flaw affects the latest version of macOS (High Sierra), allowing anybody to log into the root account with a blank, or password, of their choosing!OBJECTIVE-SEE.ORG
27 JunHigh Sierra's 'Secure Kernel Extension Loading' is BrokenA new 'security' feature in macOS 10.13, is trivial to bypass.OBJECTIVE-SEE.ORG
27 JunWTF is Mughthesec!? poking on a piece of undetected adwareSome undetected adware named "Mughthesec" is infecting Macs...let's check it out!OBJECTIVE-SEE.ORG
27 JunTwo Bugs, One Func(), part twoApple's 'fix' for a macOS kernel panic, fixes nothing and worse, introduces a new bug.OBJECTIVE-SEE.ORG
27 JunTwo Bugs, One Func(), part oneThe macOS kernel had an (intentional?) off-by-one bug that could trigger a kernel panic.OBJECTIVE-SEE.ORG
27 JunHappy Birthday to Objective-SeeToday is our 2nd birthday! Let's look at our past, present, and future.OBJECTIVE-SEE.ORG
27 JunFrom Italy With Love?Reverse-engineering a 'Russian' implant reveals HackingTeam's code!?OBJECTIVE-SEE.ORG
27 Jun'Untranslocating' an AppApple's App Translocation broke several of my tools, but we can locally undo it to restore broken functionality!OBJECTIVE-SEE.ORG
27 JunForget the NSA, it's Shazam that's always listening!Does Shazam's Mac App keep recording even when you turn the app off? ...yes :/OBJECTIVE-SEE.ORG
27 JunClick File, App OpensThe 'Mac File Opener' adware is fairly normal, except for it how it persists via registered document handlersOBJECTIVE-SEE.ORG
27 JunPersisting via a Finder SyncLearn how a Finder Sync can 'extend' Finder.app and how this could be abused for persistenceOBJECTIVE-SEE.ORG
27 JunAre you from the Mac App Store?How to verify that an application came from the official Mac App Store, via receipt validationOBJECTIVE-SEE.ORG
27 JunAnalysis of an Intrusive Cross-Platform Adware; OSX/PirritIn Objective-See's first guest blog post, Amit Serper presents his detailed analysis of OSX/PirritOBJECTIVE-SEE.ORG
27 JunAnalyzing the Anti-Analysis Logic of an Adware InstallerDissecting string obfuscations, junk code insertions, and anti-debugging logic of InstallCoreOBJECTIVE-SEE.ORG
27 Jun KEVMonitoring Process Creation via the Kernel (Part III)Getting process creation notifcations from kernel-mode to user-mode, via the undocumented kev_msg_post functionOBJECTIVE-SEE.ORG
27 JunMonitoring Process Creation via the Kernel (Part II)Process monitoring via the KAuth Subsystem (and some limitations)OBJECTIVE-SEE.ORG
27 JunMonitoring Process Creation via the Kernel (Part I)Why BlockBlock needs a kext (hint: process monitoring), and how the kext was createdOBJECTIVE-SEE.ORG
27 JunKernel Debugging a Virtualized OS X El Capitan ImageHow to remotely kernel-debug a OS X 10.11 VMOBJECTIVE-SEE.ORG
27 JunReversing to Engineer: Learning to 'Secure' XPC from a PatchHow reversing Apple's 'RootPipe' patch provided the means to secure TaskExplorer's XPC serviceOBJECTIVE-SEE.ORG
27 JunBuilding HackingTeam's OS X Implant For Fun & ProfitHow to build HackingTeam's OS X implant in XcodeOBJECTIVE-SEE.ORG
27 JunDylib Hijack Scanner ReleasedAnnouncing the release of DHS; a tool to help detect (dylib) hijackersOBJECTIVE-SEE.ORG
27 JunOpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber SafeguardsOpenAI on Friday released three versions of GPT-5.6, called Sol, Terra, and Luna, as a limited preview to a small number of companies as part of an ongoing engagement with the U.S. government. While Sol is the latest flagship model and the most powerful, Terra strikes a balance b…THEHACKERNEWS.COM
26 JunStatement from the Canadian Centre for Cyber Security on frontier artificial intelligence models and their impact on cyber securityCANADA.CA
26 JunRussia Used Cellebrite on Jailed Activist's iPhone Months After Sales CutoffRussian authorities used Cellebrite's UFED forensic tools to break into the iPhone of detained opposition activist Andrey Pivovarov in June 2021, three months after Cellebrite said it would stop selling its tools and services to Russia and Belarus. The finding, published Jun…THEHACKERNEWS.COM
26 JunGuardian Agents: The Next Layer of Identity GovernanceAI agents are moving through enterprise environments, inheriting permissions, traversing systems, and executing decisions at machine speed with minimal oversight. The identity infrastructure built to govern human access wasn't designed for autonomous actors, and the gap between w…THEHACKERNEWS.COM
26 JunFCC votes to toughen rules in bid to better protect undersea cablesIn an unprecedented move, the FCC also said it plans to mandate that owners and operators of submarine line terminal equipment (SLTE) be licensed.THERECORD.MEDIA
26 JunThanks for Crushing the Submissions Inbox. We're Trying to Keep UpIt might be taking a bit longer than usual to respond to your submissions — here's why.DARKREADING.COM
26 JunMCP Auto-Execution: From Git Clone to Cloud Compromise in Amazon Q VS Code ExtensionBy automatically loading MCP servers from workspace files, Amazon Q enabled attackers to execute code and access sensitive cloud environments.WIZ.IO
26 JunRussia accuses Apple of ‘political censorship’ after VK apps removed from App StoreApple removed VK's flagship social network VKontakte, often described as Russia's equivalent of Facebook, along with VK Music, VK Messenger, VK Video, Odnoklassniki and Mail.ru services, including its email application.THERECORD.MEDIA
26 JunMeeting Trump's 2030 Quantum Deadline Will be Expensive, ComplexGetting accurate visibility into IT and OT systems will be compounded by multivendor environments, misaligned update life cycles, and interoperability gaps.DARKREADING.COM
26 JunYour First GRC Agent: A Red Teamer's WalkthroughAI won't replace GRC analysts, but it can eliminate much of the repetitive work they do. Anecdotes walks through building an agent that continuously monitors controls, identifies evidence gaps, and opens remediation tasks. [...]BLEEPINGCOMPUTER.COM
26 JunThe Pentagon Is Looking Into the Dialog Data Exposure for Unmasking National Security OfficialsExposed records from the private group included the personal information of a senior White House intelligence official and an active-duty special operations officer.WIRED.COM
26 JunAI Won't Wipe-Out Entry-Level Cybersecurity JobsInstead of eliminating jobs for early-career cyber pros, AI is creating new opportunities for candidates with strong human decision-making skills.DARKREADING.COM
26 JunAI Decline? Confidence in Autonomous Penetration Testing FallsCompanies are still experimenting with automated AI systems to find security weaknesses, but fewer are relying on the technology.DARKREADING.COM
25 JunChrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection CapabilityAn analysis of a popular Google Chrome ad block extension for YouTube has uncovered the ability to execute arbitrary JavaScript code. According to Island, the extension, named Adblock for YouTube (ID: cmedhionkhpnakcndndgjdbohmhepckk), has more than 10 million installs and carrie…THEHACKERNEWS.COM
25 JunThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More StoriesIt’s dumb out there again. This week has the usual smell of prod on fire and nobody wanting to admit who left the door open — old creds still working, trusted apps doing sketchy crap, browser tricks jumping the fence, and “normal” workflows turning into phishing pipes because app…THEHACKERNEWS.COM
25 JunUpdate Chrome to patch critical browser security flawsChrome has patched 18 vulnerabilities, including four critical flaws. Two WebGL bugs could allow attackers to escape the browser's security sandbox.MALWAREBYTES.COM
25 JunFake domain renewal emails trick website owners into paying scammersWe uncovered fake domain renewal notices and convincing websites to pressure website owners into paying scammers.MALWAREBYTES.COM
25 JunCourt allows for Ohio to implement restrictions on social media use.Five Eyes warns about the frontier AI model.THECYBERWIRE.COM
25 JunHR1 and the future of U.S. tech securityWe hope you enjoy this encore of Caveat. This week on Caveat, Dave and Ben welcome back N2K’s own Ethan Cook for our latest policy deep dive segment. As our lead analyst, Ethan shares his knowledge of law, privacy, and surveillance on the latest policy developments sh…THECYBERWIRE.COM
25 JunRussia used Cellebrite phone-hacking tool to crack down on dissident after firm cut off countryThe continued use of the powerful data extraction product soon after the company in March 2021 said it would stop working with Russia suggests the firm has been unable to pull back its technology from authoritarian government customers, researchers say.THERECORD.MEDIA
25 JunTwenty Million US IP Connections Used by Proxy ServicesDigital Citizens Alliance report claims that millions of Americans may have unwittingly had IP connections used by cybercriminalsINFOSECURITY-MAGAZINE.COM
25 JunmacOS Flaw Lets Standard Users Disable EDR and MDMmacos-xpc-flaw-disable-edr-mdm-standard-user-xm-cyberINFOSECURITY-MAGAZINE.COM
25 JunHow to Spot a Client in the DoD Industrial Base That Handles CUILearn how MSPs/MSSPs can identify if a client is a DoD contractor handling CUI.HUNTRESS.COM
25 JunAnthropic is testing desktop-like Claude Cowork for mobileAnthropic appears to be testing Claude Cowork support on mobile, allowing you to manage long-running Claude tasks from your phone. [...]BLEEPINGCOMPUTER.COM
25 JunPirloTV sports piracy network disrupted as 44 domains seizedA major sports piracy ring linked to the illegal PirloTV streaming platform has been disrupted in an action that targeted 44 domains. [...]BLEEPINGCOMPUTER.COM
25 JunBluekit phishing kit adopts browser-in-the-middle for login theftThe Bluekit phishing-as-a-service platform continues to evolve with nearly 70 new hostnames identified over the past week and by adding browser-in-the-middle capabilities for improved data theft. [...]BLEEPINGCOMPUTER.COM
25 JunThe Four Elevations of Effective Fraud PreventionFraudsters don't attack just one transaction. They target accounts, platforms, and entire ecosystems. IPQS explains the four elevations of fraud prevention and why broader visibility improves fraud detection. [...]BLEEPINGCOMPUTER.COM
25 JunIn Less Than 24 Hours, Attackers Weaponize Cisco CUCM FlawThe flaw enables server-side request forgery (SSRF) and escalates privileges to root, impacting Cisco Unified CM and Unified CM SME deployments.DARKREADING.COM
25 JunEdTech Attackers Shift From Schools to Their Software SuppliersEducational institutions, the edtech companies they rely on, and, more concerningly, the challenges they pose for schools are the focus of the latest Reporters' Notebook video series.DARKREADING.COM
25 JunUncovering Hidden Attack Paths in Cloud Environments Using Runtime SignalsWiz now layers runtime signals into the Security Graph, exposing hidden attack paths to give security teams a complete picture of risk.WIZ.IO