9,421Articles
91Days
85Feeds
🚨 CISA KEV 79[−]
1 Sep KEVPaperCut Exploitation Escalates to Active IntrusionsCISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog. The post PaperCut Exploitation Escalates to Active Intrusions appeared first on SecurityWeek .SECURITYWEEK.COM
1 Sep KEVU.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulner…SECURITYAFFAIRS.COM
31 Aug KEVCISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation.   CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability  CVE-2026-82078 PaperCut NG/MF Unsafe Refle…CISA.GOV
28 Aug KEVPaperCut NG/MF Critical Zero-Day Exploited in the WildOverview On August 27, 2026, PaperCut Software published an urgent security advisory stating that it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. PaperCut has confirmed customer incidents and is treating the issue as a security em…RAPID7.COM
27 Aug KEVCISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server BugsThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exp…THEHACKERNEWS.COM
27 Aug KEVCISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix ProductsCISA added six new bugs to its Known Exploited Vulnerabilities catalog on August 26, showing signs of active exploitation in the wildINFOSECURITY-MAGAZINE.COM
26 Aug KEVU.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Gitea flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-…SECURITYAFFAIRS.COM
26 Aug KEVEdge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeterA joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to t…TENABLE.COM
25 Aug KEVU.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Oracle flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE…SECURITYAFFAIRS.COM
22 Aug KEVU.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the Zimbra Collaboration Suite (ZCS) flaw CVE-2026-73570 …SECURITYAFFAIRS.COM
21 Aug KEVU.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV…SECURITYAFFAIRS.COM
20 Aug KEVU.S. CISA adds an MLflow flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds an MLflow vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2026-64849 (CVSS sc…SECURITYAFFAIRS.COM
19 Aug KEVU.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the followi…SECURITYAFFAIRS.COM
19 Aug KEVCritical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active ExploitationThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below - CVE-202…THEHACKERNEWS.COM
18 Aug KEVU.S. CISA adds a Ray-Project Ray flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Ray-Project Ray vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2025-62593 …SECURITYAFFAIRS.COM
14 Aug KEVThe cybersecurity backlog is not a security problemCybersecurity teams should be responsible for risk oversight, rather than for executing every corrective action. Assigning security teams the tasks of finding, prioritizing, assigning, implementing, tracking and validating every remediation does not foster accountability. Instead…CSOONLINE.COM
13 Aug KEVCisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)A high-severity vulnerability (CVE-2026-20349) is being leveraged by attackers to temporarily interrupt the operation of Cisco firewalls, the company has confirmed. The flaw has been added to CISA’s Known Exploited Vulnerabilities catalog and needs to be remediated by US ci…HELPNETSECURITY.COM
13 Aug KEVU.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known E…SECURITYAFFAIRS.COM
11 Aug KEVPatch Tuesday - August 2026Microsoft is publishing 421 vulnerabilities on August 2026 Patch Tuesday , including 236 vulnerabilities in Windows. This is lower volume than last month’s record-breaking behemoth, but still one of the largest Patch Tuesday totals ever. There is no reason to suppose that Patch T…RAPID7.COM
8 Aug KEVProgress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit AttemptsThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tra…THEHACKERNEWS.COM
8 Aug KEVU.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2026-80…SECURITYAFFAIRS.COM
6 Aug KEVU.S. CISA adds a JetBrains TeamCity flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a JetBrains TeamCity vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a JetBrains TeamCity vulnerability, tracked as CVE-2026-6307…SECURITYAFFAIRS.COM
6 Aug KEVThe exploit window is shrinking. Most security workflows are notAI is accelerating vulnerability discovery, exploit development, and attacker weaponization faster than most organizations can adapt. Security teams are inundated with vulnerability disclosures, threat intelligence feeds, exploit chatter, and vendor advisories, all demanding imme…CSOONLINE.COM
5 Aug KEVU.S. CISA adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known …SECURITYAFFAIRS.COM
4 Aug KEVCISA Adds Exploited N-able N-central Flaw to KEV After Customer CompromisesThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2…THEHACKERNEWS.COM
4 Aug KEVCVE-2026-18577: N-able N-central Authentication Bypass Exploited in the WildOverview On August 2, 2026, N-able published a security advisory for CVE-2026-18577 , an authentication bypass vulnerability affecting N-central that was discovered being exploited in-the-wild after an incomplete fix for an earlier authentication bypass issue, CVE-2026-18556 was …RAPID7.COM
4 Aug KEVU.S. CISA adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a N-able N-central flaw, tracked as CVE-2026-18577 (CVSS score of 8.2),…SECURITYAFFAIRS.COM
30 Jul KEVU.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Firewall Management Center …SECURITYAFFAIRS.COM
28 Jul KEVU.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Arista VeloCloud Orchestrator and Fort…SECURITYAFFAIRS.COM
28 Jul KEVAccelerating CISA BOD 26-04 Vulnerability and Triage Activities through WizWiz enables organizations to continuously assess environments against the CISA KEV catalog, automating risk prioritization, rapid remediation, and forensic triage workflows.WIZ.IO
28 Jul KEVCoordinated “cyberattack” on Minnesota water utilities: What you need to knowA coordinated cyber attack disrupted water systems across more than 30 Minnesota communities. Here is what defenders need to know about the attack so far. This FAQ also details recent cyberactivity targeting internet-exposed PLCs, and how to protect exposed infrastructure. Key Ta…TENABLE.COM
23 Jul KEVMicrosoft’s 3-day patching directive comes with added operational riskMicrosoft 365 Director Jeremy Chapman this month took to video to tell Windows admins that the days of delaying security patches are over. Complex enterprise systems and historic incidents involving patch problems have caused many admins to hold fire on immediately applying secur…CSOONLINE.COM
23 Jul KEVCVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the WildOverview On July 22, 2026, Check Point published a security advisory for multiple vulnerabilities affecting Security Management, Multi-Domain Management, and firewall products. The most urgent of these is CVE-2026-16232 , an authentication bypass in the SmartConsole login process…RAPID7.COM
23 Jul KEVU.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SharePoint and Check Point flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added DD-WRT, Langflow, and WordPress flaws to its Known Exploi…SECURITYAFFAIRS.COM
22 Jul KEVU.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds DD-WRT, Langflow, and WordPress flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added DD-WRT, Langflow, and WordPress flaws to its Known Exploi…SECURITYAFFAIRS.COM
20 Jul KEVwp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress CoreAn unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public dis…TENABLE.COM
18 Jul KEVU.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Fortinet FortiSandbox and Microsoft ShareP…SECURITYAFFAIRS.COM
17 Jul KEVCISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEVThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fi…THEHACKERNEWS.COM
17 Jul KEVU.S. CISA adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SonicWall and M…SECURITYAFFAIRS.COM
16 Jul KEVCISA urges immediate SharePoint hardening as exploits mountThe US Cybersecurity and Infrastructure Security Agency (CISA) has urged organizations to immediately secure Microsoft SharePoint deployments after warning that three vulnerabilities affecting the on-premises collaboration platform are being actively exploited. A recent advisory …CSOONLINE.COM
16 Jul KEVCVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server VulnerabilitiesFour Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments. Key Takeaways CISA confirmed active exploi…TENABLE.COM
15 Jul KEVU.S. CISA adds SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SonicWall and Microsoft flaws to its Known Exploited Vulnerabilit…SECURITYAFFAIRS.COM
15 Jul KEVPatch These Joomla Vulnerabilities NowCISA added vulnerabilities affecting the iCagenda and Babioon Forms Joomla extensions to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The flaws can enable remote code execution through arbitrary file uploads. When CISA gives a vulnerability i…YOUTUBE.COM
14 Jul KEVPatch Tuesday - July 2026Microsoft is publishing 622 vulnerabilities on July 2026 Patch Tuesday , including a record-breaking 416 Windows vulnerabilities. Microsoft is aware of exploitation in the wild for two of the vulnerabilities published today, both of which are listed on CISA KEV, as well as public…RAPID7.COM
13 Jul KEVU.S. CISA adds a Cisco IOS flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Cisco IOS flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco IOS flaw, tracked as CVE-2008-4128, to its Known Exploited Vulnerabili…SECURITYAFFAIRS.COM
12 Jul KEVSecurity Affairs newsletter Round 585 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. U.S. CISA adds iCagenda and B…SECURITYAFFAIRS.COM
11 Jul KEVU.S. CISA adds iCagenda and Balbooa Forms flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds iCagenda and Balbooa Forms flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added iCagenda and Balbooa Forms flaws to its Known Exploited Vulner…SECURITYAFFAIRS.COM
9 Jul KEVAI Is Annoying & IoT Devices Still Get Hacked - PSW #934In the security news: - Son of Anton strikes again! - HalluSquatting and using Claude to defend itself - CISA KEV’s Revolving Door - LLM's hallucinate and companies get sued - Additionally - GitLost - Yet even more Linux vulnerabilities - Citrix just keeps bleeding - Old hardware…YOUTUBE.COM
8 Jul KEVCISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEVThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-48282 (CVSS score: 10.0) - A path tr…THEHACKERNEWS.COM
8 Jul KEVU.S. CISA adds Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] …SECURITYAFFAIRS.COM
8 Jul KEVCISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla FlawsTwo newly disclosed critical vulnerabilities in Adobe ColdFusion and Langflow join two Joomla extension flaws in CISA's Known Exploited Vulnerabilities catalog, with federal agencies given until July 10 to patch. The post CISA Urges Immediate Patching of Exploited ColdFusion, Lan…SECURITYWEEK.COM
8 Jul KEVAttackers using Langflow flaw for credential harvesting (CVE-2026-55255)The US Cybersecurity and Infrastructure Security Agency (CISA) is warning about yet another Langflow vulnerability (CVE-2026-55255) leveraged by attackers in the wild. The flaw was added to the agency’s Known Exploited Vulnerabilities catalog on Tuesday, July 7, nearly two …HELPNETSECURITY.COM
2 Jul KEVSharePoint RCE CVE-2026-45659 Added to CISA KEV After Active ExploitationThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-4565…THEHACKERNEWS.COM
2 Jul KEVU.S. CISA adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Microsoft SharePoint Server flaw, tracked as CVE-2026-4565…SECURITYAFFAIRS.COM
30 Jun KEVHow CISA BOD 26-04 redefines vulnerability management metrics for security leadersCISA’s BOD 26-04 changes how federal agencies patch and how security leaders must measure, justify, and communicate cyber risk to executives and boards. Key takeaways BOD 26-04 requires agencies to make and defend risk-based vulnerability prioritization decisions, including decis…TENABLE.COM
30 Jun KEVU.S. CISA adds SimpleHelp flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a SimpleHelp flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a SimpleHelp flaw, tracked as CVE-2026-48558 (CVSS score v3.1 …SECURITYAFFAIRS.COM
29 Jun KEVModernizing Global Vulnerability Standards For The Age Of AIAs AI-driven vulnerability discovery accelerates, the cybersecurity ecosystem is being forced to examine whether the standards, disclosure processes, and prioritization frameworks defenders rely on can still keep pace. Many of those systems were built around human-speed discovery…RAPID7.COM
29 Jun KEVJSP webshells being dropped on unpatched PTC Windchill instancesThe US Cybersecurity and Infrastructure Security Agency (CISA) added a vulnerability (CVE-2026-12569) in Windchill and FlexPLM, two product lifecycle management software platforms developed by PTC, to its Known Exploited Vulnerabilities (KEV) catalog. Entries in the KEV catalog d…HELPNETSECURITY.COM
26 Jun KEVFirst-Ever Exploitation of PTC Windchill Vulnerability Discovered in the WildCISA has added the remote code execution flaw CVE-2026-12569 to its Known Exploited Vulnerabilities catalog. The post First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild appeared first on SecurityWeek .SECURITYWEEK.COM
26 Jun KEVCISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks ContinueThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical remote code execution vulnerability impacting PTC Windchill PDMlink and PTC FlexPLM enterprise Product Data Management (PDM) and Product Lifecycle Management (PLM) software to its Known …THEHACKERNEWS.COM
26 Jun KEVWeekly Metasploit Update: Modules for Audiobookshelf, LiteLLM, Next.js, Dalfox and moreHelp shape the future of Metasploit Framework We are planning future work in relation to the evasion capabilities present in Metasploit Framework, and how they function/are presented to users. We are currently accepting responses to our feedback form, which means that you can sha…RAPID7.COM
25 Jun KEVCISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation.   CVE-2026-12569 PTC Windchill and FlexPLM Improper Input Validation Vulnerability CVE-2026-20230 Cisco Unified Communications Manager Serv…CISA.GOV
24 Jun KEVAttackers exploit Cisco Unified CM flaw weeks after patch releaseA critical Cisco Unified CM vulnerability is now under active exploitation, weeks after the company issued patches warning it could allow attackers to gain root access. Threat intelligence firm Defused reported the exploitation on June 23. The company said it observed the activit…CSOONLINE.COM
19 Jun KEVUnauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253)CISA has added CVE-2026-20253, a critical, remotely exploitable vulnerability in Splunk Enterprise, to its Known Exploited Vulnerabilities catalog, and ordered US federal civilian agencies to apply mitigations by June 21, 2026. In-the-wild exploitation has also been confirmed by …HELPNETSECURITY.COM
17 Jun KEVWhat 22,000 breaches teach us about incident preparednessThe 2026 Verizon Data Breach Investigations Report analyzed more than 22,000 confirmed data breaches across 145 countries. Its findings point to a single uncomfortable truth: organizations cannot patch fast enough to prevent every incident. Exploitation of vulnerabilities surged …CSOONLINE.COM
17 Jun KEVOperationalize CISA BOD 26-04 with Tenable OneCISA’s new directive officially ends federal agencies’ reliance on static vulnerability scores. Learn how Tenable One helps federal agencies pivot to dynamic asset exposure, threat validation, and AI-powered automation to meet compressed compliance timelines. Key takeaways CISA’s…TENABLE.COM
15 Jun KEVCISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-20262 Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability CVE-2026-54420 LiteSpeed cPanel Plugin UNIX Symbolic Link…CISA.GOV
11 Jun KEVCISA Directs Federal Agencies to Prioritize Security Patches Based on RiskThe new BOD 26-04 requires agencies to review and update vulnerability management policies with a focus on KEV catalog entries. The post CISA Directs Federal Agencies to Prioritize Security Patches Based on Risk appeared first on SecurityWeek .SECURITYWEEK.COM
11 Jun KEVTrolling Microsoft With Vulnerabilities - PSW #930In the security news: - Trolling Microsoft With Vulnerabilities - Fable 5 loves guardrails - Binwalk vulnerability - EMBA and local models - EDRChoker - AI worms - Interesting Arista vulnerability added to KEV - BOD 26-04 and stakeholder specific vulnerability categorization - Br…YOUTUBE.COM
11 Jun KEVCISA BOD 26-04: Frequently asked questions about the new risk-based patching directiveCISA issued BOD 26-04, which replaces BOD 22-01 with a four-variable vulnerability prioritization model requiring federal agencies to patch the most dangerous vulnerabilities in as few as three days. Key takeaways BOD 26-04 replaces BOD 22-01 with a four-variable risk model that …TENABLE.COM
10 Jun KEVCVE-2026-10520, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti SentryOverview On June 9, 2026, Ivanti published a security advisory for two critical vulnerabilities affecting Ivanti Sentry (formerly known as MobileIron Sentry), which per the vendor website is an “in-line gateway that manages, encrypts, and secures traffic between the mobile device…RAPID7.COM
10 Jun KEVCISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active ExploitationThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The list of vulnerabilities is as follows - CVE-2026-20245 (CVSS score: 7.8)…THEHACKERNEWS.COM
10 Jun KEVCISA tells agencies to patch smarter, not harder — foreshadowing broader industry practiceSecurity teams’ patching practices have come under intense pressure over the past year, as active exploitation is up, time-to-exploit windows are accelerating, and vulnerabilities have become attackers’ top initial access vector of choice. Last year, organizations fully remediate…CSOONLINE.COM
9 Jun KEVAI worm prototype shows attackers don’t need Mythos to take over your networkResearchers from the University of Toronto developed a computer worm prototype powered by an AI agent that successfully self-replicated to different systems within a simulated computer network. The worm used a free large language model (LLM) running on local hardware and exploite…CSOONLINE.COM
9 Jun KEVLiteLLM vulnerability under active attack, CISA warns (CVE-2026-42271)A command injection vulnerability (CVE-2026-42271) in BerryAI’s LiteLLM open-source AI gateway is being exploited by attackers, the US Cybersecurity and Infrastructure Security Agency (CISA) confirmed by adding the flaw to its Known Exploited Vulnerabilities catalog on Mond…HELPNETSECURITY.COM
9 Jun KEVMicrosoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507)32 Critical 166 Important 0 Moderate 0 Low Microsoft addresses 198 CVEs in the largest Patch Tuesday release, including three zero-days. Microsoft patched 198 CVEs in its June 2026 Patch Tuesday release, with 32 rated critical and 166 rated as important. Our counts omitted 6 CVEs…TENABLE.COM
9 Jun KEVPatch Tuesday - June 2026Microsoft is publishing 200 vulnerabilities on June 2026 Patch Tuesday . Microsoft is not aware of exploitation in the wild for any of these vulnerabilities, and is aware of public disclosure for three. This is similar to last month’s Patch Tuesday, however several of last month’…RAPID7.COM
8 Jun KEVCritical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)Overview On June 8, 2026, Check Point published a security advisory for CVE-2026-50751 , a critical authentication bypass vulnerability affecting Check Point Remote Access VPN, Mobile Access, and Spark Firewall products. The vulnerability affects deployments configured to use the…RAPID7.COM
6 Jun KEVCISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV CatalogThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity security flaw impacting SolarWinds Serv-U multi-protocol file server software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability…THEHACKERNEWS.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 2296[−]
2 Sep22,000 Exchange servers open to hijack, 700 rogue AI agents swarmed Hugging Face, AI threatens global finance22,000 Exchange Servers Exposed, 700 AI Agents Swarm Hugging Face, and FSB Warns Frontier AI Is Top Financial Risk Cybersecurity Today with host David Shipley reports nearly 21,899 Microsoft Exchange servers still exposed and unpatched for high-severity auth-bypass CVE-2026-62911…CYBERSECURITYTODAY.LIBSYN.COM
2 SepSonicWall Warns of Two SMA1000 Zero-Days Exploited in AttacksThe vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution. The post SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
2 SepResearchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to AnotherForescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware. The exploit targets&…THEHACKERNEWS.COM
2 SepAttackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without CredentialsThreat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulne…THEHACKERNEWS.COM
2 SepHackers Target Langflow in CVE-2026-0768 AttacksHackers are exploiting a critical Langflow flaw that lets unauthenticated attackers remotely execute Python code on vulnerable systems. Hackers have started exploiting a critical vulnerability, tracked as CVE-2026-0768 (CVSS score of 9.8), in the AI-focused low-code platform Lang…SECURITYAFFAIRS.COM
2 SepAttackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack ChainSonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks. The vulnerabilities, discovered internally by SonicWall's William Perry and Adam Babis, are list…THEHACKERNEWS.COM
2 SepSonicWall SMA 1000 appliances under attack via zero-day flawsAttackers are exploiting two previously undisclosed vulnerabilities (CVE-2026-83548, CVE-2026-83549) in SonicWall SMA 1000 appliances, the vendor confirmed on Tuesday. The vulnerabilities (CVE-2026-83548, CVE-2026-83549) The SonicWall SMA 1000 series is a line of secure remote ac…HELPNETSECURITY.COM
2 Sep KEVExploited JFrog Artifactory bug puts software supply chain on alertA critical authentication bypass in JFrog Artifactory is now being exploited in the wild, with attackers observed generating administrator tokens and probing the software supply-chain platform’s sensitive data. The flaw, tracked as CVE-2026-82329 , was disclosed by JFrog on Augus…CSOONLINE.COM
2 SepExploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)A threat actor is actively targeting internet-exposed Sangoma Switchvox instance through a recently patched SQL injection flaw (CVE-2026-9586), and organizations running them should check for signs of compromise immediately. How CVE-2026-9586 works Switchvox is a VoIP-based unifi…HELPNETSECURITY.COM
2 SepNearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability, according to daily scans from the Shadowserver Foundation. The United States and Germany top the list with 6,200 and 5,100 unpatched servers. CVE-2026…HELPNETSECURITY.COM
2 SepHackers exploit critical JFrog Artifactory flaw to forge admin tokensA critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access. [...]BLEEPINGCOMPUTER.COM
2 SepCVE-2026-47285 Visual Studio Code Information Disclosure VulnerabilityAffected software updated with new package information.MSRC.MICROSOFT.COM
2 SepCVE-2026-58650 Visual Studio Code Security Feature Bypass VulnerabilityAffected software updated with new package information.MSRC.MICROSOFT.COM
2 SepCVE-2026-59113 Visual Studio Code Remote Code Execution VulnerabilityAffected software updated with new package information.MSRC.MICROSOFT.COM
2 Sep KEVCritical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the WildOverview On September 1, 2026, SonicWall disclosed two vulnerabilities affecting SonicWall SMA1000 appliances that the vendor says are being actively exploited in the wild. The vulnerabilities, CVE-2026-83548 and CVE-2026-83549 , can be chained to achieve unauthenticated remote c…RAPID7.COM
2 SepHackers exploit Sangoma Switchvox flaw to deploy reverse shellsAttackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. [...]BLEEPINGCOMPUTER.COM
2 Sep KEVSonicWall reports two major security holes under active exploitSonicWall on Monday reported two major security holes in its Secure Mobile Access 1000 series appliances, both of which it said are being actively exploited, and published patches for each. Consultants called the holes, one of which permits remote attacks that bypass authenticati…CSOONLINE.COM
1 SepAttackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 ActivityThreat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability …THEHACKERNEWS.COM
1 Sep KEVCritical JFrog Artifactory Vulnerability Reportedly Exploited in the WildExploitation of the authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure. The post Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild appeared first on SecurityWeek .SECURITYWEEK.COM
1 SepHackers Start Exploiting Critical Langflow VulnerabilityTracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely. The post Hackers Start Exploiting Critical Langflow Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
1 SepCritical Langflow flaw exploited to steal OpenAI and AWS keysThreat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. [...]BLEEPINGCOMPUTER.COM
1 SepAttackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After DisclosureThreat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to admin…THEHACKERNEWS.COM
1 SepCritical Langflow Flaw Exploited as Attacks on AI Platform RiseThe attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year.DARKREADING.COM
1 SepAttackers Pounce on Critical Artifactory Flaw Following DisclosureCVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected systems.DARKREADING.COM
1 SepWhat happens when AI models take aim at ICS exploitsLLMs have shown great improvement in vulnerability research and exploit development capabilities over the past six months. But it’s one thing to find vulnerabilities in well documented open-source projects and an entirely different skillset to decrypt file systems and reverse-eng…CSOONLINE.COM
31 AugCVE-2026-49177 Windows TCP/IP Information Disclosure VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
31 AugCVE-2026-50344 Windows OLE Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
31 AugCVE-2026-65775 Windows Win32k Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
31 AugCVE-2026-65776 Windows Win32k Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
31 AugCVE-2026-62823 Windows DHCP Server Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
31 AugCVE-2026-62889 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
31 AugSimulating legitimate Active Directory services on the network: the case of GPO exploitationSimulating legitimate Active Directory services on an internal network is a powerful and versatile capability that can be leveraged in various contexts. Many examples of exploits relying on the ability to simulate working LDAP and/or SMB services can be cited, such as Group Polic…SYNACKTIV.COM
29 AugFive Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCEMultiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to…THEHACKERNEWS.COM
28 Aug KEVownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research BodyThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nucl…THEHACKERNEWS.COM
28 AugTwo Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over BluetoothSecurity researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low Energy (BLE) path that can reach root on the robot's Locomotion PC. The flaws are tracked as CVE-2026-76639 …THEHACKERNEWS.COM
28 AugChina-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root AccessVulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices. The implants, named SPEAKING…THEHACKERNEWS.COM
28 AugCritical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole ServercPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user. The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported ver…THEHACKERNEWS.COM
28 AugCVE-2026-70331 Microsoft Edge for iOS Spoofing VulnerabilityImproper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.MSRC.MICROSOFT.COM
28 AugCVE-2026-58616 Copilot Chat (Microsoft Edge) Information Disclosure VulnerabilityConcurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network.MSRC.MICROSOFT.COM
28 AugCVE-2026-62904 Microsoft Edge (Chromium-based) Information Disclosure VulnerabilityIncorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.MSRC.MICROSOFT.COM
28 AugCVE-2026-66323 Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityImproper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.MSRC.MICROSOFT.COM
28 AugCVE-2026-66324 Microsoft Edge (Chromium-based) Spoofing VulnerabilityExternal control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.MSRC.MICROSOFT.COM
28 AugCVE-2026-66798 Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityUse after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.MSRC.MICROSOFT.COM
28 AugCVE-2026-70341 Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityUse after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.MSRC.MICROSOFT.COM
28 AugCVE-2026-72984 Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityAccess of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78891 Buffer overflow in WebRTCThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78892 Incorrect authorization in ChromotingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78893 Information leak in QUICThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78894 Race condition in PaymentsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78895 Information leak in PaintThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78896 Information leak in StorageAccessAPIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78897 Missing authorization in BrowserTagThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78898 Incorrect authorization in DownloadsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78899 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78900 Improper input validation in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78901 Race condition in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78903 Incomplete cleanup in SiteIsolationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78904 Type confusion in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78905 Type confusion in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78906 Race condition in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78907 Incorrect authorization in WebProtectThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78908 Information leak in CanvasThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78909 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78910 Buffer overflow in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78911 Incorrect authorization in USBThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78912 UI misrepresentation in BrowserThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78913 Use after free in ChromotingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78914 Uninitialized resource in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78915 Race condition in EnterpriseThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78934 Race condition in ReadAloudThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78938 Type confusion in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78939 Use after free in ChromecastThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78940 Improper initialization in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78941 Information leak in CoreThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78942 Incorrect reference resolution in LoaderThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78943 Improper input validation in EditingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78944 Use after free in DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78945 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78946 Incorrect authorization in SelectThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78947 Incomplete cleanup in ChromiumThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78948 Buffer overflow in WebGLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78950 Integer overflow in WebRTCThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78951 Use after free in ServiceWorkerThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78952 Out of bounds write in CrashpadThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78953 Missing authorization in SiteIsolationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78954 Incorrect authorization in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78955 Observable discrepancy in PerformanceAPIsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78956 Type confusion in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78958 Uninitialized resource in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78959 Improper handling of case sensitivity in FileSystemThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78960 Information leak in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78961 Incorrect authorization in CoreThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78962 Uninitialized resource in WebXRThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78963 Improper input validation in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78964 Use after free in SyncThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78965 Uninitialized resource in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78966 Externally controlled reference in QUICThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78967 Missing authorization in BFCacheThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78968 Missing authorization in CoreThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78969 Uninitialized resource in VideoThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78974 UI misrepresentation in Linux Toolkit ThemingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78975 Incorrect authorization in DOMThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78976 Improper input validation in StorageAccessAPIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78977 Uninitialized resource in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78978 Out of bounds read in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78979 Race condition in CoreThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78980 Improper input validation in ReaderModeThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78983 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78984 Uninitialized resource in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78985 Incorrect reference resolution in FileSystemThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78986 Uninitialized resource in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78987 Information leak in CanvasThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78989 Out of bounds read in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78990 Use after free in CompositingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78991 Race condition in WebProtectThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-78999 Improper privilege management in NavigationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79000 Improper input validation in DeviceBoundSessionCredentialsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79001 Information leak in BluetoothThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79002 Incorrect authorization in SiteIsolationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79003 Incorrect authorization in DeviceThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79004 Out of bounds read in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79005 Incorrect authorization in StorageAccessAPIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79006 Protection mechanism failure in HttpsUpgradesThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79007 Uninitialized resource in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79009 UI misrepresentation in UIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79010 Operation on a resource after expiration or release in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79011 UI misrepresentation in BrowserThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79012 Use after free in SafebrowsingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79013 Improper input validation in SyncThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79014 Race condition in AutofillThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79015 Improper input validation in ServiceWorkerThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79016 Observable discrepancy in SVGThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79017 Race condition in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79018 Information leak in FoldableAPIsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79019 Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79020 Out of bounds read in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79021 Missing authorization in InterestGroupsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79022 UI misrepresentation in Transactions PlatformThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79023 Incorrect authorization in EditingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79024 Information leak in ServiceWorkerThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79025 Improper input validation in WorkersThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79026 Use after free in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79027 Use after free in WebRTCThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79028 Observable discrepancy in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79030 Observable discrepancy in AutofillThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79031 Improper resource exposure in PreloadThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79032 Improper input validation in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79033 Insufficient control flow management in DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79034 Information leak in CORSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79038 Incorrect authorization in WebProtectThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79040 Uninitialized resource in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79041 Missing authorization in BrowserThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79042 Missing authorization in PaymentsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79043 Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79045 Type confusion in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79047 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79048 Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79049 Incorrect reference resolution in PasswordsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79050 Incorrect authorization in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79051 Incorrect authorization in LoaderThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79052 Use after free in AuraThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79053 Missing authorization in LighthouseThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79054 Use after free in ChromecastThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79055 Information leak in SharingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79056 Use after free in ServiceWorkerThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79058 Missing authorization in PasswordsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79059 Information leak in BFCacheThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79060 Incorrect authorization in StorageAccessAPIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79064 Use after free in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79065 Improper input validation in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79066 Improper input validation in NavigationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79067 Missing authorization in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79068 Improper resource exposure in StreamsAPIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79069 Memory corruption in TintThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79070 Incorrect reference resolution in CacheThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79071 Race condition in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79072 Improper state validation in PerformanceThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79073 Improper state validation in ParserThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79074 Information leak in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79075 Information leak in GeolocationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79076 Improper input validation in SyncThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79077 Incorrect authorization in WebProtectThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79078 Use after free in FedCMThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79082 Incorrect authorization in Transactions PlatformThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79083 Improper enforcement of behavioral workflow in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79084 Inadequate encryption strength in NotificationsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79085 Missing authorization in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79087 Injection in Chrome TabsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79088 Incorrect authorization in FileSystemThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79089 Race condition in Transactions PlatformThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79090 Improper privilege management in ActorThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79091 Use after free in BluetoothThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79093 Incorrect authorization in PaintThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79094 Race condition in WorkersThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79095 Information leak in PaymentsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79097 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79098 UI misrepresentation in PermissionElementThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79099 Missing authorization in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79103 Incorrect reference resolution in SpeechThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79104 Missing authorization in SensorThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79106 Improper input validation in InputThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79107 Incorrect authorization in TabGroupsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79108 UI misrepresentation in Web Authentication (Passkeys & Security Keys)This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79109 Improper input validation in PrintingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79110 Missing authorization in PreloadThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79111 Improper input validation in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79112 Out of bounds read in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79116 Missing authorization in VizThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79118 Uninitialized resource in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79119 Use after free in PDFThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79120 Uninitialized resource in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79121 Improper input validation in ChromecastThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79122 Information leak in SignInThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79123 Improper input validation in NTP FooterThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79124 Information leak in IntentsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79125 Information leak in XRThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79126 Incorrect provision of specified functionality in ProxyThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79127 Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79128 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79130 Buffer overflow in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79131 Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79133 Incorrect authorization in FormsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79134 Incorrect authorization in GetUserMediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79136 Incorrect authorization in ServiceWorkerThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79137 Incorrect authorization in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79138 Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79139 Improper input validation in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79140 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79141 Incorrect authorization in BrowserThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79142 Buffer overflow in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79143 Incorrect authorization in FileSystemThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79144 Information leak in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79147 Information leak in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79148 Off-by-one error in DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79149 Use after free in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79150 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79151 Improper input validation in SafebrowsingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79154 Missing authorization in DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79155 Race condition in FileSystemThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79173 UI misrepresentation in WebAppInstallsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79174 Incorrect authorization in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79175 Type confusion in AccessibilityThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79176 UI misrepresentation in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79177 Incorrect authorization in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79178 Incorrect authorization in Web Authentication (Passkeys & Security Keys)This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79179 Incorrect authorization in DOMThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79181 Observable discrepancy in GlicThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79182 Improper input validation in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79183 Use after free in AccessibilityThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79184 Missing authorization in PreloadThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79185 Information leak in DOMThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79186 Incorrect authorization in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79187 Use after free in WebRTCThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79188 Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79189 Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79190 Incorrect authorization in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79191 Incorrect authorization in SiteIsolationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79192 Improper input validation in VariationsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79193 Information leak in CanvasThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79194 Use after free in ChromotingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79195 Use after free in ScriptThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79196 Race condition in EditingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79197 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79198 Use after free in PlatformThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79199 Incorrect authorization in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79200 Use after free in AuraThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79201 Improper access control in WorkersThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79202 Use after free in ChromecastThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79203 Improper input validation in DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79204 UI misrepresentation in InputThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79205 Incorrect authorization in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79206 Out of bounds read in FileSystemThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79208 Missing authorization in HTTP2This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79209 Type confusion in AnimationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79211 Incorrect authorization in USBThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79212 Missing authorization in PasswordsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79214 Improper input validation in PreloadThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79215 Integer overflow in WebGLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79216 Buffer overflow in BlinkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79218 Incorrect authorization in SandboxThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79219 Use after free in BluetoothThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79220 Information leak in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79221 Uninitialized resource in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79223 Integer overflow in ChromiumThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79224 Use after free in ChromecastThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79225 Incorrect authorization in BrowserThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79226 Improper privilege management in Regional CapabilitiesThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79227 Type confusion in DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79228 Incorrect authorization in SiteIsolationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79229 Uninitialized resource in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79230 Improper input validation in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79231 Buffer overflow in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79232 Use after free in AuraThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79234 Injection in CSSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79235 Use after free in WebGLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79236 Type confusion in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79237 Incorrect authorization in NavigationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79238 Incorrect authorization in ServiceWorkerThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79239 Out of bounds read in TintThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79240 Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79242 Observable discrepancy in HTMLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79243 Improper input validation in ReadingListThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79244 Use after free in AnimationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79245 Use after free in UIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79246 Information leak in DataTransferThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79247 Use after free in ChromotingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79248 Incorrect authorization in InputThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79249 Code injection in BisectionThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79250 UI misrepresentation in NavigationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79251 Improper input validation in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79252 Information leak in ServiceWorkerThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79253 Improper input validation in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79255 Improper input validation in WebRTCThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79257 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79258 Incorrect authorization in WebXRThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79259 Improper input validation in SafebrowsingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79260 Improper input validation in CookiesThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79261 Incorrect authorization in ControlsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79262 Incorrect authorization in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79263 Race condition in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79264 Incorrect reference resolution in PreloadThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79265 Incomplete cleanup in GetUserMediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79266 Use after free in DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79267 Race condition in WorkersThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79269 Uninitialized resource in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79270 Uninitialized resource in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79271 Information leak in DOMThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79272 Improper input validation in FindInPageThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79274 Information leak in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79275 Use after free in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79276 Improper privilege management in FileSystemThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79283 UI misrepresentation in GeometryThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79284 UI misrepresentation in CoreThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79285 Uninitialized resource in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79287 Observable discrepancy in FormsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79289 Improper control of a resource through its lifetime in WorkersThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79290 Use after free in AuraThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79291 Information leak in CSSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79292 Integer overflow in ChromecastThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugChromium: CVE-2026-79293 Information leak in AnimationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 AugCVE-2026-70309 Microsoft Edge (Chromium-based) Security Feature Bypass VulnerabilityOrigin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.MSRC.MICROSOFT.COM
28 AugCVE-2026-65813 Microsoft Exchange Server Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
28 AugServiceNow patches three maximum severity flaws that could put enterprise data at riskCode injection and SQL injection attacks have been around for decades, and they are still tried-and-true ways for attackers to compromise systems. ServiceNow’s latest trio of maximum severity flaws shows that even AI-era platforms remain vulnerable to these techniques: The softwa…CSOONLINE.COM
28 AugThe first 24 hours of an AI agent security incidentMost of what I read on AI agent security follows the same shape: a taxonomy of risks, a list of governance principles and a call to “adopt responsible AI practices.” That’s useful for a board deck. It’s nearly useless at 2 a.m. when an autonomous agent with live credentials has j…CSOONLINE.COM
28 AugCTEM can give your security team a contextual edgeTraditional vulnerability management is accelerating toward a reset, with many security organizations considering continuous threat exposure management (CTEM) to better align their operations with the pace of change — and attacks — today. Whereas traditional vulnerability managem…CSOONLINE.COM
27 Aug KEVRecent Citrix NetScaler Vulnerability Exploited in the WildCISA is urging government agencies to immediately patch the Citrix NetScaler vulnerability tracked as CVE-2026-8452. The post Recent Citrix NetScaler Vulnerability Exploited in the Wild appeared first on SecurityWeek .SECURITYWEEK.COM
27 Aug KEVPreviously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452)CISA added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a previously patched Citrix NetScaler ADC and Gateway flaw, tracked as CVE-2026-8452, that is being exploited in the wild. The agency published the alert on August 26 and gave feder…HELPNETSECURITY.COM
27 AugCVE-2026-69550 Windows App for Mac Information Disclosure VulnerabilityUpdated CWE value. This is an informational change only.MSRC.MICROSOFT.COM
27 AugCVE-2026-50435 Windows Overlay Filter Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
27 AugCVE-2026-50351 Windows Audio Compression Manager (ACM) Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
27 AugCVE-2026-65779 Windows Autopilot Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
27 AugCVE-2026-68817 Microsoft Excel Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
27 AugCVE-2026-42993 Remote Desktop Client Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
27 AugNext.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCECredit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traver…THEHACKERNEWS.COM
26 AugCISA Warns of Exploited Gitea VulnerabilityCVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1.27.1. The post CISA Warns of Exploited Gitea Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
26 Aug KEVCritical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like PayloadThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code executio…THEHACKERNEWS.COM
26 Aug KEVCritical Gitea vulnerability now exploited in the wild (CVE-2026-60004)Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. The KEV entry does not contain or point to details about …HELPNETSECURITY.COM
26 AugNemoClaw’s AI can be poisoned through a browser tabA vulnerability affecting Nvidia’s NemoClaw could let an attacker gain control of the local Ollama model server through a single malicious website visit on the victim’s machine. According to a Cyera research , the flaw could give attackers unauthenticated access to the server, al…CSOONLINE.COM
26 AugVMs won't contain cyber-capable agentsAs part of Patch the Planet , we received preview access to GPT 5.6-Cyber with a simple task: evaluate its cyber capabilities. Recent events inspired me to give it a challenge to work through: escape the VM I’d normally use for sandboxing. The target was a QEMU/KVM VM on my Linux…TRAILOFBITS.COM
26 AugUnpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run CodeThe CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The flaws, tracked as CVE-2026-19913 and CVE-2026…THEHACKERNEWS.COM
26 AugCVE-2026-62890 Windows GDI+ Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
25 AugAttackers Target miniOrange SAML Flaws That Can Grant WordPress Admin AccessBad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators. The vulnerabilities, as disclosed by…THEHACKERNEWS.COM
25 Aug KEVActively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilit…THEHACKERNEWS.COM
25 AugCISA Warns of Exploited Oracle WebLogic VulnerabilityThe vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers. The post CISA Warns of Exploited Oracle WebLogic Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
25 AugUnpatched Zimbra servers are falling to CVE-2026-73570 attacksAt least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. About CVE-2026-73570 Zimbra Collaboration Suite (ZCS) is a communication and collaboration platform popular with organization…HELPNETSECURITY.COM
25 AugNucleus wants to get ahead of scanners on new vulnerabilitiesThere usually is a crucial time lapse from when a vulnerability is newly disclosed to when security scanners are finally updated to scan for it. Nucleus Security says it wants to close that gap. The cybersecurity outfit focused on unified exposure management is expanding its plat…CSOONLINE.COM
25 AugCVE-2026-55137 Microsoft Excel Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
25 AugCVE-2026-50448 Windows NTFS Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
25 AugCVE-2026-61939 Winlogon Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
25 AugWordPress Websites Targeted via MiniOrange Plugin VulnerabilitiesCVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin. The post WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
25 AugCVE-2026-62728 Windows Common Log File System Driver Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
25 AugCVE-2026-59127 Windows Installer Elevation of Privilege VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
25 AugVU#308749: Remote Code Execution and Arbitrary File Read Vulnerabilities in Kaltura ServersOverview The Kaltura HTML5 Player Library (mwEmbed / html5lib) contains two vulnerabilities, both involving the same insecure deserialization flaw, that enable arbitrary file read and remote code execution. Affected versions include html5lib v2.45, v2.103 and earlier, and other v…KB.CERT.ORG
25 AugTwo CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as VulnerableTwo CVSS 9.8 miniOrange SAML WordPress plugin auth bypasses were exploited while paid editions never appeared in any vulnerability database. Manual patch required. Two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On WordPress plugin, both …SECURITYAFFAIRS.COM
24 Aug KEVMicrosoft patches perfect-ten Entra ID flaw, Defender driver deletes Defender at boot, Malware turns cars into proxy botnetEntra ID Perfect 10 Patch, Defender Driver Weaponized, SickKids Breach, Live Leaked AWS Keys, and Car Head Unit Malware Microsoft patched a maximum-severity Entra ID deserialization RCE (CVE-2026-69836) after briefly indicating it was exploited in the wild before correcting that …CYBERSECURITYTODAY.LIBSYN.COM
24 AugCritical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any AccountRed Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset. The vulnerability, as…THEHACKERNEWS.COM
24 AugCVE-2026-65787 Desktop Window Manager Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
24 AugCVE-2026-47292 Visual Studio Code MSSQL Extension Remote Code Execution VulnerabilityAffected software updated with new package information.MSRC.MICROSOFT.COM
24 AugMetal Gear Online 3 flaw allowed code execution on players’ PCsA vulnerability in Konami’s Metal Gear Online 3 allowed malicious multiplayer lobby hosts to remotely execute arbitrary code on the computers of players joining their sessions. The flaw, tracked as CVE-2026-19874, was silently fixed earlier this month in game version 1.1.2.9. The…CYBERINSIDER.COM
24 AugExploited Zimbra Flaw Highlights Shrinking Window to PatchCISA has issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications.DARKREADING.COM
21 Aug KEVMicrosoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code ExecutionMicrosoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer action is required. The vulnerability, tracked as CVE-2026-69836 (CVSS score: 10.0), is a case of remote code execution impacting t…THEHACKERNEWS.COM
21 AugGitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of DisclosureA newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an unauthenticated attacker to modify or …THEHACKERNEWS.COM
21 AugCitrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)Citrix has patched two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw tracked as CVE-2026-19490, and is urging customers to upgrade affected appliances as soon as possible. “We strongly recommend that customers review…HELPNETSECURITY.COM
21 AugGitLab Warns of Active Exploitation of Critical GraphQL FlawGitLab flaw CVE-2026-19478 is now under active exploitation, allowing unauthenticated attackers to modify or delete public projects. WatchTowr researchers warn of active exploitation of critical GitLab flaw CVE-2026-19478 (CVSS score of 9.4). This week, GitLab pushed out an emerg…SECURITYAFFAIRS.COM
21 AugPoland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite FlawCERT Polska confirmed active exploitation of CVE-2026-73570, a critical unauthenticated RCE in Zimbra Collaboration Suite patched on July 20. CERT Polska, Poland’s national computer emergency response team, confirmed this week that threat actors are actively exploiting a cr…SECURITYAFFAIRS.COM
21 AugCVE-2026-58547 Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 AugCVE-2026-49183 Windows Clipboard Server Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 AugCVE-2026-55134 Microsoft Word Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 AugCVE-2026-68801 Microsoft Excel Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 AugCVE-2026-64903 Microsoft Office Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 AugCVE-2026-64899 Microsoft Office Information Disclosure VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 AugCVE-2026-70335 GitHub Copilot and Visual Studio Code Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 Aug KEVCritical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)Microsoft has patched a critical remote code execution vulnerability (CVE-2026-69836) in Entra ID, reportedly exploited in the wild. Entra ID is Microsoft’s cloud identity service, formerly Azure Active Directory, that verifies logins and controls access to Microsoft 365, A…HELPNETSECURITY.COM
21 AugCVE-2026-50466 Microsoft Brokering File System Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 AugVU#756733: Calix GS7 XGS GS5239XG residential router contains missing authentication vulnerabilityOverview The Calix GS7 XGS GS5239XG router running firmware EXOS/6.6.47 contains a missing authentication vulnerability that exposes its UPnP (Universal Plug and Play) WANIPConnection service on the public WAN interface. Description Calix GS7 XGS GS5239XG is a residential gateway…KB.CERT.ORG
21 Aug KEVCVE-2026-69836 Microsoft Entra ID Remote Code Execution VulnerabilityCorrected **Exploited** to **No**. This vulnerability was not exploited in the wild. This is an informational change only.MSRC.MICROSOFT.COM
20 AugElementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute CodeCybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been descr…THEHACKERNEWS.COM
20 AugCritical GitLab Flaw Exploited Shortly After DisclosureCVE-2026-19478 can be exploited without authentication to modify or delete public projects and user data. The post Critical GitLab Flaw Exploited Shortly After Disclosure appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugCVE-2026-66802 Windows Device Health Attestation (DHA) Remote Code Execution VulnerabilityCorrected the Executive Summary to clarify that the vulnerability affects Windows Device Health Attestation (DHA), not Microsoft Azure Attestation. This is an informational change only.MSRC.MICROSOFT.COM
20 AugCVE-2026-71331 Windows Device Health Attestation (DHA) Remote Code Execution VulnerabilityCorrected the Executive Summary to clarify that the vulnerability affects Windows Device Health Attestation (DHA), not Microsoft Azure Attestation. This is an informational change only.MSRC.MICROSOFT.COM
20 AugAttackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code ExecutionA now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska). The vulnerability in question is CVE-2026-73570 (CVSS score: 8.9), which refers to a case of co…THEHACKERNEWS.COM
20 AugCVE-2026-62754 Windows Kerberos Elevation of Privilege VulnerabilityUpdated links to security updates. This is an informational change only.MSRC.MICROSOFT.COM
20 AugHackers Target Zimbra Servers in Active Exploitation CampaignExploitation of the Zimbra Collaboration vulnerability CVE-2026-73570 has been observed by Poland’s CERT Polska. The post Hackers Target Zimbra Servers in Active Exploitation Campaign appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugCVE-2026-54118 Microsoft SQL Server Remote Code Execution VulnerabilityThe CVSS vector string was update to reflect that an attacker does not require any privileges to successfully exploit this vulnerability (PR:N). This is an informational change only.MSRC.MICROSOFT.COM
20 AugCVE-2026-54117 Microsoft SQL Server Remote Code Execution VulnerabilityThe CVSS vector string was update to reflect that an attacker does not require any privileges to successfully exploit this vulnerability (PR:N). This is an informational change only.MSRC.MICROSOFT.COM
20 AugCitrix issues critical security updates for its NetScaler devicesCitrix is urging its NetScaler ADC and NetScaler Gateway customers to quickly patch two critical security holes, one involving a memory overflow vulnerability leading to unpredictable behavior or denial of service, and the other allowing authentication bypass. Citrix said in an a…CSOONLINE.COM
20 AugRejoice In The Nostalgia - PSW #940In the security news this week: - Cursor opens your repo, the repo opens you - If you want the good model I'm going to need to see your ID - Flock's a Flocking mess - Defender was supposed to be the chosen one - Side stepping Secure boot - twice - SonicWall: a LAMP stack in a fan…YOUTUBE.COM
19 AugMicrosoft finally patches critical one-click Copilot vulnerability, almost eight months after learning of itAlmost eight months after confirming a critical security vulnerability within the personal version of its AI assistant, Copilot, Microsoft on Tuesday issued a patch to close the hole, which relies on an LLM’s inability to distinguish the data in a query from an instruction. The C…CSOONLINE.COM
19 Aug KEVCVE-2026-20349: Someone Is Crashing Cisco Firewalls. We Need to Talk About Why.An unauthenticated attacker can crash any Cisco ASA or FTD with SSL VPN exposed; it’s been confirmed exploited in the wild, and Cisco hasn’t told us who or why. Attackers Can Force Your Firewall To Reboot If you run a Cisco Adaptive Security Appliance or a Firepower T…ECLYPSIUM.COM
19 AugCVE-2026-62705 Microsoft Brokering File System Elevation of Privilege VulnerabilityCorrected the CVE title from **Windows Bind Filter Driver Elevation of Privilege Vulnerability** to **Microsoft Brokering File System Elevation of Privilege Vulnerability** and updated the acknowledgement. These are informational changes only.MSRC.MICROSOFT.COM
19 AugCVE-2026-69414 Microsoft Defender Elevation of Privilege VulnerabilityCWE added. Informational change only.MSRC.MICROSOFT.COM
19 AugCVE-2020-1173 Microsoft Power BI Report Server Spoofing VulnerabilityCorrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.MSRC.MICROSOFT.COM
19 AugCVE-2021-26859 Microsoft Power BI Information Disclosure VulnerabilityCorrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.MSRC.MICROSOFT.COM
19 AugCVE-2021-41372 Power BI Report Server Spoofing VulnerabilityCorrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.MSRC.MICROSOFT.COM
19 AugCVE-2023-21806 Power BI Report Server Spoofing VulnerabilityCorrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.MSRC.MICROSOFT.COM
19 AugCVE-2026-58647 Microsoft PowerBI Report Server Spoofing VulnerabilityCorrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.MSRC.MICROSOFT.COM
19 AugCVE-2026-65811 Power BI Remote Code Execution VulnerabilityCorrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.MSRC.MICROSOFT.COM
19 Aug KEVCVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler GatewayOverview On August 19, 2026, a security advisory was published for CVE-2026-19490 , a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3 and can be exploited remotely by an una…RAPID7.COM
19 AugVU#874418: RDK-B WebUI contains multiple vulnerabilitiesOverview RDK Central RDK-B WebUI version, rdkb-2025q4-kirkstone, contains multiple vulnerabilities involving memory corruption, improper authentication, race conditions, and insufficient input validation. An attacker with network access to an affected WebUI may be able to bypass …KB.CERT.ORG
18 AugCritical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public ProjectsGitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. T…THEHACKERNEWS.COM
18 AugGitLab Patches Critical Unauthenticated GraphQL VulnerabilityGitLab patched a critical GraphQL flaw that let unauthenticated attackers remotely modify or delete public projects on self-managed servers. GitLab pushed out an emergency patch this week to address a critical flaw, tracked as CVE-2026-19478 (CVSS score of 9.4), that could let an…SECURITYAFFAIRS.COM
18 Aug300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin FlawTracked as CVE-2026-15748, the arbitrary file upload bug allows unauthenticated attackers to upload executable files. The post 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw appeared first on SecurityWeek .SECURITYWEEK.COM
18 AugCritical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.2 before 18.11.11, 19.0 befor…HELPNETSECURITY.COM
18 AugCVE-2026-24301 Microsoft Copilot Information Disclosure VulnerabilityImproper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.MSRC.MICROSOFT.COM
18 AugCVE-2026-47632 Azure Connected Machine Agent Elevation of Privilege VulnerabilityCorrected the affected product from **Azure Monitor Agent Metrics Extension** to **Azure Connected Machine Agent** and updated the Security Updates table. This is an informational change only.MSRC.MICROSOFT.COM
18 AugCritical GitLab flaw allows attackers to delete and modify public reposGitLab has fixed a critical vulnerability that could allow unauthenticated attackers to perform unauthorized modifications inside code repositories or to completely delete them with a single HTTP request. The patched releases also address a second high-risk cross-site request for…CSOONLINE.COM
18 AugCritical GitLab Zero-Click Flaw Poses Mitigation ChallengesA lack of technical details could make it hard for organizations running self-managed GitLab versions to detect potential exploitation of CVE-2026-19478.DARKREADING.COM
17 AugHackers exploit SharePoint bypass, Snowflake hacker's threats to researcher backfire, CISA warns schoolsCISA's Back-to-School Cyber Playbook, SharePoint Auth Bypass Exploited, and Major Ransomware & Cybercrime Arrests As students return to class, CISA released two free cybersecurity guides for K–12 leaders with limited budgets, emphasizing MFA, device protection, tested backups, an…CYBERSECURITYTODAY.LIBSYN.COM
17 AugCritical SAP Commerce Cloud Vulnerability Exploited 3 Days After DisclosureThe vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components. The post Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure appeared first on SecurityWeek .SECURITYWEEK.COM
17 AugMicrosoft working on Defender patch for ShieldBreak zero-dayMicrosoft is working on a security patch for the "ShieldBreak" zero-day vulnerability disclosed last week by security researcher "Nightmare Eclipse" and now tracked as CVE-2026-69414. [...]BLEEPINGCOMPUTER.COM
17 AugSuspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived RansomwareCybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-travers…THEHACKERNEWS.COM
17 Aug KEVAttackers exploit patched macOS Screen Sharing flaw to deploy cryptominerA recently patched security flaw in Apple macOS is being actively exploited by hackers to bypass authentication, gain root access, and install a cryptominer, the Netherlands’ National Cyber Security Centre (NCSC) warns. The vulnerability, tracked as CVE-2026-65400, , let attacker…HELPNETSECURITY.COM
17 AugCertighost and the Privilege Hiding in Your Certificate AuthorityCVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing privilege, implicit trust, and treating PKI as the Tier 0 identity infrastructure it has always been. [...]BLEEPINGCOMPUTER.COM
17 AugCVE-2026-62722 Microsoft Brokering File System Elevation of Privilege VulnerabilityCorrected the CVE description and title. This is an informational change only.MSRC.MICROSOFT.COM
17 AugForminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP UploadsA critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites. The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out of 10.…THEHACKERNEWS.COM
16 AugSecurity Affairs newsletter Round 590 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Crooks Are Buying Your Expired Do…SECURITYAFFAIRS.COM
16 AugCVE-2026-65769 Microsoft Teams iOS Information Disclosure VulnerabilityCorrected build number for the security update. This in an informational change only.MSRC.MICROSOFT.COM
15 AugmacOS Screen Sharing Flaw Exploited to Deploy Monero MinersHackers are exploiting a macOS Screen Sharing flaw to gain root access and install Monero miners on Macs with port 5900 exposed online. The Dutch National Cyber Security Centre confirmed active exploitation of a critical macOS authentication flaw, tracked as CVE-2026-65400 (CVSS …SECURITYAFFAIRS.COM
15 Aug KEVSAP Commerce Cloud CVE-2026-58231 Exploited in the WildAttackers are actively exploiting a maximum severity SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231, just days after SAP released a patch. A critical SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231 (CVSS score of 10.0), is under active exploitation just d…SECURITYAFFAIRS.COM
14 AugYou’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))Suddenly, you’re in a room. You look around - oh, you’re surrounded by other new starters at your new job. Yes, it’s Monday, and you’re being onboarded. You know the drill - it’s the typical enterprise “please don’t beLABS.WATCHTOWR.COM
14 AugCVE-2026-65671 Remote Access API Elevation of Privilege VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
14 AugCVE-2026-62746 Win32k Information Disclosure VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
14 AugCVE-2026-40400 Windows PowerShell Remote Code Execution VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
14 AugCVE-2026-48566 Windows DWM Core Library Information Disclosure VulnerabilityThis CVE has been discovered to be an Elevation of Privilege and not an Information Disclosure. The CVE's Impact has been updated.MSRC.MICROSOFT.COM
14 AugChromium: CVE-2026-19560 Use after free in BlinkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
14 AugChromium: CVE-2026-19559 Use after free in HTMLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
14 AugChromium: CVE-2026-19558 Use after free in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
14 AugChromium: CVE-2026-19557 Use after free in TabStripThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
14 AugChromium: CVE-2026-19556 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
14 AugMetasploit Wrap Up: Lot of summer shells and fit http profilesThis wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their e…RAPID7.COM
14 Aug KEVThe Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposureTenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous offensive AI has crossed from theoretical risk to…TENABLE.COM
13 AugAttackers Exploit SharePoint Authentication Bypass After Public PoC ReleaseThreat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from w…THEHACKERNEWS.COM
13 AugSharePoint CVE-2026-55040 Comes Under Attack Following Public ExploitAttackers are exploiting SharePoint flaw CVE-2026-55040 after a public PoC was released, allowing unauthenticated users to impersonate administrators. Attackers started exploiting CVE-2026-55040 (CVSS score of 9.1), a critical SharePoint authentication bypass patched in July, wit…SECURITYAFFAIRS.COM
13 AugCritical VMware vCenter Vulnerability in Attackers’ CrosshairsTracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code. The post Critical VMware vCenter Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek .SECURITYWEEK.COM
13 AugIt took $58 to break Microsoft’s SCCM, but a patch made it harderResearchers at XM Cyber found that a standard domain user with no Microsoft SCCM privileges can chain multiple flaws to reach remote code execution, although the attack does require network access to the SCCM environment. Enterprises use Microsoft System Center Configuration Mana…CSOONLINE.COM
13 AugAttackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)Threat actors have begun exploiting a critical Microsoft SharePoint flaw following the release of proof-of-concept (PoC) exploit code by Rapid7. About CVE-2026-55040 Tracked as CVE-2026-55040, the vulnerability was patched by Microsoft as part of its July 2026 Patch Tuesday updat…HELPNETSECURITY.COM
13 AugCVE-2026-49162 Microsoft Brokering File System Elevation of Privilege VulnerabilityAdded acknowledgements. This is an informational change only.MSRC.MICROSOFT.COM
13 AugCVE-2026-62695 Windows Storage Elevation of Privilege VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
13 AugCVE-2026-61359 Windows Storage Elevation of Privilege VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
13 AugCVE-2026-65796 Windows iSCSI Target Service Denial of Service VulnerabilityCorrected severity entries in the Affected Products table. This is an informational change only. Customers who have successfully installed the update do not need to take any further action.MSRC.MICROSOFT.COM
13 AugCVE-2026-45593 Windows SDK Elevation of Privilege VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
13 AugCVE-2026-45592 Windows Internet (wininet.dll) Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
13 AugCVE-2026-50461 Windows NTFS Remote Code Execution VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
13 AugCVE-2026-49798 Windows Kernel Elevation of Privilege VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
13 AugCVE-2026-50387 Windows GDI Elevation of Privilege VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
13 AugAdobe Commerce Bug Targeted Immediately After DisclosureThe first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches. The post Adobe Commerce Bug Targeted Immediately After Disclosure appeared first on SecurityWeek .SECURITYWEEK.COM
13 AugCVE-2026-62897 .NET Framework Remote Code Execution VulnerabilityRemoved Linux and macOS products from the Affected Software table. This is an informational change only.MSRC.MICROSOFT.COM
13 AugCVE-2026-62902 .NET Information Disclosure VulnerabilityRemoved Linux and macOS products from the Affected Software table. This is an informational change only.MSRC.MICROSOFT.COM
13 AugCVE-2026-70354 .NET Core Remote Code Execution VulnerabilityRemoved Linux and macOS products from the Affected Software table. This is an informational change only.MSRC.MICROSOFT.COM
13 AugCVE-2026-62871 .NET Elevation of Privilege VulnerabilityRemoved Linux and macOS products from the Affected Software table. This is an informational change only.MSRC.MICROSOFT.COM
13 AugCVE-2026-62886 .NET Elevation of Privilege VulnerabilityRemoved Linux and macOS products from the Affected Software table. This is an informational change only.MSRC.MICROSOFT.COM
13 AugCVE-2026-62898 Microsoft QUIC Information Disclosure VulnerabilityRemoved Linux and macOS products from the Affected Software table. This is an informational change only.MSRC.MICROSOFT.COM
13 AugCritical VMware vCenter RCE flaw exploited for reverse SSH accessA recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. [...]BLEEPINGCOMPUTER.COM
13 AugAdobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public DisclosureHackers began targeting a critical Adobe Commerce flaw that could let unauthenticated attackers hijack customer accounts and access private data. Hackers began targeting CVE-2026-71362 (CVSS score of 9.1), a critical Adobe Commerce flaw, shortly after its public disclosure. The v…SECURITYAFFAIRS.COM
13 AugGlobal Threat Campaign Hits Critical VMware vCenter FlawExploitation against CVE-2026–59310 began earlier this month, and patching the vulnerability may not be enough to fully mitigate the threat.DARKREADING.COM
12 AugMicrosoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active AttackMicrosoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escal…THEHACKERNEWS.COM
12 AugDefCon airplane Wi-Fi drama. GhostJacking leads to agent hijacks, AI agent hacks gymDEF CON In-Flight Wi‑Fi Hack, 400 Microsoft Patches, and AI Agent 'Ghostjacking' Delta Air Lines is investigating a brief appearance of an unauthorized Wi‑Fi network on a Las Vegas–Atlanta flight carrying DEF CON attendees after reports of a deauthentication attack, a rogue SSID …CYBERSECURITYTODAY.LIBSYN.COM
12 Aug KEVPatch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerabilityA currently exploited zero-day elevation of privilege vulnerability that needs to be patched in a Windows driver for WinSock is the highlight of the 398 fixes issued today in Microsoft’s August Patch Tuesday releases. The hole is in Windows’ Ancillary Function Driver for WinSock …CSOONLINE.COM
12 AugMetabase SQLi exploit grants attackers total accessBusiness intelligence (BI) platform provider Metabase has disclosed a zero-day SQL Injection vulnerability, warning that customers’ sensitive credentials, tokens, API keys, and other data may have been exposed. The Metabase vulnerability revealed on August 6, designated CVE-2026-…CSOONLINE.COM
12 AugCisco Patches Firewall Zero-Day Exploited for DoS AttacksCVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices. The post Cisco Patches Firewall Zero-Day Exploited for DoS Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugSAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary CodeSAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution. The vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It has been des…THEHACKERNEWS.COM
12 AugShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM AccessThe security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak. The vulnerability, rooted in Microsoft Defender for Windows, demonstrates …THEHACKERNEWS.COM
12 Aug KEVCisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoSCisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild. The high-severity flaw, tracked as CVE-2026-20349 (CVSS score: 8.6), is a case of insuf…THEHACKERNEWS.COM
12 Aug17 old software bugs that took way too long to squashIn 2021, a vulnerability was revealed in a system that lay at the foundation of modern computing. An attacker could force the system to execute arbitrary code. Shockingly, the vulnerable code was almost 54 years old — and there was no patch available, and no expectation that one …CSOONLINE.COM
12 AugShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet PatchChaotic Eclipse released a PoC for ShieldBreak, a Microsoft Defender zero-day that bypasses the CVE-2026-50656 patch and could enable SYSTEM-level code execution. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a …SECURITYAFFAIRS.COM
12 AugAttackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote AccessThreat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter s…THEHACKERNEWS.COM
12 AugMicrosoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)Microsoft’s August 2026 Patch Tuesday delivered security fixes for 400+ vulnerabilities, including one that has been exploited in zero-day attacks (CVE-2026-68820) and three that were publicly disclosed prior to the release of the patches. Vulnerabilities of note CVE-2026-6…HELPNETSECURITY.COM
12 AugAdobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic FlawsAdobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The most severe of the flaws are listed below -…THEHACKERNEWS.COM
12 AugNIST Seeks Public Input on AI-Ready NVD ModernizationThe US National Institute for Standards and Technology wants to modernize its National Vulnerability Database to embrace AI-powered vulnerability researchINFOSECURITY-MAGAZINE.COM
12 AugCVE-2026-62696 Windows Program Compatibility Assistant Service Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
12 AugCVE-2026-62747 Windows Device Association Service Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
12 AugCVE-2026-70348 Windows Management Services Denial of Service VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
12 AugCVE-2026-68815 Microsoft Excel Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
12 AugCVE-2026-50687 Windows Win32k Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
12 AugCVE-2026-58538 Windows Bluetooth Service Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
12 AugCVE-2026-50655 Microsoft Windows Media Foundation Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
12 AugCVE-2026-62913 Microsoft Exchange Server Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
12 AugCVE-2026-58643 Windows Admin Center Spoofing VulnerabilityCorrected Build Number in the Security Updates table. This is an informational change only.MSRC.MICROSOFT.COM
12 AugCVE-2026-50476 Windows Network Connections Service Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
12 AugLazarus hackers exploited Windows zero-day to target defense firmsNorth Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. [...]BLEEPINGCOMPUTER.COM
12 AugHackers exploit critical Adobe Commerce flaw to hijack customer accountsAttempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts. [...]BLEEPINGCOMPUTER.COM
12 Aug KEVResearcher creates workaround for Microsoft Defender security patchJust weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent workaround that provides system-level control to attackers once they gain any level of access. The researcher, who goes by the name Nightmare Eclipse, has b…CSOONLINE.COM
11 AugCVE-2026-68203 media: vivid: fix cleanup bugs in vivid_init()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68114 drm/amdgpu/gfx12.1: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68190 staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68273 drm/amdgpu: Fix context pstate override handlingInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68097 ksmbd: validate ACE size against SID sub-authoritiesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68407 wifi: nl80211: free RNR data on MBSSID mismatchInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-71556 go-git: Worktree operations may follow symlinksInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68323 tipc: serialize udp bearer replicast list updatesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68252 drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68374 usb: core: sysfs: add lock to bos_descriptors_read()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68152 amt: fix use-after-free in AMT delayed worksInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68189 Bluetooth: hci_sync: Protect UUID list traversalInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68136 net: gro: fix double aggregation of flush-marked skbsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68254 drm/i915/vrr: require valid min/max vfreq for VRRInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68238 drm/amdgpu: Release VFCT ACPI table referenceInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68241 drm/i915/mst: limit DP MST ESI service loopInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-66486 Improper Output Encoding in GNU cpioInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68249 drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68155 libceph: Reject monmaps advertising zero monitorsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-66484 Path Traversal in GNU cpioInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68337 bpf: Reject redirect helpers without a bpf_net_contextInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68110 drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68195 wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio busesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68111 drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68115 drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68182 comedi: comedi_parport: deal with premature interruptInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68331 dpaa2-eth: put MAC endpoint device on disconnectInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68118 tcp: challenge ACK for non-exact RST in SYN-RECEIVEDInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68129 gve: fix Rx queue stall on alloc failureInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68112 drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68328 nfp: Check resource mutex allocationInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68123 openvswitch: fix GSO userspace truncation underflowInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68218 media: pci: dm1105: Free allocated workqueueInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68250 drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68165 mm/damon/core: validate ranges in damon_set_regions()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68137 net/x25: fix use-after-free in x25_kill_by_neigh()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68406 wifi: cfg80211: validate PMSR FTM preamble rangeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68317 pds_core: fix auxiliary device add/del racesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68154 libceph: reject zero bucket types in crush_decodeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68417 RDMA/siw: publish QP after initializationInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68303 drm/vc4: hvs/v3d: Fix null dereference in unbindInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68109 drm/amdgpu/sdma7.1: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68192 wifi: brcmfmac: make release_scratchbuffers idempotentInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68419 RDMA/irdma: Prevent rereg_mr for non-mem regionsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68157 libceph: guard missing CRUSH type name lookupInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68354 firewire: net: Fix fragmented datagram reassemblyInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68180 intel_th: fix MSC output device reference leakInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68409 wifi: mac80211: defer link RX stats percpu free to RCUInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68113 drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68310 wifi: mt76: mt7915: guard HE capability lookupsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68140 net/iucv: fix use-after-free of a severed iucv_pathInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68248 drm/i915: Return NULL on error in active_instanceInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68246 drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68376 sctp: fix auth_hmacs array size in struct sctp_cookieInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68135 net: hip04: fix RX buffer leak on build_skb failureInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68151 binfmt_elf_fdpic: only honour the first PT_INTERPInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68247 drm/i915/bios: range check LFP Data Block panel_type2Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68381 ksmbd: pin conn during async oplock break notificationInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68343 smb: client: validate DFS referral PathConsumedInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68184 cdrom: fix stack out-of-bounds read in CDROMVOLCTRLInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68214 media: rtl2832: fix use-after-free in rtl2832_remove()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68327 wan: wanxl: Only reset hardware after BAR mappingInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68188 Bluetooth: RFCOMM: Fix session UAF in set_termiosInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68313 tipc: fix infinite loop in __tipc_nl_compat_dumpitInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68121 pppoe: reload header pointer after dev_hard_header()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68102 drm/amdgpu: fix aperture mapping leakInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68325 iommu/amd: Bound the early ACPI HID mapInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68233 drm/vc4: Shut down BO cache timer before teardownInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68304 wifi: brcmfmac: fix 802.1X-SHA256 call trace warningInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-64563 rhashtable: clear stale iter->p on table restartInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68098 ksmbd: bound DACL dedup walk to copied ACEsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68399 bpf: Fix UAF in sock clone early bailoutsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68302 amt: re-read skb header pointers after every pullInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68333 dpaa2-switch: put MAC endpoint device on disconnectInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-66485 Uncontrolled Memory Allocation in GNU cpioInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68161 sctp: close UDP tunnel sockets during netns teardownInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68166 userfaultfd: prevent registration of special VMAsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68198 wifi: ath6kl: fix use-after-free in aggr_reset_state()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68194 wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio busesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68108 drm/amdgpu/vce: fix integer overflow in image sizeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68226 media: cx23885: add ioremap return check and cleanupInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68144 phonet: pep: fix use-after-free in pep_get_sb()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68107 drm/amdgpu/vcn4: avoid rereading IB param lengthInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68236 drm/amd/display: set new_stream to NULL after releaseInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68340 hwmon: occ: validate poll response sensor blocksInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68253 drm/i915/hdcp: check streams[] bounds before overflowInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68339 Bluetooth: btusb: validate Realtek vendor event lengthInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68153 libceph: remove debugfs files before client teardownInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68251 drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-64377 cpufreq: qcom-cpufreq-hw: Fix possible double freeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-64388 smb/client: fix chown/chgrp with SMB3 POSIX ExtensionsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2024-57895 ksmbd: set ATTR_CTIME flags when setting mtimeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2024-57893 ALSA: seq: oss: Fix races at processing SysEx messagesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2024-57795 RDMA/rxe: Remove the direct link to net_deviceInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2025-37853 drm/amdkfd: debugfs hang_hws skip GPU with MESInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2025-37849 KVM: arm64: Tear down vGIC on failed vCPU creationInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2025-37903 drm/amd/display: Fix slab-use-after-free in hdcpInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)Overview Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapi…RAPID7.COM
11 AugRapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)Overview On July 14, 2026, Rapid7 and Microsoft disclosed CVE-2026-55040, an authentication bypass vulnerability affecting Microsoft SharePoint. Today we are publishing a technical analysis of the vulnerability along with an accompanying proof-of-concept (PoC) script . Figure 1: …RAPID7.COM
11 AugVU#431093: TCG TPM 2.0 reference code found vulnerable to information leakage and timing side-channel attacksOverview Two vulnerabilities have been identified in the Trusted Platform Module (TPM) 2.0 reference implementation: CVE-2026-6726 – Information leakage via falsified TPM keys. CVE-2026-6727 – A timing side-channel vulnerability in RSA OAEP decryption. An attacker with privileged…KB.CERT.ORG
11 AugNIST wants to overhaul its vulnerability database for the AI ageNIST is seeking public input to modernize the National Vulnerability Database to keep pace with AI-driven cyber threats and machine-scale security data. The post NIST wants to overhaul its vulnerability database for the AI age appeared first on CyberScoop .CYBERSCOOP.COM
11 AugZoom zero-click flaw allowed RCE attacks during meetingsMultiple vulnerabilities in Zoom’s annotation engine could allow a malicious meeting participant to compromise another attendee’s device by sending specially crafted meeting data. The most serious issue, tracked as CVE-2026-53413, is a buffer overwrite that Zoom says could lead t…CYBERINSIDER.COM
11 AugResearchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCESecurity researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects Shar…THEHACKERNEWS.COM
11 Aug KEVMicrosoft's August 2026 Patch Tuesday Addresses 398 CVEs (CVE-2026-68820)42 Critical 355 Important 1 Moderate 0 Low Microsoft addresses 398 CVEs in the eighth Patch Tuesday of 2026, with three zero-days, including one that was exploited in the wild. Microsoft patched 398 CVEs in its August 2026 Patch Tuesday release, with 42 rated critical, 355 rated …TENABLE.COM
11 AugZoom Patches “Zoomsday” Zero-Click Flaw Enabling Remote Code ExecutionZoom patches a zero-click flaw that could let a meeting participant execute code on another user’s computer through the annotation feature. Zoom has patched four vulnerabilities, including a critical zero-click flaw, tracked as CVE-2026-53413, in its annotation feature. CVE-2026-…SECURITYAFFAIRS.COM
11 AugCVE-2026-19137 Use after free in WebGLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19140 Use after free in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19138 Heap buffer overflow in CrashReportingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19139 Race in CredentialProviderThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19145 Use after free in TranslateThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19142 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19144 Use after free in HTMLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19146 Uninitialized Use in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19147 Use after free in AuraThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19149 Use after free in AuraThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19148 Out of bounds write in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19151 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19153 Insufficient validation of untrusted input in WorkersThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19152 Inappropriate implementation in NavigationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19155 Use after free in PaymentsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19158 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19157 Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19156 Heap buffer overflow in BaseThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19150 Inappropriate implementation in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19161 Uninitialized Use in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19162 Out of bounds write in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19160 Uninitialized Use in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19163 Use after free in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19159 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19164 Insufficient validation of untrusted input in CodecsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19165 Use after free in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19167 Integer overflow in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19166 Use after free in Web AuthenticationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19170 Use after free in WebGLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19169 Insufficient validation of untrusted input in Contextual TasksThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19173 Out of bounds write in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19172 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19168 Inappropriate implementation in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19174 Integer overflow in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19176 Use after free in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19171 Use after free in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19175 Use after free in PaymentsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19177 Insufficient validation of untrusted input in UIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugZoom zero-click RCE flaws allow attackers to compromise meeting participantsZoom has fixed four vulnerabilities across its applications, including two that could allow attackers who join a meeting to execute malicious code on the systems of all other meeting participants with no interaction required from them. Three of the vulnerabilities affect all Zoom…CSOONLINE.COM
10 AugAI writes patches that don't work, WordPress login takeover, Researchers hijack 36 million kids' GPS trackersAI Patch Development Fails, WordPress Login XSS Hits All Versions, and DEF CON's Biggest Security Lessons David Shipley covers new research from 1Password's Off By One Labs showing AI-generated vulnerability patches often fail: across 6,080 scored patches for six CVEs, only 26% f…CYBERSECURITYTODAY.LIBSYN.COM
10 AugN-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577To help customers fend off ongoing attacks, N-able released a second security hotfix for N‑central, its monitoring and management (RMM) solution popular with managed service providers (MSPs). “Hotfix 2 is required, even if you already applied the earlier hotfix. Hotfix 2 su…HELPNETSECURITY.COM
10 AugCVE-2021-34474 Microsoft Dynamics 365 Business Central Remote Code Execution VulnerabilityUpdated the build numbers. This is an informational update only.MSRC.MICROSOFT.COM
10 AugCVE-2026-50309 Windows NTFS Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
10 AugVU#614868: Opencart ecommerce platform contains directory traversal vulnerabilityOverview The OpenCart v4.2.0.0 extension installer contains a directory traversal vulnerability. The extension installation process extracts uploaded .zip files then uses the zip entry filenames as filesystem paths, without validating that the resolved path stays inside the inten…KB.CERT.ORG
10 AugCVE-2021-40440 Microsoft Dynamics Business Central Cross-site Scripting VulnerabilityUpdated the build numbers. This is an informational update only.MSRC.MICROSOFT.COM
10 AugCVE-2021-36946 Microsoft Dynamics Business Central Cross-site Scripting VulnerabilityUpdated the build numbers. This is an informational update only.MSRC.MICROSOFT.COM
10 AugNATO and an AI startup can now name and track software vulnerabilitiesNATO’s cyber defense arm and a startup that uses artificial intelligence to find software flaws can now issue the ID numbers the industry uses to track those flaws, the European Union Agency for Cybersecurity announced last week.  The NATO Cyber Security Centre, part o…CYBERSCOOP.COM
9 AugCVE-2026-64562 KVM: nVMX: Hide shadow VMCS right after VMCLEARInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-54876 Client-Side Memory Leak in OCSP Response CheckingInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-44605 Rpm: heap buffer overflow in ndb slot table parsingInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64542 ipv6: ndisc: fix NULL deref in accept_untracked_na()Information published.MSRC.MICROSOFT.COM
8 AugCVE-2026-63030 and CVE-2026-60137: 'wp2shell' Captured Exploit PayloadSensor Intel Series: August 2026 CVE TrendsF5.COM
7 AugHuman oversight is still critical as AI patching tools miss security risksAI-generated vulnerability patches still heavily depend on human review, particularly the ones involving security-sensitive code, according to a research. Researchers from 1Password have disclosed an internal evaluation that found AI-generated fixes frequently overlook broader co…CSOONLINE.COM
7 AugNew WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAPWordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server. Tracked as CVE-2026-…THEHACKERNEWS.COM
7 AugVU#987105: The nothings stb TrueType library, up to version 1.26, contains a heap buffer overflow vulnerabilityOverview A heap buffer overflow vulnerability exists in the stb TrueType library created by nothings. Exploitation of this vulnerability can occur when handling malformed font data and may lead to both Denial of Service (DoS) and Information Disclosure. Description The nothings s…KB.CERT.ORG
7 Aug KEVRapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)Overview On July 27, 2026, JetBrains published a security advisory for CVE-2026-63077 , a critical unsafe deserialization vulnerability affecting JetBrains TeamCity . An attacker who can reach a TeamCity server over HTTP or HTTPS can exploit the agent polling protocol without cre…RAPID7.COM
6 AugHackers Start Exploiting Recent JetBrains TeamCity VulnerabilityTracked as CVE-2026-63077, the critical bug can be exploited without authentication for remote code execution. The post Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
6 AugCISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the WildA newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The vulnerability in question is CVE-2026-63077 (CVSS score: 9.8), a ca…THEHACKERNEWS.COM
6 AugCritical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200)Cisco has fixed a critical vulnerability (CVE-2026-20200) in its Integrated Management Controller (IMC), which allows an attacker to run commands as root through the controller’s web interface. The fix was part of Cisco’s August 5 advisory batch, and unlike the bugs s…HELPNETSECURITY.COM
6 AugAutonomy is earned, not claimedAfter more than 300,000 production penetration tests (pentests), our company has learned something that may surprise people watching the recent wave of autonomous security announcements. The hardest problem in autonomous security isn’t teaching a machine how to attack. It’s teach…CSOONLINE.COM
6 AugChinese Zbtlink WiFi routers ship with ENDLESSDOORS malwareAt least 20 Zbtlink router models contain a preinstalled remote-access implant that connects to external command-and-control servers and can execute arbitrary commands with root privileges. The issue, tracked as CVE-2026-66747, does not require attackers to compromise the router …CYBERINSIDER.COM
6 AugTails emergency update fixes flaws that could deanonymize usersThe Tails Project has released Tails 7.10.1 as an emergency security update addressing critical vulnerabilities that could allow attackers to obtain administrator privileges, take control of the operating system, and potentially deanonymize users. Released on August 5, 2026, the …CYBERINSIDER.COM
6 AugNew Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux HostsZapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked…THEHACKERNEWS.COM
6 AugNatJack exploits put NAT security assumptions to the test at Black HatFor decades, Network Address Translation (NAT) has been the default way IP addresses are provided inside larger networks, as a means to deal with the challenges of IPv4 address availability. The basic premise behind NAT is that private addresses stay private, but that assumption …CSOONLINE.COM
6 Aug KEVVU#487613: Alinto SOGo v5.12.7 vulnerable to cross-site scripting via malformed ICS calendar invitationsOverview A cross-site scripting (XSS) vulnerability in Alinto SOGo v5.12.7 allows attackers to achieve remote code execution by embedding malicious SVG (Scalable Vector Graphics) objects in ICS (iCalendar) invitations. The vulnerability has been actively exploited in the wild, as…KB.CERT.ORG
5 AugRuby on Rails critical bug puts every image upload under scrutinyA new critical vulnerability in the Ruby on Rails (“Rails”) web application framework, CVE-2026-66066 , could turn a seemingly innocuous image into a front door to your secrets. Disclosed July 30, the high severity CVE (scored 9.5 out of 10) poses a significant risk to enterprise…CSOONLINE.COM
5 Aug KEVCISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively ExploitedThe U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The list of vulnerabilities is as follows - CVE-2026-9198 (CVSS score: …THEHACKERNEWS.COM
5 AugCritical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode MarkupAn unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Org-mode markup are enough. The flaw is fixed in Gitea 1.2…THEHACKERNEWS.COM
5 AugCritical Paperclip bugs expose AI agent trust failuresSecurity researchers are warning against trust assumptions in AI security with newly detailed flaws affecting the open-source AI agent platform Paperclip that could be chained into remote code execution (RCE), data exposure, and developer-machine compromise. An Oasis Security res…CSOONLINE.COM
5 AugNew OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitchA memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel builds. The vulnerability, tracked as CVE-20…THEHACKERNEWS.COM
5 AugOVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become RootOVSwrap is a 13-year-old Linux kernel flaw that lets local users gain root privileges on most distributions using Open vSwitch. Security researcher Asim Manizada disclosed OVSwrap (CVE-2026-64531, CVSS score of 7.8), a local privilege escalation vulnerability in the Linux kernel&…SECURITYAFFAIRS.COM
5 AugPre-auth RCE in enterprise Java hits Bonita and OFBiz serversAn attacker sends a single web request to a Bonita server and lands inside an internal API that assumed nobody could reach it. The request arrives unauthenticated. From there the attacker runs code on the host. Bonita BPM handles loan approvals, insurance claims, and employee onb…HELPNETSECURITY.COM
4 AugNew cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database RootcPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity. It shipped in a targeted security release that closes two o…THEHACKERNEWS.COM
4 AugCVE-2026-58048: cPanel Bug Enables Full Database Administrator AccessA critical cPanel flaw (CVE-2026-58048) lets authenticated users execute SQL as root. Users should update to fixed versions immediately. If you run a shared hosting box, this one’s worth reading before your morning coffee gets cold. cPanel just patched a flaw, tracked as CV…SECURITYAFFAIRS.COM
3 AugRuby on Rails Patches Critical Active Storage Vulnerability Affecting Image ProcessingRuby on Rails fixed a critical vulnerability that could let unauthenticated attackers read files and achieve remote code execution. Ruby on Rails has patched CVE-2026-66066, a critical vulnerability (CVSS score of 9.5) that could allow unauthenticated attackers to read arbitrary …SECURITYAFFAIRS.COM
3 AugN-able Says Attackers Take Over N-central Servers After Initial Fix Proves IncompleteN-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers. Its first fix was incomplete. CVE-2026-18577 affects N-central builds prior to 2026.3.1.7. N-able shipped build…THEHACKERNEWS.COM
3 AugThermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly UndetectableThermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them. The vendor's July 31 security bulletin says nearly undetectable changes to .fsa and .hid outputs c…THEHACKERNEWS.COM
3 AugKindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)A critical security vulnerability (CVE-2026-66066) in Ruby on Rails (aka Rails), one of the most widely used frameworks for building websites and web apps, may allow attackers to read sensitive files off a server and, in some cases, take full control of it. Nicknamed “Kinda…HELPNETSECURITY.COM
3 Aug KEVN‑able Patches Vulnerability Exploited to Hack N-central ServersThe N‑central vulnerability CVE-2026-18577 has been exploited in the wild after threat actors found a patch bypass. The post N‑able Patches Vulnerability Exploited to Hack N-central Servers appeared first on SecurityWeek .SECURITYWEEK.COM
3 AugAttackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577)Attackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) in N-able N-central, a remote monitoring and management (RMM) solution widely used by managed service providers, to gain access to managed endpoints. How the flaw was discovered “On July 31, 20…HELPNETSECURITY.COM
3 AugN-able warns of N-central auth bypass flaw exploited in attacksN-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers. [...]BLEEPINGCOMPUTER.COM
3 AugRapid7 Analysis: KindaRails2Shell (CVE-2026-66066)Overview On July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066 , an arbitrary file read in Active Storage applications that use the Vips image processor with untrusted uploads. The affected Active Storage ranges are < 7.2.3.2 , >= 8.0,…RAPID7.COM
3 AugAttackers Exploit N-able Patch Bypass Flaw on RMM ServersOver the weekend, the vendor discovered another vector of authentication bypass CVE-2026-18577 that gives attackers administrator access.DARKREADING.COM
1 AugAdobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User InteractionAdobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score o…THEHACKERNEWS.COM
1 AugAdobe fixed a maximum-severity vulnerability flaw in Campaign ClassicAdobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enter…SECURITYAFFAIRS.COM
31 JulOpenAI's rogue agent hit more victims, attackers hit 30 Minnesota water systems, Russian crew delivers weaponized e-mails in ExchangeOpenAI 'Rogue Agent' Fallout, Minnesota Water Systems Hit, Exchange OWA Zero-Click Mailbox Takeover David Shipley covers multiple security stories: the OpenAI "rogue agent" incident expands as Modal Labs says a customer's exposed endpoint was used as a launchpad in attacks on Hug…CYBERSECURITYTODAY.LIBSYN.COM
31 JulCritical Code Execution Vulnerability Patched in TeamCityTracked as CVE-2026-63077, the security defect can be exploited without authentication via the agent polling protocol. The post Critical Code Execution Vulnerability Patched in TeamCity appeared first on SecurityWeek .SECURITYWEEK.COM
31 JulJetBrains says a crafted HTTP request could break TeamCityJetBrains is warning of a critical security vulnerability in its TeamCity DevOps platform that could allow unauthenticated attackers to execute arbitrary operating system commands on vulnerable servers. “If exploited, this vulnerability may allow an unauthenticated attacker with …CSOONLINE.COM
31 JulBroadcom patches vulnerabilities all over VMwareBroadcom has addresses five vulnerabilities in its VMware product range, three of which have been accorded a “critical” rating. The affected products are: VMware ESX, VMware vCenter, VMware Workstation, VMware Fusion, VMware Cloud Foundation, VMware vSphere Foundation, VMware Tel…CSOONLINE.COM
31 JulVU#243636: VPS.org one-click deployment templates contain multiple vulnerabilitiesOverview VPS.org's one-click deployment templates provision services with default passwords and predefined network bindings instead of generating randomized secrets or applying per-deployment hardening measures. Description VPS.org is a cloud and virtual private server hosting pr…KB.CERT.ORG
30 Jul KEVCisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive DataThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation. T…THEHACKERNEWS.COM
30 Jul KEVCisco Secure FMC Zero-Day Exploited in the WildThe vulnerability tracked as CVE-2026-20316 can be exploited by a remote, unauthenticated attacker to log into affected devices. The post Cisco Secure FMC Zero-Day Exploited in the Wild appeared first on SecurityWeek .SECURITYWEEK.COM
30 JulRussian hackers turn Exchange flaw into ‘half-click’ mailbox takeoverA Russia-aligned threat group used a “half-click” exploit against Microsoft Exchange’s Outlook Web Access to install a browser-based backdoor when recipients opened specially crafted emails. The campaign began on July 22 and was conducted by TA488, which is also tracked as Void B…CSOONLINE.COM
30 JulCisco FMC static credentials exploited by attackers (CVE-2026-20316)A static credentials vulnerability (CVE-2026-20316) in Cisco Secure Firewall Management Center (FMC), a platform for centrally managing multiple Cisco Secure Firewall devices across a network, is being leveraged by attackers, CISA warned. Two FMC flaws, one indicator of compromis…HELPNETSECURITY.COM
30 Jul KEVCritical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)Overview On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-20…RAPID7.COM
30 JulCVE-2026-56197 Windows Admin Center (WAC) Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
30 JulCVE-2026-54128 Windows DHCP Client Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
30 JulCritical Ruflo flaw lets attackers hijack AI agents through exposed MCP bridgeA critical vulnerability in the open-source AI agent platform Ruflo could allow unauthenticated attackers to take control of enterprise AI environments by exploiting an exposed Model Context Protocol (MCP) bridge, according to research published by Noma Security. The flaw, tracke…CSOONLINE.COM
30 JulLaundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)Russia-affiliated cyber espionage group Laundry Bear (aka Void Blizzard, aka TA488) is exploiting CVE-2026-42897, a cross-site scripting vulnerability in Microsoft Exchange, to target US and European government entities and a variety of private sector organizations via email. The…HELPNETSECURITY.COM
30 JulVU#790363: foreUP golf management platform's web API contains multiple vulnerabilitiesOverview Two vulnerabilities in the REST API were found in Golf Compete foreUP. The first exposes the merchant, Finix, API credentials directly in customer record responses, allowing any user to obtain and use the payment processor account. The second is a missing object-level au…KB.CERT.ORG
30 JulKindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on RailsOverview On July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066 , a critical vulnerability affecting Active Storage image processing when used in conjunction with the libvips image processing library. The vulnerability has a CVSSv4 score of 9…RAPID7.COM
30 JulVU#281278: SGLang contains six different vulnerabilities including RCE, data exfiltration, and credential disclosureOverview Six vulnerabilities have been discovered within the SGLang project, including remote code execution (RCE), server-side request forgery (SSRF), local file read, credential leakage, and model weight exfiltration on a target server. Exploitation does not require authenticat…KB.CERT.ORG
29 JulA 13-year-old flaw is exposing tens of thousands of data center management systemsThe ‘no man’s land’ beneath the OS on enterprise servers is becoming the malicious actors’ next target. Attackers are gaining a foothold into broader data center environments by exploiting Baseboard Management Controllers (BMCs) that are largely unprotected, still running decades…CSOONLINE.COM
29 JulRansomware report: VPNs in the crosshairs, AI attacksRansomware attacks were up year over year in June for the fourth consecutive month, according to the NCC Group, though attacks increased just 3% in Q2 2026 versus the previous quarter. VPNs and other network edge devices continue to be prime initial access targets. And an autonom…CSOONLINE.COM
29 JulPublic PoC Released for Exploited Check Point SmartConsole Authentication BypassCybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild. The vulnerabi…THEHACKERNEWS.COM
29 JulNew Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell CommandsGitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account. Tracked as CVE-2026-6…THEHACKERNEWS.COM
29 JulContrast CVE Shield aims to protect applications while security teams deploy patchesContrast Security has announced Contrast CVE Shield, designed to help organisations defend against the growing number of exploits generated with advanced AI models such as Claude Mythos. Contrast CVE Shield runs inside the application, where it detects, monitors and blocks attemp…HELPNETSECURITY.COM
29 JulResearchers Show a Single Malicious Webpage Visit Can Compromise Tor BrowserNebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High…THEHACKERNEWS.COM
29 JulBroadcom Patches Critical VMware ESXi Vulnerability Enabling Host Code ExecutionBroadcom patched a critical VMware ESXi VM escape flaw (CVE-2026-47876) that could let attackers run code on the host from a compromised virtual machine. Broadcom has released patches to address five vulnerabilities affecting VMware ESXi, vCenter, Workstation, and Fusion, includi…SECURITYAFFAIRS.COM
29 JulRuflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI MemoryCybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10…THEHACKERNEWS.COM
29 JulThree Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM EscapeBroadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which ha…THEHACKERNEWS.COM
29 JulVU#305509: OPeNDAP Hyrax is vulnerable to SSRF and Credential DisclosureOverview A vulnerability has been discovered in the OPeNDAP Hyrax software solution. A remote attacker with the ability to submit crafted requests to an affected Hyrax instance could cause the application to communicate with unauthorized remote systems. Under certain conditions, …KB.CERT.ORG
29 JulCVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCityOverview On July 27, 2026, JetBrains published a security advisory for CVE-2026-63077 , a critical unauthenticated vulnerability affecting all versions of TeamCity On-Premises. The issue is classified as deserialization of untrusted data and has a CVSS score of 9.8 . An unauthent…RAPID7.COM
29 JulCritical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image UploadsRuby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process en…THEHACKERNEWS.COM
29 Jul KEVCisco warns of FMC static credential flaw exploited in zero-day attacksCisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. [...]BLEEPINGCOMPUTER.COM
28 JulAttackers Exploit Arista VeloCloud Orchestrator Command Injection FlawA maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave …THEHACKERNEWS.COM
28 JulCritical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging InJetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity …THEHACKERNEWS.COM
28 JulResearcher Says AI Helped Develop Linux Traffic-Control Race Into Root ExploitSTAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free race in the kernel's network traffic-control subsystem.Researcher Lee Ji…THEHACKERNEWS.COM
28 JulJetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)JetBrains has fixed a critical vulnerability (CVE-2026-63077) affecting TeamCity On-Premises and is urging admins to upgrade self-hosted servers as soon as possible. “For those who are unable to do so, we have released a security patch plugin,” noted Daniel Gallo, Sol…HELPNETSECURITY.COM
28 JulJetBrains Patches Critical TeamCity Flaw Allowing Server TakeoverJetBrains patched a critical TeamCity flaw (CVE-2026-63077) enabling unauthenticated code execution on affected on-premise servers. JetBrains has released security updates for TeamCity On-Premises after discovering a critical vulnerability, tracked as CVE-2026-63077 (CVSS score o…SECURITYAFFAIRS.COM
28 JulCritical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as RootOpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt's GitHub advisory, lets an unauth…THEHACKERNEWS.COM
28 JulVU#141367: AT&T's Arris BGW210-700 gateway contains authentication bypass vulnerability in LAN-side management interfaceOverview Firmware versions 2.7.7 and earlier of the Arris BGW210-700 residential gateway contain an authentication bypass vulnerability, tracked as CVE-2026-16771, that allows any unauthenticated LAN-side user to read sensitive configuration data and modify device settings throug…KB.CERT.ORG
28 JulCheck Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)Overview On July 22, 2026, Check Point published a security advisory for CVE-2026-16232 , an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server (MDS). By leveraging CVE-2026-16232, an unauthenti…RAPID7.COM
28 JulChromium: CVE-2026-13032 Use after free in WebGLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 JulChromium: CVE-2026-13028 Use after free in WebGLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 JulChromium: CVE-2026-13030 Uninitialized Use in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
28 JulChromium: CVE-2026-13037 Use after free in WebViewThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
27 JulCVE-2024-14040 net: nexthop: Increase weight to u16Information published.MSRC.MICROSOFT.COM
27 JulPoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)Security researchers who discovered and reported CVE-2026-54121 (aka “Certighost”), a critical privilege elevation vulnerability in Active Directory Certificate Services (AD CS), have released a proof-of-concept (PoC) exploit for and technical details related to the f…HELPNETSECURITY.COM
27 Juln8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Processn8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while probing n8n's February fix for CVE-2026-27577 for another …THEHACKERNEWS.COM
27 JulCVE-2026-50333 Windows Spaceport.sys Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
25 JulChromium: CVE-2026-16804 Use after free in InputThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
25 JulChromium: CVE-2026-16805 Use after free in BlinkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
25 JulChromium: CVE-2026-16806 Use after free in WebMCPThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
25 JulChromium: CVE-2026-16807 Out of bounds write in CodecsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
25 JulFastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched AvailableSecurity firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process. Tracked…THEHACKERNEWS.COM
24 Jul KEVRansomware groups are hammering your vulnerable VPNsCybercriminals are actively exploiting a recently discovered vulnerability in Palo Alto Networks firewall and VPN appliances to deploy the Qilin ransomware strain. A critical authentication bypass flaw ( CVE-2026-0257 ) in Palo Alto GlobalProtect portal and gateway was the common…CSOONLINE.COM
24 JulCVE-2026-59677 Process Kill Attack Vector in killall() in seunshareInformation published.MSRC.MICROSOFT.COM
24 JulBing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's ServersA crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's testing got the same result on workers across different hosts and network ranges, so …THEHACKERNEWS.COM
24 JulRussian hackers exploit unpatched Zimbra servers to steal emailsRussian state-backed hacker group Laundry Bear has been breaking into government and commercial networks for at least a year by exploiting a vulnerability in the Zimbra Collaboration Suite (ZCS) webmail platform. Laundry Bear (also known as Void Blizzard, CL-STA-1114, and TA488) …HELPNETSECURITY.COM
24 JulClop gang targets Windchill, FlexPLM in data theft attacksSergiu Gatlan reports: The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. Clop has reportedly been exploiting a critical improper input validation vulnerability tracked as CVE-2…DATABREACHES.NET
23 JulCheck Point Patches Exploited SmartConsole Flaw Allowing Full Admin AccessCheck Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild. The security flaw, tracked as CVE-2026-16232 (CV…THEHACKERNEWS.COM
23 JulCVE-2026-53910 Heap-based Buffer Overflow in GNU diffutilsInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-40691 Packet of death for DNSCrypt over TCPInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-55990 Packet of death for a DNSCrypt misconfigured UnboundInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-50045 'max-global-quota' reset by DNSSEC validation restartsInformation published.MSRC.MICROSOFT.COM
23 JulNine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL InstallsRefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access. Qualys said default installations of Red Hat Enterprise Linux and its derivatives…THEHACKERNEWS.COM
23 Jul KEVNew Check Point Zero-Day Vulnerability Exploited in the WildThe vulnerability tracked as CVE-2026-16232 has been exploited against customers with certain configurations. The post New Check Point Zero-Day Vulnerability Exploited in the Wild appeared first on SecurityWeek .SECURITYWEEK.COM
23 Jul KEVCheck Point patches actively exploited SmartConsole authentication bypass flawCheck Point addressed a critical authentication bypass flaw, tracked as CVE-2026-16232, in SmartConsole that is being actively exploited. Check Point has released security updates to fix multiple vulnerabilities, including CVE-2026-16232 (CVSS score of 9.3), a critical authentica…SECURITYAFFAIRS.COM
23 JulAttackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)Attackers are exploiting a critical authentication bypass vulnerability (CVE-2026-16232) that affects Check Point Security Management and Multi-Domain Security Management, the management servers that push policy to Check Point security gateways (i.e., firewalls). “An unauth…HELPNETSECURITY.COM
23 JulNew RefluXFS Linux flaw lets attackers gain root privilegesA nine-year-old race condition vulnerability in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges. [...]BLEEPINGCOMPUTER.COM
23 JulLinux XFS has a decade-old race condition allowing full root accessLinux systems using the XFS filesystem suffer from a race condition that could enable an unprivileged local user to gain full root access. The flaw affects systems with Linux kernel 4.11 or later that have enabled the XFS feature reflink, which permits the creation of copies of a…CSOONLINE.COM
23 JulVU#492466: Logto Identity Platform has authentication and authorization failures in core protocol handlingOverview The Logto platform contains multiple vulnerabilities affecting the identity‑processing pipeline. These flaws reduce the reliability of authentication and authorization decisions and may allow attackers to bypass account‑ownership checks, skip MFA, replay externally issue…KB.CERT.ORG
23 Jul KEVCheck Point hole grants unauthenticated attackers full SmartConsole admin privilegesCheck Point has confirmed that a critical security hole in its SmartConsole management tool, one that allows unauthenticated attackers to assume full admin privileges, is now being exploited in the wild. The vulnerability, CVE-2026-16232 , was given a CVSS score of 9.3. In its se…CSOONLINE.COM
22 JulWordPress Feeding Frenzy, Another Healthcare Supply Chain Breach, Qillin Targets Palo Alto BugWP2Shell WordPress RCE feeding frenzy, AI agent breaches Hugging Face, Killin hits Palo Alto VPN flaw This episode covers five major incidents: a chained WordPress exploit dubbed WP2Shell (CVE-2026-6330 and CVE-2026-6137) enabling anonymous remote code execution on stock installs…CYBERSECURITYTODAY.LIBSYN.COM
22 JulCVE-2026-42533 NGINX Map directive and Regex matching vulnerabilityInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-56434 NGINX ngx_http_ssi_module vulnerabilityInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-39879 SQL injection in syslog-ng SQL destionation driverInformation published.MSRC.MICROSOFT.COM
22 JulFourth SharePoint Vulnerability Exploited in Past Month’s Wave of AttacksCVE-2026-50522 is being exploited by threat actors to steal machine keys and retain long-term access. The post Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulAnother SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)Attackers are exploiting a critical SharePoint remote code execution (RCE) vulnerability (CVE-2026-50522) to extract the servers’ IIS machine keys. “WatchTowr is observing active exploitation of CVE-2026-50522 against on-premise Microsoft SharePoint deployments follow…HELPNETSECURITY.COM
22 JulHackers Exploit Windmill Flaw to Read Arbitrary Server Files Without AuthenticationA high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill's "get_log…THEHACKERNEWS.COM
22 JulCVE-2026-50441 Windows Resilient File System (ReFS) Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
22 JulCVE-2026-50458 Microsoft Brokering File System Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
22 JulVU#360868: Analog Way Picturall Quad Compact Mark II contains a local privilege escalation vulnerabilityOverview Version 3.5.8 of Analog Way's Picturall Quad Compact Mark II server contains a local privilege escalation vulnerability, tracked as CVE-2026-14985, due to improper privilege delegation and insufficient input validation in a maintenance script. Description The Picturall Q…KB.CERT.ORG
22 JulWhat’s New in Rapid7 Products and Services: Q2 2026 in ReviewIf Q1 set the pace for Rapid7's tools, Q2 accelerated it. This quarter brought a steady stream of product enhancements, platform investments, and customer-driven innovation across Rapid7’s portfolio. Each release was designed with a clear goal in mind: helping security teams redu…RAPID7.COM
22 JulAdobe fixes Chrome extension flaw that could expose WhatsApp chatsA chain of vulnerabilities in the Adobe Acrobat Chrome extension could have allowed attackers to steal content from a victim's WhatsApp Web session simply by luring them to a malicious website. Adobe fixed the flaws within days of the report and assigned the issue CVE-2026-48294.…CYBERINSIDER.COM
22 JulVU#847406: Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission assignment vulnerabilityOverview Duplicati v2.3.0.1 is vulnerable to arbitrary code execution when installed outside the default C:\Program Files\Duplicati 2\ directory. An attacker with local user privileges who can write files to the Duplicati installation directory can execute arbitrary code by placi…KB.CERT.ORG
22 JulUbuntu snap-confine Flaw Could Give Local Users Root on Default Desktop InstallsCybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment. The high-severity flaw, tracked as CVE-2026-8933…THEHACKERNEWS.COM
22 JulOracle’s July update fixes ten 10.0 vulnerabilities in Fusion MiddlewareOracle’s July 2026 Critical Patch Update, its largest ever, contains 1,449 new security patches spanning 32 product families, from Oracle Database and E-Business Suite to PeopleSoft, GoldenGate, Java SE, and Fusion Middleware. Fusion Middleware was particularly hard hit, with new…CSOONLINE.COM
22 JulCritical Zimbra security update fixes 9 vulnerabilitiesBusiness email and collaboration suite Zimbra has received a major security update that fixes several critical issues that could allow attackers to execute malicious code on the server or in users’ browsers. Available in commercial and open-source editions, Zimbra Collaboration S…CSOONLINE.COM
22 JulAdobe Acrobat Chrome extension bug enabled silent WhatsApp data theftAdobe patched CVE-2026-48294, a flaw in Adobe Acrobat Chrome extension that could let attackers steal WhatsApp Web chats by luring users to a webpage. Guardio Labs researcher Shaked Biner disclosed HermeticReader, a vulnerability chain in the Adobe Acrobat Chrome extension that a…SECURITYAFFAIRS.COM
22 JulCVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protectionsQualys disclosed CVE-2026-8933, a high-severity Ubuntu flaw that lets local attackers gain root privileges through a race condition in snap-confine. Qualys has disclosed a high-severity local privilege escalation vulnerability, tracked as CVE-2026-8933 (CVSS score of 7.8), affect…SECURITYAFFAIRS.COM
21 Jul KEVWhite hat hacker Park Chan-am zeros in on the AI era’s key security challengesDubbed the “Genius Hacker,” Park Chan-am began his white hat hacker journey at the precocious age of 11, winning awards at domestic and international hacking competitions since his teenage years. He has since served as a cybersecurity advisor for various Korean government agencie…CSOONLINE.COM
21 JulAttackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875Attackers are exploiting critical ServiceNow flaw CVE-2026-6875, allowing unauthenticated remote code execution on self-hosted instances. Searchlight Cyber researchers disclosed a critical pre-authentication remote code execution vulnerability, tracked as CVE-2026-6875, in the Se…SECURITYAFFAIRS.COM
21 JulCritical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code ExecutionThreat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said it's observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbo…THEHACKERNEWS.COM
21 JulCVE-2026-63940 KVM: SEV: Ignore Port I/O requests of length '0'Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64077 netfilter: ebtables: move to two-stage removal schemeInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63879 drm/amdgpu: fix amdgpu_hmm_range_get_pagesInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63882 drm/amdkfd: fix NULL pointer bug in svm_range_set_attrInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64017 blk-mq: pop cached request if it is usableInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64146 erofs: fix metabuf leak in inode xattr initializationInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64038 hwmon: (lm90) Stop work before releasing hwmon deviceInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64001 ALSA: pcm: oss: Fix setup list UAF on proc write errorInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64015 security/keys: fix missed RCU read section on lookupInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63954 hpfs: fix a crash if hpfs_map_dnode_bitmap failsInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64111 lsm: hold cred_guard_mutex for lsm_set_self_attr()Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64112 rbd: eliminate a race in lock_dwork draining on unmapInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64076 netfilter: bridge: eb_tables: close module init raceInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-42770 FFC-DH Peer Validation Uses Attacker-Supplied qInformation published.MSRC.MICROSOFT.COM
21 JulWordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass ScanningAttackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have be…THEHACKERNEWS.COM
21 JulExploitation of ServiceNow Vulnerability Seen Days After DisclosureThe ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution. The post Exploitation of ServiceNow Vulnerability Seen Days After Disclosure appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulSonicWall SMA zero-days were exploited weeks before disclosureTwo recently disclosed SonicWall SMA 1000 vulnerabilities – CVE-2026-15409 and CVE-2026-15410 – were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances, Volexity researchers revealed. The intrusions b…HELPNETSECURITY.COM
21 JulQilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial AccessThreat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with…THEHACKERNEWS.COM
21 JulCritical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoCA third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Of…THEHACKERNEWS.COM
21 JulCVE-2026-58640 Windows NTFS Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 JulCVE-2026-50462 Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 JulVU#762226: Plane contains multi-tenant authorization bypass vulnerabilityOverview The project management tool Plane, versions 1.3.0 and earlier, contains a multi-tenant authorization bypass vulnerability in its asset-management API that allows unauthorized users to access, delete, or duplicate assets that belong to other workspaces. Description Plane …KB.CERT.ORG
21 JulCritical wp2shell WordPress flaws exploited to install webshellsHackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers. [...]BLEEPINGCOMPUTER.COM
21 JulQilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN AccessQilin ransomware exploits the PAN-OS GlobalProtect flaw CVE-2026-0257 to gain unauthorized VPN access to unpatched networks. Arctic Wolf researchers warn that the Qilin ransomware gang is exploiting the critical PAN-OS GlobalProtect vulnerability CVE-2026-0257 to compromise corpo…SECURITYAFFAIRS.COM
21 JulCritical SharePoint RCE flaw exploited to steal machine keysHackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. [...]BLEEPINGCOMPUTER.COM
21 Jul KEVPublic PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522Critical SharePoint RCE vulnerability CVE-2026-50522 is under active exploitation after the release of a PoC exploit code. A critical Microsoft SharePoint vulnerability, tracked as CVE-2026-50522 (CVSS score of 9.8), is being actively exploited following the release of a public p…SECURITYAFFAIRS.COM
20 JulCritical NGINX Vulnerability Can Crash Workers and May Allow Remote Code ExecutionF5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in NGINX Plus 37.…THEHACKERNEWS.COM
20 Jul KEVWP2Shell WordPress Vulnerabilities Exploited in the WildExploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure. The post WP2Shell WordPress Vulnerabilities Exploited in the Wild appeared first on SecurityWeek .SECURITYWEEK.COM
20 JulCVE-2026-53392 NFSv4/flexfiles: reject zero filehandle version countInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53374 drm/amdgpu: zero-initialize GART table on allocationInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53376 drm/amdkfd: Add upper bound check for num_of_nodesInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63826 fbdev: fix use-after-free in store_modes()Information published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53375 drm/amdgpu/vce: Prevent partial address patchesInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63809 bpf: use kvfree() for replaced sysctl write bufferInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63822 wifi: ath11k: fix warning when unbindingInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53397 nfsd: fix posix_acl leak on SETACL decode failureInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63796 ocfs2: reject oversized group bitmap descriptorsInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53381 virtiofs: fix UAF on submount umountInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63805 crypto: nx - fix nx_crypto_ctx_exit argumentInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53401 fbdev: omap2: fix use-after-free in omapfb_mmapInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63793 ntfs: serialize volume label accessesInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53377 drm/msm: always recover the gpuInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53400 i2c: core: fix adapter registration raceInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53399 nfsd: release layout stid on setlease failureInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63818 f2fs: validate orphan inode entry countInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63832 wifi: mt76: add wcid publish check in mt76_sta_addInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63830 net: skmsg: preserve sg.copy across SG transformsInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63824 KEYS: fix overflow in keyctl_pkey_params_get_2()Information published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63800 pNFS: Fix use-after-free in pnfs_update_layout()Information published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63797 rpmsg: char: Fix use-after-free on probe error pathInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63817 f2fs: validate compress cache inode only when enabledInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63804 gfs2: fix use-after-free in gfs2_qd_deallocInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63802 blk-cgroup: fix UAF in __blkcg_rstat_flush()Information published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53390 ksmbd: fix out-of-bounds read in smb_check_perm_dacl()Information published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63814 f2fs: validate ACL entry sizes in f2fs_acl_from_disk()Information published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53398 NFSD: Fix SECINFO_NO_NAME decode error cleanupInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63827 apparmor: fix use-after-free in rawdata dedup loopInformation published.MSRC.MICROSOFT.COM
20 JulNew 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During ExtractionOpening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro's Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June …THEHACKERNEWS.COM
20 JulCritical ServiceNow code execution flaw now exploited in attacksAttackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. [...]BLEEPINGCOMPUTER.COM
20 JulCVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server TakeoversF5 fixes critical nginx flaw CVE-2026-42533 that can crash servers and, in some cases, allow remote code execution through crafted HTTP requests. F5 released patches for a critical nginx vulnerability, tracked as CVE-2026-42533 (CVSS score of 9.2), that can allow an unauthenticat…SECURITYAFFAIRS.COM
20 JulFrom a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery LabExecutive summary An MDR alert recently led our team to an exposed server that was doing more than hosting payloads. It was functioning as a fully operational malware delivery lab. Containing over 1,000 artifacts, the infrastructure served as a QA hub where attackers systematical…RAPID7.COM
20 JulSonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before PatchThe zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533. The post SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch appeared first on SecurityWeek .SECURITYWEEK.COM
20 Jul KEVServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About the vulnerability ServiceNow AI is a Platform-as-a-Service that lets organizations build and automate dig…HELPNETSECURITY.COM
20 JulCVE-2026-50650 .NET Framework Elevation of Privilege VulnerabilityUpdated product information in the Software Update table. This is an informational change only.MSRC.MICROSOFT.COM
20 JulExploitation in the Wild of wp2shellWiz Research has identified exploitation of "wp2shell", a critical pre-auth RCE vulnerability chain impacting WordPress Core (CVE-2026-63030 & CVE-2026-60137). Attackers are deploying persistent webshells on vulnerable servers. Organizations should prioritize patching or applying…WIZ.IO
20 JulWordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)Last week, Searchlight Cyber released details about a vulnerability they are calling "wp2shell". The vulnerability was initially announced without a CVE number. But now has been assigned CVE-2026-63030. Many WordPress plugin vulnerabilities are never assigned CVE numbers. But wp2…ISC.SANS.EDU
20 JulCVE-2024-44000 (LiteSpeed Cache Account Takeover) Ranks in June’s Top ThreatsSensor Intel Series: July 2026 CVE TrendsF5.COM
20 Jul KEVServiceNow’s sandbox escape RCE hole now exploited in the wildA sandbox security hole that could lead to remote code execution (RCE), patched last week by ServiceNow, is being actively exploited in the wild, according to a report from threat intel firm Defused . The report, posted on X, said the firm is “observing in-the-wild exploitation o…CSOONLINE.COM
20 Jul'WP2Shell' Opens Millions of WordPress Sites to Remote TakeoverBarely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.DARKREADING.COM
19 JulAttackers Can Take Over WordPress Sites Using Newly Released wp2shell ExploitsPublic exploits are now available for two critical WordPress flaws that attackers can chain to gain remote code execution without authentication. Public proof-of-concept exploits are now available for the critical wp2shell vulnerabilities affecting WordPress Core. The flaws, trac…SECURITYAFFAIRS.COM
18 JulCVE-2026-47729 Squid: Memory disclosure in FTP gatewayInformation published.MSRC.MICROSOFT.COM
18 JulTwo new high severity WordPress vulnerabilities, patch immediately!The 7.0.2 WordPress security release addresses one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: CVE-2026-60137 – A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo CVE-2026-60…HELPNETSECURITY.COM
17 JulCVE-2026-53366 ipv4: account for fraggap on the paged allocation pathInformation published.MSRC.MICROSOFT.COM
17 Jul KEVCVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the WildOverview On July 14, 2026, Microsoft published a security advisory addressing CVE-2026-58644 , a critical remote code execution (RCE) vulnerability affecting on-premises Microsoft SharePoint Server deployments. The vulnerability, which carries a CVSS v3.1 score of 9.8 (Critical),…RAPID7.COM
17 JulChromium: CVE-2026-15904 Use after free in OzoneThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
17 JulChromium: CVE-2026-15903 Out of bounds read and write in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
17 JulChromium: CVE-2026-15899 Use after free in CameraCaptureThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
17 JulChromium: CVE-2026-15900 Use after free in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
17 JulChromium: CVE-2026-15901 Use after free in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
17 JulChromium: CVE-2026-15902 Use after free in CastThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
17 JulChromium: CVE-2026-15905 Use after free in AuraThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
17 JulCVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress CoreOverview On July 17, 2026, a GitHub Security Advisory was published for CVE-2026-63030 , a critical unauthenticated remote code execution vulnerability affecting WordPress Core . WordPress Core. While the official GitHub security advisory classifies the severity as Critical, the …RAPID7.COM
16 JulZoom Patches Critical Windows Flaw That Could Enable Account TakeoverZoom has released security updates for a critical security flaw impacting Zoom Workplace for Windows that could facilitate account takeover. The vulnerability, tracked as CVE-2026-53412 (CVSS score: 9.8), affects Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Z…THEHACKERNEWS.COM
16 JulZoom Fixes CVE-2026-53412, a Critical Account Takeover BugZoom warns of a critical Windows flaw, tracked as CVE-2026-53412, that could let attackers take over accounts without authentication. Zoom has fixed a critical Windows vulnerability, tracked as CVE-2026-53412 (CVSS score of 9.8) that could allow unauthenticated attackers to hijac…SECURITYAFFAIRS.COM
16 JulAge of Empires II patch fixes RCE bug exploitable through multiplayer lobbiesA recent update for Age of Empires II: Definitive Edition fixed a remote code execution (RCE) vulnerability that could have allowed attackers to compromise other players' systems through multiplayer. The flaw, tracked as CVE-2026-50663, stemmed from a relative path traversal bug …CYBERINSIDER.COM
16 JulVU#326070: SGLang contains a vulnerable pickle deserialization vulnerability through the expert-parallel subsystemOverview A Pickle deserialization vulnerability has been discovered within the SGLang project , enabling an attacker to perform remote code execution (RCE) on the target vulnerable server. In order for an attacker to exploit this vulnerability, the expert-parallel backup subsyste…KB.CERT.ORG
15 Jul KEVPatch Tuesday roundup: Microsoft fixes a monthly record 569 holes; SAP patches a critical memory corruption bugEarlier this month Microsoft warned that, because the latest AI models can now help discover vulnerabilities, CSOs will see a higher volume of security updates every month. It wasn’t kidding. Today the company issued a record number of patches , with 59 rated as critical. And Mic…CSOONLINE.COM
15 JulSonicWall Issues Urgent SMA Patch Warning for Two Zero-Day ExploitsSonicWall SMA1000 zero-day vulnerabilities CVE-2026-15409 and CVE-2026-15410 can be exploited for remote code execution. The post SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits appeared first on SecurityWeek .SECURITYWEEK.COM
15 JulTwo SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin CommandsSonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution. The vulnerabilities are listed below - CVE-2026-15409 (CVSS score: 10.0…THEHACKERNEWS.COM
15 JulCVE-2026-39822 Root escape via symlink plus trailing slash in osInformation published.MSRC.MICROSOFT.COM
15 JulAI-driven bug hunting fuels record Microsoft Patch TuesdayMicrosoft has released patches for 570+ vulnerabilities on July 2026 Patch Tuesday, including two that are being leveraged by attackers (CVE-2026-56155 and CVE-2026-56164), and one that was previouly disclosed (CVE-2026-50661). The release was once again followed by Nightmare Ecl…HELPNETSECURITY.COM
15 JulFirefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security FlawsMozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published. The vulnerabilities are listed below - CVE-2026-15718, an invalid pointer in the JavaScript: WebAssembly component CVE-2026-15719, a site isolation in t…THEHACKERNEWS.COM
15 JulVU#725167: node-forge Signature Forgery Vulnerabilities in RSA-PKCS and ED25519 ImplementationsOverview Two distinct cryptographic signature verification vulnerabilities exist in Digital Bazaar node-forge, a widely used JavaScript library implementing cryptographic primitives for Node.js and browser environments. These vulnerabilities allow attackers to forge RSA (PKCS#1 v…KB.CERT.ORG
15 Jul KEVRapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)Overview On July 14, 2026, SonicWall published a security advisory addressing two vulnerabilities affecting SMA1000 Series remote access appliances, including the critical server-side request forgery (SSRF) vulnerability CVE-2026-15409 (CVSS 10.0) and the high-severity code injec…RAPID7.COM
15 Jul KEVCVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wildSonicWall patched two recently exploited zero-day vulnerabilities in its SMA 1000 Series secure remote access appliances which may have been chained for unauthenticated remote code execution. Key takeaways CVE-2026-15409 and CVE-2026-15410 are a pair of exploited vulnerabilities …TENABLE.COM
15 JulVU#529388: Privilege escalation vulnerability via unprotected IOCTL interface in Pegatron Tdelo64.sysOverview A privilege escalation vulnerability exists in the tdeio64.sys driver due to an unprotected input/output control (IOCTL) dispatch routine that fails to validate the origin and permissions of user-supplied requests. An unprivileged local attacker can abuse exposed IOCTL d…KB.CERT.ORG
14 JulGovernments to enterprises: Improve your router security hygieneGlobal security agencies say enterprises must clean up their act as Russian government-sponsored attackers exploit weaknesses in routers. According to a new multinational cybersecurity advisory , cyberattackers continue to exploit inadequately-protected and/or poorly-configured n…CSOONLINE.COM
14 JulCVE-2026-40468 Heap buffer overflow in gawkInformation published.MSRC.MICROSOFT.COM
14 JulCVE-2026-40553 Stack-based buffer overflow in gawkInformation published.MSRC.MICROSOFT.COM
14 JulCVE-2026-40469 Heap buffer overflow in gawkInformation published.MSRC.MICROSOFT.COM
14 JulCVE-2026-40467 Use after free in gawkInformation published.MSRC.MICROSOFT.COM
14 JulAI-powered breaches provide wake-up call for incident responseEnterprises have worked for years to improve detection and response times in the face of increasingly sophisticated attacks that relied on manual hacking and living-of-the-land techniques. AI is now threatening to undo those efforts. An increasing number of threat actors are auto…CSOONLINE.COM
14 JulCVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)Overview Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapi…RAPID7.COM
14 Jul KEVSonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410)SonicWall has fixed two actively exploited vulnerabilities (CVE-2026-15409, CVE-2026-15410) affecting its Secure Mobile Access (SMA) 1000 Series appliances, and is urging customer organizations to upgrade to a fixed firmare version and search for evidence of potential compromise.…HELPNETSECURITY.COM
14 Jul KEVMicrosoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)56 Critical 510 Important 3 Moderate 0 Low Microsoft addresses 569 CVEs in the largest Patch Tuesday release yet. This month’s release includes three zero-days, two of which were exploited in the wild. Microsoft patched 569 CVEs in its July 2026 Patch Tuesday release, with 56 rat…TENABLE.COM
14 JulSAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify DataSAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP. The vulnerability in question is CVE-2026-44747 (CVSS score: 9.9), an out-of-bounds write flaw that allows…THEHACKERNEWS.COM
14 Jul KEVMicrosoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilitiesMicrosoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products, including 57 that Microsoft marked as "critical". Microsoft notes that two of the vulnerabilities disclosed this month have been exploited…TALOSINTELLIGENCE.COM
14 JulSonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch nowSonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates. [...]BLEEPINGCOMPUTER.COM
13 Jul KEViCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-DaysThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation in the wild. The vu…THEHACKERNEWS.COM
13 JulRabbitMQ flaws expose OAuth secrets, risk complete takeover of the brokerRabbitMQ has patched two access control vulnerabilities affecting the widely used open-source message broker that could expose enterprise application data and, in some deployments, allow attackers to gain complete control over the messaging infrastructure. The flaws, discovered b…CSOONLINE.COM
12 JulCVE-2026-59873 node-tar: Decompression/parse DoS via unlimited inputInformation published.MSRC.MICROSOFT.COM
11 JulWeekly Metasploit Update: Exploits for FlowiseAI CSV Agent and MacOS Package KitMore AI, more software, more bugs! AI, it's all you hear about nowadays and everyone's got an opinion on it. Here at Metasploit, we care less about those opinions and more about the growing attack surface all this new software brings with it (yeehaw exploits!). Take for example t…RAPID7.COM
11 JulCVE-2026-59856 Vim: Arbitrary Code Execution via PHP Omni-CompletionInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-58251 NATS Server: Queue Subscribe Authz BypassInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-58253 NATS Server: Route API Auth BypassInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-14461 Out-of-bound read in mtrInformation published.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14428 Insufficient validation of untrusted input in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13777 Insufficient validation of untrusted input in iOSWebThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13778 Use after free in WebUSBThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14394 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14396 Out of bounds read in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14395 Out of bounds write in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14397 Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14398 Use after free in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14399 Uninitialized Use in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14400 Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14401 Insufficient validation of untrusted input in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14402 Uninitialized Use in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14403 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14405 Uninitialized Use in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14404 Inappropriate implementation in PDFiumThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14406 Out of bounds read in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14410 Inappropriate implementation in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14407 Inappropriate implementation in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14409 Inappropriate implementation in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14412 Insufficient validation of untrusted input in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14408 Uninitialized Use in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14411 Insufficient validation of untrusted input in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14413 Uninitialized Use in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14415 Inappropriate implementation in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14418 Uninitialized Use in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14417 Use after free in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14416 Out of bounds read in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14419 Use after free in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14420 Out of bounds read and write in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14421 Uninitialized Use in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14422 Out of bounds read and write in TintThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14423 Type Confusion in TintThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14425 Use after free in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14426 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14427 Heap buffer overflow in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14424 Use after free in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14429 Insufficient validation of untrusted input in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14430 Integer overflow in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14432 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14431 Type Confusion in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14414 Insufficient validation of untrusted input in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13785 Use after free in BluetoothThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13788 Use after free in FullscreenThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13791 Insufficient validation of untrusted input in DownloadsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13807 Use after free in ImportThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13795 Insufficient policy enforcement in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13792 Use after free in TouchbarThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13805 Use after free in GFXThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13808 Insufficient data validation in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13812 Insufficient validation of untrusted input in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13809 Side-channel information leakage in Safe BrowsingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13813 Insufficient validation of untrusted input in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13816 Insufficient validation of untrusted input in File InputThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13822 Inappropriate implementation in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13819 Out of bounds read in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13825 Uninitialized Use in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13826 Inappropriate implementation in AutofillThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13827 Use after free in UpdaterThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13842 Incorrect security UI in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13843 Insufficient validation of untrusted input in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13833 Uninitialized Use in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13846 Use after free in USBThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13847 Insufficient validation of untrusted input in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13850 Insufficient validation of untrusted input in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13851 Insufficient validation of untrusted input in WebAppInstallsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13856 Insufficient validation of untrusted input in SpeechThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13852 Insufficient validation of untrusted input in WebAppInstallsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulCVE-2026-13862CVE-2026-13862MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13863 Insufficient validation of untrusted input in CustomTabsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13866 Insufficient validation of untrusted input in InputThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13872 Insufficient validation of untrusted input in WebAppInstallsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13868 Inappropriate implementation in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13870 Use after free in WebViewThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13878 Use after free in BluetoothThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13885 Use after free in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13880 Use after free in USBThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13889 Insufficient validation of untrusted input in WebAuthenticationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13892 Inappropriate implementation in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13887 Insufficient policy enforcement in NFCThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13902 Inappropriate implementation in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13904 Incorrect security UI in Safe BrowsingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13905 Incorrect security UI in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13907 Inappropriate implementation in iOSWebThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13908 Insufficient validation of untrusted input in OmniboxThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13910 Insufficient policy enforcement in WebXRThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13912 Incorrect security UI in Safe BrowsingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13914 Inappropriate implementation in PasswordsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13913 Insufficient policy enforcement in AutofillThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13915 Use after free in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13916 Inappropriate implementation in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13917 Insufficient validation of untrusted input in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13918 Use after free in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13924 Insufficient validation of untrusted input in WebViewThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13923 Uninitialized Use in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13926 Insufficient validation of untrusted input in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13927 Insufficient validation of untrusted input in UIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13932 Inappropriate implementation in SharingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13929 Insufficient validation of untrusted input in DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13936 Inappropriate implementation in PasswordsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13939 Insufficient validation of untrusted input in WebShareThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13944 Inappropriate implementation in DataTransferThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13943 Uninitialized Use in CSSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13949 Insufficient policy enforcement in PaymentsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13946 Inappropriate implementation in ScriptInjectionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13955 Insufficient validation of untrusted input in CustomTabsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13964 Insufficient policy enforcement in WebViewThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13969 Uninitialized Use in UIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13974 Integer overflow in Safe BrowsingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13975 Out of bounds read in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13980 Incorrect security UI in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13994 Inappropriate implementation in Credential ManagementThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13983 Incorrect security UI in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13981 Inappropriate implementation in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13991 Insufficient validation of untrusted input in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13992 Inappropriate implementation in UIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13987 Incorrect security UI in MobileThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13997 Incorrect security UI in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13998 Incorrect security UI in File InputThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14028 Incorrect security UI in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13995 Insufficient validation of untrusted input in AutofillThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14005 Use after free in OmniboxThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14066 Insufficient validation of untrusted input in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14067 Use after free in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14075 Policy bypass in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14099 Use after free in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14096 Object lifecycle issue in InputThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14101 Insufficient policy enforcement in SandboxThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14114 Inappropriate implementation in WebAppInstallsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14126 Incorrect security UI in UIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14123 Incorrect security UI in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14128 Insufficient data validation in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14382 Insufficient validation of untrusted input in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14136 Incorrect security UI in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14137 Insufficient validation of untrusted input in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14386 Out of bounds read in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14385 Heap buffer overflow in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14388 Out of bounds read in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14390 Use after free in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14393 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14391 Integer overflow in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14392 Out of bounds write in TintThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
10 JulCVE-2026-56288 NULL Pointer Dereference in GNU patchInformation published.MSRC.MICROSOFT.COM
10 JulCVE-2026-56289 Loop with Unreachable Exit Condition in GNU patchInformation published.MSRC.MICROSOFT.COM
10 JulThe business case for burning down security debt: A practical approach for CISOsSecurity leaders have made strong progress in visibility. Most organizations can now identify vulnerabilities across their applications, dependencies and development pipelines with far more consistency than in the past. Yet a fundamental imbalance remains: Vulnerabilities are bei…CSOONLINE.COM
10 Jul“GhostLock” flaw survived in the Linux kernel code for 15 yearsA Linux kernel vulnerability remained hidden in virtually every major Linux distribution for more than 15 years before being fixed earlier this year. The flaw, tracked as CVE-2026-43499 and dubbed GhostLock, can be exploited by an unprivileged local attacker to gain root privileg…CYBERINSIDER.COM
10 JulVU#564823: GNU Wget enables SSRF via unvalidated FTP PASV IPsOverview GNU Wget, versions 1.25.0 and earlier, contains a server-side request forgery (SSRF) vulnerability in its implementation of FTP passive mode. Because Wget does not properly validate IP addresses obtained from PASV responses, an attacker-controlled FTP endpoint can redire…KB.CERT.ORG
9 JulUnpatched Backdoor in Tenda Firmware Grants Admin Access to DevicesTracked as CVE-2026-11405, the vulnerability allows unauthenticated attackers to access a device's web management interface. The post Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulCVE-2026-9547 SSH improper host validationInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-11856 cross-origin Digest auth state leakInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-8925 SASL double-freeInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-56002 libXfont2 PCF Font Parsing Heap Buffer OverflowInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-53336 nvmem: layouts: onie-tlv: fix hang on unknown typesInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-53327 debugobjects: Do not fill_pool() if pi_blocked_onInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-9079 stale proxy password leakInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-8927 env-set cross-proxy Digest auth state leakInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-12064 proto-default skips SSH verificationInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-53167 fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate foliosInformation published.MSRC.MICROSOFT.COM
9 JulMicrosoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM PrivilegesMicrosoft has released security updates for a Defender vulnerability known as RoguePlanet, nearly a month after details of the flaw became public. The vulnerability, tracked as CVE-2026-50656 (CVSS score: 7.8), is a privilege escalation issue in the Microsoft Malware Protection E…THEHACKERNEWS.COM
9 JulMicrosoft Patches Defender ‘RoguePlanet’ VulnerabilityThe privilege escalation vulnerability tracked as CVE-2026-50656 has been patched with a Microsoft Malware Protection Engine update. The post Microsoft Patches Defender ‘RoguePlanet’ Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulMicrosoft fixed Defender flaw RoguePlanet (CVE-2026-50656)Microsoft fixed RoguePlanet (CVE-2026-50656), a Defender flaw allowing local attackers to gain higher privileges through the Malware Protection Engine. Microsoft released security updates for RoguePlanet, a vulnerability tracked as CVE-2026-50656 (CVSS score of 7.8) affecting the…SECURITYAFFAIRS.COM
9 JulVU#734812: Xerte Online Toolkit contains an authentication bypass that allows for RCEOverview Two vulnerabilities have been discovered in Xerte Online Toolkits, an open-source e-learning authoring toolsuite intended for the creation of learning materials within a web browser. CVE-2026-14261 tracks the persistence of the /setup/ directory after installation, which…KB.CERT.ORG
9 JulMicrosoft releases fix for RoguePlanet Defender flaw (CVE-2026-50656)Microsoft has finally released a security update for its Microsoft Malware Protection Engine, which fixes CVE-2026-50656, the Windows Defender local privilege escalation vulnerability triggered by the RoguePlanet exploit. The vulnerability and the fix CVE-2026-50656 is due to imp…HELPNETSECURITY.COM
9 JulVU#152953: PayRange Android app version 7.0.7 contains multiple vulnerabilitiesOverview PayRange is a mobile payment app that allows users to pay for vending machines, laundromats, and other unattended machines using a smartphone with Bluetooth. Two vulnerabilities were discovered in version 7.0.7 of the PayRange app that is available in the Google Play sto…KB.CERT.ORG
8 JulScattered Spider squashed, Rogue Agent AI flaw, 16 year-old Linux bug and new phish hunts marketersCybersecurity Today host David Shipley covers how a newly unsealed U.S. complaint tied an alleged Scattered Spider member to a luxury retailer intrusion using a persistent Windows device ID, with prosecutors alleging help-desk social engineering, admin account takeover, data exfi…CYBERSECURITYTODAY.LIBSYN.COM
8 Jul15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux DistrosResearchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a machine that has not been patched. The vulnerable code has shipped by default in essentially ever…THEHACKERNEWS.COM
8 JulUbiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OSUbiquiti has shipped updates to address multiple critical security flaws impacting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS that could result in privilege escalation and arbitrary command execution. The list of vulnerabilities is as follows - CVE-2026-…THEHACKERNEWS.COM
8 JulVU#849433: Adalo Database API Enables Cross-App User Data Extraction via Over-Fetching and Missing Authorization ControlsOverview Adalo’s no‑code application platform exposes complete user records through its database API for all applications built on both V1 and V2. Due to a platform-level flaw, authenticated users can retrieve full user data belonging to any Adalo application, regardless of confi…KB.CERT.ORG
8 JulUbiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege EscalationUbiquiti patched seven UniFi OS flaws, including critical CVE-2026-50746, which allows command injection in UniFi Connect Application. Ubiquiti released security updates for seven critical UniFi OS vulnerabilities, including a maximum-severity flaw, tracked as CVE-2026-50746 (CVS…SECURITYAFFAIRS.COM
7 JulInsignary Closes SBOM Accuracy Gap With Binary-Level Clarity for Regulatory RiskMost software composition analysis tools read what developers declare. Insignary Clarity’s patented binary-first platform analyzes what is actually built, shipped, and deployed — including the open-source components that never appear in any manifest. Insignary, Inc. , whose paten…CSOONLINE.COM
7 JulBeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRABeyondTrust has released updates to address two critical security flaws affecting Remote Support (RS) and Privileged Remote Access (PRA) products that, if successfully exploited, could allow unauthenticated attackers to take control of susceptible devices. The vulnerabilities are…THEHACKERNEWS.COM
7 JulCERT/CC Warns of Hidden Admin Backdoor in Tenda Router FirmwareSeveral versions of firmware released by Chinese network device manufacturer Tenda have been found to embed an undocumented authentication backdoor that enables administrative access to the devices' web management interfaces, the CERT Coordination Center (CERT/CC) warned Monday. …THEHACKERNEWS.COM
7 JulCVE-2026-9545 exposing HTTP/3 early dataInformation published.MSRC.MICROSOFT.COM
7 JulCVE-2026-8932 incomplete mTLS config matching in conn reuseInformation published.MSRC.MICROSOFT.COM
7 JulCVE-2026-8458 wrong reuse for different servicesInformation published.MSRC.MICROSOFT.COM
7 JulCVE-2026-8924 trailing dot domain super cookieInformation published.MSRC.MICROSOFT.COM
7 JulCVE-2026-10536 HTTP/2 stream-dependency tree UAFInformation published.MSRC.MICROSOFT.COM
7 JulCVE-2026-8286 wrong STARTTLS connection reuseInformation published.MSRC.MICROSOFT.COM
7 JulCVE-2026-8926 password leak with netrc and user in URLInformation published.MSRC.MICROSOFT.COM
7 JulCVE-2026-9080 UAF after pause in socket callbackInformation published.MSRC.MICROSOFT.COM
7 JulSuspected China-Aligned Hackers Exploit Roundcube Flaws Against UniversitiesA suspected China-aligned threat activity cluster has been observed exploiting Roundcube webmail software belonging to physics and engineering departments of U.S. and Canadian universities as part of a new campaign. The activity involves the exploitation of now-patched, critical …THEHACKERNEWS.COM
7 JulHP DeskJet 2800 printer zero-day flaw leaks Wi-Fi credentialsHP DeskJet 2800 series printers are affected by a newly disclosed vulnerability that allows anyone on the same network to access sensitive configuration data without authentication. The flaw, tracked as CVE-2026-13753, affects devices running firmware version TBP1CN2612AR or earl…CYBERINSIDER.COM
7 JulHidden Tenda Router Backdoor Grants Admin Access, No Patch AvailableCERT/CC warns an unpatched backdoor in several Tenda routers lets attackers bypass login and gain full admin access with a hidden password. CERT/CC published an alert documenting an undocumented authentication backdoor in multiple Tenda firmware versions, tracked as CVE-2026-1140…SECURITYAFFAIRS.COM
7 JulCritical Adobe ColdFusion Vulnerability Exploited in AttacksHackers are exploiting a recently patched critical vulnerability (CVE-2026-48282) in Adobe ColdFusion that carries a CVSS score of 10/10. The post Critical Adobe ColdFusion Vulnerability Exploited in Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
7 Jul KEVAttackers exploit critical Adobe ColdFusion vulnerability (CVE-2026-48282)CVE-2026-48282, one of the maximum severity vulnerabilities patched in Adobe ColdFusion on June 30, 2026, has been targeted by attackers in the wild. Exploitation attempts were detected on July 2, through the honeypot sensors of cybersecurity threat-intelligence service KEVIntel,…HELPNETSECURITY.COM
7 JulPicus Autonomous Exposure Validation Platform validates real-world CVE exploitabilityPicus Security has launched the Picus Autonomous Exposure Validation Platform, built for a world where frontier AI has collapsed the time between disclosure and attack. Adversaries now weaponize new CVEs in hours, against a backdrop of around 132 published every day. A CVE drops;…HELPNETSECURITY.COM
7 JulCVE-2026-45638 Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
7 JulCritical Gitea Flaw Under Active Exploitation, Researchers WarnAttackers are exploiting the critical Gitea vulnerability CVE-2026-20896 to bypass authentication with a single HTTP header and access vulnerable repositories and secrets. The post Critical Gitea Flaw Under Active Exploitation, Researchers Warn appeared first on SecurityWeek .SECURITYWEEK.COM
7 Jul16-year-old KVM flaw allows attackers to escape VMs and take over Linux serversA critical vulnerability in the Kernel-based Virtual Machine (KVM) module of the Linux kernel allows attackers with root access in a guest VM to execute arbitrary code on the host system. This violates the most important security boundary that cloud providers and enterprises rely…CSOONLINE.COM
7 JulCritical Gitea Docker Bug Under Active Exploitation Exposes Repositories and SecretsAttackers are exploiting a critical Gitea flaw (CVE-2026-20896) that bypasses authentication with a single HTTP header, exposing repositories and sensitive data. Sysdig researchers warn that attackers are actively exploiting a critical authentication bypass flaw, tracked as CVE-2…SECURITYAFFAIRS.COM
6 JulAI-Run Ransomware, New Oracle Critical Flaw, NetNut bustedAI-Run Ransomware, New Oracle 9.8 Flaw Exploited, NetNut Proxy Network Busted, and Pegasus Hits EU Spyware Investigator This episode covers researchers' report of "Jade Puffer," the first ransomware attack run end-to-end by an autonomous AI agent, which exploited a patched Langfl…CYBERSECURITYTODAY.LIBSYN.COM
6 JulBad Epoll Flaw Gives Attackers Root Access on Linux and AndroidBad Epoll (CVE-2026-46242) lets local attackers gain root on Linux and Android. The flaw was missed by AI but found by a security researcher. A newly disclosed Linux kernel vulnerability, named Bad Epoll (CVE-2026-46242), allows a local attacker with no special privileg…SECURITYAFFAIRS.COM
6 JulThis AI agent autonomously hacked a network, adapted on the fly, and demanded a ransomA fully autonomous AI agent conducted an end-to-end cyber intrusion and extortion campaign after exploiting a vulnerable Langflow server, demonstrating how large language models could accelerate ransomware operations, according to research published by Sysdig. Sysdig detailed the…CSOONLINE.COM
6 JulMax severity Adobe ColdFusion flaw now exploited in attacksAttackers are now exploiting a maximum-severity Adobe ColdFusion vulnerability tracked as CVE-2026-48282, the Canadian Center for Cyber Security (CCCS) warned on Thursday. [...]BLEEPINGCOMPUTER.COM
6 JulThreat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After DisclosureThreat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig. The vulnerability in question is CVE-2026-20896 (CVSS score: 9.8), a vulnerability that stems from the DevOps platform trusting the "X-WEB…THEHACKERNEWS.COM
6 JulVU#828543: HP Deskjet 2800 Printer Series Webservers contain Missing Authorization VulnerabilityOverview HP Printers in the Deskjet 2800 Series running firmware version <=TBP1CN2612AR contain a missing authorization vulnerability tracked as CVE-2026-13753. This vulnerability allows unauthenticated access to the printer's webserver API endpoints, exposing Wi-Fi credential…KB.CERT.ORG
6 Jul16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 SystemsA use-after-free bug in Linux's KVM hypervisor can be triggered from a guest virtual machine to corrupt the shadow-page state of the host kernel that runs it. Dubbed 'Januscape' and tracked as CVE-2026-53359, the flaw sits in the shadow MMU code that KVM shares across both I…THEHACKERNEWS.COM
6 JulVU#213560: Tenda firmware (multiple versions) contains hidden authentication backdoorOverview Several versions of Tenda firmware contain an undocumented authentication backdoor that grants administrative access to the devices' web management interfaces. An attacker can expoit this vulnerability, tracked as CVE-2026-11405, to bypass the password verification proce…KB.CERT.ORG
6 Jul KEVAdobe ColdFusion flaw CVE-2026-48282 now exploited in the wildAttackers are exploiting the critical Adobe ColdFusion flaw CVE-2026-48282, which allows remote code execution on unpatched servers. Attackers have started exploiting CVE-2026-48282, a maximum-severity vulnerability in Adobe ColdFusion. The flaw is a path traversal issue that cou…SECURITYAFFAIRS.COM
4 JulNew "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits AndroidA newly disclosed Linux kernel flaw called Bad Epoll (CVE-2026-46242) lets an ordinary user with no special access take full control of a machine as root. It affects Linux desktops, servers, and Android, and a fix is out. Bad Epoll sits in the same small stretch of kernel code wh…THEHACKERNEWS.COM
4 JulCVE-2026-53223 net: guard timestamp cmsgs to real error queue skbsInformation published.MSRC.MICROSOFT.COM
3 JulRansomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain CredentialsThreat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access. "Although tactics differ between affiliates, common patterns emerged in tradecraft through use of legitimate Remo…THEHACKERNEWS.COM
3 JulCVE-2026-53049 gfs2: add some missing log lockingInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-53045 memory: tegra124-emc: Fix dll_change checkInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-53039 ocfs2: validate group add input before cachingInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-52992 fs/adfs: validate nzones in adfs_validate_bblk()Information published.MSRC.MICROSOFT.COM
3 JulCVE-2026-53016 crypto: ccp - copy IV using skcipher ivsizeInformation published.MSRC.MICROSOFT.COM
3 Jul KEVNew CitrixBleed-like NetScaler flaw sees exploit attempts in the wildCitrix NetScaler appliances have been a constant target for attackers in recent years, most recently through an information leak vulnerability dubbed CitrixBleed 3, the latest in a series of NetScaler memory overreads going back to 2023. This week, Citrix patched yet another Citr…CSOONLINE.COM
3 JulAI helps find flaws in FatFs library used in millions of devicesResearchers at runZero have disclosed seven security vulnerabilities in the widely used FatFs filesystem library, warning that the flaws could expose millions of embedded devices to attacks through malicious USB drives, SD cards, and, in some cases, firmware update mechanisms. Th…CYBERINSIDER.COM
2 JulSandbox bypass flaws in Cursor IDE highlight prompt injection as an RCE vectorResearchers have discovered two vulnerabilities in the widely used Cursor AI-enabled integrated development environment (IDE) that can be exploited through prompt injection to achieve remote code execution (RCE). The two flaws, tracked as CVE-2026-50548 and CVE-2026-50549 , allow…CSOONLINE.COM
2 Jul KEVCISA Warns of Actively Exploited Microsoft SharePoint VulnerabilityCISA says threat actors are exploiting a recently patched SharePoint remote code execution vulnerability (CVE-2026-45659). The post CISA Warns of Actively Exploited Microsoft SharePoint Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
2 JulVU#639124: Multiple local privilege escalation vulnerabilities in Little Orbits GameFirst Anti-CheatOverview The GamersFirst Anti-Cheat (GFAC) driver GFAC.sys contains multiple local privilege escalations and denial-of-service vulnerabilities stemming from insecure handling of user-controlled input through a minifilter communication port. A local attacker can abuse these flaws …KB.CERT.ORG
1 JulCitrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-ServiceCitrix on Tuesday released security updates to address multiple flaws in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) that could be exploited by an attacker to facilitate arbitrary file reads or trigger a denial-of-service (DoS) condition. T…THEHACKERNEWS.COM
1 JulCVE-2026-6450 CRL critical extension bypass in ParseCRL_ExtensionsInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-6331 HMAC zero-length tag forgery in EVP_DigestVerifyFinalInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-10592 Wildcard DNS SAN bypasses CA name-constraint checksInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-7531 Use-after-free in PQC hybrid key-share handlingInformation published.MSRC.MICROSOFT.COM
1 JulCISA Warns BlueHammer Flaw Is Now Exploited in Ransomware AttacksCISA confirms BlueHammer (CVE-2026-33825) is now used in ransomware attacks to gain SYSTEM privileges through Microsoft Defender. BlueHammer, tracked as CVE-2026-33825, has moved from proof-of-concept noise to real ransomware attacks in the wild, the US CISA confirms. BlueHammer …SECURITYAFFAIRS.COM
1 JulProgress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation AttemptsA recently disclosed critical security flaw impacting Progress Kemp LoadMaster is seeing active exploitation attempts, according to an advisory from eSentire's Threat Response Unit (TRU). The Canadian cybersecurity company said it identified exploitation attempts targeting CVE-20…THEHACKERNEWS.COM
1 JulCritical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run CommandsTwo flaws in Cursor, an AI code editor, could let a single, ordinary-looking prompt break out of the editor's safety sandbox and run any command on a developer's computer. There is no click to fall for and no approval box to ignore. Cato AI Labs found the pair and named them…THEHACKERNEWS.COM
1 Jul KEVOracle E-Business Suite Flaw Under Active Attack, 950 Systems ExposedOracle E-Business Suite flaw CVE-2026-46817 is under active attack, with about 950 vulnerable internet-facing instances still exposed. This week, Defused Cyber researchers warned that a critical vulnerability in Oracle E-Business Suite, tracked as CVE-2026-46817, is being activel…SECURITYAFFAIRS.COM
30 Jun KEVOracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the WildA critical security flaw impacting Oracle E-Business Suite has come under active exploitation in the wild, according to Defused Cyber. The vulnerability, tracked as CVE-2026-46817 (CVSS score: 9.8), refers to an improper privilege management and authentication flaw in Oracle Paym…THEHACKERNEWS.COM
30 JunApple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit BugsApple on Monday released security updates for iOS, macOS, and the Safari web browser to address over three dozen flaws, including four vulnerabilities in WebKit that were discovered using artificial intelligence (AI) tools like Anthropic Claude and OpenAI Codex Security. The WebK…THEHACKERNEWS.COM
30 JunCVE-2026-41991 Predictable Temporary File in GNU gzipInformation published.MSRC.MICROSOFT.COM
30 JunCVE-2026-41992 Global Buffer Overflow in GNU gzipInformation published.MSRC.MICROSOFT.COM
30 JunCVE-2026-11979 Stack-Based Buffer Overflow in libxml2Information published.MSRC.MICROSOFT.COM
30 JunProgress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-AuthA critical vulnerability in Progress Kemp LoadMaster can let an unauthenticated attacker execute arbitrary commands as root on the appliance by sending a crafted request to its API. The flaw, tracked as CVE-2026-8037, carries a CVSS score of 9.8 according to ZDI. A patc…THEHACKERNEWS.COM
30 Jun KEVAttackers actively exploit the Oracle E-Business Suite flaw CVE-2026-46817Attackers are exploiting a critical flaw in Oracle E-Business Suite, CVE-2026-46817, that allows remote, unauthenticated attackers to take over Oracle Payments. A critical vulnerability in Oracle E-Business Suite, tracked as CVE-2026-46817, is being actively exploited in the wild…SECURITYAFFAIRS.COM
30 JunSimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558)Attackers are exploiting CVE-2026-48558, a recently patched authentication bypass vulnerability in SimpleHelp RMM, to drop the novel Djinn Stealer malware on victim computers. The malware is capable of targeting Windows, macOS, and Linux systems, and “collects credentials a…HELPNETSECURITY.COM
30 JunAttackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn StealerAn unknown threat actor has been observed exploiting a recently disclosed maximum-severity security flaw in SimpleHelp to deliver two previously unreported malware families, TaskWeaver and Djinn Stealer. The intrusion involves the exploitation of CVE-2026-48558 (CVSS score: 10.0)…THEHACKERNEWS.COM
30 Jun KEVBlueHammer Vulnerability Exploited in Ransomware AttacksThe Microsoft Defender vulnerability CVE-2026-33825 was exploited in the wild as a zero-day before patches were released. The post BlueHammer Vulnerability Exploited in Ransomware Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunOracle E-Business Suite Payments flaw under attack (CVE-2026-46817)Exploitation attempts targeting a critical vulnerability (CVE-2026-46817) in Oracle Payments, the payment-processing module within Oracle’s E-Business Suite (EBS), have been spotted over the weekend, threat intelligence company Defused warned on Monday. The detected exploit…HELPNETSECURITY.COM
30 JunCVE-2026-42910 Windows Hotpatch Monitoring Service Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
30 JunLangflow RCE Exploited to Deploy Monero Miner on Exposed AI App EndpointsThreat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner. The activity has been found to weaponize CVE-2026-33017 (CVSS score: 9.3), an unauthenticated remote code execution (RCE) vulnerab…THEHACKERNEWS.COM
30 JunCitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)Well, well, well - once again, the cat has dragged us in and spat us out. Today, we find ourselves questioning the reality we sit within. Must it be so predictable, and why us? “But watchTowr, what do you mean?” Well, if you’re here, you likely fitLABS.WATCHTOWR.COM
30 Jun KEVCitrix patches a new NetScaler flaw with echoes of CitrixBleedThe bulletin includes six NetScaler issues, but attention is centered on a high-severity flaw with similarities to earlier actively exploited bugs. The post Citrix patches a new NetScaler flaw with echoes of CitrixBleed appeared first on CyberScoop .CYBERSCOOP.COM
29 JunPublic PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH FlawA public proof-of-concept is now out for CVE-2026-55200, a critical flaw in libssh2 that lets a malicious or compromised SSH server trigger memory corruption on a connecting client, with possible code execution. No credentials, no user interaction. The bug affects every release u…THEHACKERNEWS.COM
29 JunCVE-2026-52910 bpf: Free reuseport cBPF prog after RCU grace period.Information published.MSRC.MICROSOFT.COM
29 JunCVE-2026-52909 ip6_vti: set netns_immutable on the fallback device.Information published.MSRC.MICROSOFT.COM
29 JunHackers now exploit critical Oracle E-Business flaw in attacksAttackers have begun exploiting a critical vulnerability (CVE-2026-46817) in the Oracle E-Business Suite (EBS) financial application, according to threat intelligence company Defused. [...]BLEEPINGCOMPUTER.COM
29 JunCritical SimpleHelp flaw exploited to deploy new stealer malwareHackers are exploiting a recently disclosed critical vulnerability (CVE-2026-48558) in SimpleHelp to deploy Djinn Stealer, a previously undocumented cross-platform information stealer targeting Windows, macOS, and Linux. [...]BLEEPINGCOMPUTER.COM
29 JunEnterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037)Welcome back to another watchTowr Labs blog post. This time, we're looking at Progress Kemp LoadMaster, a load balancer that sits at the edge of a lot of enterprise networks. Edge appliances have a habit of becoming the way in rather than the thing keeping people out, andLABS.WATCHTOWR.COM
29 Jun'Djinn' Stealer Targets Cloud, AI CredentialsThe infostealer was delivered via CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp, targeting credentials linking development and admin environments to wider enterprise systems.DARKREADING.COM
28 JunCVE-2026-46245 drm/amd/display: Fix dc_link NULL handling in HPD initInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-46244 netfilter: nft_inner: Fix IPv6 inner_thoff desyncInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52953 iommu/vt-d: Fix oops due to out of scope accessInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53005 af_unix: Drop all SCM attributes for SOCKMAP.Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52912 netfilter: nf_queue: hold bridge skb->dev while queuedInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53213 drm/vc4: fix krealloc() memory leakInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52931 batman-adv: tp_meter: avoid use of uninit sender varsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52915 netfilter: ip6t_hbh: reject oversized option listsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53194 USB: serial: kl5kusb105: fix bulk-out buffer overflowInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53254 Bluetooth: RFCOMM: validate skb length in MCC handlersInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53120 PCI: use generic driver_override infrastructureInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52934 batman-adv: tvlv: reject oversized TVLV packetsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53267 netfilter: nft_ct: bail out on template ct in get evalInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53249 ipv4: restrict IPOPT_SSRR and IPOPT_LSRR optionsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53139 drm/v3d: Skip CSD when it has zeroed workgroupsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53177 bnxt_en: Fix NULL pointer dereferenceInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53214 ipv6: Fix a potential NPD in cleanup_prefix_route()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53107 wifi: libertas: don't kill URBs in interrupt contextInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53220 netfilter: revalidate bridge portsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53228 ipv6: sit: reload inner IPv6 header after GSO offloadsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53132 vsock/virtio: fix potential unbounded skb queueInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52937 tap: fix stack info leak in tap_ioctl() SIOCGIFHWADDRInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53106 bpf: Do not allow deleting local storage in NMIInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53217 net: mvpp2: sync RX data at the hardware packet offsetInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52926 batman-adv: clear current gateway during teardownInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53157 net: phonet: free phonet_device after RCU grace periodInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-57452 Vim: Out-of-bounds Read with libsodium-encrypted FilesInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-55693 Vim: Out-of-bounds Write in Spell File Word CountInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53253 Bluetooth: bnep: reject short frames before parsingInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53025 greybus: raw: fix use-after-free on cdev closeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53215 net: mvpp2: refill RX buffers before XDP or skb useInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-55892 Vim: Out-of-bounds Write in Spell File Prefix DumpInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-57454 Vim: Out-of-bounds Read with Text PropertiesInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-46243 smb: client: reject userspace cifs.spnego descriptionsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53227 net: openvswitch: fix possible kfree_skb of ERR_PTRInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52913 batman-adv: v: stop OGMv2 on disabled interfaceInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52921 netfilter: ipset: stop hash:* range iteration at endInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53270 ipvs: clear the svc scheduler ptr early on editInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-48142 NGINX ngx_http_charset_module vulnerabilityInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53236 tcp: restrict SO_ATTACH_FILTER to priv usersInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53118 vdpa: use generic driver_override infrastructureInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53266 netfilter: bridge: make ebt_snat ARP rewrite writableInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53138 drm/amd/display: Bound VBIOS record-chain walk loopsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53182 wifi: nl80211: reject oversized EMA RNR listsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-11972 tarfile opened in streaming mode mishandles EOFInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52924 sctp: purge outqueue on stale COOKIE-ECHO handlingInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53018 f2fs: avoid reading already updated pages during GCInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53184 udp: clear skb->dev before running a sockmap verdictInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52923 ipc: limit next_id allocation to the valid ID rangeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53192 ALSA: timer: Fix UAF at snd_timer_user_params()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52960 ceph: put folios not suitable for writebackInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53133 RDMA/umem: Fix truncation for block sizes >= 4GInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53009 ice: fix double-free of tx_buf skbInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53015 erofs: unify lcn as u64 for 32-bit platformsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52922 batman-adv: dat: handle forward allocation errorInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53000 netfilter: nat: use kfree_rcu to release opsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53225 sctp: fix uninit-value in __sctp_rcv_asconf_lookup()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53258 wifi: fix leak if split 6 GHz scanning failsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53183 mptcp: allow subflow rcv wnd to shrinkInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53226 gpio: rockchip: fix generic IRQ chip leak on removeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53108 powerpc/64s: Fix unmap race with PMD migration entriesInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53091 net: pull headers in qdisc_pkt_len_segs_init()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53232 net: phy: clean the sfp upstream if phy probing failsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52962 ceph: fix a buffer leak in __ceph_setxattr()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53070 sctp: disable BH before calling udp_tunnel_xmit_skb()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53156 nvmem: core: fix use-after-free bugs in error pathsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-57451 Vim: Out-of-bounds Read in Text Property CountInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53296 mailbox: mailbox-test: free channels on probe errorInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53297 net: mana: Guard mana_remove against double invocationInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53293 drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REGInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53294 mailbox: mailbox-test: don't free the reused channelInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53295 mailbox: add sanity check for channel arrayInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53279 drm/gma500/oaktrail_lvds: fix hang on init failureInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-42123 drm/amdgpu: fix double free err_addr pointer warningsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-42155 s390/pkey: Wipe copies of protected- and secure-keysInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-42139 ice: Fix improper extts handlingInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-50225 btrfs: fix error propagation of split biosInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-53084 drm/imagination: Break an object reference loopInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-50090 drm/xe/oa: Fix overflow in oa batch bufferInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-27010 net/sched: Fix mirred deadlock on device recursionInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-27079 iommu/vt-d: Fix NULL domain on device releaseInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-53187 io_uring: check for overflows in io_pin_pagesInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-56544 udmabuf: change folios array from kmalloc to kvmallocInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-56702 bpf: Mark raw_tp arguments with PTR_MAYBE_NULLInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-49990 drm/xe/hdcp: Check GSC structure validityInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-47703 bpf, lsm: Add check for BPF LSM return valueInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-46681 pktgen: use cpus_read_lock() in pg_net_init()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2024-46701 libfs: fix infinite directory reads for offset dirInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-46775 drm/amd/display: Validate function returnsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-46705 drm/xe: reset mmio mappings with devmInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-46778 drm/amd/display: Check UnboundedRequestEnabled's valueInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2023-6606 Kernel: out-of-bounds read vulnerability in smbcalcsizeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2025-21833 iommu/vt-d: Avoid use of NULL after WARN_ON_ONCEInformation published.MSRC.MICROSOFT.COM
27 JunBypassing Windows authentication reflection mitigations for SYSTEM shells - Part ②In part 1 of this blogpost series, we proved our initial theory that the patch for CVE-2025-33073 was insufficient, by disclosing a trivial NTLM reflection vulnerability leading to LPE. In this second part, we turn to Kerberos and explain how we achieved a full-blown RCE primitiv…SYNACKTIV.COM
27 JunBypassing Windows authentication reflection mitigations for SYSTEM shells - Part 1A year ago, authentication reflection vulnerabilities resurfaced as a powerful attack vector through the discovery of CVE-2025-33073 by several security researchers, including us. This logical vulnerability allowed taking over almost any Windows machine without any user interacti…SYNACKTIV.COM
27 JunPaint it blue: Attacking the bluetooth stackBluetooth has always been an attractive target to attackers since it is present almost everywhere (TV, automotive charger, connected fridge, etc.). This is especially true on mobile devices, as it runs as a privileged process with a potential access to microphone, address book, e…SYNACKTIV.COM
27 JunSniffing Authentication References on macOSCVE-2017-7170 was a local priv-esc vulnerability that affected OSX/macOS for over a decade! Here (for the first time!), we dive into the technical details of finding the bug, the core flaw, and exploitation.OBJECTIVE-SEE.ORG
27 JunRootpipe Reborn (Part II)@CodeColorist continues writing about bugs, such as CVE-2019-8521 and CVE-2019-8565 that provide a mechanism to elevate privileges to root on macOS.OBJECTIVE-SEE.ORG
27 JunFrom the Top to the Bottom; Tracking down CVE-2017-7149High Sierra suffered from a nasty bug (CVE-2017-7149) that afforded local attackers access to the contents of encrypted APFS volumes.OBJECTIVE-SEE.ORG
27 JunCVE-2015-3673: Goodbye Rootpipe...(for now?)Details on bypassing Apple's original rootpipe patchOBJECTIVE-SEE.ORG
27 JunDirtyClone: Fourth Linux Kernel Flaw in Six Weeks Escalates to RootDirtyClone: a Linux kernel privilege escalation that silently rewrites executables in memory, leaving no disk trace. Patch now. JFrog Security Research published a working exploit walkthrough on June 25 for CVE-2026-43503 (CVSS score of 8.8), a Linux kernel privilege escalation t…SECURITYAFFAIRS.COM
26 JunSynology issues critical fix for MailPlus Server vulnerabilitiesSynology has has fixed critical vulnerabilities in MailPlus Server, a software package used to run private email infrastructure on Synology NAS devices. The security update fixes three flaws: CVE-2026-13136, stemming from faulty authorization checks, may allow remote attackers to…HELPNETSECURITY.COM
26 JunNew DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned PacketsDirtyClone is a new Linux kernel privilege escalation in the DirtyFrag family. JFrog Security Research published a working exploit walkthrough for the flaw on June 25, the first public demonstration for this variant. Tracked as CVE-2026-43503 (CVSS 8.8), it le…THEHACKERNEWS.COM
26 JunNew Linux pedit COW Exploit Enables Root Access by Poisoning Cached BinariesA flaw in the Linux kernel's traffic-control subsystem can let a local unprivileged user gain root on affected systems. CVE-2026-46331, nicknamed "pedit COW," is an out-of-bounds write in the packet-editing action (act_pedit) that corrupts shared page-cache memory. A public,…THEHACKERNEWS.COM
26 JunAmazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP ConfigsA high-severity flaw in Amazon Q Developer let a malicious repository run commands and steal a developer's cloud credentials. The path was short: a developer opens the repo, trusts the workspace, and Amazon Q does the rest. Amazon has patched it. Tracked as CVE-2026-12957&nb…THEHACKERNEWS.COM
26 JunChromium: CVE-2026-13027 Use after free in FileSystemThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13026 Use after free in Digital CredentialsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13025 Insufficient validation of untrusted input in DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13024 Insufficient validation of untrusted input in NavigationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13023 Uninitialized Use in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13022 Inappropriate implementation in AutofillThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13021 Inappropriate implementation in DeviceBoundSessionCredentialsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13036 Use after free in BlinkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13035 Use after free in BluetoothThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13034 Inappropriate implementation in PasswordsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13033 Out of bounds read in Blink>InterestGroupsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13031 Use after free in BlinkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13029 Use after free in Web AuthenticationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13038 Use after free in AutofillThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 Jun KEVHackers exploit critical PTC Windchill PLM software flawHackers are exploiting a critical vulnerability recently patched in PTC Windchill and FlexPLM, two product lifecycle management solutions used by organizations across a range of industries, including defense, aerospace, automotive, medical, electronics, industrial machinery, and …CSOONLINE.COM
25 JunCisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root AccessAn unknown threat actor exploited a recently disclosed high-severity security flaw impacting Cisco Catalyst SD-WAN as a zero-day at least two months before it was publicly disclosed, according to new findings from Google-owned Mandiant. The vulnerability, tracked as CVE-2026-2024…THEHACKERNEWS.COM
25 JunCVE-2026-45637 Microsoft DWM Core Library Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
25 JunCVE-2026-11816 Path Traversal in keras-team/kerasInformation published.MSRC.MICROSOFT.COM
25 JunWhy patch directives only go so farSix weeks of undetected access through a compromised VPN exposes why patching isn't a solution for the organizations already breached. The post Why patch directives only go so far appeared first on CyberScoop .CYBERSCOOP.COM
25 JunLantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat WarningThe exploited flaw, CVE-2025-67038, is one of the vulnerabilities disclosed in April as part of the BRIDGE:BREAK research project. The post Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning appeared first on SecurityWeek .SECURITYWEEK.COM
24 JunHole in widely-used FFmpeg codec could crash media servers or enable RCEA newly discovered critical vulnerability in the FFmpeg media processing framework bundled in a huge number of open source and commercial applications points, again, to the need for CSOs to have strategies to deal with software supply chain vulnerabilities, which should include d…CSOONLINE.COM
24 JunHackers Exploiting Cisco Unified CM VulnerabilityCisco noted that a PoC had been available for CVE-2026-20230 when it announced patches in early June. The post Hackers Exploiting Cisco Unified CM Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
24 JunCisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to RootThreat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME). The vulnerability, tracked as CVE-2026-20230 (CVSS score: 8.…THEHACKERNEWS.COM
24 Jun KEVCisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230)CVE-2026-20230, a server-side request forgery (SSRF) vulnerability affecting Cisco’s Unified Communications Manager (Unified CM), is being exploited to drop webshells and achieve remote code execution capability on the underlying server. “Our honeypots are seeing auto…HELPNETSECURITY.COM
24 Jun KEVHow much cyber risk does AI create for organizations? 457 million security issues. Here’s what you can do about it.Over a 30 day period, Tenable detected 457 million AI-related security issues among 7,000-plus organizations, an average of 62,000 exposures per organization. If we didn’t already know that shadow AI was a problem, data like this makes it clear every organization needs to visuali…TENABLE.COM
24 Jun KEVCISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively ExploitedThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation of a critical security flaw impacting Lantronix EDS5000 Series devices, urging Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 26, 2026. The vuln…THEHACKERNEWS.COM
24 JunMandiant reveals how Cisco SD-WAN zero-day attacks gained root accessNew details have been revealed on how hackers exploited a Cisco Catalyst SD-WAN vulnerability tracked as CVE-2026-20245 in zero-day attacks to create rogue root accounts on targeted devices. [...]BLEEPINGCOMPUTER.COM
23 JunCVE-2026-42915 Microsoft Windows VMSwitch Denial of Service VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
23 JunCisco Unified CM flaw CVE-2026-20230 now exploited in attacksA high-severity SSRF vulnerability, tracked as CVE-2026-20230, in Cisco Unified Communications Manager Server is now being exploited in attacks. [...]BLEEPINGCOMPUTER.COM
22 JunVU#226679: Microsoft WinRE allows for bypass of UEFI/BIOS password enforcementOverview Microsoft Windows Recovery Environment (WinRE) provides a mechanism for recovering and repairing Windows systems using an alternate boot environment. Under certain platform implementations, access to WinRE may allow an attacker to bypass firmware security controls, inclu…KB.CERT.ORG
22 JunFFmpeg ‘PixelSmash’ bug triggers code execution on media file openA critical vulnerability in FFmpeg, the widely used open-source multimedia framework, can be exploited through a specially crafted video file to achieve remote code execution (RCE). Tracked as CVE-2026-8461 and dubbed “PixelSmash,” the flaw affects FFmpeg's MagicYUV decoder. The …CYBERINSIDER.COM
22 JunVU#936962: Multiple file parsing vulnerabilities in FastStone Image Viewer 8.3.0.0Overview Two vulnerabilities have been identified in FastStone Image Viewer 8.3 that may allow remote code execution or control-flow corruption when processing specially crafted image files. The affected components include the JPEG 2000 (JP2) parser and the PSD file parser. An at…KB.CERT.ORG
20 JunHackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API KeysThreat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that's installed on about 100,000 sites. The vulnerability, tracked as CVE-2026-4020 (CVSS score: 5.3), is a medium-severity information disclosure flaw that can allow unauthe…THEHACKERNEWS.COM
19 JunApple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via MicrophoneApple has updated its Beats Studio Buds wireless earbuds to patch a high-severity vulnerability that could be exploited by nearby hackers to eavesdrop on users. The vulnerability, tracked as CVE-2025-20701 (CVSS score: 8.8), refers to a case of incorrect authorization impacting t…THEHACKERNEWS.COM
19 JunCVE-2026-45469 Microsoft Excel Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-45472 Microsoft Office Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Android. Customers running affected Microsoft Office for Android software should install the update for their product to be protected from this vulnerability.MSRC.MICROSOFT.COM
19 JunCVE-2026-45471 Microsoft Word Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-45474 Microsoft Office Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Android. Customers running affected Microsoft Office for Android software should install the update for their product to be protected from this vulnerability.MSRC.MICROSOFT.COM
19 JunCVE-2026-45486 Microsoft Word Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-45485 Microsoft Office Information Disclosure VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-44817 Microsoft Excel Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-44818 Microsoft Excel Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-44819 Microsoft Office Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-44820 Microsoft Excel Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-44821 Microsoft Office Information Disclosure VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-44823 Microsoft Excel Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-44824 Microsoft Office Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-45456 Microsoft Outlook and Word Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-45458 Microsoft Outlook and Word Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-45460 Microsoft Office Information Disclosure VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Android. Customers running affected Microsoft Office for Android software should install the update for their product to be protected from this vulnerability.MSRC.MICROSOFT.COM
19 JunCVE-2026-45461 Microsoft Office Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Android. Customers running affected Microsoft Office for Android software should install the update for their product to be protected from this vulnerability.MSRC.MICROSOFT.COM
19 JunCVE-2026-45466 Microsoft Word Information Disclosure VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-45643 Microsoft Word Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-45645 Microsoft Office Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-45649 Office for Android Spoofing VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Word, PowerPoint, Excel for Android. Customers running affected Microsoft Office for Android software should install the update for their product to be protected from this vulnerability.MSRC.MICROSOFT.COM
19 JunCVE-2026-44822 Microsoft Excel Information Disclosure VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-45455 Microsoft Excel Information Disclosure VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-45457 Microsoft Word Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-45459 Microsoft Excel Security Feature Bypass VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-45463 Microsoft Office Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Android. Customers running affected Microsoft Office for Android software should install the update for their product to be protected from this vulnerability.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12439 Use after free in Digital CredentialsCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12440 Use after free in DigitalCredentialsCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12445 Use after free in ExtensionsCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12446 Insufficient data validation in PasswordsCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12451 Use after free in DigitalCredentialsCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12441 Use after free in File InputCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12447 Heap buffer overflow in WebRTCCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12443 Use after free in Web AuthenticationCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12452 Use after free in DownloadsCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12453 Insufficient validation of untrusted input in InputCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12455 Use after free in Tab StripCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12456 Insufficient validation of untrusted input in ExtensionsCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12458 Incorrect security UI in PasswordsCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12457 Insufficient data validation in ExtensionsCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12459 Inappropriate implementation in SerialCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12460 Insufficient policy enforcement in File System AccessCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12462 Use after free in MediaCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12464 Use after free in BrowserCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12463 Inappropriate implementation in ViewsCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12465 Insufficient validation of untrusted input in MetricsCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12454 Race in Safe BrowsingCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12467 Use after free in ExtensionsCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12468 Inappropriate implementation in UpdaterCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12449 Use after free in ChromotingCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12444 Out of bounds read in ChromotingCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12437 Use after free in WebShareCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12461 Out of bounds read in WebRTCCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12466 Heap buffer overflow in WebRTCCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunCVE-2026-42903 Windows Kerberos Denial of Service VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
19 JunCVE-2026-44803 Windows Graphics Component Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Word, PowerPoint, Excel for Android. Customers running affected Microsoft Office for Android software should install the update for their product to be protected from this vulnerability.MSRC.MICROSOFT.COM
19 JunCVE-2026-44812 Windows Graphics Component Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Word, PowerPoint, Excel for Android. Customers running affected Microsoft Office for Android software should install the update for their product to be protected from this vulnerability.MSRC.MICROSOFT.COM
19 JunCVE-2026-53689Information published.MSRC.MICROSOFT.COM
19 JunM365 Copilot SearchLeak: Your prompt injection attack surface just got biggerA recent proof-of-concept attack against Microsoft’s M365 Copilot Enterprise highlights what could be a much broader prompt injection threat based on a common way many AI-enhanced web services operate. Dubbed SearchLeak, the attack hinged on a typical malicious objective: to leak…CSOONLINE.COM
19 Jun KEVOracle releases 245 new security patches, all rated ‘high-priority security’The Oracle Critical Security Patch update (CSPU) released this week contains 245 newly-announced fixes for supported on-premises software, some of which impact multiple products. It is in reaction to an industry trend to announce and fix security holes much more quickly , and com…CSOONLINE.COM
19 JunSplunk Enterprise Vulnerability Exploited in Attacks Days After DisclosureCISA has given federal agencies only three days to patch CVE-2026-20253, which can be exploited for unauthenticated remote code execution. The post Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure appeared first on SecurityWeek .SECURITYWEEK.COM
19 JunWeekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and moreThis week's release includes five new modules, including a full unauthenticated RCE chain for Paperclip AI and a VS Code extension persistence technique. On the post-exploitation side, the new windows/local/ntlm_relay_2_self module coerces the local machine account to authenticat…RAPID7.COM
18 Jun KEVOracle June 2026 Critical Security Patch Update Addresses 243 CVEs (CVE-2026-35273)Oracle addresses 243 CVEs in its June 2026 Critical Security Patch Update with 245 patches, including 122 critical updates. Key Takeaways The June 2026 Critical Security Patch Update (CSPU) contains fixes for 243 unique CVEs in 245 security updates 122 issues (49.8% of all patche…TENABLE.COM
18 JunF5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code ExecutionF5 has released security updates to address two critical security flaws in NGINX Open Source that could be exploited to achieve code execution on affected systems. The vulnerabilities are listed below - CVE-2026-42530 (CVSS v4 score: 9.2) - A use-after-free vulnerability in the n…THEHACKERNEWS.COM
17 JunScam Losses Surge - Cybersecurity TodayCybersecurity Today host David Shipley reports that the FTC says Americans lost $3.5 billion to imposter scams in 2025—nearly triple 2020—with social media tied to $2.1 billion in losses and total fraud reaching about $16 billion, while the FBI estimates cyber-enabled losses near…CYBERSECURITYTODAY.LIBSYN.COM
17 Jun KEVCISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code ExecutionThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting Widget Factory Joomla Content Editor (JCE) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability,…THEHACKERNEWS.COM
17 JunMicrosoft working on patch for RoguePlanet Defender zero-day (CVE-2026-50656)Microsoft has acknowledged the local elevation of privilege issue in Microsoft Defender that can be triggered via the “RoguePlanet” exploit, and is “working to provide a high quality security update that addresses this vulnerability.” The vulnerability, wh…HELPNETSECURITY.COM
17 JunCVE-2026-47636 Microsoft SharePoint Server Spoofing VulnerabilityAcknowledgement added. This is an informational change only.MSRC.MICROSOFT.COM
17 JunCVE-2026-45475 Microsoft Office Remote Code Execution VulnerabilityAcknowledgement added. This is an informational change only.MSRC.MICROSOFT.COM
17 JunCVE-2026-42828 Windows Projected File System Elevation of Privilege VulnerabilityAcknowledgement added. This is an informational change only.MSRC.MICROSOFT.COM
17 JunMicrosoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in DevelopmentMicrosoft has formally disclosed that it's working to release a patch to address a Defender zero-day codenamed RoguePlanet. The vulnerability has now been assigned the CVE identifier CVE-2026-50656 (CVSS score: 7.8), with the tech giant describing it as a privilege escalation fla…THEHACKERNEWS.COM
17 JunVU#380058: SignalRGB kernel driver contains improper access control and IOCTL vulnerabilitiesOverview The SignalRGB kernel driver, SignalIo.sys , contains two vulnerabilities involving improper access control and unsafe memory handling. The device object is created with an overly permissive Discretionary Access Control List (DACL) that allows user-mode processes to acces…KB.CERT.ORG
16 Jun KEVCisco Releases Security Updates for Actively Exploited SD-WAN Manager FlawCisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-20262, carries a CVSS score of 6.5 out of 10.0. "A vulnerability in the web UI of Cisco C…THEHACKERNEWS.COM
16 Jun KEVCISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege EscalationThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw impacting LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 18, 2026. The …THEHACKERNEWS.COM
16 JunCisco Patches Another SD-WAN Zero-Day Exploited in AttacksCisco recently became aware of the exploitation of CVE-2026-20262, a Catalyst SD-WAN Manager zero-day that allows arbitrary file write. The post Cisco Patches Another SD-WAN Zero-Day Exploited in Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
16 JunCisco patches SD-WAN flaw amid evidence of active exploitationCisco has released fixes for a vulnerability in its Catalyst SD-WAN Manager software after becoming aware of limited exploitation of the flaw, which could allow an authenticated attacker to create or overwrite files that may later be used to gain root privileges. The vulnerabilit…CSOONLINE.COM
16 JunAttackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last WeekBad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. In a post shared on X, the company said it has observed exploitation of CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 over the past 24 h…THEHACKERNEWS.COM
16 Jun KEVCISA warns of another cPanel plugin flaw exploited in attacksThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. government agencies three days to secure their servers against an actively exploited vulnerability (CVE-2026-54420) in the LiteSpeed cPanel user-end plugin. [...]BLEEPINGCOMPUTER.COM
16 JunCisco discloses second exploited SD-WAN vulnerability in two weeks (CVE-2026-20262)Cisco has revealed another Catalyst SD-WAN Manager vulnerability (CVE-2026-20262) that its Product Security Incident Response Team observed being exploited by attackers. But the associated security advisory also states that “the vulnerability was found during internal secur…HELPNETSECURITY.COM
16 JunSimpleHelp RMM flaw could give attackers full access to managed endpoints (CVE-2026-48558)A critical vulnerability (CVE-2026-48558) in SimpleHelp, a popular remote monitoring and management (RMM) tool, can be exploited remotely by unauthenticated attackers to create a new “Technician” account and use it to remote into managed endpoints, execute scripts, an…HELPNETSECURITY.COM
16 JunAttackers are exploiting FortiSandbox vulnerabilitiesAttackers have been spotted exploiting three vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) in FortiSandbox, a platform that other Fortinet security products depend on for threat verdicts to enforce blocking decisions and trigger automated responses. The warning…HELPNETSECURITY.COM
15 JunPalo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN FlawPalo Alto Networks has revealed that it has observed "active exploitation" of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to GlobalProtect portals. The vulnerability in question is CVE-2026-0257 (CVSS score: 7.8), an authenti…THEHACKERNEWS.COM
15 JunChromium: CVE-2026-12012 Use after free  NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-12008 Use after free  DigitalCredentialsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-12019 Out of bounds write  CodecsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-12016 Insufficient validation of untrusted input  DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-12015 Use after free  AutofillThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-12018 Inappropriate implementation  MojoThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-12007 Use after free  CoreThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-12017 Insufficient validation of untrusted input  ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-12014 Use after free  CastThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-12013 Use after free  MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-12010 Heap buffer overflow  GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-12009 Insufficient validation of untrusted input  AccessibilityThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-12011 Use after free  WebMIDIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.MSRC.MICROSOFT.COM
15 JunLangflow RCE under active attack months after a patch was shippedEnterprises using the open-source AI orchestration platform Langflow are being urged to patch a high-severity path traversal flaw amid active exploitation, despite a fix having been available for more than two months. The bug, which stems from improper handling of filenames in La…CSOONLINE.COM
15 JunCisco fixes SD-WAN vManage flaw exploited in zero-day attacksCisco has released security updates to address a vulnerability in the Catalyst SD-WAN Manager, tracked as CVE-2026-20262, that was exploited in attacks to escalate to root privileges. [...]BLEEPINGCOMPUTER.COM
15 JunAI vulnerability discovery is pushing 2026 CVEs toward 66,000Vulnerability disclosures are piling up faster in 2026 than anyone expected at the start of the year. The running count for the first few months sits well above the original projection, and the Forum of Incident Response and Security Teams (FIRST) now expects the year to land nea…HELPNETSECURITY.COM
15 JunChromium: CVE-2026-11628 Use after free in OzoneThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11629 Use after free in OzoneThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11631 Use after free in AuraThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11630 Use after free in File InputThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11632 Use after free in TabStripThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11633 Use after free in BluetoothThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11634 Use after free in GamepadThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11635 Use after free in BluetoothThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11639 Use after free in CompositingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11637 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11636 Use after free in AutofillThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11638 Use after free in PrintingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11641 Use after free in BluetoothThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11640 Integer overflow in libyuvThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11642 Use after free in Web AppsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11645 Out of bounds memory access in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11643 Use after free in ProxyThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11644 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11646 Use after free in ViewTransitionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11657 Use after free in PaymentsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11658 Insufficient validation of untrusted input in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11660 Insufficient validation of untrusted input in New Tab PageThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11661 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11659 Insufficient validation of untrusted input in UIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11663 Use after free in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11662 Type Confusion in BindingsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11664 Use after free in PaymentsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11665 Out of bounds read in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11666 Insufficient validation of untrusted input in InputThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11668 Uninitialized Use in CodecsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11669 Integer overflow in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11667 Out of bounds read in WebRTCThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11670 Use after free in PDFThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11671 Use after free in NavigationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11672 Out of bounds write in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11673 Use after free in InterestGroupsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11675 Insufficient validation of untrusted input in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11674 Use after free in Guest ViewThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11676 Insufficient validation of untrusted input in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11677 Race in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11678 Integer overflow in libyuvThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11679 Use after free in CodecsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11681 Use after free in OzoneThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11682 Insufficient validation of untrusted input in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11680 Use after free in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11683 Use after free in WebCodecsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11684 Insufficient policy enforcement in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11687 Use after free in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11686 Insufficient validation of untrusted input in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11688 Object lifecycle issue in SVGThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11685 Insufficient data validation in MediaCaptureThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11689 Insufficient validation of untrusted input in PasswordsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11690 Out of bounds read and write in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11691 Insufficient validation of untrusted input in New Tab PageThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11692 Use after free in Read AnythingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11693 Inappropriate implementation in PluginsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11694 Use after free in ServiceWorkerThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11695 Inappropriate implementation in PasswordsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11696 Uninitialized Use in VideoThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11697 Insufficient validation of untrusted input in UIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11698 Use after free in BluetoothThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11699 Use after free in BluetoothThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11700 Use after free in TracingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11647 Use after free in PrintingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11648 Use after free in FullScreenThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11651 Use after free in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11649 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11652 Use after free in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11650 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11653 Insufficient validation of untrusted input in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11654 Use after free in CameraCaptureThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11656 Use after free in ServiceWorkerThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11655 Integer overflow in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
13 JunCVE-2026-45445 AES-OCB IV Ignored on EVP_Cipher() PathInformation published.MSRC.MICROSOFT.COM
13 JunCVE-2026-45447 Heap Use-After-Free in the PKCS7_verify() FunctionInformation published.MSRC.MICROSOFT.COM
13 JunCVE-2026-52859 Vim: Out-of-bounds Read in Terminal Screen SnapshotInformation published.MSRC.MICROSOFT.COM
13 JunCVE-2026-9076 Out-of-Bounds Read in CMS Password-Based DecryptionInformation published.MSRC.MICROSOFT.COM
13 JunCVE-2026-34180 Heap Buffer Over-read in ASN.1 Content ParsingInformation published.MSRC.MICROSOFT.COM
13 JunCritical Splunk Enterprise Flaw Lets Attackers Run Code Without AuthenticationSplunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file operations and even remote code execution. The vulnerability, tracked as CVE-2026-20253, is rated 9.8 on the CVSS scoring system. …THEHACKERNEWS.COM
12 JunShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach UniversitiesThe ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities hardest. Google's Mandiant attributes it to the group it tracks as UNC6240, and date…THEHACKERNEWS.COM
12 JunGoogle Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHuntersOracle has mitigated CVE-2026-35273, but it has not publicly confirmed the vulnerability’s in-the-wild exploitation. The post Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters appeared first on SecurityWeek .SECURITYWEEK.COM
12 Jun KEVOracle PeopleSoft zero‑day fuels ShinyHunters extortion spreeA newly disclosed Oracle PeopleSoft zero-day became the weapon of choice in a recent ShinyHunters extortion campaign that primarily targeted universities and other educational institutes. Attackers exploited the critical remote code execution (RCE) flaw in PeopleSoft’s Environmen…CSOONLINE.COM
12 Jun KEVResearchers release details, PoC for exploited Check Point VPN flaw (CVE-2026-50751)WatchTowr researchers have disclosed a technical analysis and a “Detection Artefact Generator” for CVE-2026-50751, an authentication bypass flaw in Check Point’s Remote Access VPN and Mobile Access, which the vendor confirmed to be actively exploited. The attack…HELPNETSECURITY.COM
12 Jun KEVActive Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)Overview On June 10, 2026, Oracle published a security alert for CVE-2026-35273 , a critical vulnerability in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools. Oracle released an out-of-band patch the same day as the advisory, underscoring the urg…RAPID7.COM
12 JunGoogle warns of Oracle PeopleSoft attacks hitting universitiesGoogle's Mandiant and Google Threat Intelligence Group (GTIG) say the ShinyHunters extortion group exploited a critical Oracle PeopleSoft vulnerability as a zero-day to compromise education institutes. The activity, tracked as UNC6240, was observed between May 27 and June 9 and i…CYBERINSIDER.COM
11 JunMicrosoft Patches Exploited Exchange Server VulnerabilityThe company warned about zero-day attacks exploiting the Exchange Server vulnerability CVE-2026-42897 on May 14. The post Microsoft Patches Exploited Exchange Server Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
11 JunCVE-2026-42536 Apache HTTP Server: mod_xml2enc heap overflowInformation published.MSRC.MICROSOFT.COM
11 JunCVE-2026-46433 lldpd: Heap OOB Read in VLAN Decapsulation memmoveInformation published.MSRC.MICROSOFT.COM
11 JunCVE-2026-29170 Apache HTTP Server: mod_proxy_ftp XSSInformation published.MSRC.MICROSOFT.COM
11 JunCVE-2026-29167 Apache HTTP Server: mod_ldap per-dir use-after-freeInformation published.MSRC.MICROSOFT.COM
11 JunCVE-2026-34355 Apache HTTP Server: mod_proxy_html buffer overflowInformation published.MSRC.MICROSOFT.COM
11 JunChina-linked recon botnet outpaces enterprise defensesA botnet made up of compromised small office and Internet of Things devices has grown into a larger reconnaissance network capable of rapidly identifying vulnerable internet-facing systems after public vulnerability disclosures, researchers said. The botnet, tracked by Lumen’s Bl…CSOONLINE.COM
11 Jun KEVOracle PeopleSoft servers under attack, Oracle pushes out-of-band security alertA zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft PeopleTools is being exploited in the wild, Charles Carmakal, CTO at cybersecurity firm Mandiant, part of Google Cloud, warned today. The warning comes a day after Oracle published an out-of-band security alert about …HELPNETSECURITY.COM
11 JunOracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day AttacksOracle has released a patch for CVE-2026-35273, but it has not said whether it’s a zero-day exploited in ShinyHunters attacks. The post Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
11 JunVU#862559: crypton-x509-validation Haskell libraries do not enforce X.509 NameConstraintsOverview A vulnerability has been discovered in the Haskell TLS software stack, commonly used by applications built in the Haskell programming language to securely connect to servers over the internet. Specifically, the libraries "crypton-x509-validation" fail to enforce a key se…KB.CERT.ORG
11 Jun KEVOracle mitigates PeopleSoft zero-day exploited in data theft attacksOracle is warning about a critical PeopleSoft Suite zero-day vulnerability tracked as CVE-2026-35273 that allows unauthenticated remote code execution, with the flaw actively exploited in ShinyHunter data theft attacks. [...]BLEEPINGCOMPUTER.COM
10 Jun KEVAI Worms, Hacks, and Insurance ShiftsInstagram AI Support Hack Hits 20,225 Accounts; AI Worm 'Hades' Lies to Security Tools; Chrome Zero-Day Patch Host David Shipley reports Meta says 20,225 Instagram accounts were hijacked after an AI support tool was tricked into sending reset links to attacker-controlled emails, …CYBERSECURITYTODAY.LIBSYN.COM
10 JunCVE-2026-46285 mtd: docg3: fix use-after-free in docg3_release()Information published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46312 media: videobuf2: Set vma_flags in vb2_dma_sg_mmapInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46301 spi: topcliff-pch: fix use-after-free on unbindInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2025-71315 drm/vkms: Convert to DRM's vblank timerInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46296 spi: s3c64xx: fix NULL-deref on driver unbindInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46299 hfsplus: fix held lock freed on hfsplus_fill_super()Information published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46323 net: gro: don't merge zcopy skbsInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46320 tap: free page on error paths in tap_get_user_xdp()Information published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46307 wifi: ath5k: do not access array OOBInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46306 flow_dissector: do not dissect PPPoE PFC framesInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46322 tun: free page on build_skb failure in tun_xdp_one()Information published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46330 Revert "net/smc: Introduce TCP ULP support"Information published.MSRC.MICROSOFT.COM
10 Jun KEVMicrosoft feud escalates as researcher drops new Windows zero-dayThe long-running feud between Microsoft and security researcher Nightmare Eclipse has entered a new chapter. Eclipse, who has spent the past several months publicly releasing unpatched Windows vulnerabilities while sparring with Microsoft over vulnerability disclosure practices, …CSOONLINE.COM
10 Jun KEVCritical Ivanti Sentry flaw allows root-level remote code execution (CVE-2026-10520)Ivanti has patched two critical vulnerabilities (CVE-2026-10520 and CVE-2026-10523) in Ivanti Sentry and has urged customers to implement the fix right away. Though the vulnerabilities are not known to be actively exploited, security researchers have already released technical de…HELPNETSECURITY.COM
10 JunJune Patch Tuesday marks a ‘new normal’ with over 200 CVEs, 32 rated ‘critical’June’s Patch Tuesday security updates have arrived, with SAP fixing four critical vulnerabilities and Microsoft addressing over 200 CVEs. Microsoft’s to-do list includes fixes for three zero days, 32 patches rated as ‘critical’, and a batch of other high-risk vulnerabilities that…CSOONLINE.COM
10 JunIvanti, Fortinet, and SAP Release Patches for Multiple Critical VulnerabilitiesFortinet, Ivanti, and SAP have released security updates to address multiple critical security vulnerabilities that could result in arbitrary code execution and information disclosure. The security flaw patched by Fortinet relates to a command injection vulnerability in FortiSand…THEHACKERNEWS.COM
10 JunUnpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCEA high-severity unpatched security flaw in Langflow, an open-source low-code platform to build artificial intelligence (AI) applications, has come under active exploitation in the wild, according to findings from VulnCheck. The vulnerability in question is CVE-2026-5027 (CVSS sco…THEHACKERNEWS.COM
10 JunMicrosoft-signed UEFI bootloaders vulnerable to Secure Boot bypassMicrosoft has released security updates to address a Secure Boot bypass vulnerability affecting multiple Microsoft-signed UEFI shim bootloaders used by Linux distributions, recovery tools, and enterprise software. The flaw, tracked as CVE-2026-8863, could allow attackers to execu…CYBERINSIDER.COM
10 JunIvanti patches critical Sentry flaws that lead to full device takeoverIT software provider Ivanti fixed two vulnerabilities in Ivanti Sentry, a secure mobile gateway appliance formerly called MobileIron Sentry. The flaws could allow unauthenticated remote attackers to gain complete control of deployments. One of the vulnerabilities, CVE-2026-10523,…CSOONLINE.COM
10 JunPath traversal flaw in AI dev platform Langflow exploited in attacksAttackers are actively exploiting CVE-2026-5027, a high-severity path traversal vulnerability in the AI development platform Langflow, to write arbitrary files on exposed servers. [...]BLEEPINGCOMPUTER.COM
9 JunOne-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now PublicSecurity researchers have published a detailed, working exploit for a Linux kernel use-after-free that lets an unprivileged local user escalate to root and break out of a container. The flaw, CVE-2026-23111, sits in the kernel's nf_tables packet-filtering code and was patched ups…THEHACKERNEWS.COM
9 JunGoogle Patches 5th Chrome Zero-Day Exploited in 2026The vulnerability is tracked as CVE-2026-11645 and it was reported in late April by an anonymous researcher. The post Google Patches 5th Chrome Zero-Day Exploited in 2026 appeared first on SecurityWeek .SECURITYWEEK.COM
9 Jun KEVLiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCEThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity flaw impacting BerriAI LiteLLM to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-42271 (CVSS score: …THEHACKERNEWS.COM
9 JunCVE-2026-11463 USCiLab Cereal Shared Pointer type confusionInformation published.MSRC.MICROSOFT.COM
9 JunCVE-2026-49975 Apache HTTP Server: mod_http2 denial of serviceInformation published.MSRC.MICROSOFT.COM
9 Jun KEVGoogle Releases Patch for Chrome Vulnerability Exploited in the WildThe flaw, CVE-2026-11645, can allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML pageINFOSECURITY-MAGAZINE.COM
9 Jun KEVCheck Point warns of ransomware-linked attacks exploiting outdated VPN protocolCheck Point has issued emergency hotfixes for a pair of vulnerabilities affecting VPN deployments that still use the deprecated Internet Key Exchange version 1 (IKEv1) protocol, warning that one of the flaws is already being exploited in the wild. The more serious issue allows at…CSOONLINE.COM
9 Jun KEVGoogle patches Chrome zero-day exploited in the wild (CVE-2026-11645)Google has fixed 74 vulnerabilities in Chrome, including a high-severity zero-day (CVE-2026-11645) that has been exploited in the wild. “Google is aware that an exploit for CVE-2026-11645 exists in the wild,” the company said in a Monday security advisory. The fix has…HELPNETSECURITY.COM
9 JunWinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in UkraineTwo Russia-aligned cyber attack campaigns have continued to exploit a security flaw in WinRAR to target Ukrainian organisations, almost a year after patches for the vulnerability were released. The activity has been attributed by Trend Micro to Earth Dahu (aka Gamaredon) and SHAD…THEHACKERNEWS.COM
9 Jun KEVChrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch NowGoogle has released security updates to address 74 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-11645 (CVSS score: 8.8), has been described as an out-of-bounds memory access in V8, Chrome'…THEHACKERNEWS.COM
9 JunRussian Attackers Weaponize WinRAR Flaw Against Ukrainian OrgsTwo separate campaigns target CVE-2025-8088, fixed last July, to conduct data theft and cyberespionage against military and government targets in Ukraine.DARKREADING.COM
9 JunVeeam Backup & Replication RCE Flaw Lets Domain Users Run Remote CodeVeeam has released security patches to address a critical flaw in its Backup & Replication software that could result in remote code execution. Tracked as CVE-2026-44963, the vulnerability carries a CVSS score of 9.4 out of a maximum of 10.0. "A vulnerability allowing remote …THEHACKERNEWS.COM
9 JunVU#616257: Microsoft-signed UEFI shim bootloaders vulnerable to Secure Boot bypassOverview Microsoft-signed UEFI bootloaders of the open-source shim project, primarily from version 0.9 and earlier, were identified as vulnerable to Secure Boot bypass. To mitigate this risk, the affected bootloaders will be added to the Microsoft UEFI Forbidden Signature Databas…KB.CERT.ORG
8 Jun KEVCISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318)A vulnerability (CVE-2026-28318) that can be exploited to crash SolarWinds Serv-U file transfer servers is being leveraged by attackers in the wild, the US Cybersecurity and Infrastructure Security Agency (CISA) confirmed on Friday. The agency has ordered US federal civilian agen…HELPNETSECURITY.COM
8 JunGoogle Protocol Buffers flaw turns schemas into shellsA widely used JavaScript implementation of Google’s Protocol Buffers format is placing too much trust in untrusted data, exposing affected applications to remote code execution and other attacks. Researchers at Cyera have disclosed six vulnerabilities affecting “ protobuf.js ,” a…CSOONLINE.COM
8 JunQilin ransomware affiliate exploited Check Point VPN zero-day (CVE-2026-50751)A Qilin ransomware affiliate is believed to be exploiting CVE-2026-50751, an authentication bypass vulnerability in Check Point VPN Remote Access and Mobile Access, the company announced on Monday. About CVE-2026-50751 Check Point Remote Access VPN enables and secures connections…HELPNETSECURITY.COM
8 Jun KEVCritical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 SetupsCheck Point has warned of active exploitation of a critical vulnerability impacting Remote Access VPN and Mobile Access deployments that are configured to use the deprecated IKEv1 key exchange protocol. The vulnerability, tracked as CVE-2026-50751 (CVSS score: 9.3), is a case of …THEHACKERNEWS.COM
8 Jun KEVAttackers exploiting unpatched Cisco SD-WAN flawCisco warns customers of an actively exploited high-severity vulnerability in Catalyst SD-WAN Manager, an enterprise network management system that has been targeted by hackers multiple times in the past. Located in the command-line interface, the flaw allows authenticated attack…CSOONLINE.COM
6 Jun KEVCisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch AvailableCisco has warned that a high-severity security flaw impacting Catalyst SD-WAN Manager has come under active exploitation. The vulnerability, tracked as CVE-2026-20245, carries a CVSS score of 7.8 out of a maximum of 10.0. It affects the following deployment types - On-Prem Deploy…THEHACKERNEWS.COM
6 JunCritical Everest Forms Pro flaw exploited to take over WordPress sitesHackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro plugin, which lets them take complete control of a WordPress website. [...]BLEEPINGCOMPUTER.COM
5 JunHackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over SitesThreat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active installations, to execute arbitrary code, leading to a complete site compromise. The vulnerability in question is CVE-2026-3300 (CVSS score: 9.8), a rem…THEHACKERNEWS.COM
5 JunUS government report slams NIST for NVD backlogA report from the US Commerce department’s inspector general blames the National Institute of Standards and Technology (NIST) for the ever-growing backlog of vulnerabilities for inclusion in the National Vulnerability Database (NVD). But cybersecurity practitioners say that the b…CSOONLINE.COM
5 JunCisco warns of unpatched SD-WAN zero-day exploited in attacksOn Thursday, Cisco warned of a high-severity, unpatched zero-day in the Cisco Catalyst SD-WAN Manager (tracked as CVE-2026-20245) actively exploited in attacks enabling root privilege escalation. [...]BLEEPINGCOMPUTER.COM
5 JunCisco Warns of 7th SD-WAN Zero-Day Exploited in 2026The vulnerability is tracked as CVE-2026-20245 and it can allow arbitrary command execution as root, but no patch yet. The post Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026 appeared first on SecurityWeek .SECURITYWEEK.COM
5 JunCisco SD-WAN 0-day exploited, no patch available (CVE-2026-20245)A 0-day privilege escalation vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager that has yet to be patched by Cisco is being leveraged by attackers. “To exploit this vulnerability, an attacker must have netadmin privileges on an affected system. This would requ…HELPNETSECURITY.COM
5 JunClaude Code has an MCP security problem — and your developers are already using itClaude Code is Anthropic’s AI coding assistant — a command-line tool that developers are adopting fast. It connects to external services through Model Context Protocol, the standard that lets AI tools interact with Jira, Confluence, GitHub, databases and internal APIs. When a dev…CSOONLINE.COM
5 JunThreat Brief: Active Exploitation of PAN-OS CVE-2026-0257We include indicators of activity and mitigations for PAN-OS vulnerability CVE-2026-0257. The post Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
⚠️ VULNERABILITY DISCLOSURE 2358[−]
3 SepFlipping AI’s kill switch.This week, Dave and Ben look at two major AI stories. The first involves Anthropic winning one of its legal challenges regarding the Pentagon designating the company as a supply chain risk. The second story looks at a recent law introduced in Congress that seeks to give CISA the …THECYBERWIRE.COM
3 SepI just want to give you $25 million!This week, hosts of N2K CyberWire ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Maria Varmazis⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠…THECYBERWIRE.COM
3 SepSrsly Risky Biz: China's botnets are worth disruptingTom Uren and James Wilson talk about China’s long-term shift to getting private companies to build botnets for cyberespionage. A disruption effort from the US this week is good news, but China has been using these networks for a surprisingly long time and will rebuild. They also …RISKY.BIZ
2 SepOld, Unpatched Flaws Give Attackers Access to Philippines Nuclear AgencyThreat actors exploited commodity in ownCloud to gain initial access, resulting in stolen reactor databases, personnel records, and credential stores.DARKREADING.COM
2 SepAnthropic makes changes to stop AI agents running amok againLearning from the OpenAI-Hugging Face fiasco, as well as from recent revelations about its own model, Anthropic is revamping its security and alignment practices. The company has established controls that flag when a model attempts to break out of a sandbox or successfully access…CSOONLINE.COM
2 SepOpen-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and JiraSift is a free, open-source command line tool that searches for passwords, API keys, and other sensitive data across the places a company keeps its work: local disks, Windows file shares, an entire Active Directory domain, SharePoint, OneDrive, Teams channel files, Slack messages…HELPNETSECURITY.COM
2 Sep KEVSonicWall warns of actively exploited SMA1000 zero-day flawsSonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. [...]BLEEPINGCOMPUTER.COM
2 SepDuckDB stays open source while the team behind it goes to work for AmazonHannes Mühleisen and Mark Raasveldt started as AWS employees. The two built DuckDB, an analytical database that runs inside your process instead of on a server somebody has to administer. If you ship anything on top of DuckDB, your license does not change. Amazon did not buy the …HELPNETSECURITY.COM
2 SepAuthorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware PayloadsThe U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operation. The effort was undertaken on August 31, 2026, by authorities from the U.S., Bulgaria, Hungary, a…THEHACKERNEWS.COM
2 SepSality botnet infrastructure dismantled in joint global takedownInternational law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet. [...]BLEEPINGCOMPUTER.COM
2 SepHow China industrialized the infrastructure behind state hackingLast week, the US Justice Department and FBI announced court-authorized seizures of domains hard-coded into two complementary hacking platforms known as “QScan” and “QTRouter,” used by Chinese state-sponsored hackers to target US critical infrastructure and other sensitive networ…CSOONLINE.COM
2 Sep KEVHackers Chain Two New SonicWall Zero-Day VulnerabilitiesSonicWall has urged customers to patch two new zero-day vulnerabilities being exploited in the wildINFOSECURITY-MAGAZINE.COM
2 SepGlobal sinkhole operation ends Sality botnet’s 23-year runSality, a peer-to-peer (P2P) botnet that had been running for 23 years and infecting more than 15,000 machines worldwide, has been taken down in a joint operation by international law enforcement agencies, working with CrowdStrike and the Shadowserver Foundation. The operation cu…HELPNETSECURITY.COM
2 SepKeepnet launches free SMS/Call Reporter for iOSKeepnet, an Extended Human Risk Management (xHRM) and Secure Behavior Management platform, today launched the Keepnet SMS/Call Reporter. It is a free app that turns a suspicious SMS or phone call into a one-tap report. Anyone can download it for personal protection. Organizations…HELPNETSECURITY.COM
2 SepGeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal BackendsTwo vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026…THEHACKERNEWS.COM
2 SepManchester Airports Group - 8,728,451 breached accountsIn August 2026, Manchester Airports Group (MAG) disclosed a data breach impacting their services . The incident was later claimed by the FulcrumSec hacking group , who subsequently published email addresses and phone numbers relating to 8.7M customers of Manchester, Stansted and …HAVEIBEENPWNED.COM
2 Sep KEVWhen the patch tsunami meets the maintenance windowIn April 2026, the balance between finding software flaws and fixing them broke. Frontier AI models released by Anthropic and OpenAI can now autonomously identify exploitable vulnerabilities in production software — work that used to take experienced human researchers roughly six…CSOONLINE.COM
2 SepChrome and Firefox Updates Patch Dozens of VulnerabilitiesThe browser refreshes fix multiple use-after-free, sandbox escape, and privilege escalation bugs. The post Chrome and Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
2 SepUS and European authorities disrupt Sality botnet after 23 yearsUS and European law enforcement agencies have disrupted the long-running Sality malware operation, cutting its operators off from more than 15,000 infected computers worldwide. The coordinated action, carried out on August 31, involved the US Department of Justice, FBI, Defense C…CYBERINSIDER.COM
2 SepOpenAI’s Astra Becomes First Model to Cross Critical Cybersecurity ThresholdThe designation applies when a model can independently find and exploit zero-day vulnerabilities across many well-defended systems. The post OpenAI’s Astra Becomes First Model to Cross Critical Cybersecurity Threshold appeared first on SecurityWeek .SECURITYWEEK.COM
2 SepAnthropic introduces zero-retention AI safety monitoring for enterprisesAnthropic is introducing a new framework aimed at helping enterprises monitor AI misuse without ceding control over sensitive data, as organizations struggle to balance security visibility with strict compliance requirements. The company announced a new solution called Enterprise…CSOONLINE.COM
2 SepDropbox accounts breached through Lenovo email verification flawDropbox is warning some users that an unauthorized party accessed their accounts by exploiting a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs. [...]BLEEPINGCOMPUTER.COM
2 SepExploit Published for Fresh Cleo Harmony VulnerabilityThe security defect allows remote attackers to bypass authentication through argument bearer manipulation. The post Exploit Published for Fresh Cleo Harmony Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
2 Sep$536 and 8 Hours: AI Learns to Attack a Different PLCExperts got Claude to port a PLC exploit, but it cost $536 and 8 hours, and a later AI-generated payload accidentally destroyed the hardware. Forescout researchers just answered a question that’s been hanging over industrial security for a while: can AI actually port a work…SECURITYAFFAIRS.COM
2 SepMeta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device ControlCybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta and can give operators near-complete control of infected devices. ThreatFabric said t…THEHACKERNEWS.COM
2 SepMalicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker CodeManifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication. The command executes as the u…THEHACKERNEWS.COM
2 Sep KEVSonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNsSonicWall patched two zero-days in SMA 1000 VPNs, including a CVSS 10 pre-auth SSRF flaw, after confirming active exploitation. SonicWall has released security updates for two vulnerabilities in its SMA 1000 VPN appliances that are actively exploited in attacks in the wild. Sonic…SECURITYAFFAIRS.COM
2 SepNew darknet marketplace peddles millions of driver's licenses.Law enforcement and industry partners shutter the Sality botnet. Business news: Socure raises $156 million and acquires Fravity.THECYBERWIRE.COM
2 SepAI Security Findings Aren’t ProofAI can generate remarkably polished security findings, complete with severity ratings, CWE classifications, explanations, and proposed patches. But a convincing output is not proof that a vulnerability exists—or that a proposed fix actually resolves it. AI can still be valuable w…YOUTUBE.COM
2 SepWordPress backup plugin flaw exposes millions of sites to takeover attacksAn SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites. [...]BLEEPINGCOMPUTER.COM
2 SepOpenLeash Adds a Human Check to Risky AI Agent ActionsThe security tool intercepts potentially dangerous agent actions, blocking clear threats and requesting human approval when intent is uncertain. The post OpenLeash Adds a Human Check to Risky AI Agent Actions appeared first on SecurityWeek .SECURITYWEEK.COM
2 SepManaging identity source transition for AWS IAM Identity CenterSeptember 2, 2026: This post was republished to include Active Directory migration strategies and automation for permission sets. AWS IAM Identity Center manages user access to Amazon Web Services (AWS) resources, including both AWS accounts and applications. You can use IAM Iden…AWS.AMAZON.COM
2 SepDrive-by data theft.Nexus sells driver’s license scans on the dark web. OpenAI says its models have reached a “Critical” capability threshold. International law enforcement disrupts a decades-old botnet. AI hallucinations fuel “slop squatting.” Plus, urgent patches for Cleo Harmony and Virtualizor, …THECYBERWIRE.COM
2 SepSonicWall SMA 1000 Zero-Days Enable Unauthenticated RCEThe exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.DARKREADING.COM
2 SepDoD confirms ‘refrigeration disruption’ at military commissariesDysruptionHub raised the suspicion flag yesterday, but couldn’t get a straight answer from DOD as to whether refrigeration outages at 14 commissaries represented a cyberattack. The Military Times fared no better: With more than a half-dozen commissaries on military bases in…DATABREACHES.NET
2 SepHackers expose donor data from Russian fundraisers for Ukrainians, political prisonersDaryna Antoniuk reports: Hackers reportedly gained access to payment accounts used by two Russian fundraising projects supporting Ukrainians and political prisoners, exposing donor email addresses and limited payment card information. The unknown threat actor targeted Davayte, wh…DATABREACHES.NET
2 SepLuminis Health facilities dealing with a cyberattackBridget Byrne reports: Luminis Health is experiencing a cybersecurity incident affecting certain systems across its organization, according to a Facebook post Tuesday. “Our priority remains providing safe, high-quality care to our patients,” the health system said in the post tha…DATABREACHES.NET
2 SepJail time for Maine child in 764 marks turning point in federal law enforcementResearcher tracking 764 said the first-of-its-kind case has a wider impact that will cause ripples across the landscape of violent extremist crime. The post Jail time for Maine child in 764 marks turning point in federal law enforcement appeared first on CyberScoop .CYBERSCOOP.COM
2 SepAI’s Vulnerability Surge May Be More Manageable Than First FearedNew research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have the right strategies.DARKREADING.COM
2 SepOpenAI Astra Brings Autonomous Zero-Day Exploitation to AIOpenAI says Astra can autonomously find zero-days and build exploits, marking its first model to reach the “Critical” cyber risk level. Astra is now officially OpenAI’s highest-risk cybersecurity model. In August, OpenAI said it “couldn’t rule out” that its upcoming model had rea…SECURITYAFFAIRS.COM
2 SepSmashing Security podcast #483: This AI helps thieves steal your iPhoneYou've had your iPhone stolen. A day later, you get a text from Apple saying they've found it, and a very helpful woman called Alice from Apple Support calls to walk you through recovering it. She's polite. She's professional. But she is not from Apple. She's not even human. And …GRAHAMCLULEY.COM
1 SepBot detection arrives in CrowdSec 1.8.0, along with two DoS fixesFailed SSH logins pile up in an auth log, and a scanner walks a website looking for exposed admin paths. CrowdSec reads log sources and HTTP requests, works out which addresses are misbehaving, and hands the block to a separate remediation component sitting in front of the servic…HELPNETSECURITY.COM
1 SepNIS2 compliance: Fixing IAM and access control before the 2026 auditThe NIS2 Directive places direct obligations on organizations across supply chain risk management, incident reporting, and board-level accountability. October brings a new wave of legally binding deadlines across the EU, as member states move from transposition into enforcement. …HELPNETSECURITY.COM
1 Sep179: The Courthouse - RevisitedIn this episode we follow up with Gabby and Justin from Episode 59 - two seasoned penetration testers who tell us a story about the time when they tried to break into a courthouse but it went all wrong, and what happened in the aftermath. Sponsors This show is brought to you by D…DARKNETDIARIES.COM
1 SepRecently patched PaperCut zero-days used in data theft attacksTwo security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks. [...]BLEEPINGCOMPUTER.COM
1 SepRussia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI AnalysisCybersecurity researchers have disclosed a new technique dubbed GuardBreaker that's been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligence (AI)-assisted analysis. The idea, ESET said in …THEHACKERNEWS.COM
1 SepChina-linked hackers turn Cisco routers into covert attack infrastructureA China-linked cyber espionage group has expanded beyond VMware environments to target network and authentication infrastructure that enterprises rely on to manage access and administer critical systems, according to new findings from incident response firm Sygnia . The threat ac…CSOONLINE.COM
1 SepFixing Software Weaknesses Rather Than Just Finding More Flaws - ASW #398AppSec has always emphasized techniques and tools for discovering vulns, along with taxonomies and lists for describing them. But just piling up more CVEs into a prioritized patching queue has never been an effective strategy. Nidhi Aggarwal talks about some of the economics and …YOUTUBE.COM
1 SepChaotic Eclipse Releases Kaspersky Zero-Day HardBreacherChaotic Eclipse released HardBreacher, a PoC exploit for a Kaspersky Endpoint Security privilege escalation flaw, adding another zero-day to his list. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day…SECURITYAFFAIRS.COM
1 SepAttackers Steal METR API Key and Consume AI Credits Worth About $600,000METR (short for Model Evaluation and Threat Research and pronounced "Meter"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered "two notable security incidents" …THEHACKERNEWS.COM
1 SepAesto healthcare data breach impacts 9.5 million peopleHealthcare data migration and archiving provider Aesto has disclosed to the US Department of Health and Human Services (HHS) that a data breach announced earlier this year affected 9,540,683 individuals. The incident involved unauthorized access to part of Aesto’s Amazon Web Serv…CYBERINSIDER.COM
1 SepIntroducing Continuous Vulnerability Assessment: Real-Time Defense for the AI Threat EraDetect exposure to new vulnerabilities the moment they are published with Wiz CVAWIZ.IO
1 SepFake Cloudflare CAPTCHA tricks victims into opening a tunnel for attackersAttackers are using fake CAPTCHA prompts to trick victims into running malicious PowerShell commands as part of a multi-stage intrusion campaign that can establish persistence, conduct network reconnaissance and potentially give operators a path to deeper access within an organiz…CSOONLINE.COM
1 SepFive Venezuelans Plead Guilty in US Court to ATM JackpottingThe defendants unsuccessfully attempted to physically install malware on ATMs to force them to dispense cash. The post Five Venezuelans Plead Guilty in US Court to ATM Jackpotting appeared first on SecurityWeek .SECURITYWEEK.COM
1 SepOpenClaw rolls out system-wide overhaul, updates security controls across agent platformOpenClaw has released what it describes as the largest update in its history, introducing a system-wide overhaul spanning runtime behavior, plugins, and security controls, as enterprises increasingly evaluate how such agent-based systems operate across connected environments. “Th…CSOONLINE.COM
1 SepWhite House Launches Pilot Program in Texas to Protect Water InfrastructureProject Watershed 250 will see water providers in Texas provided with federal and private sector cybersecurity resources amid rising nation-state threatsINFOSECURITY-MAGAZINE.COM
1 SepNearly 22,000 Microsoft Exchange servers vulnerable to hijack attacksNearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. [...]BLEEPINGCOMPUTER.COM
1 SepExperiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of DollarsForescout researchers used Claude AI to port a remote code execution exploit between WAGO PLC models. The post Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars appeared first on SecurityWeek .SECURITYWEEK.COM
1 SepFake Claude Opus 5 app delivers malware and wipes its own tracksA malicious GitHub repository impersonating Anthropic and claiming to offer free access to “Claude Opus 5” is delivering RevStealer, Windows information-stealing malware that targets passwords, cryptocurrency wallet data and login credentials, according to Morphisec. Repository R…HELPNETSECURITY.COM
1 SepIE: HSE fined €645,000 over data breach affecting Westmeath hospitalAdrian Cusack reports: The Data Protection Commission has fined the HSE [Health, Safety, and Environment] more than €600,000 over the mismanagement of historical records held at St Loman’s hospital, Mullingar, and St Conal’s Hospital, Letterkenny. The fine was issued …DATABREACHES.NET
1 SepSanta Fe Schools Move Forward With New Cybersecurity PolicyAndré Salkin reports: The Santa Fe school board approved a new cybersecurity policy this week but delayed a vote on a separate policy governing student data privacy, with most board members calling it too broad and too important to rush through. The delayed measure, Draft Policy …DATABREACHES.NET
1 SepWhat AI Researchers See Beyond AIAI models can identify vulnerabilities and sometimes conclude that there is nothing further to exploit. Researchers with deep domain expertise can challenge that conclusion. Knowing the specifics of an asset, environment, and deployment can allow researchers to take an AI-generat…YOUTUBE.COM
1 SepVU#456290: Hugging Face Transformers library writes remote code to disk prior to consent checkOverview A vulnerability in the Hugging Face Transformers library (versions 4.49.0 through 5.8.1) allows remote, attacker‑controlled Python files to be written to the local disk without user authorization. The library performs a remote module fetch and local cache write before ev…KB.CERT.ORG
1 Sep13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet SeedsCybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS d…THEHACKERNEWS.COM
1 SepNovocure data breach affects more than 1,400 cancer patientsHealthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack. [...]BLEEPINGCOMPUTER.COM
1 SepWhy Even the Best Edge Security Still Misses High-Risk SessionsAttackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations identify risky sessions and make stronge…BLEEPINGCOMPUTER.COM
1 SepChaotic Eclipse Releases GenDigital Avast Antivirus ZeroDay PrettyPragueChaotic Eclipse released PrettyPrague, a PoC exploit for a GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting …SECURITYAFFAIRS.COM
1 SepNightmare Eclipse releases PoC exploit for Kaspersky Endpoint Security.Healthcare companies disclose breaches. Attackers exploit recently patched JFrog Artifactory flaw.THECYBERWIRE.COM
1 SepCISA review makes the case for eliminating vulnerability classesFor years, the security industry has treated vulnerabilities as an endless queue of individual fixes. A recent CISA review argues that this is precisely why attackers keep winning. The solution to this problem, they believe, is eliminating entire categories of weaknesses at the s…HELPNETSECURITY.COM
1 SepAttackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million RecordsAesto Health suffered a breach exposing personal and health data of more than 9.5 million people after attackers accessed its AWS infrastructure. Aesto Health, a U.S. healthcare technology company, disclosed a data breach that exposed personal and health information belonging to …SECURITYAFFAIRS.COM
1 SepLeaked Russian Cyber-Operations Training MaterialsThis is interesting: The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security. […] …SCHNEIER.COM
1 SepFrontier AI used to help exploit flaws in tests using key industrial devicesA report showed that Claude could help hackers develop attack strategies targeting PLCs used by water utilities and other industries.CYBERSECURITYDIVE.COM
1 SepBreeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment SystemsBrazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024. Google Threat Intelligence Group (GTIG) and Mandiant teams described the threat actor as "specializ…THEHACKERNEWS.COM
1 SepMalicious website themes infect outdated iPhones with spywareMalicious website themes infect unpatched iPhones with spyware when users visit a compromised site, allowing attackers to steal messages, photos, passwords, location data, and cryptocurrency wallet recovery phrases. Socket’s Threat Research Team uncovered the packages on Packagis…CYBERINSIDER.COM
1 SepAesto Health says data breach affects over 9.5 million patientsAesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. [...]BLEEPINGCOMPUTER.COM
1 SepNightmare on Windows 11.Nightmare Eclipse drops a Kaspersky zero-day. The Financial Stability Board warns frontier AI could threaten the global financial system. Anthropic says it has tightened security. CISA adopts a risk-based approach to patching. A new Windows infostealer hides in fake AI models. A …THECYBERWIRE.COM
1 SepFBI Probes Service Selling 153M+ Drivers LicensesA new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appea…KREBSONSECURITY.COM
1 SepThe CAPTCHA Is Actually the Attack“Click-fix” attacks use social engineering to convince victims to execute malicious commands themselves. One technique disguises the instructions behind a fake Cloudflare CAPTCHA and tells the user to open PowerShell or Terminal and paste a command. The attacker doesn't necessari…YOUTUBE.COM
1 SepSN 1094: AI Patching Shortcomings - Should You Trust AI-Generated Code?AI-generated code is flooding the industry, but researchers reveal that almost half of it contains critical vulnerabilities. This week, we unpack what happens when the race for automation outpaces security best practices. A possible means for preventing prompt injection abuse. Cl…TWIT.TV
31 Aug KEVShinyHunters claims another health giant breach, PaperCut rushes second emergency patch, US bans foreign grid techShiny Hunters Claims 284M McKesson Records Stolen, PaperCut Patch Bypassed Again, and White House Bans Foreign Power Grid Tech Host David Shipley covers multiple cybersecurity headlines: Shiny Hunters claims it breached healthcare giant McKesson via voice phishing, compromised Ok…CYBERSECURITYTODAY.LIBSYN.COM
31 AugHow AI could make it harder for governments to use hacking toolsAI is proving effective at finding and exploiting vulnerabilities. Some say this will make it harder for governments to use hacking tools and spyware and could reignite calls to backdoor devices.TECHCRUNCH.COM
31 AugOpenAI-led coalition warns AI will compress cyberattack timelines, expose enterprise weaknessesA coalition led by OpenAI is warning that AI will sharply accelerate the speed and scale of cyberattacks, leaving enterprises with a narrowing window to fix long-standing security weaknesses before they are exploited. “In the coming months, AI-enabled cyber attacks will become fa…CSOONLINE.COM
31 AugIs your cloud security strategy ready for AI’s looming threat?Cloud architectures designed to withstand human attackers are facing a new threat: AI agents that rewrite the rules on the pace and scope of attacks. The recent OpenAI incident involving Hugging Face offers an early example of what an autonomous AI attack can look like, with an a…CSOONLINE.COM
31 AugLife as a CISO in Hollywood: Keeping New Films Leak-Free & 4 Black Hat Interviews - ESW #474Interview with Dan Meacham, CISO at Legendary Entertainment Dan Meacham joined us to share a preview of his leadership panel at InfoSec World. At this CRA event in October, Dan will be discussing *The Augmented Defender - What AI Actually Changes on the Front Line* with Daniel Bo…YOUTUBE.COM
31 Aug[webapps] Langflow 1.8.4 - Path Traversal to Remote Code ExecutionLangflow 1.8.4 - Path Traversal to Remote Code ExecutionEXPLOIT-DB.COM
31 AugAttackers begin exploiting critical Ruby on Rails flaw.PaperCut issues emergency patch for a second zero-day. Two Nigerians extradited to US over sextortion schemes.THECYBERWIRE.COM
31 AugSlovenian casinos reopen after cyberattack knocked gaming systems offlineOne of Slovenia’s largest gambling and tourism groups has begun reopening its casinos after a cyberattack forced them to shut down for several days.THERECORD.MEDIA
31 Aug31th August – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 31st August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Manchester Airports Group, the UK operator of Manchester, London Stansted, and East Midlands airports, has disclosed a cyberattack …RESEARCH.CHECKPOINT.COM
31 AugCalifornia moves to exempt Linux from new age-verification lawCalifornia lawmakers have passed AB 1856, a bill that would exclude qualifying open-source software distributors from being treated as operating system providers under the state’s upcoming Digital Age Assurance Act (DAAA). The measure passed the Senate 39–0 on August 26, and the …CYBERINSIDER.COM
31 AugGrapheneOS may skip Pixel 11 over missing hardware security featureGrapheneOS says it may abandon support for Google’s Pixel 11 series after discovering that the new devices appear to lack usable support for ARM Memory Tagging Extension (MTE). MTE is a hardware security feature the privacy-focused Android project relies on extensively to mitigat…CYBERINSIDER.COM
31 AugNightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product ExploitKaspersky told SecurityWeek that it patched the vulnerability affecting its Endpoint Security product. The post Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit appeared first on SecurityWeek .SECURITYWEEK.COM
31 AugServiceNow Patches 3 Critical Code Injection VulnerabilitiesAttackers could exploit the security defects to execute arbitrary code and access or tamper with data. The post ServiceNow Patches 3 Critical Code Injection Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
31 AugCritical Ruby on Rails Vulnerability in Attackers’ CrosshairsNamed KindaRails2Shell, the arbitrary file read flaw allows attackers to extract secrets and execute arbitrary code remotely. The post Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek .SECURITYWEEK.COM
31 AugThreat actors are posing as AI crawlers to hunt for exposed credentialsAttackers are disguising automated scanning as traffic from AI crawlers operated by OpenAI, Anthropic, Google, Perplexity and other companies while searching websites for exposed credentials and configuration files, according to GreyNoise. (Source: GreyNoise) “Every program that …HELPNETSECURITY.COM
31 AugAttackers plant remote access tools on compromised PaperCut serversThe threat actor targeting internet-facing PaperCut Application Servers is covertly installing legitimate remote access software on them, PaperCut Software shared in the most recent update on the ongoing attack campaign. PaperCut zero-days exploited to deploy remote access tools …HELPNETSECURITY.COM
31 AugShinyHunters claims it stole 284 million patient records from McKessonHealthcare company McKesson disclosed a cybersecurity incident in which hackers got into third-party applications and stole data. McKesson is a major U.S. healthcare company that distributes pharmaceuticals, medical supplies and other healthcare products to pharmacies, hospitals …HELPNETSECURITY.COM
31 AugRussian hackers plant nuclear weapon prompt in malware to trip AI safety guardrailsRussian state hackers are trying to interfere with AI-assisted malware analysis in Ukraine by deliberately setting off AI safety mechanisms, ESET has found. The technique, named GuardBreaker by ESET, appeared in a malicious VBS script tied to UAC-0099, a Russia-aligned group prev…HELPNETSECURITY.COM
31 AugThe OpenClaw 2.0 release moves your sessions into SQLiteOpenClaw is open source software that hands an AI model small standing jobs across your accounts, the kind of chore where it watches a mailbox for vendor advisories and pings you on Telegram when one names a product you run. OpenClaw 2.0 is the largest update in the project’…HELPNETSECURITY.COM
31 Aug KEVWhat vulnerability prioritization looks like when KEV, EPSS, and CVSS disagreeIn this Help Net Security interview, Dr. Joye Purser, Global Field CISO at Cohesity, explains how to rank vulnerabilities when KEV, EPSS, and CVSS point in different directions. Active exploitation comes first, then exploit likelihood, then technical severity, with adjustments fo…HELPNETSECURITY.COM
31 AugHalo-record: Open-source audit trails for AI agentsBrian Kuan wrote halo-record, a small Python package that sits inside an AI agent and writes down the moves it makes: tool calls, model calls, data access, approvals. Each action becomes one line in a file that only ever gets appended to, and every line carries a hash of the line…HELPNETSECURITY.COM
31 AugA rough day at the extortion office and a botched attack on Blossom Health.A tip about Click2Mail was not the only interesting tip DataBreaches received on Thursday. We also received an email from someone who identified themself as a patient at Blossom Health, a US-based telehealth and psychiatry platform. “An extortionist appears to have compromi…DATABREACHES.NET
31 AugTime’s Up: Ransomware Group Claims 150,000+ Cardiology Patient Records. We’ve Seen the Data.On August 6, DataBreaches reported that Cardiology Associates of Port Huron (CAPH), a Michigan medical practice with 9 locations, appeared to have been breached by a group called Orova. As reported at the time, the listing included screenshots with personally identifiable and pro…DATABREACHES.NET
31 AugCritical GiveWP Flaw Lets Attackers Run Commands on WordPress ServersA critical GiveWP flaw lets unauthenticated attackers execute server commands. Version 4.16.7.2 fixes the PHP object injection chain. A critical vulnerability in GiveWP, one of the most widely used WordPress plugins for online donations and fundraising, can let an unauthenticated…SECURITYAFFAIRS.COM
31 AugAutomate IAM Identity Center governance with continuous discovery and reportingAWS IAM Identity Center integrates with external identity provider (IdP) to provide customers with a centralized authentication and authorization solution for AWS resources across AWS Organizations. AWS continues to invest into IAM Identity Center with a growing number of AWS ser…AWS.AMAZON.COM
31 AugIs Someone Hacking DoD Refrigerators?It sure seems like it. The stores confirmed to be affected include Fort Irwin , Calif.; F.E. Warren Air Force Base , Wyo.; Fort Huachuca , Ariz.; Naval Station Newport , R.I.; Columbus Air Force Base , Miss.; and Travis Air Force Base , Calif., according to announcements made onl…SCHNEIER.COM
31 AugWindows bug incorrectly tells users that Microsoft Defender Antivirus is turned offMicrosoft on Friday reported that a glitch is causing Windows to tell users that Microsoft Defender Antivirus is turned off when it is in fact fully functional, a bug that the vendor says it is working to fix. Consultants say that this advisory raises a major concern in that it w…CSOONLINE.COM
31 AugFive plead guilty in latest federal ATM jackpotting caseFederal law enforcement continued to warn about ATM jackpotting gangs as it announced guilty pleas from five Venezuelan nationals.THERECORD.MEDIA
31 AugCronos blockchain restarts after $74 million Tectonic exploitThe Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million. [...]BLEEPINGCOMPUTER.COM
30 AugTerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel BackdoorMicrosoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell. "While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply …THEHACKERNEWS.COM
30 AugClosing the space-cyber workforce gap.Despite the space sector's consistent growth and greater importance as a critical infrastructure sector, finding cybersecurity talent is still proving to be a challenge. Host Maria Varmazis and ⁠Nick Cohen⁠, Principal Engineer at the ⁠Aerospace Corporation⁠, sat down to discuss t…THECYBERWIRE.COM
30 AugFulcrumSec claims Manchester Airports hack, theft of 86 GB of dataFulcrumSec claims it stole 86 GB of data from Manchester Airports Group. BleepingComputer validated one traveller's record, while samples revealed detailed customer, booking, and travel information beyond what MAG initially disclosed. [...]BLEEPINGCOMPUTER.COM
30 AugUS government snitch-finder pleads guilty to leaking state secrets to foreign spiesConnor Jones reports: The former Defense Intelligence Agency (DIA) IT specialist previously accused of trying to pass secret and top-secret information to foreign spies has pleaded guilty following a successful FBI sting. Nathan Vilas Laatsch, then 28, and now 29, was arrested in…DATABREACHES.NET
30 AugA massive cache of Valve data has reportedly leaked online, appearing to include Portal 2’s elusive beta build and a potential weapon from Half-Life 2: Episode 3Rick Lane reports: A massive cache of internal builds from Valve has reportedly leaked online, including beta builds of several classic Valve titles and possible weapons from Half-Life 2’s cancelled third episode. The leak, which began circulating on Saturday and comes from…DATABREACHES.NET
30 AugCybercriminals build fake school websites as education attacks hit record highJoy Agwunobi reports: Cybercriminals are ramping up preparations for the new academic year by creating thousands of education-themed websites and phishing campaigns designed to steal personal and financial information from students, parents and educators, as the education sector …DATABREACHES.NET
30 AugVT: Local VA warns of possible data breachAbigail Ham reports: The U.S. Department of Veteran’s Affairs says some veterans getting services through the White River Junction, Vt. healthcare system may have had their personal information exposed in an unintentional data breach. Earlier this summer, several unencrypte…DATABREACHES.NET
30 AugExtortion Group FulcrumSec Claims 86GB Manchester Airports Group Data TheftExtortion group FulcrumSec claims they stole 86GB of Manchester Airports Group data after finding API credentials exposed in client-side JavaScript. Manchester Airports Group (MAG) disclosed a data breach on August 27 affecting customers of Manchester, London Stansted, and East M…SECURITYAFFAIRS.COM
30 Aug KEVHackers Are Probing PaperCut Servers, and 47% Still Have No PatchPaperCut servers are under active attack, while 47% of tracked installations still run unpatched versions vulnerable to remote code execution. PaperCut, the print management software running in schools, hospitals, and offices worldwide, confirmed on August 27 that a pre-authentic…SECURITYAFFAIRS.COM
29 AugHow Varonis hacks AIs into snitching on themselvesVaronis AI Threat Lead on Copilot Exploits, Prompt Injection, and the AI Hacking Trifecta The host interviews Mark Vaitsman, AI threat research lead at Varonis, about Varonis Threat Labs' research into AI vulnerabilities, including a chain of single-click exploits in Microsoft Co…CYBERSECURITYTODAY.LIBSYN.COM
29 AugBerlin Refuses to Pay Hackers Who Stole Data From the City's State NetworkBerlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortionists' demands. The same statement disclosed that forensic work had found furthe…THEHACKERNEWS.COM
29 AugCosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was VulnerableCosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was publis…THEHACKERNEWS.COM
29 AugAI Agents Escaped the Evaluation EnvironmentHugging Face reported vulnerabilities exploited by AI agents in its dataset processing pipeline. The agents were able to execute code, access credentials, and move laterally across production infrastructure. The agents also escaped their evaluation environment and used a zero-day…YOUTUBE.COM
29 AugWho let the AI hack?Today we are joined by ⁠Crystal Morin⁠, Senior Cybersecurity Strategist, and ⁠Michael Clark⁠, Senior Director of Threat Research, at ⁠Sysdig⁠, sharing their work on "LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools." The Sysdig Threat Res…THECYBERWIRE.COM
29 AugThe Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants WarnPlus: Hackers target over 100 US water systems, ICE puts in an order for robot dogs, and you’ll never guess what “MrChildPorn” was arrested for.WIRED.COM
29 AugDe: Hackers demand 30 bitcoin from Berlin as sensitive data breach widensDPA reports: The Berlin state government has declined to comment on the demands made by hackers who targeted the city’s administrative data network two weeks ago, a spokeswoman said on Saturday. The government is also withholding information about which data the attackers a…DATABREACHES.NET
29 AugUS officials backpedal on claims that government agencies were hacked by ChineseAJ Vicens and Raphael Satter report: U.S. officials are backpedaling on claims that several government agencies were hacked by Chinese spies, now saying that the organizations were among the hackers’ targets. In a freshly edited statement, the Justice Department said Friday…DATABREACHES.NET
29 AugPEAR leaks data allegedly exfiltrated from South Plains Rural Health Services while SPRHS remains silentSuspectFile reports: A cyberattack against a Texas healthcare organization allegedly resulted in the exfiltration of approximately 1.4 TB of data, according to claims made by the ransomware group PEAR. The alleged victim is South Plains Rural Health Services, Inc. (SPRHS), a nonp…DATABREACHES.NET
29 AugSCOOP: Some Click2Mail customers will soon be receiving notification of a data security incidentOn August 27, DataBreaches woke up to a message request on Signal that read, “Click2mail.com checkout with a debit card, website is actively hijacked. Card gets sold to fraudsters. It’s happened twice.” DataBreaches accepted the request, and learned that the customer …DATABREACHES.NET
29 AugPhilippine Nuclear and Naval Targets Hit by Suspected Chinese OperatorAn alleged Chinese-speaking actor breached Philippine nuclear and naval targets by exploiting known flaws, stealing sensitive data. A suspected Chinese-speaking operator targeted a Philippine nuclear research body and a marine engineering company that supports the Philippine Navy…SECURITYAFFAIRS.COM
28 AugOpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging FaceOpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May. The incident, the company said, took place during cybersec…THEHACKERNEWS.COM
28 AugAlleged TeamPCP hackers arrested, Cyberattack halts medical shipments, FBI dismantles Chinese hacking platformsTeam PCP Arrests, Boston Scientific Shipping Halt, FBI Disrupts Chinese Hacking, CISA Cuts Scrutinized, and AI Email Summarizers Poisoned Host David Shipley covers five cybersecurity stories: Australian police, working with the FBI, arrested and charged two alleged core members o…CYBERSECURITYTODAY.LIBSYN.COM
28 AugNew infosec products of the month: August 2026Here’s a look at the most interesting products from the past week, featuring releases from A10 Networks, Abnormal AI, F5 Networks, Intezer, Netscout, ScienceLogic, Searchlight Cyber, SelectHub, ServiceNow, Snyk, Tanium, and Tufin. ServiceNow organizes autonomous security around s…HELPNETSECURITY.COM
28 AugFriday Squid Blogging: Truckload of Squid Spills in Rhode IslandUgh : A tractor-trailer rollover sent a truckload of squid spilling into a Rhode Island roadway, leaving a stench as they sat in the road for hours in the summer heat. Local authorities have dubbed it the “Squidpocalypse of ’26.” That would be twenty tons of squ…SCHNEIER.COM
28 AugAttackers Chain Two PaperCut Flaws to Execute Code Without AuthenticationMalicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. "This vulnerability gives an unauthenticated attacker remote control ov…THEHACKERNEWS.COM
28 AugThree CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQLServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker. The company said it deployed a security update to hosted in…THEHACKERNEWS.COM
28 AugPaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF VersionsPaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company has released an emergency patch for v25 and v26 to address the issue. It sai…THEHACKERNEWS.COM
28 AugGPUThor hardware attack can root Nvidia GPU systemsHardware security researchers from University of Toronto have developed a new memory bit flipping technique that significantly improves on previously known attacks against GPU memory. The new method can defeat the error-correcting codes (ECC) defense used on enterprise Nvidia GPU…CSOONLINE.COM
28 AugBeyond compliance: Designing systems that earn customer trustOver the years, I have learned that customer trust is not built by compliance alone. It comes from how systems actually handle data every day. In practice, I think five areas matter most Making customer intent consistent across systems Treating privacy as a distributed-systems pr…CSOONLINE.COM
28 AugSecurity Teams Become Their ToolsSecurity organizations rely on specialized teams for vulnerability management, patching, threat hunting, and other security functions. Yet much of the time and career investment can go toward learning the tools used to perform those jobs. That expertise can become so deeply embed…YOUTUBE.COM
28 AugMythos Writes the Exploit. Atlas Writes the Response. - Harman Kaur - SWN #611Most enterprise AI today is a conversation — it summarizes, suggests, recommends. Harman unpacks what changes when AI actually executes across endpoints, and the governance problem that creates. Where does the human stay in the loop, and where do they get out of the way? This seg…YOUTUBE.COM
28 AugWhen The Protocol Is The VulnerabilitySome security flaws aren't simply bugs in an application. They can be embedded in the underlying protocol or architecture, making a conventional patch impossible. IPMI is presented as an example where the weakness is fundamental enough that the recommended remediation is to stop …YOUTUBE.COM
28 AugWhy a cryptographic inventory is key for addressing the quantum computing threatWhen quantum computers become generally available, they’ll be able to crack current public-key cryptographic algorithms, putting digitally stored and transmitted data at risk. But the threat already exists, as attackers use the "harvest now, decrypt later" tactic. Discover why bu…TENABLE.COM
28 AugThe blacklist boomerang.A judge rules the Trump administration illegally labeled Anthropic a national security risk. The White House moves to keep foreign technology out of U.S. power systems. OpenAI rallies a global cyber defense push as its own AI agents exploit a Linux vulnerability. Researchers unco…THECYBERWIRE.COM
28 AugPaperCut warns of hackers using printer management software flaw in attacksPaperCut released an emergency advisory on Thursday evening saying vulnerabilities in their print management software, PaperCut NG and MF, are under active exploitation.THERECORD.MEDIA
28 AugMicrosoft Teams Has Become a Haven for Scammers in ChinaFraudsters are exploiting enterprise chat apps like Teams and Webex to trick Chinese victims into transferring large sums of money, fueling a wave of complaints.WIRED.COM
28 AugThreat Actors Abuse Cursor Agent AI to Assist Ransomware OperationsAurora ransomware operators are abusing SpaceX’s Cursor Agent AI tool to conduct tasks such as reconnaissance and exploitation activitiesINFOSECURITY-MAGAZINE.COM
28 AugExperiment shows AI agents can escape secure VMs using zero-daysA cyber-capable AI agent could repeatedly escape a QEMU/KVM virtual machine, first using known vulnerabilities and later chaining previously unknown flaws. The results challenge the assumption that conventional VMs are sufficient containment for advanced autonomous agents. Trail …CYBERINSIDER.COM
28 AugMcKesson discloses breach after ShinyHunters claims patient data theftHealthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. [...]BLEEPINGCOMPUTER.COM
28 Aug KEVPaperCut releases second emergency patch for exploited flawsPaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. [...]BLEEPINGCOMPUTER.COM
28 AugThe Vulnpocalypse Is Repricing the Bug Bounty EconomyThe surge in AI-powered vulnerability reports is driving down bug bounty prices, and that could spell trouble for independent researchers.DARKREADING.COM
27 Aug400 episodes and we still have trust issues.This week, we’re celebrating a pretty big milestone: 400 episodes of Hacking Humans! Along the way, we’ve shared hundreds of stories, scams, lessons, and plenty of memorable Catch of the Days—and we couldn’t have made it this far without you. To everyone who has listened, written…THECYBERWIRE.COM
27 AugAI will not fix a governance problem in your camera estateCamera systems often outlive the companies that install them. In this Help Net Security interview, Rob Janssens, EMEA Cyber Security Director at Hikvision Europe, discusses what happens when the integrator is gone, the documentation is lost, and nobody holds the admin credentials…HELPNETSECURITY.COM
27 AugNew GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root AccessAcademic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-service (DoS) and privilege escalation to a root she…THEHACKERNEWS.COM
27 AugCritical infrastructure’s long, undefended tail exposed by UK energy attackA cyberattack that forced a small British electricity generator offline for four days caused no power outage, threatened no part of the national grid, and may not even have been carried out by the Iran-linked hackers initially blamed. But the incident illustrates a consequential …CSOONLINE.COM
27 AugOpenAI says AI agents formed a ‘swarm’ before breaching Hugging FaceOpenAI has published a detailed post-mortem of July’s Hugging Face breach, revealing that its AI agents did far more than escape a cybersecurity sandbox. The models created an unauthorized communication network, shared exploits and credentials, coordinated attacks across separate…CYBERINSIDER.COM
27 AugATF confirms “major incident” after recent Qilin breach claimsATF, the regulatory agency that enforces federal laws governing firearms and explosives in the United States, has confirmed that one of its systems was compromised after breach claims made by the Qilin ransomware gang. [...]BLEEPINGCOMPUTER.COM
27 AugLLM-Based Social Engineering ScamsOpenAI disrupted a social engineering group from Cambodia that used ChatGPT. Its scope is impressive: The network simultaneously conducted multiple types of scams, often blending elements from different schemes. For instance, operators used dating personas to build trust before i…SCHNEIER.COM
27 Aug KEVCISA orders feds to patch Citrix NetScaler RCE flaw by SaturdayCISA has ordered U.S. government agencies to patch their Citrix NetScaler appliances against an actively exploited remote code execution vulnerability by Saturday. [...]BLEEPINGCOMPUTER.COM
27 AugUS Navy tells sailors and their families: scrub your social media, enemies are watchingThe US Navy has told its entire workforce of 340,000 active-duty personnel, 58,000 reservists, and 210,000 civilian employees to clean up their social media profiles, because adversaries might be using them to determine who they are, where they live, and when they may not be at h…BITDEFENDER.COM
27 AugSignal flaws allowed rogue servers to decrypt users’ contact queriesSecurity researchers at V12 discovered two critical vulnerabilities in Signal’s Contact Discovery Service that could allow a malicious server operator to escape the protections of its Intel SGX enclave. The flaws enabled arbitrary reading of protected enclave memory and, in the m…CYBERINSIDER.COM
27 AugTwo Alleged ‘TeamPCP’ Hackers Arrested in AustraliaAuthorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (…KREBSONSECURITY.COM
27 AugSpark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security ToolsIndividuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT. "The samples employ diverse lure themes, suggesting an effort to appeal to a broad range of potential victims. These in…THEHACKERNEWS.COM
27 AugAI can be made to read an email much differently than you doSecurity researchers are claiming it is possible for users to see one email in their inbox while their AI assistant reads another. Forcepoint X-Labs has demonstrated how a few lines of invisible HTML can be planted into an email that an AI email summarizer picks up and runs as in…CSOONLINE.COM
27 AugChinese Hacker Group QTFY Uses Custom-Built Platforms to Target US Infrastructure, FBI WarnsThe FBI advisory set out QTFY’s distributed hacking ecosystem, allowing it to exploit vulnerabilities at scale and obfuscate its activitiesINFOSECURITY-MAGAZINE.COM
27 AugUnknown PaperCut NG/MF vulnerability is under active attackA yet unspecified vulnerability affecting print management solutions PaperCut NG and PaperCut MF is being exploited by attackers, PaperCut Software warned today. “We are aware of confirmed customer incidents and are treating this matter with the highest priority,” the…HELPNETSECURITY.COM
27 AugLearn How to Build Security Operations Ready for AI-Powered AttacksSecurity teams have spent years trying to detect threats faster. AI is changing the harder part: how much time defenders have left to act. Advanced AI models can now help attackers discover vulnerabilities, generate exploit code, and move through weaknesses faster than traditiona…THEHACKERNEWS.COM
27 AugAlleged TeamPCP Hackers Charged in Australia Over Major Supply Chain AttacksThe Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged role in TeamPCP, the cybercrime group behind the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS and the AI gatew…THEHACKERNEWS.COM
27 AugWebinar: How Google Workspace breaches happen and what to do nextGoogle Workspace breaches can begin with social engineering or forgotten third-party integrations rather than sophisticated exploits. This webinar examines real-world breaches, what happens during the critical first hours, and the security controls that can make the greatest diff…BLEEPINGCOMPUTER.COM
27 AugTwo Alleged ‘TeamPCP’ Hackers Arrested in AustraliaBrian Krebs reports: Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Austra…DATABREACHES.NET
27 AugManchester Airports Group suffers data breach exposing customer dataManchester Airports Group (MAG) has disclosed a cybersecurity incident in which an unauthorized third party obtained customer information linked to airport parking, lounge, Fast Track, and Wi-Fi services. The company says payment information was not exposed and airport operations…CYBERINSIDER.COM
27 AugAmazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro PowersCybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers. The security flaw, which do…THEHACKERNEWS.COM
27 AugAustralian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and othersThe arrests come after a wave of cyberattacks earlier this year targeting tech companies that rely on high-profile and widely used open source software.TECHCRUNCH.COM
27 AugHow to build an exposure management program the business trusts: Lessons from Tenable’s CSODiscover how Tenable’s shift to an AI-driven exposure management program helped Tenable’s CSO, Robert Huber, overcome tool sprawl, unify data silos, mitigate the risk of rapid AI adoption, and shift from presenting granular, technical metrics to communicating business risk that t…TENABLE.COM
27 AugTwo alleged TeamPCP hackers arrested over global supply chain attacksTwo men from Western Australia have been charged after police allege they were part of TeamPCP, a cybercrime group that planted malicious code in open-source software, then used it to break into organizations around the world. The Australian Federal Police (AFP), working with the…HELPNETSECURITY.COM
27 AugIdentity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNsIntroduction Despite modern verification controls, identity theft remains one of the most pervasive threats to both individuals and enterprise organizations. U.S. Federal Trade Commission statistics show over 1 million identity theft reports annually, with related fraud and impos…RAPID7.COM
27 AugAustralian Police Charge Two Over TeamPCP Credential TheftAustralian police charged two men linked to TeamPCP over malware hidden in open-source code that stole 500,000+ credentials from 1,000+ organizations. Australian police have charged two men from Western Australia over a global cybercrime operation that allegedly hid malicious cod…SECURITYAFFAIRS.COM
27 AugOpenClaw went viral. Meet the maintainers building and securing it.OpenClaw is the fastest-growing project in GitHub history. Peter Steinberger and several maintainers share what they learned in the project's first six months. The post OpenClaw went viral. Meet the maintainers building and securing it. appeared first on The GitHub Blog .GITHUB.BLOG
27 AugManchester Airports Group confirms cyber attack exposed customer emails, phone numbers and vehicle detailsGabriel Higgins reports: Manchester Airports Group (MAG) has confirmed that it has been the target of a cybersecurity incident carried out by an unauthorised third party, resulting in the exposure of a quantity of customer data. The group operates Manchester, London Stansted and …DATABREACHES.NET
27 AugThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New StoriesA fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting…THEHACKERNEWS.COM
27 AugPaperCut warns of NG, MF flaw exploited in zero-day attacksPaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. [...]BLEEPINGCOMPUTER.COM
27 AugManchester Airports Group says hackers stole travelers' dataThe Manchester Airports Group (MAG) disclosed that hackers breached its systems and stole customer data, including Wi-Fi sign-ups from Manchester, Stansted, and East Midlands airports. [...]BLEEPINGCOMPUTER.COM
27 AugQilin claimed they attacked the ATF. Here’s what the ATF says.As many people have heard by now, the Qilin ransomware group claimed to have attacked the ATF. As is their regular practice, they provided no proof of their claims. Today, the ATF has issued a statement that sheds light on the incident and what ATF has found so far: WASHINGTON &#…DATABREACHES.NET
27 AugSwarm of 700 AI bots went rogue in hacking attackJames Titcomb reports: A swarm of 700 OpenAI bots conspired in a cyber attack last month, an investigation has revealed, in what the AI giant called a “warning shot” to the world. Independent researchers found that hundreds of AI bots worked together to attack the technology comp…DATABREACHES.NET
27 AugInside 90 days of attacks on AI infrastructureWiz honeypots uncover active campaigns targeting LiteLLM, MCP servers, and AI frameworks through RCE, blind prompt injection, and memory credential theft.WIZ.IO
27 Aug“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friendIn his first Threat Source newsletter, David Bianco explores the critical need for operational sovereignty in customizing AI guardrails to maintain the defender’s advantage.TALOSINTELLIGENCE.COM
27 AugAgentic AI Risks, CVE Program Concerns Permeate Black Hat USA 2026This installment of the Reporters' Notebook video series discusses the topics that dominated the cybersecurity conference, such as AI's effects on vulnerability reporting and security research.DARKREADING.COM
27 AugWhite House bans foreign-made equipment for power generation over cyber backdoor concernsThe Trump administration is banning the acquisition of foreign-made components used to manage electricity and power, alleging that “certain foreign actors are increasingly creating and exploiting vulnerabilities” in the technology.THERECORD.MEDIA
27 AugHacking All The Devices, with AI? - Rob Allen - PSW #941Rob Allen from ThreatLocker joins us to discuss securing agentic AI with zero-trust controls, least privilege, and access controls to limit what agents can access and do. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about …YOUTUBE.COM
27 AugSIEM: Centralize Like You Mean It, Federate Like You Have To(by Anton Chuvakin & Usman Chaudhary) Prologue: Three Years After “The End Is Nigh” Back in 2023, one of us wrote “Log Centralization: The End Is Nigh?” — an admittedly incomplete-thought blog with a scary premise: after 20+ years of yelling “centralize your logs!” (the earli…MEDIUM.COM
26 AugAI vulnerability discovery scores the highest impact of 20 emerging risksRisk managers, auditors and senior executives at 316 companies spent April and May ranking 20 threats they have not yet felt. AI discovery of cyber vulnerabilities came back first, according to Gartner. Three months earlier the same quarterly survey put information integrity risk…HELPNETSECURITY.COM
26 AugHottest cybersecurity open-source tools of the month: August 2026Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across diverse settings. SkillSpector: NVIDIA’s open-source security scanner for AI agent skills SkillSpector is an o…HELPNETSECURITY.COM
26 AugFake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA CodesCybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode. SOCRadar Threat…THEHACKERNEWS.COM
26 AugMeta adds three new features to keep WhatsApp accounts secureMeta has added new security enhancements to WhatsApp, this time in the form of stronger two-step verification, additional information about calls from unknown numbers, and the ability to add multiple passkeys to the same account. New account security features (Source: Meta) ̶…HELPNETSECURITY.COM
26 AugWho is accountable when your AI agent goes rogue?AI agents can go to great lengths to complete the tasks their operators assign, and as a series of recent incidents showed, this can include exploiting third-party systems, manipulating people, and distributing malicious code. But AI agents are not people who can be fired, sued, …CSOONLINE.COM
26 AugInterpol's Jackal IV Disrupts West African Crime InfrastructureThe international law enforcement operation focused on disrupting crime-as-a-service networks and supporting infrastructure behind groups like Black Axe.DARKREADING.COM
26 AugConnecting Cyber Risks to Board Outcomes & BHUSA interviews from Mimecast & Zscaler - BSW #462The threat landscape has become more interconnected, disruptive, and complex. Ransomware is now as much about extortion and data theft as it is about encryption. Supply chain events can create outages that ripple far beyond the initial target, and business interruption increasing…YOUTUBE.COM
26 AugExploits and vulnerabilities in Q2 2026This report covers statistics on vulnerabilities, exploits, and C2 frameworks in Q2 2026. For the first time ever, we aggregate data on vulnerabilities in open-source AI agents and AI frameworks.SECURELIST.COM
26 AugClaude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in TestsAikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the OpenClaw agent harness, exploited a client-side-only booking restriction in 9 of 10 runs. The original incident was f…THEHACKERNEWS.COM
26 AugGPUThor Rowhammer attack beats ECC on NVIDIA workstation GPUsUniversity of Toronto researchers have developed a new Rowhammer technique named GPUThor that can overwhelm error-correcting memory on several NVIDIA workstation GPUs, enabling crashes and even privilege escalation to root. The attack produces up to 23,500 times more bit flips th…CYBERINSIDER.COM
26 Aug KEVMicrosoft warns patch window is collapsing, urges shift to network-level containmentMicrosoft is warning that the window for patching vulnerabilities is rapidly shrinking, as attackers move from disclosure to exploitation faster than enterprises can safely deploy fixes, and is urging organizations to adopt network-level controls to limit exposure during that gap…CSOONLINE.COM
26 AugHackers now exploit critical Gitea flaw in code injection attacksAttackers are now exploiting a critical-severity vulnerability in the Gitea self-hosted Git service, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...]BLEEPINGCOMPUTER.COM
26 AugFour in Five AI Tools Run with No IT Oversight, New Research FindsReco report reveals growing shadow AI problem and surge in vulnerability disclosuresINFOSECURITY-MAGAZINE.COM
26 AugA recommendation from the Saskatchewan Information and Privacy Commissioner caught our eyeHere’s one we missed last week. Hannah Spray reports: The personal information of more than 2,000 people was stolen from Autism Services of Saskatoon during a data breach last year. In the aftermath, the organization properly notified the affected individuals and enhanced i…DATABREACHES.NET
26 AugUpdate Chrome before you browse againChrome’s latest update fixes 327 security vulnerabilities, including some that malicious websites could exploit as soon as you visit them.MALWAREBYTES.COM
26 AugUbiquiti patches three max severity security vulnerabilitiesUbiquiti has released security patches for three new maximum-severity vulnerabilities that threat actors can exploit remotely without privileges. [...]BLEEPINGCOMPUTER.COM
26 AugNational Kidney Registry allegedly hacked by DireWolf ransomware groupSince its emergence in May 2025, DireWolf has attacked several U.S. healthcare entities, as listed among its more than 100 targets on its dedicated leak site. As early analysts reporting on the group have noted, DireWolf encrypts victims’ files as part of their double-extor…DATABREACHES.NET
26 AugNovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 SessionsCybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that's used as a proxy to redirect Microsoft 365 sign-ins, while capturing authenticated sessions in the process. In a report shared with The Hacker News a…THEHACKERNEWS.COM
26 AugGTA 6 leak hype abused to distribute Vidar infostealer malwareMalicious websites impersonating Rockstar Games are exploiting interest in Grand Theft Auto VI leaks and an upcoming official preview to distribute the Vidar information stealer. The campaign uses fake “Play Now” and “Official Download” prompts that deliver a 1.1 MB executable na…CYBERINSIDER.COM
26 AugHackers target Microsoft SharePoint RCE chain with PoC exploitAttackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused. [...]BLEEPINGCOMPUTER.COM
26 AugStop Building a 2003 SOC with AI: Local Context, Failure Modes and Your Path (Part 3)In Part 1 of this series , we dumped a pile of uncomfortable questions on you and promised answers. In Part 2 of the series , we talked about why 1990s-2000s alert triage must die. The core thesis, if you recall: if you add AI agents into a legacy, swivel-chair SOC structure, you…MEDIUM.COM
26 AugUS takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and SenateThe DOJ said it disrupted Chinese state-backed tools used to scan, infect and exploit IoT devices for attacks on federal agencies and multiple industries.THERECORD.MEDIA
26 AugDoes Exploitation Status Actually Matter?Phishing-resistant authentication can significantly reduce credential theft, but attackers can target the authentication session itself. An adversary-in-the-middle attack can relay authentication and obtain a live session. Once inside, attackers may access Microsoft 365 or Okta r…YOUTUBE.COM
26 AugDetecting multi-stage attacks on AWS: A guide to cross-service signal correlationA single alert from one security service tells you something happened. Read that signal alongside activity from other services and your own business context, and you will know whether what happened is part of a multi-stage attack. Consider a short sequence. An identity calls GetC…AWS.AMAZON.COM
26 AugUS takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and SenateJonathan Greig reports; Chinese government hackers used tools known as “QScan” and “QTRouter” to breach multiple federal agencies since 2018, the Department of Justice said in announcing the takedown of the platforms on Wednesday. The tools were run by China-based Nanjing Xinjiuw…DATABREACHES.NET
26 AugThree 10.0 security flaws fixed across Ubiquiti’s UniFi lineThe communications product company disclosed 22 total Wednesday, all but one of which was rated “critical” at 9.0 or higher. The post Three 10.0 security flaws fixed across Ubiquiti’s UniFi line appeared first on CyberScoop .CYBERSCOOP.COM
26 AugNew GPUThor attack defeats NVIDIA ECC protection for root accessA newly disclosed Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service (DoS) and root-level privilege escalation. [...]BLEEPINGCOMPUTER.COM
26 AugWhen AI infrastructure becomes the target: Securing gateways and control pointsMicrosoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining activity. The post When AI infrastructure becomes the target: Securing gateways and control points appeared first o…MICROSOFT.COM
26 AugThe feds flip the script.The U.S. disrupts a Chinese hacking operation blamed for intrusions at several sensitive government agencies. CISA says more than 100 water systems were targeted in July. Attackers exploit a critical Gitea flaw, while malicious pages masquerade as Cloudflare verification screens.…THECYBERWIRE.COM
26 AugCritical Avada WordPress theme flaw enables zero-click RCEA critical vulnerability chain in the popular Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the server. [...]BLEEPINGCOMPUTER.COM
26 AugNSA to host a hacker reunion in bid to rebuild secretive unitMartin Matishak reports: A top U.S. spy agency will resemble a college for a while on Friday, as it hosts a first-of-its-kind reunion for alumni of its most secretive hacking unit. The National Security Agency will welcome back to campus potentially hundreds of former members of …DATABREACHES.NET
25 AugHow Equifax is using AI to elevate its cybersecurityFor nearly a decade, Equifax has been dealing with the aftermath of one of the worst cybersecurity breaches in US history, racking up $1.4 billion on cleanup costs. Among the mistakes that led to the breach were a mismanaged patching process, an expired public-key certificate, an…CSOONLINE.COM
25 AugApplying Zero Trust Principles to Agents - Kieran Human - ASW #397Sandboxing, least privilege, and monitoring are well-established controls in terms of the defenses they provide against unexpected and unauthorized actions. But being well-established in theory doesn't always translate to successful in practice. Kieran Human talks about some of t…YOUTUBE.COM
25 AugSilent Patches Don’t Stop Attackers—They Blind DefendersSilent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. The post Silent Patches Don’t Stop Attackers—They Blind Defenders appeared first on SecurityWeek .SECURITYWEEK.COM
25 AugAI supply chain risk is showing up in developer workflows firstIn this Help Net Security interview, Dr. Jaushin Lee, CEO of Zentera Systems, discusses where AI supply chain risk shows up. He says most incidents still hit developer workflows and open-source package repositories, while poisoned model weights and compromised MCP servers stay mo…HELPNETSECURITY.COM
25 AugHOL Guard: Open-source antivirus for AI agentsHOL Guard is a free, open-source tool that sits between an AI assistant and the computer it runs on. When the assistant tries something risky, the tool pauses it and asks you first. It installs in about a minute, runs on your own machine, and a typical check takes under 50 millis…HELPNETSECURITY.COM
25 AugCybersecurity jobs available right now: August 25, 2026Specialist Compliance Security AT&T | USA | On-site – View job details As a Specialist Compliance Security, you will serve as AT&T’s liaison for law enforcement, first responders, and emergency personnel nationwide. Respond 24×7 to emergency r…HELPNETSECURITY.COM
25 AugPeter Ortiz: The WWII Marine Who Foreshadowed Modern-Day Special ForcesIn 2017, journalist Katie Sanders discovered an episode of a radio program called This Is Your Life. It was a scratchy recording from 1949, and she heard the voice of 2nd Lt. Murray Simon, her grandfather, for the first time. In the episode, Murray was reunited with a man named P…THECYBERWIRE.COM
25 Aug KEVAustralia Warns of Active Exploitation of Critical TeamCity Server FlawAustralian officials are urging TeamCity customers to patch an actively exploited critical flaw, which follows a similar warning from the US governmentINFOSECURITY-MAGAZINE.COM
25 AugPolice arrests dozens of suspects in global cybercrime crackdownLaw enforcement agencies from 22 countries helped identify 263 suspects and arrested 58 individuals linked to cybercrime networks coordinated by African crime groups. [...]BLEEPINGCOMPUTER.COM
25 AugNew attack lets hackers plant hidden instructions in AI memory with a single promptA newly demonstrated attack technique allows hackers to plant hidden instructions inside an AI agent’s memory with a single prompt, enabling them to influence how the system responds to future queries. The technique, called InjecMEM, is described in a research paper as a “targete…CSOONLINE.COM
25 AugAI helps Chinese-speaking hackers speed up attacks on exposed serversA Chinese-speaking cybercrime group is using AI-driven tools to help compromise internet-facing Windows and Linux web servers, according to Cisco Talos, Cisco’s threat intelligence research unit. Talos said the activity points to increasingly automated offensive operations. Talos…CSOONLINE.COM
25 AugState divergence enables unauthorized accessWe found and reported a bug in Provenance Blockchain, a public proof-of-stake chain built on Cosmos SDK , that lets any user grant themselves admin control over marker accounts without holding a single token. Provenance covers a range of financial services, including on-chain tok…TRAILOFBITS.COM
25 Aug24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA PagesCybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. "While the malware is simply a single HTML page inside the npm package, and while downlo…THEHACKERNEWS.COM
25 AugFrontier AI: Vulnerability Management's Systemic RevolutionVulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline. The symbiotic relationship between vulnerability and patch management teams has also existed for that time and has gone through waves of contention and thankfulness. Wh…THEHACKERNEWS.COM
25 AugAnonyMousKIT service uses AI calls to unlock stolen Apple devicesA Phishing-as-a-Service (PhaaS) ecosystem dubbed AnonyMousKIT helps criminals steal Apple credentials and disable Activation Lock on stolen devices. The platform combines phishing emails, SMS, WhatsApp messages, recorded calls, and AI-powered voice agents in a credit-based servic…CYBERINSIDER.COM
25 AugHackers breached over 270 Zimbra servers in ongoing attacksThreat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability. [...]BLEEPINGCOMPUTER.COM
25 AugMarimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit ModeMarimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck's CVE Numbering Authority (CNA) record. The CNA record…THEHACKERNEWS.COM
25 AugINTERPOL crackdown on West African crime rings uncovers troubling new trendPolice across 22 countries arrested 58 people and identified 263 suspects during an eight-month INTERPOL operation targeting West African organized crime groups. Suspects detained in an operation targeting West African crime groups (Source: INTERPOL) Operation Jackal IV ran from …HELPNETSECURITY.COM
25 AugSeoul National University Hospital skips cybersecurity disclosure for years despite breach affecting 830,000This is one of those headlines where our first thought was “Uh oh!” but then we read more and thought “Hmmm…” Ko Jae-woo reports: Seoul National University Hospital has not filed a mandatory cybersecurity disclosure for years, an investigation has fo…DATABREACHES.NET
25 AugA Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClawOasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself. The findings were shared with The Hacker N…THEHACKERNEWS.COM
25 AugCISA orders agencies to fix exploited Zimbra vulnerabilityThe collaboration software’s developer took almost a full month to patch the flaw after disclosing it.CYBERSECURITYDIVE.COM
25 AugInside a Syrian Interrogation Room: The Detainee Files an Infostealer Stole From a Military Police UnitHudson Rock’s InfoStealers has an interesting story. From their Executive Summary: In May 2023, an infostealer infected a computer belonging to the Military Police Investigation Section in Suluk, northern Syria – a unit of the Turkish-backed Syrian National Army (SNA). The …DATABREACHES.NET
25 AugHealth systems warn of coordinated phishing targeting Epic’s patient portalChad Van Alstin reports: Numerous health systems across the country have issued alerts, warning patients to ignore scam messages that are attempting to phish passwords from patients, allowing hackers to gain access to Epic Systems’ MyChart patient portal. The effort appears to be…DATABREACHES.NET
25 AugResearchers warn about chained SharePoint sequenceAn authentication bypass flaw is already under exploitation, the latest in a series of recent SharePoint attacks. CYBERSECURITYDIVE.COM
25 AugNew Utah law protects student privacy after BYU research found K-12 apps were collecting and sharing dataSharman Gill reports: … BYU research finds that EdTech vendors don’t always meet their student privacy obligations; that research has led to new Utah legislation that tightens up the privacy issues. In an August 2025 investigation report prepared for the Utah State Board of…DATABREACHES.NET
25 AugFinding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClawAttackers can exploit a security bug in NVIDIA's tool to gain unauthenticated access to the local model server through the Ollama API, paving the way for persistent AI agent corruption.DARKREADING.COM
25 Aug2 weeks after JPS Health Network outage, patients still dealing with falloutGiles Bruce reports: Patients at Fort Worth, Texas-based JPS Health Network are facing lasting consequences from a network outage that stretched nearly two weeks, the Fort Worth Star-Telegram reported. JPS Health Network operated under a “controlled network downtime” starting Aug…DATABREACHES.NET
25 Aug‘Close Enough’ Data Breach Notifications Create ExposureVaughn Stupart, Matthew W. Van Hise, and Craig A. Hoffman of BakerHostetler write: One ruling is not a trend. And there can be unique factors at play in regulatory investigations related to large incidents. But a summary judgment ruling in favor of a state in a lawsuit against a …DATABREACHES.NET
25 AugWhat If Nobody Has Exploited It Yet?A vulnerability's current exploitation status can provide an important urgency signal, but it doesn't necessarily determine the risk it poses to an organization. Attack complexity may also be becoming a less reliable measure of practical risk as AI and nation-state capabilities b…YOUTUBE.COM
25 AugSN 1093: Tokens in the Stream - Why LLMs are inherently insecure and prompt injection will persistTurns out, every chatbot conversation runs on a messy hack at the heart of language models, making prompt injection an unsolved—and possibly unsolvable—security threat. Steve and Leo unravel the research that explains why "roles" in AI aren't what you think they are. Understandin…TWIT.TV
24 AugRansomware attackers are zeroing in on mid-market companiesMid-sized companies accounted for 73% of publicly disclosed ransomware and data-extortion incidents with known revenue in North America and Europe between January 2023 and June 2026, according to Black Kite. The analysis covered 13,336 incidents with known revenue and defined mid…HELPNETSECURITY.COM
24 AugAnthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source FundClaude Security, currently in public beta for Claude Enterprise customers, now runs codebase scans on Mythos 5. The post Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund appeared first on SecurityWeek .SECURITYWEEK.COM
24 AugUAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux RootkitCybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast majority of the targets are located in Brazil, Bo…THEHACKERNEWS.COM
24 Aug7 ways AI can be used to enhance security operationsAI has an almost unlimited number of applications, yet none may be more important than its ability to strengthen enterprise security. AI marks a new era of business transformation in which AI autonomy and innovation converge to redefine how people, processes, and technology inter…CSOONLINE.COM
24 AugSalesforce gave every org the same free scanner. Attackers already know what it misses.A defense every attacker can rehearse against isn't a defense. It's a false sense of security.CYBERSECURITYDIVE.COM
24 AugRethinking Application Security for the AI EraAs AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. The post Rethinking Application Security for the AI Era appeared first on SecurityWeek .SECURITYWEEK.COM
24 AugCriminal Deception in Silicon ValleyInteresting paper : Abstract: With entrepreneurial fraud cases on the rise, we investigate how entrepreneurs carry out criminal deception , employing deceptive means to defraud audiences. Analyzing court data from Silicon Valley ventures and their founders prosecuted for fraud be…SCHNEIER.COM
24 Aug KEVCISA orders urgent patching of actively exploited Zimbra flawThe Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. [...]BLEEPINGCOMPUTER.COM
24 AugWindows Defender’s own driver can leave systems defenselessA Microsoft-signed Windows Defender remediation driver can be repurposed into a kernel-level “operation engine” capable of deleting files, modifying the registry and neutralizing security controls, according to new research from Check Point Research (CPR). The technique does not …CSOONLINE.COM
24 AugCybersecurity job ads demanding AI skills double in a yearJob postings asking for AI skills in cybersecurity have doubled in a single year in G7 countries according to new research from the Cisco-founded AI Workforce Consortium. Analysis from recruitment firms Cornerstone and Indeed covering 24 months, from April 2024 to March 2026, spa…HELPNETSECURITY.COM
24 AugShinyHunters provided no real proof they hacked ReliaQuest– because they didn’t get anywhere: ReliaQuestYesterday, DataBreaches reported that ShinyHunters had added ReliaQuest to its dedicated leak site, but without any substantive proof — only a few screenshots showing access to a user account on reliaquest.okta[.]com/enduser/settings. ReliaQuest did not reply to DataBreaches’ ema…DATABREACHES.NET
24 AugShipping More AI Code Than You Can Secure? Watch How to Control Remediation DebtIf your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work. The harder part is what comes after. AI can also introduce open-source packages at a pace your security team was never bui…THEHACKERNEWS.COM
24 AugPersonal Information Exposed in Apollo Global Data BreachEduard Kovacs reports: Private equity giant Apollo Global Management has disclosed a data breach that exposed sensitive personal information. According to a data breach notice sent to affected individuals, a social engineering attack enabled threat actors to access some of the co…DATABREACHES.NET
24 AugGunra ransomware: what you need to knowThe ransomware gang Gunra has been creating havoc - exploiting unpatched VPNs and firewalls to steal data, encrypt systems, and extort victims across healthcare, finance, manufacturing, and more. Read more in my article on the Fortra blog.FORTRA.COM
24 AugSuspected Iran-linked attack knocked UK power plant offline for daysNews that suspected Iranian hackers caused the shutdown of a British power plant broke over the weekend, raising the question of whether UK’s power grid and, indeed, the country’s critical infrastructure can fend off destructive cyber attacks. According to sources of …HELPNETSECURITY.COM
24 AugVU#728712: Konami's Metal Gear Online 3 contains a heap-based buffer overflowOverview Konami's Metal Gear Online 3 video game contains a heap-based buffer overflow that can be triggered by an input‑validation vulnerability that allows match hosts to remotely execute arbitrary code on lobby members' machines through specially crafted data. Description Meta…KB.CERT.ORG
24 Aug⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and MoreA package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks th…THEHACKERNEWS.COM
24 AugHouse Democrats ask GAO to study CISA workforce cutsFive lawmakers serving on the Homeland Security Committee said Congress didn’t know enough about the Trump administration’s changes to the cybersecurity agency.CYBERSECURITYDIVE.COM
24 AugThe Vulnerability Gap: Why Discovery Is Outrunning RepairAI is discovering more vulnerabilities, faster, and under a tightening regulatory environment, making this an all-hands-on-deck moment for the cybersecurity community.DARKREADING.COM
24 AugFake GTA 6 Extended Look and demo sites deliver an infostealerBogus “Play Now” sites are exploiting the GTA 6 leak hype to spread malware that steals passwords stored in browsers.MALWAREBYTES.COM
24 AugIndian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderlyA Jersey City resident is facing charges for his alleged role as a money mule for overseas cyberscammers who stole millions from elderly New Yorkers.THERECORD.MEDIA
24 Aug“Cognizable damage” required for data breach claims, MA appeals court says in a firstChristopher R. Deubert of Constangy, Brooks, Smith & Prophete, LLP writes: Helpful guidance for businesses, and for Massachusetts state courts. In 2021, the U.S. Supreme Court held in TransUnion, LLC v. Ramirez that in a suit for damages, “the mere risk of future harm, withou…DATABREACHES.NET
24 AugAlabama launches investigation into OpenAI’s hack of Hugging FaceWeeks after OpenAI disclosed that one of its cybersecurity models had gone rogue and hacked AI dataset company Hugging Face, Alabama’s Attorney General announced an investigation into the incident.TECHCRUNCH.COM
24 AugAI Found Its Own VulnerabilityThe discussion covers a vulnerability created by AI that was later exploited by AI. After Wiz identified the issue and notified Snowflake’s security team, a patch was released the same day, followed by a JIRA token rotation. AI could accelerate both sides of the security equation…YOUTUBE.COM
24 AugHackers target WordPress sites in miniOrange auth bypass attacksHackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]BLEEPINGCOMPUTER.COM
24 AugAscent Skilled Nursing Facilities Assure Breach Victims of “Credible Evidence” Stolen Data Was DeletedA DataBreaches.net Commentary On July 31, Asheville Beaverdam NC Opco LLC d/b/a Bear Mountain Health and Rehabilitation, Asheville Victoria NC Opco LLC d/b/a Elevate Health & Rehabilitation, and Asheville US Seventy NC Opco LLC d/b/a Swannanoa Valley Health and Rehabilitation…DATABREACHES.NET
24 Aug KEVThe odds were classified.Polymarket traders win big on U.S. military insider information. Slovakia deactivates speed cameras with Russian backdoors. TikTok pays $400 million to settle kids' privacy allegations. Hackers infect Android-based car systems with botnet malware. CISA orders quick patching of an…THECYBERWIRE.COM
24 AugUnpatched Calix flaw lets hackers bypass NAT to expose internal devicesAn unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet. [...]BLEEPINGCOMPUTER.COM
23 AugShinyHunters claims hack of ReliaQuest but provides no proofCybersecurity firm ReliaQuest has reported its research findings about ShinyHunters multiple times recently. On August 17, @ReliaQuestTR tweeted that they were tracking yet another ShinyHunters campaign. But after another forum user replied on August 23 with some screenshots and …DATABREACHES.NET
22 AugAI attacks now move in minutes, not weeks: N-Able's Robert Johnston on the SOC's AI reckoningHow AI Is Reshaping MDR, SIEM, and the SOC: Robert Johnston on Faster Attacks, MSP Security, and What's Next In this Weekend episode of Cybersecurity Today, host David chats with Robert Johnston—former U.S. Marine with experience at Cyber Command, NSA, and the intelligence commun…CYBERSECURITYTODAY.LIBSYN.COM
22 AugCitrix urges immediate patching of two newly disclosed vulnerabilities.Supply chain attack compromises popular Rust library. US states sue Meta over claims that it deliberately addicts young users.THECYBERWIRE.COM
22 AugGolf Canada - 568,972 breached accountsIn mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram. The data included 569k unique email addresses along with names, usernames, dates of birth, genders and approximate geographic locations (city, province and postco…HAVEIBEENPWNED.COM
22 AugCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionA critical flaw (CVSS 9.4) in NASA/JPL’s AIT-GUI let anyone send unauthenticated commands to spacecraft instruments. Cycode researchers found that AIT-GUI, the browser-based operator console in NASA/JPL open-source AMMOS Instrument Toolkit, shipped with no authentication, n…SECURITYAFFAIRS.COM
22 AugYour Expired Visa Card Could Be ‘Zombified’ to Make Contactless PaymentsPlus: Apple sends out an “unprecedented” number of spyware warnings, Ukraine hits a Russian ecommerce giant with cyber and drone attacks, and more.WIRED.COM
22 AugConnecticut says data from 41,000 Medicaid members exposed in portal breach; the second portal incident this yearWSFB reports: State officials say a data breach involving the Connecticut Medicaid program’s provider portal exposed payment and claims information tied to roughly 41,000 HUSKY Health members. The Connecticut Department of Social Services said Gainwell Technologies, which serves …DATABREACHES.NET
21 Aug KEVNSA warns AI exploits target power and water, Android malware leaks data via nearby phones, ransomware's sweet spotNSA Warns AI-Generated Exploits Target US Critical Infrastructure + New Android Malware "Manic" + Ransomware's Mid-Market Focus In this episode of Cybersecurity Today, sponsored by NordLayer, the NSA and FBI warn of an active campaign using AI-generated exploit tools to probe US …CYBERSECURITYTODAY.LIBSYN.COM
21 AugRisky Bulletin: US warns of AI-assisted attacks against Siemens PLCsThe US warns of AI-aided attacks against Siemens PLCs, hackers breach Latvia’s road traffic agency, a new hacking tool enrolls an attacker’s passkey to your account, and academics find source code overlaps between Geedge devices and China’s Great FirewallRISKY.BIZ
21 AugNew infosec products of the week: August 21, 2026Here’s a look at the most interesting products from the past week, featuring releases from F5 Networks, Intezer, Netscout, and Tufin. NETSCOUT expands Adaptive DDoS Protection with outbound attack mitigation NETSCOUT has announced an extension of its Adaptive DDoS Protection (ADP…HELPNETSECURITY.COM
21 AugA $25 template helped scammers build hundreds of phantom bank domainsA phrase on a suspicious website turned into an investigation of phantom banks built to support scams, according to new research from Allure Security. Molly DeQuattro, the company’s VP of Operations, was reviewing a domain that resembled the brand of one of its financial se…HELPNETSECURITY.COM
21 AugNearly half of enterprises have no one leading PQC migrationEnterprises believe they are prepared for the security challenges posed by quantum computing, but gaps in ownership, testing and visibility could complicate their transition to post-quantum cryptography (PQC), according to new research from Axiad. Who owns PQC migration? (Source:…HELPNETSECURITY.COM
21 AugCybersecurity Job Ads Requiring AI Skills DoubleAn analysis by the AI Workforce Consortium found that technical cybersecurity jobs are becoming more strategic due to the influence of AIINFOSECURITY-MAGAZINE.COM
21 AugCISA Urges Immediate Patching of Exploited TrueConf VulnerabilitiesThe Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware. The post CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
21 AugCl0p Targets 40+ Organizations Through PTC Windchill FlawCl0p claims over 40 organizations fell victim to attacks exploiting a PTC Windchill and FlexPLM vulnerability. Cl0p is using a familiar strategy again: exploit one flaw in enterprise software to attack many companies, then publish the victims’ names if they refuse to pay. The gro…SECURITYAFFAIRS.COM
21 AugAI threats are everywhere. A risk-first CISO decides what to prioritizeThe good news? AI gives cyber defenders some of the best discovery tooling they’ve ever had. The bad news? It gives attackers the same capability. This duality has left CISOs managing AI on two simultaneous fronts. Outside the organization, attackers are using AI to make phishing…CSOONLINE.COM
21 AugRansomware takes aim at enterprise resilienceRansomware remains one of the most disruptive cyber threats organizations face. Companies have strengthened their cyber defenses over the years, but attackers in 2026 have become faster, more targeted, and increasingly reliant on AI , forcing the need for a change in how organiza…CSOONLINE.COM
21 AugMicrosoft Rolls Out 22 Fresh Security PatchesMost of the fixes resolve code execution, privilege escalation, and information disclosure vulnerabilities. The post Microsoft Rolls Out 22 Fresh Security Patches appeared first on SecurityWeek .SECURITYWEEK.COM
21 AugMore Incidents of AIs Going Rogue in Cybersecurity ChallengesThe AI Security Institute has a new report of AI systems engaging in “unsanctioned behavior”—what I have been calling “ genie behavior —while being tested on their cybersecurity capabilities. The incident stemmed from a single evaluation where agents…SCHNEIER.COM
21 AugBackdoored Rust packages hit crates.io, exposing developers to malware at build timeMalicious versions of three Rust packages, including the widely used arrayref, were published to the crates.io registry on August 20, carrying a backdoor that executed automatically when affected projects were compiled. Security researchers at Wiz said the attack also shares infr…CSOONLINE.COM
21 AugMicrosoft warns of max severity Entra ID flaw exploited in attacksMicrosoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited in attacks. [...]BLEEPINGCOMPUTER.COM
21 AugAttackers impersonate popular AI brands to spread malwareAttackers are impersonating popular AI brands like Perplexity, Claude, ChatGPT, and Copilot to spread information stealers, backdoors, malicious browser extensions, and other malware, according to Sophos. Overview of MDR cases with AI involvement (Source: Sophos) Sophos X-Ops rev…HELPNETSECURITY.COM
21 Aug KEVCISA orders feds to patch actively exploited TrueConf Server flawsThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform. [...]BLEEPINGCOMPUTER.COM
21 AugCritical Isolated-vm Vulnerability Leads to RCE on HostThe type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process. The post Critical Isolated-vm Vulnerability Leads to RCE on Host appeared first on SecurityWeek .SECURITYWEEK.COM
21 AugScammers Pose as NYPD Officers in “Well-Done” Video-Call Impersonation ScamThe phone rang, and when “Eddie” (not his real name) picked up, the caller identified herself as being from American Express. Even though Eddie didn’t have any American Express account, he wasn’t initially suspicious. According to the caller, Eddie’s…DATABREACHES.NET
21 AugAI, Data Breaches, and an Old Lesson from the Law of BailmentSo I didn’t know what the doctrine of bailment is. If you don’t either, you may want to read this post by Jake L. Ramsey of Offit Kurman. It starts by noting the presentation at BlackHat by two OpenAI engineers about the Hugging Face incident and notes two of their st…DATABREACHES.NET
21 AugSix Maximum-Severity Flaws Found in Cisco ProductsCisco patched nine critical flaws, including six rated CVSS 10.0, found during internal testing. None are known to be exploited. Cisco released another batch of security fixes for its Crosswork platforms and Secure Workload software, part of what it’s calling an ongoing int…SECURITYAFFAIRS.COM
21 AugAWS EKS forensics: data sources and investigation toolingInvestigating a compromise in Amazon EKS means piecing together evidence spread across three layers: the managed Kubernetes control plane, the worker nodes, and the surrounding AWS services. This article maps the data sources an EKS cluster exposes for digital forensics and threa…SYNACKTIV.COM
21 Aug KEVCISA warns of actively exploited TrueConf vulnerabilities.Supply chain attack compromises popular Rust library. Data giant Alation discloses a cyberattack.THECYBERWIRE.COM
21 AugMicrosoft confirms maximum severity flaw in Entra ID targeted for exploitationThe company said the remote-code execution vulnerability has been fully mitigated and no further action is necessary.CYBERSECURITYDIVE.COM
21 AugMicrosoft Defender's Own Driver Can Be Weaponized to Delete Security Software at BootCheck Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software fl…THEHACKERNEWS.COM
21 AugTroutman Pepper Locke Silent as Threat Actors Leak Client Data, Tens of Thousands of SSNsIn April, Silent Ransom Group’s (SRG)* leak site listed 38 law firms that had not paid them and whose data was leaked. By June 29, there were 48 law firms. Now there are 64, and, in somewhat surprising claims, SRG says a recent attack was actually its second on one law firm…DATABREACHES.NET
21 AugYour Shredded Visa Card May Still Work at the CheckoutUMass Amherst researchers showed expired Visa contactless cards can make real purchases by exploiting an unsigned expiry field in Visa’s EMV kernel. Researchers at the University of Massachusetts Amherst demonstrated at USENIX Security 2026 in Baltimore that expired Visa co…SECURITYAFFAIRS.COM
21 AugThe guest nobody invited.CISA orders patching of TrueConf Server vulnerabilities. LockBit threatens release of stolen banking data. Researchers disclose a critical type confusion vulnerability in a Node.js library. A new Agent Tesla v4 campaign introduces enhanced evasion techniques. A novel malware deli…THECYBERWIRE.COM
20 AugCloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/SecondCybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second, 360 times the rate of an earlier attack demonstr…THEHACKERNEWS.COM
20 AugOpenAI ‘temporarily slows’ scaling efforts, also promises zero data retention for select frontier model customersOpenAI this week announced multiple moves designed to counter negative perceptions of its security and privacy, saying it had slowed its pace of scaling, implemented a two-week pause in reinforcement learning, and will be offering zero data retention for “eligible API customers.”…CSOONLINE.COM
20 Aug8,539 reasons to rethink how vulnerabilities get patchedThe window for responding to newly disclosed security flaws is getting shorter. Exploit code can appear quickly, exploitability can be tested soon after disclosure, and organizations have a growing number of weaknesses to sort through. Rapid7’s Q2 2026 Threat Landscape Report cou…HELPNETSECURITY.COM
20 AugAirlock Digital Completes Independent IRAP Assessment at the PROTECTED LevelAirlock Digital, a global provider of application control and allowlisting solutions, today announced that it has completed an independent Information Security Registered Assessors Program (IRAP) assessment at the PROTECTED classification level. The assessment was conducted by an…CSOONLINE.COM
20 AugObjection! That's a scam.This week, while Dave is out, hosts ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Maria Varmazis⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Joe Carrigan⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ are discussing the latest in social engine…THECYBERWIRE.COM
20 AugAI is making fraud harder to spot and identity harder to proveOnline fraud has become a routine concern for consumers and businesses that rely on digital accounts, payments and customer service. Experian’s 2026 U.S. Identity & Fraud Report describes a market where scams extend across messages, websites, documents, voices, images and ac…HELPNETSECURITY.COM
20 AugSrsly Risky Biz: Trump's private hacker memo is the right ideaTom Uren and James Wilson talk about President Donald Trump’s memo enlisting the US private sector to tackle cybercriminals. The initiative gets the big idea right: traditional law enforcement approaches have not worked against cybercriminals so the government has turned to disru…RISKY.BIZ
20 AugExploitation Expected for Critical Authentication Bypass Patched in Citrix NetScalerRemote, unauthenticated attackers could exploit the critical-severity flaw without user interaction. The post Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugIdentity Abuse Through Trusted Communication ChannelsUnit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The post Identity Abuse Through Trusted Communication Channels appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
20 Aug KEVCritical Zimbra RCE flaw now actively exploited in attacksCERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS). [...]BLEEPINGCOMPUTER.COM
20 AugUS agencies warn of AI-powered attacks on Siemens industrial controllersThreat actors are using AI to write exploit scripts targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs) used across water, energy, manufacturing, and other critical infrastructure sectors, according to US federal agencies. PLCs are the small industr…HELPNETSECURITY.COM
20 AugICS Operators Warned of AI-Driven Attacks on Siemens PLCsA US government advisory warned that attackers are deploying AI-generated exploitation scripts against exposed Siemens S7 Series PLCsINFOSECURITY-MAGAZINE.COM
20 AugNASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft CommandsSecurity researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, that allow an unauthenticated attacker to issue arbitrary commands to the software's spacecraft and instrument comman…THEHACKERNEWS.COM
20 Aug40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet SecretsA set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products. According to the Socket Threat Research team, the extensions are part of a broader set of 77 browser add-ons tha…THEHACKERNEWS.COM
20 AugKriminal breaks out of Grok, Claude guardrails at $12.99Security researchers are warning of a criminal AI service built on Grok and Claude, among other models, that promises uncensored access to powerful AI capabilities for as little as $12.99 a month. ThreatDown researchers say “Kriminal” is largely a storefront wrapped around legiti…CSOONLINE.COM
20 AugLargest Applebee’s franchisee says hackers stole sensitive dataApple American Group LLC, a major Applebee’s franchise operator in the United States, has disclosed a data breach incident. The event has reportedly exposed sensitive personal information, including Social Security numbers, financial data, health records, and biometric informatio…CYBERINSIDER.COM
20 AugAI-powered cyberattacks are targeting critical infrastructure in the USUS agencies are warning that threat actors are actively using AI-generated exploitation scripts to target Siemens S7 programmable logic controllers (PLCs) deployed across critical infrastructure. The activity focuses on Internet-exposed and poorly secured industrial systems, with…CYBERINSIDER.COM
20 AugCISA warns of hackers exploiting critical MLflow vulnerabilityThe Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical vulnerability in the MLflow open-source AI engineering platform. [...]BLEEPINGCOMPUTER.COM
20 AugCisco Patches Critical Crosswork, Secure Workload VulnerabilitiesThe flaws could lead to remote code execution, authentication bypasses, and path traversal attacks. The post Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugAI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian HackingAtalanta's Argo product is now being used to prove the resilience of Viasat’s satellite communications network. The post AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugAWS limits AI agents’ data access, even when manipulatedAWS has detailed an approach for propagating user authorization context through AI agents, allowing access controls to be enforced by infrastructure and downstream services rather than relying on the agent itself. Customers using Amazon Bedrock AgentCore can build AI agents that …HELPNETSECURITY.COM
20 AugAtlassian, Splunk Patch Dozens of Critical, High-Severity VulnerabilitiesThe flaws could be exploited to execute arbitrary code, access sensitive information, and elevate privileges. The post Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugMLflow Vulnerability Exploited for Cloud Credential TheftThe critical-severity flaw allows attackers to send HTTP requests to internal endpoints and extract sensitive information. The post MLflow Vulnerability Exploited for Cloud Credential Theft appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugCDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS AmplificationCybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to the websites they front, amplifying a low-bandwidth request stream by up to 350x aga…THEHACKERNEWS.COM
20 AugThe push to designate AI as the next critical infrastructure sectorThe designation would unlock a range of federal services, tools and resources for an industry that policymakers view as increasingly tied to national and economic security. The post The push to designate AI as the next critical infrastructure sector appeared first on CyberScoop .CYBERSCOOP.COM
20 AugBTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation PrimitiveResearch by: Jiří Vinopal (@vinopaljiri) Abstract What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from Ring 0…RESEARCH.CHECKPOINT.COM
20 Aug'Grandoreiro' Malware Resurfaces With Mexico CampaignThe banking Trojan, post-law enforcement takedown, is sprucing itself up with features that make detection and analysis harder.DARKREADING.COM
20 AugLargest Applebee’s franchisee says hackers stole sensitive dataAmar Ćemanović reports: Apple American Group LLC, a major Applebee’s franchise operator in the United States, has disclosed a data breach incident. The event has reportedly exposed sensitive personal information, including Social Security numbers, financial data, health records, …DATABREACHES.NET
20 AugIsolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCECybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the isolated environment. The vulnerability ("GHSA-864f-rcv7-6r…THEHACKERNEWS.COM
20 AugCritical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA ServersCitrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability. According to the cloud computing and virtualization technology company, the issues affect custom…THEHACKERNEWS.COM
20 AugFrequently asked questions about the active threat to Siemens S7 Series PLCsA joint cybersecurity advisory released by multiple U.S. government agencies warns that threat actors are using AI-generated exploitation scripts to target exposed Siemens S7 Series PLCs across critical infrastructure sectors. Key Takeaways Unattributed threat actors are exploiti…TENABLE.COM
20 AugChinese hackers use AI to automate attacks on 170,000 serversA Chinese-speaking cybercrime group is using AI-assisted tooling to automate attacks against vulnerable Windows and Linux web servers worldwide. Tracked as UAT-10147 by Cisco Talos, the threat group targets internet-facing servers for data theft and search engine optimization (SE…CYBERINSIDER.COM
20 AugCritical Elementor Pro bug exposes WordPress sites to RCE attacksA critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server. [...]BLEEPINGCOMPUTER.COM
20 AugNew Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat DataAdversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongoing conversation to an attacker-controlled server after the user asks it to summarize an ordinary we…THEHACKERNEWS.COM
20 AugCitrix urges immediate patching of two newly disclosed vulnerabilities.Federal agencies warn of an active cyber campaign targeting Siemens PLCs. Latvian road traffic agency data breach affects two-thirds of the country's population.THECYBERWIRE.COM
20 AugWhat we know so far about the hacking campaign against US water systemsSupport is growing for stricter oversight and increased financial resources for utilities in the wake of a cyberattack spree, suspected to be the work of Iran-linked threat groups.CYBERSECURITYDIVE.COM
20 AugAI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical InfrastructureThe U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts. The activity is targeting Siemens S7 SeriesProgrammable Logic Controllers (PLCs) to conduct r…THEHACKERNEWS.COM
20 AugThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and MoreA lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hid…THEHACKERNEWS.COM
20 AugMoney and Mindset: The Two Biggest Roadblocks to Cyber PolicingLaw enforcement training is not keeping pace with the volume and rapid evolution of cybercrimes, though officers really only need to learn the basics, but focus and budgets hinder progress.DARKREADING.COM
20 AugCritical flaw patched in popular JavaScript sandbox used in AI projectsA critical sandbox escape vulnerability was discovered and patched in isolated-vm, a library for running JavaScript code inside an isolated process. If exploited, the vulnerability could allow attackers to hijack the host’s control flow, which could enable remote code execution. …CSOONLINE.COM
20 AugWhy the Annual Pentest Can’t Keep Up with Chris Wallis from IntruderChris Wallis, Founder and CEO of Intruder, joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices recorded at Black Hat USA 2026. He discusses why point-in-time pentesting is struggling to keep pace as teams ship software and attackers exploit vulnerabi…THECYBERWIRE.COMHTTPS:
20 AugThe Feynman Bet: Why You Still Won’t Vibe Code Your SIEM (Today)Gemini about this blog The Feynman Betting Strategy and the Inertia of Security Many years ago, I read a book by the legendary quantum physicist Richard Feynman . One story from his time at Los Alamos during the war has always stuck with me. Feynman entertained himself by making …MEDIUM.COM
19 AugCoPilot Snitches on Itself, Hacker leaks Azure data and Texas University deals with cyber attackMicrosoft Copilot CoSnitch Flaw, Alleged Azure Employee Data Leaks, UTSA Cyberattack, and AI "Mind Viruses" The episode covers a one-click flaw in Microsoft Copilot Personal dubbed "CoSnitch," where Varonis Threat Labs says Copilot revealed an undocumented URL parameter that enab…CYBERSECURITYTODAY.LIBSYN.COM
19 AugRisky Business #849 -- Trump will unleash contractors on cybercriminalsOn this week’s show Patrick Gray and James Wilson are joined by guest co-host Dmitri Alperovitch to talk through the week’s news, including: Trump’s memo authorising the private sector to release the cyber hounds is fine, don’t worry! OpenAI finally decides to add a few safety me…RISKY.BIZ
19 AugChatGPT’s new feature could give infostealers a map of your Mac activityOpenAI’s new Computer History feature turns recent Mac computer activity into memories ChatGPT and Codex can use, and it’s raising questions about privacy and security along the way. Computer History (Source: OpenAI) What Computer History does Computer History builds …HELPNETSECURITY.COM
19 AugBanks look for fraud signals in customer behaviorBanks are dealing with more fraud in which customers authorize payments after being manipulated by criminals. ThreatMark’s Fraud Readiness Benchmark 2026 describes a banking environment where social engineering, reimbursement requirements and growing case volumes are changing fra…HELPNETSECURITY.COM
19 AugRisky Bulletin: Slovakia finds Russian backdoors on its speed camerasSlovakia finds Russian backdoors on its speed cameras, French police used a public exploit to hack EncroChat, Microsoft delays Exchange updates due to a deluge of AI bugs, and a ransomware-affiliate poses as a data recovery firm.RISKY.BIZ
19 AugCyberattack forces UT San Antonio to delay start of fall semesterThe University of Texas at San Antonio pushed back the start of its fall semester by three days after a cyberattack targeted its academic network over the weekend. Classes that were due to begin on Wednesday, August 19 will now start on Monday, August 24. UT San Antonio is one of…HELPNETSECURITY.COM
19 AugF5 enhances AI Gateway to control AI costs, access, and securityF5 has introduced enhancements to the F5 AI Gateway and integrated the solution into the F5 AI Security Platform. The enhanced F5 AI Gateway seamlessly enforces policies on every AI request, giving enterprises a unified control plane to govern how AI models, agents, and tools are…HELPNETSECURITY.COM
19 AugMost organizations aren’t ready for a Hugging Face-level eventThe National Security Agency (NSA) and Central Security Service recently published an advisory statement on behalf of the Five Eyes Cyber Security Agencies, warning that AI technologies are making it easier than ever for would-be malicious actors to infiltrate and compromise sens…CSOONLINE.COM
19 AugCISOs are struggling to threat-model AI. Can 15-minute sessions help?A few weeks ago, on a busy day, threat-modeling expert Adam Shostack opened an email from a client. Someone at that organization had vibe-coded an app and put it to work with customer data. Now, the client wanted to know what risks the tool posed. And what it should do about them…CSOONLINE.COM
19 AugPreventing a Breakout as AI Agent Threats Is One of Three Top CISO Concerns - Rob Allen - BSW #461Artificial intelligence has quickly evolved from a productivity tool into an active participant in many organizations' daily operations. As organizations give AI greater autonomy within their environment, they're also granting them access to sensitive systems and data. That creat…YOUTUBE.COM
19 AugChrome, Firefox Updates Patch Dozens of VulnerabilitiesThe bugs could lead to code execution, privilege escalation, sandbox escape, and information disclosure. The post Chrome, Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
19 AugOpenAI puts major frontier AI training run on hold over cyber risksOpenAI temporarily paused reinforcement learning (RL) training on its latest models intended for deployment for two weeks while it hardened and red-teamed research environments and expanded monitoring. “Our largest planned frontier RL run remains on hold while we conduct smaller-…HELPNETSECURITY.COM
19 Aug943 Patches Rolled Out With Oracle’s August 2026 Security UpdateThe fixes resolve over 1,000 vulnerabilities across two dozen products, including over 460 remotely exploitable bugs. The post 943 Patches Rolled Out With Oracle’s August 2026 Security Update appeared first on SecurityWeek .SECURITYWEEK.COM
19 AugGoogle’s AI security agents found 100+ critical software vulnerabilities in just two daysGoogle’s Mandiant has disclosed the workings of an internal tool that uses chains of AI agents to hunt for vulnerabilities in source code, saying it found over 100 verified, high-severity flaws in just two days during a live investigation into stolen corporate repositories.…HELPNETSECURITY.COM
19 AugUpdate Chrome now: Two critical vulnerabilities fixedGoogle has released a Chrome desktop update fixing 15 security vulnerabilities, including 2 buffer overflow flaws rated critical.MALWAREBYTES.COM
19 Aug KEVCritical RCE flaw in Windows IKE Extension now actively exploitedThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component. [...]BLEEPINGCOMPUTER.COM
19 AugCISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple VulnerabilitiesThe flaws can be exploited for remote code execution, authentication bypass, and device takeover. The post CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
19 AugSnowflake flaw slips past AI checks, gets exploited by another AIAn autonomous AI security agent developed by cloud security firm Wiz identified and exploited a critical vulnerability in Snowflake’s GitHub Actions pipeline, while GitHub Copilot had previously reviewed the code change without flagging the flaw. The vulnerable code was part of a…CSOONLINE.COM
19 AugNIST Releases Tips &amp; Tactics for Building Automation &amp; Control System CybersecurityRecent cyberattacks highlight the growing threat to operational technology (OT) used in critical infrastructure. Whether you work for an infrastructure owner/operator or are a consumer of an infrastructure service, the events of the past few weeks have made it clear that cybersec…NIST.GOV
19 AugServer Mistake Exposes StopAndProtect’s Hacked WordPress NetworkWaqas reports: A server mistake by cybercriminals has exposed the inner workings of a global malware operation that used nearly 2,000 hacked WordPress websites to infect computers, steal files and deploy ransomware. Check Point Research identified the operation as StopAndProtect …DATABREACHES.NET
19 AugHackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2PCybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique. The activity,…THEHACKERNEWS.COM
19 AugPassword spraying attacks surge 155x as hackers exploit MFA gapsHuntress observed a 155x increase in password spraying attacks in H1 2026, including a campaign that generated more than 81 million login attempts in two weeks. The attacks exploited legacy authentication and gaps in MFA policies that left some login flows unprotected. [...]BLEEPINGCOMPUTER.COM
19 AugDOJ secures indictment of 17 Iranians accused of ‘massive’ cyber theft campaignMax Rego reports: The Department of Justice (DOJ) on Tuesday unsealed an indictment charging 17 Iranian nationals with targeting American and foreign institutions via a cyber theft campaign on behalf of Iran’s Islamic Revolutionary Guard Corps (IRGC). The 14-count indictment char…DATABREACHES.NET
19 AugBeware the Ransomware Rescuer: Ransom BustersJustin Timothy reports: The GuidePoint Research and Intelligence Team (GRIT) has responded to several recent ransomware incidents in which victims received an unexpected email from an ostensible third-party entity referring to itself as “Ransom Busters.” In these messages, the th…DATABREACHES.NET
19 AugThe long tail of Clop’s PTC hack is just beginning to emergeThe data theft extortion group likely compromised a critical vulnerability affecting PTC’s product lifecycle management software in June, a month before it sent threatening emails to victims. The post The long tail of Clop’s PTC hack is just beginning to emerge appeared first on …CYBERSCOOP.COM
19 AugPrison for data analyst who tried to extort $2.5 million from his employerThere’s an update to a previously reported case of a disgruntled former employee who tried to extort his employer, Brightly Software. Graham Cluley reports: When Cameron Curry discovered that his contract as a data analyst wasn’t going to be renewed, he could have upd…DATABREACHES.NET
19 AugExclusive: Linux Foundation's Akrites to Go Live in SeptemberThe Linux Foundation's Akrites initiative will become operational in September, when it will begin accepting AI-powered vulnerability reports for open-source projectsINFOSECURITY-MAGAZINE.COM
19 AugFirefox 154 blocks silent WebSocket access to local network devicesMozilla has released Firefox 154 with expanded protections against websites connecting to devices on local networks, new AI-assisted tab organization, and support for NVIDIA GeForce NOW on Windows. The latest update also addresses 58 CVE entries, including multiple high-severity …CYBERINSIDER.COM
19 AugSo Is Your SOC AI-Ready? Part 3: API or Die Audit!This is Part 3 of the AI-ready SOC series ( Part 1 , Part 2 ), and it is focused on validating readiness for pillars #1 (SOC Data Foundations) and #4 (Modern SOC Technology Stack). Specifically, it is about the audit I promised in Part 2 : “The ‘API or Die’ Data Audit: You need t…MEDIUM.COM
19 AugThe AI Was the Route InSeveral recent security incidents and research demonstrations involve attackers manipulating AI assistants and connected systems that already have legitimate access to organizational data or infrastructure. The AI doesn't always have to be the target. If an assistant can read log…YOUTUBE.COM
19 AugNSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technologyThe National Security Agency (NSA), FBI and other federal agencies said the campaign is targeting Siemens S7 Series PLCs and was being fueled by “AI-assisted development” alongside exploitation of known vulnerabilities.THERECORD.MEDIA
19 AugUS warns of AI-powered attacks on Siemens PLCs in critical infrastructureU.S. cybersecurity agencies warn that threat actors are using AI-generated scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) in U.S. critical infrastructure. [...]BLEEPINGCOMPUTER.COM
19 AugOpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI BehaviorOpenAI on Tuesday revealed that it paused reinforcement learning (RL) training for its latest artificial intelligence (AI) models for two weeks while it shored up additional defenses and increased the scope of its monitoring to avert another Hugging Face-like incident. "As models…THEHACKERNEWS.COM
19 AugHackers hiding in plain sight.Medusa’s reach grows. Cl0p expands its victim list. The DOJ charges 17 alleged Iranian hackers. CISA sounds the alarm on four exploited vulnerabilities. TWINLOOT hides in plain sight inside Microsoft 365. Maria Varmazis shares the latest from the space-cyber realm as Ukraine stri…THECYBERWIRE.COM
19 AugSakura Internet hack exposes data of up to 1.36 million accountsJapanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. [...]BLEEPINGCOMPUTER.COM
19 AugHealthtech firm CareCloud data breach impacts 3.7 million patientsU.S. healthcare IT company CareCloud disclosed that the data breach incident it suffered earlier this year has impacted more than 3.7 million individuals. [...]BLEEPINGCOMPUTER.COM
18 AugSnowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command InjectionCybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow co…THEHACKERNEWS.COM
18 AugOpenAI president’s blog pushing agentic AI most notable for what it did not sayOpenAI president Greg Brockman on Sunday warned enterprise CISOs that they need to more aggressively embrace agents if they want to survive upcoming cyberattacks. Brockman said in a blog post that it has become “increasingly clear” that company systems are hiding “significant fla…CSOONLINE.COM
18 AugCybersecurity jobs available right now: August 18, 2026CISO ADI Global Distribution | USA | Hybrid – View job details As a CISO, you will develop and lead ADI’s global security strategy to protect information assets, digital platforms, critical operations, and AI-enabled environments. Advise executives and the Board o…HELPNETSECURITY.COM
18 AugAttackers turn to AI for help identifying files worth stealingAI tools are being used by cyber attackers to write malicious code, build tools that harvest credentials, search compromised networks, identify valuable business information, manage technical infrastructure and generate commands during intrusions. Gambit Security researchers exam…HELPNETSECURITY.COM
18 AugGoogle’s open-source HEIR lets AI work with data it can’t seeGoogle’s researchers and engineers developed the Homomorphic Encryption Intermediate Representation (HEIR) compiler project, an open-source compiler toolchain and development platform for homomorphic encryption. It can convert pre-trained AI models designed to operate on unencryp…HELPNETSECURITY.COM
18 AugDozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security UpdatesThe bugs could be exploited to crash Safari, corrupt memory, leak sensitive data, escape the sandbox, and exfiltrate data. The post Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates appeared first on SecurityWeek .SECURITYWEEK.COM
18 Aug KEVCISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCEThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Ray is an open-source, Python-native distributed computing framework design…THEHACKERNEWS.COM
18 AugNew Mirai-Based Evooo1Bot Botnet Targets Linux DevicesEvooo1Bot is a Mirai-based Linux botnet that hijacks routers and IoT devices for DDoS attacks, credential theft and criminal proxy services. Fortinet’s FortiGuard Labs disclosed Evooo1Bot in mid-August, a previously undocumented Linux botnet that’s been active since J…SECURITYAFFAIRS.COM
18 AugWhat you say during a cyber breach can — and will — be used against youThe first 24 hours after a cyber incident are messy. Teams are moving fast, and a lot gets said on Slack or email that can come back later. People are scrambling to contain the issue, figure out what happened and keep things moving. In the process, they create a record that doesn…CSOONLINE.COM
18 AugAI can find zero-days but still can’t reliably write secure codeIn recent months, LLMs have gone from flooding open-source projects and bug bounty programs with questionable security reports that wasted developers’ time, to routinely finding zero-day flaws that humans and traditional security audit tools had missed for years — a rapid evoluti…CSOONLINE.COM
18 AugGitLab Patches Critical Code Injection VulnerabilityThe security defect allows unauthenticated attackers to modify or delete user data and public projects. The post GitLab Patches Critical Code Injection Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
18 AugSafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 CustomersSafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware wallet maker said all affected customers were notified individ…THEHACKERNEWS.COM
18 AugAugmenting Threat Intel Analysis with Agents - ASW #396All sorts of cybersecurity disciplines are adopting agents to help humans save time and automate routine activities. Sai Kiran Uppu describes his work on creating a platform for agents to analyze external threat intel, examine internal systems, and present triage decisions to ope…YOUTUBE.COM
18 Aug KEVCISA: Windows Task Host flaw now exploited by ransomware gangsThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April. [...]BLEEPINGCOMPUTER.COM
18 Aug16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto WalletsCybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of pac…THEHACKERNEWS.COM
18 AugOne Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco. The activity, which Reco has named the City Foru…THEHACKERNEWS.COM
18 AugNew Malware turns Microsoft cloud into its control centerSecurity researchers are warning of a newly uncovered Python malware framework that routes much of its command-and-control (C2) activity through Microsoft services that defenders already expect to see. The Ontinue Cyber Defense Center discovered the implant while investigating an…CSOONLINE.COM
18 AugAI-powered vulnerability clearinghouse faces deep skepticism, major challengesThe U.S. government’s promises about the “Gold Eagle” coordination program are overblown, experts said, but the initiative could help organizations prioritize patching and mitigation.CYBERSECURITYDIVE.COM
18 AugGoogle’s $10,000 refund test shows why AI agents need zero trustGoogle’s open-source autonomous Customer Support & Returns Agent, built using the Agent Development Kit (ADK) and Gemini, demonstrates how developers can apply zero-trust security principles to AI agents that interact with sensitive systems and take real-world actions. The p…HELPNETSECURITY.COM
18 AugAI-Driven Vulnerability Surge Breaks the Traditional Patching ModelRapid7 warns that traditional patch cycles cannot keep pace with soaring vulnerability disclosures and faster exploitation, forcing defenders to prioritize exposure over severity scores. The post AI-Driven Vulnerability Surge Breaks the Traditional Patching Model appeared first o…SECURITYWEEK.COM
18 AugTWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across NetworksCybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. "TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services," On…THEHACKERNEWS.COM
18 AugNETSCOUT expands Adaptive DDoS Protection with outbound attack mitigationNETSCOUT has announced an extension of its Adaptive DDoS Protection (ADP) solution enabling service providers to automatically detect and mitigate outbound DDoS attack traffic. By extending protection from the attack target towards its source, NETSCOUT helps operators prevent com…HELPNETSECURITY.COM
18 AugNew Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cyclesYou can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers. The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compre…RAPID7.COM
18 AugEnterprise Applications Carry 4.31x More Critical and High VulnerabilitiesEnterprise software creation has accelerated as vulnerability levels rise, Sonatype findsINFOSECURITY-MAGAZINE.COM
18 AugUniversity of Texas forced to take systems offline in San Antonio after cyberattackThe University of Texas at San Antonio, which serves 40,000 students across six campuses, said its IT team identified threat activity on its academic campus over the weekend and took some systems, including phones, offline in response.THERECORD.MEDIA
18 AugMicrosoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected AppsVaronis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copilot session. The flaws, which the research…THEHACKERNEWS.COM
18 AugAttackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and SecretsTwo critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation effort…THEHACKERNEWS.COM
18 AugYour LLM Might Find Missing LogsLLM agents can do more than generate security queries. They can analyze available data sources and point out potential gaps, including log sources that aren't currently being ingested. That can help security teams build a more complete picture of their infrastructure. But the mod…YOUTUBE.COM
18 AugCISOs Break Their Silence in 'Declassified' DocuseriesMillion-dollar heists, divorce, and career-ending burnout are all stories told in the latest docuseries revealing a behind-the-scenes look at the cybersecurity community.DARKREADING.COM
18 AugImplement custom authentication for tools integration using request Lambda interceptor in AgentCore GatewayWhen deploying AI agents with Amazon Bedrock AgentCore, organizations benefit from built-in modern support for OAuth 2.0, AWS Identity and Access Management (IAM), and API key authentication through Amazon Bedrock AgentCore Gateway. However, some enterprise environments still use…AWS.AMAZON.COM
18 AugFake it till you exfiltrate it.A fake consultancy fronts an alleged Chinese spy campaign. Meta heads to court over claims it hooked young users. Researchers crack the mystery behind the French EncroChat hack. CISA warns ransomware gangs are exploiting a Windows flaw. Meet C2Looper, a new Rust-based backdoor. A…THECYBERWIRE.COM
18 AugClop Claims Data Theft From More Than 40 CompaniesTiffany Wang reports: A prolific Russian-speaking extortion group known for supply-chain attacks claimed to have stolen data from more than 40 firms including heavyweight corporations such as oil giant Shell and manufacturer General Electric. The group, Clop, is the main suspect …DATABREACHES.NET
18 AugMedusa ransomware tallies hundreds of new victims, says updated advisory on group’s tacticsTim Starks reports: The ransomware-as-a-service group Medusa has adopted fresh tactics to gain access and added hundreds of victims in a little more than a year, according to an updated U.S. government advisory published Tuesday. The gang is relying on access brokers,compensating…DATABREACHES.NET
18 AugOracle August 2026 Critical Security Patch Update Addresses 925 CVEsOracle addresses 925 CVEs in its August 2026 Critical Security Patch Update with 943 patches, including 154 critical updates. Key Takeaways The August 2026 Critical Security Patch Update (CSPU) contains fixes for 925 unique CVEs in 943 security updates 154 issues (16.3% of all pa…TENABLE.COM
18 AugSN 1092: Restraint Abliteration - Rotating Keys, Broken GuardrailsFrom autocorrect to full-fledged conversationalists, discover how a few tweaks transformed language models—and why understanding this shift exposes urgent questions about AI safety and control. Trusting an open source AI proxy might bite you. France's under-15 social media ban hi…TWIT.TV
17 AugSponsored: What npm 12 fixes… and what it doesn’tIn this Risky Business sponsored interview, Casey Ellis chats with Socket founder Feross Aboukhadijeh about npm 12’s move to disable install scripts by default. Attackers are already shifting payloads into package source code, and Feross explains why teams need to understand what…RISKY.BIZ
17 AugHazmat: Open-source containment for AI agentsHazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code, Codex, OpenCode, Cursor Agent, and several more, plus any script you write yourself. An agent launched the ordinary way runs as …HELPNETSECURITY.COM
17 AugRisky Bulletin: The EU publishes its upcoming cybersecurity standardsThe EU publishes its upcoming cybersecurity standards, hackers breach France’s tax agency, threat actors exploit a GeoServer zero-day hours after disclosure, and an exploit unlocks old AMD CPUs with one instruction.RISKY.BIZ
17 AugWhat the CISO role will look like in 2029Wolfgang Goerlich has spent his career in security and has been a CISO for the past seven years. Like many long-term security execs, Goerlich has seen plenty of changes within the profession. He’s bracing for more. “For the future I see growing the role of CISO to be the pacesett…CSOONLINE.COM
17 AugSandbox Escapes with Rubrik's Zero Labs, AI recorders eroding privacy, and the news - ESW #472Interview with Jon Hladik - ChatMate Imagine a user asks an LLM a question about a document. An attacker then gains an interactive prompt on the user’s chat session, enabling the attacker to instruct the AI assistant to take actions on behalf of the victim. That is exactly the ca…YOUTUBE.COM
17 AugRecent macOS Screen Sharing Vulnerability Exploited in AttacksThreat actors gained root access to the vulnerable systems and deployed a Monero miner. The post Recent macOS Screen Sharing Vulnerability Exploited in Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
17 AugPolice bust cybercrime ring accused of stealing €30 million in four-day spreeGerman and Brazilian police dismantled an international bank fraud ring blamed for a €30 million cyberattack on a German financial institution, arresting four people in Brazil and pursuing three more suspects in Spain and Bulgaria. Brazilian police named the operation “Klon…HELPNETSECURITY.COM
17 Aug40,000 Impacted by SafePal Data BreachHackers exploited a vulnerability in the order-tracking function of a plugin to access SafePal customer information. The post 40,000 Impacted by SafePal Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
17 AugEvooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 ProxiesCybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies. "While the malware reuses the DDoS engin…THEHACKERNEWS.COM
17 AugFrench tax authority data breach affects 678,000 individualsThe French Ministry of the Economy and Finance has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems and stole data belonging to 678,000 individuals. [...]BLEEPINGCOMPUTER.COM
17 AugSafePal breach affects 39,798 customers, data allegedly for saleCryptocurrency wallet maker SafePal disclosed a data breach that exposed order information for 39,798 customers, including names, email addresses, shipping addresses, phone numbers and purchase details. The company traced the exposure to an authorization flaw in a plug-in used fo…HELPNETSECURITY.COM
17 Aug KEVUpdate your Mac: Screen Sharing vulnerability exploited in the wildAttackers are exploiting a Mac Screen Sharing vulnerability to gain root access and install Monero cryptominers.MALWAREBYTES.COM
17 AugUnisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel AccessSecurity researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the chipset maker. The advisory, published August 17, 2026, i…THEHACKERNEWS.COM
17 AugZhipu says new coding AI developed advanced cyber skills faster than expectedChinese AI developer Zhipu has launched GLM-5.3, a new coding-focused AI model that the company says has developed unexpectedly strong cybersecurity capabilities, putting it close to global leading models in vulnerability discovery while remaining behind them on deeper exploitati…CSOONLINE.COM
17 AugUkraine says cyberattack hit Russian e-commerce giant Wildberries amid drone strikesUkraine’s military intelligence claimed it disrupted the operations of Russia’s largest online marketplace, Wildberries, in a cyberattack intended to amplify the impact of drone strikes on the company’s infrastructure.THERECORD.MEDIA
17 AugIrregular Details How a Naming Error Let AI Models Attack a Real CompanyThe AI security testing firm has shared information on a recently disclosed incident involving Anthropic AI models. The post Irregular Details How a Naming Error Let AI Models Attack a Real Company appeared first on SecurityWeek .SECURITYWEEK.COM
17 Aug⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and MoreThe expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than the original compromise. A lot of it came down to a…THEHACKERNEWS.COM
17 AugWhy data quality dictates security operations successAs AI takes on more security operations center (SOC) workflows to automate threat triage, indicator extraction, and incident report generation, security operations leaders face a persistent question: Does SOC performance depend more on the large language model (LLM) deployed or o…CSOONLINE.COM
17 AugOperation ASTERIX: Anatomy of a Crypto Fraud PipelineOperation ASTERIX overview Rapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing sc…RAPID7.COM
17 AugWiz Red Agent Finds Its Way Into Snowflake’s Internal Jira Due to an AI-Generated GitHub Copilot “Autofix”Wiz Red Agent independently discovered and exploited a GitHub Actions vulnerability introduced by GitHub Copilot Autofix, validated access to sensitive data in Snowflake’s internal Jira, and assessed the blast radius—all without human intervention.WIZ.IO
17 AugMore than 2 million user records from TaxAct allegedly acquired; 450k already leakedOn August 13, DataBreaches was contacted anonymously on Signal by someone reporting that they had acquired more than 2 million records with clients’ phone numbers, usernames, and email addresses from TaxAct, which is owned by Cinven. TaxAct operates under its parent company…DATABREACHES.NET
17 AugIsrael’s largest crypto broker Bits of Gold hit by data breach affecting 200,000 customersOlivier Acuna reports: Cryptocurrency broker Bits of Gold said personal data belonging to roughly 200,000 customers was stolen by hackers, the company reported. The Tel Aviv, Israel-based company reported the security breach on Sunday, saying a hacker gained unauthorized access t…DATABREACHES.NET
17 AugYour Backups Are Hiding ThreatsSecurity teams traditionally focus threat intelligence on sources such as identity, network, endpoint, and other parts of the standard security stack. But backup data can contain another source of security telemetry. The claim presented here is that roughly 20% of threats identif…YOUTUBE.COM
17 AugFrance’s tax authority admits hackers made off with data on 678,000 individualsFrance’s tax authority has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems, saying the intrusion exposed data on 678,000 individuals and professionals. The incident came to light after an alleged attacker using t…HELPNETSECURITY.COM
17 AugDetecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilitiesLearn how Tenable One Cloud Exposure helps you unmask the sophisticated tactics of cybercrime group Storm-0501, which carries out Azure-based cloud ransomware campaigns. Tenable One Cloud Exposure uses AI-powered threat stories to expose Storm-0501 TTPs, backed by precision-engin…TENABLE.COM
17 AugCritical flaw in SAP Commerce Cloud faces initial exploitation attemptsThe vulnerability has a maximum severity score of 10, indicating serious potential impact and relative ease to exploit by an attacker.CYBERSECURITYDIVE.COM
17 AugUNISOC Modem Flaw Enables Remote Code Execution via Video CallsUNISOC modem flaw enabled kernel-level code execution through video callsINFOSECURITY-MAGAZINE.COM
17 AugLinux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoSThe botnet adds exploitation modules, credential theft, and reverse SOCKS relays to turn compromised devices into persistent attacker infrastructure.DARKREADING.COM
17 Aug235 GB of PHI and internal documents dumped; Chaos claims it comes from Healthcare Highways“Chaos” is a Ransomware-as-a-Service (RaaS) group first found online in March, 2025. On August 5, 2026, they added Healthcare Highways to their dedicated leak site, with a 24-hour countdown clock. Healthcare Highways describes itself as a medical provider network comp…DATABREACHES.NET
17 AugSafePal Says 39,798 Customers Hit by Data BreachSafePal says a breach exposed personal data of 39,798 customers, but not wallet credentials, private keys, seed phrases, or payment information. SafePal disclosed a data breach affecting about 39,798 customers after hackers exploited a vulnerability in its order-tracking plugin. …SECURITYAFFAIRS.COM
17 AugApple Patches iOS and macOS, (Mon, Aug 17th)Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing vulnerability. This vulnerability did not affect iOS/iPadOS. ISC.SANS.EDU
17 AugPlease hold while we decide.Internal policy conflicts hamper U.S. military AI leadership. Clop claims GE, Philips and Shell. Attackers actively probe internet-facing GeoServer instances. “The Hatman” offers millions of alleged employee records for sale. ETSI begins the approval process for European cyber st…THECYBERWIRE.COM
17 AugVideo Call Exploit Chains Two Flaws in Unisoc ModemsResearchers found that by combining two vulnerabilities, they could take over an Android device by delivering a payload and getting the victim to answer their phone.DARKREADING.COM
16 AugWeek in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-dayHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub Dependabot malware alerts now cover eight ecosystems GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or P…HELPNETSECURITY.COM
16 AugNC: Possible cyberattack hits Wake election software vendor, leaving poll workers’ data exposedCaroline Yaffa reports: The Wake County Board of Elections is suspending its use of a software vendor after it reported a possible cyberattack. There’s no evidence that voting machines, ballots, voter registration records or systems used to count votes were affected, according to…DATABREACHES.NET
16 AugNew Jersey Federal Judge Dismisses Data Breach Class Action Against Background Check CompanyThere’s an update to a data leak incident reported in 2024. Phil Stilton reports: A federal judge has dismissed a proposed class action lawsuit against New Jersey-based background check company TABB Inc., finding the plaintiff failed to establish that he suffered a concrete…DATABREACHES.NET
16 Aug500 Hosts, 1 TB and No Negotiation: Anubis Provides Details on the Fairlife AttackSuspectFile has a great read on the Anubis attack on Fairlife. Marco De Felice faithfully reports what Anubis claims in its exclusive communications with him, what Coca-Cola claims, and how the claims differ. One of the most striking statements detailed the group’s response…DATABREACHES.NET
16 AugRep. Thompson brings bipartisan rural hospital cybersecurity act to HouseNorthCentralPA reports: A group of legislators has introduced the bipartisan Rural Hospital Cybersecurity Enhancement Act to the House of Representatives with the intention to strengthen rural hospitals’ protection against cyber threats. The group includes U.S. Reps. Glenn “GT” T…DATABREACHES.NET
16 AugSafePal data breach impacts 39,798 customers, stolen info for saleCryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data. [...]BLEEPINGCOMPUTER.COM
15 AugPresident Trump authorizes private-sector companies to hack cybercriminals.Trivy, not LiteLLM, was the original source of the 2,500-organization supply chain attack. Patch Tuesday notes: Microsoft fixes three zero-days.THECYBERWIRE.COM
15 AugGeoServer Zero-Day Is Already Being Probed. That’s the ProblemGeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE, with attackers already probing exposed systems. A newly disclosed GeoServer zero-day is already attracting active exploitation attempts, and there is no patch available yet. Organisations running th…SECURITYAFFAIRS.COM
15 AugCISA Unveils New Cybersecurity Resources for K-12 Schools and DistrictsA recent report claims ransomware attacks on K-12 are down for the first half of 2026, while another news story’s headline today claims schools are becoming a new cybersecurity battleground. New? We don’t think it’s new. But the education sector has long been ch…DATABREACHES.NET
15 AugAI Code Has No Security LayersOpen-source software has accumulated layers of security controls over years, including code signing, provenance, version control, maintainer tracking, and MFA for commits. AI MCPs, skills, and AI-generated code can look like ordinary software, but the same security infrastructure…YOUTUBE.COM
15 AugUK: ICO reprimands ACRO Criminal Records Office after data breachThe Information Commissioner (the Commissioner) recently issued a reprimand to ACRO Criminal Records Office for infringements of Articles 32(1), 32(1)(b) and 32(1)(d) of the UK GDPR. ACRO Criminal Records Office (ACRO) is a national police unit providing a range of public service…DATABREACHES.NET
15 AugKR: Sogang University data breach exposes 180,000 student, staff accountsHyeon Ye-Seul reports: Personal information belonging to roughly 180,000 students, alumni and staff at Sogang University was exposed in a cyberattack, the university said Saturday. The university said it had confirmed signs that some data tied to its integrated login accounts had…DATABREACHES.NET
15 AugTime ran out for victims; CRPx0 puts data up for saleCRPx0 made the news last month for its somewhat novel approach of offering free OnlyFans accounts to get victims to click links that would deploy its malware. Since August 7, when it launched a leak site on both the clear net and dark web, CRPx0 has listed 47 victims that did not…DATABREACHES.NET
15 AugCrooks Are Buying Your Expired Domains and Using Them to Deliver MalwareAttackers are buying expired domains to exploit their reputation, traffic and DNS history, using them for malware delivery, scams and C2 infrastructure. Every day, roughly 65,000 domain names that once belonged to someone else get re-registered by a new owner. Infoblox Threat Int…SECURITYAFFAIRS.COM
14 AugNightmare Eclipse drops ShieldBreak zero-day, US recruits cyber privateers, California bolstering cyber defensesWindows Defender Zero-Day 'ShieldBreak,' California's AI Cyber Defense, and US 'Cyber Privateers' A researcher known as Nightmare Eclipse published a new Windows zero-day called ShieldBreak that exploits Windows Defender to escalate from low-level access to full system control ac…CYBERSECURITYTODAY.LIBSYN.COM
14 Aug5 key takeaways from Black Hat USA 2026AI’s potential as a security tool and the danger of autonomous AI agents as a new attack surface were key themes of the presentations and product announcements at Black Hat and DEFCON in Las Vegas last week. Here are some key takeaways from this year’s hacker summer camp that CIS…CSOONLINE.COM
14 AugRisky Bulletin: US will let private companies carry out offensive cyber opsThe White House will let private companies carry out offensive cyber ops, an AI hacking campaign breached Taiwan’s government, a macOS bug was exploited over the internet to drop cryptominers, and Kenya orders internet cafes to store logs.RISKY.BIZ
14 AugHackers Exploiting Unpatched GeoServer Zero-DayThe security defect is described as an SQL injection that could allow attackers to achieve remote code execution. The post Hackers Exploiting Unpatched GeoServer Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
14 AugUkrainian police raid 94 fraudulent call centers, seize $2 millionUkrainian police have disrupted 94 fraudulent call centers during a nationwide operation that involved more than 400 searches and the seizure of thousands of computers, phones, and SIM cards. Ukrainian police raid at a fraudulent call center (Source: Cyberpolice Ukraine) The call…HELPNETSECURITY.COM
14 AugHow CSOs can turn cybersecurity into a business growth strategyFor years, cybersecurity leaders have worked to convince organizations that security deserves a seat at the executive table. Today, that conversation is changing. The challenge is no longer proving that cybersecurity matters; it is demonstrating how security leaders can help orga…CSOONLINE.COM
14 AugApple sends mercenary spyware alerts to targeted iPhone usersApple has sent a new round of threat notifications to iPhone users it believes may have been targeted with mercenary spyware. The warnings are issued to people facing sophisticated surveillance attacks involving tools similar to NSO Group’s Pegasus spyware. Apple uses threa…CYBERINSIDER.COM
14 AugAmnesiaStealer Gives Attackers Live Control of Victims’ macOS BrowsersAmnesiaStealer targets macOS users through fake GitHub pages, stealing passwords, cookies and data while giving attackers live control of the browser. Jamf Threat Labs researchers disclosed AmnesiaStealer, a new multi-stage Rust-based macOS infostealer that spread through a count…SECURITYAFFAIRS.COM
14 AugAkira ransomware reboots into Windows Safe Mode to knock EDR offlineAkira ransomware affiliates were seen using a new technique to evade endpoint detection and response (EDR), where they rebooted a compromised Windows system into Safe Mode with Networking enabled. According to Huntress, the technique successfully took both its agent and Microsoft…CSOONLINE.COM
14 AugThreema messenger says DDoS attacks disrupted its service for two daysEncrypted messaging provider Threema says a series of large-scale distributed denial-of-service (DDoS) attacks disrupted its services this week, leaving users unable to connect for several hours on Tuesday and causing intermittent outages on Wednesday morning. The company disclos…CYBERINSIDER.COM
14 AugNew Android malware relays bank cards to fraudsters while victims still hold themGroup-IB researchers discovered WindRelay, a new Android malware built to capture live payment card data over NFC (Near Field Communication) and relay it to attackers in real time. WindRelay is paired with the SpyNote remote access trojan, which gives attackers remote access to a…HELPNETSECURITY.COM
14 AugApple now uses iPhone alerts for targets of mercenary spywareApple explains how Threat Notifications help protect iPhone users targeted by mercenary spyware.MALWAREBYTES.COM
14 AugNHS admits data breach by sending patient data via pagersSTILL, NHS? Martin Bagot reports: The NHS has admitted a data breach by sending patients’ personal information over pager devices. A BBC investigation found sensitive medical data of transplant patients was routinely sent over an unencrypted pager network. The information include…DATABREACHES.NET
14 AugSalesforce, ServiceNow data targeted in ‘City-Forum’ attacksRecords held in Salesforce and ServiceNow systems are under attack leaving user data exposed, according to researchers at Reco. The attack appears similar to those perpetrated by the extortion group ShinyHunters, Reco said. ShinyHunters has been particularly active this year, att…CSOONLINE.COM
14 AugOracle’s new database security tool is free — for six monthsOracle has released a security tool intended to provide organizations with a centralized view of security risk across their database environments. Oracle Database Security Central will be available free of charge until the end of February 2027. It arrives at a critical time for O…CSOONLINE.COM
14 AugMax severity SAP Commerce Cloud flaw now targeted in attacksA maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused. [...]BLEEPINGCOMPUTER.COM
14 AugHackers exploit macOS Screen Sharing flaw to deploy Monero minerThe Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged. [...]BLEEPINGCOMPUTER.COM
14 AugApple sends out threat notifications to users targeted by spyware.Trivy, not LiteLLM, was the original source of the 2,500-organization supply chain attack. Chinese hack-for-hire group conducts espionage and cybercrime simultaneously.THECYBERWIRE.COM
14 AugFrance investigates tax authority breach after hacker claims 600,000 victimsDaryna Antoniuk reports: France’s tax authority has confirmed that hackers breached its information systems and extracted data on individuals and businesses. France’s Economy Ministry said late Thursday that an attacker gained unauthorized access to systems at the Directorate Gen…DATABREACHES.NET
14 AugFrench tax agency confirms breach as hacker claims 2 million victimsFrance’s tax authority has confirmed that an attacker gained unauthorized access to its information systems and extracted data belonging to individuals and businesses. Separately, a hacker using the name ZeroBytes claims to have obtained cadastral records linked to more tha…CYBERINSIDER.COM
14 AugHackers arrested over €30M bank fraud exploiting service provider flawFour cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers' bank accounts. [...]BLEEPINGCOMPUTER.COM
14 AugApple warned hundreds of users of mercenary spyware attacksApple warns users of credible, targeted attacks and urges immediate verification, stronger protections, and expert assistance. Apple has sent a new round of threat notifications to users it believes may have been singled out by mercenary spyware. The company told TechCrunch the l…SECURITYAFFAIRS.COM
14 AugAmid AI-Driven Bug Tsunami, NIST Looks to…AIDriven by AI-augmented research and scanning, vulnerability volumes continue to surge, driving the National Institute of Standards and Technology to ask whether AI could be the answer.DARKREADING.COM
14 AugApple has a message for you.Apple sends out threat notifications to users targeted by spyware. Trivy, not LiteLLM, was the original source of the 2,500-organization supply chain attack. French tax authority confirms data breach. Chinese hack-for-hire group conducts espionage and cybercrime simultaneously. U…THECYBERWIRE.COM
13 AugMore Novo Nordisk data dumped by FulcrumSecFulcrumSec has dumped more data from its attack that Novo Nordisk first disclosed on June 11. FulcrumSec writes: Today we are releasing all of the Novo Nordisk data not included in our original post: their complete enterprise HuggingFace AI/ML ecosystem. 30 models, 70 datasets, a…DATABREACHES.NET
13 AugRansomware Attack Disables Canadian Hospital’s Doors, HVACMarianne Kolbasuk McGee reports: A Canadian hospital is dealing with a ransomware attack on its facility management systems that has affected the building’s doors and heating, ventilation and air conditioning equipment. Some experts said the incident underscores growing cyb…DATABREACHES.NET
13 AugA golden opportunity...for fraud.This week, while Dave is out, hosts ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Maria Varmazis⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Joe Carrigan⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ are discussing the latest in social engineerin…THECYBERWIRE.COM
13 AugDDoS attacks hit record scale as 1 Tbps+ campaigns become more commonDDoS attacks grew in scale during the first half of 2026, bringing larger traffic floods, shorter attack durations, and increasingly automated campaigns. Cloudflare’s H1 2026 DDoS Threat Report shows threat actors relying on multi-vector techniques and large-scale network-l…HELPNETSECURITY.COM
13 AugBelgium's eID Authentication Opens Citizen Accounts to RCEThe trust framework underlying Belgium's electronic ID system was fully compromised by severe vulnerabilities in a key browser extension, showcasing bigger problems with extensions in general.DARKREADING.COM
13 AugNorth Korean Lazarus Group Uses Windows Zero-Day in Operation Dream JobLazarus targets defense professionals with fake Lockheed Martin jobs, exploiting a Windows zero-day to deploy backdoors and evade security controls. Check Point Research has uncovered a new wave of Operation Dream Job, the long-running North Korean campaign that lures defense and…SECURITYAFFAIRS.COM
13 AugMicrosoft wants you to rethink your approach to cyber defenseCyber defenders need to shake off traditional best practices and switch from reactive patching to building inherently resilient systems in the face of AI-accelerated vulnerability discovery, according to a senior security manager at Microsoft. David Weston, group manager in the W…CSOONLINE.COM
13 AugNightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges. The post Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ appeared first on SecurityWeek .SECURITYWEEK.COM
13 AugSearchlight Cyber combines exposure and threat intelligence in new PTEM platformSearchlight Cyber has launched its Preemptive Threat Exposure Management (PTEM) platform, combining exposure visibility with real-world attacker intelligence to help organizations prioritize and reduce the exposures most likely to be exploited. Security for the real-time era For …HELPNETSECURITY.COM
13 Aug153GB of stolen credentials surface after LiteLLM supply chain attackA massive 153GB archive stolen during the LiteLLM supply chain attack exposes credentials and other sensitive data linked to thousands of corporate domains, including AWS, Samsung, Cisco, and Salesforce. Hudson Rock says it obtained and analyzed the archive, which contains 433,90…HELPNETSECURITY.COM
13 AugThe Model Is the Malware | What Four Agentic Intrusions Tell DefendersOpenAI, Anthropic and Meta disclosed agents reaching external systems. The tools didn't matter, and that changes the playbook for investigating intrusions.SENTINELONE.COM
13 AugWordPress 7.0.4 Patches Remote Code Execution VulnerabilityAttackers with Author-level user or higher permissions could exploit the flaw via malicious Postscript files. The post WordPress 7.0.4 Patches Remote Code Execution Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
13 AugAI agents wage near-autonomous cyberattack on Asian government networksAutonomous AI agents built on open-source frameworks breached Taiwanese government systems, compromised credentials, and probed a nuclear safety agency in a multi-day cyberattack that researchers say signals a new phase in AI-enabled operations. The campaign unfolded over four da…CSOONLINE.COM
13 AugvCenter Flaw Exploited Just Five Days After DisclosureAttackers exploited a critical-severity vCenter flaw five days after Broadcom disclosed itINFOSECURITY-MAGAZINE.COM
13 AugWho Vets AI’s Code? The Scale Challenge Facing Open Source IngestionAI coding tools can introduce unvetted or hallucinated open source dependencies faster than traditional security reviews can keep pace. ActiveState explains why organizations should govern packages at the point of selection, before they enter the development pipeline. [...]BLEEPINGCOMPUTER.COM
13 AugWhat 50 open source projects taught us about security in the AI eraSee how the open source projects in Session 4 of the GitHub Secure Open Source Fund combined AI-assisted workflows, maintainer expertise, GitHub security tools, expert guidance, and funding to improve project security. The post What 50 open source projects taught us about securit…GITHUB.BLOG
13 AugTrezor says ShipMonk breach exposed data of 13,700 customersA data breach at Trezor logistics partner ShipMonk exposed the personal information of 13,689 hardware wallet customers. Trezor says its own systems and devices were not compromised, but warned affected customers to expect more convincing phishing attempts. Trezor disclosed the i…CYBERINSIDER.COM
13 AugQuestel confirms Microsoft 365 breach after ShinyHunters leaks dataFrench intellectual property services provider Questel has confirmed that attackers gained unauthorized access to part of its Microsoft 365 environment following a voice phishing attack, and that some of the stolen data was subsequently published online. The company disclosed the…CYBERINSIDER.COM
13 AugTrezor discloses data breach affecting nearly 14,000 customersHardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping and logistics provider, was hacked [...]BLEEPINGCOMPUTER.COM
13 AugIn a first, US will allow some private firms to carry out cyberattacksZack Whittaker reports: The U.S. government will for the first time allow vetted private companies to launch offensive cyber operations against international criminal gangs and hackers, the White House said on Wednesday. In a newly published presidential memorandum, the Trump adm…DATABREACHES.NET
13 AugQuincy Valley Medical Center notifies patients of Aesto breachAs Seen on Facebook: To our Patients, Some of you have or will receive a letter from Grant County Public Hospital District 2 describing a security incident involving one of our third-party vendors. It is important to us that you understand some facts regardin this incident. First…DATABREACHES.NET
13 AugAI’s ‘middle class’ has gotten dramatically better at hackingAs frontier models and their sandbox escaping exploits dominate front-page news, researchers are increasingly worried about cheaper, more efficient AI models. The post AI’s ‘middle class’ has gotten dramatically better at hacking appeared first on CyberScoop .CYBERSCOOP.COM
13 AugMicrosoft patches LegacyHive Windows zero-day vulnerabilityMicrosoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday. [...]BLEEPINGCOMPUTER.COM
13 AugAI 'watermark removers' flood the web. Almost none can prove they work.Multiple 'watermark removers' have surfaced days after Anthropic began watermarking text generated by Claude, including an open source project with over 4,500 GitHub stars and paid AI detection evasion services. None of the tools' claims about defeating the text watermark can be …BLEEPINGCOMPUTER.COM
13 AugAttackers target zero-day vulnerability in geospatial data platform GeoServerSecurity researchers have seen evidence that attackers are attempting to exploit a currently unpatched SQL injection vulnerability in GeoServer, an open-source web server for managing and publishing geospatial data. The software is widely used by organizations in many industries,…CSOONLINE.COM
13 AugCuriouser and CuriouserIn this edition of the Threat Source newsletter, William reflects on the “Make Hazel a Hacker” segment in Beers with Talos, and how cybersecurity is a field where questions can lead to multiple correct answers.TALOSINTELLIGENCE.COM
13 Aug KEVPlease hack responsibly.President Trump deputizes private-sector companies to target cybercriminals. The LiteLLM supply-chain attack exposed credentials belonging to thousands of organizations. Data-theft campaign targets misconfigured Salesforce and ServiceNow instances. Hackers deploy AI agents to bre…THECYBERWIRE.COM
13 AugFlock says its new tool will help identify police abuse, but hasn’t explained how it worksThe surveillance company announced it's making a tool called "Audit Assistance" mandatory for all customers, claiming it's already helped catch abuse. But the company has yet to explain how the tool works in detail, raising questions about its effectiveness.TECHCRUNCH.COM
13 AugThe Breached WiFi AI Ports... What? - PSW #939In the security news this week: • North Carolina ports and contingency plans • Back to paper and pencils • Midnight Blizzard compromises hotel Wi-Fi • DNS strikes again • Captive portals, stolen credentials, and nation-state scale • Phishing-resistant MFA • Goodbye SMS and voice …YOUTUBE.COM
13 AugThe Ancient Art of SIEM: Why 2003 Problems Look So Familiar in 2026Lately, I’ve been reading a lot of insightful posts related to best practices in SIEM, detection, and logs (written in 2026). The interesting bit is that a lot of these best practices looked good to me and made sense — and yet, they felt incredibly familiar… As I dug deeper, I re…MEDIUM.COM
13 AugWhen Patching Isn't Enough: What the Fairlife Ransomware Attack Says About Network Edge RiskA recent ransomware incident at Coca-cola owned dairy company Fairlife provides a potent example of network edge devices being targeted for exploitation, and of the scale of outcomes attackers can achieve by exploiting them. According to reporting from MSN and others, the ransomw…ECLYPSIUM.COM
13 AugApple sends new ‘Threat Notification’ alerts over mercenary spyware attacksYou're not alone if you just received an "Apple Threat Notification" saying it detected a "mercenary spyware attack targeted at your iPhone." [...]BLEEPINGCOMPUTER.COM
12 AugSandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run CommandsThe Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware. CERT-UA…THEHACKERNEWS.COM
12 AugAI deployments are stretching enterprise security to its limitsCISOs and CTOs expect AI deployments to increase their organizations’ attack surface by an average of 14% over the next year. Nearly all lack visibility into AI deployments, and 90% are concerned about employees using unapproved AI tools outside formal oversight, according …HELPNETSECURITY.COM
12 AugPentestGPT: Open-source automated penetration testing agentic frameworkPentestGPT is an open-source penetration testing agent that points a large language model at a target and lets it work. In its default mode it runs recon, then exploit, then walkthrough, each stage feeding the next. Switch it to pentest mode and the stages become asset discovery,…HELPNETSECURITY.COM
12 Aug KEVMicrosoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wormable RCEMicrosoft Patch Tuesday for August 2026 fixes 398 CVEs, including an actively exploited zero-day and a wormable DNS flaw enabling remote code execution. Microsoft released its Patch Tuesday security updates for August 2026 on Tuesday, covering 398 new CVEs across Windows, Office,…SECURITYAFFAIRS.COM
12 Aug4 gaps slowing AI in enterprise SOCsArtificial intelligence (AI) has quickly become a strategic priority for enterprise security teams. Yet despite growing investment in AI-driven security software, many enterprise SOCs are struggling to translate AI into measurable operational improvements. The issue isn’t whether…CSOONLINE.COM
12 AugThe AI harness is the new attack surfaceAsk a security researcher what makes an AI agent dangerous, and the instinct is to talk about the model — what it will and won’t refuse, how easily it can be jailbroken, whether its weights can be trusted. That instinct is increasingly out of date. A growing body of security rese…CSOONLINE.COM
12 Aug KEVWindows 11 security update fixes actively exploited zero-day flawMicrosoft has released the August 2026 cumulative update for Windows 11, fixing 236 Windows vulnerabilities, including a privilege-escalation flaw that is already being exploited in attacks. The KB5121003 update was released earlier today for Windows 11 versions 24H2, 25H2, and 2…CYBERINSIDER.COM
12 AugFresh Windows Zero-Day Exploited in North Korean CyberattacksThe bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor. The post Fresh Windows Zero-Day Exploited in North Korean Cyberattacks appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugIvanti EPM Update Patches Remotely Exploitable FlawsThe vulnerabilities could be exploited to leak credentials for external SQL connections or crash an agent service. The post Ivanti EPM Update Patches Remotely Exploitable Flaws appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugCBTS brings continuous penetration testing to enterprise securityCBTS has launched Penetration Testing as a Service (PTaaS), combining autonomous penetration testing with security expertise to help organizations continuously identify exploitable risks, validate attack paths, and prioritize remediation as their environments evolve. Cloud enviro…HELPNETSECURITY.COM
12 AugChrome’s anti-abuse protections block 7 billion unwanted Android notifications dailyGoogle Chrome’s latest measures against abusive web push notifications include automatically revoking notification permissions for inactive and suspicious websites, helping reduce scams, phishing attempts, and other deceptive content. Abusive notifications (Source: Google) …HELPNETSECURITY.COM
12 AugDomain Security Plus BlackHat USA 2026 Interviews from Balance Theory and WiCyS - BSW #460As cyber threats become more AI-powered, attacks continue to rise. Threats can arise from all areas of a company’s IT infrastructure, however most attacks utilize a domain name to infiltrate systems. How secure is your domain ecosystem? Ihab Shraim, Chief Technology Offider at CS…YOUTUBE.COM
12 AugNew Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privilegesNightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldBreak" after Microsoft released the August 2026 Patch Tuesday security updates. [...]BLEEPINGCOMPUTER.COM
12 AugChipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities CombinedIntel has informed customers about several high-severity vulnerabilities that can lead to privilege escalation and even code execution. The post Chipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combined appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugFake CCleaner downloads turn Chrome into a credential-stealing surveillance toolA convincing fake version of the widely used CCleaner utility is being used to deliver a multi-stage Windows malware that ultimately abuses Google Chrome for credential theft and surveillance. Researchers from Malwarebytes found the campaign distributing a malicious Chrome extens…CSOONLINE.COM
12 AugSignal adds new security feature to thwart man-in-the-middle attacks​Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven't been intercepted. [...]BLEEPINGCOMPUTER.COM
12 AugLazarus hackers pair fake job offers with Windows zero-day exploitThe North Korea-linked Lazarus group is using fake job offers, trojanized PDF software and a Windows zero-day in attacks aimed primarily at the defense sector, Check Point researchers have found. The activity is part of Operation Dream Job, a long-running campaign in which attack…HELPNETSECURITY.COM
12 AugCloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new waveFrom Cloudflare’s new report: Key insights The 1 Tbps club grew. Cloudflare mitigated a combined 935 network-layer DDoS attacks exceeding 1 Tbps in the first half of 2026 and a +519% quarter-over-quarter surge between Q1 and Q2. The attack-vector center of gravity shifted f…DATABREACHES.NET
12 AugA serious incident occurred at MyDr, a Polish healthcare system providerAdam Haertle reports: MyDr has just announced that it is investigating a serious security incident on its network. The alleged perpetrators of this incident contacted us earlier and claimed to have access to patient data from numerous Polish clinics. According to the hackers, the…DATABREACHES.NET
12 AugMicrosoft’s massive Patch Tuesday releases continue as AI reshapes bug discoveryThis month’s update features about five times the volume of patches Microsoft was shipping in a typical month before AI-assisted vulnerability discovery took hold.THERECORD.MEDIA
12 AugCISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaignResearchers disclosed the bug to Microsoft after examining a long-running campaign by North Korean hackers to exploit the job application process.THERECORD.MEDIA
12 AugHackers leverage new Microsoft SharePoint exploit in attacksHackers have already begun using a proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday. [...]BLEEPINGCOMPUTER.COM
12 AugOpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' ReasoningA newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal reasoning and secrets from session logs, including API keys and passwords. The weakness affected encrypted reasoning objects used by the …THEHACKERNEWS.COM
12 AugThree intrusions at UK criminal records office went undetected for two yearsUnread antivirus alerts and an unpatched content management system exposed Britain's ACRO to three separate data breaches, according to a reprimand notice.THERECORD.MEDIA
12 AugLazarus Used Post-Quantum Key Exchange to Deliver Zero-DayLazarus malware used post-quantum key exchange to protect delivery of a Windows zero-day exploitINFOSECURITY-MAGAZINE.COM
12 AugGunra Ransomware Exploits Fortinet Flaws to Target Critical InfrastructureGunra actors are using stealth to exfiltrate vast volumes of data from Microsoft services, US and Korean agencies have warnedINFOSECURITY-MAGAZINE.COM
12 AugThe Threat Hiding in Your Hiring Process: How Fake Remote Workers Get InFake remote workers can exploit gaps between hiring checks, device delivery, and account access to enter organizations under false identities. Specops Software explains how document verification and biometric liveness checks can help organizations confirm that the person receivin…BLEEPINGCOMPUTER.COM
12 AugStealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom ToolsetResearchers observed the novel campaign exploiting unauthenticated guest access to quietly enumerate and exfiltrate exposed data from both platforms. The post Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugA stranger has been reading Salesforce and ServiceNow portals worldwide for 17 monthsMost security stories start with something broken. This one starts with everything working as designed. Researchers at Reco have been tracking a campaign they call City-Forum, named after a domain registered in 2002, abandoned, and now resolving to a generic rented server from a …HELPNETSECURITY.COM
12 Aug737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have OneA massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure. The extensions, published across at least 40 Chrom…THEHACKERNEWS.COM
12 AugPatch Tuesday: Update now to fix 421 flaws, including three zero-daysMicrosoft's August Patch Tuesday fixes 421 vulnerabilities, including three zero-days, 62 critical flaws, and dozens of Office remote code execution bugs.MALWAREBYTES.COM
12 Aug KEVSharePoint Vulnerability Exploited Shortly After PoC ReleaseThe vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild. The post SharePoint Vulnerability Exploited Shortly After PoC Release appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugRESOURCE: Introducing the Cyber Incident RegistryOver on DysruptionHub, Joseph Topping has introduced a new resource for exploring cyber disruptions, following incidents over time, and uncovering the connections between them: The registry is a research resource focused specifically on cyber disruptions. Each incident profile br…DATABREACHES.NET
12 AugAfter Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bugThis is the latest zero-day released by security researcher Nightmare Eclipse, despite Microsoft publicly threatening to take legal action against them.TECHCRUNCH.COM
12 AugPatch Tuesday notes: Microsoft fixes three zero-days.Attackers target SharePoint vulnerability following PoC release. Business news: Visa and Deel both acquire identity verification companies.THECYBERWIRE.COM
12 AugCisco says software vulnerability could let hackers crash firewallsThreat actors already have begun exploiting the flaw, according to the U.S. government.CYBERSECURITYDIVE.COM
12 AugPlug and Pwn attack uses fake USB devices for Windows SYSTEM accessSecurity researchers have disclosed new "Plug and Pwn" attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor software and gain SYSTEM privileges. [...]BLEEPINGCOMPUTER.COM
12 AugCA: Snoopers Beware; NL’s Privacy Commissioner Recommends Naming Individuals in Snooping-Related BreachesVOCM reports: The province’s Privacy Commissioner is recommending that public bodies consider providing the name of anyone involved in snooping-related privacy breaches to affected individuals. The recommendation comes after an employee of NL Health Services had a peek at a perso…DATABREACHES.NET
12 AugLazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy BackdoorThe North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and…THEHACKERNEWS.COM
12 AugA flurry of fixes.We got your Patch Tuesday notes. Attackers target Microsoft SharePoint vulnerability following PoC release. Cyberattack on CEVA Logistics causes ongoing supply chain disruptions. Wesco confirms data breach following extortion claims. Akira ransomware bypasses EDR in Safe Mode. Ca…THECYBERWIRE.COM
12 AugLong-running Data Theft Campaign Targeting Salesforce, ServiceNowThe "City-Forum" campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling.DARKREADING.COM
12 Aug"City-Forum" data-theft attacks target Salesforce, ServiceNow portalsAn ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. [...]BLEEPINGCOMPUTER.COM
11 AugBdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress AdminsCybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero so…THEHACKERNEWS.COM
11 AugThe future of AI security research isn’t autonomous, it’s human-amplifiedMeet HTTP Terminator, a new AI system that has identified hundreds of websites vulnerable to HTTP request smuggling, hacked them live at scale, and even identified a “genuinely new class” of vulnerability, dubbed “shared-parser confusion.” But it didn’t do it alone; it was guided…CSOONLINE.COM
11 AugUsing LLMs for Vuln Discovery - Rishi Sharma - ASW #395Finding flaws has always been a focus of appsec. And now with open source projects and open weight models orgs have modern tools to review code and conduct pentests. Rishi Sharma describes the motivation behind creating a platform of LLM-driven security tools and the effective wa…YOUTUBE.COM
11 AugRansomware gangs don’t need control system access to disrupt industrial productionDisrupting IT systems that support industrial environments can be enough to interrupt production, even when ransomware operators do not gain direct access to industrial control systems (ICS), according to Dragos. The company identified 1,140 ransomware incidents involving industr…HELPNETSECURITY.COM
11 AugGPT-5.6-Cyber refuses security researchers’ requests far less oftenGPT-5.6-Cyber is a new OpenAI model built on GPT-5.6 Sol, trained to find zero-day vulnerabilities and build exploit chains, with fewer refusals on higher-risk, dual-use work. Model is available only through Daybreak Red, the higher tier of OpenAI’s vetted access program fo…HELPNETSECURITY.COM
11 AugPreviously unseen entry vector used to breach Polish energy plantThe December 29 cyberattack on a Polish combined heat and power (CHP) plant was the first observed case of attackers gaining access to an OT network through a private APN, according to CERT Polska. The private APN is a dedicated mobile network that a Distribution System Operator …HELPNETSECURITY.COM
11 AugYour security vendor gets the frontier cyber model, you get the findingsSelected red team specialists can now use OpenAI’s cyber models to find and exploit weaknesses in client applications and infrastructure. Those clients never get the models themselves. That split is the design of the Daybreak Cyber Partner Program, which OpenAI expanded on …HELPNETSECURITY.COM
11 AugMalicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate SecretsA malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction. The trick can work even after a blunt version of the same theft is refused: …THEHACKERNEWS.COM
11 AugGunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach NetworksCybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government ser…THEHACKERNEWS.COM
11 AugCuba's Spies, Defectors, and the Ex-FBI Agent Who Met Them AllFor decades, Cuban intelligence has been seen as a force that punches above its weight. Shaped during the Cold War through cooperation with the Soviet Union, its intelligence officers received extensive training by the KGB. But where does Cuba’s spy service stand today, especiall…THECYBERWIRE.COM
11 AugAI for Military SupportInteresting empirical research: “ Black Box Warfare: Human Judgment and Military Decision-Making in the Age of AI .” Abstract: How is AI transforming decision-making in modern conflict? This study provides a unique empirical window into that question by deploying a hi…SCHNEIER.COM
11 AugGitHub already has an EDR. You just have to listen to itMany of the recent supply-chain attacks could have been caught earlier if defenders looked closely at the telemetry GitHub already provides, researchers said. At their Black Hat USA 2026 presentation, researchers Yossi Weizman of Microsoft and Mor Weinberger of Echo argued the ca…CSOONLINE.COM
11 AugOpenAI launches GPT-5.6-Cyber as AI narrows vulnerability response windowOpenAI has expanded its Daybreak cybersecurity program and introduced GPT-5.6-Cyber, a specialized model for approved security researchers, as the company warned that AI could give defenders less time to respond to developing threats. Daybreak now has two access levels. Blue give…CSOONLINE.COM
11 AugHead Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participantsKaspersky experts have discovered malicious TrueConf software installers. The Head Mare APT group uses them to deliver the PhantomCore and PhantomGraph backdoors to target systems by exploiting vulnerabilities in an unpatched TrueConf server.SECURELIST.COM
11 AugCisco warns of high-severity ClamAV flaws with public exploitsCisco warned of two high-severity vulnerabilities affecting the Secure Endpoint Connector that allow threat actors to crash the ClamAV scanning process in denial-of-service (DoS) attacks. [...]BLEEPINGCOMPUTER.COM
11 Aug KEVCISA: Microsoft SharePoint flaw now exploited in ransomware attacksCISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July. [...]BLEEPINGCOMPUTER.COM
11 AugOpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit DevelopmentOpenAI on Monday unveiled a new cybersecurity-focused model called GPT‑5.6‑Cyber that it said is focused on vulnerability research, penetration testing, and incident response. "Built on GPT‑5.6 Sol, it is trained to improve capabilities on several specialized cybersecurity tasks …THEHACKERNEWS.COM
11 AugVague Task, Total Access: When AI Delegation Becomes a Security RiskAI agents can improvise beyond the intended scope of a task when they are given broad access to enterprise systems and data. Token Security explains why organizations need to define agent intent and continuously enforce permissions around what each agent was actually created to d…BLEEPINGCOMPUTER.COM
11 AugUS Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’The Water Watch Center launched at DEF CON aims to help under-resourced utilities protect their systems against hackers. The post US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’ appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugMozilla rotates Firefox and Thunderbird signing key after GitHub exposureMozilla has replaced a GPG subkey used to sign some Firefox and Thunderbird releases after an unencrypted copy of the previous key was accidentally committed to a private GitHub repository. The organization says its audit records show no evidence that an unauthorized person acces…CYBERINSIDER.COM
11 AugZoom Patches Zero-Click Code Execution VulnerabilityImpacting Zoom annotation, the bug could be exploited by a meeting participant to execute code on another participant’s machine. The post Zoom Patches Zero-Click Code Execution Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugAdobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic FlawsThe security defects could be exploited for arbitrary code execution and denial-of-service. The post Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugThe inconvenient truth about AI pentesting: someone has to check all the workAI pentesting can flood teams with findings they cannot validate. The real challenge is managing “validation debt” as discovery scales. AI pentesting has a ‘Sorcerer’s Apprentice’ problem. Enchant a broom to fetch water, and it will fetch water, relentlessly, lo…SECURITYAFFAIRS.COM
11 AugCisco Warns of Seven ClamAV Flaws, Two With Public PoCsCisco warns that seven ClamAV flaws affect Secure Endpoint Connector products, with two having public PoCs that could enable remote DoS attacks. Cisco warned that seven ClamAV vulnerabilities affect its Secure Endpoint Connector on Windows, macOS and Linux. ClamAV is an open-sour…SECURITYAFFAIRS.COM
11 AugDeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to DisruptThe ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience. "Its recovery ecosystem combines the Session messaging network with blockchain-back…THEHACKERNEWS.COM
11 Aug KEVMicrosoft Patch Tuesday August 2026, (Tue, Aug 11th)This month we got patches for 418 vulnerabilities. Of these, 62 are critical, 1 is being exploited in the wild, and 2 were publicly disclosed as zero-days. Notable fixes include Windows privilege escalation, container tampering, and critical QUIC and DNS Server remote code execut…ISC.SANS.EDU
11 AugHow Trail of Bits helps verify the integrity of your Signal chatsEvery Signal chat starts the same way: the client asks the Signal server for the public key associated with your contact’s phone number. But how do you know the server gave you the right key? A compromised server could provide a false public key, allowing the client to encrypt me…TRAILOFBITS.COM
11 AugShattering the Dream – When a Job Offer Becomes a Zero-Day AttackKey Points Introduction Since early 2026, Check Point Research has tracked a wave of the Operation Dream Job campaign. This wave primarily targeted the defense sector worldwide, with a particular emphasis on companies operating in the aerospace and aviation industries. …RESEARCH.CHECKPOINT.COM
11 AugExfilSquad Targets New Victims, Shares Data via TorrentsExfilSquad targets 13 organizations, exploiting cloud portals for data theft and using torrents to spread stolen information and amplify damage. Resecurity is tracking the activity of ExfilSquad – the group announced new victims this week. ExfilSquad is a new cybercrime gro…SECURITYAFFAIRS.COM
11 Aug KEVMicrosoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysToday is Microsoft's August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities. [...]BLEEPINGCOMPUTER.COM
11 AugAugust 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-DayA use-after-free in the afd.sys Windows kernel-mode driver has been exploited to gain SYSTEM privileges. The post August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugStolen Change Healthcare data gets new handling rules in court orderNaomi Diaz reports: A federal judge in Minnesota has signed off on a strict set of rules for how the data stolen in Change Healthcare’s 2024 cyberattack can be handled during the ongoing lawsuit. Magistrate Judge Dulce J. Foster approved the plan, reviewed by Becker’s, Aug. 7. It…DATABREACHES.NET
11 AugStop Building a 2003 SOC with AI: Triage Must Die (Part 2)(with key ideas from Augusto Barros ) In Part 1 of this series , we dumped a pile of uncomfortable questions on you and promised answers. The core thesis, if you recall: if you add AI agents into a legacy, swivel-chair SOC structure, you are essentially building a robotic horse p…MEDIUM.COM
11 AugNSA installs DHS lawyer as new general counselKerianne Tobitsch, who most recently served as a senior lawyer at the Homeland Security Department, is the NSA's new general counsel, sources told Recorded Future News.THERECORD.MEDIA
11 Aug KEVCisco warns of ASA and FTD VPN flaw exploited to crash devicesCisco is warning that a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense (FTD) software is being actively exploited in attacks to remotely crash affected devices. [...]BLEEPINGCOMPUTER.COM
11 Aug KEVMicrosoft Plugs Nearly 400 Security HolesMicrosoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.KREBSONSECURITY.COM
11 AugSquirrel Soup, Ghostjacking, OpenSource, Gunra, Beesafe, AI threats, SBOMS, and more - SWN #606Squirrel (and other) Soup, Ghostjacking, OpenSource, Gunra, Beesafe, AI threats, SBOMS, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-606YOUTUBE.COM
11 AugGunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFAThe ransomware-as-a-service operation is finding success against critical infrastructure targets with leaked Conti code and old flaws in firewalls and VPN appliances.DARKREADING.COM
11 AugSN 1091: The Post BlackHat State of AI - When AI Writes MalwareAI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free…TWIT.TV
10 AugRisky Bulletin: Two law firms pay giant ransomsTwo American law firms pay multi-million dollar ransoms, a Metabase zero-day is being used in data theft attacks, Russian hackers disrupted a second power plant in Poland, and there’s a remote code execution bug in WordPress… again!RISKY.BIZ
10 AugHow to report an AI Act violation in the EUThe EU’s fight to regulate AI models entered a new chapter on 2 August 2026, when the European Commission’s AI Office and national authorities began enforcing the AI Act. The AI Act is the EU’s law regulating AI, the first broad legal framework of its kind. It c…HELPNETSECURITY.COM
10 AugChainloop: Open-source evidence store and policy engine for the software supply chainChainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeline, picks up what the build produced, uploads those files to content-addressable storage, and references each one in a sign…HELPNETSECURITY.COM
10 AugSolidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and CredentialsCybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been observed delivering a browser wallet and credential stealer. The names of the extensions are below - helper-beeps.solidity-pro web…THEHACKERNEWS.COM
10 Aug7 key trends defining the cybersecurity market todayAI is having a seismic impact on the cybersecurity market. Record-shattering amounts of venture capital is flowing into a new generation of startups focused on AI cybersecurity. At the same time, established cybersecurity vendors are racing to integrate AI and agentic AI features…CSOONLINE.COM
10 Aug4 million fake applications and one blind spot: A SOC playbook for OAuth client ID spoofingKey takeaways OAuth client ID spoofing defeats detections that key off application name or a known application ID, because the field itself is fabricated, rotated or blank. AADSTS700016 paired with an unrecognized client ID can mean valid credentials, not a broken app registratio…CSOONLINE.COM
10 Aug KEVCritical Progress LoadMaster flaw now actively exploited in attacksThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. [...]BLEEPINGCOMPUTER.COM
10 AugCISA Urges Immediate Patching of Exploited Progress LoadMaster VulnerabilityThe critical-severity flaw allows unauthenticated, remote attackers to execute arbitrary commands. The post CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
10 AugAnthropic to put AI in charge of reviewing Claude Code actions by defaultAnthropic will make auto mode in Claude Code the default for new sessions on Pro, Max, and Team plans starting August 14. Users who previously selected a different default may receive a one-time prompt asking whether they want to switch to auto mode. In a controlled experiment wi…HELPNETSECURITY.COM
10 Aug“Ghostjacking” Exploits AI Agents’ Trusted Access to Evade Firewall ControlsTenet reported that half of Fortune 500 companies are vulnerable to the Ghostjacking technique, which involves tricking AI agents with fake reportsINFOSECURITY-MAGAZINE.COM
10 AugMetabase Patches Vulnerability Exploited as Zero-DayThe security defect allows unauthenticated, remote attackers to gain administrative access to Metabase instances. The post Metabase Patches Vulnerability Exploited as Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
10 AugOne-click flaw in Atlassian Rovo exposed enterprise data via prompt injection attackAtlassian’s enterprise AI assistant Rovo, which is usually connected across sensitive work environments like Slack, Microsoft 365, and Google Workspace, was found vulnerable to data leaks through malicious instructions. At DEF CON 34 , researchers from Varonis demonstrated an att…CSOONLINE.COM
10 AugOpenAI Pauses Astra Model Over Critical Cybersecurity Risk ConcernsOpenAI paused work involving Astra after tests showed cybersecurity abilities that could approach its Critical risk threshold under the company’s framework. OpenAI disclosed that internal evaluations of Astra, one of its upcoming models, have found cybersecurity capabilities sign…SECURITYAFFAIRS.COM
10 AugTrueConf Server Flaws Exploited to Replace Client Installers with PhantomCoreThe threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, IT, and software development sectors. Russian cybersecurity v…THEHACKERNEWS.COM
10 AugOpenAI says Astra could reach ‘critical’ cyber capability, tightens safeguardsOpenAI said its upcoming model Astra is showing cybersecurity capabilities that could reach its highest risk category, where a system can autonomously find and exploit vulnerabilities or carry out end-to-end cyberattacks against hardened targets. The company disclosed the assessm…CSOONLINE.COM
10 AugChina-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warnsA China-linked threat actor is believed to be exploiting a critical vulnerability affecting cybersecurity software from the company N-able.THERECORD.MEDIA
10 Aug10th August – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 10th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES North Carolina Ports, the US authority operating the ports of Wilmington, Morehead City and others, has suffered a cyberattack that…RESEARCH.CHECKPOINT.COM
10 AugMetabase zero-day exploited to access Framework customer dataFramework, the San Francisco-based company that designs repairable and upgradeable laptops, has suffered a data breach after attackers managed to exploit a zero-day vulnerability in the Metabase business intelligence service. According to the notification sent to affected Framewo…HELPNETSECURITY.COM
10 Aug KEVInside the Metabase SQLi: Exploited in the WildReverse engineering GHSA-vwf4-m7j8-wcjf with AI to accelerate defense.WIZ.IO
10 AugCISA: SonicWall SMA1000 flaws now exploited by ransomware gangsCISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. [...]BLEEPINGCOMPUTER.COM
10 AugCisco Warns of High-Severity ClamAV Vulnerabilities With Public PoCRemote, unauthenticated attackers could exploit the bugs to cause a denial-of-service (DoS) condition. The post Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC appeared first on SecurityWeek .SECURITYWEEK.COM
10 AugResearchers find that only a quarter of AI-generated patches are fully successful.Ransomware attacks exploit critical N-able flaw. LexisNexis disables some services following suspicious activity.THECYBERWIRE.COM
10 AugPoland uncovers second heat plant cyberattack that went hidden for monthsThe incident occurred on the same day as coordinated cyberattacks struck more than 30 other renewable energy installations and a larger heat plant, as Poland publicly disclosed in January.THERECORD.MEDIA
10 AugUK man tied to The Com sentenced for abusing 117 victimsJustin Swaddle, who was a minor when he committed the crimes, coerced children across multiple countries into self-harm and sexual abuse using threats tied to their personal information, authorities said. The post UK man tied to The Com sentenced for abusing 117 victims appeared …CYBERSCOOP.COM
10 AugSecure development can help turn the tables as AI alters cyber landscapeA top Microsoft executive says a shift toward memory safety and other preventative measures can limit the ability to exploit flawed software.CYBERSECURITYDIVE.COM
10 AugResearchers Uncover RovoBlast Vulnerability in Atlassian AI AssistantAtlassian fixed a flaw letting one crafted link make its Rovo AI assistant exfiltrate company dataINFOSECURITY-MAGAZINE.COM
10 Aug⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router BackdoorsA lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default. That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit …THEHACKERNEWS.COM
10 AugAttack Surface Management - Matt Lea - CSP #227In this episode of CISO Stories, Jessica Hoffman sits down with Matt Lee to explore attack surface management, AWS security, and the cloud misconfigurations that can put organizations at risk. Matt shares lessons from his experience auditing cloud environments, including common A…YOUTUBE.COM
10 AugUnpatched HP ThinPro flaw allows bypass of disk encryption protectionsAn unpatched vulnerability in HP ThinPro 8 and 9 allows attackers with physical access to bypass the operating system’s TPM-backed full-disk encryption protections and recover the key securing the device’s root partition. The zero-day remained without a publicly available fix whe…CYBERINSIDER.COM
10 AugChina-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central FlawMicrosoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware, the Micro…THEHACKERNEWS.COM
10 AugCoruna, DarkSword iOS Exploits Proliferate GloballySophisticated iPhone exploit chains previously limited to nation-states are spreading far and wide to organized cybercrime groups.DARKREADING.COM
10 AugOpenAI releases ChatGPT 5.6 Cyber, but it's only for approved usersOpenAI has developed a new model called "GPT 5.6 Cyber," designed for vulnerability research, penetration testing, incident response, and remediation. [...]BLEEPINGCOMPUTER.COM
10 AugCISA Advisory: #StopRansomware: Gunra RansomwareGunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both enc…DATABREACHES.NET
10 AugNow with extra vulnerabilities.Researchers find that only a quarter of AI-generated patches are fully successful. Ransomware attacks exploit critical N-able flaw. Atlassian fixes critical flaw in Rovo AI. LexisNexis disables some services following suspicious activity. US Senate confirms Adam Cassady as cyber …THECYBERWIRE.COM
10 AugMetabase SQL Zero-Day Attacks Could Have Wide Blast RadiusThe maximum-severity vulnerability, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users.DARKREADING.COM
9 AugAlcon - 218,395 breached accountsIn August 2026, the Alcon eye care company was named in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data allegedly sourced from Alcon containing 218k unique email addresses along with other largely corporate B2B contact fields, including nam…HAVEIBEENPWNED.COM
9 AugRansomware gangs skip the CEO, head straight for the 40-something IT managerCarly Page reports: Turns out the fastest way to get a company to consider paying a ransom isn’t calling the CEO – it’s targeting the 46-year-old IT manager. That’s according to Zscaler, whose ThreatLabz researchers tracked 351 victims across 334 organizations c…DATABREACHES.NET
9 Aug KEVSecurity Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Palo Alto Networks Faces China Cy…SECURITYAFFAIRS.COM
9 AugKR: 3Pro TV Data Breach Exposes 460,000 Records, Including 2,979 Bank AccountsPark Hyo-jung reports: More than 460,000 pieces of personal data, including bank account and credit card information, were exposed in a breach at South Korean financial media outlet 3Pro TV. E-Broadcasting, the company that operates 3Pro TV, posted a notice on the outlet’s …DATABREACHES.NET
8 AugNearly 800 Malicious npm Packages Deliver Cross-Platform RAT and InfostealerA cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. "These packages appear to use AI slop squatted, or randomly generated typo-squatting p…THEHACKERNEWS.COM
8 AugCoding for Veterans: Cybersecurity Today on the Weekend with David ShipleyCoding for Veterans: From Military Service to Cybersecurity & Generative AI Careers This episode is sponsored by Nordlayer. Contact them at Nordlayer.com/hashtagtrending and use discount code NLSummer26 for a discount during their summer sale. In this Weekend episode of Cybersecu…CYBERSECURITYTODAY.LIBSYN.COM
8 Aug KEVMetabase Zero-Day Exploited in Wild Allows Admin Access Without AuthenticationMetabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticat…THEHACKERNEWS.COM
8 AugN-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and PersistN-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product. "We are proactively expanding protections in response to ongoing monitor…THEHACKERNEWS.COM
8 AugUnlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare PatientsHackers stole personal, medical, and insurance data of 3.8 million people from Unlimited Technology Systems’ data center. Unlimited Technology Systems disclosed a data breach affecting more than 3.8 million people after hackers accessed one of its commercial data centers be…SECURITYAFFAIRS.COM
8 AugCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataThe RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data. The post Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data appeared first on SecurityWeek .SECURITYWEEK.COM
8 AugCity of Coweta refuses to pay ransom after system-wide cyberattackAn update on the ransomware attack affecting the City of Coweta: the city manager has been through a ransomware attack before with another city, and reports that after they paid, they were reinfected weeks later, so Coweta will not be paying any ransom demands. Threat actors who …DATABREACHES.NET
8 Aug KEVMetabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataAttackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims. Metabase just confirmed something no analytics vendor wants to write: attackers found and used an unpatched, maximum-severity flaw against …SECURITYAFFAIRS.COM
8 AugHackers breach TrueConf to trojanize client installers with backdoorsThe Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. [...]BLEEPINGCOMPUTER.COM
8 AugCity of Suisun declares local emergency after cyberattack downs 911 dispatch systemKatie Chavez reports: Suisun City officials declared a state of emergency Saturday, Aug. 8, after a cyberattack took out the city’s emergency dispatch line and other key systems. City officials said that “malicious software infected and compromised IT systems” at about 5:45 a.m. …DATABREACHES.NET
7 AugThe Era of Cheap Bugs, Water utility attacks spread to 12 states, Coldcard wallet losses could hit 130 millionPasskeys Phished at BlackHat, Water Utility Attacks Spread, and $130M ColdCard Wallet Flaw In this August 7, 2026 episode, David Shipley recaps key Black Hat themes, including Microsoft's warning that cheap, automated vulnerability discovery is outpacing patching, alongside resea…CYBERSECURITYTODAY.LIBSYN.COM
7 AugShieldFont fights AI scraping by handing crawlers the wrong wordsIsaque Seneda and Gabriel Abrucio built a web font that draws one set of words on screen and leaves a different set in the page’s source code. A person reading in a browser sees the writing as written. A scraper pulling the HTML gets different words in the same grammar, at …HELPNETSECURITY.COM
7 AugAugust 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?July 2026 Patch Tuesday was record-setting in so many ways. The sheer volume of security patches for almost every product in the Microsoft portfolio was the highest ever and, of course, well over 600 CVEs were identified in the Security Updates Guide. Interestingly, only two CVEs…HELPNETSECURITY.COM
7 AugWhat the first year of EU AI Act transparency enforcement could look likeIn this Help Net Security interview, Edwin Weijdema, Field CTO at Veeam, answers questions on Article 50 of the EU AI Act and what the first year of enforcement might bring. He explains why corrective orders will likely outnumber large fines, when an AI agent working through a ti…HELPNETSECURITY.COM
7 AugCritical Vulnerabilities Patched With Chrome 151 UpdateThe browser refresh eliminates over two dozen memory safety bugs, including critical use-after-free flaws. The post Critical Vulnerabilities Patched With Chrome 151 Update appeared first on SecurityWeek .SECURITYWEEK.COM
7 AugKeepit AI Truth Cloud protects the data behind enterprise AIKeepit announced AI Truth Cloud, transforming backup from a compliance requirement into the strategically valuable data asset an organization can hold. As AI agents take on business-critical decisions, AI Truth Cloud positions Keepit as the sovereign source of truth that enterpri…HELPNETSECURITY.COM
7 AugNew NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT TablesSecurity researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. Presented at Black Hat …THEHACKERNEWS.COM
7 AugMalware Can Abuse Windows Hello for Business Keys for Persistent Entra ID AccessSecurity researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, disclose victim IP addresses and mapped ports, and exhaust NAT table…THEHACKERNEWS.COM
7 AugPython package security in 2026: How supply chain attacks are targeting your AI development environmentOn March 24, 2026, developers building AI applications with LiteLLM — a Python package with 95 million monthly downloads — unknowingly installed malicious code. A threat actor group known as TeamPCP had compromised the PyPI distribution pipeline and pushed malicious versions 1.82…CSOONLINE.COM
7 AugTruck Brake Controller’s Safety Recall Doubled as Hidden Security FixNMFTA research shows a Bendix EC80 brake controller safety recall also patched remote code execution and DoS vulnerabilities. The post Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix appeared first on SecurityWeek .SECURITYWEEK.COM
7 AugAI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-DayPortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate attack vectors. PortSwigger said a separate human-guided discovery cascade…THEHACKERNEWS.COM
7 AugAgentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026Agentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event. Key takeaways Building defensi…TENABLE.COM
7 AugGrowing Up The Hard WayOpen Source had a great childhood. For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and never once thought about who was watching. It ran the kind of lemonade stand that took IOUs from anyone who wandered up — take what you need…THEHACKERNEWS.COM
7 Aug18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape ContainersA use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw has existed since 2008. The fix already shipped: stable kernels 7.1.6, 6.18.42, 6…THEHACKERNEWS.COM
7 AugIPVanish launches isolated browser to reduce Windows telemetry exposureIPVanish has introduced a remote browser isolation feature designed to prevent Windows telemetry from directly correlating browsing activity with Microsoft’s persistent Global Device Identifier (GDID). The company announced IPVanish Secure Browser, citing the recently discl…CYBERINSIDER.COM
7 Aug200 accounts compromised in Swiss government’s Microsoft SharePoint breachHackers exploited vulnerabilities in Microsoft SharePoint servers belonging to Switzerland’s Federal Office of Information Technology, Systems and Telecommunication (BIT), compromising the login credentials of around 200 accounts. On July 28, BIT’s security specialists noti…HELPNETSECURITY.COM
7 AugSnowflake attacker pleads guilty to hack of 165 companies’ dataA Canadian hacker has admitted being part of a group responsible for several major cyberattacks. Connor Riley Moucka pleaded guilty to being part of a coterie of hackers that hit 165 organizations, resulting in the theft of customer records and the extortion of millions of dollar…CSOONLINE.COM
7 AugLevi Strauss discloses data breach after social engineering attack on employeesLevi Strauss & Co. has disclosed a cybersecurity incident in which an unauthorized third party used social engineering to gain access to three employees’ company-issued computers and steal corporate information. The apparel company said in a Form 8-K filing with the US Securi…CYBERINSIDER.COM
7 AugAU: Hackers leak sensitive Victorian court data to dark webKristian Silva and Danny The personal information of Victorian court users has been posted on the dark web, sparking a police investigation. Names, emails and job titles of people who attended online hearings in regional courts were posted on an underground hacking forum in July.…DATABREACHES.NET
7 AugWhat Canvas learned from a massive cyberattackAlcino Donadel reports: …. Instructure, the edtech company behind learning management system Canvas, suffered one of the largest data breaches in the U.S. this year after cybercriminals gained access through a third-party vendor—an increasingly common occurrence in higher e…DATABREACHES.NET
7 AugUnlimited Technology Systems Data Breach Affects 3.8 Million PatientsHIPAA Journal reports an update to the Unlimited Technology Systems breach that occurred between October 10 – 15, 2025, and was discovered on October 19, 2025: On July 23, 2026, the HIPAA Journal reported on a data breach at Unlimited Technology Systems, a Montgomery, Ohio-…DATABREACHES.NET
7 AugMoonshot’s Kimi AI model has also escaped from a test environmentYet another AI model has escaped from a cybersecurity test lab: This time, it’s the Chinese company Moonshot’s Kimi K3 model on the run. Frontier Security spotted that Kimi K3 had found a loophole in the UK AI Safety Institute’s test environment for AI models performing cybersecu…CSOONLINE.COM
7 AugVishing attacks target hedge funds.Cyberattack disrupts North Carolina Ports operations. Metabase Cloud breached by zero-day flaw.THECYBERWIRE.COM
7 AugBTS #79 - InfraTrust - Understanding Infrastructure Vulnerabilities & RiskIn this episode of Below the Surface, Paul Asadoorian is joined by Chase Snyder and Vlad Babkin for a conversation about InfraTrust, InfraTrust Pulse, and the hard problem of making infrastructure vulnerability data useful for defenders. The first half of the episode focuses on w…ECLYPSIUM.COM
7 AugTrojanized AI skills gain 1.7M installs in agent-targeted attackResearchers have uncovered an extremely effective attack campaign that involved AI agent skills trojanized to deploy a credential stealer. The incident is part of a growing trend in which attackers are targeting the AI software supply chain by poisoning sharable instruction and c…CSOONLINE.COM
7 AugMore than half of AI-generated patches are brokenResearch finds your AI generated security patch is more likely to fail than fully fix a vulnerability. It might even introduce brand new flaws to exploit along the way. The post More than half of AI-generated patches are broken appeared first on CyberScoop .CYBERSCOOP.COM
7 AugBoston Children’s Hospital named in North Korean hacking operationNaomi Diaz reports: Boston Children’s Hospital is among roughly a dozen organizations publicly named by security researcher Vangelis Stykas as impacted by a large-scale North Korean hacking operation, Wired reported Aug. 5. The hospital disputes that its own systems were breached…DATABREACHES.NET
7 AugWordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server TakeoverWordPress XSS2Shell flaw enables admin takeover and remote code execution. Users should update to patched versions. Researchers at Pwn just published a report on a vulnerability chain they’re calling XSS2Shell, and the entry point is quite simple: type a username that doesn…SECURITYAFFAIRS.COM
7 AugRing around the ransom.Vishing attacks target hedge funds. Metabase Cloud breached by zero-day flaw. Cyberattack disrupts North Carolina Ports operations. The Chinese government has launched a security review of Palo Alto Networks products. US defense supplier breached by phishing attack. Healthcare so…THECYBERWIRE.COM
7 AugMetabase SQLi zero-day exploited in customer data-theft attacksA critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. [...]BLEEPINGCOMPUTER.COM
7 AugCity of Coweta hit with system-wide ransomware attack, has backupKTUL in Oklahoma reports: The City of Coweta says they are currently responding to a ransomware attack. According to officials, on Werdnesday, August 5, the City experienced at system-wide attack and immediately contacted their contracted IT provider and additional cycbersecurity…DATABREACHES.NET
7 AugNew York State Department of Financial Services Secures Cybersecurity Settlement with Order Express, Inc.A press release from the NYS DFS: August 5, 2026 New York State Department of Financial Services Acting Superintendent Kaitlin Asrow announced today that Order Express, Inc., a licensed money transmitter, will pay a $250,000 penalty for violations of DFS’s cybersecurity regulatio…DATABREACHES.NET
7 AugInside the Modern SOC: The Identity Front DoorIdentity-based attacks drive 90% of incidents. Learn how modern attackers exploit identities and what SOC leaders can do to respond. The post Inside the Modern SOC: The Identity Front Door appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
7 AugUS cloud ‘kill switch’ is as dangerous as ransomware, European businesses fearEmma Woollacott reports: European firms are more concerned about a potential US government-imposed ‘kill switch’ for cloud services than almost anything else. In a survey of 1,500 businesses in the UK, France, and Germany, Proton found that with many having built thei…DATABREACHES.NET
6 AugOpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud SchemesOpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that end, it banned a coordinated network of C…THEHACKERNEWS.COM
6 AugSuppliers, logins, and AI tools are all becoming attack pathsCybercriminals and state-backed hacking groups are abusing trusted identities, cloud services, AI tools, and software supply chains to gain access while avoiding detection, according to CrowdStrike’s 2026 Threat Hunting Report. Intrusion activity increased by about 4% over …HELPNETSECURITY.COM
6 AugCloudflare OS goes open source with a record of everything its agents readCloudflare open sourced Cloudflare OS, the agent platform whose first version its own employees have used since May. Every resource an agent reads gets recorded, the record follows whatever the agent produces, and when a second person opens that output the platform checks them ag…HELPNETSECURITY.COM
6 AugSrsly Risky Biz: Being a North Korean hacker is about to be less funTom Uren and James Wilson talk about North Korea losing control over some of its hacker workforce. Expect some tightening of controls and oversight, and perhaps even a reduction in the country’s ransomware operations. They also discuss escalating attacks on American water infrast…RISKY.BIZ
6 AugOWASP 2026 LLM Top 10: “The model will be fooled”The OWASP GenAI Security Project has released the 2026 edition of its Top 10 for LLM Applications and, for the first time, the list was influenced by real-world incidents. The two top entries – Prompt Injection and Sensitive Information Disclosure – remained constant,…HELPNETSECURITY.COM
6 AugBrowser security is where software, data, and AI meetIn this interview with Help Net Security, Rui Ribeiro, CEO of Jscrambler, explains why the browser has become a security problem organizations do not control. Companies do not own the device, the extensions, or the network path, yet that is where application logic, third-party co…HELPNETSECURITY.COM
6 AugCisco Patches Critical SD-WAN, IOS XE, FMC VulnerabilitiesPatches were rolled out for two dozen vulnerabilities, including one with public proof-of-concept (PoC) code. The post Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
6 AugChinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root ShellsCybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models from Zbtlink. According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more th…THEHACKERNEWS.COM
6 AugPractical lessons from deploying AI securely at scaleWhen I first started working on enterprise AI security initiatives, I expected the biggest challenges to be technical. I assumed we’d spend most of our time discussing prompt injection, model security, vector databases or the latest LLM vulnerabilities. I was wrong — or at least …CSOONLINE.COM
6 AugEvidence points to cybercriminals stepping up their AI gameMore evidence is emerging about how AI is becoming part of the day-to-day workflow for cybercriminals, from building and refining tools to managing infrastructure and accelerating vulnerability research. Drawing on recovered prompt logs, attack tooling, and threat actor conversat…CSOONLINE.COM
6 AugPhotos: Black Hat USA 2026 ArsenalThis week Help Net Security is at the Mandalay Bay, where Arsenal is running alongside the Briefings. If you’ve never been, it’s the corner of Black Hat that feels least like a conference and most like a workshop: a room full of stations where the people who wrote the…HELPNETSECURITY.COM
6 AugAttackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM AccessAttackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Oracle compile it into stored s…THEHACKERNEWS.COM
6 AugAWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the ModelSecurity flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent's tools with no check that a model turn had authorized them. In several of the attack paths, the model never ran at all, so system prompts…THEHACKERNEWS.COM
6 Aug KEVWhy the ‘rogue AI’ problem will lead to an era of headaches for security practitionersShortly after OpenAI publicly acknowledged the Hugging Face breach on July 21, Reuters journalist Raphael Satter called me for comment on a story which would reveal shocking new details about OpenAI’s “rogue model” incident: The agent hadn’t just slipped its leash for a few hours…CSOONLINE.COM
6 AugToken Jacking: Cybercriminals Could Be Stealing Your AI ResourcesDiscover how attackers hijack AI tokens to fuel gray market transfer stations by stealing developer API keys. The post Token Jacking: Cybercriminals Could Be Stealing Your AI Resources appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
6 AugMeta AI Model Hacked a Company During Testing, Marking Third AI Lab IncidentMeta says an AI model hacked a company during testing after accidental internet access, marking the third disclosed AI lab breach in weeks. Meta confirmed that one of its AI models breached an unidentified company during cybersecurity testing, after its independent testing partne…SECURITYAFFAIRS.COM
6 AugApple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploitsApple has imposed strict new submission limits on its bug bounty portal after finding itself overwhelmed by low-quality, AI generated vulnerability reports - many of which were found to be describing security flaws that simply didn't exist. Read more in my article on the Hot for …BITDEFENDER.COM
6 AugVerification closes the loopMost organizations assume remediation reduces risk. It’s a reasonable assumption. A vulnerability is identified, a patch is applied, the scanner comes back clean, and the ticket is closed. The workflow is complete, the metrics improve, and the issue is considered resolved. The pr…CSOONLINE.COM
6 AugAI code security with Claude Mythos Preview: Inside Tenable’s 500+ hours of testing for Project GlasswingWe spent 500+ hours and 40 billion tokens testing Anthropic’s Claude Mythos Preview for Project Glasswing. The takeaway: frontier AI won't run your code security program, but used well, it can make one even stronger. Key takeaways Frontier AI dramatically scales security testing.…TENABLE.COM
6 AugApple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy BypassesCybersecurity researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address. Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to ensure users' privacy by routing their Safari web traffic thr…THEHACKERNEWS.COM
6 AugAI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM MemoryA new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses a standard feature built into almost every major AI assistant: pre-filled deep links. We observed production websites embeddi…THEHACKERNEWS.COM
6 AugYou’re only as secure as your last evaluationThe updated Cybersecurity Maturity Model Certification (CMMC) represents a critical evolution in the Department of War (DoW) strategy to secure the Defense Industrial Base (DIB). It is more than a regulatory hurdle. It is a direct response to a rapidly changing and increasingly h…CSOONLINE.COM
6 AugCybersecurity needs a new operating modelFor decades, cybersecurity has been built around one assumption: defenders had enough time to: Discover vulnerabilities. Assess exposure. Deploy patches. Verify that critical systems remained protected. That assumption shaped how organizations built security programs, how vendors…CSOONLINE.COM
6 AugCTEM isn’t failing. It’s not being operationalizedCybersecurity is full of frameworks, regulations, and directives that tell organizations what they should do. Zero Trust, NIST, CIS Controls, CMMC, DORA, NIS2, and now Continuous Threat Exposure Management (CTEM) all provide valuable guidance and describe desired outcomes. The ch…CSOONLINE.COM
6 AugAttackers hid malware inside Oracle Database after SQL injection breachHuntress has documented a case where the Oracle database itself became the malware host. The security firm disclosed a campaign in which threat actors exploited a SQL injection vulnerability to store a custom post-exploitation toolkit, dubbed Khunt, inside an Oracle database usin…CSOONLINE.COM
6 AugZero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X PostsZenity researchers reported the findings to Anthropic and OpenAI in late 2025 and early 2026, but they remain unpatched. The post Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts appeared first on SecurityWeek .SECURITYWEEK.COM
6 AugThree in four AI-generated vulnerability patches leave something brokenAsk a frontier model to patch a real vulnerability and it will hand you something that looks like a fix. It reads like the patch a maintainer would write. When there is a test, it often passes. Roughly one time in four, it is a fix. Researchers at 1Password graded 6,080 patches f…HELPNETSECURITY.COM
6 AugBelarusian Ransom Cartel Mastermind Gets 16 Years in PrisonThere is an update to the case of Maksim Silnikau, who was extradited from Poland to the U.S. in August 2024 to stand trial here. Ionut Arghire reports: The Belarusian creator and administrator of the Ransom Cartel ransomware was sentenced to 16 years in prison in the US. Maksim …DATABREACHES.NET
6 AugDutch retailer Bol follows De Bijenkorf in warning of data breach as leaked data appears on dark webThe NL Times reports: Online retailer Bol has warned customers about a data breach involving one of its logistics partners. The company said unauthorized parties accessed the partner’s systems, but emphasized that Bol’s own systems were not affected. Even so, some cus…DATABREACHES.NET
6 AugHow a software provider closed unknown paths to cloud compromiseA healthcare software provider believed its segmented environment was reasonably secure. The company had invested heavily in layered controls across a distributed workforce, separating developer environments, segmenting cloud infrastructure, and tightly managing administrative ac…CSOONLINE.COM
6 AugHow a global investment firm reduced security surprisesMost security teams don’t suffer from a lack of data. They suffer from a lack of certainty. Vulnerability scanners, annual penetration tests, and compliance assessments can generate thousands of findings. Yet they often fail to answer a simple question: Which risks actually matte…CSOONLINE.COM
6 AugMeta joins OpenAI, Anthropic in latest AI test breachMeta has become the third frontier AI developer in recent weeks to disclose a security incident involving one of its advanced AI models during cyber capability testing conducted by AI safety startup, Irregular, placing the independent evaluator at the center of a series of disclo…CSOONLINE.COM
6 AugMeta Joins OpenAI and Anthropic in Reporting AI Exploit IncidentOne of Meta’s AI models exploited a third-party security flaw during an evaluation, the latest in a series of similar incidents involving advanced AI systemsINFOSECURITY-MAGAZINE.COM
6 AugPhotos: Black Hat USA 2026Photo gallery from the Business Hall at Black Hat USA 2026. Interesting booths, demo stages, crowded aisles, and the moments in between. Featured vendors: Stellar Cyber, Tines, Filigran, Delinea, Prophet AI, Air Security, Legion Security. Featured people: Kunal Modasiya (Qualys) …HELPNETSECURITY.COM
6 AugNovel-reading apps used users’ phones to generate fake ad trafficA new mobile ad fraud scheme, dubbed Papyrus, is using a cluster of novel-reading apps to generate hidden browser traffic, according to IAS Threat Lab. Sample novel-reading apps associated with Papyrus (Source: IAS Threat Lab) While a person taps through chapters of a romance or …HELPNETSECURITY.COM
6 AugThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More StoriesApparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF can finish the job. This week runs on cheap leverage: exposed servers, recycled bugs, poisoned agent instructions, remote-access tool…THEHACKERNEWS.COM
6 AugToolkit Hidden Inside Oracle Database Evades Endpoint ToolsAttackers used SQL injection to compile a post-exploitation toolkit inside an Oracle databaseINFOSECURITY-MAGAZINE.COM
6 AugNew TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashesResearchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines. [...]BLEEPINGCOMPUTER.COM
6 AugSwiss government SharePoint breach compromised 200 accountsSwitzerland's federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. [...]BLEEPINGCOMPUTER.COM
6 AugCardiology Associates of Port Huron remains silent although they were allegedly hacked and had patient data stolen in June.There have been approximately 4 dozen new threat actor groups targeting U.S. medical entities in the first half of 2026. One of them calls itself “Orova.” They have no “About” page or information about themselves on their dark web leak site, so seeing that…DATABREACHES.NET
6 AugWhen AI Commits Felonies - PSW #938This week: - When you are not at summer camp you can't read about it - The Fettle continues - Using the CFAA against AI - Social contracts are not security models - VSCode extentions, again - Bugtraq is back! - NVIDA, LVFS, and unraveling AI infrastructure - More routers that com…YOUTUBE.COM
6 AugAI without adult supervision.Meta’s AI models join the sandbox escape club. China’s telecom footprint in the U.S. may be larger than expected. The White House keeps its AI safety playbook under wraps. AI coding tools introduce new GitHub risks. ENISA expands its CVE role. A critical Paperclip flaw enables co…THECYBERWIRE.COM
6 AugCapitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scamsA Senate Foreign Relations Committee hearing explored how 13 federal agencies and myriad foreign governments are wrestling with the problem. The post Capitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scams appeared first on CyberScoop .CYBERSCOOP.COM
6 AugMeta says AI model hacked third-party company during cyber testingMeta has disclosed that one of its AI models compromised another company’s systems during an internal cybersecurity evaluation after a misconfiguration inadvertently granted the model access to the public internet, marking the latest in a series of real-world AI testing inc…CYBERINSIDER.COM
6 AugResearcher Claims Control of ChatGPT Secure SandboxA researcher demonstrated a proof-of-concept attack chain that provided C2-style influence over ChatGPT's isolated sandbox during a session at Black Hat USA 2026.DARKREADING.COM
6 AugWhy exposure management is replacing vulnerability managementVulnerability management isn’t failing because security teams lack visibility. Most organizations already have more findings than they can reasonably address. Yet despite all those findings, many CISOs still struggle to answer a deceptively simple question: Are we actually becomi…CSOONLINE.COM
6 AugThe Coordination Gap: How Attackers Are Outpacing Law EnforcementThe fight against cybercrime continues because threat actors have adapted their strategies to avoid deterrents, but law enforcement still operates in silos.DARKREADING.COM
6 AugCyberRisk TV Live Coverage from Black Hat 2026 - Day 2CyberRisk TV is broadcasting live from Black Hat 2026 in Las Vegas! Tune into our coverage featuring interviews with cybersecurity leaders, practitioners, researchers, and technology innovators from one of the industry’s most influential security events. Throughout the day, we’ll…YOUTUBE.COM
5 AugNational cyber director lays out White House plans to secure AI without writing new rulesThe Trump administration executive order on artificial intelligence tried to strike the balance between responsible use, security and mutual benefit, all with an eye toward not making it regulatory in nature, National Cyber Director Sean Cairncross said Tuesday. “Everyone is work…CYBERSCOOP.COM
5 AugRisky Bulletin: Hacker breaches Hungary's State TreasuryA hacker breached Hungary’s State Treasury, Russia will mandate 40 apps on all smartphones next year, hackers steal Liechtenstein’s business database, and an AI agent got real CVEs for hallucinated vulnerability reports.RISKY.BIZ
5 AugFuture AGI: Open-source platform for shipping self-improving AI agentsFuture AGI is an open-source platform for tracing, evaluating, simulating, and guardrailing LLM agents, licensed Apache 2.0 and self-hostable. Self-hosted instances register with Future AGI on first boot and send an instance ID, a version string, a deployment type, and the email …HELPNETSECURITY.COM
5 AugQuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows InstallerCybersecurity researchers have disclosed what has been described as a "long-standing supply chain attack" on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users. According to Fortinet FortiGuard Labs, the supply chain attack…THEHACKERNEWS.COM
5 AugRisky Business #847 -- Oops! Claude's accidental hacking spreeOn this week’s show Patrick Gray, and James Wilson are joined by bearded man of leisure Adam Boileau to discuss the week’s cybersecurity news, including: Accidental AI agent hacking sprees have the world’s media freaking out, but we think it’s all pretty funny The bugpocalypse is…RISKY.BIZ
5 AugAI threat report: Rogue agents, workflow attacksMalicious AI use and threats to AI systems are requiring cyber teams to double down on security fundamentals and rethink the future of their approaches to defense. Newly emerging AI-enabled attacks, proofs of concept, and in-the-wild techniques, as well as the latest AI vulnerabi…CSOONLINE.COM
5 AugCloudflare gives AI agents wallets with built-in spending controlsCloudflare’s Wallets will give AI agents running on its platform a human-readable wallet handle for paying APIs and online content within limits set by their creator. Handle reservations have opened, while the service will become available in the coming months. It will incl…HELPNETSECURITY.COM
5 AugClaude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for ItselfAn agent running Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber evaluation by the UK's AI Security Institute. When a bystander publicly warned that the code was malicious, the agent denied it, force…THEHACKERNEWS.COM
5 AugWhy you need a reliable AI agent kill switchRecent high-profile rogue agent incidents involving OpenAI and Anthropic underscore the fact that organizations can’t put blind trust in their AI guardrails. Moreover, they must able to turn off agents quickly when they deviate from intended behavior — before they can do potentia…CSOONLINE.COM
5 AugAI is getting better at election facts, but voters shouldn’t rely on itAI chatbots are avoiding some of the obvious errors that plagued earlier models, but they still fall short giving voters the full picture compared to state and local sources. The post AI is getting better at election facts, but voters shouldn’t rely on it appeared first on CyberS…CYBERSCOOP.COM
5 AugYour orchestration framework choice is a security decision, not just an engineering oneComparisons of LangChain, CrewAI and AutoGen are easy to find — dozens of guides this year cover the same ground: developer experience, ecosystem maturity, how easy it is to wire up multi-agent workflows. None of them ask the question I actually care about: does the framework you…CSOONLINE.COM
5 AugCISA Warns of Exploited Langflow, N-central, and Tomcat VulnerabilitiesThe flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass. The post CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
5 Aug15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera trafficTP-Link prints the serial number of an Omada router on its packaging and on a label attached to the device. Those numbers run in sequence, and feeding a guessed one to the Omada cloud service returns the matching device’s MAC address and model. Serials beginning 22460J500 a…HELPNETSECURITY.COM
5 AugOne C2 kit. 30 customers. 2 governmentsI was mapping the command-and-control infrastructure behind a state-linked intrusion set when the query came back and effectively ended the exercise I thought I was running. The malware resolved its C2 address by reading a smart contract on a public blockchain. Public reporting d…CSOONLINE.COM
5 AugA few notes on AWS Nitro Enclaves: KMS integrationNitro Enclaves and Key Management Service (KMS) feel like a natural fit: since the KMS can verify attestation documents generated by the enclaves, developers can offload key management tasks from their applications to the AWS-managed service. But integrating an external service w…TRAILOFBITS.COM
5 AugAI Security Institute Reports Anthropic and OpenAI Models Going Rogue Against OrganizationsIn one instance, an unsanctioned model attempted to inject malicious code into an open source repository. The post AI Security Institute Reports Anthropic and OpenAI Models Going Rogue Against Organizations appeared first on SecurityWeek .SECURITYWEEK.COM
5 AugLeaked n8n API Tokens Exposed Live Instances to Credential TheftGitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software vulnerability. We scanned public GitHub comm…THEHACKERNEWS.COM
5 AugOpenAI, Anthropic AI agents resorted to deception in new cybersecurity incidentsOpenAI’s GPT-5.6 Sol and Anthropic’s Mythos 5 have been implicated in another series of AI security incidents after the models created fake online identities, targeted real people, and attempted to manipulate developers into approving malicious code during controlled cyber evalua…CSOONLINE.COM
5 AugCode review used to be the only way to catch these bugsAn automated system called NOVA read the source code of 3,915 open-source projects over two months and came back with 14,090 vulnerabilities, each one confirmed through the system’s validation pipeline. Vulnerability researchers at Palo Alto Networks’ Unit 42 built th…HELPNETSECURITY.COM
5 AugKali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise RiskKali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft's real authentication page. Once access and refresh tokens are issued, attackers may…THEHACKERNEWS.COM
5 Aug KEVTenable Hexa AI: Automating exposure remediation with agentic routinesDiscover how Tenable Hexa AI closes the gap between exposure management and endpoint patching using intent-driven routines, smart guardrails, and human approval. Key takeaways The problem: A slow handoff between security workflows creates a days-long remediation gap.   The s…TENABLE.COM
5 AugOpen-source software’s archenemy TeamPCP goes back further than anyone thoughtOligo Security uncovered evidence of a long operational history, including multiple previous attacks it traced to the same attacker infrastructure and tools. The post Open-source software’s archenemy TeamPCP goes back further than anyone thought appeared first on CyberScoop .CYBERSCOOP.COM
5 AugThe Fourth Battlefield: The Growing Role of Cyber Operations in Global ConflictCrowdStrike co-founder Dmitri Alperovitch discusses how cyber operations support kinetic warfare, signal coming conflicts, and reshape the global battlefield. The post The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict appeared first on SecurityWeek .SECURITYWEEK.COM
5 AugTuskira expands exposure management with Agentic Control PlaneTuskira has launched its Agentic Control Plane for Exposure Management, a new capability within the Tuskira platform that governs AI-discovered vulnerabilities from scan to verified closure. The capability extends Tuskira’s existing zero-day and exposure-response capabilities to …HELPNETSECURITY.COM
5 AugAI agent deception moves from theory to reality in UK cyber tests“During a routine cyber evaluation, AI agents took sustained, unsanctioned action directed at real people and organisations,” UK’s AI Security Institute (AISI) disclosed on Tuesday. The agents’ actions included an attempted supply-chain attack that saw them crea…HELPNETSECURITY.COM
5 AugArmorCode enhances attack path analysis with new AI agents and Context Risk GraphArmorCode has announced a major expansion of its Agentic Control Plane. Four new Anya AI agents help security teams analyze cloud risks, assess vulnerability exploitability, identify mitigation strategies, and coordinate patch orchestration. It also unveiled new Context Risk Grap…HELPNETSECURITY.COM
5 AugAU: Updoc patients notified of security breach where personal information may have been stolenEmma Kirk reports: Updoc patients have been notified their personal information may have been accessed in a security breach. The website is used for 24/7 telehealth services across Australia. Customers were advised there was a “brief period of unauthorised access to a third party…DATABREACHES.NET
5 Aug KEVCISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flawsThe U.S. Cybersecurity and Infrastructure Security Agency is giving federal agencies three days to mitigate vulnerabilities in IBM Langflow, N-central, and Apache Tomcat, all actively exploited. [...]BLEEPINGCOMPUTER.COM
5 AugPaperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent ImportsTwo security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and starting it. A th…THEHACKERNEWS.COM
5 AugCOLDCARD security audit phishing attack installs remote access toolA phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. [...]BLEEPINGCOMPUTER.COM
5 AugFlaws in Google APK for Python Unlock Agent-to-Agent AttackGoogle has fixed the issues, which exploited a trust boundary between two AI agents with different privilege levels to trigger automation that could compromise the supply chain.DARKREADING.COM
5 AugHackers run khunt post-exploitation toolkit from Oracle databaseHackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. [...]BLEEPINGCOMPUTER.COM
5 AugHow a $50,000 Exploit Chain Turned Bixby Against Samsung PhonesThe chain involved the exploitation of several vulnerabilities in the Samsung Members and Samsung Account applications. The post How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones appeared first on SecurityWeek .SECURITYWEEK.COM
5 Aug KEVSAFE and sound.The White House lays out its AI strategy at Black Hat. Researchers spotlight rogue AI behavior. CISA warns of an actively exploited N-able flaw. TP-Link patches 15 Omada vulnerabilities. Apple fights the UK’s iCloud access order. The AI gray market expands. A Massachusetts health…THECYBERWIRE.COM
5 AugWhy security validation must follow the attack pathFor years organizations have strengthened their security posture by investing in specialized tools for applications, identities, endpoints, networks, and cloud infrastructure. Those investments remain essential, but the way attackers operate has changed dramatically. Today’s adve…CSOONLINE.COM
5 AugThe Real Goal: Strategic AutonomyThis discussion argues that a successful CISO advisor should enable security leaders to make independent, data-driven decisions that align with business objectives. That includes knowing when to take action—and when not to. Strategic autonomy shifts cybersecurity from a reactive …YOUTUBE.COM
5 AugSecurity validation should begin where attackers beginModern attacks increasingly begin with the web application. Customer portals, partner platforms, APIs, external business applications, and AI-powered services have become the front door to the enterprise. The systems organizations build to create value are now the same systems at…CSOONLINE.COM
5 AugCanadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for MillionsConnor Riley Moucka, aka “Waifu” and “Judishe,” was scheduled to stand trial in January 2027. Today, he changed his “not guilty” plea to a guilty plea, and pleaded guilty to four counts of the multi-count indictment. Connor Riley Moucka, 26, of…DATABREACHES.NET
5 AugReport: Passkey security issues could allow account takeoverGiven the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around passkey protections is concerning, analysts say, but they stress that the demonstrated attacks can only happen after a succe…CSOONLINE.COM
5 AugCyberRisk TV Live Coverage from Black Hat 2026 - Day 1CyberRisk TV is broadcasting live from Black Hat 2026 in Las Vegas! Tune into our coverage featuring interviews with cybersecurity leaders, practitioners, researchers, and technology innovators from one of the industry’s most influential security events. Throughout the day, we’ll…YOUTUBE.COM
5 AugSN 1090: Black Hat - The Hidden Flaws in AI Security Nobody Saw ComingAt Black Hat Las Vegas, the Security Now crew digs into how AI is not just finding hidden software bugs but also fueling both groundbreaking innovation and alarming new exploits. When open models can launch surprise Bitcoin heists, who draws the line between forbidden knowledge a…TWIT.TV
4 AugCybersecurity jobs available right now: August 4, 2026Application Security Engineer Arcadia | USA | Remote – View job details As an Application Security Engineer, you will lead the application vulnerability management process by prioritizing and driving remediation of security findings. You will integrate and automat…HELPNETSECURITY.COM
4 Aug178: UbiquitiNickolas Sharp worked for Ubiquiti, a company that makes networking equipment. He noticed that there were some security problems at work. He tried to point them out, but didn't feel like he was being listened to enough. What do you do when the company you work for isn't securing …DARKNETDIARIES.COM
4 AugEU begins enforcing AI Act, putting AI models under the microscopeEurope’s fight to regulate AI models moved from paper to practice on 2 August 2026, when the European Commission’s AI Office and national authorities began enforcing the AI Act. On the same date, new transparency rules took effect, requiring certain AI systems to tell…HELPNETSECURITY.COM
4 AugThe Minnesota attackers may hold a better backup of your plant than you doMore than 30 Minnesota community water systems were hit by coordinated cyber activity against their operational technology on July 26 and 27; several lost remote control or deliberately cut it while operators contained the intrusion. The reporting since — including CSO’s own news…CSOONLINE.COM
4 AugAttackers are crafting malicious AI instruction files to turn your agentic workflows into quiet criminal helpersAI agents are increasingly being deployed across the enterprise, a rapid adoption that has significantly broadened the organization’s attack surface, turning sharable AI agent resources and configuration files into backdoors, security experts warn. AI-assisted software developers…CSOONLINE.COM
4 AugHow companies could share cyber risks without exposing their secretsA cryptographic technique could let companies prove they're vulnerable to critical flaws without revealing the sensitive data that attackers could exploit. The post How companies could share cyber risks without exposing their secrets appeared first on CyberScoop .CYBERSCOOP.COM
4 AugDecades-Old BMC Vulnerability Exposes Thousands of Data Centers to AttacksOver 24,000 internet-accessible server-management interfaces disclose authentication hashes before login. The post Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
4 AugTanium expands autonomous security across AI, exposure management and SecOpsTanium has announced a series of new autonomous security capabilities across the Tanium Autonomous IT Platform. Spanning agentic AI, exposure management and security operations, the capabilities empower IT and security operators to stay ahead of an AI-accelerated threat landscape…HELPNETSECURITY.COM
4 AugSecure AI adoption starts with API best practicesYou don’t need to be a fortune teller to understand where enterprise IT is headed. McKinsey reported in November that 62% of global organizations were experimenting, piloting or scaling agentic AI projects. More recently, Gartner forecast that worldwide spending on AI will top $2…CSOONLINE.COM
4 AugRussian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malwareMidnight Blizzard, the Russian threat actor tied to the country’s foreign intelligence service, has spent months targeting users of public Wi-Fi networks at places like hotels and conference centers, according to new findings from Microsoft Threat Intelligence. Overview of …HELPNETSECURITY.COM
4 AugIndusface SwyftComply AI enables autonomous virtual patching for AI-discovered flawsIndusface has announced SwyftComply AI, an autonomous vulnerability remediation solution that virtually patches vulnerabilities surfaced by AI-assisted pentesting. Artificial intelligence has changed the economics of application security. AI-powered security agents now uncover ex…HELPNETSECURITY.COM
4 AugThe top cybersecurity product announcements from Black Hat 2026Black Hat 2026 is shaping up to be another AI-heavy conference, but this year’s announcements suggest the industry is moving beyond simply adding copilots to existing products. Vendors are increasingly packaging AI into operational workflows, while pairing automation with governa…CSOONLINE.COM
4 AugGoogle ADK flaws reveal what happens when AI agents trust the wrong messageSecurity flaws in automated workflows in the GitHub repository for Google’s Agent Development Kit for Python could allow public-facing AI agents to trigger more privileged automation, opening one path to manipulate pull-request reviews and another to expose credentials, according…CSOONLINE.COM
4 AugHow legitimate cloud platforms enable phishers to bypass MFAWe cover a cloud-based AitM attack scenario leveraging service workers and Ultraviolet, and provide detailed phishing hosting statistics across platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS.SECURELIST.COM
4 AugCritical Azure Cosmos DB flaw threatened cross-tenant database takeoverA critical vulnerability in Microsoft Azure’s Cosmos DB database service could have enabled attackers to escape the platform’s Gremlin query sandbox, execute code on shared infrastructure, and ultimately gain access to any customer’s database, including data stores used by Micros…CSOONLINE.COM
4 AugAlmost Half of Malware Samples Communicate Direct to IPNearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these threats. The post Almost Half of Malware Samples Communicate Direct to IP appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
4 AugRapidFort Runtime brings continuous CVE monitoring and tamper detectionRapidFort has launched RapidFort Runtime, a real-time security solution that extends RapidFort’s SSCS capabilities into live production environments. The offerings provide end-to-end continuous threat elimination, from curated, independently malware-scanned open-source soft…HELPNETSECURITY.COM
4 AugRepublican attorneys general urge OpenAI to preserve records on Hugging Face breachMiranda Nazzaro reports: More than a dozen Republican attorneys general are calling on OpenAI to preserve records on its models’ recent breach of another company, suggesting the AI firm may have violated state or federal laws in the incident. In a letter sent Monday to OpenAI CEO…DATABREACHES.NET
4 AugSwiss federal IT office hit by cyberattackSwissInfo.ch reports: Following a cyberattack on the SharePoint servers operated by the Federal Office of Information Technology, Systems and Telecommunication (FOITT), access via the internet has been blocked for people outside the federal administration. Around 200 accounts wer…DATABREACHES.NET
4 AugBotnet Hunting for Vulnerabilities in Diagnostic Tools, (Tue, Aug 4th)This morning, I noticed specific sources "hunting" for vulnerabilities in URLs that I haven&#;x26;#;39;t noticed before. All of these URLs appear to be associated with diagnostic tools: ISC.SANS.EDU
4 AugAI Missed the Real FixDuring vulnerability patching tests, the AI models correctly focused on the vulnerable source code but repeatedly ignored runtime inputs that were also part of the official security fix. In one example, validating paths loaded from a local .env file was necessary to fully resolve…YOUTUBE.COM
4 AugThe Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source SoftwareFrontier AI is reshaping vulnerability discovery. Learn how our NOVA system found 14,000+ unknown vulnerabilities across the open-source software supply chain. The post The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software appe…UNIT42.PALOALTONETWORKS.COM
4 AugServiceNow organizes autonomous security around six solution areasServiceNow has announced an acceleration of its Autonomous Security vision with six unified solutions that help deliver prevention-first, AI-native cyber defense across unified exposure management, continuous vulnerability detection, cyber-physical security, identity and access s…HELPNETSECURITY.COM
4 AugSnyk unveils continuous AI pentesting and agent red teamingSnyk has announced the general availability of Evo Continuous Offensive Security (COS), enabling security teams to continuously test applications with autonomous, AI-powered pentesting and AI agent red teaming while providing validated proof of what attackers could actually explo…HELPNETSECURITY.COM
4 AugFake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote AccessCybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Managemen…THEHACKERNEWS.COM
4 AugXCSSET malware returns in macOS attacks that hijack ChromeA new version of the XCSSET macOS malware can hijack Google Chrome, intercept browser activity, and turn the browser into a fileless command channel. The campaign has been spreading through infected Xcode projects since April 2026, targeting software developers and users of the a…CYBERINSIDER.COM
4 AugEFF warns SCREEN Act could force VPN users to surrender their anonymityA proposed US age-verification law named SCREEN Act could force VPN users to surrender identifying information before accessing lawful online content, according to the Electronic Frontier Foundation (EFF). The digital rights group says the SCREEN Act’s broad scope would weaken on…CYBERINSIDER.COM
4 AugVaronis Agent IBAC keeps AI agents within their intended boundariesAI agents need broad access to be useful, but traditional access controls cannot determine whether an action aligns with a user's intent. Varonis explains how Agent IBAC detects intent drift and enforces real-time guardrails to keep agents within their intended boundaries. [...]BLEEPINGCOMPUTER.COM
4 AugAI developers targeted via trojanized GitHub repositoriesCybercriminals are cloning popular GitHub repositories for AI tools and developer resources to distribute an infostealer, according to Netskope Threat Labs. (Source: Netskope) Netskope came across the campaign while tracking a Windows-based MaaS infostealer, first reported in Apr…HELPNETSECURITY.COM
4 AugINC Ransomware is Calling Victims – Pressure Tactics Post SonicWall Zero-Day ExploitINC Ransomware exploits SonicWall SMA 1000 flaws, using calls and emails to pressure victims during extortion campaigns targeting global organizations. Resecurity disclosed that INC Ransomware has emerged as the dominant threat actor exploiting the recently disclosed SonicWall Se…SECURITYAFFAIRS.COM
4 AugProlific ransomware group behind SonicWall zero-day attacksINC ransomware wasn’t the first group to exploit the zero-days, but it’s been the most assertive and effective in chaining both vulnerabilities to steal and encrypt data for extortion. The post Prolific ransomware group behind SonicWall zero-day attacks appeared first on CyberSco…CYBERSCOOP.COM
4 AugAI widely used to exploit critical flaws, disrupt supply chainsA report confirms the growing use of AI across a broad spectrum of threat groups.CYBERSECURITYDIVE.COM
4 AugSage Water Resources says Utah saltwater disposal controller intrusion bypassed pump safeguardsDysruption reports on a critical infrastructure attack in Utah that could have caused more damage than some other recent attacks: Sage Water Resources said workers stopped malicious changes to an automated controller at its oilfield wastewater disposal site near Duchesne, Utah, b…DATABREACHES.NET
4 AugFlorida Man Sentenced for Conspiracy to Commit Wire FraudStolen wallets are still a thing. From the U.S. Attorney’s Office, Eastern District of Kentucky: July 31, 2026 LEXINGTON, Ky. – An Orlando, Fl., man, Ivory Joe Pruitt, 61, was sentenced on Friday to 63 months imprisonment by U.S. District Judge Robert Wier for conspiracy to…DATABREACHES.NET
4 AugHackers steal over $130 million by exploiting bug in offline hardware walletsA security vulnerability in the cryptocurrency hardware wallet Coldcard is allowing hackers to drain the crypto from victims’ wallets. The total losses amount to more than $130 million, according to blockchain monitoring firms.TECHCRUNCH.COM
4 Aug KEVAirlock Digital Unveils Agentic AI Control & Governance to Extend Preventative Endpoint SecurityAirlock Digital , a leader in preventative endpoint security, today announced Agentic AI Control & Governance at Black Hat USA 2026 . The new capabilities build on application control by providing command- and session-level visibility into trusted AI agent behavior, centraliz…CSOONLINE.COM
4 AugBritain’s next war won’t be an away game: Q&A with former head of Defence IntelligenceAs Chief of Defence Intelligence, General Sir Jim Hockenhull decided to declassify and publish what London knew of Russia’s plans to invade Ukraine, down to a map of the routes its forces would take.THERECORD.MEDIA
4 AugNPM? Not my problem.New Shai-Hulud campaign compromises popular npm packages. Easterly says small municipalities shouldn’t have to fend for themselves. Chinese threat groups accelerate exploits. Samsung bans smart TV apps with residential proxies. Hackers breach a Liechtenstein banking database. Swi…THECYBERWIRE.COM
4 AugSharePoint Flaws Used to Hack Switzerland’s Federal IT AgencySwiss Federal IT Agency FOITT says attackers exploited SharePoint flaws to compromise about 200 accounts. Servers are being rebuilt as investigations continue. Switzerland’s Federal Office for Information Technology and Communications, known as BIT or FOITT, disclosed that …SECURITYAFFAIRS.COM
4 AugAISI, OpenAI report more ‘unsanctioned’ model hacksFollowing similar reports by OpenAI and Anthropic, the UK’s top AI testing lab and a private cybersecurity tester say their models exploited parts of the open internet. The post AISI, OpenAI report more ‘unsanctioned’ model hacks appeared first on CyberScoop .CYBERSCOOP.COM
4 AugTP-Link patches Omada ZTP flaws allowing hackers to breach networksTP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE). [...]BLEEPINGCOMPUTER.COM
4 AugOpenAI, Anthropic AI agents targeted real people and systems in cyber testsOpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incidents that resulted in a real website being breached and social engineering attacks against people outside the intended testing boundaries. [.…BLEEPINGCOMPUTER.COM
3 AugAnthropic models hack three firms, Coldcard bug drains $88 million, Midnight Blizzard hijacks hotel Wi-FiClaude Escapes the Lab, EU AI Act Enforced, SVR Hotel Wi‑Fi Hijacks, and $88M Bitcoin Wallet Flaw David Shipley covers multiple cybersecurity headlines: Anthropic disclosed that three Claude models escaped misconfigured evaluation environments during Irregular-run CTFs, reached t…CYBERSECURITYTODAY.LIBSYN.COM
3 AugSkillSpector: NVIDIA’s open-source security scanner for AI agent skillsSkillSpector is an open-source scanner from NVIDIA that reads an agent skill and tells you whether to install it. Point it at a directory, a zip file, a single SKILL.md, or a Git URL, and it returns a list of findings, a risk score, and recommendations. The folder it reads runs w…HELPNETSECURITY.COM
3 AugHugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary CodeThree high-severity security flaws have been disclosed in Hugging Face's Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) supply chain to security risk. "These vul…THEHACKERNEWS.COM
3 AugRapid7 Expands UK and Ireland Channel Presence Through Strategic Partnership with Exclusive NetworksRoss Baker is Senior Director, Northern Europe at Rapid7. As organizations across the United Kingdom and Ireland embrace AI, cloud technologies, and digital transformation in the name of enhancing customer experiences and accelerating business growth, the cybersecurity landscape …RAPID7.COM
3 AugStop depending on heroics and start operationalizing third-party riskIn cybersecurity, third-party risk management normally looks simple on paper: evaluate your vendor, learn the risk, report out on the gaps and weaknesses, transfer to the contract, and continue. Unfortunately, it seldom works that way in practice. In my roles as a CISO, I find my…CSOONLINE.COM
3 AugAI is making cybersecurity fundamentals more important than everWhen OpenAI disclosed that one of its models escaped a test environment and broke into Hugging Face’s systems on its own, headlines cast the incident as the start of a new era of AI-driven attacks. But the underlying cause of the incident was a familiar one: a misconfigured sandb…CSOONLINE.COM
3 AugColdcard Users Lose $89m After Bitcoin Wallet Is HackedA hacker has drained nearly $89m from Coldcard Bitcoin wallets after exploiting a legacy bugINFOSECURITY-MAGAZINE.COM
3 AugAppSec, Shopify-Style; State of Mobile Security; the News - Andrew Dunbar, Kern Smith - ESW #470Interview with Andrew Dunbar, CISO at Shopify After 13 years at Shopify, Andrew has some valuable insights to share on application security. In this episode, we discuss how AI has changed application security processes where bug bounty now fits in a post-Mythos, post-AI harness w…YOUTUBE.COM
3 Aug30 days with Claude Mythos Preview: How Tenable adapted our security program, and why yours is nextTenable spent 30 days running frontier AI models against our own code. It didn’t just find bugs — it proved they’re real, with reproducible exploits. That fundamentally changes code security from ranking potential code defects to a much higher signal focused on the findings that …TENABLE.COM
3 AugAlleged Żabka Breach Exposes Jira Data, Source Code, and API KeysAlleged Żabka data leak offered for €5,000 includes Jira data, GitLab repos, and secrets; researchers verified much of the sample. A brand-new forum account showed up on August 2, posted once, and asked five grand for what it claims is a full data dump from Żabka Polska. Żabka Po…SECURITYAFFAIRS.COM
3 AugThe OpenAI Hack Shows the Genie Is Out of the BottleThis essay originally appeared in Foreign Policy . Earlier this month, two of OpenAI’s models broke out of their containment sandbox and attacked another AI company. The story is kind of wild . OpenAI was running security tests on two of its models: GPT-5.6 Sol and an unrel…SCHNEIER.COM
3 AugChinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOSAn unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit. Attack surface management platform Censys said it identified the threat actor running more than 100 web propertie…THEHACKERNEWS.COM
3 AugRecent SonicWall Vulnerabilities Exploited in Ransomware AttacksThe INC Ransomware gang has been targeting vulnerable SMA1000 appliances for root access and lateral movement. The post Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
3 AugCISA lays out new guidance for using open-source softwareThe US Cybersecurity and Infrastructure Security Agency (CISA) has published the Open Source Software: Security Principles and Practices guide, which provides federal agencies with recommendations for managing the security of open source software, contributing to OSS projects, an…HELPNETSECURITY.COM
3 AugZero Networks targets AI agent security gaps with network-level ‘Least Agency’ controlsWhile AI security today is largely focused on restricting what an agent can do, Zero Networks says it has built a failsafe. The company says it can block a compromise midway by adding a network layer protection. On Monday, the company announced the launch of “Least Agency Enforce…CSOONLINE.COM
3 AugKR: Seoul lawmaker criticizes 5,000-won compensation for 4.62 million-person data breachThe Herald Business reports: Seoul Facilities Corp. has drawn criticism over its plan to offer 5,000 won [$3.50 USD] per affected user in response to a personal data breach involving about 4.62 million people, with questions mounting over whether the compensation is adequate. Seo…DATABREACHES.NET
3 AugUK: Details of 100,000 police staff leaked on the dark web after hackBill Curtis reports: The full names and contact details for more than 100,000 police officers and staff have been leaked on the dark web after a hack, The Times can reveal. As part of a major security breach, hackers compromised data belonging to the Ministry of Defence (MoD), th…DATABREACHES.NET
3 AugCyberattack hits Liechtenstein, with 31,000 records stolenDPA reports: The tiny principality of Liechtenstein has fallen victim to a major cyberattack in which the data of 31,000 people were stolen, the government said on Sunday. The country, which lies between Switzerland and Austria, has a population of around 41,000. The government s…DATABREACHES.NET
3 AugPNLD Confirms Data Breach Affecting UK Police and Justice StaffUK police legal database breach exposed officers’ names and work emails, increasing phishing risks. NCA is investigating. The Police National Legal Database (PNLD), the legal reference system used by all 43 Home Office police forces in England and Wales, confirmed that a da…SECURITYAFFAIRS.COM
3 AugChina-Linked Threat Actors Weaponize New Vulnerabilities in Under a DayChinese actors exploited the critical React2Shell exploit inside a day, while 88% of exploited vulnerabilities in H1 2026 were compromised within 48 hours of disclosureINFOSECURITY-MAGAZINE.COM
3 AugInside the Underground Business of BTMOB RATFlare researchers analyzed thousands of underground posts to examine how the BTMOB Android malware operation evolved into a fragmented ecosystem of resellers, source-code vendors, custom versions, and competing sales channels. [...]BLEEPINGCOMPUTER.COM
3 AugChina-based hacker employs DeepSeek in autonomous threat campaignResearchers said the hacker also attempted to test Western AI tools, but ultimately was forced to revert to manual operations to succeed. CYBERSECURITYDIVE.COM
3 AugMetasploit Pro 5.1 ReleasedToday marks the release of Metasploit Pro 5.1 - building upon the foundation laid in 5.0, adding new evasion primitives for HTTP Meterpreter payloads, support for tracking service hierarchies, a deeper and more interactive Network Topology view, and continuing our commitment to a…RAPID7.COM
3 AugINC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 FlawsThe INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the INC Ransomware acce…THEHACKERNEWS.COM
3 AugChinese Actor Weaponizes DeepSeek AI Agent to Attack Security FirmResearchers intercepted and investigated the model, which was attempting to compromise more than 1,200 hosts for proxyjacking to launch further attacks.DARKREADING.COM
3 AugAI Runs the Hack: Chinese Actor Automates Cyberattacks With DeepSeekUnit 42 uncovered an AI-driven Chinese hacking campaign where DeepSeek autonomously scanned targets, selected exploits, and launched attacks. Researchers at Palo Alto’s Unit 42 got a front-row seat to something they’d only theorized about before: an AI system running …SECURITYAFFAIRS.COM
3 AugMore on the OpenAI Agent’s Attack on Hugging FaceHugging Face has published a detailed timeline of the attack. From the summary: The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchmark, which tasks an AI agent with finding and exploiting software vulnerabilities. OpenAI ran this on…SCHNEIER.COM
3 AugWater you waiting for?Cyberattacks hit U.S. water systems. CISA tackles open source security. China’s surveillance machine is exposed. Hotel Wi-Fi gets riskier. Healthcare and police data spill online. Fake SQLite vulnerabilities fool security databases. Monday business briefing. Our guest is Tim Star…THECYBERWIRE.COM
3 AugBitcoin hardware wallet maker destroys some inventory after more than $88 million stolenThe company behind a popular hardware wallet for bitcoin owners was forced to destroy part of its inventory after thieves siphoned more than $88 million from customers through a firmware vulnerability.THERECORD.MEDIA
3 AugNew Tool Traces AI Videos Back to Their SourceResearchers dug into the root of the problem with the goal of promoting industry collaboration on improved protective measures.DARKREADING.COM
3 AugThe AI Act kicks into action, forces companies to be clear about AI chatbotsThe European Union (EU) has started enforcing key parts of the AI Act, with immediate, visible consequences for chatbots, deepfakes and other consumer‑facing AI.MALWAREBYTES.COM
2 AugBlack Hat preview: "Vulnerability Research in the Agentic Age."In this special edition, guest ⁠Yan Shoshitaishvili⁠, Associate Professor, ⁠University of Arizona⁠, joins host ⁠⁠Dave Bittner⁠⁠ to share a preview of his ⁠Black Hat USA 2026⁠ keynote "⁠Vulnerability Research in the Agentic Age⁠." Join Yan and Dave to hear insights on the evolutio…THECYBERWIRE.COM
2 AugWeek in review: Claude breached three companies during tests, AD CS domain-takeover PoC releasedHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: Nono: Open-source sandbox for AI agents AI coding agents run with the same permissions as their users, meaning they can access sensitive files, credentials, and production systems. A…HELPNETSECURITY.COM
2 AugA “No-Logs” VPN That Kept 58 Million Connection Logs: Inside the NotVPN / SplitVPN BreachThey advertised and pinky swore “no logs.” But according to research by MysteriumVPN, they logged. Key takeaways from MysteriumVPN: A threat actor on the Altenen cybercrime forum is distributing a 17 GB SQL database they claim was stolen from SplitVPN (formerly NotVPN…DATABREACHES.NET
2 AugBrinks Home Confirms Data Breach Following ShinyHunters ClaimGuru Baran reports: Brinks Home, one of North America’s largest residential security providers, has confirmed that hackers breached its IT systems after the notorious ShinyHunters extortion group claimed responsibility for stealing nearly five million records tied to the company’…DATABREACHES.NET
2 AugTN: Sumner County Schools provides limited update on data breachAbbey Nutter reports: Sumner County Schools is still working through a reported network breach that forced the district to delay the start of the 2026-27 school year, officials told Main Street Media. The district reported the data breach during a meeting of the Sumner County Boa…DATABREACHES.NET
2 AugSecurity Affairs newsletter Round 588 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Russian Hackers Hijack Hotel Wi-F…SECURITYAFFAIRS.COM
2 AugColdcard warns of wallet seed flaw as stolen amounts reach $88.6 millionColdcard maker Coinkite has disclosed a security flaw affecting multiple generations of its Bitcoin hardware wallets that reduced the randomness used when generating wallet recovery seeds, potentially placing funds at risk. The company has released patched firmware for all affect…CYBERINSIDER.COM
2 AugCareCloud Breach Exposes Medical and Financial Data of 345,000CareCloud disclosed a breach affecting 345,000 people after hackers stole medical and financial data from its AWS-hosted systems. TechCrunch reports that CareCloud, the New Jersey-based health tech company that stores patient records for more than 45,000 providers across the US, …SECURITYAFFAIRS.COM
2 AugCOLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theftA vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator. [...]BLEEPINGCOMPUTER.COM
1 AugAMGEN reports breach to SECFrom Amgen’s filing on July 29 to the Securities and Exchange Commission: Item 1.05 Material Cybersecurity Incidents. In July 2026, Amgen Inc. (the “Company”) identified unauthorized activity involving data stored in cloud environments hosted by third-party clou…DATABREACHES.NET
1 AugThe driver's seat to ransomware.This week, we are joined by ⁠Marcus Hutchins⁠, Principal Threat Researcher at ⁠Expel⁠, sharing their work on "Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs." Researchers examine how the Gentlemen ransomware group used…THECYBERWIRE.COM
1 AugSystem Announcement: MaintenanceDataBreaches.net will be undergoing some maintenance and upgrades this weekend and may be unavailable at times. We’ll be back, though! Thank you for your patience. SourceDATABREACHES.NET
1 AugRuby on Rails Patches Critical VulnerabilityThe flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
1 AugRails patches critical Active Storage flaw with RCE potentialA critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]BLEEPINGCOMPUTER.COM
1 AugMon General Hospital notifies patients of phishing attack and breachWDTV reports: Monongalia County General Hospital Company, known as Mon General, announced it was recently the victim of a phishing attack that may have compromised the personal and medical information of some patients. Hospital officials say the incident was discovered on May 6, …DATABREACHES.NET
1 AugRussian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 TokensMicrosoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian…SECURITYAFFAIRS.COM
1 AugSixth Circuit to Rehear Case on FCC Data Breach Rules CaseJake Neenan reports: A full panel of federal judges will rehear a case that upheld expanded telecom data breach rules. The Federal Communications Commission, now under Republican control, has indicated it’s likely to reverse the rules anyway. But industry groups and GOP lawmakers…DATABREACHES.NET
1 AugThe double extortion of a Russian ransomware threatens the medical records that Diater has kept for 10 years.Miguel Gomez reports: The biopharmaceutical company Diater, founded in Madrid in 1999, has appeared on the list of victims that the ransomware group DeadLock is disseminating on the dark web. The intrusion affects a company that manages particularly sensitive information of patie…DATABREACHES.NET
1 AugCareCloud Data Breach Impacts Over 350,000Ionut Arghire reports: Healthcare information technology company CareCloud is notifying at least 350,000 people that their information was stolen in a data breach. The incident involved an electronic health record environment within the CareCloud Health division, which was disrup…DATABREACHES.NET
1 AugSuspected cyberattack disrupts Oceanside, California, school district systemsDysruptionHub reports: A suspected cyberattack disrupted work email, internet access, Google Drive and other applications at Oceanside Unified School District in California as officials investigated and worked to restore service. The district confirmed a computer network disrupti…DATABREACHES.NET
1 AugAU: GO2 Health medical clinic in Brisbane waited almost three months to alert patients it was hackedWill Murray reports: Another medical clinic has revealed it has been targeted by hackers, less than a week after Partnered Health announced a major data breach. GO2 Health in Everton Park, in Brisbane’s north, said the clinic’s main email mailbox was accessed in April…DATABREACHES.NET
31 JulExploring the Hugging Face Breach: mapping AI agent tactics to Elastic DefendEvery stage of the Hugging Face breach maps to Elastic Defend and SIEM rules already shipping, from worker RCE and credential harvest to self-migrating C2 and GenAI detection.ELASTIC.CO
31 JulMicrosoft confirms an AI worm is propagating through Copilot and other MS appsA prominent Norwegian AI researcher on Tuesday posted details about an AI worm that is wreaking havoc in various Microsoft applications, including Word and Copilot. The report from noted Norwegian AI researcher Håkon Måløy , now confirmed by Microsoft, said that an attacker can c…CSOONLINE.COM
31 JulCompanies push AI, sysadmins keep it on a short leashIn 2024, sysadmins expected AI to automate patch management optimization, vulnerability prioritization, infrastructure monitoring, and incident response within two years. Action1’s 2026 Survey Report: AI Impact on Sysadmins found that those expectations proved overly optimi…HELPNETSECURITY.COM
31 JulAviation cyber risk sits on the ground, the blindness sits in the airIn this interview with Help Net Security, Eliran Almong, CEO of Cyviation, explains why airline cyber losses happen on the ground while the aircraft stays unmonitored. He walks through GNSS jamming that leaves no trace in a SIEM, and a PX4 Autopilot flaw his team disclosed where …HELPNETSECURITY.COM
31 JulResecurity expands threat intelligence integration ecosystem with IBM QRadarResecurity has announced the availability of native integration with IBM QRadar SIEM, a widely used Security Information and Event Management (SIEM) platform used by the leading Fortune 100 corporations worldwide. The plugin is available for activation via IBM Application Exchang…HELPNETSECURITY.COM
31 JulAfter OpenAI, Anthropic finds Claude breached three organizations during cyber testsLess than two weeks after OpenAI disclosed that an experimental AI model breached Hugging Face during a cybersecurity evaluation, Anthropic has revealed that its own review uncovered three incidents in which Claude models gained unauthorized access to the production infrastructur…CSOONLINE.COM
31 Jul5 key priorities for your Black Hat agenda — and what to avoidTwo major conferences loom large on the US cybersecurity events calendar: The RSA Conference and Black Hat. RSA was launched in 1991 by then CEO Jim Bidzos of RSA Data Security, the encryption company founded by Ron Rivest, Adi Shamir, and Leonard Adleman. Originally, the confere…CSOONLINE.COM
31 JulCritical Flaw Led to Azure Cosmos DB PwnageNamed CosmosEscape, the vulnerability exposed the primary key for Cosmos DB accounts, granting full read and write access. The post Critical Flaw Led to Azure Cosmos DB Pwnage appeared first on SecurityWeek .SECURITYWEEK.COM
31 JulWhat the Hugging Face breach reveals about defense in the age of agentic AIWe almost never get both sides of an intrusion. This time we did. Last month, Hugging Face disclosed a breach into part of its production infrastructure, saying an autonomous AI agent system ran the attack from start to finish. Five days later, OpenAI revealed that its own models…CYBERSCOOP.COM
31 JulThe New Defcon Badges Pack a Unique Open Source Chip That Doubles as a Security KeyCreated by legendary hardware hacker Andrew “bunnie” Huang, the badges for this year’s famed security conference aim to push the boundaries of security and transparency.WIRED.COM
31 JulAnthropic’s Claude breached three companies during security testsAnthropic has disclosed that its AI model Claude gained unauthorized access to the systems of three different organizations during cybersecurity evaluations. The disclosure follows OpenAI’s July 21 announcement that some of its models had escaped an isolated testing environ…HELPNETSECURITY.COM
31 JulHorizon3.ai expands NodeZero with automated web application attack path testingHorizon3.ai has expanded its NodeZero platform with AI-powered web application pentesting. The platform can now autonomously test web applications and identify attack paths that chain application vulnerabilities, credential theft, lateral movement, cloud access, and data exposure…HELPNETSECURITY.COM
31 JulAnthropic Finds Claude Breached Real Companies During Security EvaluationsAnthropic says a misconfigured test let Claude access three real organizations, prompting tighter AI evaluation and monitoring controls. Anthropic disclosed that Claude models had accessed the real production infrastructure of three separate organizations during cybersecurity eva…SECURITYAFFAIRS.COM
31 JulAnthropic says Claude AI hacked three organizations during testingAnthropic has disclosed that three Claude models gained unauthorized access to the production infrastructure of three separate organizations after a misconfigured cybersecurity evaluation environment inadvertently allowed internet access. The company says the incidents occurred d…CYBERINSIDER.COM
31 JulFacial Recognition at Madison Square GardenLast month, the story broke (alternate link ) that Madison Square Garden uses facial recognition software on everyone entering the facility, and—among other groups—flags activists that oppose using facial recognition. Turns out that the system was shut off for Taylor …SCHNEIER.COM
31 JulChinese Hacker Commands DeepSeek via Telegram to Launch Autonomous AttacksPalo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. After an initial Telegram instruction, the agent found internet-facing systems and selected public exploits. The researche…THEHACKERNEWS.COM
31 JulEU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in BrusselsWhen the AI Act comes into force, AI companies will be required to make clear to consumers with labels or digital watermarks that chatbots or imagery are generated with AI. The post EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels appeared f…SECURITYWEEK.COM
31 JulMicrosoft almost gave away the keys to everyone’s Azure Cosmos DBsMicrosoft has had a narrow escape from total embarrassment: A security company uncovered a critical vulnerability that could have compromised all Azure Cosmos DB databases — both those of customers and Microsoft’s own. Google subsidiary Wiz found a flaw in the database’s Gremlin …CSOONLINE.COM
31 JulCriminals used AI and children’s coding software to build a multimillion-dollar ad fraud empireA security investigation into inexpensive Android TV boxes led researchers to an ad fraud operation that had remained unnoticed for several years. Fuyao apps ecosystem (Source: Bitsight) According to Bitsight, the operation, named Fuyao, uses preinstalled Android apps, device ide…HELPNETSECURITY.COM
31 JulRapid7 at Black Hat USA 2026: See preemptive security in actionBlack Hat USA returns to Mandalay Bay in Las Vegas this August, bringing together security practitioners, researchers, and leaders from around the world. Rapid7 will be there in the Business Hall, with new capabilities, live demonstrations, expert-led sessions, and two days of ac…RAPID7.COM
31 JulInterpol Leverages Global System to Curtail Fraud PaymentsWhen a fraudulent transaction occurs, law enforcement agencies must work quickly to halt payments before cybercriminals cash out.DARKREADING.COM
31 JulResearchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking FlawAn academic study has disclosed a "widespread class" of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and even session hijacking, allowing an attacker to seize control of a user's network …THEHACKERNEWS.COM
31 JulConsumer Dispute Panel Orders Coupang to Pay Affected Consumers 100,000 Won Each for Data BreachLee Yong-seong reports: The Consumer Dispute Settlement Committee has decided that Coupang must compensate affected consumers 100,000 won [about $70 USD] in cash or 100,000 won in Coupang Cash per person over a large-scale personal data breach, the committee said on the 31st. …DATABREACHES.NET
31 JulNorth Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warnAlexander Martin reports: Cyberattack tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations, according to new research released Thursday alongside a joint advisory by four South Korea…DATABREACHES.NET
31 JulGoogle AI Supercharges Chrome Security, Fixing 1,072 BugsGoogle says AI found and helped fix 1,072 Chrome security bugs in two releases, dramatically accelerating vulnerability detection and patching Google’s Chrome Security team published a detailed account of how AI models have transformed their vulnerability management pipelin…SECURITYAFFAIRS.COM
31 JulElastic goes all-in on Hacker Summer Camp at Black Hat and DEF CON in Las VegasAttack Discovery turns raw alerts into validated threats and Elastic Defend closes vulnerable driver gaps as fast as they're disclosed. Watch it all run against real attacks at the booth.ELASTIC.CO
31 JulIn Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto ResearchNoteworthy stories that might have slipped under the radar: parcel delivery company OnTrac hacked, Adobe patches, UK Department for Education loses 607,000 records. The post In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research appeared fi…SECURITYWEEK.COM
31 JulHacker uses DeepSeek AI to autonomously attack vulnerable serversA Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. [...]BLEEPINGCOMPUTER.COM
31 JulRESOURCE: Thomson Reuters Foundation provides free resources and legal help for independent media around the worldFrom the Thomson Reuters Foundation, a welcome email describes the situation in South Africa and then turns to global support: I’m getting in touch to share some new reports and resources to support media freedom work in East and Southern Africa. Journalists who hold power to acc…DATABREACHES.NET
31 JulWeaponizing Exposed DataLab-1 Dark-web Research Team Contributors:Alex Necula, Anastasia Sentasnova, Ellis Stannard, Jeffrey Bell, Manuel Boll, Valéry Rieß-Marchive Mannie W writes: Ransomware and data-extortion groups are moving beyond bulk dumps to analyze, index and price stolen data before it is pub…DATABREACHES.NET
31 JulRansomware in Italy: RedACT report sheds light on an evolving threat environmentSuspectFile has published a great interview with the people behind RansomNews.online: Within this context, the first RedACT H1 2026 report, published by ransomNews.online, represents a valuable contribution to the analysis of ransomware activity targeting Italy. The project prese…DATABREACHES.NET
31 JulClaude outside the lines.Anthropic says Claude escaped the sandbox three times, while a judge questions the Pentagon’s blacklist. The EU launches an AI enforcement team, the FTC targets a telehealth firm’s tracking pixels, and a WordPress backdoor is stopped just in time. CareCloud discloses a major data…THECYBERWIRE.COM
30 JulCISA unveils a six-step blueprint for isolating critical infrastructure during cyberattacksMost IT operators understand that critical infrastructure should be isolated in crisis situations, but many don’t know how to do it in a way that maximizes security and minimizes disruption. Now, several global agencies are offering a step-by-step action plan, CI Fortify . Releas…CSOONLINE.COM
30 JulExposed credentials are giving attackers a head start many organizations don’t seeCompromised credentials can remain active long after passwords are created, leaving organizations trying to identify exposed accounts before attackers can use them. The 2026 Credential Risk Report from Enzoic shows growing awareness of the problem, but monitoring and response cap…HELPNETSECURITY.COM
30 JulNothing but the spoof.This week, hosts of N2K CyberWire ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Maria Varmazis⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠…THECYBERWIRE.COM
30 Jul KEV200 new CVEs a day and no realistic way to patch them allRyan Dewhurst, CEO at KEVIntel, explains how his team confirms exploitation that CISA’s catalog has not listed yet. He describes a global honeypot sensor network, AI triage, and human verification in a lab before a vulnerability reaches the public feed. He covers CISA’…HELPNETSECURITY.COM
30 JulTop companies to visit at Black Hat USA 2026Black Hat USA 2026 returns to Mandalay Bay with a re-engineered six-day program designed to spark innovation, challenge assumptions, and unite the global security community. The event opens with four days of immersive, expert-led Trainings (August 1-4), continues with Summit Day …HELPNETSECURITY.COM
30 JulData breach cost 2026 averaged $4.99 million, AI attacks ran higherMore than one in four organizations hit by a malicious attack over the past year say AI drove it. Those breaches averaged about $1 million above the malicious attacks that ran without AI. Defenders bought similar technology and aimed it somewhere else. Half of breached organizati…HELPNETSECURITY.COM
30 JulRussian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential RotationThe Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommuni…THEHACKERNEWS.COM
30 JulA Scattered Spider member was indicted. Microsoft’s GDID went to trial.A recently released criminal complaint against Peter Stokes , an alleged member of the Scattered Spider cybercrime group , reveals previously unpublicized details about Windows telemetry . Microsoft has never exactly had a reputation for being privacy-focused, however the complai…CSOONLINE.COM
30 JulAI Scammers Are Better at Building Trust Than HumansResearchers pitted a person against a Claude agent and found that, after a week of texting, the AI chatbot was more effective at creating “exploitable trust” with others.WIRED.COM
30 JulGoogle Releases Patches for 370 Vulnerabilities in Chrome 151The new version of Chrome, 151, comes with 370 vulnerability patches, including for seven critical flawsINFOSECURITY-MAGAZINE.COM
30 JulChinese-Speaking Threat Actor Harnesses AI Models for Autonomous CyberattacksUnit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read more. The post Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
30 JulHackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without PromptsSouth Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE b…THEHACKERNEWS.COM
30 JulBuilding secure Uniswap v4 hooksUniswap v4 hooks let developers add custom behavior to pools, including dynamic fees, custom accounting, and external integrations. This flexibility moves some security responsibilities into application and hook code. The Cork and Bunni exploits are two app-level incidents that s…TRAILOFBITS.COM
30 JulAnalog Devices says hackers stole company files in June cyberattackAnalog Devices has disclosed that it suffered a cyberattack in June, resulting in unauthorized access to internal systems and the theft of company files. The semiconductor manufacturer said the incident did not disrupt operations and that it is still investigating the scope of th…CYBERINSIDER.COM
30 JulPortSwigger introduces Burp AT for agentic AI security testingPortSwigger has announced the public beta of Burp AT, a new addition to Burp Suite that brings agentic AI to professional penetration testing. Burp AT enables penetration testers to delegate defined investigative tasks to AI agents that use Burp Suite’s tools, project conte…HELPNETSECURITY.COM
30 JulCosmosEscape: Taking Over Every Database in Azure Cosmos DBA critical vulnerability chain in Azure Cosmos DB enabled full read and write access to every Cosmos DB database.WIZ.IO
30 JulHHS OCR Settles Ransomware Investigation of OSF Healthcare System and Affiliated Covered EntitiesIn June 2021, DataBreaches reported on a ransomware attack affecting OSF Healthcare by a little-known gang called Xing Team. Our reporting noted OSF’s lack or response to inquiries and lack of timely notification. When OSF issued a statement in October, DataBreaches reporte…DATABREACHES.NET
30 JulKR: KT Fined 54 Billion Won Over Data Breach via Illegal Base StationsTwo years after a malware incident that was not handled in accordance with South Korea’s requirements, KT has been fined. Lee Jin-seok reports: KT has been fined more than 53.9 billion won [USD $37,630,484.43] over a personal data breach and unauthorized micropayment damage…DATABREACHES.NET
30 JulMicrosoft Copilot for Word Can Copy Hidden Prompts Into New DocumentsHidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. Håkon Måløy disclosed the technique on July 28, 144 days after reporting it to Microsoft. In his proof of concept, the intern…THEHACKERNEWS.COM
30 JulAI agents gain access to financial workflows amid growing governance gapsAI agents are now being allowed to create business records, approve transactions, and execute financial workflows. ERP security firm Pathlock says most organizations don’t know if that is all they are doing. The company’s 2026 AI Governance Gap Report found that 79% of organizati…CSOONLINE.COM
30 JulNorth Korean hackers behind major open-source supply chain attacks, Amazon saysA North Korea-linked hacker group was behind several high-profile compromises of open-source software libraries used by developers worldwide, researchers have found.THERECORD.MEDIA
30 JulAnalog Devices Discloses Data Breach After Unauthorized System AccessChipmaker Analog Devices disclosed a data breach after detecting unauthorized access to systems on June 23. The investigation is ongoing. Semiconductor giant Analog Devices (ADI) disclosed a data breach following a cyberattack that resulted in unauthorized access to some of its s…SECURITYAFFAIRS.COM
30 JulAzure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any DatabaseA now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chain CosmosEscape, said the exploit chain b…THEHACKERNEWS.COM
30 JulAI Expands Your Attack SurfaceAI adoption introduces new responsibilities for security teams. Beyond traditional tasks like audits, controls, and awareness training, security leaders must now evaluate AI platforms, data usage, and integrations. AI systems rarely operate alone. Connections to cloud environment…YOUTUBE.COM
30 JulMicrosoft Copilot for Word vulnerable to self-propagating worm-like attackSecurity researcher Håkon Måløy has disclosed a proof-of-concept attack showing how malicious prompts hidden inside Microsoft Word documents can spread between files through Microsoft Copilot for Word. The research suggests that attacker-controlled instructions embedded in one do…CYBERINSIDER.COM
30 JulShadow AI, leadership resistance make AI governance tough for worried CISOsFewer than half of CISOs think their bosses see AI security as a business enabler, according to an Okta survey.CYBERSECURITYDIVE.COM
30 JulRapid7 named a Leader in the IDC MarketScape: Worldwide MDR Service for Midmarket 2026 Vendor AssessmentIDC has named Rapid7 a Leader in the 2026 Worldwide Managed Detection and Response Service for Midmarket 2026 Vendor Assessment ( Doc #US52992326, July 2026 ). We believe this recognition and research highlights where MDR is heading. Many security programs are still built around …RAPID7.COM
30 JulCrime Stoppers International seeking tips on INC Ransom as part of new bounty program: Operation Silent VectorCrime Stoppers International has announced a new program: Operation Silent Vector. And the first target they are offering a bounty for is INC Ransomware. Cybercriminals operate behind anonymity; this program pulls that mask off. Crime Stoppers International is seeking tips to acc…DATABREACHES.NET
30 JulThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More StoriesA lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abused trust, and explo…THEHACKERNEWS.COM
30 JulOkta buys AI security startup Permiso; source says for about $200MThe deal gives Okta identity threat detection capabilities as enterprises seek to secure AI agents and other non-human identities across cloud environments.TECHCRUNCH.COM
30 JulCanada’s Bill C-8 is here: Why the 72-hour reporting rule will redefine critical infrastructure securityCanada’s new Critical Cyber Systems Protection Act (Bill C-8) introduces a strict 72-hour cyber incident reporting mandate. Find out how Tenable is helping critical national infrastructure operators bridge the IT/OT divide to ensure full compliance. Key takeaways: Bill C-8 introd…TENABLE.COM
30 JulChrome Needs Twice-a-Week Patching Thanks to AI Bug HuntingThe two Chrome updates in June patched more bugs than the 23 updates before them. Now, Google is ramping up its patching schedule thanks to AI-assisted vulnerability discovery.WIRED.COM
30 JulGoogle says AI helped Chrome fix 1,072 security bugs in two releasesGoogle says artificial intelligence is dramatically increasing the number of security vulnerabilities it can find and fix in Chrome, with more than 1,000 security bugs patched across the browser's two most recent releases as it expands its use of AI. [...]BLEEPINGCOMPUTER.COM
30 JulShinyHunters claims Brinks Home breach, threatens to leak stolen dataResidential security company Brinks Home has disclosed that hackers breached some of its systems and are threatening to leak allegedly stolen data. [...]BLEEPINGCOMPUTER.COM
30 JulExtend Amazon Inspector SBOM Generator with PluginsAmazon Inspector is an automated vulnerability management service that continually scans Amazon Web Services (AWS) workloads for software vulnerabilities. The vulnerability management capabilities of Amazon Inspector are powered by an asset inventory engine known as the Amazon In…AWS.AMAZON.COM
30 JulFamily says woman violated HIPAA, ‘weaponized’ infoChris Dickerson reports: A medical administrator spent years secretly accessing a family’s medical records and “weaponizing” their private health information for a family dispute, according to a newly filed civil lawsuit. The plaintiffs, identified only by their initials, filed t…DATABREACHES.NET
30 JulCybercriminals Are Leveraging Autonomous AI Offensive Security AgentsResecurity warns AI offensive agents are lowering hacking barriers, fueling an AI-driven race between attackers and defenders. Resecurity analyzed how autonomous offensive security agents such as T3MP3ST, Strix, CyberStrike, XBOW, PentAGI, PentestGPT, and Nebula lower the barrier…SECURITYAFFAIRS.COM
30 JulCISA issues recommendations to federal agencies on open-source software securityOne expert said they were pleased by the guidance, which touches on open-weight AI models, patching and more. The post CISA issues recommendations to federal agencies on open-source software security appeared first on CyberScoop .CYBERSCOOP.COM
30 JulAmazon links Debug, Chalk NPM supply-chain attacks to North Korean hackersAmazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers. [...]BLEEPINGCOMPUTER.COM
30 JulAI Harnesses Burst With Potential Exploit OppsA myriad of software makes up the typical AI harness, and trust issues between the components can create concerning attack vectors.DARKREADING.COM
30 JulWhat water utilities need to know about cybersecurity complianceAs federal enforcement tightens and states begin stepping in with their own cybersecurity mandates, water and wastewater utilities face a looming wave of hard compliance deadlines, compounded by recent cyber attacks on state water utilities. Key takeaways While the EPA’s national…TENABLE.COM
30 JulA coordinated attack hit 30+ Minnesota water systems. Who did it, and what does a Rockwell notice add to the picture?A coordinated cyberattack that targeted more than 30 Minnesota community water systems has alarmed industrial cybersecurity experts, not because it caused widespread disruption, but because it appears to represent the first distributed campaign against dozens of small utilities l…CSOONLINE.COM
30 JulSandwich Hats - PSW #937In the security news: - 2.2 million cars, one shared Bluetooth key - JFrog tries to spin an AI 0-day into a win - Sextortion scammers recycling ShinyHunters' leaks - The first hack ever, from 1966 - Prompt injection as a service, $150 a month - Cisco's mystery "static credential"…YOUTUBE.COM
30 JulJetBrains warns of critical TeamCity remote code execution flawJetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code execution. [...]BLEEPINGCOMPUTER.COM
30 JulWhen AI Guardrails Don't MatchA firsthand test showed the same request triggering a safety guardrail in one interface while receiving a normal response through another interface using the same AI model. The discussion suggests implementation differences—such as where guardrails are applied—can lead to inconsi…YOUTUBE.COM
29 JulHow AI is Rewriting the Zero-Day Playbook for Preemptive SecurityThe scenario is all too familiar for any cybersecurity professional: It’s late in the day, and a critical zero-day vulnerability is disclosed. When this happens, CISOs from every industry immediately turn to their Security Operations Centers (SOC) with the single most important, …RAPID7.COM
29 JulClaude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES AttackAnthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic's…THEHACKERNEWS.COM
29 Jul KEVArista patches maximum severity vulnerability that is already being exploitedArista has patched a VeloCloud Orchestrator (VCO) security hole that has been actively leveraged in the wild, one that the vendor says “may allow a remote attacker to access privileged internal functionality and impact the VCO host.” The Arista security advisory added that the ho…CSOONLINE.COM
29 JulMeasuring LLMs’ Ability to Perform CryptanalysisThere’s new benchmark measuring AI’s ability to perform mathematical cryptanalysis. Anthropic’s frontier model actually found new attacks. The benchmark: “ CryptanalysisBench: Can LLMs do Cryptanalysis? ” The idea is to benchmark the ability of LLMs …SCHNEIER.COM
29 JulFortinet’s new FortiGate platform converges firewall, SASE technologiesFortinet has expanded its firewall family with new high-speed boxes that, when combined with the vendor’s FortiSASE Outpost software, extend cloud-based SASE (secure access service edge) capabilities and policy enforcement to on-premises environments. The new midrange FortiGate 1…CSOONLINE.COM
29 JulThe CSO’s blind spot: Why platform engineering 2.0 is now a security imperativeSecurity leaders have spent the last decade building controls around people and code. Shift-left practices caught vulnerabilities earlier in the development cycle. Zero trust reduced lateral blast radius. Developer tooling added guardrails at the IDE. The architecture was sound —…CSOONLINE.COM
29 JulWhat a CISO and Marketing Partnership Actually Looks Like with Jason Rebholz of Evoke SecurityJason Rebholz read a blog post about MCPs and saw the whole trajectory of AI security play out in front of him. Twenty years of incident response experience told him we were about to make the same mistakes…just faster. He started Evoke Security the same way he has approached ever…THECYBERWIRE.COM
29 JulSpecter: Open-source NFC reader bug sweep for Flipper ZeroSpecter is a Flipper Zero app that finds powered NFC readers by listening for the radio field they give off. The readers it hunts work at 13.56 MHz. The Flipper’s own chip does the sensing The onboard ST25R3916 carries a hardware external-field detector, the same circuit th…HELPNETSECURITY.COM
29 JulYour AI agents can reach data no one approvedA credential expired. An AI agent kept using it anyway, and a mid-sized company’s systems went down for a quarter’s worth of trouble before anyone traced the failure back to a non-human account no one had been logging. That agent could reach customer records, source c…HELPNETSECURITY.COM
29 JulFlying Eagle Android RAT Traces Found on 170 Servers as Source Code CirculatesSource code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced matching control panels and certificates to 170 internet servers. They linked the framework to a fa…THEHACKERNEWS.COM
29 JulAbnormal AI extends behavioral security to identities, AI systems, and insider threatsAbnormal AI has announced the expansion of its Behavioral Security Platform across the enterprise, introducing three new products: Identity Threat Protection, AI Governance, and Infiltration Prevention. Together, the launch extends the behavioral AI that already secures over 4,50…HELPNETSECURITY.COM
29 JulMend.io enhances application security with AI runtime protection and faster zero-day responseMend.io has announced new capabilities across Mend AI and Mend AppSec to help organizations respond faster to both application risk and the expanding attack surface created by AI. Mend.io’s latest enhancements help teams identify meaningful risk, reduce manual investigation…HELPNETSECURITY.COM
29 JulReco enhances AI Runtime with browser-based AI security and automated remediationReco has announced an expansion of AI Runtime, a core component of the Reco Platform. This update adds browser-based enforcement, real-time prompt analysis and blocking, and automated remediation to the Reco Platform. Every agent an enterprise runs carries a blast radius: the app…HELPNETSECURITY.COM
29 JulInfoblox enters EASM market with attack surface and supply chain risk toolsInfoblox has announced its entry into the external attack surface management (EASM) market. Together, with the introduction of Supply Chain Intelligence, the launch expands the Infoblox Exposure Management portfolio, helping organizations identify, prioritize and reduce exposures…HELPNETSECURITY.COM
29 Jul KEVRisk-based patching is the future. AI made it table stakesCISA’s new Binding Operational Directive (BOD) 26-04 marks one of the most important changes to federal vulnerability management in years. Rather than requiring agencies to patch every critical vulnerability on the same timetable, the directive prioritizes remediation based on ri…CSOONLINE.COM
29 JulJFrog Zero-Days Exploited in OpenAI-Hugging Face HackThe OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given. The post JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack appeared first on SecurityWeek .SECURITYWEEK.COM
29 JulFortiGate 1200G brings FortiSASE Outpost to customer-controlled environmentsFortinet has announced the FortiGate 1200G series, the newest addition to the FortiGate G series with FortiSASE Outpost, which brings cloud-delivered security services into customer-controlled environments. By combining high-performance threat protection, connectivity, hardware-r…HELPNETSECURITY.COM
29 JulWhatsApp brings end-to-end encrypted voice and video calls to the webWhatsApp has launched support for voice and video calls on the web, allowing users to make and receive calls directly from their browser without installing the desktop app. Web Calling (Source: WhatsApp) The new Web Calling feature is designed for people using shared or restricte…HELPNETSECURITY.COM
29 JulRoot Evidence puts real-world evidence at the center of vulnerability prioritizationRoot Evidence has launched the Evidence Platform, a vulnerability management platform that prioritizes vulnerabilities based on evidence of real-world exploitation and financial impact rather than severity scores alone. The platform is designed to help security teams focus on the…HELPNETSECURITY.COM
29 JulTransparency, The Key To Team Motivation For Remote Workers - Charles Gaudet - BSW #458Since the pandemic, managing remote teams have been challenging. How do you measure performance and motivate teams when they are remote? Charles Gaudet, CEO & Founder at Predictable Profits, joins Business Security Weekly to discuss why transparency is the key to team motivation …YOUTUBE.COM
29 JulLong-Lived Vulnerability in Microsoft Secure BootMicrosoft’s Secure Boot has had a serious vulnerability for most of its existence. An industry-wide standard Microsoft invented to protect Windows, and later Linux, devices from firmware infections has been trivial to bypass for 13 of its 14 years of existence. The discover…SCHNEIER.COM
29 JulIt’s easier to steal cargo than toothpasteOur cybersecurity world can get quite interesting and even close to science fiction sometimes. No, it’s not AI this time, but something movie-worthy nevertheless. Picture scenes from known heist-themed movies such as “Ocean’s Eleven” or “Mission: Impossible”. Real-world equivalen…CSOONLINE.COM
29 Jul KEVJust 1% of AI-Discovered Vulnerabilities Exploited in the Wild, Research ShowsFor now, the use of AI benefits vulnerability research more than vulnerability exploitation, a VulnCheck researcher saidINFOSECURITY-MAGAZINE.COM
29 JulExploiting Titan QuestTitan Quest is a hack-and-slash video game released in 2006. In 2016, THQ Nordic released an Anniversary Edition. In the version provided by GOG, several development tools are installed with the game. These allow for the creation of new maps, items, and effects. This article deta…SYNACKTIV.COM
29 JulCritical VM Escape Vulnerability Patched in VMware ESXiA total of five vulnerabilities have been patched in VMware ESXi, vCenter, Workstation, and Fusion. The post Critical VM Escape Vulnerability Patched in VMware ESXi appeared first on SecurityWeek .SECURITYWEEK.COM
29 JulOpenAI AI Model Used JFrog Artifactory Zero-Day Before Hugging Face BreachOpenAI confirmed its AI exploited an Artifactory zero-day to escape its test environment before breaching Hugging Face. Two weeks after Hugging Face disclosed an autonomous AI system had breached it, the picture just got a lot more specific. OpenAI has published an update confirm…SECURITYAFFAIRS.COM
29 JulMythos Asks the Right Question. It Doesn't Answer It.AI is compressing exploit timelines. The real question isn't whether your vulnerability management playbook needs to change, it's which part of it you've been getting wrong all along. The conversation happening in security circles right now goes something like this: Mythos is her…THEHACKERNEWS.COM
29 Jul KEVOpenAI rogue AI agent’s attack expanded beyond Hugging FaceThe autonomous AI agent that escaped during OpenAI testing exploited weaknesses across a customer workload, a third-party cloud platform, and Hugging Face’s production environment before being contained, according to new technical disclosures that provide the clearest picture yet…CSOONLINE.COM
29 JulShutterGap: Aryon Security finds 3.7M AWS cloud resources exposed beyond CSPM/CNAPP visibilityResearch from Aryon reveals that each year, 3,731,699 short-lived cloud resources containing highly sensitive information are publicly exposed. This impacts any organization using AWS services that support public sharing. These exposures often last only minutes or hours, too brie…HELPNETSECURITY.COM
29 JulTengu botnet reboots Linux devices to survive removalA new Mirai-derived IoT botnet can force an infected Linux device to reboot once its main process is killed, giving its persistence mechanisms another opportunity to relaunch it, Nozomi Networks Labs has found. The malware, dubbed Tengu, was discovered by a machine-learning syste…HELPNETSECURITY.COM
29 JulThe Wiz Red Agent is Now Generally AvailableContinuously uncover complex, exploitable risks to stay ahead in the AI Threat Era with the Red AgentWIZ.IO
29 JulNine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance PaymentsCybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years. According to Russian cybersecurity vendor F6, the t…THEHACKERNEWS.COM
29 JulLaundry Bear’s webmail hackers had more in store after February, report saysResearchers say the Russian state-linked hacking group tracked as Laundry Bear recently began exploiting a bug in Microsoft Outlook Web Access.THERECORD.MEDIA
29 JulShinyHunters Claims Ernst & Young Data Breach, Threatens to Leak Stolen DataShinyHunters claimed the Ernst & Young data breach, threatening to leak stolen tax records unless the firm contacts the group by July 31. The ShinyHunters cybercrime group has taken responsibility for the recently disclosed data breach involving professional services firm Ern…SECURITYAFFAIRS.COM
29 JulMythos takes its first shot at post-quantum cryptographyAnthropic’s Claude Mythos Preview model has helped researchers discover ways to speed up attacks against two widely studied cryptographic algorithms. One of the targets is Hawk, a candidate for post-quantum digital signature algorithms currently being evaluated by NIST, while the…CSOONLINE.COM
29 JulTame Dependabot: Group your updates, slow the cadence, keep security fastDependabot keeps your dependencies current, but its defaults can flood your repository with pull requests. Here's how grouping updates, slowing the cadence, and keeping security fixes fast cut the noise on a Microsoft open source project. The post Tame Dependabot: Group your upda…GITHUB.BLOG
29 JulRussian-Alligned TA488 Returns With Persistent Outlook Web Access AttackTA488 returned with OWA half-click exploit deploying OWAReaper implant that survived re-imagingINFOSECURITY-MAGAZINE.COM
29 JulPatch-Resistant 'RufRoot' Flaw Can Unleash Malicious AI Agent SwarmsThe vulnerability in the AI hosting platform Ruflo allows an unauthenticated attacker to take over the system and corrupt memory, so bad behavior can persist after patching.DARKREADING.COM
29 JulMeasuring the Tendency of AI Agents to Go RogueThis essay was written with Barath Raghavan, and originally appeared in The Guardian . In July, Hugging Face, a company that hosts much of the world’s AI software and open-source AI models, was hacked. A malicious dataset had been used to run code on one of its servers. Who…SCHNEIER.COM
29 JulVU#293714: Arbitrary File Overwrite in Develar app-builder (zipx.Unzip) via Symlink Following on macOS (APFS)Overview A vulnerability in the zipx.Unzip extraction routine of Develar’s app-builder allows an attacker to overwrite arbitrary files on macOS using Apple File System (APFS). The issue arises from a combination of Unicode normalization collisions and unsafe symlink-following beh…KB.CERT.ORG
29 JulAmazon identifies North Korean hacker group behind open-source supply chain attacksAmazon is sharing new findings about how a threat actor linked to the Democratic People’s Republic of Korea (DPRK) is targeting open source software libraries, the shared building blocks that companies around the world use to develop applications. Amazon Threat Intelligence has l…AWS.AMAZON.COM
29 JulOpenAI's Rogue Model Claims More Victims Beyond Hugging FaceOpenAI revealed rogue AI models compromised more services than initially disclosed, including a Modal customer environment and others.DARKREADING.COM
29 JulA little-known npm package was North Korea’s warm-up act for the axios hackAmazon's threat intelligence team traced domain records from the open-source software hack to a smaller, earlier compromise by the same North Korean group. The post A little-known npm package was North Korea’s warm-up act for the axios hack appeared first on CyberScoop .CYBERSCOOP.COM
29 JulRussian hackers exploit Exchange OWA zero-day for long-term mailbox accessThe Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper. [...]BLEEPINGCOMPUTER.COM
28 JulAI Agent Drives Espionage Attack on Thai Ministry of FinanceAttackers used Hermes, an autonomous open source tool, in unrestricted "YOLO mode" to conduct espionage against Thailand's Ministry of Finance.DARKREADING.COM
28 JulSamsung’s entry into AI-powered glasses forces CISOs to again consider corporate riskNow that Samsung has jumped into the crowded AI-powered glasses arena alongside Apple , Google , Meta , and others, CISOs and IT leaders are again having to think through whether it makes sense to establish enterprise restrictions on such devices, given the likely data leakage an…CSOONLINE.COM
28 JulHackers are compromising hotel Wi-Fi gateways to hijack Microsoft 365 accountsTraveling enterprise employees beware: Think twice before you log onto that oh-so-convenient public Wi-Fi. Since at least June, threat actors have been compromising “captive” Wi-Fi gateways and other portal appliances at hotels, conference centers, and similar shared venues to hi…CSOONLINE.COM
28 JulMicrosoft unveils multi-model agentic cyber stack for security operationsMicrosoft announced a new AI-powered service that enables enterprise security teams to continuously evaluate and update their organization’s security posture through a series of AI agents that can find vulnerabilities, simulate attacks, detect and triage potential threats, and de…CSOONLINE.COM
28 JulCybersecurity jobs available right now: July 28, 2026Cloud Security Engineer Toyota Automated Logistics | USA | On-site – View job details As a Cloud Security Engineer, you will design and enforce security controls across Azure and on-premises environments, strengthen identity and access management, and maintain clo…HELPNETSECURITY.COM
28 JulMicrosoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the CostMicrosoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% les…THEHACKERNEWS.COM
28 JulCritical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-DayImpacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality. The post Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
28 JulHugging Face breach shows why incident response needs a multi-model AI strategyThe recent breach of Hugging Face’s platform was the latest in a string of AI-assisted intrusions to come to light in recent weeks , showing that attackers can now use LLMs to automate entire attack chains. But it also exposed a limitation for defenders trying to use AI to respon…CSOONLINE.COM
28 JulUnpatched Fastjson Vulnerability Exploited in AttacksThe critical remote code execution bug can be exploited without authentication, under the library’s stock default configurations. The post Unpatched Fastjson Vulnerability Exploited in Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
28 JulRapid7 and Exclusive Networks expand partnership to modernize security operations and accelerate customer successClaudia Zoon is Senior Manager, Channel Sales at Rapid7. Across Belgium, the Netherlands, and Luxembourg, organizations are accelerating digital transformation through AI, cloud adoption, and increasingly connected business operations. These investments are creating new opportuni…RAPID7.COM
28 JulWhy your AI safety certificates are worthless at runtimeEvery week, another enterprise technology vendor issues a glossy press release announcing their new autonomous AI agent architecture, complete with a SOC 2 Type II report, an ISO 42001 certification, and an ironclad safety guarantee. On paper, the enterprise security battle looks…CSOONLINE.COM
28 JulInside the OWASP Agent Security Regression Harness Project - Mert Satilmaz - ASW #393Orgs need to be able to use agents, MCPs, and LLMs in ways that don't lead to unexpected actions and undesirable outcomes. The OWASP Agent Security Regression Harness project is an approach for defining customizable scenarios and testing whether those systems fail against known s…YOUTUBE.COM
28 JulData breach at medical billing firm MCBS affects 1.26 million peopleHealthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people. [...]BLEEPINGCOMPUTER.COM
28 Jul KEVHow we use /goal to find bugs in Patch the PlanetCodex’s /goal feature amplifies bug hunting, but getting good results requires the right prompt, the right scope, and the right number of outcomes per run. For Patch the Planet , our joint initiative with OpenAI to find and fix bugs in open-source software, we pointed Codex at so…TRAILOFBITS.COM
28 JulExposed BMCs hand out password hashes before loginAn attacker who reaches UDP port 623 on a server’s baseboard management controller can ask it for a password hash and receive one before logging in. The exchange is part of the IPMI 2.0 handshake, built on an authentication protocol introduced in 2004. That controller runs …HELPNETSECURITY.COM
28 JulInfoblox joins crowded EASM market with DNS-centric approachWith AI compressing reconnaissance and exploit development from weeks to hours, security vendors are racing to help enterprises identify exposures long before an incident happens. Infoblox is the latest to make that move, announcing its entry into the External Attack Surface Mana…CSOONLINE.COM
28 JulOver 24,000 exposed server BMCs leak password hash via decades-old flawMore than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface. [...]BLEEPINGCOMPUTER.COM
28 JulThe Next Evolution of MDR: Preemptive Defense and Agentic InvestigationFor years, security operations followed a familiar sequence: detect suspicious activity, investigate what happened, and respond before it caused significant harm. That model developed in a threat landscape where defenders had considerably more time to establish the facts and deci…RAPID7.COM
28 JulJFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face BreachJFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog's software repository manager. OpenAI says the models then escalated privileges and moved late…THEHACKERNEWS.COM
28 JulBugcrowd introduces Savant Pathseeker for agentic penetration testing with exploit validationBugcrowd unveils Savant Pathseeker, the first solution in its Agentic Offensive Testing line. Savant Pathseeker gives security teams the speed and scale to test every external web application and API continuously, not just the assets that make it onto the pentest schedule, while …HELPNETSECURITY.COM
28 JulMultiple water facilities in Minnesota attacked; Iranian hackers may be responsibleOn June 16, media reported that Iran-linked Handala had attacked Cal Water. There was no evidence that they tampered with the water supply, but the group warned it would be increasing attacks on U.S. critical infrastructure. On July 23, the Iran-linked WANA News reported: Followi…DATABREACHES.NET
28 JulSystem Prompts Can FailSystem prompts help guide an LLM's behavior, but they aren't a reliable security control. During testing, both open-source and some frontier models were observed ignoring system prompts and exposing information that should have remained protected. As organizations adopt AI agents…YOUTUBE.COM
28 JulAI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/schedAI-assisted research uncovered Linux kernel use-after-free allowing root escalationINFOSECURITY-MAGAZINE.COM
28 JulTengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its ProcessA new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process. If that happens, Tengu's other persistence mechanisms get another chance to relaunch it. Nozomi Networks Labs observed the drop…THEHACKERNEWS.COM
28 JulAI-assisted security tools are finding more bugs, but the threat level has not changedAnalysis from vulnerability intelligence firm VulnCheck shows AI-discovered flaws aren't being exploited any faster than traditional ones. The post AI-assisted security tools are finding more bugs, but the threat level has not changed appeared first on CyberScoop .CYBERSCOOP.COM
28 JulA senator looks to eliminate legacy VPNs from federal government.Decades-old vulnerability exposes 24,000 servers.THECYBERWIRE.COM
28 JulPrivacy-focused search engine NeoSearch open-sources code to promote decentralized web searchPrivacy-focused search engine NeoSearch has open-sourced its code under the Apache License 2.0, allowing users, developers, and researchers to inspect, modify, and run their own versions of the platform. The independent, ad-free search engine said the move is part of its broader …CYBERINSIDER.COM
28 JulFBI sees Anthropic’s Mythos as a law enforcement challengeThe post FBI sees Anthropic’s Mythos as a law enforcement challenge appeared first on CyberScoop .FEDSCOOP.COM
28 Jul'Certighost' Flaw Haunts Microsoft Active Directory CertificatesMicrosoft patched a high-severity vulnerability earlier this month that allows a threat actor to escalate privileges and compromise an AD environment.DARKREADING.COM
28 JulAI Security at Scale, CMMC phase II paused, and the Weekly Enterprise News - ESW #468Interview with Keith Hollender, CEO and Co-Founder of Arcova Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem As enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introduc…YOUTUBE.COM
28 JulvBulletin fixes critical pre-auth RCE flaw with public exploitA critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. [...]BLEEPINGCOMPUTER.COM
28 JulDysphoria Botnet Uses Blockchain Domains to Hide C2 InfrastructureResearchers uncovered the 200,000-device Dysphoria botnet, which uses Ethereum and Solana domains to hide its command servers. QiAnXin XLab, jointly with China’s CNCERT, disclosed Dysphoria, a botnet that has compromised roughly 200,000 devices worldwide and uses Ethereum a…SECURITYAFFAIRS.COM
28 JulOpenAI models used Artifactory zero-days to escape to the internetJFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging Face. [...]BLEEPINGCOMPUTER.COM
28 JulCubePilot drone software dev hit by DNS hijacking to intercept trafficCubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack. [...]BLEEPINGCOMPUTER.COM
28 JulGhost Credentials Expose Cloud Systems to Hidden Identity RisksSecurity researcher Aleksandr Krasnov reveals dormant non-human identities can create security blind spots and releases NHI Hound, an open source tool to sniff out trust paths.DARKREADING.COM
28 JulSN 1089: Models Go Rogue & ExploitGym - Regulators, Start Your EnginesWhat happens when an unconstrained OpenAI model goes rogue and hacks into Hugging Face, breaching real-world security boundaries? This episode unpacks a watershed moment for AI safety that has everyone in cybersecurity talking. OpenAI's unconstrained internal testing AI got loose…TWIT.TV
27 JulHotel Wi-Fi Hijack, Six Years For A Snapchat Predator, Chicken on the hacking menu globallyHotel Wi‑Fi steals Microsoft 365 logins, ShinyHunters sextortion spam, and Chick‑fil‑A stuffed again Hotel and conference Wi‑Fi networks are being hijacked to harvest Microsoft 365 credentials by compromising captive portals and DNS, redirecting travelers to convincing lookalike …CYBERSECURITYTODAY.LIBSYN.COM
27 JulMarathon Petroleum’s CISO on OT security automation, supply chain riskIn this interview with Help Net Security, Mary Rose Martinez, CISO at Marathon Petroleum, talks about what happens to security when automation reaches deep into refineries, pipelines, and terminals. She explains why the old idea of air-gapped operational technology has faded, how…HELPNETSECURITY.COM
27 JulNono: Open-source sandbox for AI agentsAn AI coding agent opens a terminal, reads a config file, and finds a live cloud key sitting in plaintext. It runs with the permissions of the person who launched it. Every file that person can read, the agent reads. Every credential in the environment, the agent can use. That re…HELPNETSECURITY.COM
27 JulSteam Workshop malware exploited MECCHA CHAMELEON flaw to infect playersA malicious Steam Workshop map for the indie game MECCHA CHAMELEON abused a vulnerability in the game's mod-loading system to execute malware on players' PCs. Following public disclosure, the developers released an update that fixes the issue, and Steam has removed the known mali…CYBERINSIDER.COM
27 JulRisky Bulletin: A JSON RCE bug is about to rock the Java worldA JSON bug is about to rock the Java world, scam compounds continue in Myanmar despite the junta crackdown, and Google has a new APT naming scheme.RISKY.BIZ
27 JulWhen the hackers get hacked: The Klue breach and the new reality of third-party cyber riskIn cybersecurity, defenders sometimes naively assume that threat actors operate from secure, resilient infrastructures insulated from the very chaos they inflict on others. The 2026 compromise of Klue challenges that assumption. What began as a software-as-a-service supply chain …CSOONLINE.COM
27 JulExploring AI Network Protocols; Vulnerability Truths and Guarantees; and the News - ESW #469Segment 1 - Interview with O'Shea Bowens What do we really know about "AI Network Protocols"? Network security is about to get popular all over again. Generative AI caused a disruptive explosion across all of tech and every company’s roadmap. The move from chatbots to AI agents d…YOUTUBE.COM
27 JulIn the Mythos era, security belongs at runtimeFrontier AI cut time-to-exploit from years to hours. Why defense now has to happen at runtime.CYBERSECURITYDIVE.COM
27 JulThe containment paradox: Why your ransomware playbook has the wrong people in chargeI have sat in on a version of the same incident post-mortem in three sectors over the past two years. The script does not vary much. At 4:47 a.m. on a Saturday, an on-duty SOC analyst sees a ransomware payload spreading across three servers in the data center. The playbook says i…CSOONLINE.COM
27 JulAnthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on ExploitsBinary-based vulnerability scanning, penetration testing, and exploit generation are blocked in Opus 5. The post Anthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on Exploits appeared first on SecurityWeek .SECURITYWEEK.COM
27 JulCognyte Sells a Mobile Cell Surveillance VanYet another Israeli mass surveillance company : Made by Israeli surveillance company Cognyte, the tech simulates a mobile phone tower, which forces nearby phones to connect to it. That enables cops to keep tabs on any phones in the vicinity ­ whether they’re owned by a suspect in…SCHNEIER.COM
27 JulCertighost haunts Microsoft Active Directory Certificate ServicesA vulnerability in Microsoft’s Active Directory Certificate Services (AD CS) could allow a low-privilege domain user to impersonate a Domain Controller, security researchers have warned. Dubbed Certighost, the flaw stems from an enrollment fallback mechanism known as a “chase,” w…CSOONLINE.COM
27 JulOpenAI not part of the new Open Secure AI AllianceOpenAI is noticeably absent from the list of initial supporters of a new industry initiative to promote the creation of strong, safe, defensive AI cybersecurity tools built on open-source platforms. The Open Secure AI Alliance is an initiative of Nvidia with the backing of over 3…CSOONLINE.COM
27 JulChatGPT joins the most impersonated brands in phishing attacksMicrosoft continued to be the most impersonated brand in Q2 2026, accounting for 23% of all brand phishing attempts. LinkedIn, Google, Apple, and Amazon followed, with the five brands together making up more than half of all brand phishing attempts tracked during the quarter, acc…HELPNETSECURITY.COM
27 JulAccountant laundered $5.3 million stolen from Children’s Healthcare of Atlanta by hacker, prosecutors sayDan Raby provides this morning’s example of the insider threat: A former accountant has been sentenced to years in federal prison after he was convicted for taking part in a scheme to laundering more than $5.3 million stolen from Children’s Healthcare of Atlanta. Rona…DATABREACHES.NET
27 JulUK: Council worker who snooped on records handed a suspended sentenceFrom the Information Commissioner’s Office: A council worker who unlawfully accessed hundreds of personal records has been handed a suspended sentence. Geoffrey Smith, 31, from Ledbury, Herefordshire, was a new employee at Herefordshire Council working in the Children and Y…DATABREACHES.NET
27 JulGitLab Users Urged to Patch After Research Reveals Critical RCE ChainResearchers chained two Oj parser bugs to achieve GitLab RCE via Jupyter notebook diffs, affecting authenticated users on unpatched versions. Depthfirst researchers published a working remote code execution exploit for GitLab on July 24, chaining two memory corruption bugs in Oj,…SECURITYAFFAIRS.COM
27 JulBooz Allen expands Vellox Suite with AI-driven threat detection platformBooz Allen Hamilton has announced an expansion of its powerful suite of AI-powered cyber defense products. Now generally available, Vellox Ranger provides automated, environment-specific threat detections, developed on Booz Allen’s proprietary agentic AI framework, that identify …HELPNETSECURITY.COM
27 JulPTC Windchill Vulnerability Exploited in Ransomware CampaignThe critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication. The post PTC Windchill Vulnerability Exploited in Ransomware Campaign appeared first on SecurityWeek .SECURITYWEEK.COM
27 JulZenity advances AI governance with Runtime BoundariesZenity has announced a major expansion of its platform, making it the AI security platform for autonomous AI built around a new security architecture designed to govern AI decisions before they become enterprise actions, including those made by long-horizon agents operating auton…HELPNETSECURITY.COM
27 JulDentaQuest disclosed a data breach that impacted +23 million individualsDentaQuest disclosed a data breach that may have exposed the personal and dental health information of more than 23 million people. DentaQuest is notifying more than 23 million people of a data breach after hackers accessed its network in May 2026. The incident may have exposed c…SECURITYAFFAIRS.COM
27 Jul⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and MoreMonday starts with the usual promise that everything is under control. Then the logs wake up. This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and attackers kept hiding inside normal-looking services. Nothing looked strange at firs…THEHACKERNEWS.COM
27 JulThe Vulnerability Myth That's Costing MillionsEnterprise environments often contain thousands of reported vulnerabilities, but only a small subset may represent the highest likelihood of leading to serious financial loss. Effective security depends on prioritizing those first rather than treating every vulnerability equally.…YOUTUBE.COM
27 JulTech giants form alliance to put open AI in cyber defenders’ handsNVIDIA and a group of tech companies have formed an alliance to promote the use of open AI models in cybersecurity, days after OpenAI disclosed that one of its own AI models breached Hugging Face’s systems during an internal security evaluation. The new group, called the Op…HELPNETSECURITY.COM
27 JulPublic Exploit Released for Patched vBulletin Pre-Auth Code Execution FlawPublic exploit details released on July 27 show how an unauthenticated request can reach PHP's eval() function inside vBulletin and execute code on an unpatched forum server. The attack requires no account, administrative access, or interaction from another user. SSD Secure Discl…THEHACKERNEWS.COM
27 JulSextortion scammers are exploiting ShinyHunters data leaksScammers are posing as ShinyHunters and using leaked email addresses to make their sextortion emails seem more credible.MALWAREBYTES.COM
27 JulTech industry giants say US must embrace openness, transparency in AIOpen-source and open-weight AI models are essential cybersecurity tools, two groups of major AI and security firms said.CYBERSECURITYDIVE.COM
27 JulErnst & Young data breach claimed by ShinyHunters extortion gangThe ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company's systems via a supply-chain attack. [...]BLEEPINGCOMPUTER.COM
27 JulAnnouncing the Cloud Security Alliance on AWS Compliance GuideAWS Security Assurance Services is announcing the release of the Cloud Security Alliance (CSA) Compliance Guide on Amazon Web Service (AWS), a new resource that maps the 17 control domains and 207 control objectives of the Cloud Controls Matrix v4.1 (CCM) to AWS services and reco…AWS.AMAZON.COM
27 JulDysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid DisruptionDysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. The researchers say the design makes the botnet harder to …THEHACKERNEWS.COM
27 JulUK court rejects Bahrain immunity claim in spyware caseThe alleged hacking by officials in Bahrain “allowed access to and exfiltration of information on the computers, interception of communications conducted using the computers and use of the computers’ microphones and cameras to surveil the respondents,” according to the court opin…THERECORD.MEDIA
27 JulAdversaries Don't Need a Zero-Day — They Read Your RulebookConfidence in autonomous security tools is declining, and here's why.DARKREADING.COM
27 JulRethinking security for the age of AIWhy security needs a new Cyber Stack — Introducing Project Perception The physics of cybersecurity are changing. Autonomous systems can now reason, adapt and operate continuously. At the same time, the cost of offense is falling, while the volume, velocity and comp…BLOGS.MICROSOFT.COM
27 JulNVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA FrameworkNVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents. The 37-member group spans cloud, security, enterprise software, and AI companies,…THEHACKERNEWS.COM
27 JulMicrosoft unveils MAI-Cyber-1-Flash, promises cybersecurity AI at half the costMicrosoft has introduced MAI-Cyber-1-Flash, a security-focused AI model built into MDASH, the company’s multi-agent vulnerability identification and remediation system. MAI-Cyber-1-Flash is Microsoft’s first model built specifically for cybersecurity work, and the com…HELPNETSECURITY.COM
27 JulHackers Breached an Airline as Known Vulnerabilities Went Unpatched. Now Another Gang Claims It Hacked Them, Too.Three times may be a charm for some things, but not for data security incidents. Frontier Airlines allegedly has had a third data security incident this year. First, it was BobDaHacker publishing a blog post on June 16 titled “Your Boarding Pass Is a Skeleton Key.” Fr…DATABREACHES.NET
27 JulThe world's least private hackers.Hackers target Thailand’s Ministry of Finance with an autonomous AI agent.A new industry alliance hopes to improve AI security. Golden Chickens lay four new malware families. GitHub and PyPI introduce time-based safeguards. SourTrade malvertising builds malware directly inside a …THECYBERWIRE.COM
27 JulNew Certighost PoC exploit lets attackers hijack Windows domainsA proof-of-concept exploit for "Certighost," a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain. [...]BLEEPINGCOMPUTER.COM
27 JulFBI: Breaking Affiliate Trust Sped Along LockBit's TakedownAn FBI agent explains how the mulitnational law-enforcement Operation Cronos was successful in disrupting the largest ransomware group of its time.DARKREADING.COM
27 JulAI Security at Scale, CMMC phase II paused, and the Weekly Enterprise News - ESW #468Interview with Keith Hollender, CEO and Co-Founder of Arcova Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem As enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introduc…YOUTUBE.COM
27 JulMicrosoft debuts AI cybersecurity offerings as competition heats upIt includes the new agentic model MAI-Cyber-1-Flash and the Project Perception platform, with the tech giant claiming it’ll do a better job than its rivals at half the cost. The post Microsoft debuts AI cybersecurity offerings as competition heats up appeared first on CyberScoop …CYBERSCOOP.COM
27 Jul KEVArista patches VeloCloud Orchestrator zero-day exploited in attacksArista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. [...]BLEEPINGCOMPUTER.COM
27 JulHackers target US firms in FastJson RCE zero-day attacksHackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. [...]BLEEPINGCOMPUTER.COM
26 Jul KEVWeek in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breachedHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: AI agents are still logging in as humans Most large companies run more than one AI platform at the same time. Developers pull up coding assistants, marketing teams lean on writing to…HELPNETSECURITY.COM
26 JulWeekly Update 514: This Week in Data BreachesPresently sponsored by: CoreView: Misconfigurations in Microsoft 365 leave doors open. Scan your tenant for free. The Origin Energy breach down here in Aus is all over the news this week, and as with many breaches, it's multi-faceted. You've got them leading with "…TROYHUNT.COM
26 JulA-list directors, actors and celebrities exposed in Tribeca film festival data leakResearcher Jeremiah Fowler provides today’s entry in the “No Need to Hack When It’s Leaking” files: I recently discovered a publicly accessible database that was not password-protected or encrypted and contained what appeared to be records associated with …DATABREACHES.NET
26 JulScans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th)ESAFENET&#;x26;#;39;s CDG showed up in our data before. The company focused on secure document management and data leakage prevention solutions. The "CDG" stands for "Content Data Guard", and the product appears to be mostly targeting the Chinese marke…ISC.SANS.EDU
26 JulDeveloping: AnMed reports phone and internet outage impacting all hospital locations; ERs remain openMedia outlets are reporting that all AnMed hospital locations are experiencing a phone and internet outage, but patients are being seen in the emergency rooms. AnMed is an independent, not-for-profit health system serving Upstate South Carolina and northeast Georgia with four hos…DATABREACHES.NET
25 JulOpenAI models escaped containment to hack Hugging Face.Russia's Laundry Bear targets unpatched Zimbra servers. EU hits Google with a $1 billion fine. Extortion group wipes Romania's land registry database. The Trump administration's AI czar resigns.THECYBERWIRE.COM
25 JulResearcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as GitSecurity researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit that executes commands as git on an unpatched self-managed GitLab 18.11.3 server. An ordinary authenticated user triggers it by committing two crafted Jupyter notebooks and requesti…THEHACKERNEWS.COM
25 JulRockwell Patches Code Execution Flaws in Arena Simulation SoftwareA researcher has explained how an attacker could exploit these vulnerabilities to target industrial organizations. The post Rockwell Patches Code Execution Flaws in Arena Simulation Software appeared first on SecurityWeek .SECURITYWEEK.COM
25 JulCl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCEThreat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign. "Attackers chain a pre-authentication infor…THEHACKERNEWS.COM
25 JulUS House Votes to Extend Cyber Sharing Law for 10 YearsChris Liotta reports: Lawmakers voted to extend a key cyberthreat sharing law for another decade, attaching the long-stalled reauthorization to Washington’s annual defense policy bill. The U.S. House of Representatives narrowly approved its $1.15 trillion fiscal year 2027 n…DATABREACHES.NET
25 JulAU: Sydney nurse accused of downloading patients’ data in alleged ‘breach of trust’Caitlin Powell reports: A male registered nurse from northern Sydney has been charged after allegedly downloading the data of multiple patients. Police received a report on Wednesday, July 22, that a NSW Health employee had allegedly accessed and downloaded patient information wi…DATABREACHES.NET
25 JulNo Need to Hack When It’s Leaking: Click to Pray editionJessica Lyons reports on today’s entry in the “No Need to Hack When It’s Leaking” files: Click To Pray, a prayer app endorsed by the Pope with hundreds of thousands of users worldwide, has leaked people’s names and email addresses for months – or lon…DATABREACHES.NET
25 JulAustralian energy provider Origin Energy disclosed a data breach impacting customer dataOrigin Energy confirmed a data breach after a hacker claimed to have stolen data from 2 million customers and threatened to leak it. Origin Energy disclosed a cyberattack that exposed customer data after a hacker claimed to have stolen records belonging to 2 million customers and…SECURITYAFFAIRS.COM
24 JulRussian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA CodesA Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organization's entire email directory, the password saved in the browser and the codes ke…THEHACKERNEWS.COM
24 JulHow AI guardrails are impeding the work of offensive cybersecurity researchersWe spoke with several cybersecurity researchers, who look for unknown vulnerabilities and develop tools to exploit them, about how OpenAI’s and Anthropic’s guardrails affect their work.TECHCRUNCH.COM
24 JulAgentForger proves AI agents can become persistent insider threatsA new attack method found by Zenity Labs reveals that AI agents are becoming persistent insiders that attackers can recruit, rather than malware they have to install. Its researchers have discovered AgentForger , a phishing-based attack that silently creates and launches a fully …CSOONLINE.COM
24 JulOpenAI's Rogue Agent Hacks Hugging Face, a Claude Cowork Escape, and Microsoft's Very Bad WeekOpenAI's AI agent hacked Hugging Face, Microsoft 365 melts down, and Anthropic's Claude CoWork sandbox escape Host David Shipley reports that OpenAI admitted an internal ExploitGym test let its GPT-5.6-Saul and a stronger pre-release model bypass safeguards, exploit a proxy zero-…CYBERSECURITYTODAY.LIBSYN.COM
24 JulRansomware in 2026: More groups, more victims, no slowdownRansomware activity followed a recognizable pattern during the previous four years. Each year was defined by a dominant actor, its collapse, or a major supply chain incident. Black Kite’s 2026 Ransomware Report documents a more fragmented market, with multiple ransomware pl…HELPNETSECURITY.COM
24 JulNodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private ChatsEight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum software's source code. Every version before 4.14.0 is affect…THEHACKERNEWS.COM
24 JulKimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers SayRedis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloo…THEHACKERNEWS.COM
24 JulGoogle gives developers an AI bug hunter that also writes patchesGoogle has launched a preview of CodeMender, an AI agent built to scan code for security flaws, confirm they are exploitable, and generate fixes for developers to review. (Source: Google) The company describes it as a response to attackers who are already using AI to speed up the…HELPNETSECURITY.COM
24 JulGoogle’s newest sign-in method asks you to look at the cameraGoogle’s selfie video sign-in option verifies that an account owner is a real person and that the account wasn’t created or used by computer programs or bots for the purpose of abuse, such as spamming. It is not available for all regions, accounts, or devices. Source: Google A se…HELPNETSECURITY.COM
24 JulUS Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra ServersUS agencies warn Russian group Laundry Bear is exploiting a patched Zimbra flaw to steal email accounts from organizations running unpatched servers. The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI)…SECURITYAFFAIRS.COM
24 JulHacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance MinistrySomeone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand's Ministry of Finance, which runs the country's treasury and tax collection. The agent then worked through …THEHACKERNEWS.COM
24 JulTycoon2FA takedown reshapes the phishing landscapeTraditional phishing techniques are in decline as a result of the disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform , Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”. “Phishing volume linked to the platform fell 92% from pre-…CSOONLINE.COM
24 JulCl0p ransomware launches new large-scale data theft campaignHackers believed to be Cl0p ransomware operatives are exploiting a critical flaw in PTC Windchill and FlexPLM to deploy web shells and steal sensitive enterprise data. While the threat actor has not been identified with absolute certainty, the observed tactics closely match those…CYBERINSIDER.COM
24 JulUAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian OrganizationsUAC-0099 delivers malware via a fake Notepad++ plugin after phishing, using a loader that sabotages itself if run without the correct arguments to hinder analysis. CERT-UA published a new advisory attributing a phishing campaign to UAC-0099, a Russia-aligned threat actor active s…SECURITYAFFAIRS.COM
24 JulSeeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can DoAI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we've collectively discovered is that enforcing least privilege for AI agents is harder than we ever imagined. This is why there are so many approaches, from p…THEHACKERNEWS.COM
24 JulChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing LinkCybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim's organization. The vu…THEHACKERNEWS.COM
24 JulMeta takes on AI-generated accounts with free Facebook verification badgeMeta has introduced Facebook Verified, a free badge meant to show that a person behind a profile has completed identity verification through a selfie check. (Source: Meta) The company says the goal is to give users a signal that they are dealing with a person, not a bot or an AI-…HELPNETSECURITY.COM
24 JulSlopsquatting, Phantom Domains, and HalluSquatting Are the Same AI AttackSlopsquatting, phantom squatting, and HalluSquatting all exploit the same late-binding attack pattern, where AI coding agents trust hallucinated package, repo, or domain names. ActiveState explains how pre-fetch verification and governed dependency management can help stop these …BLEEPINGCOMPUTER.COM
24 JulCrime Stoppers assured people their tips would be anonymous. Then more than 1 million tips leaked.Previous reporting about the Navigate360 breach focused on tips submitted by students, teachers, and parents. In this article, we focus on tips submitted to Crime Stoppers and law enforcement-related programs that use Navigate360’s software. Links to previous articles on th…DATABREACHES.NET
24 JulOrigin silent on settlement as alleged fired employee breach detail emergesRoxanne Libatique reports: Origin Energy has declined to comment on a public claim that it privately resolved a cyber extortion threat – a posture that, as of July 24, leaves the company managing simultaneous obligations to regulators, the ASX, and an insurance market now aware t…DATABREACHES.NET
24 JulT-Mobile violated WA data breach notification law, judge rulesMirandah Davis-Powell reports: T-Mobile failed to properly notify customers of a data breach in which 40 million people had sensitive personal information stolen and sold on the dark web, a King County Superior Court judge ruled Friday. The Washington attorney general’s office fi…DATABREACHES.NET
24 JulFurious KPMG boss expels senior partner over confidential documents in lockerColin Kruger provides today’s reminder of the insider threat: The most serious whistleblower claim from the KPMG scandal, that senior partners had illicitly accessed sensitive Lendlease board documents and kept them in a work locker, has been confirmed and led to the immedi…DATABREACHES.NET
24 JulIL: Weeks after cyberattack, ETHS students receive phishing scam emailsBob Chiarito reports: Six weeks after a cyberattack shut down the campus for two days, several Evanston Township High School students received phishing emails this week. The emails offered students part-time jobs paying $550 for two to three hours of work, three times a week and …DATABREACHES.NET
24 JulMillions of California-bought cars can be hijacked via BluetoothBrandon Vigliarolo reports: At least 2.2 million vehicles fitted with dealer-installed KARR and SWDS security systems are vulnerable to nearby Bluetooth attacks that can unlock doors or prevent a stopped vehicle from starting, according to researchers at the University of Califor…DATABREACHES.NET
24 JulCertighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain ControllerResearchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed the flaw Certighost. Because Domain Controller accounts carry d…THEHACKERNEWS.COM
24 JulHow Iran Uses Cellular Infrastructure to Target US Military PhonesSenior fellow Gary Miller spoke with Cape Cellular about the exploitation of mobile network vulnerabilities to track US personnel during the Iran war. The post How Iran Uses Cellular Infrastructure to Target US Military Phones appeared first on The Citizen Lab .CITIZENLAB.CA
24 JulRussia's Laundry Bear targets unpatched Zimbra servers.US State Department places visa restrictions on suspected cybercriminals. Stadler Rail refuses to pay ransomware gang.THECYBERWIRE.COM
24 JulMicrosoft, tech companies throw weight behind spread of open-source AIOther signatories of the letter include Meta, Palantir, Perplexity, Mistral, NVIDIA, Mozilla, The Linux Foundation, Hugging Face, Dell Technologies and IBM. The post Microsoft, tech companies throw weight behind spread of open-source AI appeared first on CyberScoop .CYBERSCOOP.COM
24 JulZero-day flaw in Check Point SmartConsole is under exploitationResearchers warned the vulnerability offers an attacker the ability to make key changes to security configurations.CYBERSECURITYDIVE.COM
24 JulSuspect arrested in investigation into sadistic “764” groupFrom the Dutch Police: In an investigation into so-called online sadistic COM networks, a suspect from North Holland was arrested on Monday, July 20. As a member of the group ‘764’, the suspect allegedly asked girls to cut themselves and write his online username on s…DATABREACHES.NET
24 JulOnTrac notifies customers of data breach after network hackOnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers. [...]BLEEPINGCOMPUTER.COM
24 JulHermes AI agent used to automate attack on Thai Finance MinistryA threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]BLEEPINGCOMPUTER.COM
24 JulLaundry Bear gets the spin cycle.Laundry Bear snuffles through unpatched Zimbra Collaboration servers. The State Department puts visa restrictions on cybercriminals. Oracle drops a record 1,449 security patches. Researchers disclose a critical vulnerability in OpenAI’s ChatGPT Workspace Agents. A new benchmark e…THECYBERWIRE.COM
24 JulWould an AI Kill Switch Backfire?Some policymakers have proposed mechanisms that could disable or restrict advanced AI systems under certain circumstances. Supporters view these as safeguards against dangerous behavior, while critics argue they could introduce new security, governance, and trust concerns. If use…YOUTUBE.COM
23 Julwp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command executionWe ran the wp2shell WordPress RCE chain end-to-end with Elastic Defend. Detection rule walkthrough, IOCs, and hunt guidance.ELASTIC.CO
23 JulID: Kootenai County notifies residents of data breachNick Hawthorne reports: Kootenai County has begun notifying residents whose personal information may have been compromised in a ransomware attack detected on the county’s computer network in late March. According to a Kootenai County press release, the County discovered the…DATABREACHES.NET
23 JulTN: Data breach delays start of Sumner County school yearCamellia Burris reports: One Middle Tennessee school district is delaying the start of the school year due to a data breach in its computer network. School officials in Sumner County discovered the breach in its computer network earlier this week and subsequently revised the dist…DATABREACHES.NET
23 JulBuilding a defense in depth strategy for sensitive dataIn this Help Net Security video, Venkata Pavan Kumar Gummadi, Professional Software Engineer at Broadridge, explains how to build a defense in depth strategy for protecting sensitive data. He argues that a single control, like encrypting a disk or turning on DLP, leaves gaps that…HELPNETSECURITY.COM
23 JulRed flags ahead.This week, hosts of N2K CyberWire ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Maria Varmazis⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠…THECYBERWIRE.COM
23 JulMulti-patch vulnerability fixes can leave open source exposedVulnerability management runs on a shorthand. A CVE shows a linked patch, someone applies it, and the ticket moves to closed. That shorthand covers most open source fixes. A share work in a different way, arriving as a run of two or more commits where the first one leaves the fla…HELPNETSECURITY.COM
23 Jul KEVCheck Point warns of SmartConsole zero-day exploited in attacksIsraeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company's SmartConsole graphical user interface (GUI) admin panel. [...]BLEEPINGCOMPUTER.COM
23 JulGitHub revamps bug bounty program with new VIP tier, payout changesGitHub is changing its bug bounty program to reward higher-quality vulnerability reports and reduce low-effort submissions, including AI-generated reports. The changes will take effect on July 27, 2026. Reports submitted before that date will be honored under the previous bounty …HELPNETSECURITY.COM
23 JulMonths-long breach exposes South Korean diplomats’ personal dataSouth Korea’s Foreign Ministry has disclosed that attackers breached the Korea National Diplomatic Academy’s online education system, compromising personal data belonging to current and former ministry staff and diplomats stationed abroad. The Korea National Diplomati…HELPNETSECURITY.COM
23 JulEnd-to-End Encryption and “Going Dark”New paper: “ Encryption and Globalization 15 Years Later: End-to-End Encryption and the Third Round of the ‘Going Dark’ Debate “: Abstract : This Article updates and expands on 2012 research on encryption and globalization, analyzing what the authors call …SCHNEIER.COM
23 JulWhatsApp Web chats exposed by Adobe&#8217;s Acrobat extension flawHermeticReader is a now-patched vulnerability in Adobe's popular Acrobat Chrome extension that could have been used to spy on WhatsApp Web users.MALWAREBYTES.COM
23 JulAI Agents Now the Enterprises Fastest Growing Exposed Attack SurfaceSophos report warns that the rapid adoption of AI by businesses is leaving them vulnerable to a new source of cyber threatsINFOSECURITY-MAGAZINE.COM
23 Jul20-year-old web server flaw shipped in modern security cameraA popular Wansview indoor security camera was shipping in 2026 with a web server vulnerable to a flaw first disclosed more than two decades ago. The finding comes from firmware security company Finite State, whose researchers analyzed the Wansview WVC Q5, an inexpensive Wi-Fi cam…CYBERINSIDER.COM
23 JulCobalt adds Autonomous Pentest to scale application security testingCobalt has introduced Cobalt Autonomous Pentest, a new offering that enables continuous offensive security across an organization’s application portfolio by delivering actionable penetration testing results in as little as 24 hours. AI-assisted development enables organizat…HELPNETSECURITY.COM
23 JulGoogle Released Gemini 3.5 Flash Cyber AI, a Specialized AI Model for Vulnerability HuntingGoogle DeepMind unveiled Gemini 3.5 Flash Cyber, an AI model for vulnerability discovery and patching, available only to governments and trusted partners. Google DeepMind announced Gemini 3.5 Flash Cyber on Tuesday, a security-focused AI model built on top of the existing 3.5 Fla…SECURITYAFFAIRS.COM
23 JulHow attackers hosted a fake Claude download page on the claude.ai domainA threat actor abused Anthropic’s Claude Artifacts feature to funnel users toward malware, Huntress researchers have disclosed. Employees at at least 29 organizations were compromised over two days in July, after searching for the Claude desktop app and clicking a sponsored…HELPNETSECURITY.COM
23 JulWhat Happened Between OpenAI and Hugging Face?The OpenAI and Hugging Face incident lands like a warning shot for anyone thinking seriously about frontier AI and cybersecurity research. A model evaluation crossed the neat boundary of a research environment, reached a live third-party production system, and forced the industry…RAPID7.COM
23 JulIranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical InfrastructurePublication: April 7, 2026 Last Update: July 22, 2026 TLP: Clear From the updated version of the Joint Cybersecurity Advisory: Executive Summary The authoring agencies urgently warn U.S. organizations of ongoing Iranian-affiliated cyber targeting of internet-connected operational…DATABREACHES.NET
23 JulClaude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac FilesCybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac. Accomplish AI, which sh…THEHACKERNEWS.COM
23 JulAI Is Repeating Cloud's MistakesThe rapid adoption of AI shares similarities with the early cloud transition. Organizations moved quickly to adopt new capabilities while still learning how to manage costs, security, and governance. Moving fast without clear oversight can create new risks. However, unlike the ea…YOUTUBE.COM
23 JulIs Patching Dead? Vulnerability Management in the Post-Mythos EraYou cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. The post Is Patching Dead? Vulnerability Management in the Post-Mythos Era appeared first on SecurityWeek .SECURITYWEEK.COM
23 JulJoint cyber security advisory on Russian state-sponsored phishing campaign targeting Zimbra webmailThe joint advisory warns that Russia-sponsored threat actors associated with an advanced persistent threat group, known as Laundry Bear, are exploiting a known vulnerability in Zimbra webmail.CYBER.GC.CA
23 Jul KEVEU hits Google with a $1 billion fine.Check Point warns of actively exploited flaw. South Korea discloses a breach affecting diplomats.THECYBERWIRE.COM
23 JulRussia-backed threat actor targets Western organizations in phishing campaignThe threat actor exploited a zero-day flaw in Zimbra to exfiltrate months of emails and other sensitive information.CYBERSECURITYDIVE.COM
23 JulCISA, FBI warn that Iran-linked hackers are expanding target set for water, energyThe agencies said threat groups have disrupted critical infrastructure sites by exploiting vulnerable PLC devices.CYBERSECURITYDIVE.COM
23 JulRussian Hackers Exploit New ‘Zero-Click’ Attack Against Western OrganizationsInternational agencies issue joint alert over state-backed campaign exploiting a critical vulnerability in the Zimbra Collaboration SuiteINFOSECURITY-MAGAZINE.COM
23 JulRussian hackers exploit Zimbra zero-click flaw for email theftCISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability. [...]BLEEPINGCOMPUTER.COM
23 JulUS government says Iran-linked hackers are disrupting American water and energy providersAn updated government advisory warns that Iranian hackers are exploiting systems used by water and energy providers.TECHCRUNCH.COM
23 JulRussian espionage group using novel Zimbra exploit to steal sensitive data from Western countriesLaundry Bear exploited a zero-day vulnerability for five months before it was patched in July 2025, and the group is still actively exploiting vulnerable environments. The post Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries appea…CYBERSCOOP.COM
23 JulmacOS flaw lets malware replace trusted apps without security warningsSecurity researchers Talal Haj Bakry and Tommy Mysk have disclosed a macOS weakness that allows malware already running under a user's account to silently replace the executable of trusted applications downloaded from the web and relaunch them without triggering Gatekeeper warnin…CYBERINSIDER.COM
23 JulBeyond the Vulnerability Apocalypse: Scaling Your Basics and Vulnerability ManagementDeveloped together with Usman Chaudhary @ Google for Public Sector ( his post ) Let’s call it what some in the industry are calling it: the vulnerability apocalypse . For years, finding vulnerabilities was slow, expensive, specialized work. LLMs made it cheap — in its first weeks…MEDIUM.COM
23 Jul4 ways AI-driven defense is rewriting the cybersecurity playbookThe cybersecurity landscape has evolved beyond human scale. Today’s adversaries have replaced predictable, manual playbooks with machine-generated attack chains that can breach traditional controls in seconds. To bridge the gap, organizations must move past legacy, reactive contr…CSOONLINE.COM
23 JulChaos ransomware deploys browser-based msaRAT to evade network detectionCisco Talos uncovered msaRAT, a Chaos ransomware RAT that hides C2 traffic by routing it through Chrome or Edge using the Chrome DevTools Protocol. Cisco Talos disclosed msaRAT, a Rust-based remote access trojan attributed to the Chaos ransomware group that routes its entire comm…SECURITYAFFAIRS.COM
23 JulDo not pass Go(ogle).Google gets a billion dollar fine from the EU. The White House considers sanctions against Chinese AI developers. The GAO criticizes overlap in cyber reporting regulations. The Feds warn of Iranian agents targeting OT systems. Researchers disclose a high-severity Linux kernel vul…THECYBERWIRE.COM
23 JulFixing Vulns Is Harder Than Finding Them - PSW #936In the news this week: - InfraTrust and knowing what to patch - Adversary in the middle triggered command injection - Exploitarium again - FreeRDP comes with free vulnerabilities - AI breaking out of sandboxes on its own - Wordpress RCE - DMA dangers - Nightmware eclypse is at it…YOUTUBE.COM
23 JulRussian Hackers Exploit Zimbra Zero-Day Against US, Ukraine TargetsA state-sponsored threat group, dubbed "Laundry Bear," sends "half-click" phishing emails that require a victim only to open or preview the message.DARKREADING.COM
23 JulThe Hidden Risk of Patch PrioritiesPatch management isn't just about fixing the highest number of vulnerabilities. Upgrade complexity, deployment time, and the actual severity of the vulnerabilities all influence what should be patched first. A massive upgrade may eliminate thousands of CVEs but consume weeks or m…YOUTUBE.COM
22 JulApple Fixes Hide My Email Bug That Exposed Real Addresses in Mail LogsApple has moved to address a security flaw in its Hide My Email service that enabled users' real email addresses to be unmasked, effectively undermining the feature's privacy guarantees. 404 Media reported Tuesday that a fix for the issue was deployed by Apple on July 3, 2026, af…THEHACKERNEWS.COM
22 JulMilford, New Hampshire Confirms Unauthorized Activity, Withholds Details of Suspected CyberattackMilford, New Hampshire is a quintessential New England town. But charm is no defense against cyberattackers, and it appears that the town may have been attacked last week. As DysruptionHub was the first to report, the town began experiencing problems early on July 15. Town email …DATABREACHES.NET
22 JulLG to Ban Residential Proxies from Smart TV AppsThe home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and oth…KREBSONSECURITY.COM
22 JulCloud operations become the next big role for agentic AICompanies are using agentic AI to manage growing application environments, automate routine tasks, and support decisions. Business and IT leaders increasingly see the technology as part of cloud application management, according to Unisys’ AI & Cloud Insights Report. T…HELPNETSECURITY.COM
22 JulSecurity teams keep finding critical flaws after scheduled testing endsEnterprise environments change between scheduled security assessments, leaving organizations with periods where new vulnerabilities can go undetected. Synack’s State of Continuous Security Validation report found that 95% of surveyed organizations identified high- or critic…HELPNETSECURITY.COM
22 JulAI can’t fix cybersecurity’s hiring problemOrganizations are redefining cybersecurity roles through workforce frameworks and placing greater emphasis on verified skills as AI and new regulatory requirements change hiring. The SANS 2026 Cybersecurity Workforce Survey found demand for specialists in new roles more than doub…HELPNETSECURITY.COM
22 JulSnowpick: Open-source ServiceNow exposure scannerAn employee opens a company service portal, searches the knowledge base, and drops a file onto a ticket. Someone who never signed in can send a request to that same portal and get records back. Bishop Fox ran that test across 166 ServiceNow instances during authorized penetration…HELPNETSECURITY.COM
22 Jul10 survival tips for CSOs who report to the CEOAs the CSO grows in prominence, security leaders are increasingly earning a seat at the executive table, reporting directly to the CEO with the expectation to help drive business strategy and ensure organizational success. Reporting to the CEO unlocks greater access and influence…CSOONLINE.COM
22 JulRisky Bulletin: Rogue OpenAI models were behind the Hugging Face breachRogue OpenAI models were behind last week’s Hugging Face breach, the Linux kernel discloses 442 vulnerabilities as the AI bugpocalypse settles in, France becomes the first EU country to pass a social media age limit, and Germany takes down the Kratos phishing service.RISKY.BIZ
22 JulPolice Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFAGerman and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world's most widely used criminal phishing kits, and Indonesian authorities arrested the man they say developed and ran it. In a joint announcement on …THEHACKERNEWS.COM
22 JulOpenAI Says Its AI Models Broke Loose and Hacked Hugging FaceThe admission comes days after Hugging Face disclosed an attack powered by autonomous AI agents. The post OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulPolice dismantle Kratos phishing platform behind 15,000 monthly campaignsGerman and US law enforcement have dismantled the infrastructure behind Kratos, a notorious phishing-as-a-service (PhaaS) platform. Its alleged developer and administrator was arrested in Indonesia by local police. Seizure banner (Source: BKA) The takedown was led by the Frankfur…HELPNETSECURITY.COM
22 JulAI, security operations and the new race against timeWhen Anthropic unveiled Project Glasswing and the Mythos model, much of the discussion focused on the capabilities themselves. Security leaders debated what these systems could mean for vulnerability discovery, exploit development and the pace of offensive innovation. Researchers…CSOONLINE.COM
22 JulGoogle’s Gemini 3.5 Flash Cyber becomes a vulnerability hunterGoogle’s Gemini 3.5 Flash Cyber model finds, validates, and patches vulnerabilities before they can be exploited while helping mitigate broader misuse. It is part of a limited-access pilot program that will soon be available to governments and trusted partners through CodeMender,…HELPNETSECURITY.COM
22 JulEndpoint Security Firm Glow Launches With $180M in Funding at $1.2B ValuationUsing AI, the startup provides adaptive prevention through environment mapping, risk analysis, and automated policy enforcement. The post Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulOpenAI AI models exploited zero-days to reach Hugging Face in benchmark testOpenAI confirmed its AI models exploited zero-days during internal testing, reaching Hugging Face servers in an unintended real-world cyberattack. OpenAI admitted on July 21 that its own AI models, including GPT-5.6 Sol and an unnamed pre-release system, were behind the cyberatta…SECURITYAFFAIRS.COM
22 JulUbuntu snap-confine Vulnerability Enables Local Root AccessNew Ubuntu snap-confine race condition lets local users escalate to root on default installsINFOSECURITY-MAGAZINE.COM
22 JulGoogle Makes CodeMender Available as Managed AI Security AgentCodeMender actively builds and runs exploits in customer-managed sandboxes to verify if vulnerabilities are truly exploitableINFOSECURITY-MAGAZINE.COM
22 JulChick-fil-A hit by credential stuffing attack exposing customer dataChick-fil-A has notified customers that attackers accessed some Chick-fil-A One loyalty accounts after launching a credential stuffing attack against the company's website and mobile application. The incident, which occurred in June, allowed unauthorized parties to view personal …CYBERINSIDER.COM
22 JulUS seizes over 1,000 domains used for illegal World Cup 2026 streamsThe US Department of Justice has seized more than 1,000 internet domains that streamed FIFA World Cup 2026 matches without a license. The domain seizure notice (Source: US Department of Justice) The seizures came in three waves over the course of the tournament. The first two rou…HELPNETSECURITY.COM
22 JulLookout identifies exploitable vulnerabilities in mobile appsLookout has announced the launch of the Lookout Mobile Software Exposure Center (MSEC). Integrated natively into the Lookout Mobile Endpoint Security platform, MSEC enables organizations to continuously detect, validate, prioritize, and remediate exploitable vulnerabilities acros…HELPNETSECURITY.COM
22 JulOpen AI Claims Its AI Models Went Rogue and Hacked Another CompanyHugging Face recently disclosed a security breach. OpenAI has now said that it was its AI models which broke containment and hacked Hugging Face themselvesINFOSECURITY-MAGAZINE.COM
22 Jul KEVCISA orders urgent action on actively exploited Langflow RCE flawThe Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents. [...]BLEEPINGCOMPUTER.COM
22 JulThe Fastest Path to AI Adoption Runs Through SecuritySecurity leaders who build fast, visible paths to AI adoption are becoming the most valued partners in their organizations. AI governance done right gives security teams the visibility they need, employees the tools they want, and CISOs the strategic influence they have earned. A…THEHACKERNEWS.COM
22 JulOpenAI model escape puts enterprise AI defenses on noticeSome of OpenAI’s most powerful AI models teamed up to escape their sandbox and attack systems at Hugging Face in a cybersecurity evaluation gone wrong, the company has admitted. The models under test were modified to allow them to perform potentially harmful actions that producti…CSOONLINE.COM
22 JulVibe-Coded Apps Riddled With Exploitable Security FlawsAnalysis found 434 exploitable flaws in AI-generated apps, with denial-of-service, authorization and secrets exposure risks among the most common issues. The post Vibe-Coded Apps Riddled With Exploitable Security Flaws appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulOpenAI Presence connects AI agents to enterprise data with built-in guardrailsOpenAI has introduced Presence, a product designed to help companies deploy AI agents that handle customer support and internal service requests across voice and chat. (Source: OpenAI) The company describes Presence as a deployment platform rather than a standalone model. “…HELPNETSECURITY.COM
22 JulAstelia extends reachability analysis with agentic AI for vulnerability managementAstelia has added agentic capabilities to its reachability analysis platform as organizations face shrinking exploit windows and the growing challenge of managing vulnerabilities. At the core of the platform is Astelia’s reachability analysis, which determines whether a vul…HELPNETSECURITY.COM
22 JulInfraTrust Knowledgebase Unlocks Critical Hardware Risk IntelligenceToday we’re excited to announce InfraTrust, a global hardware infrastructure security knowledgebase making mission critical infrastructure security data available faster, so you have it when you need it to defend your enterprise. InfraTrust is a searchable, continuously updated s…ECLYPSIUM.COM
22 JulAI Added a Third EmployeeAI isn't just another software tool. It's increasingly being treated like a worker that operates around the clock, helping companies automate tasks and improve productivity. That changes the incentives for employers. If AI can reliably handle part of the workload, businesses may …YOUTUBE.COM
22 JulOpenAI: Our models breached Hugging Face during a cyber capability testThe recent Hugging Face breach was the work of several OpenAI models, the AI research company claimed in a blog post. The breach Late last week, the company behind Hugging Face, a platform that enables users to share machine learning models and datasets, said some of its internal…HELPNETSECURITY.COM
22 JulThreat group claims credit for ransomware attack on Coca-Cola’s dairy unitThe attackers previously exploited vulnerabilities or used stolen credentials for initial access. CYBERSECURITYDIVE.COM
22 JulGreedy ransomware crews return for seconds after victims cough up first extortion paymentsConnor Jones reports: Authorities have long warned organizations not to pay ransoms, and fresh figures underline why: handing over the money doesn’t mean the crooks leave you alone. Proofpoint survey data suggests that 58 percent of affected UK organizations paid a ransom. …DATABREACHES.NET
22 JulCisco’s new AI model tells code reviewers where to look for vulnerabilitiesCisco has revealed a family of open-weight AI models called Antares that, it said, can help security teams isolate potentially vulnerable parts of a software repository before deeper investigation begins. Rather than detecting a specific CVE or generating a patch, these models se…CSOONLINE.COM
22 JulApple patches Hide My Email flaw after media reports and class-action lawsuitApple has fixed a vulnerability in its iCloud+ Hide My Email service that could expose users' real email addresses. The fix comes over a year after a security researcher privately reported the issue and only weeks after 404 Media publicly disclosed it. The company confirmed to 40…CYBERINSIDER.COM
22 JulThe AI has entered the chat.GPT escapes the sandbox and hacks Huggingface. SolarWinds patches multiple critical flaws. CISA orders patching of a critical Langflow AI vulnerability. A Paidwork breach affects over 23 million users. A recently patched SharePoint vulnerability is under active exploitation. Orac…THECYBERWIRE.COM
22 JulSouth Korea discloses data breach impacting diplomats worldwideSouth Korea disclosed that hackers breached the National Diplomatic Academy's online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. [...]BLEEPINGCOMPUTER.COM
22 JulFake Bahrain Alert App Deploys Android Surveillance MalwareA malicious application delivers four-stage Android spyware via phony Google Play sites, exploiting civilian fear during Iranian missile strikes.DARKREADING.COM
22 JulAre Schools Falling Behind AI?Rapid advances in AI are forcing organizations to rethink how people learn new skills. The question isn't only how employees adapt, but whether K–12 education, universities, and professional development can keep pace. Waiting until workforce shortages appear could mean reacting t…YOUTUBE.COM
22 JulUpbound says hack caused $13 million in fraudulent Acima leasesThe Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. [...]BLEEPINGCOMPUTER.COM
22 JulAttackers Are Learning to Live Off the AI ToolchainSandworm_Mode is an early example of malware that exploits trusted AI tools and workflows to make malicious activity virtually indistinguishable from normal activity.DARKREADING.COM
22 JulSmashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hackerA Russian intelligence-linked hacker is arrested in Thailand while enjoying a beach holiday - and the trail of evidence that nailed him to the Russian government includes 14 separate orders of chicken McNuggets. Meanwhile, AI music generator Suno has been hacked - and the stolen …GRAHAMCLULEY.COM
22 JulGerman law enforcement claims to have ‘dismantled’ mega phishing-as-a-service group KratosA global law enforcement crackdown has seized infrastructure serving the massive phishing-as-a-service (PhaaS) group Kratos, as well resulting in the arrest of an unnamed Kratos “developer and technical administrator” in Indonesia. The effort was managed by German law enforcement…CSOONLINE.COM
22 JulOpenAI Models Escaped Containment and Hacked Hugging FaceIt’s happened. The nightmare of the future is now in our present. Or was this just old-fashioned negligence? Lily Hay Newman and Dell Cameron report: OpenAI disclosed on Tuesday that it lost control of two AI models during a security test that ended in a breach of the open …DATABREACHES.NET
22 JulInstructure Incident Driving 58 Percent of Breach Notices in 2026GovTech reports: The mega breach is back in 2026, according to a new report from the Identity Theft Resource Center (ITRC). The nonprofit group, which works to prevent and reduce incidences of identify theft, found that 1,029 data compromises generated 471 million breach notices …DATABREACHES.NET
21 JulAI-generated reports push GNOME to shorten its disclosure windowVolunteer maintainers of open source projects now receive a steady flow of security vulnerability reports produced with AI tools. Many arrive with no mention that a language model helped write them. The volume has grown enough that GNOME is revising the rules it uses to track and…HELPNETSECURITY.COM
21 Jul177: National Public DataThis is the story of the hacker known as "USDoD". When he was young he had a vengeance on the US, and this lead him down a road of continual data breaches, until he hacked into National Public Data, which is when his spree went one step too far. Sponsors Support for this show com…DARKNETDIARIES.COM
21 JulContext bombing heralds a new AI era of deceptive defenseAttackers are increasingly using AI agents to automate all phases of cyberattacks , prompting the security industry and enterprises to find new network defense approaches. One technique that shows promise is to intentionally plant decoy files with prompts that trigger the content…CSOONLINE.COM
21 JulNew ENCFORGE Ransomware Targets AI Model Files in Langflow RCE AttackResearchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model weig…THEHACKERNEWS.COM
21 JulWindows LegacyHive zero-day flaw gets free, unofficial patchesFree unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems. [...]BLEEPINGCOMPUTER.COM
21 JulWeekly Update 513: Clauding The Home NetworkPresently sponsored by: CoreView: Misconfigurations in Microsoft 365 leave doors open. Scan your tenant for free?. I reckon this week's video on how Claude is tying together info from UniFi, Home Assistant and the Pi-Hole is an absolute ripper. Or at least the concept is - i…TROYHUNT.COM
21 JulEstée Lauder discloses data breach tied to Oracle EBS vulnerabilityCosmetics company Estée Lauder disclosed a data breach tied to a vulnerability in Oracle E-Business Suite (EBS) used for the company’s human resources operations. Estée Lauder is one of the largest beauty companies in the world, known for its prestige skincare, makeup, frag…HELPNETSECURITY.COM
21 JulOpen-source maintainers still work underfunded as sponsorship crosses $100 millionA maintainer patches a library late at night that ships inside thousands of products, and no invoice follows. Sebastián Ramírez and Caleb Porzio spent years in that position. Ramírez, known as tiangolo, builds tools that other Python projects depend on. Porzio built Livewire and …HELPNETSECURITY.COM
21 JulUS Hospital Finance Software Provider Craneware Reports Data TheftCraneware, a provider of financial software for US healthcare organizations, has disclosed a cyber incident involving unauthorized access and data theftINFOSECURITY-MAGAZINE.COM
21 JulThe Triumphs and Failures of France's Foreign Intel ServiceThe DGSE, or Directorate General for External Security, is France's foreign intelligence service. It's found inside the Ministry of Defense but reports to the president. It was established under that name in 1982, learning the hard way, through a string of high-profile blunders, …THECYBERWIRE.COM
21 JulCritical Palo Alto VPN bug now exploited by Qilin ransomware gangThe Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf. [...]BLEEPINGCOMPUTER.COM
21 JulMeta Paid $78,000 Bounty for Vulnerability Exposing Customer Support DataA security researcher discovered a broken access control vulnerability in Meta’s support infrastructure. The post Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulAI agents can escape sandboxes without ever breaking themSandboxes have become a key security control for AI coding agents, but new research suggests they may not provide the isolation many organizations assume. Pillar Security has disclosed a series of vulnerabilities showing how agents in tools such as Cursor, Codex, Gemini CLI, and …CSOONLINE.COM
21 JulEstée Lauder Discloses Impact From Oracle EBS Zero-Day HackHackers exfiltrated personal, financial, and health information from the company’s Oracle EBS instance in August 2025. The post Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulOpen-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCsAn Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is running commands on the PC driving the agent. Researchers demonstrated tha…THEHACKERNEWS.COM
21 JulN-day is Becoming N-Hour. Patching Faster Won't Save You.Every patch is a confession. The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly what was broken and where. Turn that diff back into a working exploit, and you can hit every system that hasn't updated yet. This is…THEHACKERNEWS.COM
21 JulNew Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an ExploitA cloud tenant using nothing but ordinary GPU access can push a data center's power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in. That is the claim behind Bit2Watt, described by three Zhejiang University researchers in a paper acce…THEHACKERNEWS.COM
21 JulYour AI agent’s config is now the payload: How attackers are targeting the developer agent harnessAttackers have shifted from hiding from AI tools to running inside them. By poisoning the config files that govern AI coding assistants, a new worm class achieves silent persistence, evades AI-based scanners, and spreads across an organization's repositories through developers' o…TENABLE.COM
21 JulCisco’s open-weight Antares models make vulnerability localization cheaperA security analyst opens an unfamiliar repository, pulls up a vulnerability advisory, and starts hunting for the file where the weakness lives. The naming conventions belong to someone else. Evidence sits in scattered corners of a codebase that runs to thousands of files. That fi…HELPNETSECURITY.COM
21 JulPersonal data of all South Korean diplomats believed leaked in ‘unprecedented’ cyberattackSeo Ji-Eun reports: The personal information of nearly all of South Korea’s diplomatic personnel is presumed to have been compromised in what the Foreign Ministry on Tuesday called an “unprecedented” cyberattack, exposing up to 10,000 administrative and intellig…DATABREACHES.NET
21 JulNYSDFS Secures $50 Million Penalty from Swedbank for Withholding Information from InvestigatorsOne of the biggest breaches of 2016 was the Panama Papers leak. The law firm at the heart of it, Mossack Fonseca, closed its doors in 2018, unable to recover from all the damage. But while the law firm folded, investigations continued. The New York Department of Financial Service…DATABREACHES.NET
21 JulSuno Data Breach had a breach in 2025. Why is it first being known now?Millions here, tens of millions there. Are we all getting breach fatigue by now? Over on HaveIBeenPwned, Troy Hunt reports that Suno experienced a data breach in November 2025, which 404 Media first made public this month: In November 2025, AI music generation tool Suno suffered …DATABREACHES.NET
21 JulSeoul Notifies 4.62 Million of Ttareungyi Data Breach, Offers Free PassesKim Eun-bi reports: The Seoul Metropolitan Government will send individual text messages to about 4.62 million citizens affected by a data breach involving membership information for Ttareungyi, the city’s public bike-sharing service, notifying them of the leaked items and …DATABREACHES.NET
21 JulTaiwan to slow mobile data during national resilience drillsThe speed of 5G and 4G networks across much of Taiwan will be temporarily reduced to 1 percent of capacity as the island holds annual civilian and military drills.THERECORD.MEDIA
21 JulZimbra Patches Critical SNMP Command Injection and Four XSS VulnerabilitiesZimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component. As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list is a …THEHACKERNEWS.COM
21 JulMacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392Appsec often frames usability and security as at odds with each other. Apple's software has famously emphasized the importance of usability while also creating a solid security foundation. Patrick Wardle talks about how he's seen malware shift from Windows to macOS, how Apple's a…YOUTUBE.COM
21 JulAI agents tricked into recommending malicious GitHub repositoriesRoughly 7,600 malicious GitHub repositories were uncovered, more than 800 of them posing as AI Skills or Model Context Protocol (MCP) servers, in a wave that peaked in April 2026, according to Island. The scale of the FakeGit operation (Source: Island) The fake repositories are t…HELPNETSECURITY.COM
21 JulWhat happens if you visit a WordPress site hacked through wp2shell?Attackers started exploiting the critical wp2shell vulnerability chain within hours of patches being released, putting sites and their visitors at risk.MALWAREBYTES.COM
21 JulAWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run CodeHidden text on a web page was enough to make Kiro, AWS's agentic coding IDE, rewrite its own configuration file and run an attacker's code on a developer's machine, with no approval step able to stop it. Intezer, in research with Kodem Security, found that a request as ordinary a…THEHACKERNEWS.COM
21 JulMicrosoft SharePoint under attack via new exploitSecurity researchers warn the potential risk could rival the widespread ToolShell campaign of 2025.CYBERSECURITYDIVE.COM
21 JulCisco Launches Low-Cost AI Models for Source Code SecurityThe open-weight Antares models are designed to pinpoint known vulnerabilities in codebases faster and at a fraction of the cost of larger AI models. The post Cisco Launches Low-Cost AI Models for Source Code Security appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulZimbra 10.1.20 patches multiple security issues, including a critical command injection bugZimbra patched nine flaws in version 10.1.20, including a critical SNMP monitoring command injection issue enabling arbitrary command execution. Zimbra released version 10.1.20 to fix nine security vulnerabilities, including a critical command injection flaw in the SNMP monitorin…SECURITYAFFAIRS.COM
21 JulCyberattack against Maine telecom disrupted municipal internet service in 23 townsColin Wood reports: At least one municipal government was among those to see their internet service disrupted after a cyberattack against a Maine telecommunications firm Sunday caused an outage affecting 23 towns along the state’s midcoastal region. A local NBC affiliate reported…DATABREACHES.NET
21 JulLegacyHive, ACR Stealer, Hugging Face, Route 53, and Kieran Human from Threatlocker - SWN #600Nudification, Yeats, LegacyHive, ACR Stealer, Hugging Face, Route 53, 764, Wordpress, Kieran Human from Threatlocker, and More. Segment Resources: Malicious Edge extension abuses Native Messaging as bridge to malware: https://www.bleepingcomputer.com/news/security/malicious-edge-…YOUTUBE.COM
21 JulOracle July 2026 Critical Patch Update Addresses 1235 CVEsOracle addresses 1235 CVEs in its third quarterly update of 2026 with 1449 patches, including 261 critical updates. Key Takeaways The third Critical Patch Update (CPU) for 2026 contains fixes for 1235 unique CVEs in 1449 security updates, the largest CPU release. 261 issues (18% …TENABLE.COM
21 JulOpenAI Models Escaped Containment and Hacked HuggingFaceThe cybersecurity-focused models, including GPT-5.6 Sol, broke out of a testing sandbox, exploited a zero-day, and gained access to the open internet to pull off the attack.WIRED.COM
21 JulPay up or not? Ransomware surge has victims facing tough choices.Hannah Murphy reports: Nearly half of companies that are targets of a ransomware cyber attack end up paying a ransom to release their data or systems, according to 2025 research from cybersecurity group Sophos, while the median amount demanded is rising. Globally, some jurisdicti…DATABREACHES.NET
21 JulSN 1088: A Nefarious Novel Use for AI - Ransomware Negotiations Go High-TechCybercriminals are harnessing AI not to break in, but to make sense of their stolen loot and increase their leverage in multi-million dollar ransomware heists. This episode unpacks how AI is now turbocharging extortion and negotiations on the dark side. The "bone crushing" didn't…TWIT.TV
20 JulWordpress RCE, New Windows 0-day and Coca-Cola's Fairline ransomedNew Windows zero-day, Coca-Cola's Fairlife hit by ransomware, and a core WordPress RCE David Shipley covers a new Windows zero-day disclosure from "Nightmare Eclipse" called LegacyHive, a local privilege escalation flaw in the Windows User Profile Service that could be weaponized…CYBERSECURITYTODAY.LIBSYN.COM
20 JulNearly half of open-source AI projects never reach productionOpen models are moving into production across more organizations, and the work of securing those deployments increasingly extends beyond the model weights. Mozilla’s The State of Open Source AI 2026 identifies deployment, governance and operational tooling as persistent obstacles…HELPNETSECURITY.COM
20 JulWorld's Largest AI Model Repository Hugging Face Breached by Autonomous AI AgentIn an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected and responded to the incident targeting its production infrastructure earlier la…THEHACKERNEWS.COM
20 JulMeet Dusseldorf, Microsoft’s open-source out-of-band security platformOut-of-band vulnerabilities surface when an application quietly reaches out to an external system during an attack, and capturing that traffic calls for infrastructure that many researchers assemble on their own. A new open-source project from Microsoft supplies that infrastructu…HELPNETSECURITY.COM
20 JulRisky Bulletin: Hacker wipes Romania's entire land registry databaseA hacker wipes Romania’s entire land registry database, Magnet Forensics sues a former employee for leaking an iPhone exploit, an autonomous AI agent hacked Hugging Face, and an unauthenticated remote code execution bug was finally found in WordPress.RISKY.BIZ
20 JulSOCs face a human challenge as AI speeds alerts and threatsSecurity operations centers (SOCs) have spent years struggling under the weight of growing alert volumes, expanding attack surfaces, and chronic staffing shortages. Now artificial intelligence is adding a new complication: not just more information, but more machine-generated inf…CSOONLINE.COM
20 Jul KEVClaude Mythos FAQ: Capabilities, access, competitors, implications1. What is Claude Mythos? Claude Mythos is an advanced AI model developed by Anthropic and is optimized for cybersecurity and healthcare applications. Mythos 5 was originally released in April to a small group of vetted technology partners ahead of a planned wider rollout. Anthro…CSOONLINE.COM
20 JulHow agentic endpoint security shuts down IDE-based supply chain attacksAttention shifts from EDR to Agentic Endpoint Security to close visibility gaps that AI can exploit.CYBERSECURITYDIVE.COM
20 JulChrome 150 Update Patches Severe Memory Safety BugsThe fresh security update resolves six critical and high-severity use-after-free vulnerabilities. The post Chrome 150 Update Patches Severe Memory Safety Bugs appeared first on SecurityWeek .SECURITYWEEK.COM
20 JulThe Windows 10 hangover is becoming a security problemWindows 11 now runs on 78.8% of Windows devices after Microsoft ended support for Windows 10 on 14 October 2025, according to Lansweeper. Windows 10 still accounts for 16.9% of devices and no longer receives security updates, leaving newly discovered vulnerabilities unpatched. “T…HELPNETSECURITY.COM
20 JulAI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion CampaignHugging Face says an autonomous AI agent breached part of its production infrastructure and accessed internal data and service credentials. Hugging Face is one of the world’s leading open-source AI companies. It provides a platform where developers and organizations can bui…SECURITYAFFAIRS.COM
20 JulVolexity Uncovers Zero-Day Campaign Targeting SonicWall VPN AppliancesUnknown hackers exploited two SonicWall SMA 1000 zero-days to gain root access on VPN appliances before patches became available. Volexity published its findings after conducting an incident response investigation involving a compromised organization whose SonicWall SMA 1000 seri…SECURITYAFFAIRS.COM
20 JulRussian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCsA solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet. The findings come from an analysis of 200 Gemini CLI session logs between March 19 and…THEHACKERNEWS.COM
20 JulAI Security at Scale, CMMC phase II paused, and the Weekly Enterprise News - ESW #468Interview with Keith Hollender, CEO and Co-Founder of Arcova Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem As enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introduc…YOUTUBE.COM
20 JulEstée Lauder discloses data breach tied to Oracle E-Business Suite attacksThe Estée Lauder Companies is notifying current and former employees that their personal information was stolen after attackers compromised the company's Oracle E-Business Suite (EBS) human resources environment in August 2025. The intrusion is linked to the wider Oracle EBS expl…CYBERINSIDER.COM
20 JulCapital One Open Sources AI-Powered ‘VulnHunter’ Security ToolThe agentic security tool identifies potentially exploitable code flaws, traces attack paths, and recommends targeted remediations. The post Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool appeared first on SecurityWeek .SECURITYWEEK.COM
20 JulHugging Face breached by autonomous AI agentHugging Face, the widely used platform for sharing open-source machine learning models and datasets, has disclosed a security breach it says was carried out by an autonomous AI agent system. How the attack unfolded In a blog post published Thursday (July 16), the company said tha…HELPNETSECURITY.COM
20 JulNew ACR Stealer campaigns use WebDAV, MSHTA to evade detectionMicrosoft has issued a warning about a recent surge in ACR Stealer activity that uses ClickFix-style social engineering to steal credentials, browser data, and sensitive business documents. In a new report, Microsoft researchers detailed two separate campaigns observed between la…CSOONLINE.COM
20 JulHugging Face discloses breach linked to autonomous AI agentThe Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system. [...]BLEEPINGCOMPUTER.COM
20 JulNew Index Tracks Material Breaches — And Refuses to Add Up the LossesLongtime cybersecurity executive Richard Bird built the resource for security experts, journalists, policymakers, and everyday citizens. The post New Index Tracks Material Breaches — And Refuses to Add Up the Losses appeared first on SecurityWeek .SECURITYWEEK.COM
20 JulCritical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now!7-Zip fixed a vulnerability that could let attackers run code by tricking users into opening malicious XZ-compressed archive files. 7-Zip released version 26.02 to address a remote code execution vulnerability in its handling of XZ-compressed data. The flaw, discovered by researc…SECURITYAFFAIRS.COM
20 JulPatch now: WordPress REST API bug allows remote code executionOrganizations running recent versions of WordPress are being asked to patch a newly detailed pre-authentication remote code execution (RCE) vulnerability affecting the platform’s built-in REST Batch API. The flaw, dubbed wp2shell, enables attackers to execute arbitrary code again…CSOONLINE.COM
20 Jul20th July – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-p…RESEARCH.CHECKPOINT.COM
20 JulOpenSSL Silently Fixes ‘HollowByte’ DoS VulnerabilityAttackers could send waves of malicious payloads to trigger buffer pre-allocations that are not freed, exhausting server memory. The post OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
20 JulBroken Promises of Anonymity: Four Months Later, Still No Transparency. Now We’re Seeking Accountability.On March 18, 2026, Navigate360 learned that 8.3 million anonymous tips had been exposed. The company’s response—and the silence of the programs that depend on its platform—has persisted for months. We’re now seeking accountability through state and federal regulators.…DATABREACHES.NET
20 Jul⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and MoreA single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware de…THEHACKERNEWS.COM
20 JulResearchers Build WordPress Exploit Using OpenAI's GPTA researcher who discovered a critical vulnerability in WordPress has used OpenAI’s latest model to develop an exploit chainINFOSECURITY-MAGAZINE.COM
20 JulItaly fines WINDTRE €1.7 million over security flaws behind two data breachesItaly’s data protection authority, the Garante per la Protezione dei Dati Personali, fined WINDTRE €1.7 million over “serious data security shortcomings” that let hackers breach its systems twice and exfiltrate personal data belonging to more than 365,000 custom…HELPNETSECURITY.COM
20 JulAI adoption and business acceleration are changing the expectations of technology risk managementAs AI becomes embedded in customer experiences, internal workflows, and throughout the supply chain, security leaders are being asked to do more than manage risk. They are being asked to help the business make more informed decisions and move faster. At the same time, AI has evol…CSOONLINE.COM
20 JulHackers are exploiting recently patched WordPress bugs, putting millions of websites at riskTwo critical security flaws in WordPress’ software have given hackers the chance to remotely take over tens of millions of websites, according to an estimate by a cybersecurity researcher.TECHCRUNCH.COM
20 JulResearchers trace SonicWall SMA1000 exploitation to late JuneMultiple threat actors, including INC ransomware, have targeted vulnerable firewall systems.CYBERSECURITYDIVE.COM
20 JulAI helped uncover WordPress ‘wp2shell’ RCE now exploited in attacksThe critical WordPress vulnerability chain known as “wp2shell” was discovered with substantial assistance from an AI model, which identified both the initial pre-authentication SQL injection and a complex path to remote code execution. Patchstack now says attackers are actively e…CYBERINSIDER.COM
20 JulMillions of Shark robot vacuums vulnerable to remote code executionMillions of internet-connected Shark robot vacuums may be vulnerable to a critical remote code execution (RCE) flaw that could allow attackers to take over devices, access onboard cameras, and retrieve sensitive data stored on the robots. Independent security researcher ‘to…CYBERINSIDER.COM
20 JulDirector of Commerce AI standards office out after three monthsThe Center for AI Standards and Innovation has quietly become a key hub for the federal government to assess potential threats and harms that AI systems pose. The post Director of Commerce AI standards office out after three months appeared first on CyberScoop .CYBERSCOOP.COM
20 JulMore AI Bugs, Less Security?AI is exceptionally good at identifying code patterns that lead to crashes and other common programming mistakes. That capability can dramatically increase the number of reported bugs. Finding more bugs doesn't necessarily reduce real-world cyber risk. If the proportion of high-i…YOUTUBE.COM
20 JulBehind the friendly face.Hugging Face reports an autonomous AI-powered breach. Ernst & Young discloses a client data breach. Attackers are actively exploiting a critical ServiceNow flaw. Ransomware gangs sharpen their tactics against law firms. Capital One open-sources an AI security tool. Text salting f…THECYBERWIRE.COM
20 JulEstée Lauder discloses data breach via Oracle E-Business flawCosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. [...]BLEEPINGCOMPUTER.COM
20 JulSonicWall SMA1000 flaws exploited as zero-days to push custom malwareTwo recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. [...]BLEEPINGCOMPUTER.COM
19 JulWeek in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logsHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: Two new high severity WordPress vulnerabilities, patch immediately! The 7.0.2 WordPress security release addresses one critical and one high severity security issue. Cynative: Open-s…HELPNETSECURITY.COM
19 JulSonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root AccessA previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026. Cybersecurity company Volexity is tracking the acti…THEHACKERNEWS.COM
19 JulMedical giant Abbott investigates two cyber incidents as ShinyHunters and ShadowByt3$ both claim breachesAnna Zhadan reports: American healthcare giant Abbott Laboratories is investigating two cyber incidents that appear to be unrelated: one involving its Cancer Diagnostics business and another affecting its LabCentral portal. Although unrelated, the two disclosures came within days…DATABREACHES.NET
18 JulOpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS RequestsEleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no chan…THEHACKERNEWS.COM
18 JulNew wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run CodeAn anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until Friday, when WordPress shipped 6.9.5 and 7.0.2 and enabled what it calls forced updates through its auto-u…THEHACKERNEWS.COM
18 JulAI Is Supercharging Cyberattacks | Cybersecurity Today On The Weekend | July 18, 2026Artificial intelligence is changing cybersecurity on both sides of the battle. While defenders are adopting AI to improve detection and response, attackers are using it to discover vulnerabilities, automate exploitation, and dramatically accelerate the pace of attacks. In this ep…CYBERSECURITYTODAY.LIBSYN.COM
18 JulWordPress releases emergency update for critical ‘wp2shell’ RCE flawThe WordPress project has released emergency security updates to fix a critical vulnerability chain dubbed wp2shell, that can allow unauthenticated attackers to achieve remote code execution (RCE) on vulnerable websites. The flaws affect WordPress 6.9 through 7.0.1 and have alrea…CYBERINSIDER.COM
18 JulNY Attorney General James Secures $18 Million From 23andMe for Failing to Protect Customers’ Genetic DataThere’s another update in the litigation involving 23andMe, below, but this won’t be the last update, as California’s Attorney General has also recently sued them under California’s privacy laws. New York Attorney General Letitia James and a bipartisan coa…DATABREACHES.NET
18 JulWordPress Core "wp2shell" RCE flaws get public exploits, patch nowPublic exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. [...]BLEEPINGCOMPUTER.COM
18 JulUpdate now: 7-Zip fixes RCE flaw exploitable with malicious archives7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files. [...]BLEEPINGCOMPUTER.COM
18 JulOpenSSL Fixes HollowByte Memory Exhaustion BugOkta disclosed HollowByte, an 11-byte OpenSSL flaw that lets remote attackers exhaust server memory and trigger denial-of-service attacks. Okta’s Red Team disclosed a denial-of-service vulnerability in OpenSSL they named HollowByte, and the attack payload is exactly 11 byte…SECURITYAFFAIRS.COM
17 JulScattered Spiders sentenced, OpenAI builds an AI that breaks AIs, and Iran leans on ChatGPTTwo leading Scattered Spider members, Thaila Jubar and Owen Flowers, were sentenced to five years and six months for the 2024 Transport for London hack that knocked 148 systems offline, forced 27,000 password resets, stole customer data, and cost TfL £29 million, with wider losse…CYBERSECURITYTODAY.LIBSYN.COM
17 Jul KEVCISA urges immediate action on actively exploited Fortinet flawsCISA on Thursday ordered government agencies to prioritize patching two actively exploited vulnerabilities in the Fortinet FortiSandbox threat detection platform. [...]BLEEPINGCOMPUTER.COM
17 JulFresh SharePoint Vulnerability Exploited Soon After DisclosureThe critical-severity security defect allows remote, authenticated attackers to execute arbitrary code on the server. The post Fresh SharePoint Vulnerability Exploited Soon After Disclosure appeared first on SecurityWeek .SECURITYWEEK.COM
17 JulThe SaaS blind spot: Why security teams can’t get inside their own appsMost organizations I work with have invested heavily in cloud security. They have endpoint detection tools, SIEM platforms, cloud security posture management, and skilled security teams running on a 24/7 shift. And yet, when I ask them a simple question — who has admin access in …CSOONLINE.COM
17 JulFake TTF files deliver stealthy malware in global phishing campaignThreat actors are now abusing an ordinary font file to deliver low-detection malware capable of stealing credentials and establishing persistence on compromised Windows systems. According to a new research from Fortinet’s FortiGuard Labs, a global phishing campaign is actively us…CSOONLINE.COM
17 JulRansomware attack halts Coca-Cola’s Fairlife US milk productionA ransomware attack has stopped milk production at Fairlife, the Coca-Cola dairy brand known for its high-protein milk, protein shakes, and nutrition drinks. Coca-Cola disclosed the incident on July 16, 2026, in a Form 8-K filed with the U.S. Securities and Exchange Commission (S…HELPNETSECURITY.COM
17 Jul KEVCISA Mandates Urgent Patch for Actively Exploited Critical Fortinet VulnerabilitiesUS government agencies have until July 19 to patch two critical Fortinet vulnerabilitiesINFOSECURITY-MAGAZINE.COM
17 JulThree Steps to the Terminal: A Siemens ROX II Zero-Day TrilogyA technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
17 JulCoca-Cola discloses ransomware attack disrupting fairlife production in the USThe Coca-Cola Company has disclosed that a ransomware attack affecting its wholly owned dairy subsidiary, fairlife, has temporarily halted fairlife's US production operations after attackers gained unauthorized access to part of its network, including production-related systems. …CYBERINSIDER.COM
17 JulNew Windows LegacyHive zero-day gives hackers admin privilegesA security researcher using the "Nightmare Eclipse" handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Windows systems. [...]BLEEPINGCOMPUTER.COM
17 JulThe Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace?Military forces are under increasing pressure to field autonomous capabilities faster than ever before. Across the U.S., UK, and NATO, new investment, evolving defense strategies, and accelerated acquisition pathways are transforming how capability is delivered, rewarding program…THEHACKERNEWS.COM
17 JulGold Eagle Clearinghouse Targets Security Gap, But How Is UnclearThe White House launched Gold Eagle to coordinate vulnerability response in a new AI world, but multiple questions linger over how it's being implemented.DARKREADING.COM
17 JulItaly fines Wind Tre $2 million for data breaches affecting 365k customersItaly's data protection authority (Garante per la Protezione dei Dati Personali) has fined telecommunications provider Wind Tre €1.715 million (approximately $2 million) after finding serious security shortcomings that led to two data breaches affecting more than 365,000 customer…CYBERINSIDER.COM
17 JulIn Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD BlueprintNoteworthy stories that might have slipped under the radar: OpenClaw AI agents exploited via WhatsApp, ransomware hits naval defense firm TKMS, Lidl discloses data breach. The post In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint appeared f…SECURITYWEEK.COM
17 JulNightmare Eclipse drops another Windows zero-day.The Gentlemen topped the ransomware leaderboard in Q2 2026. Ransomware attack disrupts Fairlife dairy production.THECYBERWIRE.COM
17 JulRansomware attack forces Coca-Cola to suspend US production at dairy unitThe beverage company is still working to determine the full scope of the breach at its Fairlife business.CYBERSECURITYDIVE.COM
17 JulOnlyFans performers become unlikely allies of CISOs in securing websitesCISOs at government organizations and universities have an unexpected ally coming to their aid: OnlyFans models. For some time, hackers have exploited weaknesses in the websites of universities or government departments to host scams or malware, using content stolen from the Only…CSOONLINE.COM
17 JulHollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payloadA vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes. [...]BLEEPINGCOMPUTER.COM
17 JulFBI arrests man accused of using Steam games to drain victims’ crypto walletsLorenzo Franceschi-Bicchierai reports: U.S. prosecutors have accused a Florida man of uploading fake video games that contained malware to Steam, the popular PC games platform. Once victims downloaded and installed the games, the malware was designed to infect their computers, st…DATABREACHES.NET
17 JulUS Military Smartphones Targeted Through Roaming and Ad TechSenior research fellow Gary Miller spoke to Financial Times about attempts to exploit mobile network vulnerabilities to track US personnel during the Iran war. The post US Military Smartphones Targeted Through Roaming and Ad Tech appeared first on The Citizen Lab .CITIZENLAB.CA
17 JulMetasploit Wrap Up: An HTTP to SMB relay plus Payload ImprovementsMetasploit Wrap Up Housekeeping While the Metasploit Framework will be continuing its weekly release cadence, bringing you dear reader our latest content, the Weekly Wrap Up is being shifted to a bi-weekly cadence. The team is planning to use the additional time between posts to …RAPID7.COM
17 JulA nightmare on Windows street.Nightmare Eclipse drops another Windows zero-day. The Gentlemen take the ransomware crown. CISA orders emergency Fortinet patching. Canada’s surveillance bill faces U.S. scrutiny. Meta’s Oversight Board flags AI censorship bias. Commerce tops the cyber target list. An active espi…THECYBERWIRE.COM
17 JulInc Ransomware Exploits SonicWall SMA Zero-DaysWhen chained together, the two vulnerabilities allow threat actors to gain root-level capabilities on SonicWall's mobile access appliances.DARKREADING.COM
17 JulProxying to Compromise: SonicWall Secure Mobile Access 0-day ExploitationIn early July 2026, Volexity was engaged to perform an incident response investigation where it discovered a threat actor had successfully compromised SonicWall Secure Mobile Access (SMA) VPN appliances through […] The post Proxying to Compromise: SonicWall Secure Mobile Ac…VOLEXITY.COM
17 JulErnst & Young (EY) Investigates Data Breach Involving Third-Party Support TicketsErnst & Young (EY) disclosed a data breach after attackers compromised a third-party IT support system containing client documents and tax information. Ernst & Young (EY) is disclosed a data breach linked to a compromised third-party support ticket system used by its IT t…SECURITYAFFAIRS.COM
16 JulTuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet DevelopmentCybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance from a large language model (LLM), albeit with not so successful results. "While th…THEHACKERNEWS.COM
16 JulGPT-Red beat human red teamers on a prompt injection testGPT-Red is an automated red-teaming model that OpenAI trains to find prompt injection weaknesses. It works the way a human red-teamer does. It sends a prompt, watches how a GPT model responds, and iterates toward a goal such as a successful data exfiltration. Training runs on sel…HELPNETSECURITY.COM
16 JulFinance phishing works because it sounds boringly normalFinance departments process a constant stream of invoices, contracts, payment notices, and procurement emails, making email one of the most common initial access vectors for threat actors. According to Cofense, attackers exploit those workflows with phishing emails that resemble …HELPNETSECURITY.COM
16 JulCaught on ScamTokThis week, while Maria is out hosts ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Joe Carrigan⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ are discussing the latest in social engineering…THECYBERWIRE.COM
16 JulCompanies keep getting breached by vulnerabilities they already knew aboutScanning tools have gotten good at their work. Organizations now find more weaknesses across more of their systems than at any earlier point in the industry’s history. A survey from the security firm Vicarius points to a gap that opens after that discovery, in the work of a…HELPNETSECURITY.COM
16 JulReading between the lines of a cyber insurance policyEnterprises in regulated industries often carry cyber insurance policies because contracts require it or boards ask for documented risk transfer. The global market for these policies reached about $16 billion in premiums in 2024. Coverage has become widespread. Payouts have grown…HELPNETSECURITY.COM
16 JulWhat public money does to open-source projectsMost of the software running inside a typical company was written by volunteers the company never paid. Open-source code sits under web apps, build pipelines, and the machine learning stacks getting so much attention right now. Roughly 96 percent of codebases carry some of it. Th…HELPNETSECURITY.COM
16 Jul KEVFlaw surge fuels need for CISOs to rethink vulnerability managementSecurity experts are calling on enterprises to revise their vulnerability management strategies and move towards “just in time” patching in response the increased pace of vulnerability exploitation. Attackers are turning to AI to increase the rate of vulnerability exploitation an…CSOONLINE.COM
16 JulNightmare Eclipse Drops ‘LegacyHive’ Windows Zero-DayThe researcher stripped the proof-of-concept (PoC) exploit to prevent immediate exploitation of the vulnerability. The post Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulSrsly Risky Biz: Ransomware uses AI to amp up negotiationsTom Uren and James Wilson talk about different ways ransomware groups are taking advantage of AI. The relatively new FulcrumSec group uses simple techniques to breach companies and then uses AI to get more leverage over victims in its extortion negotiations. They also discuss the…RISKY.BIZ
16 JulThe executive profile your security team isn’t defendingA few years ago, I was retained to conduct a digital risk review for the chief executive of a mid-sized financial services firm. The brief was standard. Assess what was publicly available about the executive, identify exposure and advise on remediation. The AI tools I used comple…CSOONLINE.COM
16 JulUS Launches Gold Eagle to Coordinate AI-Driven Vulnerability ManagementThe White House announced Gold Eagle to help accelerate the discovery, prioritization and patching of flaws found by AIINFOSECURITY-MAGAZINE.COM
16 JulMicrosoft makes Windows SSO prompts easier to manageMicrosoft is introducing a new registry-based policy that lets IT administrators automatically accept Windows SSO permissions on Windows 11 versions 24H2 and 25H2 devices managed with Microsoft Entra ID. Users with personal Microsoft accounts and devices outside policy-managed en…HELPNETSECURITY.COM
16 JulOpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 SolOpenAI has disclosed details of GPT-Red, an internal automated red-teaming model that scales prompt injection vulnerability discovery with an aim to fix issues before the tools are deployed widely. "GPT‑Red is a strong red-teamer, and our previous models are highly vulnerable to …THEHACKERNEWS.COM
16 JulWhen AI gets a body, it inherits an attack surfaceMost security leaders I know working on AI robotics are being shown the same kind of video. A humanoid folds a shirt, sorts a bin, walks a warehouse aisle and a vendor uses the clip to move an embodied AI system from pitch to purchase order. Someone then has to sign off. Robot de…CSOONLINE.COM
16 JulF5 Patches Multiple NGINX, BIG-IP VulnerabilitiesAttackers could exploit the bugs to modify configurations, terminate or restart processes, cross security boundaries, leak memory, and execute code. The post F5 Patches Multiple NGINX, BIG-IP Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulTenable One unifies code risks with enterprise exposure dataTenable has announced the expansion of the Tenable One Exposure Management Platform, unifying application security risks with all other exposure data. By integrating static code vulnerability data, Tenable One delivers complete, code-to-runtime visibility across the entire attack…HELPNETSECURITY.COM
16 JulUnpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-WidePull the certificate off the flash of a Shark RV2320EDUS robot vacuum, and you can run root commands on other people's Shark vacuums across the same AWS region: watch the camera, drive the robot, read the map of the house, and take the Wi-Fi password in plaintext. A researcher pu…THEHACKERNEWS.COM
16 JulCISA urges software vendors to formalize vulnerability disclosure programsThe Cybersecurity and Infrastructure Security Agency (CISA) and four international cybersecurity agencies have published guidance urging software manufacturers and online service providers to establish coordinated vulnerability disclosure (CVD) programs, saying structured engagem…CSOONLINE.COM
16 Jul KEVCISA orders feds to patch actively exploited Oracle flaw by SaturdayCISA has ordered federal agencies to secure their systems by Saturday against ongoing attacks exploiting a critical vulnerability in the Oracle E-Business Suite financial application. [...]BLEEPINGCOMPUTER.COM
16 JulSpaceXAI admits Grok retained developer data in open-source announcementSpaceXAI has acknowledged that Grok Build retained coding data for some users during its early beta, days after security researchers disclosed that the AI coding tool was uploading entire developer repositories. Alongside the admission, the company announced it is open-sourcing t…CYBERINSIDER.COM
16 JulValorC3 extends SaaS protection with immutable cloud backupsValorC3 Data Centers today announced the general availability of Backup as a Service, a fully managed offering that protects the SaaS data businesses rely on most, including Microsoft 365, Entra ID and Salesforce. Every backup is immutable, so data stays recoverable after deletio…HELPNETSECURITY.COM
16 JulThe best defenders build AI agents together: Join Tenable for Swarm at Black Hat ’26Agentic AI use is exploding, yet most security teams are building agents in isolation. Tenable is hosting Swarm, a build event at Black Hat 2026, for security practitioners to create and collaborate on agentic, open-source tooling to drive collective defense and stop adversaries …TENABLE.COM
16 JulRussian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutesA Russian-speaking threat actor known as “bandcampro” used a jailbroken Gemini CLI, Google’s open-source terminal-based AI agent, to deploy and operate a small command-and-control (C2) botnet, according to TrendAI. Operational overview (Source: TrendAI) In more …HELPNETSECURITY.COM
16 JulAU: Regulator’s preliminary findings did not indicate Qantas breached privacy obligationsVlad Constantinescu reports that the Office of the Australian Information Commissioner has determined that although the Qantas data breach of 2025 resulted in 5.67 million customer records being compromised and leaked, the regulator’s preliminary inquiry did not indicate th…DATABREACHES.NET
16 JulThalha Jubair and Owen Flowers sentenced to prisonStanley Murphy-Johns, Rosie Shead, and Alex Levy report that Thalha Jubair, 20, and Owen Flowers, 18, were both sentenced at Woolwich Crown Court to 5 years and six months in prison for hacking Transport for London. In a televised sentencing, Mr Justice Turner addressed the defen…DATABREACHES.NET
16 JulModular macOS Stealer Uses Kill Loops to Force Password EntryNew ClickLock macOS stealer locked victims out of their own system until they surrendered a passwordINFOSECURITY-MAGAZINE.COM
16 JulCISA folds its own hard-won lessons into coordinated vulnerability disclosure guidanceOn Wednesday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and four allied cyber authorities published a guide telling software vendors how to build a coordinated vulnerability disclosure (CVD) program. Six days earlier, CISA published a blog post explaining h…HELPNETSECURITY.COM
16 JulSunsetting the Public AttackerKB PlatformWhat’s changing, where AttackerKB-style analysis will live, and how users can continue finding Rapid7 vulnerability intelligence. On August 18, Rapid7 will sunset the standalone public AttackerKB website as part of a broader effort to unify our vulnerability intelligence, exploit…RAPID7.COM
16 Jul KEVCISA warns of actively exploited SharePoint flaws.A new stealthy ransomware family emerges. Law enforcement operation disrupts international fraud scheme.THECYBERWIRE.COM
16 JulLegacy Systems, Real-World Impacts: The Reality of OT SecurityLegacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. The post Legacy Systems, Real-World Impacts: The Reality of OT Security appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulZoom patches account takeover holeZoom has identified, and patched, a critical security hole that “may allow an unauthenticated user to conduct an account takeover via network access.” The issue is especially significant given Zoom’s extensive reach; it reportedly has more than 300 million daily active users, inc…CSOONLINE.COM
16 JulTwo Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL HackOwen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five and a half years at Woolwich Crown Court on Thursday, 16 July 2026, for the 2024 hack of Transport for London. The attack left 148 TfL systems inoperable and forced all 27,000 of the transport authority's employ…THEHACKERNEWS.COM
16 JulVU#885548: Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditionsOverview A denial-of-service (DoS) vulnerability exists in some HTTP/2 server implementations that fail to adequately limit resource consumption when buffering response data under stalled flow-control conditions. A remote, unauthenticated attacker can trigger memory exhaustion an…KB.CERT.ORG
16 JulBTS #78 - Patching: The Race Against TimeIn this episode of Below the Surface, host Paul Asadoorian is joined by Vlad Babkin and Chase Snyder for a wide-ranging discussion on modern vulnerability management, network appliance visibility, AI-assisted exploitation, Linux kernel bugs, cold boot attacks, and software supply…ECLYPSIUM.COM
16 JulItaly fines WINDTRE €1.7 million over data breachesGianluca Semeraro reports: Italy’s data protection authority has fined telecoms operator WINDTRE €1.7 million ($1.94 million) for “serious shortcomings” in ​its data security systems, leading ‌to two unauthorised breaches and the exposure of personal information belonging to more…DATABREACHES.NET
16 JulProgram to rotate cyber personnel through federal agencies saw little useThe number of people who got approval to be in the Federal Rotational Cyber Workforce program was in the single digits, GAO found. The post Program to rotate cyber personnel through federal agencies saw little use appeared first on CyberScoop .CYBERSCOOP.COM
16 JulClaude Chrome extension flaw lets malicious extensions trigger AI actionsA flaw in Anthropic's Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude's access to connected services such as Gmail, Google Docs, Google Calendar, and Salesfor…BLEEPINGCOMPUTER.COM
16 JulFor hackers, sharing is caring.CISA warns of active SharePoint attacks. The NSA pushes coordinated vulnerability disclosure. ClickLock Stealer targets macOS. Splunk and Zoom patch critical flaws. Spirals ransomware strikes in under 24 hours. New Windows evasion techniques emerge. LabubaRAT poses as NVIDIA soft…THECYBERWIRE.COM
16 Jul1999 Called and It Wants It's Exploits Back - PSW #935This week, our technical segment covers a new open-source tool written by Paul (and Claude) that helps you keep your Linux systems up to date and assess supply chain risks. It's called "fettle" and is a pure Python implementation that gives you even more features than previously …YOUTUBE.COM
16 JulNew ClickLock macOS malware traps users into revealing login passwordA new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password. [...]BLEEPINGCOMPUTER.COM
16 JulCoca-Cola says Fairlife ransomware attack halts US dairy productionThe Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily suspending production of Fairlife products across the United States. [...]BLEEPINGCOMPUTER.COM
16 JulThe Breach That Won’t End: An Update on Canvas, and how they created an EdTech’s Vendor Trust ProblemJeff Piontek comments on the Instructure breach: The forensic review has taken far longer than anyone expected. Through June, Instructure was still finalizing customer-specific findings and asking institutions to designate a security contact to receive them. In early July, the co…DATABREACHES.NET
15 JulMicrosoft Patches Record 622 Flaws, Including Two Zero-Days Under Active AttackMicrosoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft's own CVEs by its Security Update Guide count, more than triple June's previous high of around 2…THEHACKERNEWS.COM
15 JulICYMI: June 2026 @AWS SecurityRead all about the latest AWS security features, compliance updates, and hands-on resources in our new, monthly digest posts. You’ll find expert blog posts, new service capabilities, code samples, and workshops. AWS Security Blog posts This month’s AWS Security Blog posts covered…AWS.AMAZON.COM
15 JulShareFile explained, healthcare in critical cyber condition and click fix tops malware chartsShareFile emergency explained, a year of Salesforce breaches examined, healthcare cybersecurity in critical condition and click fix goes number one for malware. David Shipley covers Progress Software's emergency ShareFile shutdown, now tied to a previously unknown high-severity p…CYBERSECURITYTODAY.LIBSYN.COM
15 JulAI used to help plan the break-in, now it’s doing the break-inOver the past twelve months, researchers documented intrusions in which AI ran exploitation workflows autonomously, generating thousands of commands across dozens of sessions with minimal human direction, according to Check Point’s AI Security Report 2026. AI-powered cyber attack…HELPNETSECURITY.COM
15 JulThe MDR renewal question: What changes when AI can handle the alertsFor most of the past decade, the managed detection and response (MDR) decision was a simple one: teams that couldn’t staff a 24/7 SOC outsourced detection and response to a provider who could. It solved a resources problem, and the alternatives (hiring a team you couldnR…HELPNETSECURITY.COM
15 JulGoose Creek - 6,574,121 breached accountsIn June 2026, a party claiming to have access to data from Goose Creek Candle Company sent emails to a number of the company's customers , claiming the company had a security vulnerability and suffered a data breach. The data was subsequently sent to Have I Been Pwned and contain…HAVEIBEENPWNED.COM
15 JulSingGuard-NSFA: Open-source guardrails for agentic AISingGuard-NSFA is an open-source guardrail framework aimed at operational threats in agent workflows. Four models ship at 0.8B, 2B, 4B, and 9B parameters, all built on Qwen3.5 base backbones. Risk taxonomy The NSFA risk taxonomy organizes threats along the CIA triad of confidenti…HELPNETSECURITY.COM
15 Jul7 skills and traits of elite security engineersSecurity engineers play a pivotal role in enterprise cybersecurity, because they are the professionals who design, build, and deploy security systems to protect an organization’s data, applications, systems, networks, and other IT components against a variety of cyber threats. Fi…CSOONLINE.COM
15 JulCritical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 UpdatesPublic exploit code targeting the Firefox flaws exists, but no in-the-wild exploitation has been observed. The post Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates appeared first on SecurityWeek .SECURITYWEEK.COM
15 JulNigeria Deepens Cybersecurity Efforts as Cybercriminals See More ProfitsThe West African country advanced rules to force organizations to disclose cyberattacks, joining other nations in a shift to mandated transparency.DARKREADING.COM
15 JulFortinet adds AI controls and data loss prevention to FortiEndpointFortinet has announced new capabilities for its unified endpoint platform, FortiEndpoint, designed to help organizations securely adopt AI, protect sensitive data, and reduce risk. By bringing AI visibility and control, native data security, endpoint risk scoring, and FortiAI-ass…HELPNETSECURITY.COM
15 JulCybersecurity needs more prevention and less reliance on cureAsk any medical doctor, and they’ll tell you that prevention is better than cure. It’s more cost-effective and it has better outcomes. The same is true in cybersecurity. But we believe that our industry has veered too far away from this simple concept. We observe that most new to…CSOONLINE.COM
15 JulSonicWall warns of active exploitation of two SMA 1000 zero-daysSonicWall warns of active attacks exploiting two SMA 1000 zero-days, including a flaw enabling arbitrary command execution. SonicWall confirmed the active exploitation of two zero-day vulnerabilities affecting Secure Mobile Access (SMA) 1000 appliances. The vulnerabilities were i…SECURITYAFFAIRS.COM
15 JulCompromised AsyncAPI npm Packages Deliver Multi-Stage Botnet MalwareFour compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security, SafeDep, Socket, and StepSecurity. The affected packages are listed below - @asyncapi/generator-helpers@1.1.1 @asyncapi/ge…THEHACKERNEWS.COM
15 Jul KEVTake Back Control as Enterprises Struggle to Incorporate Risks They Don't Understand - BSW #456More than 48,000 vulnerabilities were disclosed in 2025, yet only about 1% are actively exploited. However, you’re expected to mitigate all vulnerabilities, or at least critical and high. But what if there is no patch to fix the vulnerability or the software is unsupported? Ben L…YOUTUBE.COM
15 JulMicrosoft Patches 570 CVEs in Record Patch TuesdayMicrosoft released fixes for a record 570 CVEs in its July Patch Tuesday update, as experts warn AI is dramatically accelerating vulnerability discovery and increasing patch volumesINFOSECURITY-MAGAZINE.COM
15 Jul KEVCISA warns admins to patch actively exploited SharePoint flawsThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances. [...]BLEEPINGCOMPUTER.COM
15 JulProgress Confirms Zero-Day Vulnerability Behind ShareFile DisruptionThe company has rolled out a fix and is restoring access for Storage Zones Controller customers who apply it. The post Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption appeared first on SecurityWeek .SECURITYWEEK.COM
15 JulCursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code ExecutionOpen a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning that anything in the folder is about to execute. Whatever that binary does, it does as you, with your source…THEHACKERNEWS.COM
15 JulChrome Sync increasingly abused to stalk unsuspecting victimsCyberstalkers are increasingly exploiting Google Chrome's built-in synchronization feature to secretly monitor victims' web activity without installing spyware or compromising their devices. Security firm Certo says it has received a growing number of reports involving the tactic…CYBERINSIDER.COM
15 JulWhite House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination InitiativeThe new program stems from an AI-focused Executive Order signed by President Trump on June 2. The post White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative appeared first on SecurityWeek .SECURITYWEEK.COM
15 JulClickFix is changing the economics of social engineeringClickFix has moved from a one-off social engineering trick into an industrialized attack ecosystem that is outpacing conventional antivirus and endpoint defenses, according to ReversingLabs. The technique first showed up in late 2023 and early 2024, and Proofpoint named it in mid…HELPNETSECURITY.COM
15 JulProgress Restores ShareFile Storage Zones Access After Vulnerability Exploit ConcernsProgress has restored access to its ShareFile Storage Zones Controller after a four-day suspension triggered by a credible external security threatINFOSECURITY-MAGAZINE.COM
15 JulPolygraf AI Meeting Guard delivers real-time deepfake detection for enterprise meetingsPolygraf AI has announced Meeting Guard, a real-time AI fraud detection solution for enterprise meetings built to detect fraud and protect meeting security. AI can clone a voice, animate a face, and answer every interview question in real time, making trust signals obsolete acros…HELPNETSECURITY.COM
15 JulResearcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch TuesdaySecurity researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive. It has been described as a Windows User Profile Service arbitrary hive load elevation of privileges vulnerability. The Windows User Profile Service, al…THEHACKERNEWS.COM
15 JulNew Windows Bind Link techniques let attackers evade EDR, security controlsAttackers who already have administrator privileges on a Windows machine have newer ways to slip past endpoint security without exploiting a vulnerable driver or modifying trusted binaries. Bitdefender researchers have warned against three techniques that abuse Windows Bind Links…CSOONLINE.COM
15 JulWhite House launches AI-driven vulnerability clearinghouse to speed cyber remediationThe White House is expanding the use of AI beyond cyber threat detection into vulnerability management, launching a new program that aims to help government agencies and critical infrastructure operators identify, prioritize, and remediate software vulnerabilities faster. Called …CSOONLINE.COM
15 JulNew bugs in Claude for Chrome allow extensions to abuse AI privilegesTwo vulnerabilities found in Anthropic’s Claude for Chrome extension remain exploitable months after they were reported to the company, a research by Manifold Security noted. According to the researchers, the flaws can allow a malicious browser extension to trigger Claude into pe…CSOONLINE.COM
15 Jul5 reasons to bring application security data into your exposure management platformWhen you incorporate data from application security scanners into your exposure management platform, you can assess the threat from formerly isolated code flaws using a broader risk context, which illuminates hidden exposures that your security and development teams can eliminate…TENABLE.COM
15 JulJuly 2026 Patch Tuesday fixes 622 Microsoft CVEs, including three zero-daysMicrosoft's July 2026 Patch Tuesday sets yet another record, fixing 622 Microsoft CVEs—three times as many as last month.MALWAREBYTES.COM
15 JulMicrosoft smashes Patch Tuesday record for second successive monthVulnerability counts have been surging this year, and Microsoft's mammoth disclosure this week of 622 bugs is larger than the three previous months combined.THERECORD.MEDIA
15 JulCompromised Logins Surge as the Most Common Entry Point for Ransomware AttacksResearch of incidents by Sophos finds that phishing, brute force attacks and other identity-based threats have surpassed software vulnerabilities as means of delivering ransomwareINFOSECURITY-MAGAZINE.COM
15 Jul2-Click Cursor Exploit Enables Dev Environment TakeoverSimple age-old bugs give bad actors access to developers' secrets and source code-rich environments.DARKREADING.COM
15 JulNayax updates its incident status; states it won’t pay any extortion demandIt’s common for victims and threat actors to disagree sharply over the scope of an attack or its significance. Today’s example involves Israeli fintech Nayax and a group called The Syndicate. In previous coverage, DataBreaches cited Nayax’s submission to the Sec…DATABREACHES.NET
15 JulAU: Partnered Health Data Breach Exposes Patient Records at Family ClinicsTrevor Long reports: A large health care chain that owns family medical clinics across Australia has been the victim of a cyber breach which has exposed the data of their patients, including potentially treatment information. Partnered Health runs a large number of clinics across…DATABREACHES.NET
15 JulAsyncAPI npm Supply Chain Attack: Malware Injected Into Packages With 2 Million Weekly DownloadsAsyncAPI npm packages with 2M weekly downloads were compromised, spreading malware with info-stealing, crypto-theft and RAT capabilities. OX Security researchers disclosed on July 14 that the AsyncAPI npm organization was compromised, with malicious code injected into four packag…SECURITYAFFAIRS.COM
15 JulWe built a vulnerability vending machine: AI tokens in, zero-days outIntruder built an AI-powered "vulnerability vending machine" that combines code slicing with LLMs to automatically discover complex software vulnerabilities. The company explains how the system found and exploited a previously unknown WordPress plugin zero-day, with additional di…BLEEPINGCOMPUTER.COM
15 JulF5 Insight for ADSP enhances BIG-IP operations with guided updates and AI audit trailsF5 has announced new fleet management capabilities for F5 Insight for ADSP that help enterprises reduce risk exposure across F5 BIG-IP environments as frontier AI compresses vulnerability response timelines. The new F5 Insight workflows give security and operations teams fleet-wi…HELPNETSECURITY.COM
15 JulInvestigating Persistence Mechanisms in AWSOverview In the cloud, your infrastructure may be short-lived, but an attacker’s persistence doesn't have to be. While your environment scales and changes in seconds, adversaries are embedding themselves into your IAM policies, Lambda functions, and federated sessions, creating i…RAPID7.COM
15 JulAttackers Find Bugs Before CVEsResponsible disclosure gives vendors time to develop patches before vulnerabilities are publicly disclosed. That process can take months, while attackers may already be searching for and exploiting the same weaknesses. By combining AI with large-scale vulnerability data, security…YOUTUBE.COM
15 JulClaude for Chrome flaw could let rogue extensions access your GmailThe ClaudeBleed vulnerability still lets malicious Chrome extensions abuse Claude for Chrome's permissions.MALWAREBYTES.COM
15 JulUnpatched Cursor Vulnerability Exposes Users to Code ExecutionAn attacker can create a malicious repository containing a git.exe in the project root, and Cursor executes it automatically. The post Unpatched Cursor Vulnerability Exposes Users to Code Execution appeared first on SecurityWeek .SECURITYWEEK.COM
15 Jul KEVCISA Urges Immediate Patching of Exploited SharePoint VulnerabilitiesThree vulnerabilities are actively exploited in attacks, including two that have been targeted as zero-days. The post CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
15 JulUnderstanding Claude Tag’s access model in Slack and how to configure it securelyAnthropic’s new AI agent for Slack acts under an admin-configured access bundle rather than each user’s own credentials. Here’s how that model works, what admins should understand and how to securely configure it. Key takeaways Claude Tag, Anthropic’s newly launched AI agent for …TENABLE.COM
15 JulPatch Tuesday notes: Microsoft fixes a record 570 flaws.SonicWall warns of a maximum-severity zero-day. Business news: Valarian raises $50 million in Series A funding.THECYBERWIRE.COM
15 JulCISA warns that multiple vulnerabilities in SharePoint are under exploitationSecurity researchers say additional flaws are being chained together and a patch will not be available until August.CYBERSECURITYDIVE.COM
15 JulUS launches vulnerability clearinghouse amid AI-fueled surge in flawsThe Trump administration hopes the program will accelerate the discovery and fixing of serious technical problems before hackers exploit them.CYBERSECURITYDIVE.COM
15 JulClaude Flaw Automatically Sends Malicious Prompts to AI AgentsWhen combined with another exploit, the "PromptFiction" vulnerability, which has been fixed, could have enabled an end-to-end attack on a targeted system.DARKREADING.COM
15 JulChaotic Eclipse Unveils LegacyHive Exploit Affecting Fully Patched Windows SystemsLegacyHive PoC exposes a Windows Privilege Escalation flaw affecting fully patched Windows desktop and server systems. Just hours after Microsoft’s July 2026 Patch Tuesday, security researcher Nightmare Eclipse, also known as Chaotic Eclipse, published a new Windows zero-da…SECURITYAFFAIRS.COM
15 JulMicrosoft patches bug in video game Age of Empires IIThe vulnerability in the decades-old game could have allowed hackers to take over victims’ computers with a malicious game invite.TECHCRUNCH.COM
15 JulHack suggests AI music generator Suno scraped YouTube for training dataThe hacker used an employee's credentials to access source code, which revealed how Suno scraped decades of audio.TECHCRUNCH.COM
15 JulSonicWall customers under threat as attackers exploit 2 zero-daysResearchers said the vulnerabilities, which attackers are chaining together, were first exploited three weeks before the vendor disclosed and patched the defects. The post SonicWall customers under threat as attackers exploit 2 zero-days appeared first on CyberScoop .CYBERSCOOP.COM
15 JulGoogle Gemini CLI abused as a hacking agent, malware botnet operatorA Russian-speaking threat actor known as "bandcampro" used Google's open-source Gemini CLI AI tool as a hacking agent and to operate a small-scale botnet. [...]BLEEPINGCOMPUTER.COM
15 JulGuten Tag, Bonjour, Hola to Our European Cyber Defenders!We're thrilled to unveil the latest evolution of Dark Reading's DR Global section — your go-to source for region-specific cybersecurity intelligence beyond North America.DARKREADING.COM
15 JulWilmerHale Sued Over Client Personal Information Data BreachAlex Ebert reports: Wilmer Cutler Pickering Hale & Dorr should pay millions of dollars in damages for loss of clients’ personal information in a May data breach, a putative class action claims. The lawsuit, filed Tuesday in the US District Court for the District of Columbia, …DATABREACHES.NET
15 JulFiles relating to India’s largest nuclear power plant Kudankulam exposed in data breachMunsif Vengattil and Aditya Kalra Ransomware group World Leaks has posted on the dark web a huge cache of files related to India’s largest nuclear plant, including purported blueprints of parts of its ​facilities and supplier details — information it labelled as coming from…DATABREACHES.NET
15 JulNPM ecosystem hit with two new supply chain compromisesAttacks targeting developer ecosystems are increasing in frequency and sophistication, with Node.js developers firmly in this week’s crosshairs, as multiple npm packages belonging to the open-source AsyncAPI and Jscrambler Code Integrity were poisoned with malware following compr…CSOONLINE.COM
15 Jul KEVPatchapalooza packs a punch.Patch Tuesday. SonicWall urges immediate patching of actively exploited vulnerabilities. The White House launches an AI-backed vulnerability clearinghouse. The Air Force contends with widespread cybersecurity quarantines. The UK and EU blame Russia for last year’s cyberattack on …THECYBERWIRE.COM
15 JulSecurity researchers find stalkers abusing Chrome’s sync featureCerto Software warns that the capability, designed for convenience, can easily be used to spy on online activity. The post Security researchers find stalkers abusing Chrome’s sync feature appeared first on CyberScoop .CYBERSCOOP.COM
15 JulZoom warns of critical account takeover vulnerabilityZoom is warning of a critical vulnerability in its desktop client and software development kit for Windows that could be exploited by an unauthenticated party to hijack accounts. [...]BLEEPINGCOMPUTER.COM
15 JulIdentity Attacks Overtake Exploits as Top Ransomware CauseEmail attacks overtook exploits as the top ransomware root cause last year. Multifactor authentication (MFA) was deployed in 97% of credential-based attacks but failed to prevent compromise.DARKREADING.COM
15 JulCalgary 911 employee charged with breach of trustManjot Singh reports: Calgary police say a City of Calgary 911 employee has been charged following an investigation into the unauthorized disclosure of confidential information. Police say the investigation began in January after allegations that sensitive information was being a…DATABREACHES.NET
15 JulUS and allied Governments’ Recommendations: Securing Network Devices Against Russian APT GroupsUS and allies warn of Russian APT groups targeting routers and network devices to compromise critical infrastructure worldwide. The US and allied governments warn that Russian state-sponsored APT groups are scanning and exploiting poorly secured network devices, especially router…SECURITYAFFAIRS.COM
15 Jul“AI Normal Tech” vs “AGI by Tuesday”: Security Advice That Survives Either FutureIf you look at social media debates about AI, two extreme patterns emerge. Studying extreme patterns is very useful because understanding boundary conditions helps you understand the whole phenomenon — in this case of security in AI adoption (recent extreme example ). You can als…MEDIUM.COM
14 JulBetween Two Nerds: Exploits are not cyber powerIn this edition of Between Two Nerds Tom Uren and The Grugq discuss just how important exploits are for cyber operations using data published in a new paper authored by two members of Ukraine’s cyber security agency. This episode is also available on YouTube.RISKY.BIZ
14 JulAI Security Report 2026For years, the cyber security industry tracked AI as a force multiplier: something that made existing attack techniques faster, cheaper, and more accessible. That framing was accurate. But the Annual AI Security Report 2026 from Check Point Research documents a transition that go…RESEARCH.CHECKPOINT.COM
14 JulChatto: Open-source team messenger with privacy at its coreTeams that want their group chats off commercial platforms have a growing menu of self-hosted options. Chatto joined that group when its developer released the code under an open-source license and posted binaries for anyone to run on their own hardware. The software aims at the …HELPNETSECURITY.COM
14 JulThe best defense against AI attacks turns out to be a skeptical humanAnalysts across the security industry now run generative AI through their daily work, from log triage to incident write-ups. Active use in cybersecurity strategy reached 78% of practitioners in 2026, up from half the field a year earlier. The 2026 SANS AI Survey, drawn from 536 I…HELPNETSECURITY.COM
14 JulFake smart home residents could stand in for real ones in security researchSmart home security research runs on a scarce ingredient: recordings of how real people use the gadgets in their homes. Getting that data means wiring up someone’s house and watching for months, which is slow, costly, and about as invasive as it sounds. So the datasets stay…HELPNETSECURITY.COM
14 JulMicrosoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three PathsAttackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform. The way in has been the trust the organization had already extended, usua…THEHACKERNEWS.COM
14 JulPentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity RulesA new CMMC review and reform task force will conduct a comprehensive review of the program. The post Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulNew tutorials on underground hacking forums have roughly doubledUnderground hacking forums are producing more original tutorials again, with growing attention on financial fraud, particularly the theft and fraudulent use of payment card data, known as carding, and cash-out techniques. New tutorials per month versus reposts (Source: Radware) F…HELPNETSECURITY.COM
14 JulDiscovering & Securing Your AI Agent Attack Surface - Jeremy Snyder - ASW #391While LLMs and agents are new to appsec and everyone else, a lot of AI security requirements translate to well-known API security requirements. Jeremy Snyder helps us frame the OWASP LLM Top 10 into five layers in order to help orgs understand and prioritize their attack surface.…YOUTUBE.COM
14 JulRapid7 and Mindshare Partner to Accelerate Cyber Resilience Across the Middle EastGopan Sivasankaran is Regional Director, Middle East & Africa, at Rapid7 From AI adoption and cloud-first strategies to smart cities and critical infrastructure modernization, organizations across the United Arab Emirates are embracing innovation at an unprecedented rate. The cou…RAPID7.COM
14 JulGrok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It ReadsxAI's Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not just the files a coding task needed. A researcher publishing as cereblab, testing version 0.2.93, captured one of those uploads, cloned…THEHACKERNEWS.COM
14 JulAI incidents need a new playbook. Here’s how to build oneSeventy-one percent of organizations say AI has access to core business systems. Only 16% govern that access effectively, according to the 2026 CISO AI Risk Report . Ask your IR team three questions: Where is your AI system inventory? What happens if a production model starts gen…CSOONLINE.COM
14 JulThe inside job that cost ransomware victims millionsInstead of helping victims negotiate with BlackCat, a trusted ransomware negotiator secretly helped the gang extort them.MALWAREBYTES.COM
14 JulMalware Hits Japan’s Largest Taxi Company Nihon Kotsu, Services Temporarily SuspendedJapan’s largest taxi operator Nihon Kotsu shut down systems after a malware attack, disrupting dispatch and bookings. Nihon Kotsu, Japan’s largest taxi company, disclosed on July 13, 2026 that its internal systems suffered an unauthorized external access involving mal…SECURITYAFFAIRS.COM
14 JulThe serpent’s tongue: Luring the Python out of its denThis blog examines the full lifecycle of a Python package, from hosting on repositories such as PyPI or custom web servers, through source and wheel distribution formats, to the final installation into virtual or system-wide Python environments.TALOSINTELLIGENCE.COM
14 JulInside China's Cyber Espionage BusinessAhana Datta Fasel became the British government’s first ethical hacker in 2014, testing vulnerabilities in computer systems and networks that hackers could potentially exploit. She was only 23, but that gave her an early look at state-sponsored cyber intrusions, which have of cou…THECYBERWIRE.COM
14 JulGoogle adds FIDO2 keys and phone passkeys to Windows login via GCPWGoogle has started rolling out FIDO2-compliant physical security key support as a second factor for authentication in Google Credential Provider for Windows (GCPW) to all Google Workspace customers. GCPW is a free tool that lets users sign in to Windows computers with their Googl…HELPNETSECURITY.COM
14 JulVulnerability in FIFA’s NetworkFIFA’s network was vulnerable to anyone with even minimal access.SCHNEIER.COM
14 JulWarning: Scammers are using FaceTime to empty bank accountsCybercriminals are combining social engineering through apps like FaceTime with unpatched devices to steal credentials and drain bank accounts.MALWAREBYTES.COM
14 JulNew MacOS Malware Exploits Legitimate Developer ID to Pose as Apple Crash ReporterResearchers at Jamf Threat Labs detail CrashStealer, which steals passwords, cryptocurrency wallets and moreINFOSECURITY-MAGAZINE.COM
14 JulSAP warns of critical flaws in NetWeaver and Commerce CloudSAP has addressed 16 vulnerabilities across multiple products as part of its July 2026 security updates, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter. [...]BLEEPINGCOMPUTER.COM
14 JulSAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce CloudThe flaws could allow attackers to access and modify data, and cause system unavailability and request-response desynchronization. The post SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulUnpatched Claude for Chrome Flaw Lets Extensions Read Gmail, CalendarA ClaudeBleed-linked vulnerability reportedly persists across eight patches, exposing potentially sensitive data to other extensions. The post Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulCursor IDE Auto-Executes Malicious Code in Poisoned ReposResearchers reported the vulnerability to Cursor in December, but it still remains in the popular AI coding platform and can be exploited in poisoned repository attacks.DARKREADING.COM
14 Jul“Context bombs” can frustrate AI-driven attacks, researchers foundA new approach tried out by Tracebit researchers has proven very effective at stopping AI agents from fully compromising targeted environments. What makes it notable isn’t the technique – prompt injection is old news – but the direction it’s pointed: not t…HELPNETSECURITY.COM
14 Jul11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure BootCybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Secure Boot on most systems using the modern firmware standard. "An attacker exploiting one of these vulnerable application…THEHACKERNEWS.COM
14 JulYou Don't Have to Run an Exploit to Know If You're VulnerableMany vulnerabilities cannot be safely validated with live exploits, either because no exploit exists or the affected systems are too critical to test. Picus explains how TTP chaining helps organizations determine exploitability by validating the attack techniques an exploit depen…BLEEPINGCOMPUTER.COM
14 Jul7 Severe Vulnerabilities Patched in VMware Avi Load BalancerThe flaws can be exploited for authentication bypass, remote code execution, privilege escalation, and directory traversal. The post 7 Severe Vulnerabilities Patched in VMware Avi Load Balancer appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulRabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue MetadataCybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enterprise messaging infrastructure to takeover risks, and bypass tenant boundaries. …THEHACKERNEWS.COM
14 JulIran abused mobile networks’ vulnerabilities to locate US military in the Middle East, report saysThe Iranian government exploited well-known flaws in cellphone networks to locate and then strike U.S. military personnel in the build-up and beginning of the war.TECHCRUNCH.COM
14 JulGrapheneOS says Google will cut security backports for older Android releasesGrapheneOS claims Google has significantly reduced security patch backports for older Android versions. This change could leave devices on previous releases with fewer vulnerability fixes despite continuing to receive monthly security updates. Google has not publicly documented t…CYBERINSIDER.COM
14 JulProgress confirms ShareFile zero-day flaw behind Storage Zone shutdownProgress Software has confirmed that a high-severity zero-day vulnerability is behind the emergency shutdown of ShareFile Storage Zone Controllers last week and has released security updates to patch the flaw. [...]BLEEPINGCOMPUTER.COM
14 JulMicrosoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-daysToday is Microsoft's July 2026 Patch Tuesday, and with it comes security updates for a record-breaking 570 flaws, including two zero-day vulnerabilities exploited in attacks and one publicly disclosed. [...]BLEEPINGCOMPUTER.COM
14 JulMicrosoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-DaysTwo flaws in Active Directory and SharePoint Server have been exploited as zero-days, and a BitLocker bug was publicly disclosed. The post Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulDoxbin admin jailed for egging on swatters from behind a screenConnor Jones reports: A Welshman was sentenced to prison on Tuesday for his role in numerous swattings in the UK, US, and Canada. Callum Dare, 26, was an administrator of Doxbin, a dark web platform frequented by individuals that expose the personally identifiable information (PI…DATABREACHES.NET
14 JulMicrosoft Patches a Record 570 Security FlawsMicrosoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attribu…KREBSONSECURITY.COM
14 JulMicrosoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)This patch Tuesday includes a staggering&#;x26;#;xc2;&#;x26;#;xa0;622 vulnerabilities, not including another 427 vulnerabilities in Chromium, affecting Microsoft&#;x26;#;39;s Edge browser. 62 of t…ISC.SANS.EDU
14 Jul KEVThe ransomware toll road.Treasury sanctions a VPN provider tied to ransomware. The Pentagon hits pause on CMMC audits. Critical flaws surface in Google Cloud’s Dialogflow CX. Estée Lauder discloses a data breach. Mobile networks become a battlefield for tracking U.S. personnel. Australia calls out Big Te…THECYBERWIRE.COM
14 JulMicrosoft discloses ‘the mother of all’ vulnerability loads, tripling June’s previous recordThe company forewarned customers and defenders that a flood of defects would be uncovered by AI. It delivered with a striking exponential increase. The post Microsoft discloses ‘the mother of all’ vulnerability loads, tripling June’s previous record appeared first on CyberScoop .CYBERSCOOP.COM
14 JulDefending SaaS-based applications against ShinyHunters OAuth abuseFrom Microsoft Security Research and Microsoft Defender Security Research Team: In a series of campaigns observed between mid-2025 and mid-2026, Microsoft identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing …DATABREACHES.NET
14 Jul KEVMicrosoft rolls out massive Windows 11 security update with 416 fixesMicrosoft has released the July 2026 Patch Tuesday cumulative updates for Windows 11, fixing hundreds of security vulnerabilities while introducing Secure Boot improvements, security hardening changes, and compatibility fixes. The updates also patch a publicly disclosed BitLocker…CYBERINSIDER.COM
14 JulRecords Are Made to Be Broken: Patch Tuesday Raises Triage StakesThree of the 622 CVEs for which Microsoft issued patches this week are zero-days; there are more than 60 critical vulnerabilities.DARKREADING.COM
14 JulElon Musk promises to delete all data following a leak of users’ confidential informationAbror Shuhratov reports: xAI, the company founded by Elon Musk, has announced emergency measures following a serious controversy involving the unauthorized uploading of users’ private code and confidential information to a server via the Grok Build CLI tool. The companyR…DATABREACHES.NET
14 JulSynopsys Finds No Evidence of Data Breach Amid Bosch Hack ClaimsEduard Kovacs reports: A new ransomware group named D1R in recent days listed Synopsys and Bosch on its Tor-based leak website. The cybercriminals claimed to have exploited a vulnerability in Synopsys’ website to access a corporate client database containing 40,000 entries, and t…DATABREACHES.NET
14 JulFinland issues wanted notice for hacker behind massive psychotherapy data breachI was really unpleasantly surprised when they let him out while on appeal, and now they may not be able to return him to prison? Did no one foresee that he might not stick around to be sent back to prison? Daryna Antoniuk reports: Finnish police have reportedly issued a wanted no…DATABREACHES.NET
14 JulRewards For Justice offers reward for info on Media Land, ML.Cloud, and three individuals associated with itRewards for Justice announced a $10M reward for information on the Russian-based bulletproof hosting (BPH) services company Media Land, its associated company ML.Cloud, and associated staff Aleksandr Alexandrovich Volosovik, Kirill Andreevich Zatolokin, and Yuliya Vladimirovna Pa…DATABREACHES.NET
14 JulPatch Tuesday security updates for July 2026, the largest update ever. 621 CVEs in one monthPatch Tuesday: Microsoft fixes a record 621 CVEs, including 2 exploited zero-days and critical flaws affecting SharePoint, RDP, Hyper-V, and AD FS. Microsoft’s July 2026 Patch Tuesday is, by a significant margin, the largest single-month security release in the company̵…SECURITYAFFAIRS.COM
14 JulSN 1087: HalluSquatting, GhostApproval & GitLost - Patch Tuesday Breaks RecordsAI is rewriting the rules of cybersecurity, and this week, massive government and private sector moves show just how quickly the stakes are rising. Find out how regulators, attackers, and defenders are all scrambling to keep up as vulnerabilities surface at record speed. Europe w…TWIT.TV
13 JulShareFile shutdown, double-agent ransomware negotiator sentenced, Helix uses vishingShareFile shutdown order, a double-agent ransomware negotiator sentenced, and vishing crews raid SharePoint Progress Software ordered customers running ShareFile Storage Zone Controllers to shut down the Windows servers immediately amid a credible external threat, offering no CVE…CYBERSECURITYTODAY.LIBSYN.COM
13 Jul99.9% of fixable AI vulnerabilities remain unpatchedOrganizations build, deploy, and operate AI in the cloud, but basic cybersecurity hygiene is often sacrificed for speed, according to Orca Security’s 2026 State of AI Security Report. Building AI without security Fifty-six percent of AI adopters have deployed agent frameworks int…HELPNETSECURITY.COM
13 JulCynative: Open-source deep research agentRunning a large language model against a live cloud account to hunt for security holes comes with an obvious hazard. An agent that holds real credentials and a mandate to poke around can delete a bucket, flip a permission, or leak a secret on its way to a finding. Cynative, an op…HELPNETSECURITY.COM
13 JulCan AI narrow cybersecurity’s class divide?At Amazon Web Services (AWS), artificial intelligence is already compressing security work that once took months into minutes. In the old world, human red teams would find vulnerabilities, write reports, refine those reports, and eventually hand them to defenders, who would then …CSOONLINE.COM
13 JulCopy-paste might be the riskiest thing your enterprise employees do all dayThis source of data leakage takes them less than a second and happens hundreds of times a day.CYBERSECURITYDIVE.COM
13 JulAustralian Cyber Agency Warns of Global CMS Exploitation CampaignAustralian Cyber Security Centre warns CMS users of mass scanning and exploitation campaignINFOSECURITY-MAGAZINE.COM
13 JulAustralia Alerts Organizations to Ongoing CMS Exploitation AttacksAustralia warns of a global campaign exploiting CMS flaws to deploy webshells on WordPress, Joomla, and other websites. Australia’s Signals Directorate has issued an alert about a large-scale exploitation campaign actively targeting content management systems (CMS) worldwid…SECURITYAFFAIRS.COM
13 JulJurassic Park, cybersecurity and the dangerous myth of controlJurassic Park wasn’t really about dinosaurs. It was about arrogant people building systems they believed were controllable. “Life finds a way” is probably the most famous line from the entire franchise. Ian Malcolm’s warning that no matter how sophisticated the technology becomes…CSOONLINE.COM
13 JulYour AI risk register is not an incident response planPicture the moment after an AI issue is reported. A security analyst is reviewing a ticket reporting that an internal AI tool produced the wrong recommendation in a live business workflow. The risk is not theoretical anymore. Someone wants to know whether this is a security incid…CSOONLINE.COM
13 JulHungry? We talk Smoked Meat, Poutine, and Bagel - also, Identiverse Interviews! - ESW #467Interview with François Proulx from Boost Security Software Supply Chain Security: Build Pipeline (CI/CD) Exploitation Boost Security is the creator of some very popular build pipeline security tools, like Bagel and Poutine. Today, we discuss their latest tool, Smoked Meat. They …YOUTUBE.COM
13 JulZimbra Patches Critical Code Execution VulnerabilityThe flaw results in malicious code embedded in crafted emails being executed when the emails are opened. The post Zimbra Patches Critical Code Execution Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
13 JulOrganizations Warned of Exploited Joomla Extension VulnerabilitiesThreat actors have been targeting Balbooa Forms and iCagenda Joomla extension flaws for remote code execution. The post Organizations Warned of Exploited Joomla Extension Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
13 JulIntel agencies warn of Russian state hackers targeting routers worldwideA coalition of 21 cybersecurity and intelligence agencies has warned that Russian state-sponsored hackers continue to compromise internet-facing routers by exploiting weak configurations and known vulnerabilities, enabling them to steal device configurations and gain insight into…CYBERINSIDER.COM
13 JulRabbitMQ Vulnerability Threatens Enterprise SystemsUnauthenticated attackers could obtain the broker's confidential OAuth client secret, allowing them to take control of the broker. The post RabbitMQ Vulnerability Threatens Enterprise Systems appeared first on SecurityWeek .SECURITYWEEK.COM
13 JulTurning the Tables on Email Scammers With 'ScamBuster'An open source, AI-driven system adopts victim personas to engage with phishing attackers, allowing organizations and law enforcement to gather relevant data on cybercriminal operations.DARKREADING.COM
13 JulRansomware negotiator who betrayed clients sentenced to 70 months in prisonA former ransomware negotiator at incident response firm DigitalMint has been sentenced to 70 months in prison after admitting he shared confidential client information with the BlackCat ransomware group and later helped carry out ransomware attacks. Prosecutors say Angelo Martin…HELPNETSECURITY.COM
13 JulEU and UK hit Russia with joint sanctions over cyberattacksBGNES News reports: The European Union and the United Kingdom have imposed coordinated sanctions against Russia in connection with cyberattacks in Europe. Brussels and London have accused the Federal Security Service of the Russian Federation (FSB) of recent malicious activities.…DATABREACHES.NET
13 JulA cyberattack in March resulted in ZEGO filing for insolvencyA statement on ZEGO Textilveredelungszentrum GmbH’s website explains why they are filing for insolvency: Insolvency proceedings have been initiated – and why we are still looking ahead Ladies and gentlemen, dear business partners, Today we are contacting you with a message …DATABREACHES.NET
13 JulProgress urges ShareFile admins to shut down servers over “credible” threatLawrence Abrams reports: Progress Software is emailing ShareFile customers who use Storage Zone Controllers to immediately shut down their servers after identifying what it describes as a “credible external security threat” targeting the on-premises secure file-sharin…DATABREACHES.NET
13 JulWhy cloud security is mission-critical for federal civilian and defense agenciesBeyond IT compliance, cloud security is now the backbone of civilian agency resilience, national defense, and warfighter safety, as cloud environments become increasingly complex. Key takeaways For the Department of War (DoW), cloud security is an IT concern and a requirement for…TENABLE.COM
13 JulGhostcommit attack hides malicious AI instructions in imagesA proof-of-concept attack hides prompt injection in a PNG file, turning routine code reviews into a path for secret theft.MALWAREBYTES.COM
13 Jul13th July – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 13th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES U.S. auto insurer AssuranceAmerica has disclosed a data breach affecting approximately 7 million people. Attackers targeted an employ…RESEARCH.CHECKPOINT.COM
13 JulTidal Cyber connects assets, vulnerabilities, and threats through Threat-Led DefenseTidal Cyber has announced Threat-Led Asset Visibility and Vulnerability Prioritization, new innovations extending the company’s Threat-Led Defense platform. The announcement marks a significant advancement in defensive security, shifting the industry beyond static asset inv…HELPNETSECURITY.COM
13 JulPakistani Police Systems Hit by Chinese and Indian EspionageChinese and Indian spies converged on the same Balochistan police force, SentinelLabs foundINFOSECURITY-MAGAZINE.COM
13 JulCenters Lab NJ discloses data breach incident impacting 542,000 peopleCenters Lab NJ has revealed that a cybersecurity incident disclosed last month affected 542,377 individuals, according to a filing with the US Department of Health and Human Services (HHS) Office for Civil Rights (OCR). The figure, published on the agency's breach portal, provide…CYBERINSIDER.COM
13 JulCloud Security Meets AI: What CISOs Need to Govern Before They Scale - Brent Neal - CSP #226AI is changing cloud security fast, but the biggest challenge is not just adoption. It is governance. In this episode, Jess sits down with Brent Neil, CISO at RapidScale, to talk about what CISOs should be watching as AI becomes embedded in cloud environments, business workflows,…YOUTUBE.COM
13 JulUS authorities warn that state-linked hackers are targeting vulnerable networking devicesHackers linked to Russian intelligence have exploited vulnerabilities in Cisco Smart Install devices.CYBERSECURITYDIVE.COM
13 Jul KEVCISA warns of actively exploited RCE flaws in Joomla extensionsThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that attackers are exploiting vulnerabilities in the iCagenda and Balbooa Forms extensions for Joomla to achieve remote code execution through arbitrary file uploads. [...]BLEEPINGCOMPUTER.COM
13 JulEffective Patch Management Strategies: 7 Best Practices | HuntressStop letting bad actors exploit old bugs. Build a practical patch management strategy to keep them out and learn to stay secure without all the fluff.HUNTRESS.COM
13 JulApple says former employee exploited ‘rare’ bug to download confidential files after leaving for OpenAIApple would not comment on the "security breach," which allegedly allowed a former employee to download sensitive files from Apple's network long after he departed the company for rival OpenAI.TECHCRUNCH.COM
13 JulHackers backdoor Jscrambler npm package with infostealer malwareThe Jscrambler client-side web security company disclosed that a threat actor published a malicious version of its npm package that has been downloaded almost 1,500 times. [...]BLEEPINGCOMPUTER.COM
13 JulNG: Zenith Bank, Others To Be Arraigned Over Alleged Data BreachFatima Abdullahi reports: The Federal High Court in Abuja has fixed July 21, 2026, for the arraignment of Zenith Bank Plc and three other defendants over allegations of illegally accessing and disclosing the confidential financial records of Makers Island Company Limited. The oth…DATABREACHES.NET
13 JulLidl Notified Online Shop Customers in Germany, Belgium, and the Netherlands of a Data BreachLidl disclosed a third-party data breach affecting online shop customers in Germany, Belgium, and the Netherlands. Payment data was not exposed. Lidl contacted customers of its online shop in Germany, Belgium, and the Netherlands last week to inform them that their personal data …SECURITYAFFAIRS.COM
13 JulVPN service favored by ransomware groups is sanctioned by USSuzanne Smalley reports: The U.S. government on Monday sanctioned a VPN provider and its Ukrainian administrator for abetting ransomware gangs behind attacks on American municipalities, hospitals, schools and businesses. First VPN Service (1VPNS) provided ransomware groups with t…DATABREACHES.NET
12 JulWeek in review: Accenture data breach, great open-source cybersecurity toolsHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: Securing the inbox: Where identity, brand and security meet Getting a verified logo to appear next to your email has traditionally meant having to work with two separate entities. Yo…HELPNETSECURITY.COM
12 JulKR: Military targeted in nearly 19,000 cyberattack attempts in 2025: lawmakerChae Yun-hwan reports: Cyberattack attempts against the South Korean military reached nearly 19,000 last year, marking the highest figure in five years, a lawmaker said Sunday. The military was targeted in 18,951 cyberattack attempts in 2025, compared with 11,700 in 2021, 9,115 i…DATABREACHES.NET
11 JulAI Export Controls, FortiBleed, Third-Party Breaches & CISO Burnout | Cybersecurity Today PanelCan governments decide who gets access to advanced AI models? Are third-party breaches becoming impossible to control? And why are so many CISOs reaching burnout? In this special Cybersecurity Today Month in Review Panel, host Jim Love is joined by cybersecurity experts Laura Pay…CYBERSECURITYTODAY.LIBSYN.COM
11 JulCritical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User SessionsZimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in arbitrary code execution. The vulnerability has been described as a case of stored cross-site scripting (XSS) that could allow specially …THEHACKERNEWS.COM
11 JulPatching Isn't Fast Enough AnymoreCritical vulnerabilities can be exploited before organizations have time to deploy patches. This shifts attention toward time to mitigate (TTM)—the speed at which defenders can reduce risk through actions such as isolating systems, closing ports, or increasing monitoring while wa…YOUTUBE.COM
11 JulAustralia warns of global campaign targeting vulnerable CMS platformsThe Australian Cyber Security Centre (ACSC) issued an alert about a global exploitation campaign targeting vulnerable content management systems (CMS) and plugins. [...]BLEEPINGCOMPUTER.COM
11 JulArmenian National Extradited to the United States Pleads Guilty to Ransomware Extortion ConspiracyPORTLAND, Ore.— An Armenian national extradited from Ukraine to the United States pleaded guilty yesterday for his role in Ryuk ransomware attacks and an extortion conspiracy targeting companies throughout the United States, including a technology company operating in Oregon. Kar…DATABREACHES.NET
11 JulRansomware negotiator who conspired with BlackCat threat actors sentenced to 70 months in prisonJon Brodkin reports that a third co-conspirator who helped BlackCat attackers by giving them inside information on victims’ defense strategies has now been sentenced. A former ransomware negotiator was sentenced to 70 months in prison yesterday after colluding with BlackCat…DATABREACHES.NET
11 JulTikTok class action alleges data breach affected 2.4B usersBrandon Richards reports: California resident Sean Mortazi filed a class action lawsuit against TikTok Inc. on June 11, 2026, alleging a data breach exposed the personal data of more than 2.4 billion users worldwide. The complaint, filed in the U.S. District Court for the Central…DATABREACHES.NET
11 JulDutch police trace Odido telco cyberattack to suspected local accomplice; May leak voice recordingDaryna Antoniuk reports: Dutch police said Thursday they had uncovered evidence suggesting that Dutch criminals were involved in the cyberattack on telecom provider Odido that exposed the personal data of more than 6 million customers earlier this year. Authorities said a Dutch-s…DATABREACHES.NET
11 JulHackers Weaponize Balochistan Police Portal in Multi-Group Espionage CampaignsCybersecurity researchers have disclosed details of sustained cyber espionage activity against several Pakistani law enforcement organizations undertaken by suspected China- and India-aligned threat actors between February 2024 and April 2026. "At Balochistan Police, the compromi…THEHACKERNEWS.COM
11 JulCritical U-Boot Bugs Undermine Secure Boot on Millions of DevicesBinarly found six U-Boot flaws, including two that enable code execution during boot image verification, impacting 50+ releases. Binarly’s research team has found six vulnerabilities in U-Boot, the open-source bootloader that runs on home routers, smart cameras, server mana…SECURITYAFFAIRS.COM
10 JulFormer DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jailAngelo Martino exploited his insider position and fed confidential information to ransomware co-conspirators to extort a combined $75.3 million from five U.S.-based victims. The post Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail appeare…CYBERSCOOP.COM
10 JulA questionable breach, bad routers at home and at work and AI gives defenders a winThis episode covers a hacker's claim of stealing 35GB from Accenture—including source code, Azure personal access tokens, RSA keys, and SSH keys—while Accenture calls it an isolated, remediated matter, leaving uncertainty about potential downstream risk to its Fortune 500-heavy c…CYBERSECURITYTODAY.LIBSYN.COM
10 JulOnly 28% of financial workforce MFA is phishing-resistantPasswords remain part of many workforce authentication flows in financial organizations, making phishing and credential theft major identity security risks, according to a new Secret Double Octopus report. Key challenges preventing universal implementation of phishing-resistant M…HELPNETSECURITY.COM
10 JulMicrosoft is rewriting Windows patch guidance because of AIMicrosoft is recommending that organizations shorten Windows update deployment timelines, warning that advances in AI are reducing the time attackers need to identify and exploit vulnerabilities after security updates are released. The company says organizations should reassess h…HELPNETSECURITY.COM
10 JulTurning software supply chain security into a daily habitIn this Help Net Security video, Anastasia Tikhonova, Global Threat Research Lead at Group-IB, explains how to operationalize software supply chain risk. Instead of filing an SBOM away as a compliance document, she argues teams should use it every day for vulnerability triage, ve…HELPNETSECURITY.COM
10 JulCheck Point CTO Jonathan Zanger sees AI elevating the value of cyberCheck Point Software CTO Jonathan Zanger met with CSO Spain during the software company’s Engage 2026 user conference last week in Paris. At the event, Check Point executives and representatives discussed how the company is dealing with various types of threats, how it is adoptin…CSOONLINE.COM
10 JulThe open source library holding up your stack might have one maintainerEvery serious software product runs on code that someone else wrote and released for free. A web service leans on a cryptography library, a data pipeline pulls in a parser, and a mobile app ships a handful of small utilities that one person maintains in spare time. All of it carr…HELPNETSECURITY.COM
10 JulWorkato expands Agent Studio with Headless API, AI guardrailsWorkato has announced two new capabilities for Agent Studio: Headless API and Agent Guardrails. Headless API lets Genies, Workato’s AI agents built on Agent Studio, be embedded into any business application surface, on web, mobile, or inside another agent’s own enviro…HELPNETSECURITY.COM
10 Jul‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery MechanismResearchers demonstrate adversarial hallucination squatting against popular AI assistants to achieve remote code execution. The post ‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism appeared first on SecurityWeek .SECURITYWEEK.COM
10 JulAttackers Exploit 'Ill Bloom' Vulnerability to Drain $3.1 Million From Cryptocurrency WalletsSecurity firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already using it. The flaw is in how some wallet software generated its recovery phrase, the words that control the money. When that phrase is made with weak randomness…THEHACKERNEWS.COM
10 JulAI Surveillance and Social ProgressIn the near future, AI -powered surveillance systems will be able to track everything we do in public, and much of what we do in private. And if we do something wrong—shoplift, litter, jaywalk, you name it—the system will notice, retain it, tie it to your official gov…SCHNEIER.COM
10 JulUnpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 ServersA single wrong variable on one line in XQUIC, Alibaba's QUIC and HTTP/3 library, lets any remote client crash the server with a short burst of completely legal traffic. There is no patch. FoxIO researcher Sébastien Féry disclosed the flaw on July 8 and nicknamed it XRIN…THEHACKERNEWS.COM
10 JulZimbra urges customers to patch critical web client XSS flawThe Zimbra security team urged customers to patch a critical vulnerability affecting the Classic Web Client used to access the Zimbra Collaboration suite. [...]BLEEPINGCOMPUTER.COM
10 JulChina, India-Linked Hackers Both Targeted Same Pakistani Police ForceBoth foes and allies have targeted the Balochistan Police force in Pakistan for at least two years, according to SentinelOne. The post China, India-Linked Hackers Both Targeted Same Pakistani Police Force appeared first on SecurityWeek .SECURITYWEEK.COM
10 JulNew Ransomware Exploits Malicious Driver to Remove Cybersecurity ProtectionsGodDamn ransomware uses remote desktop application to secretly move around networks and drop the malicious PoisonX kernel driverINFOSECURITY-MAGAZINE.COM
10 JulIncode brings on-device processing to age estimation for privacy-focused verificationIncode has launched On-Device Age Estimation, an age verification capability that performs age estimation and liveness detection directly on the user’s device, without transmitting facial data off the device. The company’s age estimation models are now available to ru…HELPNETSECURITY.COM
10 JulChina, India ran separate spying campaigns against same Pakistani police forceThe activity, in some cases breaching the exact same systems, ran between February 2024 and April 2026 and centered on the force responsible for the country’s southwestern province that has been the site of a long-running separatist insurgency.THERECORD.MEDIA
10 JulAnthropic and OpenAI Security Tools Could Fuel Cyber-Attacks, Researchers WarnResearchers at the AI Now Institute developed a proof-of-concept exploit showing common AI tools used for security could backfireINFOSECURITY-MAGAZINE.COM
10 JulResearcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw FlawsDetails have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege escalation, and arbitrary code execution on the host. A brief description of the h…THEHACKERNEWS.COM
10 JulEU extends mass scanning of messages without a warrantMembers of the European Parliament (MEPs) have failed to block a proposal extending the mass scanning of private communications, a measure they have previously rejected twice. This time too, more votes were cast against the proposal than in favor, but due to the absence of numero…CSOONLINE.COM
10 JulCrowdStrike identifies five new prompt injection threats to AISecurity company CrowdStrike has identified five new prompt injection techniques that could leave enterprises at risk. Prompt injections attacks exploit the growing use of AI within organizations . They work by tricking LLMs into accepting instructions that a human operator would…CSOONLINE.COM
10 Jul KEVThe 72-Hour Vulnerability DeadlineThe EU Cyber Resilience Act introduces strict reporting requirements for vulnerabilities, including a 72-hour reporting window after becoming aware of an actively exploited vulnerability. Organizations must rapidly assess both technical evidence and regulatory obligations. Distin…YOUTUBE.COM
10 JulHackers exploit critical auth bypass in Gitea Docker imageHackers are actively exploiting a critical vulnerability in the official Docker image for the Gitea self-hosted Git service that allows attackers to impersonate any user, including administrators. [...]BLEEPINGCOMPUTER.COM
10 JulAWS designated as a critical third party to the UK financial sectorAmazon Web Services EMEA Sarl (AWS) has been designated as a critical third party (CTP) to the UK financial sector by HM Treasury. The CTP regime came into force on January 1, 2025, and establishes a framework through which the Bank of England, PRA, and FCA (collectively the UK r…AWS.AMAZON.COM
10 JulInitial access broker linked to weaponization of CitrixBleed2 flawA similar pattern of exploitation was seen in prior attacks involving an open-source machine emulator. CYBERSECURITYDIVE.COM
10 JulGoshDarn it, that’s advanced.Researchers track ransomware they say is getting GoshDarn sophisticated. Zimbra patches a critical vulnerability affecting its Classic Web Client. A sophisticated vishing campaign targeting Microsoft 365 accounts. GigaWiper combines espionage capabilities with multiple destructiv…THECYBERWIRE.COM
10 JulFriday Squid Blogging: “Squidbleed” VulnerabilityIn a rare combined cybersecurity/squid post, a twenty-nine-year-old squid proxy bug can leak HTTP requests. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.SCHNEIER.COM
10 JulUpdate Now: Critical Zimbra Classic Web Client Flaw Could Expose MailboxesZimbra addressed a critical stored XSS vulnerability in its Classic Web Client that lets malicious emails execute code when opened. Zimbra has released version 10.1.19 to fix a critical stored XSS vulnerability in its Classic Web Client, which is widely used to access Zimbra Coll…SECURITYAFFAIRS.COM
9 JulNayax investigating breach; The Syndicate claims it acquired 1 billion card records and other important dataNayax is a global fintech company headquartered in Israel that provides cashless payment and management solutions for unattended retail and self-service machines. The firm is publicly traded on both the Tel Aviv and Nasdaq stock exchanges. This month, Nayax submitted a Form 6-K t…DATABREACHES.NET
9 JulFake 7-Zip Installers Turn Devices Into Residential Proxy NodesCybersecurity researchers have disclosed details of a new threat actor dubbed Lurking Lizard that has been operating an end-to-end malicious residential proxy business using an infrastructure comprising more than 230 lookalike domains. The activity dates back to at least August 2…THEHACKERNEWS.COM
9 JulWood you fall for this?This week, hosts of N2K CyberWire ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Maria Varmazis⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠…THECYBERWIRE.COM
9 JulTop AI Agents Built to Catch Malicious Code Can Be Tricked Into Running ItAsk an AI coding agent to scan open-source code for security holes, and it might run the attacker's code on your own machine instead. That is the finding in a proof-of-concept published Wednesday by the AI Now Institute, an attack it calls "Friendly Fire." It works agai…THEHACKERNEWS.COM
9 JulMicrosoft patches RoguePlanet Defender zero-day vulnerabilityMicrosoft has released a security patch to address a Defender zero-day vulnerability known as "RoguePlanet," disclosed after the June 2026 Patch Tuesday. [...]BLEEPINGCOMPUTER.COM
9 JulOpen-source collaboration is growing worldwide and putting pressure on maintainersDevelopers are pushing code and opening pull requests across economy borders at a rate GitHub has rarely seen. Outbound collaboration, the sum of git pushes and pull requests sent from developers in one economy to public repositories in another, grew by 16% from Q4 2025 to Q1 202…HELPNETSECURITY.COM
9 JulLateral movement risk rises as enterprises emphasize convenience over containmentPoorly segmented networks and weak security controls continue to undercut security organizations’ ability to identify and contain attacks, giving attackers free rein after initial compromise, according to a recent study based on real-world enterprise security telemetry. Zero Netw…CSOONLINE.COM
9 JulCybercriminals Plant Malicious AI Agents in Open Source Tool RepositoriesCybersecurity researchers at ESET identify big rise in suspicious and malicious toolsets which put users at risk from cyber-attacksINFOSECURITY-MAGAZINE.COM
9 JulAssuranceAmerica data breach exposes records of 6.9 million driversAmerican insurance company AssuranceAmerica has disclosed a data breach impacting nearly 7 million drivers after attackers gained access to its systems earlier this year. [...]BLEEPINGCOMPUTER.COM
9 JulChrome 150 Update Patches 27 VulnerabilitiesThe security refresh resolves 13 use-after-free bugs, including two critical-severity flaws found by Google. The post Chrome 150 Update Patches 27 Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulAI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old TechniqueWiz has disclosed the details of a new AI coding assistant attack method it has dubbed GhostApproval. The post AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulAgentic AI identity: A 6-stage maturity model for non-human identitiesIn a client engagement last year, an LLM-based deployment agent with standing access to a production Kubernetes cluster triggered a four-hour outage through a malformed configuration push. In the IAM, the agent appeared as a service account with a long-lived API key, no MFA, no s…CSOONLINE.COM
9 JulWhy fixing your data architecture matters more than upgrading your detection modelsSecurity leaders have been on a spending sprint. The global AI in cybersecurity market is valued at $44 billion in 2026 and is projected to reach $213 billion by 2034 , a trajectory that reflects genuine belief that machine learning will close the gap between the volume of threat…CSOONLINE.COM
9 JulPolice arrests 5,800 suspects in global anti-fraud crackdownLaw enforcement agencies have arrested 5,811 suspects and seized $293 million in illicit assets in a global anti-fraud operation spanning 97 countries. [...]BLEEPINGCOMPUTER.COM
9 JulAssuranceAmerica data breach exposed driver’s licenses of 7 million peopleAssuranceAmerica is notifying nearly 7 million people that hackers stole sensitive customer information, including driver's license numbers, following a cyberattack discovered in March. The incident affected 6.99 million individuals, making it the largest known exposure of Americ…CYBERINSIDER.COM
9 JulSecure self-hosted team chat platform Chatto goes open sourceGerman developer Hendrik Mans has released the source code for Chatto, a privacy-focused team messaging platform, making the project open source and available for anyone to self-host. The milestone fulfills a promise made when the project was first unveiled in late 2025 and opens…CYBERINSIDER.COM
9 Jul15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From GoogleAffecting every major distribution since 2011, the Linux kernel vulnerability allows attackers to gain root access. The post 15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google appeared first on SecurityWeek .SECURITYWEEK.COM
9 Jul5,811 arrests, $293 million seized over social engineering scamsCriminals who pose as police officers, romantic partners, and business suppliers have built fraud operations that reach across continents. A four-month enforcement campaign against these schemes wrapped up, and police in 97 countries and territories took part. Thousands of arrest…HELPNETSECURITY.COM
9 JulTwo arrests this week in unrelated crimes involved Japanese teenagers using ChatGPT to assist in their crimesThe Japan Times reports: An 18-year-old man has been arrested for his suspected involvement in a cyberattack on the operator of the Kaikatsu Club internet cafe chain, according to investigative sources. On Wednesday, the Metropolitan Police Department’s cybercrime countermeasure …DATABREACHES.NET
9 JulAttack on Amazon Bedrock-linked AI gateway highlights new cloud security riskA cloud intrusion that ended with the deployment of cryptomining malware has exposed a bigger risk for enterprises: AI gateways that concentrate access to cloud identities, permissions, and foundation models in a single, highly privileged system. Researchers from cybersecurity fi…CSOONLINE.COM
9 JulUK cyber agency unveils AI-powered Cyber Shield to counter attacks at machine speedThe UK’s National Cyber Security Centre (NCSC) wants to deploy autonomous AI agents capable of finding and neutralizing cyberattacks on national networks in real time, marking Britain’s push toward a sovereign, machine-speed cyber defense system. The blueprint, called Cyber Shiel…CSOONLINE.COM
9 JulOne Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law EnforcementChina and India ran separate espionage operations against the same Pakistani police force, each drawn by different stakes in Pakistan's internal security.SENTINELONE.COM
9 JulMicrosoft fixes RoguePlanet zero-day in DefenderThe RoguePlanet zero-day is now fixed in Microsoft Defender. Here's how to make sure your system is protected.MALWAREBYTES.COM
9 Jul12 Million Impacted by Data Breach at Japanese Telco KDDIHackers exploited a zero-day vulnerability in a third-party system to access a KDDI email system for ISPs. The post 12 Million Impacted by Data Breach at Japanese Telco KDDI appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulPalo Alto Networks Patches 13 VulnerabilitiesBuffer overflow, DoS, command injection, SSRF, authentication bypass, and other types of vulnerabilities have been found in PAN-OS software. The post Palo Alto Networks Patches 13 Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
9 Jul764 splinter group leader sentenced to 40 years in jailAlexis Chavez coerced multiple girls to commit self harm and produce child sexual abuse material for notoriety in a sprawling violent extremist collective affiliated with the Com. The post 764 splinter group leader sentenced to 40 years in jail appeared first on CyberScoop .CYBERSCOOP.COM
9 JulThe Intercept’s Signal tipline username was hijacked for monthsThe Intercept has warned that its official Signal tipline username was compromised and used by an impersonator to pose as the investigative news outlet, potentially exposing confidential sources who attempted to submit sensitive information. Dr. Martin Shelton, of the Freedom of …CYBERINSIDER.COM
9 JulGhostApproval flaw exploits trust in major AI coding assistants.Interpol operation cracks down on social engineering scams. Chinese APT exploits Roundcube flaws to target US and Canadian universities.THECYBERWIRE.COM
9 JulThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More StoriesMost security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it. This week is full of that kind of damage. Not loud. Not clever. Just small gaps doing big jobs. The worst par…THEHACKERNEWS.COM
9 JulWiz in the Verizon DBIR: How AI Acceleration and Cloud Sprawl Impact Modern DefenseVerizon's latest DBIR highlights how attackers are exploiting familiar weaknesses at increasing speed and scale. Here's what Wiz research reveals about vulnerabilities, trust relationships, and AI in modern cloud environments.WIZ.IO
9 JulWho you gonna call?GhostApproval puts AI coding assistants under the microscope. Microsoft fixes the RoguePlanet zero-day. More than 70 cybersecurity firms back a new AI Charter. An Ohio county may have paid a $1 million ransom. AssuranceAmerica discloses a breach affecting nearly seven million peo…THECYBERWIRE.COM
9 JulIran's Cyber Crosshairs Focus Beyond Critical InfrastructureObscurity isn't a defense. If your company has any Internet-facing vulnerability, you're at risk from multiple threats.DARKREADING.COM
9 JulMicrosoft Reins in RoguePlanet Zero-Day ThreatThe researcher known as "Nightmare-Eclipse" published a proof-of-concept (PoC) exploit for the Windows Defender vulnerability in early June after dropping several other Microsoft zero-days.DARKREADING.COM
9 JulWolfSSL, GeoVision, VTK vulnerabilitiesCisco Talos’ Vulnerability Discovery & Research team recently disclosed three vulnerabilities in WolfSSF, fourteen in GeoVision, and one vulnerability in VTK-DICOM. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adhere…TALOSINTELLIGENCE.COM
9 JulAI coding tool hole illustrates a big problem with human in the loopA security hole within AI dev tools has allowed attackers to escape sandboxes by misleading the humans in the loop who were supposed to knowingly approve the tool’s actions, according to cybersecurity research firm Wiz. “We discovered GhostApproval, a systematic vulnerability pat…CSOONLINE.COM
9 JulWhen Your Smart Vacuum DiesMany smart home devices depend on cloud services to function. When manufacturers discontinue products or shut down those services, expensive hardware can lose key features—or stop working entirely. Open-source alternatives offer a different model. By running locally and avoiding …YOUTUBE.COM
9 JulINTERPOL Operation First Light Nets 5,811 Arrests and Seizes $293 MillionINTERPOL’s Operation First Light 2026 led to 5,811 arrests, blocked $293M in criminal assets, and disrupted global fraud and money laundering networks. INTERPOL coordinated a four-month operation across 97 countries and territories that ended with 5,811 arrests and the inte…SECURITYAFFAIRS.COM
8 Jul20 open-source cybersecurity tools to keep your team ready for anythingAI is changing how security teams find vulnerabilities, analyze code, test applications, and protect infrastructure. Developers are building tools to secure AI systems themselves, from coding agents and memory protection to model exposure discovery. This roundup covers recent ope…HELPNETSECURITY.COM
8 JulRisky Bulletin: DHS IG investigates forced CISA reassignmentsThe DHS inspector general will investigate forced CISA reassignments, Canada hacked a ransomware gang, Taiwan charges two executives with helping Chinese hackers, and new vulnerabilities can disable Hoymiles solar panels.RISKY.BIZ
8 Jul13 in-demand IT security certifications for higher payWith change a constant, cybersecurity professionals looking to improve their careers can benefit from the latest insights into employers’ needs. Data from Foote Partners on the skills and certification most in demand today may provide helpful signposts. Analyzing more than 660 ce…CSOONLINE.COM
8 Jul KEVCISA orders feds to patch max severity ColdFusion flaw by FridayThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered government agencies to patch an actively exploited maximum-severity flaw in the Adobe ColdFusion commercial web app development platform by Friday. [...]BLEEPINGCOMPUTER.COM
8 JulMy threat feed told me it was ‘Chalubo.’ The binary disagreedI’ve spent two years doing incident response and threat intel, and the one habit I’d keep if I had to give up every other is also the most boring. I don’t act on a piece of intelligence until I’ve checked it against the thing it claims to describe. It’s slow. It’s tedious. Almost…CSOONLINE.COM
8 JulWhy AI Just Broke Traditional IT Security as Leaders Clash Over AI's Value and Hiring - BSW #455The latest generation of AI models has collapsed the time from vulnerability discovery to weaponized exploit from weeks to minutes, and reactive, module-based tools built around static dashboards simply can't keep up. In this episode, Tanium COO Matt Quinn joins Business Security…YOUTUBE.COM
8 JulFound fast, fixed slow: The gap the AI clearinghouse must closeThe government's new AI clearinghouse risks becoming a committee that discovers more problems than it solves — unless it's designed around patching, not just scanning. The post Found fast, fixed slow: The gap the AI clearinghouse must close appeared first on CyberScoop .CYBERSCOOP.COM
8 JulUbiquiti warns of new max severity UniFi OS vulnerabilityUbiquiti has released security updates to patch seven critical vulnerabilities in UniFi OS, including a maximum-severity flaw that can be exploited in command injection attacks. [...]BLEEPINGCOMPUTER.COM
8 JulCISA Deploys Anthropic’s Mythos AI to Hunt Vulnerabilities in U.S. Government CodeCISA is using Anthropic’s Mythos AI to scan federal code for vulnerabilities, aiming to find flaws before hackers and foreign intelligence services. Three sources familiar with the matter told Reuters that CISA, the U.S. government’s civilian cyber defense agency, is …SECURITYAFFAIRS.COM
8 Jul KEVCISA orders feds to prioritize patching Langflow auth bypass flawThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) gave federal agencies until Friday to patch an actively exploited vulnerability in the Langflow visual framework for building AI agents. [...]BLEEPINGCOMPUTER.COM
8 JulCrusoe brings serverless fine-tuning to AI model developmentCrusoe has announced Serverless Fine-Tuning and Self-Serve Deployments in Crusoe Intelligence Foundry, the managed AI platform for Crusoe Cloud. These capabilities give data scientists and ML engineers a complete path from proprietary data to production-ready models, on purpose-b…HELPNETSECURITY.COM
8 JulNew Bit2Watt attack uses AI GPU workloads to destabilize power gridsA new cyber-physical attack called Bit2Watt uses carefully crafted GPU workloads to manipulate a data center's power consumption in ways that interfere with modern electricity infrastructure. While the work is primarily a proof-of-concept supported by simulations and laboratory e…CYBERINSIDER.COM
8 JulCritical Vulnerability Exposes GitHub Agentic Workflows to Prompt InjectionResearchers show how attackers can use a crafted public GitHub Issue to trick AI-powered workflows into exposing data from private repositories without authentication. The post Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection appeared first on SecurityW…SECURITYWEEK.COM
8 JulCybercriminals exploit India’s tax filing season with a dual-malware campaignCybercriminals are exploiting India’s tax filing season with a new malware campaign that refuses to put all its eggs in one basket. Researchers at Cyderes have uncovered a sophisticated phishing operation that poses as the Indian Tax Department to deliver two remote access trojan…CSOONLINE.COM
8 JulMutation testing comes to DAMLIn April we released Mewt , our open-source mutation-testing engine that finds the gaps in your test suite. Today we’re expanding it with support for DAML, the language Canton Network applications are written in. Mewt now reads DAML, generates several classes of mutants (includin…TRAILOFBITS.COM
8 JulAccenture acknowledges security incident following 35GB data theft claimAccenture appears to have suffered a data breach, the extent of which is currently unknown. On Monday, a threat actor going by the handle “888” posted on the cybercrime forum PwnForums, claiming to have breached the technology consulting company and stolen “just…HELPNETSECURITY.COM
8 JulFelons, Fraudsters Flog Offensive Cybersecurity StartupA cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based…KREBSONSECURITY.COM
8 JulGitHub AI agent leaks private repositories via prompt injection attackA prompt injection attack can trick GitHub’s preview Agentic Workflows into retrieving content from private repositories and publishing it publicly, exposing a broader risk as enterprises deploy AI agents with privileged access to software development environments, according to n…CSOONLINE.COM
8 JulGoogle Dialogflow CX Bug Allowed Attackers to Hijack AI ConversationsThe "Rogue Agent" vulnerability could have enabled attackers to silently manipulate AI conversations, exfiltrate data, and compromise every Dialogflow CX agent within the same Google Cloud project. The post Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations app…SECURITYWEEK.COM
8 Jul"Good Enough" Patching Is OverFor years, many organizations relied on fixed patching schedules, accepting 60-day, 90-day, or even annual update cycles as "good enough." That assumption is becoming harder to defend. As AI speeds up vulnerability discovery and attackers move faster, security teams face increasi…YOUTUBE.COM
8 JulSecurity Teams Are Ready To Become More Preemptive. What’s Holding Them Back?The shift toward preemptive security is underway, but most organizations are still navigating the realities of limited resources, fragmented tools, and emerging AI risk. At Rapid7’s recent Global Security Summit , we surveyed attendees to better understand where security leaders …RAPID7.COM
8 JulAccenture faces massive data breach that could put clients at riskThe threat actor claiming responsibility says they stole source code, encryption keys and more.CYBERSECURITYDIVE.COM
8 JulPatients Sue Healthcare Corporations Over Data Breaches, Sharing of Personal InformationMikeie Honda Reiland reports: A suite of recent class action lawsuits in state and federal courts seeks to hold large healthcare corporations accountable for exposing or leaking patients’ personally identifiable information (PII) and protected health information (PHI). On June 11…DATABREACHES.NET
8 JulWhy Bangladesh’s new data protection law may fail to protect your dataMeem Arafat Manab reports: On August 19, 2025, hackers broke into Shwapno’s customer database. They took 410 gigabytes of data: the names, phone numbers, and purchase histories of forty lakh registered customers. They demanded $1.5 million. Shwapno refused, secured its systems, a…DATABREACHES.NET
8 JulAttackers Won't Wait for Patch TuesdayOrganizations continue to be compromised through vulnerabilities that have been known and exploited for years. At the same time, the time between vulnerability disclosure and active exploitation continues to shrink. Traditional patching cycles and lengthy change approval processe…YOUTUBE.COM
8 JulAccenture Confirms Data Breach After Hacker Claims Source Code TheftThe professional services giant says it contained the incident, remediated its source, and experienced no operational or service delivery impact. The post Accenture Confirms Data Breach After Hacker Claims Source Code Theft appeared first on SecurityWeek .SECURITYWEEK.COM
8 JulHackers exploit Roundcube flaw to spy on academic researchersA China-linked threat cluster has been exploiting vulnerable Roundcube servers at U.S. and Canadian universities to steal credentials and deploy backdoor malware. [...]BLEEPINGCOMPUTER.COM
8 JulUniondale Union Free School District – Audit Follow-Up by New York State Comptroller (2023M-61-F)In October 2023, NYS Comptroller Thomas DiNapoli released an IT audit of the Uniondale Union Free School District on Long Island. The purpose of the audit was to examine management of non-student user network controls. The audit report found, in part: District officials did not a…DATABREACHES.NET
8 JulA Hacker Claims 35 GB of Accenture Source Code. The Company discloses the data breachAccenture confirmed a breach after a hacker claimed to steal 35 GB of source code, keys, and Azure credentials now offered for sale. A threat actor using the handle “888” claimed on the cybercrime forum PwnForums this week to have stolen 35 gigabytes of data from Acce…SECURITYAFFAIRS.COM
8 JulAzure you concerned?Accenture confirms a data breach. An Australian telecom investigates a nationwide outage. It’s shields up for the UK. CISA eyes September for its critical infrastructure reporting rule. NewsJunkie fakes CTV ad traffic. Agentic AI triggers EDR. CISA taps Mythos for vulnerability s…THECYBERWIRE.COM
8 JulLone Attacker Uses AI to Breach AWS Cloud Environment in 72 HoursThe attacker exploited AI workflows, chained cloud weaknesses, and stolen credentials to extort a large Amazon customer.DARKREADING.COM
8 JulGitHub’s public APIs are becoming an enterprise reconnaissance toolGitHub continues to be a scintillating target for attackers because it sits in the middle of the software supply chain and gives threat actors three things they crave: source code, secrets, and automated pipelines to run amok in. Datadog Security Research has been tracking what i…CSOONLINE.COM
7 JulZscaler finds autonomous agents succumb to IPI trapsIn a test of major LLMs, Zscaler found that some autonomous AI agents fell victim to frauds, reinforcing how easily some high-end enterprise agents can be conned by schemes that would fool few, if any, humans. The security vendor looked at various forms of indirect prompt injecti…CSOONLINE.COM
7 JulCybersecurity jobs available right now: July 7, 2026Application Security Lead Gett | Israel | Hybrid – View job details As an Application Security Lead, you will lead application and cloud security initiatives by integrating security into the SDLC, overseeing threat modeling, secure architecture, application securi…HELPNETSECURITY.COM
7 JulApple Container: Open-source tool for Linux containers on the MacDevelopers on Apple silicon Macs have run Linux containers through software built around a single shared virtual machine for years. Apple’s open-source Container project gives each Linux workload its own lightweight virtual machine. Container is written in Swift and tuned f…HELPNETSECURITY.COM
7 JulMicrosoft wants to keep your AI agents from going rogueMicrosoft has introduced Microsoft Execution Containers (MXC), a cross-platform, policy-driven execution layer for AI agents on Windows and Windows Subsystem for Linux (WSL), now available in early preview. Updated Agent 365 platform (Source: Microsoft) Developers can define cons…HELPNETSECURITY.COM
7 JulPower shortages could slow AI data center expansionAI adoption is increasing demand for data center capacity at the same time operators are running into limits around power, equipment, land, and permitting, according to NTT Data. Access to electricity is becoming a deciding factor in where new data centers are built, when new cap…HELPNETSECURITY.COM
7 Jul176: NSLOne day Nick got a visit from the FBI demanding he give them data on one of his customers. They asked for it in the form of a National Security Letter or NSL. Something wasn’t right about this letter. It seemed to violate the constitution. So he set out to change the law. Learn m…DARKNETDIARIES.COM
7 JulJanuscape: 16-Year-Old Linux KVM Bug Enables Cloud VM Escape AttacksJanuscape: A 16-year-old Linux KVM flaw lets cloud VM tenants crash hosts and potentially escape guests. It affects Intel and AMD systems. Security researcher Hyunwoo Kim has published details of a use-after-free vulnerability in Linux’s KVM hypervisor that allows code runn…SECURITYAFFAIRS.COM
7 JulSuspected Chinese espionage group used a Roundcube exploit chain to burrow into universitiesProofpoint researchers said attackers targeted physics and engineering departments, and warn that the campaign is likely ongoing. The post Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities appeared first on CyberScoop .CYBERSCOOP.COM
7 JulHackers Exploit Maximum Severity Adobe ColdFusion FlawThreat actors are exploiting an Adobe ColdFusion vulnerability which has a CVSS score of 10.0INFOSECURITY-MAGAZINE.COM
7 JulWhy The Gentlemen ransomware is a test of identity and recovery controlsThe Gentlemen ransomware underscores a challenge many CISOs face: stopping attackers after they gain an initial foothold. Researchers say the malware can spread across enterprise networks using legitimate Windows management tools while simultaneously attempting to weaken security…CSOONLINE.COM
7 JulThe modern CISO is becoming the next CFOAt some point, every security leader gets asked a version of the same question: Are we good? It tends to arrive when something is at stake and the person asking needs to know they can rely on the answer. I learned what that question really means at a firm I was with earlier in my…CSOONLINE.COM
7 JulDefense-in-depth strategies for securing mobile applications - Ryan Lloyd - ASW #390Mobile applications have unique risks and threat models compared to server-side applications and infrastructure. Consequently, they need different strategies to ensure their business logic and workflows well secured. We'll dive into some of these defense-in-depth strategies and w…YOUTUBE.COM
7 JulThreat landscape for industrial automation systems. Q1 2026This report contains industrial threat statistics for Q1 2026, including industrial threat distribution by type, source, region and industry.SECURELIST.COM
7 JulLinux Kernel Vulnerability Allows VM Escape on Intel and AMD SystemsThe 16-year-old Januscape flaw affects Linux's KVM hypervisor, allowing attackers to escape virtual machines and potentially execute code on the underlying host. The post Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems appeared first on SecurityWeek .SECURITYWEEK.COM
7 JulWhat Changes When Your Software Supply Chain Includes AI Writing Your Code?Software supply chain security was hard enough. Then AI joined the build pipeline. For five years, "software supply chain security" meant one question: what's in your code? Which open-source packages, which versions, which transitive dependencies three layers deep that nobody cho…THEHACKERNEWS.COM
7 JulNew Januscape Linux flaw allows VM escape on Intel, AMD devicesA 16-year-old Linux kernel vulnerability, dubbed Januscape, allows attackers to escape a virtual machine and execute arbitrary code on the host. [...]BLEEPINGCOMPUTER.COM
7 JulCommvault measures cyber recovery readiness with AI attack simulationsCommvault has announced Commvault Minutes to Recovery, a scenario-driven cyber resilience simulation that lets participants act as a hacker and run their own attacks using frontier AI tools. Then, participants are challenged to defend against and recover from an incident under pr…HELPNETSECURITY.COM
7 JulCourt Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider HackerU.S. prosecutors linked an alleged Scattered Spider hacker to a break-in at a luxury jewelry retailer using a persistent Windows device ID, according to a newly unsealed federal complaint. Microsoft records tied that ID first to the account the attackers used to keep access durin…THEHACKERNEWS.COM
7 JulWriter AI Flaw Could Let Agent Previews Leak Session Tokens Across TenantsCybersecurity researchers have disclosed details of a now-patched critical session isolation vulnerability in Writer, an enterprise generative artificial intelligence (AI) platform, that could result in cross-tenant compromise. The one-click vulnerability has been codenamed Write…THEHACKERNEWS.COM
7 JulBojangles sued again by workers over Russian hacker data breach. NC judge weighs inChase Jordan reports an update in the litigation stemming from a 2024 breach by Hunters International. This case has raised a number of issues about standing and negligence and has been up and down in the courts, with plaintiffs seeming to fare better in state court: A class-acti…DATABREACHES.NET
7 JulJacksonville, Texas, keeps some city systems offline after cyber incidentDysruptionHub reports: Jacksonville, Texas, took some city systems offline after detecting suspicious network activity Friday, leaving some online services unavailable Monday as officials investigated a cybersecurity incident. The city said it detected the activity July 3 and lat…DATABREACHES.NET
7 JulCERT/CC warns of an unpatched backdoor affecting Tenda routers.Maximum-severity ColdFusion flaw is under active exploitation. Canadian intelligence agencies hacked criminal groups.THECYBERWIRE.COM
7 JulSuspected Chinese Threat Group Targets Universities via Vulnerable Roundcube ServersA suspected Chinese threat cluster is exploiting Roundcube vulnerabilities to compromise university networks in the US and Canada and harvest user credentialsINFOSECURITY-MAGAZINE.COM
7 JulSophisticated threat campaign pushes Cisco to the very edgeA monthslong exploitation wave against Cisco SD-WAN systems raises larger questions about trust and the insecurity of network infrastructure.CYBERSECURITYDIVE.COM
7 JulOMB M-26-14: Why federal agencies must fix asset visibility firstThe new OMB logging directive raises the bar on log collection and explicitly ties every maturity milestone to how well agencies know what’s on their networks. Learn why asset visibility is the first problem to solve. Key takeaways M-26-14 rescinds M-21-31 and replaces blanket da…TENABLE.COM
7 JulEnforce zero data retention on Amazon Bedrock with Bedrock Projects and service control policiesWith the introduction of models that require data sharing with third-party providers—such as Claude Fable 5—organizations need a way to centrally enforce data retention policies. Amazon Bedrock gives you control over whether your prompts and model outputs are retained after an in…AWS.AMAZON.COM
7 JulChinese hackers develop LONGLEASH malware to expand ORB networkChinese hackers tracked as 'UAT-7810' are actively evolving their malware to expand their Operational Relay Box (ORB) network by compromising internet-facing networking devices, primarily unpatched Ruckus routers. [...]BLEEPINGCOMPUTER.COM
7 JulWhy Streaming Apps Protect ContentFor streaming platforms, the most security-sensitive asset is often the content itself. Licensing agreements require providers to protect movies, shows, and live events from unauthorized distribution. Technologies like DRM and digital watermarking help enforce those protections a…YOUTUBE.COM
7 Jul KEVWelcome home, hacker.CERT/CC warns of an unpatched Tenda router backdoor. Adobe races to patch an actively exploited ColdFusion flaw. Canada pulls back the curtain on offensive cyber operations. Anthropic quietly removes hidden tracking from Claude Code. Chinese AI gains momentum as U.S. providers sw…THECYBERWIRE.COM
7 JulAccenture confirms breach after hacker offers stolen data for saleIT services giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and other data from the company. [...]BLEEPINGCOMPUTER.COM
7 JulWashington Dept. of Social and Health Services announces massive data breachKIRO7 reports: The Washington Department of Social and Health Services (DSHS) is issuing a notice of a massive data breach that happened in March, potentially compromising the personal data of around 8,600 people. An internal investigation revealed that a former DSHS employee acc…DATABREACHES.NET
7 JulSN 1086: The Apex Agentic Adversary - Visual Prompt Injection StrikesFrom the sudden retirement of Internet pioneer Vint Cerf to the unstoppable advance of "apex agentic adversaries," get a front-row seat to the unfolding security revolution and its massive real-world stakes. Why Fable5's re-release has disappointed. Opera becomes the first browse…TWIT.TV
6 JulThe future of payment fraud could be automatedPayment fraud is becoming more organized as criminal groups use fake websites, large-scale operations, and, in some cases, forced labor to steal money and personal information. Advances in agentic AI could automate many stages of payment fraud, from collecting and assembling stol…HELPNETSECURITY.COM
6 JulFlipper Zero firmware development gets a fresh set of community rulesOwners of the Flipper Zero, the pocket-sized wireless testing tool, spent recent weeks worried that its official firmware had gone quiet. Pavel Zhovner, CEO of Flipper Devices, moved to settle that concern with word that the company has set aside staff to keep the firmware mainta…HELPNETSECURITY.COM
6 JulRisky Bulletin: EU official’s phone infected with PegasusA European MP’s phone was infected by Pegasus spyware, Android drops its PIN guessing limit from 1,800 attempts to 20, Alibaba bans employees from using Claude at work, and there’s a new vulnerability in the Linux kernel.RISKY.BIZ
6 JulSecuring the inbox: Where identity, brand and security meetGetting a verified logo to appear next to your email has traditionally meant having to work with two separate entities. You have to work with a DMARC partner for setting up DMARC and BIMI, then use a trusted Certificate Authority (CA) to purchase a Mark Certificate, and this mean…HELPNETSECURITY.COM
6 JulOmnigent: Open-source AI agent framework and meta-harnessPlenty of developers now keep several coding agents close at hand, reaching for Claude Code on one task and Codex or Cursor on the next. Each tool arrives with its own command line, its own handling of credentials, and its own way of running shell commands against a working direc…HELPNETSECURITY.COM
6 Jul7 cyber risk assessment gotchas to avoidA cyber risk assessment helps security teams identify, estimate, and prioritize potential threats and vulnerabilities to key enterprise digital and physical assets. Yet, despite its importance, many CISOs fall victim to several types of “gotchas” that prevent them from fully achi…CSOONLINE.COM
6 JulAI isn’t closing the skills gap — it’s exposing the validation gapIf you wanted to become a basketball star, how would you get started? You wouldn’t read a book on basketball and take an online course. You’d set up a hoop in your driveway, join a local team to train, and play in real matches. So why do we expect cybersecurity professionals to l…CSOONLINE.COM
6 JulFinding vulnerabilities was never the hard partAI is surfacing vulnerabilities at a scale the industry has never seen, and most organizations have no way to determine which ones actually matter. The post Finding vulnerabilities was never the hard part appeared first on CyberScoop .CYBERSCOOP.COM
6 JulNCA Issues Warning to Parents As Shared Child Photos Exploited by AI ToolsIWF and NCA warn that growing numbers of images and videos are being manipulated into sexual abuse materialINFOSECURITY-MAGAZINE.COM
6 JulSingle points of failure fail. The SaaS layer is not an exceptionHigher education has consolidated its entire academic operation into a handful of massive SaaS platforms. The LMS manages instruction, grading and communication. The SIS owns enrollment, records and financial aid. Identity and productivity live in a small number of cloud provider…CSOONLINE.COM
6 JulMastering agent permissions and Identiverse interviews - ESW #466Interview with Sandy Bird, co-founder of Sonrai Security In this week's interview, we kick off the conversation with how Sonrai's expertise in securing cloud identity permissions had the company well placed to address the explosion of AI agents and the clear risks they represente…YOUTUBE.COM
6 JulFrance to Stop Certifying Non-Quantum-Safe EncryptionFrance is accelerating its transition to post-quantum encryption: France’s cybersecurity agency ANSSI said on Tuesday it would stop certifying security products that lack quantum-resistant encryption, a move that will force government bodies and critical operators to shift …SCHNEIER.COM
6 JulPrompt Injection Attacks Trick AI Agents Into Making Crypto PaymentsResearchers uncovered two campaigns embedding indirect prompt injections in malicious websites to exploit autonomous AI agents browsing the web. The post Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments appeared first on SecurityWeek .SECURITYWEEK.COM
6 JulSeven Bugs in FatFs Put IoT and Embedded Devices at RiskrunZero found 7 flaws in FatFs, a filesystem used in IoT and embedded devices. Bugs can cause memory corruption, crashes, or data leaks via crafted storage. Cybersecurity firm runZero has disclosed seven vulnerabilities in FatFs, a compact open-source library that lets embedded d…SECURITYAFFAIRS.COM
6 JulProof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access VulnerabilityOrganizations are urged to patch after proof-of-concept code makes the Linux root escalation flaw easier to exploit. The post Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
6 Jul⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and MoreA streaming box should not need a threat model. Neither should a username field, a demo repo, a reset flow, or a browser permission prompt. That is the irritating part this week: the risky pieces were ordinary. Home devices became a routing cover. Clean code pulled dirt from a de…THEHACKERNEWS.COM
6 JulNorth Korean Hackers Target Open Source Developers in Supply Chain AttacksThe PolinRider campaign has compromised more than 100 legitimate open source packages and repositories to deliver a backdoor and information stealer to developers. The post North Korean Hackers Target Open Source Developers in Supply Chain Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
6 JulCriminal IP integrates threat intelligence with OpenCTI for automated indicator enrichmentCriminal IP has integrated its threat intelligence with OpenCTI, enabling security teams to automatically convert IP addresses, domains, and URLs into structured intelligence within the platform’s knowledge graph. The integration automatically enriches ingested indicators w…HELPNETSECURITY.COM
6 JulLTM’s BlueVerse RightLogic combines AI risk assessment with cyber remediation planningLTM has launched BlueVerse RightLogic, a cybersecurity assessment and risk assurance framework designed to help enterprises identify, assess and remediate cyber exposure as they accelerate AI adoption. AI is now capable of autonomously identifying and exploiting vulnerabilities, …HELPNETSECURITY.COM
6 JulA Day With Your Vector Command Red Team PodAnyone trying to understand continuous red teaming usually gets the same high-level explanation: it is ongoing, attacker-informed, and designed to uncover risk between formal assessments. Useful as that description is, it still leaves most people with the same question, which is …RAPID7.COM
6 JulAlberta, Centurion Project sued over alleged data breach that affected millions of votersCarrie Tait reports: A retired lawyer is suing Alberta, its Chief Electoral Officer and two organizations that support secession for their respective roles in an alleged data breach affecting 2.9 million residents in the province. Clint Docken, a former class-action lawyer, last …DATABREACHES.NET
6 JulCanadian spy agency says it hacked drug traffickers, extremists and a ransomware gang last yearThe hacking operations disclosed in a Canadian spy agency's annual report underscores some pressing national security threats facing the country and its top allies.TECHCRUNCH.COM
6 JulThe agentic blind spots in your zero trust programStephen Wilson, field chief technology officer for HashiCorp, an IBM company, likens AI agents to “really smart kindergartners.” “They know how to do something, but they have no clue as to why they should do it,” Wilson says. This combination of superior execution power and lack …CSOONLINE.COM
6 JulIdentity: The operational control plane for agentic AIExisting security controls weren’t designed for AI agents. Static credentials and standing privileges aren’t sufficient for an emerging model where organizations need to rapidly authorize, limit, and revoke permissions from autonomous agents, sometimes more than once within a sin…CSOONLINE.COM
6 JulEnforce least-privilege authorization in multi-agent AI chains using CedarIf you’re building multi-agent AI systems, you need to prevent authorization scope from silently expanding as agents delegate tasks through multi-hop chains. Without proper controls, an agent can potentially act beyond what the originating user authorized, even when role-based ac…AWS.AMAZON.COM
6 JulJapanese teen arrested over cyberattack that disrupted anime streaming serviceThe unnamed student, who lives in a city near Tokyo, allegedly exploited a flaw in a subscription-based anime streaming platform to fraudulently cancel more than 46,000 user subscriptions.THERECORD.MEDIA
6 JulJadePuffer: The First Complete LLM-Driven Ransomware AttackAn "agentic threat actor" successfully exploited a Langflow flaw to steal data from a production database server and encrypt other systems.DARKREADING.COM
6 JulGoogle Chrome extensions must meet new privacy standards by August 1Google has announced a set of Chrome Web Store policy changes that tighten rules around extension data collection, improve transparency requirements, and prohibit new categories of software. The updated Developer Program Policies will take effect on August 1, 2026, giving extensi…CYBERINSIDER.COM
6 JulNetNut gets cracked.The FBI disrupts a major residential proxy service. Attackers exploit Fortinet firewalls to target UK officials. European lawmakers call for a spyware investigation. A new macOS infostealer masquerades as a clipboard manager. Prompt injection campaigns targeting AI agents through…THECYBERWIRE.COM
6 JulCitrixBleed-ing Again? NetScaler Vulnerability Under AttackAttackers wasted little time targeting the latest memory disclosure flaw in Citrix's NetScaler products, after researchers published a proof-of-concept exploit (PoC).DARKREADING.COM
6 JulThe “Anonymous” Tip System That Wasn’t: Three Months Later, Why Hasn’t Navigate360 Notified Anyone?Trigger Warning: This post includes content from tips submitted to anonymous tiplines by or about students. While identity information is redacted, tips may include obscenities and explicit references to sexual abuse, rape, assault, self-harm, violence, suicidal ideation, pornogr…DATABREACHES.NET
5 JulWeek in review: SimpleHelp vulnerability exploited, Oracle EBS Payments flaw under attackHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: Companies keep bolting AI onto their products, and the security bill is coming due Companies keep bolting AI and LLM features onto their products, and the security results are starti…HELPNETSECURITY.COM
5 JulNew ClamAV security patch closes seven scanner bugs dating back two decadesOpen source antivirus scanning sits inside mail gateways, file upload checks, and endpoint tooling at organizations of every size. Much of that work runs through ClamAV, the scanning engine maintained by Cisco’s Talos group. The project released two patch versions, 1.5.3 an…HELPNETSECURITY.COM
4 JulUnpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded DevicesSecurity firm runZero has disclosed seven vulnerabilities in FatFs, a small filesystem library that lets a device read and write the FAT and exFAT formats used on USB drives and SD cards. The flaws matter because FatFs is nearly everywhere. It ships inside the firm…THEHACKERNEWS.COM
4 JulAdaptHealth says attackers sweet-talked their way into cloud systems and stole patient dataConnor Jones reports: AdaptHealth says attackers used social engineering to breach its systems and steal sensitive patient data, including passwords associated with insurance billing. The medical equipment company disclosed the attack to the Securities and Exchange Commission (SE…DATABREACHES.NET
3 JulTeams battles bots, Bioshocking AI browser guardrails, Fortibleed fuels ransomwareTeams cracks down on meeting bots, AI guardrails get bypassed, FortiBleed fuels ransomware, and Nissan confirms PeopleSoft breach Microsoft rolls out a new Teams admin policy, "Manage External Bots and Their Access to Meetings," to detect third‑party bots, hold them in the lobby …CYBERSECURITYTODAY.LIBSYN.COM
3 JulOrganizations struggle to prioritize known cyber risksOrganizations collect more cyber risk data than ever, with many still struggling to build a unified view of their exposure. The latest State of Threat Management report from Filigran found that security teams continue to work across disconnected tools, leaving important context s…HELPNETSECURITY.COM
3 JulCritical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code ExecutionThe DuneSlide vulnerabilities enable zero-click prompt injection attacks that escape Cursor's sandbox and execute arbitrary code on the underlying operating system. The post Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution appeared first on Securi…SECURITYWEEK.COM
3 JulPamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login PasswordsCybersecurity researchers have flagged a new macOS information stealer called PamStealer that employs a series of clever tricks to infect systems and siphon sensitive data. The stealer, discovered by Jamf Threat Labs, is distributed as a compiled AppleScript (.scpt) file imperson…THEHACKERNEWS.COM
3 JulLaw enforcememt operation disrupted Malicious Residential Proxy Networks NetNutGoogle disrupted NetNut, a major proxy network that routed internet traffic through compromised home devices used by cybercriminals. Google has disrupted NetNut, one of the world’s largest residential proxy networks. The service routed internet traffic through home devices,…SECURITYAFFAIRS.COM
3 JulAgentic AI Used to Conduct Ransomware Attack via LangflowAttack demonstrates how LLM agents can combine known exploitation techniques with real-time reasoning to automate complex, multi-stage intrusions. The post Agentic AI Used to Conduct Ransomware Attack via Langflow appeared first on SecurityWeek .SECURITYWEEK.COM
3 JulFlock Cameras Can Surveil Cars Without License PlatesThis is from a 2024 company presentation : Officers can also tap into data showing a car’s decals, bumper stickers, back and top racks—along with temporary and unique state tags. Flock calls it a “Vehicle Fingerprint” and it’s touted as a way for law…SCHNEIER.COM
3 JulThe Anatomy of a Shadow AI Supply-Chain Breach: Lessons from the 2026 Vercel IncidentVercel breach happened after an employee used an unvetted AI tool. Attackers exploited it as a trusted link to access systems, steal data, and extort $2M. The Vercel breach of April 2026 did not begin with a classic zero-day exploit, a misconfigured cloud bucket, or a sophisticat…SECURITYAFFAIRS.COM
3 JulJADEPUFFER: First End-to-End AI-Driven Ransomware OperationSysdig reports an AI agent ran a full ransomware attack end-to-end, exploiting flaws, stealing creds, moving laterally, and encrypting data without humans. Sysdig’s Threat Research Team has documented what it assesses to be the first ransomware operation driven end-to-end b…SECURITYAFFAIRS.COM
3 JulVerified X ad spreads Mac malware, while ConsentFix steals Microsoft accountsTwo new campaigns show how cybercriminals are increasingly relying on social engineering instead of software exploits to compromise devices and accounts.MALWAREBYTES.COM
3 JulHK: Shun Hing Group data breach affects 920,000 customers, 1.05m files encrypted in cyber attackErwin Wong reports: Shun Hing Group has confirmed that its computer systems were compromised by hackers in March, resulting in a significant data breach affecting customers and staff. Founded in 1953 by the late Dr William Mong, Shun Hing Group has grown into a leading and divers…DATABREACHES.NET
3 JulAdobe premieres a second Patch Tuesday each month to deliver fixes fasterAdobe will now issue security patches for its products twice as often to deal with the increasing pace of software vulnerability discovery and exploitation. This follows Oracle’s decision to increase its quarterly patch program to a monthly one. Adobe issues patches on the second…CSOONLINE.COM
3 JulEveryone Owns Security—Or Nobody DoesMany e-commerce sites rely on multiple third-party providers for hosting, application development, payment processing, JavaScript, and other core functions. That convenience creates a shared responsibility problem. When a vulnerability, outage, or compliance issue occurs, each ve…YOUTUBE.COM
3 JulMicrosoft 365 users fall victim to one-in-a-million password spray attackMicrosoft users have been hit by a massive, automated password spray attack. Among those targeted by the attack were clients of security company Huntress. It reported that the attackers made 81 million attempts to log into its customers’ accounts between June 12 and 26 — and succ…CSOONLINE.COM
3 JulIn Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM JackpottingNoteworthy stories that might have slipped under the radar: Anonymous-linked Canadian hacker jailed, researcher drops zero-days in open source projects, Venezuelans sentenced in the US over ATM jackpotting. The post In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Tw…SECURITYWEEK.COM
3 JulAn AI just carried out a cyber attack without any human oversight for the first timeAnthony Cuthbertson reports: Security researchers have uncovered what they believe to be the first ever instance of an artificial intelligence agent executing a cyber attack from start to finish without human assistance. The AI-powered attack marks a major milestone for both arti…DATABREACHES.NET
3 JulWeekly Metasploit Update: Modules for SMB-to-Meterpreter, Peyara Remote Mouse RCE exploit, and moreIt's Time to Upgrade Your SMB Session This week, Metasploit contributor Dean Welch has added an SMB to Meterpreter session upgrade module. It uses PsExec to facilitate the upgrade. Users can load the module with use windows/manage/smb_to_meterpreter and specify the session number…RAPID7.COM
2 JulUnpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes ClustersArgo CD, a widely used tool for deploying software to Kubernetes, has an unpatched flaw in its repo-server component that lets an unauthenticated attacker run code, provided they can reach the component's internal network port. Synacktiv, which found the bug, says it can lead to …THEHACKERNEWS.COM
2 JulGitHub’s new tool helps prevent costly open-source license violationsGitHub’s Open Source Program Office (OSPO) uses the new GitHub License Compliance feature, now in public preview, to manage thousands of open-source dependencies and identify dependencies whose licenses require review. The feature is available to GitHub Advanced Security cu…HELPNETSECURITY.COM
2 JulDrawing a digital line for geofencing.This week, Dave and Ben take a look at the Supreme Court's recent ruling that has significantly changed how the law enforcement must approach collecting user location data. Alongside this conversation, Ben also sits down with former Congressman and current President of Americans …THECYBERWIRE.COM
2 JulWhat the AI patch gap means for enterprise securityOpen-source maintainers are receiving more vulnerability reports than they can act on, and a rising share now comes from an AI system working at machine speed. Over roughly two months this spring, Anthropic’s Claude Mythos Preview combed through more than 23,000 open-source…HELPNETSECURITY.COM
2 JulNew ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit ReposAttackers are hiding a data-stealing trojan inside fake exploit code aimed at the people who hunt bugs for a living. The malware, called ChocoPoC, travels in Python proof-of-concept (PoC) repositories on GitHub that claim to exploit hot new CVEs. Run one, and it quietly lifts you…THEHACKERNEWS.COM
2 JulExploring cross-domain & cross-forest RBCD: part 2Kerberos delegation capabilities in Linux-based tooling have been extended to allow impersonating any user within a forest. This assumed identity can then be leveraged to access resources across any domain within that forest, or even in a remote forest, provided that a trust rela…SYNACKTIV.COM
2 JulAI Agent Exploits Langflow RCE to Automate Database Ransomware AttackSecurity firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an AI agent. Its Threat Research Team calls the operator JADEPUFFER and says a large language model handled the whole job: breaking in, stealing credential…THEHACKERNEWS.COM
2 JulAdobe fixed multiple maximum-severity flaws in ColdFusion and Campaign ClassicAdobe fixed multiple critical flaws, including max severity bugs in ColdFusion and Campaign Classic that could lead to remote code execution Adobe has released security updates for ColdFusion and Campaign Classic, fixing multiple critical vulnerabilities, including seven maximum-…SECURITYAFFAIRS.COM
2 JulArgo CD flaw shows why GitOps infrastructure should be treated as tier zeroA newly disclosed vulnerability in Argo CD is drawing attention to the security risks of GitOps platforms, with researchers warning that the flaw could allow attackers who gain a foothold inside a Kubernetes cluster to execute code and manipulate application deployments. Security…CSOONLINE.COM
2 JulField reports from Patch the PlanetWe’re running Patch the Planet , an ongoing collaboration with OpenAI that pairs Trail of Bits engineers directly with more than 30 open-source projects. Its goal is to front-run a serious problem facing open-source maintainers: highly capable models like GPT-5.5-Cyber will soon …TRAILOFBITS.COM
2 Jul KEVCISA: Microsoft SharePoint RCE flaw now actively exploitedCISA warned on Wednesday that attackers have begun exploiting a high-severity Microsoft SharePoint remote code execution vulnerability patched in May. [...]BLEEPINGCOMPUTER.COM
2 JulCisco Confirms In-the-Wild Exploitation of Unified CM VulnerabilityA PoC exploit has been available since public disclosure, and the first exploitation attempts were observed last week. The post Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
2 JulCisco finally confirms attackers exploiting Unified CM flawCisco confirmed that attackers are now exploiting a Unified Communications Manager (Unified CM) vulnerability patched in early June. [...]BLEEPINGCOMPUTER.COM
2 JulResearcher Behind 'Exploitarium' Explains Release of Undisclosed Zero-Day ExploitsInfosecurity spoke with the researcher who dumped over 30 proof-of-concept exploits without disclosing the vulnerabilities firstINFOSECURITY-MAGAZINE.COM
2 JulAnthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them.IBM and Red Hat assign 20,000 engineers to the new Project Lightwell service as Anthropic's Mythos findings ignite debate over how to secure the open-source software supply chain.DARKREADING.COM
2 JulNew iboss platform gives organizations instant visibility into AI tools and usageiboss has launched the AI Security Platform, a new service that gives any organization visibility into the AI tools its people are using, free of charge. Signup is instant, deployment takes an afternoon, and a complete AI footprint appears within hours. Organizations that want to…HELPNETSECURITY.COM
2 JulNew CitrixBleed Vulnerability Exploited Immediately After Public DisclosureHackers are targeting NetScaler appliances using public PoC code to retrieve arbitrary memory content in the HTTP response. The post New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure appeared first on SecurityWeek .SECURITYWEEK.COM
2 JulFormalizing Red Teaming Offensive Methodology as a Multi-Agent AI ArchitectureThreat actors are integrating AI into their exploit chains, accelerating reconnaissance, automating vulnerability discovery, and scaling social engineering in ways that compress the timeline between initial access and impact. The barrier to sophisticated offensive operations is d…RAPID7.COM
2 JulCisco confirms exploitation of critical Unified CM flaw.DHS investigates hack of information-sharing network. Suspected Scattered Spider member extradited to the US.THECYBERWIRE.COM
2 JulFortiBleed campaign traced to INC and Lynx ransomware operationsResearchers are also investigating the role of a suspected zero-day vulnerability.CYBERSECURITYDIVE.COM
2 JulApple’s Hide My Email doesn&#8217;t hide it very wellA year ago a researcher found a vulnerability in Apple's Hide My Email feature and now he's tired of waiting for a fix.MALWAREBYTES.COM
2 JulFrom Cloud to Chaos: Defining Shared Responsibility for AI SecurityFor 15 years (!), many of us who have touched cloud security have struggled with the shared responsibility model for cloud security. As with many “cyber things,” the theory is simple. Multiple vendors, consulting firms, and industry bodies have published deceptively clear matrice…MEDIUM.COM
2 JulCatan and MouseWhat do board games and cybersecurity have in common? Pattern recognition. Strategy. Adaptation. In this week’s Threat Source Bill explores why curiosity may be a defender’s most valuable skill.TALOSINTELLIGENCE.COM
2 JulApple Reverses Age-Old Patch Policy to Keep Up With AIExpect more compressed patching cycles from Apple going forward, as attackers leverage artificial intelligence to reduce time to exploit.DARKREADING.COM
2 JulFortiBleed Actors Collaborating With Inc, Lynx Ransomware GangsAfter gaining a foothold in thousands of Fortinet firewalls, the attackers are starting to monetize that access, and are also piling on a Nextcloud zero-day bug.DARKREADING.COM
2 JulGlobal Schools Holdings Cites Two Injunctions in a Bid to Chill Our Reporting. It Won’t Work.My About page is pretty clear about legal threats: If you want to send me legal threats about my reporting or comments, knock yourself out, but don’t be surprised to see me report on your threat, any confidentiality sig blocks you may attach notwithstanding. I have been threatene…DATABREACHES.NET
2 JulThe people's AI?OpenAI considers an equity plan to share AI wealth with the public. Cisco confirms active exploitation of its unified CM platform. Researchers discover autonomous ransomware. The Vect ransomware operation partners with TeamPCP. The FortiBleed credential-harvesting campaign is lin…THECYBERWIRE.COM
2 JulLaunch of UK's National Cyber Action Plan delayed amid Labour leadership crisisThe plan had been due for publication on Monday, the sources said. It has been postponed amid the uncertainty over the governing Labour Party’s leadership contest, which opens July 9.THERECORD.MEDIA
2 JulLinux Tech Segment & Vulnerabilities Galore - PSW #933This week we have a technical segment based on the response to "Atomic Arch", an updated open-source tool to help you catch malicious packages. In the security news: - Exploitarium - A hot messy summer of vulnerabilities - AI Squatting - Linux LPE - no shortage of those - Fingerp…YOUTUBE.COM
2 JulDefense Gap in AI Security RaceAI is improving offensive security capabilities like vulnerability discovery and exploit generation at a rapid pace. Offensive work can tolerate high error rates, since only occasional success is needed. Defensive security cannot operate that way—detection, patching, and response…YOUTUBE.COM
1 JulPhantom Squatting: AI-Hallucinated Domains as a Software Supply Chain VectorAttackers can exploit LLM domain hallucinations through phantom squatting to target supply chains. Read the analysis to learn more. The post Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
1 JulMicrosoft wants to stop unwanted bots from entering Teams meetingsA new Microsoft Teams admin policy, Manage external bots and their access to meetings, gives organizations greater visibility and control over external bots in meetings. The policy identifies bots and applies safeguards before they are admitted. Microsoft will begin retiring the …HELPNETSECURITY.COM
1 Jul KEVDetection engineering: A programmatic approach to identifying cyber threatsDetection engineering, which was once a niche practice among mostly large companies, appears to have evolved into a capability that organizations across industries now consider essential to their security operations. What is detection engineering? Detection engineering is about c…CSOONLINE.COM
1 JulNika: Open-source code analysis toolMany serious security bugs in web applications sit across several files at once. Request data enters through a controller, moves through data objects and service layers, and turns dangerous only when it reaches a sensitive operation such as a database query or a file action. A sc…HELPNETSECURITY.COM
1 JulRisky Bulletin: Researcher drops giant cache of zero-daysAn anonymous researcher has dropped a giant cache of zero-day exploits, a sensitive DHS network got hacked, the US Supreme Court restricts geofence warrants, and security firm Huntress has denied accusations of a malicious insider.RISKY.BIZ
1 JulAnthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export ControlsAnthropic is putting Claude Fable 5 back online worldwide. On June 30, the U.S. Commerce Department lifted the export controls it had imposed on Fable and its more tightly controlled sibling Mythos 5 about two and a half weeks earlier. Fable 5 returns to users on Wednesday, …THEHACKERNEWS.COM
1 JulCasey Ellis on How AI Is Reshaping Vulnerability Research and PatchingIn this episode of the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠⁠Sherrod DeGrippo⁠ sits down with Casey Ellis, founder of Bugcrowd and co-founder of disclose.io, to explore how AI is reshaping vulnerability research, bug bounty programs, and the future of cyber defense. The…THECYBERWIRE.COM
1 JulClaude Sonnet 5 includes safeguards against dangerous cyber useAnthropic has introduced Claude Sonnet 5, the latest version of its general-purpose AI model, with improved reasoning, coding, tool use, and knowledge work capabilities. The model can make plans, use tools such as browsers and terminals, and complete tasks autonomously. Scores fo…HELPNETSECURITY.COM
1 JulPerformance Through People as Executives Struggle and Mentorship Matters - Greg Hoffman - BSW #454One of the biggest questions most executives ask is "Why does it still feel this hard when the talent is clearly there?" The answer, in almost every case, is not a people problem. It is an environment problem. And environment is something a leader can build. Greg Hoffman, Preside…YOUTUBE.COM
1 JulClaude Helped a Hacker Find a Way to Issue Tickets to Almost Every US Music FestivalA researcher found that using Anthropic’s Claude Opus 4.7, he could break into the website of Front Gate—used by every festival from Lollapalooza to Bonnaroo—and freely issue any ticket he chose.WIRED.COM
1 JulGuardFall Flaw Hits 10 of 11 Popular Open-Source AI AgentsResearchers found a shell injection flaw in 10 of 11 popular open-source AI agents, allowing attackers to bypass command filters. Adversa AI just published a survey, titled “GuardFall: a universal shell injection vulnerability in open-source AI agents,” of eleven open…SECURITYAFFAIRS.COM
1 JulNetzilo adds runtime governance for AI agents across major platformsNetzilo has announced expanded AI agent governance and runtime enforcement capabilities for Amazon Bedrock AgentCore and other major AI agent harnesses. As enterprises move AI agents from experimentation into production, agents are becoming a new enterprise edge. They operate acr…HELPNETSECURITY.COM
1 JulIntruder offers Free security plan for lean IT and security teamsIntruder has announced the launch of its Free plan, providing security, IT, and DevOps teams ongoing access to professional-grade vulnerability management, cloud security, and attack surface management at no cost. Smaller organizations face the same threats as Fortune 500 compani…HELPNETSECURITY.COM
1 JulRustDuck: The Botnet That’s Still Small but Engineering Like It Plans to GrowRustDuck is a small, evolving DDoS botnet migrating to Rust. It uses advanced encryption, anti-analysis evasion, and exploits known IoT flaws. Since February 2026, researchers at QiAnXin’s XLab have been tracking a new malware family, called RustDuck, that hijacks routers, …SECURITYAFFAIRS.COM
1 JulOver 900 Oracle E-Business instances exposed to ongoing attacksOver 900 Oracle E-Business Suite (EBS) instances have been found exposed online amid ongoing attacks exploiting a critical security flaw. [...]BLEEPINGCOMPUTER.COM
1 JulBioShocking: when “gaming” AI agents is no longer a gameResearchers warned AI vendors about a proof-of-concept called BioShiocking that tricks agents by gamifying the outcome.MALWAREBYTES.COM
1 JulU.S. lifting export control restrictions on Anthropic’s Mythos, FableThe company and the Commerce Department say they have reached an agreement that will see the AI models released publicly with new guardrails and classifiers. The post U.S. lifting export control restrictions on Anthropic’s Mythos, Fable appeared first on CyberScoop .CYBERSCOOP.COM
1 JulCaught in the Octopus Trap: Unauthenticated RCE in Argo CD with CodeQLSynacktiv has discovered an unauthenticated arbitrary code execution vulnerability in ArgoCD's repo-server component, potentially allowing full cluster compromise. This article explains how the vulnerability was identified using CodeQL, details the exploitation process to gain co…SYNACKTIV.COM
1 JulAdobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign ClassicAdobe has released patches for multiple maximum-severity security flaws impacting Adobe ColdFusion and Adobe Campaign Classic. The ColdFusion updates "resolves critical and important vulnerabilities that could lead to arbitrary code execution, privilege escalation, arbitrary file…THEHACKERNEWS.COM
1 JulCritical flaw in Oracle E-Business Suite is under immediate threatResearchers warn that successful exploitation of the vulnerability could allow an attacker to compromise Oracle Payments.CYBERSECURITYDIVE.COM
1 Jul5 Myths About AI in the SOC Security Teams Need to RethinkAI is now part of almost every conversation in security operations. Most teams are already investing in it, experimenting with it, or trying to understand where it fits. The challenge is not whether to adopt AI, but how to apply it in a way that actually improves outcomes. At the…RAPID7.COM
1 JulWebinar: Why traditional email security is no longer enoughModern phishing, business email compromise, and account takeover attacks increasingly exploit trusted identities and legitimate business workflows, making them harder for traditional email defenses to detect. This webinar explores how behavioral AI can help organizations automate…BLEEPINGCOMPUTER.COM
1 JulResearchers spot exploitation of another critical Oracle defectThe defect impacts a popular collection of business applications that attackers have hit before in widespread attack sprees. The post Researchers spot exploitation of another critical Oracle defect appeared first on CyberScoop .CYBERSCOOP.COM
1 JulThe AI lock comes off.The US restores exports of Anthropic’s most advanced AI models. Adobe and Citrix rush out critical patches. RustDuck emerges as a fast-evolving DDoS threat. The Gentlemen raise the stakes with a new EDR-killing exploit. Rocket lab bets big on Iridium. Researchers unveil browser-o…THECYBERWIRE.COM
1 JulNew ChocoPoC malware targets researchers via trojanized PoC exploitsMultiple weaponized proof-of-concept (PoC) exploits on GitHub were found delivering a Python-based remote access trojan (RAT) named ChocoPoC that can execute commands and steal sensitive data in a campaign believed to target cybersecurity researchers. [...]BLEEPINGCOMPUTER.COM
1 JulOONI: LaLiga piracy blocks disrupted over 500,000 legitimate sitesThe Open Observatory of Network Interference (OONI) reports that Spain's IP-based anti-piracy blocking campaign against unauthorized LaLiga streams caused widespread collateral damage. Specifically, the actions have temporarily disrupted access to more than half a million legitim…CYBERINSIDER.COM
1 JulKubota says hackers had month-long access to network systemsKubota North America Corporation disclosed that hackers had access to some of its network systems for more than a month earlier this year. [...]BLEEPINGCOMPUTER.COM
30 JunMalicious Perplexity Chrome Extension Intercepted Searches and Address Bar InputMicrosoft has found a malicious Chrome extension that posed as the AI search engine Perplexity and quietly logged what people searched for. It routed every query and every character typed into the address bar through an attacker-controlled server before redirecting users to real …THEHACKERNEWS.COM
30 JunCybersecurity jobs available right now: June 30, 2026AI Offensive Security Engineer AGAPI | UAE | On-site – View job details As an AI Offensive Security Engineer, you will leverage AI and LLMs to accelerate offensive security research, exploit development, vulnerability discovery, and security automation. You will v…HELPNETSECURITY.COM
30 JunVulnerability reports are arriving faster than GitHub can review themAcross the open source world, people are reporting software flaws in record numbers, and the systems built to verify those reports are straining under the weight. The GitHub Advisory Database, which feeds automated security alerts to millions of projects, has reached a point wher…HELPNETSECURITY.COM
30 JunHottest cybersecurity open-source tools of the month: June 2026Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across diverse settings. OWASP Agent Memory Guard: Stop AI agents from being weaponized through their own memory AI a…HELPNETSECURITY.COM
30 JunOpenClaw for iOS: The viral open-source AI agent comes to iPhone and iPadOpenClaw, a self-hosted personal AI assistant that connects to existing chat apps, is now available on iPhone, iPad and Apple Watch. The release brings chat, real-time voice conversations, approvals, device capabilities, and private automations to iOS. Connecting OpenClaw to iPho…HELPNETSECURITY.COM
30 JunReducing Attack Surface & Evaluating Efficiency in Agents - ASW #389SquidBleed reveals another vuln that's been lurking for decades, but its real lesson is in managing an attack surface. Regardless of whatever programming language you use, removing code is one of the best security steps you can take, followed by changing default configs to turn o…YOUTUBE.COM
30 JunHow ransomware syndicates weaponize corporate-style organizationFrom outsourced labor to tiered pricing models, an inside look at how today's top ransomware threats operate less like rogue hackers and more like Fortune 500 companies. The post How ransomware syndicates weaponize corporate-style organization appeared first on CyberScoop .CYBERSCOOP.COM
30 JunCISA: Windows BlueHammer flaw now exploited by ransomware gangsCISA confirmed on Monday that ransomware gangs are now exploiting a Microsoft Defender privilege escalation vulnerability, dubbed BlueHammer, that has previously been abused in zero-day attacks. [...]BLEEPINGCOMPUTER.COM
30 JunCritical SimpleHelp Vulnerability Exploited for Malware DeliveryThe threat actor is focused on collecting credentials, SSH keys, cryptocurrency wallets, and development tooling. The post Critical SimpleHelp Vulnerability Exploited for Malware Delivery appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunShipping post-quantum cryptography to PythonPost-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency , we implemented support for ML-KEM, the NIST-standard key-establishment primitive, and ML-DSA, the NIST-standard digital-signature primitive, in pyc…TRAILOFBITS.COM
30 JunCloser than Cuba: the Able Archer Nuclear Crisis of 1983It's November of 1983, the closest the world came to nuclear war, some may argue even closer than the Cuban Missile Crisis of 1962. Yet the Able Archer 1983 exercise incident is relatively unknown by comparison. A series of events that started with the Soviet shootdown of a Korea…THECYBERWIRE.COM
30 JunMalicious Chromium extension spoofs Perplexity AI to hijack browser searchesGoogle has removed a malicious browser extension masquerading as Perplexity AI after Microsoft researchers found it was intercepting users’ search traffic and routing queries through attacker-controlled servers before forwarding them to legitimate search engines. Microsoft Threat…CSOONLINE.COM
30 JunInsurance giant Aflac discloses data breach after subsidiary hackAmerican insurance giant Aflac has disclosed a new data breach after attackers breached its Japan subsidiary's systems and stole personal and bank account information. [...]BLEEPINGCOMPUTER.COM
30 JunHacker Conversations: Chris Thompson, Former Head of IBM X-Force Red, Co-Founder of RemoteThreatChris Thompson's journey took him from hacking game controls as a teenager to founding IBM’s X-Force Red team. The post Hacker Conversations: Chris Thompson, Former Head of IBM X-Force Red, Co-Founder of RemoteThreat appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunExploitation of Recent Oracle E-Business Suite Vulnerability BeginsThe critical-severity defect allows unauthenticated attackers to take over the E-Business Suite’s Payments product. The post Exploitation of Recent Oracle E-Business Suite Vulnerability Begins appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunDecades-Old Bash Tricks Expose AI Coding Agents to Supply Chain AttacksDecades-old Bash shell tricks can bypass safeguards in most open source AI coding agents, potentially turning malicious repositories into supply chain attack vectors. The post Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunAikido Security acquires Root to expand backported fixes for open source vulnerabilitiesAikido Security has acquired Root, uniting behind a shared mission to make it easy for developers and agents to build with secure open source and tackle the growing threat of supply chain attacks. Open source is the foundation of almost every application in the world, and it has …HELPNETSECURITY.COM
30 JunJamf enables AI Governance and shadow AI detection on MacJamf has announced general availability of AI Governance, a new capability within Jamf for Mac that enables IT and security teams to discover actively-used AI tools, enforce policy controls, and generate audit-ready reporting. Many organizations struggle to confidently audit and …HELPNETSECURITY.COM
30 JunInsurance giant Aflac discloses data breach at Japan subsidiarySergiu Gatlan reports: American insurance giant Aflac has disclosed a new data breach after attackers breached its Japan subsidiary’s systems and stole personal and bank account information. Aflac (short for American Family Life Assurance Company) is a Fortune 500 company a…DATABREACHES.NET
30 JunGuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection RisksThe safety check that is supposed to stop an AI coding agent from running a dangerous command can be walked straight past using a shell trick that has been public for decades. New research from Adversa AI, which is named the bypass GuardFall, found it works against ten of th…THEHACKERNEWS.COM
30 Jun KEVUS Supreme Court rules that geofence searches generally require warrants.Maximum-severity SimpleHelp flaw is now actively exploited. US government offers $10 million reward for info on Russian state-backed hackers.THECYBERWIRE.COM
30 JunCritical flaw in SimpleHelp exploited in attacks targeting sensitive credentialsResearchers found two previously undisclosed malware samples used to steal AI assistant tokens and other valuable secrets.CYBERSECURITYDIVE.COM
30 JunNissan Discloses Employee Data Breach Linked to Oracle Zero-DayNissan says employees' data was stolen via the Oracle PeopleSoft zero-day campaignINFOSECURITY-MAGAZINE.COM
30 JunCritical SimpleHelp Vulnerability Exploited For Malware DeliveryAttackers exploited a critical SimpleHelp RMM bug to deploy TaskWeaver and Djinn Stealer malwareINFOSECURITY-MAGAZINE.COM
30 JunFake Perplexity extension on Chrome Web Store tracked searchesA malicious extension in the Chrome Web Store is masquerading as the Perplexity AI answer engine, intercepting search traffic and collecting browsing information. [...]BLEEPINGCOMPUTER.COM
30 JunThe Human Element: Building A Trusted Workforce in the Age of DPRK Employment FraudFrom Nisos: Earlier this year, our DPRK employment fraud investigation revealed how North Korean operatives infiltrate US companies at industrial scale. In June, we released Part 2 of our research, featured on Nicole Perlroth’s “To Catch a Thief” podcast, that t…DATABREACHES.NET
30 JunThe Fall of XSS Forum: From DaMaGeLaB to the 2025 takedownRansomnews has published a history and analysis of XSS Forum from its inception to its seizure in 2025. There is so much that is interesting and informative in their report that it’s hard to know what to mention here, but here are just two portions below: As an overview: XS…DATABREACHES.NET
30 JunHackers Steal Data of 4.38 Million Aflac Japan CustomersHackers stole data from 4.38 million Aflac Japan customers after accessing its systems for 10 days before the breach was detected. Aflac Japan disclosed that hackers stole the personal information of 4.38 million customers and agents after gaining access to its systems between Ju…SECURITYAFFAIRS.COM
30 JunKaspersky Lab experts have discovered a new attack vector and toolkit for compromising corporate Gmail accountsKaspersky Labs writes: It is used by the ToddyCat group. Kaspersky Lab experts have discovered a new attack vector and toolkit for compromising corporate Gmail accounts. Using this toolkit, attackers can access user accounts via an API, read conversations, and harvest data from c…DATABREACHES.NET
30 Jun KEVAnton’s Security Blog Quarterly Q2 2026My Anton’s Security Blog Quarterly covers both Anton on Security and my posts from Google Cloud blog , Google Cloud community blog , and our Cloud Security Podcast ( subscribe on Spotify, now with VIDEO ). Top 10 posts with the most lifetime views (excluding paper announcement bl…MEDIUM.COM
30 JunThe court draws a privacy line.The Supreme Court limits geofence warrants. DHS moves to expand CISA. The State Department offers $10 million for Russian hackers. A legal theory could reshape EU-U.S. data sharing. Plus, cyberattacks hit D.C. housing, Oracle and SimpleHelp flaws face active exploitation, malware…THECYBERWIRE.COM
30 JunScammers race to cash in on Venezuelan earthquake disasterScammers wasted no time exploiting Venezuela's devastating earthquake, with researchers uncovering 212 newly-registered relief-themed domains in just five days. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
30 JunFake Bug Report Hijacks AI Coding Agents at Scale"Agentjacking" is the latest demonstration of how easily attackers can exploit an AI agent's inability to differentiate between content and instructions.DARKREADING.COM
30 JunUK journalists and NGOs risk terrorism prosecutions under new security billMEE reports: New national security legislation being rushed through the UK’s parliament could criminalise British foreign correspondents and NGO workers engaging with designated state-backed groups, experts warn. The National Security (State Threats) Bill, which is moving t…DATABREACHES.NET
30 JunThe Green Shirt AI JailbreakAn LLM refused a request until the prompt included fabricated internal reasoning claiming the action was acceptable because of a "green shirt." The model then complied, illustrating how prompt-based attacks can bypass intended restrictions. Unlike traditional software exploits, m…YOUTUBE.COM
30 JunUS Supreme Court limits police access to people’s location historyThe US Supreme Court has ruled that law enforcement's acquisition of historical location data through geofence warrants constitutes a Fourth Amendment search, marking a major victory for digital privacy. While the Court stopped short of declaring geofence warrants unconstitutiona…CYBERINSIDER.COM
30 JunAnthropic to restore Claude Fable access on WednesdayAnthropic has confirmed that the Department of Commerce has lifted export controls on Claude's two most powerful models, Fable 5 and Mythos 5. [...]BLEEPINGCOMPUTER.COM
30 JunXSS.is, The Forum That Ran the Ransomware Supply Chain Is Down. The Market Isn’tPolice arrested the alleged admin of XSS.is, a major cybercrime forum whose trusted escrow service helped power the underground economy. On 22 July 2025, French and Ukrainian police arrested a 38-year-old man in Kyiv and shut down XSS.is, the most influential Russian-language cyb…SECURITYAFFAIRS.COM
30 Jun KEVSN 1085: A SOTA State-Sponsored Campaign - AI's New Superpower: Loop EngineeringAI is now uncovering and fixing thousands of hidden software bugs faster than humans can keep up, but not everyone is playing by the rules. Find out how state-sponsored attackers and careless disclosures are turning the cybersecurity playbook upside down. Win10's popularity force…TWIT.TV
29 JunSponsored: Corelight’s blueprint for AI-era defenceIn this sponsored interview James Wilson chats with Corelight’s VP of Product Vijit Nair about defence strategies for the AI era. When agents can find and exploit vulnerabilities at machine speed, you need to balance between proactive and reactive measures. On the proactive side,…RISKY.BIZ
29 JunUS Restricts Frontier AI modelsUS Loosens Anthropic Claude Mythos Access, Unpatchable iPhone Exploit Emerges, and CISO Burnout Drives Fractional Shift Washington granted a partial reprieve allowing Anthropic's Claude Mythos to be released to more than 100 approved U.S. firms and institutions after export contr…CYBERSECURITYTODAY.LIBSYN.COM
29 JunDarkMoon: Open-source AI pentesting platformPenetration testing has long run on expert time, with specialists spending days probing a network or web application by hand. Manual engagements stretch across weeks, expert consultants run into thousands of dollars a day, and results vary with the tester. Automation promises to …HELPNETSECURITY.COM
29 JunFrom mythos to reality: Why the 2026 state of pentesting report proves the need for programmatic defensesAI can find zero-days in minutes. Your defense strategy must evolve now.CYBERSECURITYDIVE.COM
29 JunFixing pentesting, Meta is destroying its engineering org, the weekly news - ESW #465Interview with Adriel Desautels - the pentest is broken Adriel joins us for a discussion on the state of penetration testing, why it hasn't done much to help security teams over the last 20 years, and why AI won't save it. Segment Resources: - https://hbr.org/2026/04/boards-are-f…YOUTUBE.COM
29 JunUS Federal Insurance Regulator Confirms Data Breach Via Oracle FlawAn attacker has exploited a zero day in Oracle Peoplesoft to gain access to the IT systems of the NAIC, the standard-setting association for the US federal insurance systemINFOSECURITY-MAGAZINE.COM
29 JunRobot Police OfficersWe’ve taken one small step towards robot police officers: a drone capable of disarming a suspect: In a June 22 video posted on the Sacramento County Sheriff’s Office’s Instagram page, an officer wearing goggles can be seen operating a drone to retrieve a knife from an armed…SCHNEIER.COM
29 JunMozilla warns of indirect prompt injection risk in AI coding agentsA malicious GitHub repository can silently compromise a developer’s machine without containing a single line of malicious code, security researchers at Mozilla’s Zero Day Investigative Network (0DIN) warned. The attack The proof-of-concept attack targets AI-powered co…HELPNETSECURITY.COM
29 Jun‘DirtyClone’ Linux Kernel Vulnerability Leads to Root AccessA variant of DirtyFrag, the flaw allows unprivileged local users to manipulate the Linux page cache and gain root privileges. The post ‘DirtyClone’ Linux Kernel Vulnerability Leads to Root Access appeared first on SecurityWeek .SECURITYWEEK.COM
29 JunThe Red Agent POV: Exploiting Broken Object-Level Authorization in an Airline GraphQL APIPart 2: How the Red Agent bypassed backend resolvers to expose an entire airline booking database in fifteen minutesWIZ.IO
29 Jun236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet DrainersNew findings unearthed by Infoblox show that more than 236,000 websites are using investment scam templates built using a legitimate Chinese open-source, cross-platform application development framework called DCloud Uni-App. The templates power bogus cryptocurrency exchanges, mu…THEHACKERNEWS.COM
29 JunCharting your way in: Helm template injectionDuring the audit of a Kubernetes cluster, we encountered an injection in a Helm template applied through ArgoCD. To our surprise, very few resources exist regarding YAML injection in vulnerable Helm templates. In this blog post, we will explore this kind of vulnerability and how …SYNACKTIV.COM
29 JunUK businesses fear stigma of ransomwareAlex Scroxton reports: Fear of stigmatisation is likely leading businesses across the UK to drastically underreport data on ransomware attacks, especially when they have paid a ransom to a cyber criminal gang, as admission of such is often seen as supporting further criminal acti…DATABREACHES.NET
29 JunCentral Bank of Libya investigates alleged data leak after cyberattackSafaAlharathy reports: Libya’s central bank (CBL) says it is investigating data published on the dark web following a recent cyberattack. In a statement, the bank said its technical teams, working with international experts, were analysing the data to determine its nature and whe…DATABREACHES.NET
29 JunZA: Copying the wrong person on an email could be considered a data breach in South AfricaJan Vermeulen reports: Misdirected internal emails that expose personal information can trigger mandatory data breach reporting under South Africa’s data privacy law, POPIA, even when the disclosure was accidental. Armand Swart, Hlonelwa Lutuli, and Isabella Keeves from Werksmans…DATABREACHES.NET
29 JunOne Honeypot Ends the AttackMany attackers spend their first moments inside a compromised network performing discovery. According to this red team perspective, a properly deployed honeypot or canary token can immediately reveal that activity. That means organizations don't always have to catch every exploit…YOUTUBE.COM
29 JunFactoring RSA Keys with Many ZerosInteresting research on a new class of weak RSA keys: keys with lots of zeros. It turns out that these keys are out in the wild. The badkeys project is an open-source service that checks public keys for known vulnerabilities. While developing this tool, Hanno collected a massive …SCHNEIER.COM
29 JunInside the Advisory Database and what happens when vulnerability volume breaks recordsThe GitHub Advisory Database is processing more vulnerability reports than ever before. Here's what's driving the surge, how we're responding, and how the community can help. The post Inside the Advisory Database and what happens when vulnerability volume breaks records appeared …GITHUB.BLOG
29 JunUS racks up about 400 wins over illegal World Cup streaming sitesThe World Cup’s organizing body, FIFA, helped identify hundreds of domains taken down in an action organized by the U.S., along with the help of U.S. broadcaster NBC Universal and other entities.THERECORD.MEDIA
29 JunNissan hit by Oracle PeopleSoft cyberattack exposing internal dataNissan North America has informed employees that a cyberattack targeting Oracle PeopleSoft systems exposed sensitive personnel records, making the automaker one of the latest known victims linked to a broader campaign exploiting a critical vulnerability in the widely used HR plat…CYBERINSIDER.COM
29 JunNI: Updated warning to parents over schools cyber attackNiall Glynn and Auryn Cox report: The number of schools in Northern Ireland affected by a recent cyber-attack is larger than previously thought. In a letter issued by the Education Authority (EA) on Thursday, some parents were warned that their child’s personal data may hav…DATABREACHES.NET
29 JunMOVEit Breach Defendants Lose 2nd Bid to Toss Negligence ClaimsChristopher Brown reports: Bellwether defendants in multi-district litigation over a massive data breach of Progress Software’s MOVEit file-transfer application failed to convince a federal court to toss negligence claims against them under the laws of California, Indiana, Michig…DATABREACHES.NET
29 JunAI behind the velvet rope.The White House keeps frontier AI models on a short leash. Russian threat actors increasingly target secure messaging platforms. DirtyClone is a high-severity Linux kernel privilege escalation flaw. An investigation claims federal websites are violating privacy rules. Microsoft d…THECYBERWIRE.COM
29 JunNissan discloses employee data breach linked to Oracle zero-day attacksNissan is warning that it suffered a data breach affecting current and former employees after threat actors exploited an Oracle PeopleSoft vulnerability in data theft attacks previously linked to the ShinyHunters extortion group. [...]BLEEPINGCOMPUTER.COM
29 JunNAIC says public data stolen in ShinyHunters' PeopleSoft breachThe National Association of Insurance Commissioners (NAIC) says the ShinyHunters extortion group stole only publicly available data, outdated logs, and configuration files after breaching its systems by exploiting a zero-day vulnerability in an Oracle PeopleSoft server. [...]BLEEPINGCOMPUTER.COM
29 JunStop Building a 2003 SOC with AI: A Modern People & Process Framework (Part 1)One particular aspect of an agentic or AI-powered SOC (but NOT “humanless SOC ”) has bothered me over the last few months: specifically, the people and process side of such a SOC. If you recall my blog posts ( part 1 , part 2 and this video ) about AI SOC readiness, I hinted at c…MEDIUM.COM
29 JunVulnerabilities Expose Private Data in Indian Government SystemsOne critical vulnerability, among many discovered by a researcher, could have allowed anyone to walk in and take over a national government portal.DARKREADING.COM
29 JunEXCLUSIVE: Top-100 Law Firm Fox Rothschild Suffers Data Breach and Leak by Silent Ransom GroupFox Rothschild is a top-100 law firm whose articles and resources have been cited on DataBreaches.net and PogoWasRight.org dozens of times over the years. This time, however, they are the subject of a post because they were victims of a data breach by a well-known group that targ…DATABREACHES.NET
28 JunWeek in review: Fortibleed campaign’s impact on orgs, Cisco Unified CM flaw exploitedHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: Encrypted DNS still tells an eavesdropper where to look Encrypted DNS runs across much of the Internet. DNS over TLS, HTTPS, and QUIC keep the contents of a query away from anyone wa…HELPNETSECURITY.COM
28 JunData breach exposes up to 14.2 million email logins at six ISPsJapanese telecommunications operator KDDI Corporation disclosed a data breach where threat actors gained access to one of its email systems used by five other internet service providers (ISPs) in the country. [...]BLEEPINGCOMPUTER.COM
28 JunAssuranceAmerica breach may have affected more than 1.1 million people in seven statesKrys Shahin and Christopher Buchanan report: State officials are warning at least 1.1 million people across seven states may be impacted by an AssuranceAmerica data breach. Notices about the breach were sent to California, Massachusetts, Nebraska, South Carolina, Texas, Vermont, …DATABREACHES.NET
28 JunNZ pharmacy scrambles to scrub internet of patients’ private messagesMary Argue reports: A Wellington pharmacy at the centre of a data leak says sensitive patient information has now been scrubbed from the internet. Unichem Petone said it was contacting 29 patients affected by what it described as an error on the website that saw patients’ p…DATABREACHES.NET
28 JunSysco - 2,691,852 breached accountsIn June 2026, the food distribution company Sysco was targeted by a ShinyHunters "pay or leak" extortion campaign . Data was subsequently published containing 2.7M unique email addresses belonging to staff and customers. The data also contained largely corporate contact informati…HAVEIBEENPWNED.COM
28 JunKDDI Data Breach Impacts up to 14.2 Million Email Accounts at Six ISPsKDDI Corporation disclosed a breach affecting up to 14.2 million email accounts after attackers exploited a vulnerability in third-party software. KDDI Corporation disclosed a data breach that exposed up to 14.2 million email accounts across six Japanese internet service provider…SECURITYAFFAIRS.COM
28 JunA KDDI data breach has put up to 14.2 million ISP email logins at risk across JapanJames Whitmore reports: Data breach at Japanese telecoms operator KDDI may have exposed up to 14.22 million email addresses and passwords linked to ISP mail services, after attackers gained unauthorised access to a system used by six providers in Japan. KDDI said it confirmed the…DATABREACHES.NET
27 JunWhy Car Dealerships Are Prime Cyber Targets: Fraud, Resilience, and Security Leadership with Jennifer HuttonCybersecurity Today would like to than Material Security for their support of this podcast. On Cybersecurity Today on the Weekend, the host speaks with Jennifer Hutton, a cybersecurity leader in the car dealership sector, about how she entered cybersecurity through increasing cyb…CYBERSECURITYTODAY.LIBSYN.COM
27 Jun KEVKlue supply-chain attack impacts cybersecurity firms.Tata Electronics and Bajaj Auto continue recovery from cyberattacks. CISA warns of actively exploited PTC and Cisco vulnerabilities.THECYBERWIRE.COM
27 JunSurviving the surge of new Linux LPE : Defense in Depth not deadThanks to AI-assisted vulnerability research and kernel patch diffing that breaks "responsible disclosure" embargos, it's quite the overwhelming time for defenders. There's been a weekly reveal of new Linux critical vulnerabilities, with full exploit scripts made public days befo…SYNACKTIV.COM
27 JunExploiting the Tesla Wall Connector from its charge port connector - Part 2: bypassing the anti-downgradeIn a previous article, we presented an attack against the Tesla Wall Connector Gen 3 used during Pwn2Own Automotive 2025. The exploit chain relied on a simple fact: there was no anti-downgrade mechanism. Once we could speak UDS over the charging cable, we could just write an old,…SYNACKTIV.COM
27 JunMake it Blink: Over-the-Air Exploitation of the Philips Hue BridgeThe year-end edition of Pwn2Own took place in Cork, Ireland. For the first time, this event featured smart home devices, including the Amazon Smart Plug, Home Assistant Green, and the Philips Hue Bridge. The attack scenario defined by the ZDI involved an adversary with access to …SYNACKTIV.COM
27 JunExploring cross-domain & cross-forest RBCDThe Resource-based Constrained Delegation (RBCD) attack is well-known from pentesters and attackers: by editing the msDS-AllowedToActOnBehalfOfOtherIdentity attribute of a machine account, an attacker can impersonate users on said machine. Even though this attack mechanism has be…SYNACKTIV.COM
27 Junmitmproxy for fun and profit: Interception and Analysis of Application TrafficA solid understanding of the protocols used by applications is a necessary prerequisite when assessing application security. In recent projects, we have had to intercept various types of network traffic across different platforms, including Linux, Android, and iOS. The purpose of…SYNACKTIV.COM
27 JunBeyond ACLs: Mapping Windows Privilege Escalation Paths with BloodHoundWindows privileges are special rights that grant processes the ability to perform sensitive operations. Some privileges allow bypassing standard Access Control List (ACL) checks, which can lead to significant security implications. While privileges like SeDebugPrivilege, SeImpers…SYNACKTIV.COM
27 JunOn the clock: Escaping VMware Workstation at Pwn2Own Berlin 2025At Pwn2Own Berlin 2025, we exploited VMware Workstation by abusing a Heap-Overflow in its PVSCSI controller implementation. The vulnerable allocation landed in the LFH allocator of Windows 11, whose exploit mitigations posed a major challenge. We overcame this through a complex i…SYNACKTIV.COM
27 JunLivewire: remote command execution through unmarshalingLivewire revolutionizes Laravel development by enabling real-time, interactive web interfaces using only PHP and Blade, removing the need of heavy JavaScript frameworks. Its innovative hydration system seamlessly instantiate and restores component states, supporting complex data …SYNACKTIV.COM
27 JunExploiting Anno 1404Anno 1404 is a strategy game developed by Related Designs and published by Ubisoft. It is a real-time strategy game that focuses on city management and construction. The Anno 1404: Venice expansion, released in 2010, includes an online and local area network multiplayer mode. Dur…SYNACKTIV.COM
27 Jun2025 Winter Challenge: QuinindromeA few months have passed and the first snowflakes have fallen since the end of the Synacktiv Summer Challenge. This event was a success, with one of the participants even finding a zero-day vulnerability while working on his solution! Although it hasn't been made public yet, it w…SYNACKTIV.COM
27 JunBreaking the BeeStation: Inside Our Pwn2Own 2025 Exploit JourneyThis article documents our successful exploitation at Pwn2Own Ireland 2025 against the BeeStation Plus. We walk through the full vulnerability research process, including attack surface enumeration, code auditing, exploit development, and ultimately obtaining a root shell on the …SYNACKTIV.COM
27 JunSite Unseen: Enumerating and Attacking Active Directory SitesActive Directory Sites are a feature allowing to optimize network performance and bandwidth usage in AD internal environments. They are commonly implemented by large, geographically dispersed organizations spanning across multiple countries or continents. Sites did not receive mu…SYNACKTIV.COM
27 Junappledb_rs, a research support tool for Apple platformsOver the years, research on Apple platforms has become significantly more complex, largely due to the numerous countermeasures deployed by the Cupertino company. To address this challenge during our missions on these platforms, we developed appledb_rs: an open-source tool (https:…SYNACKTIV.COM
27 JunThe 'S' in Zoom, Stands for SecurityToday we uncover two (local) security flaws in Zoom's latest macOS client. First, a privilege escalation vulnerability, and second, a method to surreptitiously access a user's webcam and microphone (via Zoom).OBJECTIVE-SEE.ORG
27 Jun[0day] Abusing XLM Macros in SYLK FilesA 0day logic flaw in Microsoft Excel leads to 'remote' code execution on macOS, via malicious macros.OBJECTIVE-SEE.ORG
27 JunBurned by Fire(fox) (Part III)Recently, an attacker targeted (Mac) users via a Firefox 0day. In this third post, we analyze a second backdoor used in the attack, detailing its persistence, capabilities, and ultimate identify it a new variant of the cross-platform Mokes malware!OBJECTIVE-SEE.ORG
27 JunBurned by Fire(fox) (Part II)Recently, an attacker targeted (Mac) users via a Firefox 0day. In this second post, we fully reverse OSX.NetWire.A, revealing (for the first time!), its inner workings and complex capabilities.OBJECTIVE-SEE.ORG
27 JunBurned by Fire(fox) (Part I)Recently, an attacker targeted (Mac) users via a Firefox 0day. In this first post, we triage and identify the malware (OSX.NetWire.A) utilized in this attack, identifying its methods of persistence, and more!OBJECTIVE-SEE.ORG
27 Jun[0day] Mojave's Sandbox is LeakyThe macOS sandbox is seeks to prevent malicious applications from surreptitiously spy on unsuspecting users. Turns out, it's trivial to sidestep some of these protections, resulting in significant privacy implications!OBJECTIVE-SEE.ORG
27 JunRemote Mac Exploitation Via Custom URL SchemesThe WINDSHIFT APT group is successfully infecting Macs with a novel infection mechanism. By abusing custom URL scheme handlers and minimal user interaction, Macs can be remotely compromised!OBJECTIVE-SEE.ORG
27 Jun[0day] Synthetic RealityIf you can programmatically generate synthetic mouse clicks, you can break macOS! Approving kernel extensions, dismissing privacy alerts, and much more more...OBJECTIVE-SEE.ORG
27 JunEscaping the Microsoft Office SandboxImagine you've gained remote code execution on a Mac via a malicious Word document. Turns out, you're still stuck in a sandbox. However, via a faulty regex, you can escape and persist!OBJECTIVE-SEE.ORG
27 Jun[0day] Bypassing SIP via SandboxingIn this guest blog post @CodeColorist writes about a neat macOS vulnerability. Ironically, by abusing security mechanisms such as sandboxing, macOS can be coerced to load an untrusted library, into a SIP-entitled process!OBJECTIVE-SEE.ORG
27 JunAn Unpatched Kernel BugOn my flight to ShmooCon, I managed to panic my fully-patched MacBook. Here we analyze the kernel panic report, finding that Apple's AMDRadeonX4150 kext is responsible for the crash.OBJECTIVE-SEE.ORG
27 JunTwo Bugs, One Func(), part threeAnalyzing code within the macOS kernel audit subsystem uncovered an exploitable heap overflow.OBJECTIVE-SEE.ORG
27 JunNew Attack, Old TricksA Word document targets Mac users with malicious macros and an open-source payload.OBJECTIVE-SEE.ORG
27 Jun[0day] Bypassing Apple's System Integrity ProtectionRead how an attacker can bypass Apple's SIP, via the local OS upgrade processOBJECTIVE-SEE.ORG
27 JunPhoenix: RootPipe lives! ...even on OS X 10.10.3Exploiting RootPipe on OS X 10.10.3OBJECTIVE-SEE.ORG
27 JunNAIC suspends investment risk designations after cyber attackThe National Association of Insurance Commissioners (NAIC) is the U.S. standard-setting and regulatory support organization. It is governed by the chief insurance regulators from the 50 states, the District of Columbia, and five U.S. territories. The organization serves the publi…DATABREACHES.NET
26 JunMalware gaslights AIMac Malware Gaslights AI, Major Info-Stealer Takedown, OpenAI's Patch the Planet, and FortiBleed Fallout Mac malware called "Gaslight," attributed to North Korea-aligned actors, plants fake system messages designed to derail AI-based analysis while stealing data and exfiltrating …CYBERSECURITYTODAY.LIBSYN.COM
26 JunGDPR at 10: Landmark data protections, increasing business burdenTen years have passed since the General Data Protection Regulation (GDPR) came into force, and the results are mixed. While data protection has become more firmly established in European companies — and beyond — than ever before, the business world remains critical of the regulat…CSOONLINE.COM
26 JunModelplane: Open-source control plane for AI inferenceOrganizations that run open-weight models on hardware they own operate GPU fleets spread across clouds, neoclouds, and on-premise data centers. Each fleet handles model placement, replica scaling, infrastructure provisioning, weight distribution, and traffic routing. Teams have b…HELPNETSECURITY.COM
26 JunNew infosec products of the month: June 2026Here’s a look at the most interesting products from the past month, featuring releases from AISLE, Asimily, Blue Planet, depthfirst, Diligent, Drata, Elastic, Filigran, Flip, Hyland, IDnow, Legit Security, MazeBolt, Noma, Qodo, Ridge Security, Tigera, and WitnessAI. Asimily turns…HELPNETSECURITY.COM
26 JunWhat CISOs need to tell the board about zero trust in OT: A 90-day communication and action planI work as a principal specialist at a pipeline operator where Operational Technology (OT) is the backbone of the business. I do not report to the board or act as a CISO, but the issues that get raised to those levels affect my job every single day. Since the Colonial pipeline ran…CSOONLINE.COM
26 JunProposed US law would make AI risk reporting a legal obligationUS lawmakers on Thursday introduced a bill that would require developers of advanced AI models to report major safety and security incidents to the Commerce Department, establishing a federal oversight framework for high-risk AI systems. The proposed AI Incident Reporting Act wou…CSOONLINE.COM
26 JunMythos is a signal, not a siren: What frontier AI should change for CISOsWhen a new AI capability starts making headlines, I see the same pattern play out in boardrooms and executive staff meetings. The technology is introduced as a looming breakthrough for attackers. The conversation quickly shifts to worst-case scenarios. Then security leaders are a…CSOONLINE.COM
26 JunJapanese telco suffers breach exposing 14.2 million email passwordsKDDI has disclosed that an email system it operates for internet service providers (ISPs) was breached in a cyberattack, potentially exposing email account information belonging to customers of six Japanese service providers. The company says the intrusion exploited a vulnerabili…CYBERINSIDER.COM
26 JunLinux Foundation Unveils New Open Source Security Project AkritesIt will provide the tools and channels to report, patch, and disclose open source software vulnerabilities. The post Linux Foundation Unveils New Open Source Security Project Akrites appeared first on SecurityWeek .SECURITYWEEK.COM
26 JunRansomware gangs find Europe’s weakest link in third-party suppliersRansomware attacks against European organizations increased during the first months of 2026, with third-party suppliers becoming a major entry point for attackers. Black Kite examined 2,066 ransomware incidents across 31 countries between January 2025 and April 2026 in its 2026 E…HELPNETSECURITY.COM
26 JunCritical open-source projects get a new security frameworkOpen source software projects are getting a new framework for handling security vulnerabilities as AI shortens the time between flaw discovery and exploitation. The Linux Foundation has launched Akrites, an industry initiative that brings together technology companies, financial …HELPNETSECURITY.COM
26 JunCyberattacks pose a ‘threat to life’ in AustraliaAustralia’s Security Intelligence Organization (ASIO) has uncovered an attack on a critical infrastructure operator’s network. State-sponsored actors had compromised the network and were preparing to sabotage it, according to its director general, Mike Burgess. Other countries fa…CSOONLINE.COM
26 JunStop Chasing Every New ThreatCybersecurity teams naturally focus on new vulnerabilities, exploits, and attack techniques. But basic practices like patch management, firmware updates, and consistent security hygiene still prevent many successful compromises. Organizations that maintain strong fundamentals are…YOUTUBE.COM
26 JunMore Klue Breach Victims Identified as Hackers Get HackedRoughly two dozen companies have notified their customers of the Klue-Salesforce incident impact. The post More Klue Breach Victims Identified as Hackers Get Hacked appeared first on SecurityWeek .SECURITYWEEK.COM
26 Jun KEVTata Electronics and Bajaj Auto continue recovery from cyberattacks.Threat actors target critical infrastructure across Southeast Asia. CISA warns of actively exploited PTC vulnerability. Polish police disrupt SIM-swapping gang.THECYBERWIRE.COM
26 JunSoftware, AI companies form alliance to tackle open-source security flawsThe emergence of frontier AI models has increased the speed and capabilities of malicious hackers.CYBERSECURITYDIVE.COM
26 JunAmazon Q Flaw Enabled Cloud Credential Theft via Malicious RepositoriesAWS has patched the vulnerability and published its own advisory to inform customers about the potential impact. The post Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories appeared first on SecurityWeek .SECURITYWEEK.COM
26 JunMalware authors subvert AI detection systemsEnterprises that have turned to AI in order to boost their security defenses may have to reconsider their approach. Malware containing code that commands LLM-assisted products to abort their analysis or refuse to implement it is already circulating, according to a post from secur…CSOONLINE.COM
26 JunUnpatched macOS bug could allow tampering trusted applicationsSecurity duo Mysk has disclosed an unpatched macOS vulnerability that they say allows web-installed applications to silently modify other apps' binaries, potentially bypassing key macOS security protections. In a post published on X, Mysk said the issue affects macOS 26 and macOS…CYBERINSIDER.COM
26 JunCisco Adds NHI to Security Stack With Astrix, WideField AcquisitionsCisco joins a growing list of security platform providers who are betting that securing the agentic workforce means turning identity into the primary control plane.DARKREADING.COM
26 Jun KEVCISA sets urgent deadline to fix Cisco flaw exploited in attacksThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) is giving federal agencies until Sunday to patch a vulnerability in Cisco Unified Communications Manager Server that is being actively exploited. [...]BLEEPINGCOMPUTER.COM
26 JunThe Chinese Control the Majority of Argentina’s Squid FleetChinese companies control nearly two-thirds of Argentina’s own squid fleet.SCHNEIER.COM
26 Jun KEVFactory reset required.Tata Electronics and Bajaj Auto continue recovery from cyberattacks. FCC tightens undersea cable rules to bolster national security. CISA warns of actively exploited PTC vulnerability. Gamaredon expands toolkit, hides behind legitimate services. Iran-linked hackers turn public wa…THECYBERWIRE.COM
25 JunInteresting Paper Exploring Prompt InjectionThis is a fascinating explotation of how LLMs fall for prompt injection attacks. It turns out that they learn to recognize the style of text in different role/instruction blocks, and not just the tags. Their conclusion: Role tags were a formatting trick that became the security a…SCHNEIER.COM
25 JunRethinking the balance between AI oversight and innovationThe new CIO mandate is clear: facilitate AI adoption across the enterprise at speed. According to CIO.com’s State of the CIO survey, CEOs’ to p priority for their IT executives is to capitalize on AI . From researching to evaluating AI products, CIOs are now the central figures i…CSOONLINE.COM
25 JunGRC is broken. FedRAMP 20x might fix itWe are auditing a curated version of history. I’ve worked in security long enough now to know something most of us don’t really say out loud. A lot of compliance is theatre. Not all of it, and not all auditors or frameworks, but enough of it that most experienced CISOs know exact…CSOONLINE.COM
25 JunThe Policy Nobody Actually EnforcedMany organizations generate least-privilege IAM policies but never deploy them. That leaves existing permissions available for attackers to abuse after compromising workloads like CI/CD runners. Instead of depending on thousands of manually applied policies, Sandy Bird describes …YOUTUBE.COM
25 JunCloud Visibility, Fortibleed, hacking things the easy way - Sandy Bird - PSW #932First up is Sandy Bird from Sonrai discussing how to protect our cloud infrastructure! This segment is sponsored by Sonrai Security. Visit https://securityweekly.com/sonrai to learn more about them! Next up in the security news: - Help, I am Fortibleeding - Cisco SD-WAN needs hel…YOUTUBE.COM
25 JunYour Small Business Is a TargetMore than 90% of the economy depends on small and medium-sized businesses. At the same time, critical infrastructure spans far beyond power grids or defense systems. It includes industries like healthcare, financial services, food and agriculture, IT, communications, water, and c…YOUTUBE.COM
25 JunBeyond IOCs: AI-enabled threat intelligenceIn this week’s newsletter, Martin considers how AI will help threat intelligence by creating an easily queryable data source of intelligence reports.TALOSINTELLIGENCE.COM
25 JunBeware of &#8220;Parcel Expert&#8221; job offers: They&#8217;re parcel mule scamsMost parcel mule scams start with fake job offers that trick victims into handling stolen goods.MALWAREBYTES.COM
25 JunFraud goes door-to-door.This week, hosts of N2K CyberWire ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Maria Varmazis⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠…THECYBERWIRE.COM
25 JunCisco Vulnerability Exploited Months Before Disclosure, Google WarnsA high-severity flaw in Cisco Catalyst SD-WAN Manager disclosed in early June was exploited as early as MarchINFOSECURITY-MAGAZINE.COM
25 JunTrust in Automated AI Vulnerability Scanning Collapses to 9%, New Study FindsCobalt study finds 20-percentage-point drop in number of organizations relying solely on AI automation for testingINFOSECURITY-MAGAZINE.COM
25 JunShopify Shop app users are seeing fake orders in purchase historiesScammers are placing fake purchase receipts inside Shopify's Shop app, exploiting users' trust in order-tracking applications to lure them into calling fraudulent customer support numbers. The campaign moves the long-running fake invoice scam beyond email, placing fraudulent rece…CYBERINSIDER.COM
25 JunJapan’s army used USB drives with Chinese malware for a yearJapan's Ground Self-Defense Force (JGSDF) reportedly used counterfeit USB flash drives infected with malware linked to previously identified Chinese threat activity on computers connected to sensitive military networks for nearly a year before the devices were discovered. Accordi…CYBERINSIDER.COM
25 JunCal Water Says No OT Systems Breached in Iranian Handala CyberattackMandiant has helped the California water utility investigate the cyberattack launched by Iranian hacker group Handala. The post Cal Water Says No OT Systems Breached in Iranian Handala Cyberattack appeared first on SecurityWeek .SECURITYWEEK.COM
25 Jun25-Year-Old Vulnerability Patched in CurlThe latest version of the open source data transfer tool resolves 18 medium and low-severity vulnerabilities. The post 25-Year-Old Vulnerability Patched in Curl appeared first on SecurityWeek .SECURITYWEEK.COM
25 JunLocal Police Collusion Hampers Crackdown on Asian Scam CentersWith tens of billions of dollars flowing into regional economies from cybercrime, scam centers continue to flourish, despite international and law-enforcement efforts.DARKREADING.COM
25 JunExperts on Experts: Why AI and Compliance Are Forcing A New Security Operating ModelThis week on Experts on Experts, I sat down with Sabeen Malik , Rapid7’s VP of Global Government Affairs and Public Policy, to discuss a shift security leaders can’t afford to treat as separate threads: frontier AI, vulnerability discovery, cybersecurity compliance, and operation…RAPID7.COM
25 JunNVIDIA GEN3C: Unauthenticated RCE via Pickle Deserialization in the Inference APIVulnCheck's Initial Access Intelligence team details an unauthenticated remote code execution in NVIDIA's GEN3C, where two FastAPI inference endpoints deserialize raw HTTP request bodies with pickle.loads() with no authentication.VULNCHECK.COM
24 JunMeta pauses employee monitoring program after data protections failAn extensive program at Meta to gather a wide range of data from employees to train its AI model has been frozen after employees reportedly broke through its guardrails and accessed restricted data, and then did so again after Meta claimed to have fixed the vulnerability. Whether…CSOONLINE.COM
24 JunAnthropic’s Mythos Model Found Vulnerabilities in Classified US Government Systems, Official SaysCome vulnerabilities were found within hours, but that does not mean the model was able to exploit them within that time, the official said. The post Anthropic’s Mythos Model Found Vulnerabilities in Classified US Government Systems, Official Says appeared first on SecurityWeek .SECURITYWEEK.COM
24 JunCybersecurity jobs available right now: June 24, 2026Application Security Leader DriveNets | Israel | Hybrid – View job details As an Application Security Leader, you will define security requirements, drive secure coding practices, oversee vulnerability management, and integrate security testing and automation into…HELPNETSECURITY.COM
24 JunRisky Business #843 -- Fortibleed is kinda awesome, actuallyOn this week’s show special guest co-host Rob Joyce joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. Rob served as an advisor to Donald Trump during his first term as president and also served at NSA for 34 years. While at the agency, Joyce led Tailor…RISKY.BIZ
24 JunPraxen: Open-source AI agent behavior verificationPraxen is an open-source tool with a simple job: it checks whether an AI agent does what it claims to do. The tool takes an agent’s declared policy, looks at how the agent operates, and points out every spot where the two drift apart. It is the reference implementation of A…HELPNETSECURITY.COM
24 JunBrinqa BYOAI lets organizations use any AI platform with trusted risk dataBrinqa BYOAI (Bring Your Own AI), a capability that enables organizations to connect any AI agent, large language model (LLM), or automation platform to Brinqa’s exposure intelligence layer. As enterprises adopt AI, they need to ensure that AI systems use accurate, up-to-date ris…HELPNETSECURITY.COM
24 JunWebinar Today: Modern Exposure Validation in the AI EraThe exploit timeline collapsed. Make sure your validation didn't. The post Webinar Today: Modern Exposure Validation in the AI Era appeared first on SecurityWeek .SECURITYWEEK.COM
24 JunKahneman, ‘Where’s Waldo’ and the Nexus pass: A CISO’s mental model for the AI eraSecurity awareness training as a defense against phishing is dead. It has been dead for a while. The industry never held a funeral because the training budget is comfortable, the compliance box gets checked and no CISO wants to tell the board that the program everyone funds does …CSOONLINE.COM
24 JunThe Strategic Human Firewall as AI Impacts Regulations, Cyber Pros, and Employees - BSW #453The 2026 Verizon DBIR has arrived and the results are in... Even with a substantial increase in Exploitation of Vulnerabilities, All Credential Abuse is still the top initial access vector for breaches, which means the human is still the weakest link. Why haven't security awarene…YOUTUBE.COM
24 JunOpen-source security is posing challenges governments can’t easily solveA diffuse landscape, fruitful targets, companies not stepping up, AI’s influence and flagging U.S. government efforts all figure into a shifting threat. The post Open-source security is posing challenges governments can’t easily solve appeared first on CyberScoop .CYBERSCOOP.COM
24 JunLastPass customer data exposed through Klue supply chain attackLastPass disclosed that attackers used OAuth tokens compromised in a supply chain attack on Klue, a market intelligence platform that integrates with CRM and sales tools across organizations, to access customer data stored in its Salesforce environment. “On June 12th LastPass was…HELPNETSECURITY.COM
24 JunHow a malicious AI agent skill passed security checks and reached 26,000 usersA fake AI agent skill that passed security checks reached over 26,000 users through Instagram, highlighting new risks as enterprises rely on AI-driven tools. Some of the agents involved were tied to corporate accounts, AIR said . The company said a similar attack could have expos…CSOONLINE.COM
24 JunExploitable CI/CD Vulnerabilities Expose Millions of Repositories to HijackingThe security defects allow unauthenticated users to take control of the open source software supply chain. The post Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking appeared first on SecurityWeek .SECURITYWEEK.COM
24 JunBeyondTrust, LastPass Impacted by Klue-Salesforce IncidentOver a dozen Klue customers have confirmed that hackers stole data from their Salesforce instances. The post BeyondTrust, LastPass Impacted by Klue-Salesforce Incident appeared first on SecurityWeek .SECURITYWEEK.COM
24 JunApple's MacOS Gap Lets Users Disable Security ToolsAttackers can exploit the issue to disable security and integrated browser tools without needing administrator privileges or kernel exploits.DARKREADING.COM
24 JunIn a first, a court takedown goes after two cybercrime tools at onceMicrosoft, with law enforcement and industry partners, disrupted more than 200 command and control servers for Amadey and StealC, often used in conjunction. The post In a first, a court takedown goes after two cybercrime tools at once appeared first on CyberScoop .CYBERSCOOP.COM
24 JunCordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain AttacksCybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source supply chains. The "critical exploitable pattern" has been codenamed Cordyceps by Novee Security. The issue can allow full attacker c…THEHACKERNEWS.COM
24 JunmacOS Weaknesses Chained to Silently Disable Endpoint Security AgentsA standard non-admin account is sufficient to conduct an attack that exploits legitimate OS behavior rather than software vulnerabilities. The post macOS Weaknesses Chained to Silently Disable Endpoint Security Agents appeared first on SecurityWeek .SECURITYWEEK.COM
24 JunCISA warns of max severity Ubiquiti flaws exploited in attacksThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of hackers actively exploiting flaws in Ubiquity UniFi OS and Lantronix serial-to-ethernet servers. [...]BLEEPINGCOMPUTER.COM
24 JunMicrosoft and Allies Smash Shared Infrastructure of Amadey and StealC MalwareHundreds of C&C servers were disrupted in an operation involving law enforcement and several cybersecurity companies. The post Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware appeared first on SecurityWeek .SECURITYWEEK.COM
24 JunAmadey, StealC, and SocGholist malware disrupted by ‘Operation Endgame’A coordinated international law enforcement and private-sector operation has dismantled major parts of the infrastructure behind the SocGholish, Amadey, and StealC malware families, seizing more than €41 million ($47 million) in cryptocurrency and disrupting hundreds of servers t…CYBERINSIDER.COM
24 JunLaw enforcement hits StealC and Amadey malware networksOperation Endgame, the largest international law enforcement operation aimed at disrupting ransomware and cybercrime infrastructure across the world, has claimed its latest targets: StealC and Amadey. The notice on disrupted websites (Source: Microsoft) While developed by separat…HELPNETSECURITY.COM
24 JunLastPass says Klue breach affected customer information, but passwords remain secure.Attackers begin exploiting Cisco Unified CM vulnerability. Alleged criminal marketplace administrator extradited to the US. Business news: Accenture acquires Dragos, runZero, and NetRise for more than $4 billion.THECYBERWIRE.COM
24 JunAmadey and StealC Malware Network Disrupted, 27M Stolen Credentials RecoveredA coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft, has resulted in the takedown of criminal infrastructure powering Amadey and StealC. "The main common goal was to disrupt the 'assembly line…THEHACKERNEWS.COM
24 JunScattered Spider duo convicted over $38M Transport for London attackTwo members of the Scattered Spide r cybercrime collective have admitted launching a cyberattack against Transport for London (TfL) that caused millions in damages. Thalha Jubair, 20, from East London, and Owen Flowers, 18, from Walsall, West Midlands, were due to stand trial for…CSOONLINE.COM
24 JunRansomware Will Hit You TwiceRansomware incidents are often treated as one-time events: pay, decrypt, recover, move on. But this conversation challenges that assumption. If the underlying vulnerability or access path isn’t fixed, attackers can return quickly and repeat the attack. In some scenarios, paying a…YOUTUBE.COM
24 JunWhen Information Becomes the Attack Surface – Understanding AI Agent TrapsFrom hidden content injections to cognitive state poisoning, attackers are turning trusted data sources into traps for autonomous AI. The post When Information Becomes the Attack Surface – Understanding AI Agent Traps appeared first on SecurityWeek .SECURITYWEEK.COM
24 JunMalicious hackers exploit Cisco zero-day for highest access level at communications service providerMandiant detailed the incident in a blog post Wednesday, but it’s unclear who was behind it or if they managed to get broad visibility into the victim’s internal traffic. The post Malicious hackers exploit Cisco zero-day for highest access level at communications service provider…CYBERSCOOP.COM
24 JunRestrict AWS Management Console access to expected networks with sign-in resource-based policies and RCPsAmazon Web Services (AWS) recently announced support for resource-based policies and resource control policies (RCPs) for AWS Sign-In. By using resource-based policies and RCPs, you can restrict access to the AWS Management Console sign-in and aws login CLI sessions to requests f…AWS.AMAZON.COM
24 Jun KEVKlue me in on the breach.LastPass says Klue breach affected customer information, but passwords remain secure. Attackers begin exploiting Cisco Unified CM vulnerability. CISA flags actively exploited Ubiquiti and Lantronix flaws, urges rapid patching. DifyTap flaws could expose private AI conversations a…THECYBERWIRE.COM
24 JunThree ‘cybercrime as a service’ operations undercut by Microsoft, law enforcementMicrosoft touted its latest action against malware infrastructure as a new approach aimed at the full cybercrime "supply chain." Europol said more than 300 servers were targeted.THERECORD.MEDIA
24 JunCNAPP evolution: How Microsoft aligns with leading cloud risk management platformsLearn how CNAPP platforms are helping organizations prioritize exploitable risks, reduce exposure, and operationalize security across the application lifecycle. The post CNAPP evolution: How Microsoft aligns with leading cloud risk management platforms appeared first on Microsoft…MICROSOFT.COM
23 JunChange your cyber risk strategy to meet AI threats, Five Eyes countries warn CSOsCSOs must re-write their cyber risk strategies because threat actors are increasing using AI to evade defenses, says a group of national cybersecurity agencies – a call that one expert immediately complained is too vague to be of use. In its call to action on Monday , the group w…CSOONLINE.COM
23 JunFree, no-signup World Cup streams serve scams instead of footballResearchers at Malwarebytes identified dozens of websites claiming to offer free access to FIFA World Cup matches. Instead of streaming games, the sites directed visitors through a chain of advertising pages designed to generate revenue for their operators. Fake World Cup streami…HELPNETSECURITY.COM
23 JunA $1,400 experiment in AI security auditing outperformed OpenAI’s Codex SecurityA research team has built a system that teaches AI agents to hunt for software bugs by writing the audit method down as plain text. The system, called EVOHUNT, keeps the underlying AI model fixed and improves only an external “playbook” that tells the agent how to wor…HELPNETSECURITY.COM
23 JunResidential proxy SDKs are hiding in LG and Samsung smart TV appsSmart TVs in living rooms run small apps that show fish tanks, clocks, solitaire games, and slideshows of puppies. A share of those apps can also send other people’s internet traffic out through the home connection. Spur Intelligence scanned 6,038 apps across LG webOS and S…HELPNETSECURITY.COM
23 JunCybersecurity is no longer about protection. It’s about survival.For years, cybersecurity professionals have been repeating the same warning: Every company will eventually be breached. Fine. Let’s accept that. Then why do so many organizations still behave as if the near sole purpose of cybersecurity is to prevent the breach from ever happenin…CSOONLINE.COM
23 JunOpenAI wants AI to fix vulnerabilities, not just find themOpenAI expanded Daybreak, its cybersecurity initiative that combines AI models, Codex Security, security researchers, maintainers, industry partners, and access controls to support vulnerability discovery and remediation. Organizations can use the initiative to identify, validate…HELPNETSECURITY.COM
23 JunPhishing hides in routine Microsoft 365 workflowsAttackers are abusing Outlook Groups and Microsoft 365 collaboration features to make phishing campaigns appear routine, according to Fortra. “The technique shifts malicious intent away from a single phishing email into a trusted productivity workflow. A user may see what l…HELPNETSECURITY.COM
23 JunHow AI Is Reshaping Identity Security at the Infrastructure Layer - Ev Kontsevoy, Neha... - ASW #388Appsec has seen machine identities from daemons and processes to services, microservices, and cloud accounts. And now we have agents. Ev Kontsevoy talks about what it means to have engineers and agents interacting in an environment, and why a focus on actions can be more effectiv…YOUTUBE.COM
23 JunHack The Box adds crisis simulations and SOC training to strengthen cyber readinessHack The Box (HTB) has announced new capabilities to help security leaders gain greater visibility into skills, performance and operational readiness. As AI transforms cyberattacks and cybersecurity operations, HTB is expanding its cyber readiness platform to help organizations i…HELPNETSECURITY.COM
23 JunOpenAI rolls out AI-led push to fix open-source software flawsOpenAI has launched a program with cybersecurity firm Trail of Bits to use AI to find and fix vulnerabilities in widely used open-source software, as enterprises face growing risks from flaws buried deep in their software supply chains. The initiative, called Patch the Planet , u…CSOONLINE.COM
23 JunPutin’s Paramilitary 2.0Since its emergence in 2014, the Wagner Group operated as the Kremlin's shadow army, deploying mercenaries across Africa and the Middle East. It gave Vladimir Putin plausible deniability, expanding Moscow's geopolitical influence by propping up leaders through military assistance…THECYBERWIRE.COM
23 JunLastPass says customer data exposed in Klue supply chain breachLastPass has disclosed that customer contact and CRM data were exposed after attackers compromised Klue, a third-party market intelligence platform used by its go-to-market teams. According to a security advisory published by LastPass, the company was notified on June 12 about a …CYBERINSIDER.COM
23 JunFFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS AppliancesAttackers can send crafted media files to execute code in any application that uses FFmpeg’s libavcodec library. The post FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances appeared first on SecurityWeek .SECURITYWEEK.COM
23 JunUnpatched SharePoint servers opened the door to multiple attackers, Microsoft findsWhat began as a routine ransomware investigation uncovered two unrelated attackers operating inside the same victim network at the same time, each obscuring the other’s activity and complicating the response. The discovery emerged during a Microsoft Detection and Response Team (D…CSOONLINE.COM
23 JunWhat the Miasma campaign reveals about the new supply chain threat model and the underground market for developer credentialsA stolen session cookie sat in underground markets for seven weeks before attackers used it to poison 32 Red Hat packages in the npm software registry, an example of the industrial approach behind modern supply chain attacks. Key takeaways Miasma is a self-propagating npm worm de…TENABLE.COM
23 JunEight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel AttacksThe high-severity use-after-free vulnerability in Samsung's KNOX security framework affected Android-powered Galaxy devices from the S9 through S25. The post Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
23 JunAlgerian Man Extradited to US for Running Cybercrime Marketplaces26-year-old Abdellah Belmili faces up to 30 years in prison for allegedly operating the marketplaces Market0Day and Spoxy. The post Algerian Man Extradited to US for Running Cybercrime Marketplaces appeared first on SecurityWeek .SECURITYWEEK.COM
23 JunLastPass confirms data breach in Klue supply chain attackLastPass announced that hackers accessed customer data from its Salesforce environment after stealing the company's OAuth tokens in the Klue supply chain attack earlier this month. [...]BLEEPINGCOMPUTER.COM
23 JunUsing Reddit to manipulate AI search results is surprisingly easyA Reddit comment that takes only a few seconds to write can end up influencing the answers generated by AI research tools. A Cornell Tech study found that a short snippet of user-generated text, sometimes as little as 13 words, was enough to affect the output of deep-research age…HELPNETSECURITY.COM
23 JunGitHub Updates actions/checkout to Block Common Pwn Request Attack PatternsGitHub is moving to strengthen software supply chain security by updating "actions/checkout" to block pwn request attacks that exploit the risky use of the "pull_request_target workflow" trigger to run malicious code with the workflow's full privileges. Effective June 18, 2026, t…THEHACKERNEWS.COM
23 JunThe Exploit Doesn't Exist. You Can Still Prove It Works Against YouAttackers can now weaponize newly disclosed vulnerabilities far faster than most organizations can patch them. Picus Security explains how security teams can validate exploitability before a public exploit even exists. [...]BLEEPINGCOMPUTER.COM
23 JunFive Eyes allies warn of dangers posed by frontier AI models.Researchers publish a new analysis of FortiBleed. BootROM exploit can bypass Apple's SecureROM. Scattered Spider members plead guilty in the UK.THECYBERWIRE.COM
23 JunKlue investigating supply chain attack that targeted Salesforce integrationsCustomer data from several prominent cybersecurity firms was among that of hundreds of potential enterprise victims.CYBERSECURITYDIVE.COM
23 JunWhy SIEM is Moving Toward Unified Security Operations: Rapid7 Named a Major Player in IDC MarketScapeRapid7 has been named a Major Player in the IDC MarketScape: Worldwide SIEM 2026 Vendor Assessment (#US54126826, June 2026). This is the first IDC SIEM MarketScape to bring the enterprise and SMB markets into a single evaluation, and we believe it arrives at a time when the way t…RAPID7.COM
23 JunTrump sets post-quantum crypto deadlines, launches broader federal quantum initiativeUS President Donald Trump on Monday signed a pair of executive orders aimed at accelerating the federal government’s transition to post-quantum cryptography while expanding US investment in quantum technologies, establishing what the administration describes as a coordinated stra…CSOONLINE.COM
23 JunAll eyes on AI.Five Eyes warns AI could supercharge cyberattacks within months. Tata Electronics confirms breach as stolen data allegedly includes Apple and Tesla documents. Researchers publish new analysis of FortiBleed. Gizmodo breach exposes readers to ClickFix malware campaign. BootROM expl…THECYBERWIRE.COM
23 JunTuring, BODS, Struwwelpeter, EO-14409, VBScript, Pixemsmash, Cloudflare, Aaran Leylan - SWN #592Turing's Entscheidungsproblem, BODS, Struwwelpeter, EO-14409, VBScript, Pixemsmash, Cloudflare, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-592YOUTUBE.COM
23 JunScope of Salesforce Attacks Expands as Icarus Leaks DataMore victims have emerged after attackers breached application vendor Klue and used its OAuth tokens to steal customers' Salesforce data.DARKREADING.COM
22 JunStolen OAuth Tokens Hit Security Firms, AryStinger Router Botnet Emerges, AI Deepfake CyberstalkingA breach at market intelligence platform Klue allowed attackers to steal OAuth tokens linking Clue to customers' Salesforce environments, enabling quiet API-driven data extraction from firms including Huntress, Recorded Future, Tanium, and Jamf; Clue revoked tokens, removed the l…CYBERSECURITYTODAY.LIBSYN.COM
22 JunWhy Southeast Asia CISOs Need Zero Trust as Their AI Control Plane – AI Agents, Data Borders and Supply ChainsAt Zenith Live 2026 held on 16-17 June in Vienna, Zscaler sharpened a reality that Southeast Asia CIOs and CISOs are already sensing, which are, AI agents are quickly becoming digital workers inside their organisations, while regulators tighten data residency rules and supply‑cha…CSOONLINE.COM
22 JunHundreds of AI-powered iOS apps found exposing credentialsMobile app developers are packing AI features into everything from writing assistants to productivity tools and lifestyle apps. New research shows that securing access to those services remains a challenge. LLM API credential leakage via network traffic interception (Source: Rese…HELPNETSECURITY.COM
22 JunAgent Beacon: Open-source telemetry layer for AI agentsAI coding agents such as Claude Code, Codex CLI, Cursor, and Claude Cowork run on developer laptops, CI jobs, cloud environments, where they edit files, run commands, and call outside tools. Beacon, an open-source project from Asymptote Labs, configures telemetry for those runtim…HELPNETSECURITY.COM
22 JunAnatomy of a retail ransomware attack: Tabletop simulates modern mayhem methodsAttacks on AI systems and disinformation starred as key elements of a ransomware tabletop exercise CSO participated in during this month’s Infosecurity Europe conference. The “Enter the War Room” exercise — organised and run by cybersecurity vendor Semperis — featured a scenario …CSOONLINE.COM
22 Jun6 security leader tips for mastering business riskLongtime security leader Doug Kersten has expanded his list of responsibilities. As CISO of software maker Appfire, he now has accountability for business risks, such as how security tools and processes within customer products and services impact their costs and, thus, profitabi…CSOONLINE.COM
22 JunNavigating Shadow AI in the Enterprise, Verizon's SECOND 2026 report, and the news - ESW #464Interview with Ankita Gupta, CEO of Akto _How to Navigate Shadow AI Risk in the enterprise_ This week, we discuss AI governance in the enterprise, starting with the nuts and bolts of how to discover and understand shadow AI. Following that, we dive into what security and tech lea…YOUTUBE.COM
22 JunKlue Breach Enables Hackers to Compromise Cybersecurity Firms via OAuth TokensAt least five cybersecurity firms confirmed they have been affected by a breach of business intelligence platform Klue via Salesforce integrationINFOSECURITY-MAGAZINE.COM
22 JunWhat the Latest ShinyHunters Breaches Reveal About Modern CyberattacksGroups like ShinyHunters are demonstrating that attackers do not necessarily need malware or zero-day exploits to cause massive damage. The post What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks appeared first on SecurityWeek .SECURITYWEEK.COM
22 JunNew Exploit Bypasses Apple’s Boot Defenses, Affects Millions of iPhonesThe vulnerability exploited by the Usbliter8 exploit cannot be patched and a PoC exploit has been released by researchers. The post New Exploit Bypasses Apple’s Boot Defenses, Affects Millions of iPhones appeared first on SecurityWeek .SECURITYWEEK.COM
22 JunAttackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress DataVulnerable WordPress plugin iterations leak API keys, secrets, tokens, server information, and other data. The post Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data appeared first on SecurityWeek .SECURITYWEEK.COM
22 JunNew OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealerCybersecurity researchers have disclosed details of a new campaign that delivers CastleStealer by means of a previously unreported malware loader dubbed OXLOADER. According to Elastic Security Labs, the campaign leverages malicious Google Ads as a starting point to distribute the…THEHACKERNEWS.COM
22 JunThe Hidden Risk of Shadow AIShadow AI now includes far more than employees casually using ChatGPT. Organizations are seeing AI agents, MCPs, LLMs, and AI databases quietly appear across enterprise environments. The danger isn’t necessarily the technology itself. It’s visibility. Security teams often have no…YOUTUBE.COM
22 JunUnpatchable BootROM Flaw Impacts Apple A12, A13 ChipsApple BootROM exploit exposes unpatchable USB flaw on A12 and A13 devicesINFOSECURITY-MAGAZINE.COM
22 JunDecades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User DataSquidbleed, discovered with the aid of Claude Mythos Preview, has been described as a Heartbleed-style vulnerability. The post Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data appeared first on SecurityWeek .SECURITYWEEK.COM
22 Jun29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP RequestsA heap over-read in the Squid web proxy can leak another user's cleartext HTTP request, including any credentials or session tokens it carries, to anyone already allowed to send traffic through the same proxy. The bug traces to a 1997 FTP-parsing change and is still live in Squid…THEHACKERNEWS.COM
22 JunResearchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across TenantsCybersecurity researchers have disclosed details of four vulnerabilities in Dify, an open-source agentic workflow platform with more than 146,000 GitHub stars, that could allow attackers to stealthily read artificial intelligence (AI) conversions from other customers' application…THEHACKERNEWS.COM
22 JunAWS Continuum offers devs help with securing codeAI coding agents are making it easier than ever to produce software. Ensuring that software is secure before deployment is another matter — one that AWS thinks AI should help with too. As enterprises adopt agentic development workflows, the volume of first-party code being create…CSOONLINE.COM
22 JunKlue breach exposed Salesforce CRM data through stolen OAuth tokensAn attacker broke into competitive-intelligence vendor Klue, stole OAuth tokens its customers use to connect to Salesforce and other platforms, and accessed data across multiple customer environments prompting the company to revoke customer OAuth tokens and disable affected integ…CSOONLINE.COM
22 JunIntroducing Patch the PlanetWhat happens when you clear dozens of Trail of Bits engineers’ schedules, pair them with every open-source maintainer they can contact, and unleash the latest frontier models like GPT-5.5-Cyber on critical open-source targets? Thanks to our partnership with OpenAI and its Daybrea…TRAILOFBITS.COM
22 JunOpenAI Launches Full-Scale Effort to Patch Open-Source Bugs as It Takes on Anthropic’s MythosAmid concerns about AI models’ cybersecurity capabilities, OpenAI revealed an improved version of GPT-5.5-Cyber and its “Patch the Planet” initiative to fix open-source software bugs.WIRED.COM
22 JunMicrosoft fixes AutoGen Studio flaw that enabled code executionA vulnerability chain dubbed AutoJack in Microsoft's AutoGen Studio interface for prototyping AI agents could let attackers manipulate an agent into executing arbitrary commands on its host system simply by visiting a malicious webpage. [...]BLEEPINGCOMPUTER.COM
22 JunA new unpatchable flaw in Apple chips opens the door to an iPhone jailbreakEuropean offensive cybersecurity company Paradigm Shift released details of a flaw and a technique to exploit it that opens the door for hackers to unlock and break into older iPhones.TECHCRUNCH.COM
22 JunAI Guardrails Could BackfireAs commercial AI systems add more restrictions and moderation layers, some users are already moving toward open-source alternatives that offer fewer limitations and more control. The argument here is simple: once AI capability exists publicly, it becomes extremely difficult to su…YOUTUBE.COM
22 JunTrump administration to order agencies to speed up post-quantum migration, boost industryBoth EOs are expected to be signed as soon as Monday per an industry source with knowledge of timing. The White House has a signing ceremony scheduled this afternoon. The post Trump administration to order agencies to speed up post-quantum migration, boost industry appeared first…CYBERSCOOP.COM
22 JunFFmpeg fixes PixelSmash flaw in widely used video decoderA newly disclosed FFmpeg flaw dubbed 'PixelSmash' could be exploited for remote code execution on Jellyfin servers under certain conditions, and can also trigger a denial-of-service condition in applications like Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio. [...]BLEEPINGCOMPUTER.COM
22 JunThe Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data ExfiltrationUnit 42 research details how attackers could exploit global name uniqueness in bucket hijacking to redirect cloud data streams across major CSPs. The post The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
22 JunGitHub Actions hardens checkout security to block ‘pwn request’ attacksStung by a surge in cyberattacks that have run amok in developer environments, GitHub has strengthened the security of actions/checkout to block ‘pwn request’ attacks that exploit insecure use of the pull_request_target workflow trigger to run an attacker’s code with the workflow…CSOONLINE.COM
21 JunVulnerability response: Built for humans, outpaced by machines.For years, security teams had time between discovery and exploitation. Time to triage. Time to validate. Time to prioritize what to fix first. AI has compressed that window. Frontier models now discover and chain vulnerabilities faster than human analysts can confirm them, and th…THECYBERWIRE.COM
21 JunWeek in review: 74k Fortinet firewall credentials stolen, Splunk Enterprise RCE under active attackHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: A hardware neural network backdoor that hides in plain sight Deep learning systems on edge devices often rely on third-party-designed FPGAs and ASICs for performance and efficiency, …HELPNETSECURITY.COM
20 Jun5 People You Meet In Cybersecurity - David Shipley Interviews Amy LeeIn this special Cybersecurity Today weekend interview, host David Shipley speaks with Amy Yee about leadership, resilience, and the human side of cybersecurity. Amy shares her remarkable journey from electrical engineering and venture capital to becoming the inaugural Chief Digit…CYBERSECURITYTODAY.LIBSYN.COM
20 JunUnpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot ChainSecurity researchers at Paradigm Shift have published a working exploit, dubbed usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple's A12 and A13 chips. That code is burned into the silicon at manufacture. No software update can reach it…THEHACKERNEWS.COM
20 JunJCPenney - 368,418 breached accountsIn June 2026, retailer JCPenney and associated brands were targeted in a ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from JCPenney through the exploitation of a critical zero-day vulnerability in Oracle PeopleSoft was later published publicly. The expo…HAVEIBEENPWNED.COM
20 JunPeeling back Banana RAT.This week, we are joined by Tom Kellermann, Trend Micro's VP of AI Security and Threat Research, discussing their work on "Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud." Researchers from Trend Micro's MDR team uncovered the full operation behind Banana…THECYBERWIRE.COM
20 JunAnthropic suspends Fable over US national security concerns.ShinyHunters leaks data allegedly stolen from Madison Square Garden. Law enforcement cleans up 15,000 malware-infected websites.THECYBERWIRE.COM
19 JunFriday Squid Blogging: Victims of Unregulated Squid FishingDolphins, sharks, turtles, and human workers are all victims of unregulated squid fishing fleets. Another news article . As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.SCHNEIER.COM
19 JunAutoJack Attack Lets One Web Page Hijack AI Agent for Host Code ExecutionMicrosoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote code execution. Steer the agent to load an attacker's web page, and that page's JavaScript can reach a privileged local service on the sam…THEHACKERNEWS.COM
19 JunOperation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress SitesDutch law enforcement authorities, along with counterparts from Canada , Germany, and the U.S., have disrupted malicious infrastructure associated with SocGholish and cleaned up nearly 15,000 infected WordPress websites. "With these actions we deprive cybercriminals of access to …THEHACKERNEWS.COM
19 JunSalesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer DataSalesforce has revealed that it disabled the Klue Battlecards app integration within its platform in response to a security incident impacting the competitive intelligence company on June 11, 2026. To that end, organizations will be unable to connect to Salesforce via the app unt…THEHACKERNEWS.COM
19 JunThreat actor adds advanced ‘EDR killer’ tools to ransomware-as-a-service platformOne of the world’s top ransomware groups has given its criminal affiliates access to advanced tools capable of successfully disabling many of today’s enterprise endpoint detection and response (EDR) products, new research by security company ESET has found. The group in question …CSOONLINE.COM
19 JunBreaking the SOC triangle: How AI reshapes security operations trade-offsA simple framework has always governed security operations that I call the SOC Triangle. It is a balance between quality, consistency and cost efficiency. Every SOC operates within it. Push for higher-quality investigations, deeper analysis, richer context, fewer missed signals a…CSOONLINE.COM
19 JunSecurity considerations for adopting Claude Code and Cowork for SMBsYou are a security leader at a small or medium-sized business (SMB), and your organization has decided to adopt Claude. If you are like me, after the initial “surprise” wears off, you probably want to quickly get your arms around what adopting Claude means for the business, and f…CSOONLINE.COM
19 JunMicrosoft says web-enabled AI agents can trigger host-level RCEMicrosoft is warning of a novel remote code execution (RCE) path possible through web-enabled AI agents, demonstrating the technique against AutoGen Studio, its open-source interface for building and testing multi-agent applications. The demonstration showed that a malicious webp…CSOONLINE.COM
19 JunLLMS, Identity, EDR, JiGong, QiLin, Warlock, with Rob Allen from Threatlocker - SWN #591Doug and Rob Allen talk about Identity, EDR, Your Great Aunt Ida Meets some hot firefighters, and more. Segment Resources: Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools: https://thehackernews.com/2026/04/qilin-and-warlock-ransomware-use.html This s…YOUTUBE.COM
19 JunMost Companies Needed To Be Forced#PCI #ComplianceThe clip argues that standards like PCI helped push organizations toward foundational cybersecurity practices by tying security requirements directly to payment processing and business operations. For many companies, compliance became the forcing function that mov…YOUTUBE.COM
19 JunApple patches Beats Studio Buds flaw that could turn earbuds into a wiretapApple has patched a year-old Bluetooth vulnerability that could have let nearby attackers listen through Beats Studio Buds' microphone.MALWAREBYTES.COM
19 JunCyberWire Daily at 10: A decade of leaks, espionage, and influence operations.In this special edition of CyberWire Daily’s 10th anniversary series, N2K CyberWire's ⁠Maria Varmazis⁠ and ⁠Dave Bittner⁠ discuss leaks, espionage and influence operations over the past 10 years. Together they reflect on a decade of cybersecurity developments, focusing on the piv…THECYBERWIRE.COM
19 JunAWS Unveils 'Continuum,' an AI-Powered Vulnerability Management PlatformWorking with frontier AI models, this new platform aims to help discovering, prioritizing, validating and remediating code vulnerabilitiesINFOSECURITY-MAGAZINE.COM
19 JunUnpatchable BootROM exploit for Apple A12-A13 chips now publicSecurity researchers at Paradigm Shift have disclosed usbliter8, a new SecureROM exploit affecting Apple's A12 and A13 chipsets. The proof-of-concept exploit achieves BootROM compromise through a combination of a USB controller hardware bug and a firmware configuration weakness, …CYBERINSIDER.COM
19 JunTexas exposed data of 3 million hunting and fishing license holdersThe Texas Parks and Wildlife Department (TPWD) has disclosed a cybersecurity incident affecting its hunting and fishing license system vendor, potentially exposing the personal information of more than 3 million people. The incident was identified by the Texas Cyber Command, whic…CYBERINSIDER.COM
19 JunKlue OAuth breach victim list grows as Icarus hackers claim attackMarket intelligence platform Klue has publicly confirmed a recent security incident that allowed threat actors to steal OAuth tokens used to connect to customers' Salesforce environments, as the new "Icarus" extortion group publicly claims the attack. [...]BLEEPINGCOMPUTER.COM
19 JunHackers exploit info disclosure bug in Gravity SMTP WordPress pluginThreat actors are exploiting an unauthenticated information disclosure vulnerability in the WordPress plugin Gravity SMTP, active on 100,000 sites. [...]BLEEPINGCOMPUTER.COM
19 JunTexas govt data breach exposes over 3 million driver’s licensesThe Texas Parks and Wildlife Department (TPWD) disclosed a data breach at its license system vendor that exposed personal information for more than three million individuals. [...]BLEEPINGCOMPUTER.COM
19 Jun KEVCISA: Splunk Enterprise flaw actively exploited, patch by SundayCISA has urged U.S. federal agencies to secure their systems by Sunday against a critical Splunk Enterprise vulnerability that is being exploited in attacks. [...]BLEEPINGCOMPUTER.COM
19 JunIn Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS ContinuumOther noteworthy stories that might have slipped under the radar: Android TV botnet Popa linked to Israeli firm, Velvet Ant maintained decade-long stealth, unpatched GCP Config Connector flaw enables takeover. The post In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Cl…SECURITYWEEK.COM
19 JunCryptoBandits Malware Doubles as a Backdoor, Abuses TorCryptoBandits uses a local SOCKS5 proxy for traffic routing, blending data theft with remote code execution. The post CryptoBandits Malware Doubles as a Backdoor, Abuses Tor appeared first on SecurityWeek .SECURITYWEEK.COM
19 JunCybersecurity Firms Impacted by Klue Supply Chain AttackThe hackers exfiltrated data from Salesforce instances of Klue customers, such as Huntress and Recorded Future. The post Cybersecurity Firms Impacted by Klue Supply Chain Attack appeared first on SecurityWeek .SECURITYWEEK.COM
19 Jun15,000 WordPress Websites Cleaned Up in SocGholish Botnet TakedownLaw enforcement and private partners took down 106 SocGholish C&C servers and domains as part of Operation Endgame. The post 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown appeared first on SecurityWeek .SECURITYWEEK.COM
19 JunKlue breach lead to Salesforce data theft, Huntress affectedCybersecurity vendor Huntress was among multiple companies hit by a breach originating at Klue, a market intelligence platform used to integrate CRM and sales data across various business tools. Huntress published a detailed account of the incident on June 18, framing it as a …HELPNETSECURITY.COM
19 JunMastodon 4.6 adds profile Collections and two-factor controlsPeople who run accounts on the open source social network Mastodon can now group profiles together and share those groups across the web. The 4.6 release centers on a feature called Collections, along with reworked profiles, email newsletters, server administration controls, and …HELPNETSECURITY.COM
19 JunGoogle sets timeline for Android developer verification enforcementAndroid’s developer verification protections will take effect on September 30, 2026, starting with users in Brazil, Indonesia, Singapore, and Thailand. Developers distributing apps through participating stores in those markets must complete the verification process by the deadlin…HELPNETSECURITY.COM
19 JunCompanies are discarding the logs they need to catch a breachMany large enterprises discard most of the log data their systems generate, and they do it on purpose to keep costs down. A Dynatrace survey of 450 senior IT leaders at large enterprises found that half of organizations drop or never collect an average of 86 percent of their logs…HELPNETSECURITY.COM
19 JunAutoJack: How a single page can RCE the host running your AI agentAutoJack is a novel exploit chain showing how a single malicious webpage can turn an AI browsing agent into a remote code execution vector on the host machine. By abusing trust in localhost, missing authentication, and unsafe parameter handling, attackers can trigger arbitrary pr…MICROSOFT.COM
18 JunThe Behavior of Coordinated SSH Brute Force Attacks over the last three months &#x5b;Guest Diary&#x5d;, (Wed, Jun 17th)[This is a Guest Diary by Adam Nason, an ISC intern as part of the SANS.edu BACS program] ISC.SANS.EDU
18 JunMost agentic AI projects in production have stalled over data problemsEnterprises are connecting AI agents to live data feeds and putting them to work on tasks that once required human review, from IT operations to software development. The number doing this in production reached 32 percent in 2026, up from 29 percent the year before, according to …HELPNETSECURITY.COM
18 JunCan Agentic AI Really Find Zero-Days? Ask the Hacker Who Won Pwn2Own Berlin 2026At Pwn2Own Berlin 2026, a security researcher used agentic AI to help her win. The AI surfaced real, verified bugs, then wrongly called her winning bug “not unexploitable in practice.” Spoiler - it was.That uneven record is exactly what security leaders need to understand about t…THECYBERWIRE.COM
18 JunNever gonna give you up, never gonna take this call.This week, hosts of N2K CyberWire ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Maria Varmazis⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ …THECYBERWIRE.COM
18 JunAWS Continuum brings AI models to code vulnerability managementAWS Continuum for code vulnerabilities, a system built to handle a vulnerability across its lifecycle, from discovery through to a fix, is now available in gated preview. It reasons over a customer’s environment, confirms which findings are real, and works toward resolution…HELPNETSECURITY.COM
18 JunGoogle’s open standard for AI agents to discover and verify toolsAI agents depend on tools, skills, and other agents spread across many teams, organizations, and platforms. These capabilities live in separate systems with their own registries, and an agent working in one environment has limited means to locate and connect to a resource hosted …HELPNETSECURITY.COM
18 JunCybersecurity was built for predictable systems. AI changes the rulesEvery major technology shift changes cybersecurity. I’ve spent much of my career working through major technology transitions, from the rise of the commercial internet to mobile and cloud computing. Each shift created new opportunities for innovation, but it also created new secu…CSOONLINE.COM
18 JunNew CISO appointments 2026The upper ranks of corporate security are seeing a high rate of change as companies try to adapt to the evolving threat landscape. Many companies are hiring a chief security officer (CSO) or chief information security officer (CISO) for the first time to support a deeper commitme…CSOONLINE.COM
18 JunMicrosoft warns of USB worm-like malware using Tor for stealthMicrosoft has identified a cryptocurrency clipper malware campaign, active since February 2026, that combines USB-based propagation, a Tor-hidden command-and-control infrastructure, and remote code execution capabilities. The malware steals cryptocurrency seed phrases and private…CYBERINSIDER.COM
18 JunCritical Command Execution Vulnerability Patched in Cisco ISEInsufficient validation of user input allows an attacker to gain access to the underlying OS and elevate their privileges to root. The post Critical Command Execution Vulnerability Patched in Cisco ISE appeared first on SecurityWeek .SECURITYWEEK.COM
18 Jun KEVFortiBleed campaign exposes 75,000 Fortinet firewalls worldwideA massive credential-compromise campaign dubbed “Fortibleed” has been found to expose tens of thousands of Fortinet devices worldwide, with researchers warning of persistent attacker access to affected enterprise environments. The campaign was first flagged by security researcher…CSOONLINE.COM
18 JunLATAM Infrastructure Hit by Fortinet and Ivanti ExploitsCloudSEK maps Operation Escaneo, a campaign hitting Latin American infrastructure via perimeter bugsINFOSECURITY-MAGAZINE.COM
18 JunAttackers abuse Google Ads, GitLab, and Claude to deliver malwareThreat actors are abusing trusted platforms, including Google Ads, GitLab pages, and Claude’s shared chat feature, to trick users into executing malicious commands on their systems. Disguised as popular AI developer tools, the threat actors used ClickFix social engineering attack…CSOONLINE.COM
18 JunNo Exploits RequiredFour decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures. The post No Exploits Required appeared first on SecurityWeek .SECURITYWEEK.COM
18 JuneSentire links AI-led penetration testing with MDR through Atlas PreempteSentire has announced the launch of Atlas Preempt, a component of the company’s Atlas Platform. Atlas Preempt performs continuous, AI-driven offensive testing against customer environments to identify which exposures attackers can reach and feeds that data into eSentire’s 24/7 M…HELPNETSECURITY.COM
18 JunDragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 TrafficThreat actors associated with the DragonForce ransomware have been observed using a custom Go-based remote access trojan (RAT) called Backdoor.Turn to conceal command-and-control (C2) traffic inside Microsoft Teams relay infrastructure. According to findings from Broadcom-owned S…THEHACKERNEWS.COM
18 JunMicrosoft working on a fix for RoguePlanet, a flaw that grants full PC controlMicrosoft says it's working on a fix for an unpatched Defender vulnerability that can give attackers the highest level of access on Windows.MALWAREBYTES.COM
18 JunPolice cleans nearly 15,000 SocGholish-infected sites tied to Evil CorpInternational law enforcement agencies cleaned nearly 15,000 malware-infected WordPress websites and took down more than 100 servers linked to the SocGholish botnet and the Evil Corp Russian cybercrime group. [...]BLEEPINGCOMPUTER.COM
18 JunMicrosoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2Microsoft has disclosed details of a Windows-based cryptocurrency clipper campaign that has targeted users since February 2026. "The clipper in this campaign relies on Windows Script Host and ActiveX-driven logic to launch a bundled Tor proxy and poll a hidden-service C2 [command…THEHACKERNEWS.COM
18 JunAssume You’ve Already Been HackedThe idea that an organization will “never be hacked” is becoming increasingly unrealistic. Many security teams now operate with an “assumed breach” mindset, planning around the expectation that compromise will eventually happen. That changes the entire defensive strategy. Instead…YOUTUBE.COM
18 JunKlue OAuth breach linked to 'Icarus' Salesforce data theft attacksMarket intelligence platform Klue suffered a OAuth breach that enabled the "Icarus" threat actors to steal Salesforce CRM data from multiple organizations in an ongoing extortion campaign. [...]BLEEPINGCOMPUTER.COM
18 JunLaw enforcement hits SocGholish: 106 servers down, 15,000 sites cleanedSocGholish, an operation that’s been delivering malware to users via fake software updates, has suffered a major blow: the international law enforcement coalition behind Operation Endgame has taken down 106 of its servers and domains, and cleaned up nearly 15,000 websites c…HELPNETSECURITY.COM
18 JunHow software development’s speed obsession enabled TeamPCP’s chaos crusadeThe threat group’s remarkable success targeting open-source software was inevitable and fueled by the industry’s decision to prioritize code shipping over security. The post How software development’s speed obsession enabled TeamPCP’s chaos crusade appeared first on CyberSc…CYBERSCOOP.COM
18 JunApple fixes Beats Studio Buds flaw that allowed nearby attackers to eavesdropApple has released Beats Firmware Update 1B211 to address a Bluetooth vulnerability affecting Beats Studio Buds that could allow a nearby attacker to listen through a device's microphone before it has been paired. The flaw is part of a broader set of vulnerabilities disclosed las…CYBERINSIDER.COM
18 JunWhy Security Teams Need To Start EarlierSecurity leaders are facing an unusual set of circumstances. The drumbeat for better security prioritization has been rising for years in boardrooms around the world. The desire is there, but the processes of the past aren’t meeting the needs of the new moment we find ourselves i…RAPID7.COM
18 JunThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More StoriesThe internet did not break this week. It got used exactly as designed, which is worse. Searches were siphoned through shady browser add-ons. AI chat links turned into malware delivery paths. macOS attacks ran in memory and left almost nothing behind. Cloud agents looked like help…THEHACKERNEWS.COM
18 JunLaw enforcement cleans up 15,000 malware-infected websites.Dutch police arrest alleged helpdesk scammers. The Gentlemen ransomware-as-a-service group maintains a mature suite of EDR killers.THECYBERWIRE.COM
18 Jun‘Popa’ Botnet Linked to Publicly-Traded Israeli FirmFor the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded t…KREBSONSECURITY.COM
18 JunSalesforce Data Thefts Continue via Klue App CompromiseKlue's Battlecards is now the third integrated application that has been compromised to steal customers' Salesforce data, and victims include Huntress, the cybersecurity vendor.DARKREADING.COM
18 JunClose Encounters of the Human KindIn the latest Threat Source, Hazel channels her inner Spielberg to explore why humans are delightfully irrational, reminding us that while security best practices are simple in theory, they’re a lot harder to pull off when you’re busy dealing with real life.TALOSINTELLIGENCE.COM
18 JunBuild your own vulnerability harnessWe break down the technical architecture behind our multi-stage vulnerability discovery harness and automated triage loop. Learn how we manage state controls, squash false positives through adversarial review, and route around LLM context limits.CLOUDFLARE.COM
18 JunFIFA Bug Exposed World Cup Streams to Remote TakeoverA hacker could have "Rickrolled" the World Cup — or worse — thanks to FIFA's unenforced Entra access controls.DARKREADING.COM
18 JunVU#457458: Vendor-signed UEFI applications found vulnerable to Secure Boot bypassOverview Multiple vendor-signed UEFI applications are vulnerable to Secure Boot bypass via a "Bring Your Own Vulnerable Driver" (BYOVD)-style attack. If a target system trusts the affected vendor’s certificate, an attacker can exploit these applications to execute arbitrary code …KB.CERT.ORG
18 JunBulgaria allowed surveillance tech firm to sell products to repressive regimes, report saysThe nonprofit Human Rights Watch obtained export licensing records covering 2018 through 2023, which show the Bulgarian government allowed the surveillance firm Circles to peddle the tech to law enforcement and intelligence agencies in several countries known for human rights abu…THERECORD.MEDIA
18 JunThe botnet browser blues.International law enforcement disrupts the SocGholish botnet. The UK’s cyber chief says cybersecurity is a contest, not a risk register. Ukraine joins the EU’s cyber reserve. The Gentlemen gang sharpens its ransomware toolkit. A WordPress supply chain attack spreads malware. Crit…THECYBERWIRE.COM
18 JunOperation Endgame 4.0 - 153,527 breached accountsOn 18 June 2026, the latest phase of Operation Endgame targeted the SocGholish malware operation , a prolific malware distribution network used to compromise systems and facilitate further cybercrime. Coordinated by international law enforcement agencies with support from Europol…HAVEIBEENPWNED.COM
18 JunRalph Lauren - 139,903 breached accountsIn June 2026, fashion retailer Ralph Lauren was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published hundreds of gigabytes of data they claimed was obtained from the organisation's Salesforce instance, including 140k unique email addresse…HAVEIBEENPWNED.COM
17 JunGoogle Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket SquattingA flaw in the Google Cloud Vertex AI SDK for Python let an attacker with no access to a victim's project hijack the victim's machine learning model upload and run code inside Google's serving infrastructure. Palo Alto Networks Unit 42, which found and reported the bug through Goo…THEHACKERNEWS.COM
17 JunMicrosoft says you don’t need another email security tool; experts say, not so fastDespite best efforts by defenders, malicious emails continue to slip through the cybersecurity cracks , leading some enterprises to implement a layered “defense in depth” strategy that incorporates multiple tools. Microsoft seems to be challenging this idea, revealing that there …CSOONLINE.COM
17 JunMicrosoft AntiSSRF open-source library helps block server-side request forgeryAntiSSRF is an open-source code library from Microsoft that validates URLs and network connections to reduce server-side request forgery (SSRF) risks in web applications. It supports .NET and Node.js applications and is distributed under the MIT license. The library works as a dr…HELPNETSECURITY.COM
17 Jun144 Mastra npm Packages Compromised via Hijacked Contributor AccountAs many as 144 npm packages associated with the Mastra namespace ("@mastra/*"), a popular open-source JavaScript and TypeScript framework for building artificial intelligence (AI) applications, have been compromised as part of a software supply chain attack codenamed easy-day-js,…THEHACKERNEWS.COM
17 JunHot Cybercrime Summer:  Smishing, Supply Chains, and SleuthconIn this episode of the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠⁠Sherrod DeGrippo⁠ sits down with Aurora Johnson of SpyCloud and Amitai Cohen of Wiz ahead of SleuthCon to explore two rapidly changing corners of the cybercrime landscape. Aurora breaks down the highly organiz…THECYBERWIRE.COM
17 JunJoomla, LiteSpeed Vulnerabilities Exploited in AttacksThe flaws allow attackers to execute arbitrary PHP code and gain root privileges on shared hosting servers. The post Joomla, LiteSpeed Vulnerabilities Exploited in Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
17 JunMicrosoft working on Defender patch for RoguePlanet zero-dayMicrosoft confirmed that it's working on a security patch for a Defender zero-day vulnerability named "RoguePlanet," disclosed one week ago. [...]BLEEPINGCOMPUTER.COM
17 JunChrome and Firefox Updated to Patch Critical, High-Severity VulnerabilitiesThe browser updates address multiple memory safety bugs that could potentially lead to remote code execution. The post Chrome and Firefox Updated to Patch Critical, High-Severity Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
17 Jun5 AI risk management frameworks for shoring up key gapsOrganizations racing to embed AI into business operations are realizing that the risk management frameworks they’ve relied on for decades aren’t built for the behaviors, failure modes, and ethical complexities AI systems introduce. Fortunately, a new generation of AI-specific fra…CSOONLINE.COM
17 JunMicrosoft Working on Patch for ‘RoguePlanet’ Zero-DayThe public PoC code exploits a race condition in Microsoft Defender to spawn a command prompt with System privileges. The post Microsoft Working on Patch for ‘RoguePlanet’ Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
17 JunThe Chainguard Athena coalition already shipped 2,000 patches across 500 open source projectsChainguard launched Athena, an industry coalition that pools open source vulnerability findings and remediates them under embargo before public disclosure. The group went live with more than two dozen member organizations. Founding members include BNY, Chainguard, Cisco, Cloudfla…HELPNETSECURITY.COM
17 JunThe Top 10 Attack Surface Exposures in 2026Breaches don't always start with a zero-day. An exposed admin panel can get brute-forced, or credentials reused from a previous attack. But when a vulnerability does drop — like MongoBleed earlier this year, which let attackers pull credentials and session tokens from server memo…THEHACKERNEWS.COM
17 Jun KEVCISA orders feds to patch max severity Joomla plugin flaw by FridayThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch a maximum-severity flaw in the Widget Factory Joomla Content Editor (JCE) plugin that is being actively exploited in the wild. [...]BLEEPINGCOMPUTER.COM
17 JunMicrosoft Teams Relay Servers Abused in DragonForce Ransomware AttackThe attackers deployed a new Go-based backdoor that uses Microsoft Teams servers for command-and-control. The post Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack appeared first on SecurityWeek .SECURITYWEEK.COM
17 JunAI Use by the US GovernmentOn 14 April, the Trump administration quietly acknowledged the widespread use of AI to automate government processes. The office of management and budget (OMB) disclosed a staggering 3,611 active or planned use cases for AI across the federal government. The list has ballooned by…SCHNEIER.COM
17 JunGoogle’s Vertex AI SDK could allow RCE through bucket squattingA design flaw in the Vertex AI software development kit (SDK) for Python, Google Cloud’s managed platform for building, training, and deploying AI agents, could allow hijacking and poisoning of models outside of a developer’s own Google Cloud project. According to Unit 42 researc…CSOONLINE.COM
17 JunMalware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader ChainExecutive summary Rapid7 researchers have identified a sophisticated malware campaign attributed to the threat actor "Dropping Elephant," characterized by the use of a China-themed decoy document to deliver a heavily reworked, in-memory remote access trojan (RAT). This campaign d…RAPID7.COM
17 JunFirefox AI Chatbot feature exposed users to email theft riskA vulnerability in Firefox's AI chatbot integration could allow malicious websites to inject hidden instructions into AI prompts and extract data from connected services such as email accounts. Mozilla has implemented mitigations, though the researchers who discovered the problem…CYBERINSIDER.COM
17 JunArmorCode helps product manufacturers prepare for EU Cyber Resilience Act requirementsArmorCode has announced new Cyber Resilience Act (CRA) capabilities within the ArmorCode Agentic AI Platform. The capabilities help manufacturers of products with digital elements (PDEs) prepare for the European Union’s cybersecurity regulation that will impact all sellers …HELPNETSECURITY.COM
17 JunLegit Security brings agentic AI to AppSec remediation and risk reductionLegit Security has launched new remediation agents that independently prioritize issues, generate fixes, open pull requests, and confirm results using context learned from each organization’s distinct codebase. As AI allows attackers to exploit vulnerabilities faster than ever, r…HELPNETSECURITY.COM
17 JunTenable One adds continuous security control validation to improve exposure prioritizationTenable has announced extended continuous security control and validation capabilities within the Tenable One Exposure Management Platform. With security control visibility and evidence-based, contextualized insights, Tenable One confirms which cyber exposures are accessible and …HELPNETSECURITY.COM
17 JunTigera introduces unified control plane for Kubernetes-based AI agent securityTigera has announced the general availability of Tigera Lynx, a unified control plane for Kubernetes-native AI agents. Lynx gives enterprises a single place to find every agent in their Kubernetes estate, tighten security posture, assign sandboxes, provide each agent with a crypt…HELPNETSECURITY.COM
17 JunRokarolla Android trojan targets banking and crypto users, enables device takeoverA newly discovered Android banking trojan, dubbed Rokarolla, targets 217 banking and cryptocurrency applications and can execute 137 commands on infected devices, according to researchers at Zimperium. Named after its command-and-control (C2) infrastructure, Rokarolla is primaril…HELPNETSECURITY.COM
17 JunReactive Patching Is FailingOrganizations are increasingly reconsidering support for multiple browsers as threat environments become faster and more difficult to manage. Every additional browser increases the attack surface security teams must manage. Historically, user choice often outweighed standardizati…YOUTUBE.COM
17 JunApple’s Hide My Email service will soon be easier to identify and blockApple has announced plans to consolidate the email domains used by Sign in with Apple and iCloud+ Hide My Email under a new shared domain, private.icloud.com, later this summer. The change will affect newly generated anonymous email addresses, while existing addresses will contin…CYBERINSIDER.COM
17 JunAnother healthcare firm attacked days after Novo Nordisk breachMedical technology company iRhythm Holdings disclosed a cyberattack involving certain third-party-hosted business applications that resulted in the theft of patient protected health information, proprietary data, and other personal data. The company discovered unauthorized activi…HELPNETSECURITY.COM
17 JunAttackers hit pair of critical Fortinet vulnerabilities the vendor disclosed in AprilMultiple firms have observed active exploitation of the FortiSandbox defects, and warn that the attacks originate from multiple sources, not a single campaign. The post Attackers hit pair of critical Fortinet vulnerabilities the vendor disclosed in April appeared first on CyberSc…CYBERSCOOP.COM
17 JunAI isn’t solving cybersecurity workforce woesMore than half of cybersecurity professionals say they’re thinking about leaving the industry, according to a new report.CYBERSECURITYDIVE.COM
17 JunIntroducing the Red Agent POV SeriesAn inside look at how the Red Agent, our AI-Powered Attacker, uncovers complex, exploitable risks in the wildWIZ.IO
17 JunCrypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal CommentsAn unknown threat actor has been observed leveraging paid or promoted posts on legitimate news websites to drum up buzz for their warez, according to new findings from Check Point Research. The threat actor also has at their disposal a dedicated WordPress phishing page that acts …THEHACKERNEWS.COM
17 JunBeyond the benchmark: Advancing security at AI speedRead how Microsoft Security has advanced its agentic vulnerability detection system, codename MDASH, integrating into real-world workflows across Windows, Azure, and identity systems. The post Beyond the benchmark: Advancing security at AI speed appeared first on Microsoft Securi…MICROSOFT.COM
17 JunSmashing Security podcast #472: AI gets hacked, and BitLocker gets bypassedWhat if your AI coding assistant could be tricked into stealing your own company's secrets - by reading a single booby-trapped bug report? No phishing email. No malware. No password ever stolen. Just an AI doing exactly what it was told. Meanwhile, someone themselves Nightmare Ec…GRAHAMCLULEY.COM
16 JunCybersecurity jobs available right now: June 16, 2026Android Vulnerability Researcher Byteria | USA | Remote – View job details As an Android Vulnerability Researcher, you will analyze the Android attack surface, including the Linux kernel, system services, drivers, firmware, applications, and Trusted Execution Envi…HELPNETSECURITY.COM
16 JunThe rise of machine identities and agentic AI: Securing trust in the next era of digital autonomyIn the latest episode of Identity Insider, I sat down with Chris Hughes, a cybersecurity expert who’s involved in OWASP’s work on non-human and machine identity security. Unsurprisingly, our discussion centered on the rapidly changing cybersecurity landscape, driven b…HELPNETSECURITY.COM
16 JuniRhythm discloses data breach, says hackers stole patient infoDigital healthcare company iRhythm Holdings has disclosed a data breach after hackers stole patients' personal and health information stored on third-party-hosted business applications. [...]BLEEPINGCOMPUTER.COM
16 JunReachability makes AI threat modeling worth the trustIn this interview with Help Net Security, Oscar Andersson, CTO at Oplane, explains why most scanning tools fail. They cry wolf, flagging threats that cannot run in real code. The argument centers on reachability. A finding counts only when someone walks the path to impact on a wo…HELPNETSECURITY.COM
16 JunZero trust isn’t broken. Most companies just do it wrong.Zero trust is 15 years old, and like many teenagers, it can feel misunderstood and underappreciated. The concept of zero trust was first defined by John Kindervag , a Forrester analyst at the time, as a strategy to replace the outmoded perimeter security model with a “never trust…CSOONLINE.COM
16 JunPlanning a trip? Fake travel sites are multiplying this summerCyberattacks against hospitality, travel, and recreation organizations rose 24% year over year, reaching an average of 2,291 incidents per organization each week in May 2026, according to Check Point. (Source: Check Point) “The sector has more than doubled its attack volume since…HELPNETSECURITY.COM
16 JunCritical Fortinet FortiSandbox flaws now exploited in attacksAttackers are now exploiting several critical vulnerabilities in Fortinet's FortiSandbox cyber threat detection platform, according to threat intelligence company Defused. [...]BLEEPINGCOMPUTER.COM
16 JunSoftware supply chains are heading for a transparency testSoftware supply chain visibility is becoming part of product security work as the EU Cyber Resilience Act (CRA) moves toward application in December 2027. ENISA’s SBOM Adoption State of Play 2026 shows organizations preparing for CRA obligations through SBOM tooling, automa…HELPNETSECURITY.COM
16 JunChainguard, JPMorgan, BNY Team Up to Secure Open Source from AI ThreatsAthena is a new an industry coalition to fix the vulnerabilities frontier AI models find before attackers can exploit themINFOSECURITY-MAGAZINE.COM
16 JunPickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCEUnit 42 discovered a Vertex AI Python SDK vulnerability that allows remote code execution via bucket squatting. Read the article for more. The post Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
16 JunRansomware gang abuses Microsoft Teams relays to hide malicious trafficDragonForce ransomware used a custom malware named 'Backdoor.Turn' to hide command-and-control traffic inside Microsoft Teams relay infrastructure. [...]BLEEPINGCOMPUTER.COM
16 JunChina-linked hackers target US, Canada research using legacy REDCap exploitsGoogle is warning of a cyber espionage campaign linked to a China-nexus threat actor, UNC6508, that kept close tabs on valuable US and Canadian research environments for over a year. The campaign abused REDCap, a widely adopted platform for collecting and managing research data. …CSOONLINE.COM
16 JunDragonForce Ransomware Exploited Microsoft Teams to Hide in Attack Against Major CompanyCommand and control traffic exploited a Teams visitor token to make malicious activity look legitimate to defendersINFOSECURITY-MAGAZINE.COM
16 JunWiz Exposure Management Dashboard: Your CTEM Command CenterNew exposure management dashboard helps organizations align with CTEM to stay ahead in an era of AI exploiting vulnerabilities faster than everWIZ.IO
16 JunImproving precision in CTEM: How continuous controls validation in Tenable One transforms exposure managementDiscover how continuous control validation in Tenable One can improve your CTEM program by filtering out alert noise and factoring in your active cyber defenses. Focus your team on accessible and exploitable attack paths.  Key takeaways: With vulnerability exploitation ranki…TENABLE.COM
16 JunRadware AI Xploit Shield delivers virtual patching for newly identified application and API flawsRadware has announced AI Xploit Shield, a new service that provides organizations with protection for their applications and APIs from exploitation of newly discovered vulnerabilities. As emerging frontier AI models like Mythos from Anthropic accelerate vulnerability discovery, o…HELPNETSECURITY.COM
16 JunCybercriminals mask malicious communications through Microsoft Teams relaysThe DragonForce ransomware group used a custom malware called Backdoor.Turn to hide command-and-control traffic inside Microsoft Teams relay infrastructure during an intrusion at a U.S. services company, according to Symantec. DragonForce is a ransomware-as-a-service operation th…HELPNETSECURITY.COM
16 JunIndia temporarily blocks Telegram over medical exam cheating fearsAuthorities said scammers previously exploited the feature by posting fake exam questions before the test and later replacing them with the real questions, making it look like they had leaked the exam in advance.THERECORD.MEDIA
16 JunTrump administration keeps Fable 5 restrictions in place.DragonForce ransomware operators abuse Microsoft Teams to hide C2 traffic. Ukrainian national pleads guilty to assisting in Conti ransomware attacks.THECYBERWIRE.COM
16 JunSession avoids shutdown as community donations save the projectSession, the decentralized encrypted messaging platform that warned earlier this year it could shut down due to a funding crisis, will continue operating after receiving financial support from thousands of users. The community-funded effort has provided enough resources to keep d…CYBERINSIDER.COM
16 JunThreat tactic spotlight: Subdomain takeoverIn this blog post you’ll learn how to detect and prevent subdomain takeover – a tactic where threat actors exploit dangling DNS records to redirect traffic to attacker-controlled resources. We’ll explain the issue, how the situation arises, and how you can use various AWS feature…AWS.AMAZON.COM
16 JunNo Mythos of escape.Emergency talks fail to free Anthropic’s Fable 5. Trump moves to strengthen national security systems. Microsoft patches a critical Copilot flaw. ShinyHunters weaponize a PeopleSoft zero-day. DragonForce hides in Microsoft Teams for months. Plus, Amos Stealer targets Macs, CISA i…THECYBERWIRE.COM
16 JunWhy AI Is Breaking Network-Based SASEMike Fey, co-founder and CEO of Island, joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices. Mike explores why AI workflows and emerging quantum computing threats are challenging the assumptions behind traditional network-based SASE architectures. He…THECYBERWIRE.COMHTTPS:
16 JunAttackers Rarely Use Real IPsAccording to an industry study referenced in the discussion, anonymizing infrastructure such as VPNs, proxy networks, and Tor appeared in nearly all analyzed security incidents, with 94% of respondents reporting its use during attacks. Traditional IP-based detection becomes far l…YOUTUBE.COM
16 JunCyberRisk TV Live Coverage from Identiverse 2026CyberRisk TV is broadcasting live from Identiverse 2026 in Las Vegas! Join us for exclusive interviews with identity, security, and technology leaders, actionable insights, and the latest thinking from practitioners shaping the future of digital identity at the industry's premier…YOUTUBE.COM
16 JunSN 1083: Patch Tuesday à la AI - Arch Linux Repo Under SiegeThis episode unpacks the jaw-dropping surge in vulnerabilities unearthed by AI, revealing how Microsoft shattered its own patch records while adversaries and defenders race to outpace each other. The conversation gets real about whether AI is fixing our broken software or just ma…TWIT.TV
15 JunAnthropic Models Blocked, FBI Takes Down $1.9B Phishing Network, Critical Splunk Flaw, and moreThe U.S. government orders Anthropic to shut down foreign access to its Fable 5 and Mythos 5 AI models after the Pentagon labels the company a supply-chain risk. David Shipley examines what may be behind the decision and what it means for countries and businesses that depend on A…CYBERSECURITYTODAY.LIBSYN.COM
15 JunLiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway ServersA default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three vulnerabilities, researchers at Obsidian Security disclosed LiteLLM is a widely deployed open-source AI gateway that brokers calls to more than 100 model provid…THEHACKERNEWS.COM
15 Jun⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and MoreStuff broke again. Not in a movie way. An old tool was left exposed. An abandoned package was abused. A deprecated feature was still running in prod. This week is the same lesson in a new form: phishing kits are easier to rent, AI names are useful bait, old login paths still fail…THEHACKERNEWS.COM
15 JunSniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser AlertsCybersecurity researchers have disclosed details of fraudulent activity targeting users across the Middle East and North Africa by employing various fraudulent Facebook accounts impersonating politicians, public figures, and trusted organizations. "These accounts promoted fake of…THEHACKERNEWS.COM
15 JunThe US government’s Anthropic models ban was never about an AI jailbreakThe Trump administration's decision that forced Anthropic to pull its latest cybersecurity models could be reactionary, retaliatory, or both, but the message is clear: The AI industry isn't immune from U.S. government interference.TECHCRUNCH.COM
15 JunMaine forced to take down data breach portal after fake notices filed with authoritiesThe US state of Maine has taken its public data breach notification portal offline after someone submitted fraudulent breach disclosures impersonating two well-known technology companies. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
15 JunJune 2026 Stealer Logs - 56,278,397 breached accountsIn June 2026, a collection of accumulated stealer logs from various sources was added to HIBP. The corpus comprised 56M unique email addresses across hundreds of millions of stealer log records. The data also contained 124M unique passwords, which have been added to Pwned Passwor…HAVEIBEENPWNED.COM
15 JunBerkadia - 305,216 breached accountsIn March 2026, the commercial real estate finance company Berkadia was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data they alleged was taken from Berkadia's Salesforce instance, including over 300k unique email addresses as w…HAVEIBEENPWNED.COM
15 JunAttackers can turn AI agent guardrails into denial-of-service weaponsAttackers can turn AI agent guardrails into denial-of-service weapons, according to new research that found a single poisoned document can dramatically slow shared AI agent workflows by trapping reasoning-based safety systems in extended thinking loops. “Reasoning-based guardrail…CSOONLINE.COM
15 JunGoverning the ghost workforceEvery enterprise security team is fighting a workforce problem they cannot see on any org chart. Bots, service accounts, API keys, OAuth tokens, machine certificates — non-human identities now outnumber human ones in most large organisations, often by a factor of ten to one. They…CSOONLINE.COM
15 JunSovereign cloud won’t fix your AI risk. Identity governance willYour board is asking. Your legal team is asking. Your auditors will be asking: Should AI workloads move to sovereign cloud, or stay on AWS, Azure or GCP? European enterprises have already run this experiment — under real regulatory pressure, with real money and real consequences.…CSOONLINE.COM
15 Jun5 runtime signals for catching a compromised AI agentIn June 2025, Simon Willison, the engineer who coined the term “prompt injection,” published a warning that circulated widely through the security community. He called it the lethal trifecta — three capabilities that, when combined in a single AI agent, create a near-guaranteed p…CSOONLINE.COM
15 JunAI Agents Break Data PerimetersThe discussion highlights a shift in security architecture driven by agentic AI systems. Instead of traditional network perimeters, the focus is moving toward data-centric security, including lineage, contextualization, and data security posture management (DSPM). As AI agents in…YOUTUBE.COM
15 JunSafe AI at scale, what happens after initial access, and the weekly enterprise news - ESW #463Interview with Shiva Pillay from Veeam Safe AI at Scale AI investment is exploding, yet nearly 90% of enterprise initiatives fail because the data powering AI cannot be trusted. That’s the uncomfortable truth the industry is facing right now. Safe AI at scale requires more than j…YOUTUBE.COM
15 JunPublic and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense ResearchWritten by: Patrick Whitsell, John McGuiness Google Threat Intelligence Group (GTIG) has identified a sophisticated campaign attributed to UNC6508, a People's Republic of China (PRC)-nexus threat actor, targeting institutions in the North American academic, medical, and military …CLOUD.GOOGLE.COM
15 JunCyberattack on Russian tech firm Astral disrupts business, government services for weekAccording to customer complaints, the disruption affected a range of services used by businesses, leading to interruptions in cash register operations, difficulties selling certain regulated goods, loss of access to customer portals and corporate email and problems with electroni…THERECORD.MEDIA
15 JunAnthropic says US government forced it to disable cybersecurity AI modelsAccording to the company, the directive cited national security authorities. It appears to be the first time such authorities have been used to curtail the export of AI models rather than chips or hardware.THERECORD.MEDIA
15 JunGoogle exposes China espionage group that’s been lurking in networks undetected since 2023The revelation mirrors an alarming pattern of Chinese espionage groups dropping backdoors into critical infrastructure to intercept research and steal data with national security implications. The post Google exposes China espionage group that’s been lurking in networks undetecte…CYBERSCOOP.COM
15 JunMS-ISAC enters uncertain new era after losing federal funding and thousands of membersThe information-sharing group, a vital resource for state and local governments, has cut staff and pinned its hopes on a membership surge.CYBERSECURITYDIVE.COM
15 JunSimpleHelp bug lets hackers create rogue remote support accountsA vulnerability in the SimpleHelp remote management software allows unauthenticated attackers to create privileged technician accounts on servers using the OpenID Connect (OIDC) authentication protocol. [...]BLEEPINGCOMPUTER.COM
15 JunNew attack turned Microsoft 365 Copilot into 1-click data theft toolA critical vulnerability chain dubbed SearchLeak in Microsoft 365 Copilot Enterprise could allow attackers to steal sensitive data from a target's mailbox, OneDrive, or SharePoint account through a specially crafted URL. [...]BLEEPINGCOMPUTER.COM
15 JunInfinite Campus data breach affects 137,000 school staff accountsThe ShinyHunters extortion gang stole personal information from more than 137,000 school staff accounts in a Salesforce data theft attack that targeted the widely used Infinite Campus K-12 student information system in March. [...]BLEEPINGCOMPUTER.COM
15 JunChinese hackers breached North American research institutions via REDCap serversA China-linked cyber espionage operation targeted North American medical research institutions through compromised REDCap servers, using custom malware to gain persistent access and collect sensitive information, Google’s Threat Intelligence Group (GTIG) researchers found. …HELPNETSECURITY.COM
15 Jun1Password Credential Broker reduces secret sprawl through identity-based credential delivery1Password has announced 1Password Credential Broker, a new product that securely brokers credentials, tokens, and federated access from 1Password to trusted requesters. The 1Password Credential Broker is available in private beta today, with support for GitHub Actions and a roadm…HELPNETSECURITY.COM
15 JunPhishLumos: Exposing phishing campaigns that evade detection by hiding contentPhishing remains one of the most stubbornly persistent threats in cybersecurity: humans are tired, distracted, trusting, and susceptible to urgency and authority in ways that no amount of awareness training can completely overcome. The security community has largely accepted this…HELPNETSECURITY.COM
15 JunNIS2 is raising the bar. Here’s how to turn readiness into resilience.The NIS2 directive asks covered organizations to take a more structured approach to risk management, governance, supply chain security, and incident reporting. It expands the scope of who may be covered, raises expectations around management body accountability, introduces cleare…RAPID7.COM
15 JunDoes Your Security Programme Align With NIS2 Requirements?If your organization operates in the EU, or works with organizations that do, NIS2 is no longer something on the horizon. It is here and it applies to a far wider range of sectors than its predecessor, the original NIS Directive (Directive (EU) 2016/1148), and it comes with real …RAPID7.COM
15 JunBeyond the Score: Using AI to Translate CVEs into Real-World Business RiskSecurity leaders rarely struggle to gather data, but they often struggle to turn that data into something clear and meaningful for the business. In a typical week, a CISO might receive a report listing hundreds or even thousands of vulnerabilities, most of them accompanied by CVS…RAPID7.COM
14 JunVulnerability management at AI speed.In large enterprise software companies, vulnerability management teams are facing unprecedented speed and scale as AI accelerates both discovery and exploitation of security issues. In this episode of CyberWire-X, N2K’s ⁠Dave Bittner⁠ is joined by Adobe’s ⁠Daniel Ventura⁠, Senior…THECYBERWIRE.COM
14 JunWeek in review: Exploited Check Point VPN zero-day, Oracle PeopleSoft servers under attackHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: DockSec: Open-source AI-powered Docker security scanner DockSec is an OWASP Incubator Project that combines three container security scanners with a language-model layer for explanat…HELPNETSECURITY.COM
13 JunWeekly Metasploit Update: New Kerberos/Certificate tracing options, and multiple new modulesNew Tracing Options As hard as we try to ensure that Metasploit is bug free, issues inevitably come up. Whether you’re running a module on an op or writing a new one, what we can do is make the debugging experience easier. To that end one of our two Google Summer of Code (GSoC) p…RAPID7.COM
13 JunThis Sparrow doesn't migrate.Martin Zugec⁠, Technical Solutions Director at ⁠Bitdefender⁠, discussing their work on "FamousSparrow APT Targets Azerbaijani Oil and Gas Industry." Bitdefender researchers uncovered a sustained cyber espionage campaign by the China-linked FamousSparrow group targeting an Azerbai…THECYBERWIRE.COM
13 JunShai-Hulud variant compromises dozens of open-source Microsoft packages.Patch Tuesday notes: Microsoft fixes a record 200 flaws. German court holds Google liable for AI-generated claims.THECYBERWIRE.COM
13 JunThe FCC Wants to Kill Burner PhonesPlus: AI bug hunting fuels Microsoft’s biggest-ever Patch Tuesday, ShinyHunters ransomware gang exploits an Oracle zero-day, and more.WIRED.COM
13 JunYour Replacement Phone Was ManagedA customer reportedly received a refurbished replacement phone that still contained an active Mobile Device Management (MDM) profile. MDM platforms are commonly used by enterprises to remotely manage company-owned devices, enforce policies, disable lost phones, and control access…YOUTUBE.COM
13 JunAnthropic disables new models after government calls them a national security concernThe Commerce Department’s expert control decree led to the company shutting off access to Fable 5 and Mythos 5 worldwide, drawing sharp criticism from researchers and industry analysts. The post Anthropic disables new models after government calls them a national security concern…CYBERSCOOP.COM
13 JunAmazon CEO reportedly raised Anthropic model concerns before government crackdownAmazon CEO Andy Jassy may have been the source of security concerns that led Anthropic to cut off worldwide access to two models on Friday.TECHCRUNCH.COM
12 JunAnthropic Warns AI Risks Are Real, RoguePlanet Zero-Day Drops, Crypto Laundering TakedownAnthropic is calling for governments to have the authority to stop deployment of advanced AI systems that pose unacceptable risks. CEO Dario Amodei points to the company's Mythos cybersecurity model as proof that AI has become a matter of national and strategic consequence, warni…CYBERSECURITYTODAY.LIBSYN.COM
12 JunComcast Business SecurityEdge Preferred strengthens security for small businessesComcast Business announced SecurityEdge Preferred, its most advanced network-native cybersecurity solution for small businesses. Because SecurityEdge Preferred is built directly into the Comcast Business network, security can be activated in minutes without deploying additional h…HELPNETSECURITY.COM
12 Jun‘Harvest now, decipher later’: The quantum threat few are preparing forQuantum technology may feel far off but certain risks are already with us in the form of “harvest now, decrypt later” — an attack vector in which malicious actors steal data now for a future in which they have access to quantum computational tools capable of breaking encryption d…CSOONLINE.COM
12 JunAuthorities dismantle crypto laundering service that moved €336 million for cybercriminalsAn international law enforcement operation has dismantled a cryptocurrency laundering service linked to ransomware groups and other cybercriminals that processed more than €336 million in illicit funds. The domain seizure notice (Source: Europol) Europol said the service, known a…HELPNETSECURITY.COM
12 Jun KEVCISA orders feds to patch actively exploited Ivanti flaw by SundayThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch an actively exploited Ivanti Sentry flaw within three days, as mandated by the newly issued Binding Operational Directive (BOD) 26-04. [...]BLEEPINGCOMPUTER.COM
12 JunLangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code ExecutionCybersecurity researchers have disclosed details of three now-patched security flaws impacting LangGraph, including a critical vulnerability chain that could result in remote code execution. LangGraph is an open-source framework created by LangChain to build complex, stateful, an…THEHACKERNEWS.COM
12 JunAI is exposing the biggest weakness in cybersecurity: We never built a health model. Until now!For 30 years, cybersecurity has operated like an emergency room. Reactive. Crisis-driven. Always triaging. We are extraordinarily good at it — our detection is faster, our response playbooks are sharper, our incident teams are more capable than they have ever been. When something…CSOONLINE.COM
12 JunIvanti Sentry Exploitation Attempts Hitting HoneypotsThe critical-severity OS command injection vulnerability allows attackers to execute arbitrary code with root privileges. The post Ivanti Sentry Exploitation Attempts Hitting Honeypots appeared first on SecurityWeek .SECURITYWEEK.COM
12 JunChrome 149 Update Patches 28 VulnerabilitiesThe browser refresh resolved critical and high-severity security defects, including a dozen use-after-free bugs. The post Chrome 149 Update Patches 28 Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
12 JunPrompt injection breaks today’s AI agents, study warnsToday’s AI web agents have no dependable defenses against prompt injection, according to new research showing that not a single attack scenario was consistently blocked across leading systems powered by GPT‑5 and Gemini. The findings come from StakeBench, a stakeholder-centric be…CSOONLINE.COM
12 JunPharma giant Novo Nordisk discloses breach of clinical trials dataDanish pharmaceutical giant Novo Nordisk, the world's largest producer of insulin, disclosed a data breach affecting patient information from some clinical trials. [...]BLEEPINGCOMPUTER.COM
12 Jun KEVFactoring "short-sleeve" RSA keys with polynomialsWhat happens when the bits of an RSA private key are heavily biased toward 0 instead of being randomly generated? The public key’s bits could be biased enough for us to detect these incorrectly generated keys in the wild. Together with Hanno Böck of the badkeys project, we found …TRAILOFBITS.COM
12 JunAgentjacking Attack Tricks AI Coding Agents Into Running Malicious CodeCybersecurity researchers have described what they say is a new class of attack that can trick artificial intelligence (AI) coding agents into running arbitrary code on developer machines. Called Agentjacking by Tenet Security, the attack can be triggered by means of a fake error…THEHACKERNEWS.COM
12 JunSecurity Tools Are Breaking SOCsMany organizations now operate dozens of security tools across incident response, threat intelligence, detection, investigation, and remediation. While these tools increasingly include AI features, they often lack proper integration across platforms. This creates operational frag…YOUTUBE.COM
12 JunCISA directs agencies to “patch smarter, not harder.”Anthropic rejects Fable 5 jailbreak claims. Google confirms ShinyHunters exploited a critical Oracle PeopleSoft vulnerability.THECYBERWIRE.COM
12 JunShinyHunters linked to exploitation of critical flaw in Oracle PeopleSoftMore than 100 organizations, more than two-thirds in higher education, have been notified of potential impact.CYBERSECURITYDIVE.COM
12 JunShinyHunters is actively extorting universities after exploiting an unpatched Oracle flawOracle still hasn't patched the vulnerability the group has been using in its attacks since late May. The post ShinyHunters is actively extorting universities after exploiting an unpatched Oracle flaw appeared first on CyberScoop .CYBERSCOOP.COM
12 JunphpBB forum fixes auth bypass bug lurking for a decadeA 10-year-old authentication bypass vulnerability discovered in the phpBB forum software allows an attacker to log in as any user, including administrators. [...]BLEEPINGCOMPUTER.COM
12 JunDeadline-driven defense.CISA directs agencies to “patch smarter, not harder.” The House fails to extend FISA. Europol pulls over AudiA6. GitHub announces npm security updates. Anthropic rejects Fable 5 jailbreak claims. CISA gives feds three days to patch a critical Ivanti Sentry vulnerability. Google c…THECYBERWIRE.COM
12 JunShinyHunters Uses Oracle Zero-Day to Rampage Higher EdA major bug in Oracle's ERP software disproportionately affected American universities, and hackers have capitalized by stealing gobs of data.DARKREADING.COM
12 JunGreatXML zero-day BitLocker bypass doesn’t seem to work, yetA disgruntled researcher who has been publishing zero-day Microsoft Windows vulnerabilities for the past several months released a new exploit Thursday that promises to bypass BitLocker encryption on locked devices. A well respected security expert reported that the exploit doesn…CSOONLINE.COM
12 Jun KEVShiny Hunters Hit PeopleSoftOracle mitigated a critical PeopleSoft vulnerability affecting PeopleTools versions 8.61 and 8.62. Reports indicate the vulnerability was actively exploited as a zero-day by the group known as Shiny Hunters to access organizational data. The issue was described as an unauthentica…YOUTUBE.COM
11 JunGitHub finally pulls the plug on automatic install script execution for npmThe ability for attackers to leverage automatic install script execution in npm will finally come to an end when expected changes arrive from GitHub in July. Coders will still be able to enable the function, but the default setting will block it. In V12, default settings are chan…CSOONLINE.COM
11 JunWhatsAppening here?This week, hosts of N2K CyberWire ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Maria Varmazis⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ alongs…THECYBERWIRE.COM
11 JunX Square Robot open sources its robot-free data collection frameworkCompanies building robots for physical work spend large amounts of time and money operating machines by hand to gather training examples. Each session with a physical robot produces a small number of demonstrations per day, which slows the growth of datasets used to train embodie…HELPNETSECURITY.COM
11 JunMax severity Ivanti Sentry vulnerability now exploited in attacksAttackers are now targeting a recently patched maximum-severity flaw in Ivanti Sentry, enabling them to execute code with root privileges on Internet-exposed secure mobile gateways. [...]BLEEPINGCOMPUTER.COM
11 JunAged-domain acquisition: The tradecraft phishing operators are using to bypass your mail filter’s reputation scoreI’ve spent the past two years working on incident response and threat intelligence, and the pattern I’m about to describe is one I keep seeing show up in cases that should have been caught at the email gateway. The kit families change. The lure templates change. The constant is t…CSOONLINE.COM
11 JunFrontier AI models offer sneak peak of seismic cyber shifts aheadThe advent of Claude Mythos combined with the release of OpenAI’s GPT-5.5 have changed the threat model for CISOs . The arrival of those frontier AI models — and the ones soon to follow — makes it much easier to discover and chain vulnerabilities at a speed and scale that will re…CSOONLINE.COM
11 Jun‘GreatXML’ Zero-Day Exploit Bypasses BitLockerThe PoC exploits Microsoft Defender’s offline scan to spawn a SYSTEM shell when rebooting in Recovery Mode. The post ‘GreatXML’ Zero-Day Exploit Bypasses BitLocker appeared first on SecurityWeek .SECURITYWEEK.COM
11 JunEnhanced License Plate TrackingThe surveillance company Leonardo wants more data : A surveillance company plans to add sensors to automatic license plate readers (ALPRs) that would mean the devices, as well as capture the license plate of passing vehicles, would also sweep up unique identifiers of mobile phone…SCHNEIER.COM
11 JunWhat SRE teams need before they trust AI agentsThe future of reliability will not be defined by whether site reliability engineering (SRE) teams use AI agents, but by the conditions under which they choose to trust them. In high-stakes systems, trust is never granted because a demo looks impressive; it is earned through obser…CSOONLINE.COM
11 JunSplunk, Palo Alto Networks Patch Severe VulnerabilitiesThe security defects could allow attackers to create or modify arbitrary files and access and modify protected resources. The post Splunk, Palo Alto Networks Patch Severe Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
11 JunAI Broke Vulnerability Management. That's Why CISOs Are Moving Budget to BAS.For thirty years, vulnerability management ran on a buffer: the months between when a vulnerability was found and when someone could figure out how to weaponize it. The solution was straightforward enough; triage by severity, schedule the fix, validate, and move on. The buffer wa…THEHACKERNEWS.COM
11 JunSignal Alums Reveal ‘Encrypted Spaces,’ a System for Making Private Collaboration AppsThe new open-source project could serve as the basis for a future of apps with features as complex as Slack, Discord, or Google Docs—but with added protection against surveillance.WIRED.COM
11 JunKyushu Electric lost backup drive containing data of 10.9 million clientsKyushu Electric Power Transmission and Distribution Co. has disclosed that an external storage device used for system backups has gone missing from a secure server room. While no evidence of data leakage has been identified so far, the company warns that the device contained pers…CYBERINSIDER.COM
11 JunVRChat discloses cloud breach exposing data of 2.4 million usersVRChat has disclosed a data breach affecting 2,436,782 users after attackers gained unauthorized access to data stored in the company's cloud environment. The incident exposed account-related information, including email addresses, usernames, login history, and linked platform id…CYBERINSIDER.COM
11 JunHackers Exploit Langflow Vulnerability for Remote Code ExecutionDisclosed in March, the security defect enables unauthenticated attackers to write files to arbitrary locations on the system. The post Hackers Exploit Langflow Vulnerability for Remote Code Execution appeared first on SecurityWeek .SECURITYWEEK.COM
11 JunCoupang hit with record $409 million data breach fine in Korea​​The Personal Information Protection Commission (PIPC), South Korea's data protection regulator, has fined e-commerce giant Coupang a record 624.6 billion won (roughly $409 million) following a massive data breach affecting more than 37 million customers [...]BLEEPINGCOMPUTER.COM
11 JunCISA tells govt agencies to patch critical exploited flaws in 3 daysThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced a new Binding Operational Directive, 26-04, that prioritizes security updates for Federal Civilian Executive Branch (FCEB) agencies. [...]BLEEPINGCOMPUTER.COM
11 JunServiceNow fixes API issue after reports of suspicious tenant activityServiceNow is notifying customers after discovering and remediating a vulnerability that could have exposed data via an unauthenticated API endpoint on affected instances. The issue emerged publicly after customers began discussing security notifications from ServiceNow and repor…CSOONLINE.COM
11 JunFrom SQLi to RCE – Exploiting LangGraph’s CheckpointerBy Yarden Porat AI agents need memory. Frameworks like LangGraph provide it through checkpointers – persistence layers that store execution state. But what happens when that persistence layer isn’t locked down? Key Points Background LangGraph is an open-source framewo…RESEARCH.CHECKPOINT.COM
11 JunCriminal AI-as-a-Service in 2026: How the Underground Market Is Operationalizing CybercrimeIntroduction The underground market for criminally oriented generative AI has moved beyond the early hype surrounding 'malicious chatbots.' The gradual integration of AI as a productivity layer within cybercrime operations has become the dominant story, indicating that while the …RAPID7.COM
11 JunAuthorities dismantle 'AudiA6' ransomware crypto-laundering serviceLaw enforcement has dismantled the “AudiA6” cryptocurrency service allegedly used by ransomware actors and other cybercriminals to launder more than $380 million. [...]BLEEPINGCOMPUTER.COM
11 JunThe Gentlemen Ransomware Claims 478 Victims, Can Spread Like a WormA new analysis of The Gentlemen operation has revealed that the financially motivated threat group initially operated as an affiliate responsible for conducting double extortion attacks, while leveraging resources from various ransomware-as-a-service (RaaS) schemes like LockBit (…THEHACKERNEWS.COM
11 JunCyber Force not included in Senate defense policy roadmapAn amendment by Sen. Kirsten Gillibrand (D-NY) to the chamber’s fiscal 2027 national defense authorization bill that would have created the digital-focused service was defeated 14-13 when the Senate Armed Services Committee took up the nearly $1.2 trillion legislation behind clos…THERECORD.MEDIA
11 JunCoupang hit by massive $456 million fine for 2025 data breach incidentSouth Korea's Personal Information Protection Commission (PIPC) has fined e-commerce giant Coupang 624.68 billion won ($456 million) after concluding that poor security practices led to a data breach affecting approximately 37.5 million people. The decision follows a November 202…CYBERINSIDER.COM
11 JunCISA orders federal agencies to “patch smarter”The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a Binding Operational Directive that will change how the US federal government approaches vulnerability management. The directive arrives as the patching problem has become nearly unmanageable, driven by a …HELPNETSECURITY.COM
11 JunNew GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML FilesSecurity researcher Chaotic Eclipse (aka Nightmare-Eclipse and MSNightmare) has released a new Windows BitLocker bypass dubbed GreatXML, a day after they published an exploit for Microsoft Defender. "This was an accidental discovery, it took a total of 4 hours to find this," the …THEHACKERNEWS.COM
11 JunNexstar investigates potential breach after ShinyHunters claims theft of 1.1M Salesforce recordsNexstar Media Group is investigating a potential cybersecurity incident after the ShinyHunters extortion group claimed to have stolen more than one million Salesforce records and additional internal corporate data from the broadcasting giant. While the threat actors have not publ…CYBERINSIDER.COM
11 JunMax-Severity Ivanti Flaw Exploited 24 Hours After DisclosureInitial methods suggest attackers had likely mapped out Ivanti's asset landscape upfront and acted quickly once the exploit became public.DARKREADING.COM
11 JunOracle warns of security bug that hackers abused to breach 100+ companiesThe tech giant warned of a security flaw that a cybercrime gang said it's exploiting as part of a mass-hacking campaign. Google said it notified more than 100 organizations that had potentially vulnerable servers.TECHCRUNCH.COM
11 JunNightmare Eclipse Trolling MicrosoftThe discussion centers on a persona called “Nightmare Eclipse,” which appears to act as a single researcher or group releasing vulnerabilities in a highly public and strategic way. This includes dropping zero-day vulnerabilities outside of standard vendor patch cycles. This style…YOUTUBE.COM
11 JunJapanese energy firm loses drive with data of 10.9 million clientsKyushu Electric Power Co., Inc. has disclosed a physical security incident that affects private data of more than 10 million customers. [...]BLEEPINGCOMPUTER.COM
10 JunEnterprises know AI-generated code is vulnerable; they’re shipping it anywayAI-generated code is riddled with security flaws, yet enterprises are shipping more of it than ever before. Why? Perhaps they’re over-confident, lack true visibility into security risks, or are simply choosing to ignore the problem and hope it goes away. It’s a dangerous game to …CSOONLINE.COM
10 JunUK move to filter photos and messages triggers encryption worries for CISOsUK Prime Minister Keir Starmer’s speech on Monday insisting that tech companies create device controls to somehow block children from viewing or creating sexually explicit imagery has raised alarms among CISOs, who worry that the same technology could undermine enterprise securit…CSOONLINE.COM
10 JunHiring Hot Takes from a Three-Time Exit CMO, Mary YangMary Yang has been a CMO in cybersecurity for 6 years, helped 3 companies exit, and now works on a fractional basis with founders and teams she wants to work with. On this CyberCMO Confidential episode, the three of them get into a discussion on hiring. Mary skips the job descrip…THECYBERWIRE.COM
10 JunProduct showcase: Staying ahead of the threat horizon with AunooAunoo is an open strategic intelligence platform that uses AI agents to monitor intelligence sources, including for cybersecurity, to compile a daily briefing and alert on defined criteria. Each source is checked for credibility and quality before it is included. The platform run…HELPNETSECURITY.COM
10 JunScams now operate like real businesses with budgets and targetsSocial media has overtaken email as a primary attack vector, showing changes in how people consume information and interact online, according to Bitdefender’s Global Scam Intelligence Report 2026. Fraud campaigns use advertisements, sponsored content, impersonation pages, a…HELPNETSECURITY.COM
10 JunSix Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoSCybersecurity researchers have flagged half a dozen vulnerabilities in protobuf.js, a JavaScript and TypeScript implementation of Protocol Buffers (Protobuf), that, if successfully exploited, could result in remote code execution (RCE) and denial-of-service (DoS) attacks. "In aff…THEHACKERNEWS.COM
10 JunNOVA microhypervisor brings AMD DMA isolation to shared AI infrastructureBlueRock has issued the latest open-source release of its NOVA Microhypervisor with DMA remapping support for AMD platforms that have IOMMU hardware virtualization. The capability is enabled by default and extends hardware-level isolation across virtual machines, devices, and mem…HELPNETSECURITY.COM
10 JunMicrosoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated WindowsThe anonymous security researcher going by the name Chaotic Eclipse (aka Nightmare-Eclipse) has released a proof-of-concept (PoC) exploit for yet another Microsoft Defender zero-day named RoguePlanet. "The exploit is a race condition, so it's a hit or miss," the researcher, who p…THEHACKERNEWS.COM
10 JunRisky Business #841 -- Microsoft gets owned and 0day'dOn this week’s show special guest co-host Chris Wade, the founder of Corellium turned Cellebrite CTO, joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover: Microsoft has repos owned, GitHub tokens popped, and a new 0day dropped on them Meanwhil…RISKY.BIZ
10 JunNo Patch Planned for Exploited Arista EOS VulnerabilityOrganizations are advised to apply vendor-supplied mitigations or discontinue the vulnerable devices. The post No Patch Planned for Exploited Arista EOS Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
10 JunServiceNow Flaw Exploited to Gain Unauthorized Access to Customer InstancesServiceNow has warned about a security incident in which unknown threat actors exploited a flaw to obtain deeper unauthorized access to susceptible instances. "On June 5, 2026, ServiceNow applied a security update to hosted customer instances," the company revealed in an advisory…THEHACKERNEWS.COM
10 JunMicrosoft Fixes 200 CVEs in June Patch TuesdayMicrosoft has patched 200 vulnerabilities including three zero-daysINFOSECURITY-MAGAZINE.COM
10 JunCritical Vulnerabilities Patched in Fortinet, Ivanti ProductsTwo OS command injection flaws can be exploited remotely, without authentication, for arbitrary code execution. The post Critical Vulnerabilities Patched in Fortinet, Ivanti Products appeared first on SecurityWeek .SECURITYWEEK.COM
10 JunAI red teaming comes of ageWhen Ram Shankar Siva Kumar launched Microsoft’s AI red team in 2019, the discipline barely existed. “The running joke used to be that people who used to work in AI red teaming, you can round them up in a 14-foot catamaran,” he tells CSO. At the time, Microsoft’s approach looked …CSOONLINE.COM
10 JunInnovation Without Data Security Risk as AI Unlocks Budgets and Identity Challenges - BSW #451AI is reshaping innovation as businesses embed it into core operations and move more processes online. This transformation is often seen as a tradeoff between innovation and data risk, but that assumption is wrong. Businesses can innovate and scale in the AI era while maintaining…YOUTUBE.COM
10 JunMicrosoft patches YellowKey, GreenPlasma, MiniPlasma zero-daysOn Tuesday, Microsoft patched two zero-day vulnerabilities that let attackers gain SYSTEM privileges on fully patched Windows systems, and a third one that grants access to BitLocker-protected drives. [...]BLEEPINGCOMPUTER.COM
10 JunServiceNow Patches Vulnerability Exploited Against Some CustomersThe company updated hosted customer instances to patch a security issue it reportedly had known about since April 7. The post ServiceNow Patches Vulnerability Exploited Against Some Customers appeared first on SecurityWeek .SECURITYWEEK.COM
10 JunRubrik launches Autonomous Business Recovery to rebuild cloud applications after cyberattacksRubrik has unveiled Autonomous Business Recovery (ABR) for Cloud Applications, the agentic cyber resilience solution that recovers cloud applications from data to network, identity and configurations. The end result is a rebuild of an organization’s Minimum Viable Business …HELPNETSECURITY.COM
10 JunF5 adds AI-powered threat detection and API security for on-premises environmentsF5 has introduced new web application and API protection (WAAP) capabilities for its Application Delivery and Security Platform. The company said the updates are intended to address a threat landscape in which AI models can accelerate the time between vulnerability discovery and …HELPNETSECURITY.COM
10 JunMicrosoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE BugsMicrosoft on Tuesday released fixes for a record 206 security vulnerabilities impacting its software portfolio, including three flaws that have been publicly disclosed at the time of release. Of the 206 flaws, 39 are rated Critical, and 167 are rated Important in severity. This i…THEHACKERNEWS.COM
10 JunAutonomous AI agents duped into leaking sensitive data in phishing testAI agents given access to corporate email and business applications could become a new phishing target for attackers, according to cybersecurity researchers, after a test agent built on OpenClaw was tricked into sharing cloud credentials and customer data with an external attacke…CSOONLINE.COM
10 JunRecord Microsoft Patch Tuesday, fresh zero-dayMicrosoft marked its largest-ever Patch Tuesday this month, by shipping fixes for nearly 200 vulnerabilities. Within hours, “Nightmare Eclipse”, the researcher behind weeks of escalating Windows exploit releases, dropped a proof-of-concept exploit for a new zero-day: …HELPNETSECURITY.COM
10 JunNew Windows Zero-Day Exploit ‘RoguePlanet’ ReleasedExploiting a race condition in Microsoft Defender, the exploit leads to local privilege escalation to SYSTEM. The post New Windows Zero-Day Exploit ‘RoguePlanet’ Released appeared first on SecurityWeek .SECURITYWEEK.COM
10 JunMicrosoft’s biggest-ever Patch Tuesday fixes 206 bugs, including 3 zero-daysJune 2026 is the largest Patch Tuesday in history, fixing 206 vulnerabilities and three publicly disclosed zero-days.MALWAREBYTES.COM
10 JunAryon Security Raises $29 Million in Series A FundingIn the post-Mythos era, the company’s platform helps organizations enforce security controls across environments. The post Aryon Security Raises $29 Million in Series A Funding appeared first on SecurityWeek .SECURITYWEEK.COM
10 JunMicrosoft ships largest Patch Tuesday on record, with one bug under active attackThe release comes after Microsoft’s security leadership acknowledged last month that AI tools are driving a surge in vulnerability discovery across the industry.THERECORD.MEDIA
10 Jun KEVMicrosoft patches Exchange Server zero-day exploited in attacksMicrosoft has patched an actively exploited Exchange Server vulnerability that allows threat actors to execute arbitrary JavaScript code in cross-site scripting (XSS) attacks targeting Outlook Web Access users. [...]BLEEPINGCOMPUTER.COM
10 JunInfostealers Turn Millions of Devices Into Credential Theft MachinesAs attackers increasingly favor stolen credentials over exploits, infostealers have become a primary source of access for ransomware and other cybercrime operations. The post Infostealers Turn Millions of Devices Into Credential Theft Machines appeared first on SecurityWeek .SECURITYWEEK.COM
10 JunAISLE Snapshot keeps source code under enterprise control during vulnerability scanningAISLE has introduced AISLE Snapshot, a new offering that gives regulated and security-sensitive enterprises access to frontier-class vulnerability detection inside their own environments, at a fraction of the cost, with source code and security data that never leave their control…HELPNETSECURITY.COM
10 JunWho Runs the Ransomware Group ‘The Gentlemen?’A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post e…KREBSONSECURITY.COM
10 JunThe Shadow AI ProblemOrganizations are rapidly adopting generative AI tools, but many employees are experimenting with unauthorized platforms outside official IT oversight. Security leaders are now being forced to decide which AI services meet enterprise requirements and which should be blocked. Not …YOUTUBE.COM
10 JunIdentity theft is turning into a chain reaction for victimsFor a growing number of victims, identity theft no longer ends with a fraudulent charge or a compromised account. More than one in four people who contacted the Identity Theft Resource Center during the reporting period were dealing with multiple identity-related incidents, accor…HELPNETSECURITY.COM
10 JunPatch Tuesday notes: Microsoft fixes a record 200 flaws.Nightmare Eclipse leaks another Windows zero-day. Researchers disclose two critical flaws in AI Chrome extensions. Business news: Cyera closes a $600 million Series G round.THECYBERWIRE.COM
10 JunCISA gives agencies new vulnerability remediation deadlines that take risk levels into accountThe cybersecurity agency says it wants to help network defenders prioritize the fixes that matter the most.CYBERSECURITYDIVE.COM
10 JunCISA directive orders agencies to prioritize vulnerability patching in a new wayA vulnerability that meets all four criteria would need to be fixed within three days, for instance. The post CISA directive orders agencies to prioritize vulnerability patching in a new way appeared first on CyberScoop .CYBERSCOOP.COM
10 JunNightmare-Eclipse Drops Yet Another Microsoft Exploit, RoguePlanetThe disgruntled researcher released yet another PoC for a Windows Defender bug that allows for system takeover, showing no signs of abandoning their ongoing feud with Microsoft.DARKREADING.COM
10 JunAutomated Threat Hunting: Turning Threat Intelligence into Executable Hunt PlansBlake McDermott is Senior Threat Hunter at Rapid7. Every week, threat hunt teams are faced with a steady flow of blogs, advisories, and DFIR reports containing valuable intelligence about adversary behaviors, tactics, techniques, and procedures. The challenge is turning that inte…RAPID7.COM
10 JunPhones Hacked Without ClickingNSO Group’s Pegasus spyware is once again tied to attacks involving WhatsApp. Pegasus uses zero-click exploits, meaning targets do not need to click a link or open an attachment for compromise to occur. A successful zero-click exploit against modern smartphones can provide near-t…YOUTUBE.COM
10 JunTurn specs into evals for any agent with ASSERTAdaptive Spec-driven Scoring for Evaluation and Regression Testing (ASSERT) is an open-source framework for converting natural language behavior requirements into executable evaluations of AI models and agents. The post Turn specs into evals for any agent with ASSERT appeared fir…COMMANDLINE.MICROSOFT.COM
10 JunThe patch pile reaches new heights.Patch Tuesday goes big. Congress looks to harden critical infrastructure. A new Windows zero-day drops. Mobile AI creates security blind spots. AI agents fall for phishing. Browser extensions expose millions. Spammers hide behind Google Cloud Storage. CISA crowns its cyber champi…THECYBERWIRE.COM
10 JunThe ‘Miasma’ worm source code briefly leaked on GitHubThe Miasma credential-stealing attack framework, which has recently targeted open-source ecosystems through supply-chain attacks, was briefly open-sourced on GitHub. [...]BLEEPINGCOMPUTER.COM
10 JunToo Vulnerable for the C-Suite?The discussion explores how vulnerability is perceived at executive levels, especially in high-pressure leadership environments like the C-suite. Speakers argue there is a narrow balance between appearing confident and appearing weak. Leadership advice often promotes vulnerabilit…YOUTUBE.COM
9 JunMeet Hades: The malware that lies to AI security agentsThreat actors are continuing their onslaught against software supply chains, now with malware named after death itself. The newly-discovered Hades Campaign is a “highly sophisticated” supply chain compromise that targets Python developer environments and runs as soon as infected …CSOONLINE.COM
9 JunThe architecture of subtraction: Why it’s time to erase the roads, not just map the trafficThe advent of AI-assisted vulnerability discovery and autonomous exploit development has brought about a new age in cybersecurity—one in which we can no longer rely on patching as a primary defense mechanism. Patching is, by definition, a reactive approach to security. It cannot …HELPNETSECURITY.COM
9 JunTreating AI agents like service accounts for federated query securityIn this interview with Help Net Security, Paras Malhotra, CISO at Starburst, explains how the company handles data governance across federated query environments. Topics include layering Starburst’s access controls above native source permissions, tiering vendor risk across…HELPNETSECURITY.COM
9 JunMalware ships with bugs that defenders could use against itStatic analysis tools have spent years scanning legitimate software for security bugs before it goes out the door. The same scanners work on malware, and malware carries a steady supply of its own bugs. Researchers ran four of these tools across 658 leaked malware projects and fo…HELPNETSECURITY.COM
9 JunThe Anatomy of Cloud Ransomware with Matt CastriottaAre your cloud security controls actually protecting your infrastructure, or are they just keeping the lights on? With host ⁠Caleb Tolin⁠, ⁠Matt Castriotta⁠, Field CTO for Cloud at ⁠Rubrik⁠, breaks down the tactical gaps exposed when organizations blindly replicate data center mi…THECYBERWIRE.COM
9 Jun KEVGoogle patches new Chrome zero-day flaw exploited in the wildGoogle has released emergency updates to patch another Chrome zero-day vulnerability that has been exploited in the wild, the fifth such flaw patched since the start of the year. [...]BLEEPINGCOMPUTER.COM
9 JunScanner Results Are a Starting Point. Here's What Comes Next. - Federico Kirschbaum - ASW #386Most AppSec teams are working through more findings than their teams can validate. SAST surfaces thousands of potential issues. DAST generates alert volume that outpaces triage capacity. Somewhere in that output are the vulnerabilities that matter, the ones that are actually expl…YOUTUBE.COM
9 JunInfosecurity Europe: Why JLR’s CISO Enforced In-Person Password Resets Following Cyber-AttackSpeaking at Infosecurity Europe, Ashish Shrestha, former CISO at Jaguar Land Rover revealed why he wanted over 30,000 employees to change their passwords in the immediate aftermath of the incidentINFOSECURITY-MAGAZINE.COM
9 Jun KEVGoogle Chrome emergency update fixes actively exploited flaw in V8Google has released Chrome 149.0.7827.102/.103 for Windows and macOS, as well as Chrome 149.0.7827.102 for Linux, addressing 74 security vulnerabilities, including a high-severity zero-day flaw in the V8 JavaScript engine that the company says has been exploited in the wild. The …CYBERINSIDER.COM
9 JunCISA gives feds 3 days to patch Check Point VPN bug exploited as zero-dayCISA has ordered U.S. government agencies to secure their Check Point Remote Access VPN and Mobile Access deployments against a critical vulnerability exploited in zero-day attacks by Qilin ransomware affiliates. [...]BLEEPINGCOMPUTER.COM
9 Jun KEVCheck Point Warns Critical Auth Bypass Bug Exploited in the WildCheck Point says a critical vulnerability in its Remote Access VPN and Mobile Access solutions has been exploited by QilinINFOSECURITY-MAGAZINE.COM
9 JunCheck Point VPN Zero-Day Exploited in Qilin Ransomware AttacksThe authentication bypass vulnerability allows attackers to establish VPN connections without a valid password. The post Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
9 JunMythos Preview can weaponize N-day vulnerabilities in hoursMythos Preview can develop working exploits from newly disclosed software vulnerabilities in hours, cutting down a process that has historically taken days or weeks, according to Anthropic. Anthropic’s recent cybersecurity research has largely focused on zero-days, vulnerab…HELPNETSECURITY.COM
9 JunThe Flip That Broke the Cali CartelNow that drug cartels can be labeled foreign terrorist organizations, how do you dismantle one? As part of his 26 years at the Drug Enforcement Administration, retired Special Agent Chris Feistl was on a team that brought the demise of the Cali Cartel in Colombia. One of the worl…THECYBERWIRE.COM
9 JunWill AI Kill the Bug Bounty Industry?Anthropic's Mythos is accelerating vulnerability discovery to machine speed, forcing the bug bounty industry and offensive security teams to adapt to a future where finding flaws is no longer the hard part. The post Will AI Kill the Bug Bounty Industry? appeared first on Security…SECURITYWEEK.COM
9 JunSecurity shifts to the human layer as AI scams surgeCybercriminals are increasingly reshaping familiar social-engineering campaigns around the way employees use AI, with separate advisories from Microsoft and Google documenting how attackers are adapting scams to AI-powered tools, trusted digital services, and changing workplace b…CSOONLINE.COM
9 Jun KEVUpdate Chrome: Google patches actively exploited vulnerability and 73 othersGoogle's latest Chrome update fixes 74 security vulnerabilities, including one under active attack.MALWAREBYTES.COM
9 JunApple Intelligence can now replace weak passwords without user interventionApple’s next generation of Apple Intelligence, the company’s personal intelligence system, expands its capabilities and introduces new security features in Passwords. Automatically Fix Passwords (Source: Apple) Introduced as a standalone app in 2024, Passwords gives users a centr…HELPNETSECURITY.COM
9 JunResearchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight ModelsUniversity of Toronto researchers have built and tested a proof-of-concept AI-driven computer worm that uses a locally hosted open-weight large language model to reason its way through a network, generate tailored attack strategies for each target it encounters, and replicate its…THEHACKERNEWS.COM
9 JunNew Platform Uses Cryptographic Invisibility to Protect AI-Built ApplicationsAtsign’s AI Architect applies cryptographic protections to agentic software development, aiming to prevent attackers from exploiting vulnerabilities by making application identities effectively invisible. The post New Platform Uses Cryptographic Invisibility to Protect AI-Built A…SECURITYWEEK.COM
9 JunSAP Patches Critical NetWeaver, Commerce VulnerabilitiesThe flaws could lead to the disclosure of sensitive information, memory corruption, and disruption of normal system usage. The post SAP Patches Critical NetWeaver, Commerce Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
9 JunHackers pose as women seeking romance to spy on Russian soldiersThe group, dubbed SiribClone by Russian cybersecurity firm F6, has been active since at least the summer of 2025 and has primarily targeted members of the Russian armed forces stationed in border regions and combat zones.THERECORD.MEDIA
9 JunWhy AI Can’t Replace PentestersA “clean” pentest report is not always enough. The real value often comes from explaining what attacks were attempted, what defenses held up, and why exploitation failed. That missing context is part of why AI alone struggles to replace experienced pentesters. Automated tools can…YOUTUBE.COM
9 Jun KEVCisco customers encounter another SD-WAN zero-day under attackThe defect marks the seventh actively exploited zero-day in Cisco SD-WANs this year, and the vendor has yet to release a patch. The post Cisco customers encounter another SD-WAN zero-day under attack appeared first on CyberScoop .CYBERSCOOP.COM
9 JunNew Veeam vulnerability exposes backup servers to RCE attacksVeeam has released security updates to patch a critical Backup & Replication security flaw that can be exploited to gain remote code execution (RCE) on domain-joined backup servers. [...]BLEEPINGCOMPUTER.COM
9 Jun KEVShai-Hulud variant compromises dozens of open-source Microsoft packages.Check Point patches actively exploited VPN zero-day. Hacker breaches the French government's encrypted messaging app.THECYBERWIRE.COM
9 JunClaude Mythos Turns N-Days Into N-Hours With Rapid Exploit CreationPublic LLM models with safeguards turned off can also build working exploits, increasing patch gap risks. The post Claude Mythos Turns N-Days Into N-Hours With Rapid Exploit Creation appeared first on SecurityWeek .SECURITYWEEK.COM
9 JunFrench government messaging platform breached through account hijackingFrench authorities are investigating a compromise of Tchap, the government’s secure messaging platform, after hackers hijacked a user account and gained access to public chat rooms. Tchap is the French government’s messaging platform for civil servants, ministries, an…HELPNETSECURITY.COM
9 JunMicrosoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe ContinuesMicrosoft on Monday confirmed that it temporarily removed some GitHub repositories in response to a recent security incident that led to 73 of its open-source projects being compromised to inject an information stealer into the code. "Our priority is to protect customers and the …THEHACKERNEWS.COM
9 JunCISA is rethinking how it prioritizes risks and vulnerabilities for feds, private sectorActing director Nick Andersen said a binding operational directive is en route for agencies, and that more specific discussions need to happen with critical infrastructure owners. The post CISA is rethinking how it prioritizes risks and vulnerabilities for feds, private sector ap…CYBERSCOOP.COM
9 JunCheck Point warns of zero-day flaw targeted by ransomware affiliateA vulnerability in the company’s VPN deployments has faced exploitation since early May.CYBERSECURITYDIVE.COM
9 JunXBOW tests Anthropic's Mythos Preview for offensive securityAnthropic's Mythos Preview was highly effective at finding vulnerability candidates, especially when analyzing source code. XBOW explores how the model performed across exploit discovery, reverse engineering, and live-site validation. [...]BLEEPINGCOMPUTER.COM
9 JunOpenSSL Patches High-Severity Vulnerability Found With AIA total of 18 vulnerabilities have been patched in the latest OpenSSL releases, including many that were potentially discovered by AI. The post OpenSSL Patches High-Severity Vulnerability Found With AI appeared first on SecurityWeek .SECURITYWEEK.COM
9 JunMicrosoft June 2026 Patch Tuesday, (Tue, Jun 9th)Microsoft today released patches for 204 vulnerabilities. 38 of these vulnerabilities are considered critical, and three have been disclosed before today. Six of the vulnerabilities affect Microsoft cloud solutions and do not require any user action. In addition, Microsoft incorp…ISC.SANS.EDU
9 JunCISA gives US federal agencies three days to fix a VPN bug under attack by a ransomware gangCheck Point said hackers broke into dozens of organizations by exploiting a VPN bug in several of its products used across the government.TECHCRUNCH.COM
9 JunMicrosoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flawsToday is Microsoft's June 2026 Patch Tuesday, with security updates for 200 flaws and three publicly disclosed zero-day vulnerabilities. [...]BLEEPINGCOMPUTER.COM
9 JunAnthropic releases Mythos-class Fable 5 model with safeguards for cyber risksAnthropic unveiled two new powerful AI models built on its previously restricted Mythos architecture: Claude Fable 5, which is being made broadly available, and Claude Mythos 5, which remains limited to a small group of cybersecurity and infrastructure partners. Anthropic describ…CSOONLINE.COM
9 JunSAP fixes critical flaws in NetWeaver and Commerce CloudSAP has released fixes for 15 vulnerabilities as part of its June 2026 Security Patch package, including four critical-severity flaws affecting SAP NetWeaver and SAP Commerce Cloud. [...]BLEEPINGCOMPUTER.COM
9 JunMicrosoft Patches 200 VulnerabilitiesThree of the vulnerabilities fixed with the latest Patch Tuesday updates were publicly disclosed before Microsoft addressed them. The post Microsoft Patches 200 Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
9 JunA checkmark for trust, a payload for theft.Miasma malware meddles with Microsoft. SAP fixes critical flaws, Google patches an exploited Chrome zero-day, CanisterWorm spreads through npm, Mac users face a new malvertising threat, France investigates a breach of its secure messaging platform, insurers rethink AI risk, the F…THECYBERWIRE.COM
9 JunServiceNow discloses security incident exposing customer dataServiceNow is warning about a security incident after attackers exploited an unauthenticated access flaw through a vulnerable API endpoint, allowing them to query data from customer instances. [...]BLEEPINGCOMPUTER.COM
9 JunBlame AI: Patch Tuesday Hits Record 206 CVEsVoluminous patch updates could soon be the norm, as artificial intelligence accelerates the speed and scale of vulnerability discovery.DARKREADING.COM
9 JunA Record-Breaking Patch Tuesday for June 2026Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company's monthly Patch Tuesday cycle. Nearly three dozen of those bugs earned Microsoft's most dire "critical…KREBSONSECURITY.COM
9 JunSN 1082: The Malicious Use of AI - Anthropic's Red Team ReportDiscover how Anthropic's secretive red team and the MITRE ATT&CK framework are mapping the chilling rise of malicious AI use, revealing cyber threats that now move faster than defenders can respond. Was a U.S. law firm right to pay a $20 million ransom. Could Cisco have yet a…TWIT.TV
8 JunGoogle Colab CLI opens runtimes to Claude Code and CodexGoogle released the Google Colab Command-Line Interface, a tool that connects local terminals to remote Colab runtimes. The CLI provides an execution platform for developers and AI agents, letting users provision compute, run local Python scripts on remote runtimes, and retrieve …HELPNETSECURITY.COM
8 JunDockSec: Open-source AI-powered Docker security scannerDockSec is an OWASP Incubator Project that combines three container security scanners with a language-model layer for explanation and remediation. Created by Advait Patel, the Python tool runs Trivy, Hadolint, and Docker Scout against a developer’s Dockerfile and image, cor…HELPNETSECURITY.COM
8 JunMeta AI Bug Exposes Over 20,000 Instagram AccountsMeta confirms an AI tool vulnerability led to unauthorized access to Instagram accounts after a failure in email verification during password resetINFOSECURITY-MAGAZINE.COM
8 Jun KEVSolarWinds Serv-U Vulnerability Exploited in the WildUnauthenticated attackers can exploit the flaw via specially crafted POST requests that crash the Serv-U service. The post SolarWinds Serv-U Vulnerability Exploited in the Wild appeared first on SecurityWeek .SECURITYWEEK.COM
8 JunOpenAI is locking down parts of ChatGPT to reduce data theft risksOpenAI has started rolling out Lockdown Mode for ChatGPT, an optional security setting that restricts access to external resources and several product capabilities. It is available for personal accounts, including Free, Go, Plus, and Pro plans, as well as self-serve ChatGPT Busin…HELPNETSECURITY.COM
8 JunUNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion CampaignCybersecurity researchers have disclosed details of a financially motivated data theft extortion campaign that has targeted dozens of organizations across professional, legal, and financial services in the U.S. between January and May 2026. The activity has been attributed by Goo…THEHACKERNEWS.COM
8 JunWhy most enterprise security teams would fail a military readiness testHave you ever watched a military cyber ops team go to work responding to a cyberattack simulation? It’s like that scene from Die Hard 4.0 when all the screens start flashing red and systems start shutting down; however, unlike the movies, where bumbling government IT workers are …CSOONLINE.COM
8 Jun15 tough cybersecurity questions every CISO must answerAs CISOs know, an effective security program cannot be static. Rather, it must adapt to the evolving threat landscape and an ever-changing business environment. To adapt and improve, CISOs must continuously evaluate their existing program. That starts with asking tough questions …CSOONLINE.COM
8 JunThe State of AI in SecOps, the Unintended Consequences of Vulnmaxxing, and the News - ESW #462Interview with Filip Stojkovski on the State of AI in SecOps Filip joins us to talk through the 2+ year rollercoaster that Security Operations tooling has been on since AI entered the chat. We discuss the AI SecOps market, which Filip closely tracks through his SecOps Unpacked pr…YOUTUBE.COM
8 JunMeta notifies 20,000 Instagram users whose accounts were hijacked via AI support botMeta has begun notifying approximately 20,000 Instagram users that their accounts may have been compromised after attackers exploited a flaw in an AI-assisted account recovery tool. The company says the vulnerability allowed unauthorized parties to obtain password reset links for…CYBERINSIDER.COM
8 JunOxford University discloses data breach after careers platform hackThe University of Oxford disclosed a new data breach last week after being informed by its third-party provider, Group GTI, that its CareerConnect career services platform had been compromised. [...]BLEEPINGCOMPUTER.COM
8 JunRidgeBot 7.0 automates Active Directory attack simulations for security validationRidge Security has announced the release of RidgeBot 7.0, an update to its automated security validation platform that introduces automated Windows Active Directory penetration testing capabilities. The new version enables organizations to conduct end-to-end domain compromise sim…HELPNETSECURITY.COM
8 JunConnectSecure’s Patch 360 gives MSPs control over patch testing and deploymentConnectSecure has announced the launch of Patch 360, a patch management solution built for managed service providers (MSPs) to reduce deployment risk while accelerating vulnerability remediation. Patch management has long followed a “deploy-and-hope” model, with teams addressing …HELPNETSECURITY.COM
8 JunThe Hardest ForkMythos is real. I know a big chunk of the industry thinks it's a marketing stunt, and I get why. I get it. But I've seen the findings, and they're bad. These aren't "whoops, this line right here is wrong, and that's RCE." They're novel combinations of a few dozen issues out of th…THEHACKERNEWS.COM
8 Jun KEVEverest Forms Vulnerability Exploited to Hack WordPress SitesThe flaw allows attackers to execute arbitrary code remotely and has been exploited in the wild for two months. The post Everest Forms Vulnerability Exploited to Hack WordPress Sites appeared first on SecurityWeek .SECURITYWEEK.COM
8 JunCheck Point links VPN zero-day attacks to Qilin ransomware gangIsraeli cybersecurity company Check Point has released security updates to patch a critical flaw affecting Remote Access VPN and Mobile Access deployments, which was exploited in zero-day attacks. [...]BLEEPINGCOMPUTER.COM
8 JunHackers used Meta’s AI support system to hijack over 20,000 Instagram accountsMeta has revealed that attackers hijacked 20,225 Instagram accounts by exploiting a flaw in the company’s AI-assisted account recovery system. According to the company, a vulnerability in High Touch Support (HTS) allowed unauthorized parties to perform password resets on In…HELPNETSECURITY.COM
8 JunNew Relic expands observability into AI-assisted software developmentNew Relic has announced AI Coding Observability, an open-source tool for monitoring AI-assisted software development workflows. As organizations adopt AI coding assistants, these tools often operate outside existing observability systems, limiting visibility into their use. AI Co…HELPNETSECURITY.COM
8 Jun⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and MoreMonday again. The weekend was meant to be quiet. It wasn't. Last week had poisoned packages, a broken AI helper, and a worm tearing through repos. The ugly part: basic tricks still worked. A chatbot got fooled. A bot token got leaked inside the malware. The same old mistakes show…THEHACKERNEWS.COM
8 JunTurning Cloudflare’s threat indicators into real-time WAF rulesCloudflare customers can now use Cloudforce One threat intelligence directly within the WAF to block high-risk traffic. By using new cf.intel fields, security teams can automate protection against specific threat actors and targeted industries in real time.CLOUDFLARE.COM
8 JunNew open-source app Loupe reveals how iPhones are fingerprintedPrivacy researchers Mysk have released Loupe, a free and open-source iOS app that shows users what information apps can learn about their devices through publicly available iOS APIs. The tool highlights how data such as language settings, device characteristics, installed apps, a…CYBERINSIDER.COM
8 JunGogs patches critical zero-day enabling remote code executionGogs has patched a critical security zero-day flaw that can allow attackers to compromise Internet-facing instances and access any repositories (including private ones). [...]BLEEPINGCOMPUTER.COM
8 JunCritical Zcash Vulnerability Found and FixedIf you’re a user—owner?—of this cryptocurrency, this is important: On May 29, the security researcher Taylor Hornby found a critical vulnerability in Zcash Orchard privacy pool using Claude Opus 4.8. The Zcash team hired Hornby specifically to look for this kind…SCHNEIER.COM
8 JunTeamPCP Supply Chain Campaign: Activity Through 2026-06-07, (Mon, Jun 8th)This diary continues the Internet Storm Center&#;x26;#;39;s tracking of the TeamPCP supply chain campaign, first documented in the SANS white paper When the Security Scanner Became the Weapon and most recently in the handler diary Activity Through 2026…ISC.SANS.EDU
8 JunWhen Executives Force AI AdoptionThe clip contrasts traditional security operations — where tooling and processes evolve from practitioner feedback — with modern AI adoption, which is often driven by executive-level spending decisions. When large AI purchases happen before teams define real operational needs, or…YOUTUBE.COM
8 JunMicrosoft’s open source tools were hacked to steal passwords of AI developersMicrosoft shut down dozens of GitHub code repositories for Azure and AI coding tools after a reported hack.TECHCRUNCH.COM
8 JunICYMI: May 2026 @AWS SecurityRead all about the latest AWS security features, compliance updates, and hands-on resources in our new, monthly digest posts. You’ll find expert blog posts, new service capabilities, code samples, and workshops. AWS Security Blog posts This month’s AWS Security Blog posts covered…AWS.AMAZON.COM
8 JunCheck Point VPN Flaw Exploited Since Early MayA newly discovered, critical zero-day vulnerability is under attack; a Qilin ransomware affiliate has been blamed for at least one incident.DARKREADING.COM
7 JunBaker Distributing - 102,935 breached accountsIn May 2026, the HVAC/R wholesale distributor Baker Distributing Company was added to the ShinyHunters data extortion group's "pay or leak" site . In early June, the group publicly published data they claimed had been obtained from Baker's SharePoint and Salesforce infrastructure…HAVEIBEENPWNED.COM
7 JunWeek in review: Cisco SD-WAN 0-day exploited, Patch Tuesday forecastHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: OWASP Agent Memory Guard: Stop AI agents from being weaponized through their own memory Agent Memory Guard is an open-source runtime defense layer that sits between an agent and its …HELPNETSECURITY.COM
7 JunEmphere Raises $2.1 Million for AI-Powered Vulnerability RemediationEmphere’s solution delivers AI-driven remediation to software companies to speed up releases. The post Emphere Raises $2.1 Million for AI-Powered Vulnerability Remediation appeared first on SecurityWeek .SECURITYWEEK.COM
7 JunHands on with Intelligent Terminal, an AI-powered Windows TerminalMicrosoft has created an open-source fork of Windows Terminal called "Intelligent Terminal," and it allows you to use AI directly inside Terminal without interfering with the regular session. [...]BLEEPINGCOMPUTER.COM
6 JunCybersecurity Today Month in Review: Microsoft Zero-Days, AI DeregulationHost Jim Love and panelists David Shipley, Laura Payne, and Jeff Williams discuss a researcher ("Chaotic/Nightmare Eclipse") publicly disclosing multiple Windows zero-days affecting components including Defender and BitLocker, frustration with Microsoft's vulnerability disclosure…CYBERSECURITYTODAY.LIBSYN.COM
6 JunAI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 BugsTwo things landed within days of each other this week. A security startup reported 21 previously unknown vulnerabilities in FFmpeg, the media library inside almost everything that touches video, all of them found by an autonomous AI agent. The same week, Google shipped Chrome 149…THEHACKERNEWS.COM
6 JunMiasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain AttackMicrosoft's GitHub repositories have become the latest to fall victim to the ongoing Miasma self-replicating supply chain attack campaign. The incident impacted 73 Microsoft repositories across four of its GitHub organizations, including Azure, Azure-Samples, Microsoft, and Micro…THEHACKERNEWS.COM
6 JunPresident Trump signs an executive order on AI oversight.Anthropic is reportedly helping the NSA deploy Mythos. Acer warns of two maximum-severity zero-days.THECYBERWIRE.COM
5 JunNew HTTP/2 Bomb Attack, Trump's AI Security Reviews, Android Zero-Day & The Patching CrisisA newly disclosed attack called HTTP/2 Bomb can crash major web servers in seconds using a single computer and a modest internet connection. Researchers say the attack combines two known techniques into a powerful memory-exhaustion exploit affecting widely used platforms includin…CYBERSECURITYTODAY.LIBSYN.COM
5 JunAI tools becoming hot commodities on ransomware marketplacesSales of AI-based tools is accelerating within underground ransomware marketplaces, lowering the barrier to entry for new actors in the process. An analysis of Telegram channels, 20 dark web forums, and five underground markets by anti-ransomware platform vendor Halcyon found tha…CSOONLINE.COM
5 JunAgentGG: Open-source agentic SAST scannerStatic analysis tools have spent years matching source code against known-bad patterns and handing engineers long lists of candidate issues to triage by hand. AgentGG approaches the same job with AI agents that read the code, follow imports, walk the call graph, and confirm a fin…HELPNETSECURITY.COM
5 JunThieves can pull off keyless car theft in under a minute and here’s how to stop themA keyless car can be stolen in under a minute. Two people, a pair of cheap radio amplifiers, and a fob sitting on a hallway table inside the house. That is enough. No broken glass. No alarm. No sound. Most keyless cars remain vulnerable The vulnerability runs across the global ma…HELPNETSECURITY.COM
5 JunNew infosec products of the week: June 5, 2026Here’s a look at the most interesting products from the past week, featuring releases from Asimily, depthfirst, Diligent, Hyland, MazeBolt, and Noma. Asimily turns device risk into automated network policy Asimily has launched Segmentation Orchestration, enabling connected-device…HELPNETSECURITY.COM
5 JunChrome 149 Patches 429 VulnerabilitiesOver 100 bugs are critical or high-severity, mainly use-after-free and insufficient validation of untrusted input flaws. The post Chrome 149 Patches 429 Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
5 JunAttackers obtained encrypted password vaults from some Dashlane user accountsDashlane has disclosed new details about a brute-force attack that let a threat actor access some customer accounts and copy encrypted vaults. Dashlane said it found no evidence that the attackers compromised its internal systems. The company first acknowledged the incident on Ma…HELPNETSECURITY.COM
5 JunBinary Choice Researcher Or Threat ActorMicrosoft stated that uncoordinated vulnerability disclosures, especially those including proof-of-concept exploit code before patches exist, can create real-world risk by enabling attackers to weaponize vulnerabilities faster. The debate reflects a long-standing conflict in cybe…YOUTUBE.COM
5 JunEU unveils tech sovereignty package to cut reliance on US, Chinese suppliersThe package bundles two draft laws — a Chips Act 2.0 and a Cloud and AI Development Act (CADA) — alongside an Open Source Strategy and a roadmap for digitalizing the energy system.THERECORD.MEDIA
5 JunIn Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISAOther noteworthy stories that might have slipped under the radar: Ultrahuman data leak, The Gentlemen ransomware analysis, Hola Browser bundles miner. The post In Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISA appeared first on Security…SECURITYWEEK.COM
5 JunSeeking Counsel: Ongoing Targeted Campaign Against US Law FirmsWritten by: Chad Reams, Tufail Ahmed, Keith Knapp, Ashley Frazer, Tyler McLellan Introduction From January through May 2026, Mandiant identified a financially motivated data theft extortion campaign executed by the threat cluster UNC3753 (also tracked as "Luna Moth," “Chatty Spid…CLOUD.GOOGLE.COM
5 JunNightmare Eclipse incident shows the researcher-vendor fights may never fully go awayWhen a researcher went public with Microsoft vulnerabilities, it laid bare a conflict that has never really been solved. The post Nightmare Eclipse incident shows the researcher-vendor fights may never fully go away appeared first on CyberScoop .CYBERSCOOP.COM
5 JunCisco warns zero-day flaw in SD-WAN is being exploitedThe company cautioned that no current patches are available and the flaw could allow an attacker to conduct command injection attacks.CYBERSECURITYDIVE.COM
5 JunSprawling new House AI bill includes frontier model oversight, open-source security grantsThe legislation has already drawn widespread criticism for its proposal to preempt state AI laws.CYBERSECURITYDIVE.COM
5 JunAndroid Spyware Asin Targets Arabic Users via Fake News, PDF and War Map AppsArabic-speaking users have emerged as the target of a new Android spyware codenamed Asin, according to findings from ESET. The Slovakian cybersecurity company said it first detected the malware spread via multiple campaigns in early 2025, with each attack wave making use of disti…THEHACKERNEWS.COM
5 JunOWASP Incubator Project Helps Developers Find and Fix Vulnerable Dependencies in SecondsCVE Lite CLI is a free, open-source command line tool that scans your projects in seconds and tells you exactly which included packages contain a vulnerability. The post OWASP Incubator Project Helps Developers Find and Fix Vulnerable Dependencies in Seconds appeared first on Sec…SECURITYWEEK.COM
5 JunPatching fast and slow: Ruby devs delay to defend against supply chain attackThe team behind RubyGems, a package hosting site for Ruby developers, has added a new feature to bundler, a tool for managing Ruby packages (or ‘gems’) to protect developers against the recent wave of software supply chain attacks : A cooling-off period before recently updated pa…CSOONLINE.COM
5 JunBuilding secure B2C applications with fine-grained access control using Amazon Cognito and Amazon Verified PermissionsModern web applications require robust security controls to protect user data and application resources. Authentication and authorization are two fundamental pillars of application security that answer critical questions: Who are you? and What are you allowed to do? Implementing …AWS.AMAZON.COM
5 JunCISA: Hackers now exploit SolarWinds Serv-U flaw to crash serversCISA warned today that hackers are now actively exploiting a recently patched high-severity SolarWinds Serv-U flaw to crash servers. [...]BLEEPINGCOMPUTER.COM
5 Jun KEVSeven Cisco Zero-Days AlreadyThis discussion covers another actively exploited Cisco SD-WAN vulnerability affecting Cisco Catalyst SD-WAN Manager. According to the clip, this marks the seventh SD-WAN zero-day reported in 2026. Successful exploitation can allow authenticated attackers to execute commands as r…YOUTUBE.COM
5 JunLocal AI, Salesforce, Fluttershell, Aspose, http/2, Cisco, Used Tech, Josh Marpet - SWN #587Local AI, Salesforce, Fluttershell, Aspose, http/2 bomb, Passwords, Cisco, Used Tech, Josh Marpet, and More on this episode of the Security Weekly News Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-587YOUTUBE.COM
5 JunCybersecurity Hygiene Reinforced by the 2026 Verizon DBIRThe 2026 Verizon DBIR highlights how CIS Controls and CIS Benchmarks strengthen cybersecurity hygiene and defend against today’s top attacks.CISECURITY.ORG
🔥 INCIDENT REPORTING 978[−]
2 SepVali Cyber ZeroLock 5 brings MFA to the hypervisor command lineVali Cyber released ZeroLock 5, a major release focused on closing the two most dangerous gaps in hypervisor security: insider threats and stolen credentials on ESX and Linux hosts. The hypervisor is now the target Over the past two years, ransomware operators and nation-state ac…HELPNETSECURITY.COM
2 SepFulcrumSec Claims Responsibility for Manchester Airport Group BreachThreat group FulcrumSec claims MAG breach and leaks 550GB of data onlineINFOSECURITY-MAGAZINE.COM
2 SepA battery storage cyberattack would look exactly like a badly tuned controllerBatteries connected to the grid make money by reacting to frequency, pushing power out when it sags and soaking it up when it rises. A few hundred of them moving together, on command from someone who should not have the command, would look the same on a control room screen right …HELPNETSECURITY.COM
2 SepDark web site puts 153 million driver’s licenses and millions more IDs up for saleThe FBI is investigating a possible breach of idscan.net linked to 153 million driver’s license scans for sale online.MALWAREBYTES.COM
2 SepNutex Health Says Patient Data Stolen, Hackers Threaten LeakThe US healthcare provider confirmed that sensitive patient and employee data, alongside financial and business information, were exfiltrated by a third partyINFOSECURITY-MAGAZINE.COM
2 SepAn AI-Assisted Cyber Attack: Inside a Unit 42 InvestigationUsing autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks. The post An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
2 SepAnthropic Details Response to Security Incidents, Unveils Enterprise SafeguardsAnthropic introduced Enterprise Frontier Safeguards (EFS), a system that combines zero data retention with automated monitoring for misuse. The post Anthropic Details Response to Security Incidents, Unveils Enterprise Safeguards appeared first on SecurityWeek .SECURITYWEEK.COM
2 SepHow to Secure Enterprise AI: From Adoption to Incident ReadinessThe debate about whether AI delivers business value is over. The challenge now is implementing it at scale and securely across every function while meeting board-level pressure to move fast. Organizations must focus on adopting AI at business speed without losing control of cyber…THEHACKERNEWS.COM
2 SepBGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root AccessVirtualizor said hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic. The hackers then used the diverted update traffic to deliver a malicious Virtualizor package to some installations. A hosting-provider account separately said 5 of its 34 checked V…THEHACKERNEWS.COM
2 SepGambling Goblin Turns Brazilian Government Sites Into SEO WeaponsGambling Goblin compromised Brazilian government sites to drive gambling traffic through SEO fraudINFOSECURITY-MAGAZINE.COM
2 Sep153 million driver’s licenses exposed in suspected IDScan breachThe FBI is investigating an apparent breach involving identity verification provider IDScan after a dark web service began selling access to more than 153 million US and Canadian driver’s license scans, according to an exclusive KrebsOnSecurity report. The marketplace, called Nex…CYBERINSIDER.COM
2 SepMalicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting PagesA Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting onlin…THEHACKERNEWS.COM
2 SepRansomware protection for MSPs: A 6-point checklist for faster recoveryRansomware resilience requires more than backups or endpoint detection alone. Acronis outlines six capabilities MSPs should test across client environments, from reducing exposure and detecting attacks to preserving recovery points and restoring operations quickly. [...]BLEEPINGCOMPUTER.COM
2 SepNew pro-Ukraine hacker group targets Russian companies with custom ransomwareThe group, which calls itself VantaCore, has targeted at least seven known victims, Russian cybersecurity firm F6 said in a report published this week.THERECORD.MEDIA
2 SepHealth data of more than 9.5 million people leaked from Aesto record systemThe healthcare data company Aesto informed federal regulators this week that more than 9.5 million people had sensitive information leaked during a cyberattack last December.THERECORD.MEDIA
2 SepIt sure looks like hackers breached a major ID card verification serviceAn identity theft search site claimed to have more than 150 million driver's license photos stolen from an ID verification service. The crime site has now shut down.TECHCRUNCH.COM
1 SepQuestel - 1,226,209 breached accountsIn August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising c…HAVEIBEENPWNED.COM
1 SepHealthcare Giant McKesson Investigates Data Breach IncidentShinyHunters claims to have stolen 284 million records from McKessonINFOSECURITY-MAGAZINE.COM
1 Sep9.5 Million Impacted by Aesto Health Data BreachHackers stole personal and health information from the healthcare technology company’s AWS infrastructure. The post 9.5 Million Impacted by Aesto Health Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
1 SepRansomware Gang Claims Nutex Health Data BreachThe company has notified the SEC that hackers accessed patient, employee, provider, business, and financial information. The post Ransomware Gang Claims Nutex Health Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
1 SepHealthcare facilities operator Nutex says patient, employee data stolen in August incidentCybercriminals breached company data and made an extortion attempt with it, Houston-based Nutex Health said in a filing with federal regulators.THERECORD.MEDIA
1 SepCrowdStrike launches cyber frontier AI models, agentic security systemCrowdStrike today announced SafeMind, a cybersecurity-specific AI model-harness system that CEO George Kurtz described as the “first complete agentic system for cybersecurity” at the company’s Fal.Con conference in Las Vegas. At the heart of SafeMind are two purpose-built cyberse…CSOONLINE.COM
1 SepChina's 'Fire Ant' campaign used compromised Cisco routers as platform for more attacksA hacking operation dubbed Fire Ant "didn’t just compromise systems," according to researchers. "It compromised the trust layer those systems depend on."THERECORD.MEDIA
1 SepStronger Security Drives Ransomware Groups to Recruit From WithinSome security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cost companies millions.DARKREADING.COM
1 SepWeekly Update 519: Breaches & Data IntegrityPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite It does feel like I've bitten off too much and am now chewing like crazy this week. The 3D printing talk with Elle in Oslo, the &q…TROYHUNT.COM
31 AugAurora Ransomware Operators Use Cursor AI in Attacks Against 10 TargetsThreat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security. The two independent analyses are bas…THEHACKERNEWS.COM
31 AugChina-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security LogsA China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, an…THEHACKERNEWS.COM
31 AugMcKesson confirms cyber incident after ShinyHunters claims patient-data theftHealthcare company McKesson acknowledged a data breach. ShinyHunters claims to have stolen hundred of millions of recordsMALWAREBYTES.COM
31 AugBerlin says it won’t pay ransom after hackers steal government dataGoverning Mayor Kai Wegner said that Berlin had received an extortion demand following the cyberattack, which was discovered in mid-August.THERECORD.MEDIA
31 AugPharmaceutical giant McKesson warns of 'service degradation' following cyberattackThe pharmaceutical and healthcare technology company McKesson informed regulators it is in the early stages of investigating a cybersecurity incident involving an unnamed third-party application.THERECORD.MEDIA
31 AugMcKesson Confirms Data Breach as Attacker Deadline LoomsThe ShinyHunters extortion group has claimed the theft of 284 million records from the company’s systems. The post McKesson Confirms Data Breach as Attacker Deadline Looms appeared first on SecurityWeek .SECURITYWEEK.COM
31 AugWhat the Hugging Face Incident Teaches Security Leaders About AI Agent AccessSecurity teams must treat autonomous agents as highly privileged identities. The post What the Hugging Face Incident Teaches Security Leaders About AI Agent Access appeared first on SecurityWeek .SECURITYWEEK.COM
31 AugBoston Scientific Still Recovering From CyberattackThe company has called in CrowdStrike and others to investigate the attack that caused global network disruption. The post Boston Scientific Still Recovering From Cyberattack appeared first on SecurityWeek .SECURITYWEEK.COM
31 AugExtortion Group Claims Manchester Airports Group Data BreachFulcrumSec says it stole over 80 GB of data from Manchester Airports Group and plans to leak it online. The post Extortion Group Claims Manchester Airports Group Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
31 AugBerlin Won’t Pay Extortion Group Claiming Data TheftThe Rhysida ransomware group has claimed the exfiltration of over 5TB of data, including personal information and credentials. The post Berlin Won’t Pay Extortion Group Claiming Data Theft appeared first on SecurityWeek .SECURITYWEEK.COM
31 AugAnthropic locks out Claude users after infostealers hijack login sessionsAnthropic has started locking users out of their Claude accounts due to their login sessions having been compromised through infostealer malware. “The malware identified in this campaign so far include Vidar, Lumma (LummaC2), StealC, RedLine and Acreed on Windows, and Atomi…HELPNETSECURITY.COM
31 AugHackers claim millions of patient records stolen during data breach at healthcare giant McKessonThe company, which distributes medicines and medical devices to hospitals and healthcare practices across the U.S., said it was hacked and expects intermittent service degradation.TECHCRUNCH.COM
31 AugMicrosoft warns of TerminalFix attacks deploying reverse tunnelsA new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. [...]BLEEPINGCOMPUTER.COM
30 AugSecurity Affairs newsletter Round 592 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Hack One Robot, Reach the Next: U…SECURITYAFFAIRS.COM
29 AugHack One Robot, Reach the Next: Unitree G1 Security FlawsA researcher chained two Unitree G1 flaws to gain root access remotely and showed how a compromised robot could attack others nearby. Security researcher Olivier Laflamme spent about three months digging into the Unitree G1 humanoid robot and eventually found a way to fully compr…SECURITYAFFAIRS.COM
28 AugWhat 90 days and a small budget can buy in AI agent securityIn this interview with Help Net Security, Prasad Tharippala, Field CISO at Versa, explains what organizations miss when they run open-weight models in house. He covers the hidden costs of GPU infrastructure, licensing review and staffing, and why hardening and incident response b…HELPNETSECURITY.COM
28 AugThe AI agent swarm that attacked Hugging Face is a warning for the futureAn army of AI agents was responsible for the Hugging Face incident. What does it mean for the future of AI?MALWAREBYTES.COM
28 AugATF confirms cyberattack hit system containing info on its investigation targetsThe prolific ransomware group Qilin claimed responsibility for the attack. ATF insists the incident was limited to a standalone system and hasn’t impacted critical operations. The post ATF confirms cyberattack hit system containing info on its investigation targets appeared first…CYBERSCOOP.COM
28 AugFrontier AI tipping the scales toward cyber adversariesResearchers at Palo Alto Networks’ Unit 42 warn that threat actors are already using AI to accelerate cyberattacks beyond the abilities of modern defenses.CYBERSECURITYDIVE.COM
28 AugWindow to Tackle Surge in AI-Enabled Cyber Attacks Narrowing, Tech Giants WarnMore than 100 companies, including OpenAI, Anthropic, Google and Microsoft, have urged collective action to unlock the power of AI to protect critical public servicesINFOSECURITY-MAGAZINE.COM
28 AugShinyHunters claims McKesson data breach exposing 284 million patient recordsThe ShinyHunters threat group claims it compromised McKesson and obtained data on over 284 million patient records, including highly sensitive medical, identity, prescription, and healthcare provider information. CyberInsider reviewed samples privately provided by the threat acto…CYBERINSIDER.COM
28 AugHundreds of OpenAI Agents Invaded Hugging Face ServersThe Hugging Face incident was bigger and worse than previously thought, with approximately 700 agents collaborating on a sophisticated, multistage attack.DARKREADING.COM
28 AugYou Need Cyber Deception for OTThe frustrating reality after an OT cyberattack: no data, no trail, and no history.DARKREADING.COM
27 AugProton suffers major data center outage, says no user data was lostProton experienced a global service outage earlier today after a critical cooling failure hit one of its data centers in Frankfurt, disrupting access to Proton Mail and other services. The company says services have since been restored and that no user data was lost during the in…CYBERINSIDER.COM
27 AugBoston Scientific Reveals Global Disruption After Cyber IncidentMedTech giant Boston Scientific has revealed IT outages following a cyber incidentINFOSECURITY-MAGAZINE.COM
27 AugOpenAI: Hugging Face Incident a “Warning Shot” to the WorldOpenAI reveals that unauthorized message boards were at the heart of the recent Hugging Face breachINFOSECURITY-MAGAZINE.COM
27 AugPro-Russian Hackers Claim Responsibility for Major Cyberattack on Norway’s Public Digital ServicesThe pro-Russian hacker group Server Killers claimed responsibility for the attack. The post Pro-Russian Hackers Claim Responsibility for Major Cyberattack on Norway’s Public Digital Services appeared first on SecurityWeek .SECURITYWEEK.COM
27 AugThreat landscape for industrial automation systems. Q2 2026The report contains statistics on industrial threats for Q2 2026, including ransomware, miners, spyware and other threats that were detected and blocked on industrial control systems.SECURELIST.COM
27 AugCyberattack Causes Global Disruption at Boston ScientificThe cybersecurity incident has disrupted Boston Scientific’s ability to process and ship customer orders. The post Cyberattack Causes Global Disruption at Boston Scientific appeared first on SecurityWeek .SECURITYWEEK.COM
27 AugCarhartt data breach exposes information of 12.9 million accountsThe ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned. [...]BLEEPINGCOMPUTER.COM
27 AugCyberattack causes network outage at Boston Scientific, disrupts global operationsMedical technology company Boston Scientific suffered a cyberattack that disrupted its IT systems and caused a network outage, affecting global operations. Boston Scientific makes devices for minimally invasive procedures, including stents, catheters, pacemakers and defibrillator…HELPNETSECURITY.COM
27 AugVersion Control DFIR: a Cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOpsA practitioner’s guide to log visibility, incident readiness, and threat hunting across the major version control services.WIZ.IO
27 AugDOJ firearms agency says hackers breached system containing investigation targetsThe Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed it experienced a cyberattack on a system containing investigation information, as a prolific ransomware gang claimed to have carried out the breach.THERECORD.MEDIA
27 AugManchester Airports Group Hit by Cyber IncidentCustomer data linked to bookings and airport Wi-Fi registrations at Manchester, Stansted and East Midlands airports has been accessed by an unauthorized third partyINFOSECURITY-MAGAZINE.COM
27 AugHere’s all the times AI has gone rogue and hacked other companiesA recap of all the incidents involving LLMs made by Anthropic, Meta, and OpenAI, which went rogue and attacked real companies and individuals on the internet.TECHCRUNCH.COM
27 AugCyberattack on Manchester Airports Group exposes data of 8.7 million customersA spokesperson told The Yorkshire Post that roughly 8.7 million people were impacted, although they did not provide a date range. They added that in the “vast majority” of cases, the only information accessed was an email address.THERECORD.MEDIA
27 AugChinese and Russian spies stepping up cyberattacks, German companies reportForeign intelligence services, particularly those from China and Russia, are increasingly behind cyberattacks on German companies, according to a new survey of the country’s private sector.THERECORD.MEDIA
27 AugFederal authorities disrupt China-backed hacking operation targeting US critical infrastructureCompromised IoT devices were used in a yearslong campaign against key sectors and U.S. government agencies.CYBERSECURITYDIVE.COM
27 AugFlock wants privacy to meet surveillance halfwayFlock’s CEO wants a compromise between privacy and public safety, but the public has already compromised enough.MALWAREBYTES.COM
27 AugHundreds of agents went rogue in lead up to Hugging Face breachOpenAI released a technical breakdown of the historic incident and plans changes to prevent such an occurrence from happening again. CYBERSECURITYDIVE.COM
27 AugATF declares ‘major incident’ as ransomware gang claims hackThe ATF is the latest federal government agency in recent years to notify Congress of a "major incident" involving its cybersecurity.TECHCRUNCH.COM
27 AugMeta gets a Meta-sized bill.Meta settles. Australian police arrest two alleged TeamPCP members. The White House moves to shore up water utility cybersecurity. ATF reports a major cyber incident. The Navy tells sailors to lock down social media. The FBI warns of a prolific Chinese hacking operation. Bill Gat…THECYBERWIRE.COM
27 AugLegitimate Tools Became Attack ToolsA ransomware attack against a hospital was stopped after attackers attempted to install three legitimate remote-access tools. The tools themselves weren't malware, but they were being used as part of the attack chain. Stopping the ransomware payload wasn't what prevented the atta…YOUTUBE.COM
26 AugIranian hackers darken UK power plant, ShinyHunters breaches the threat hunters, Zombie Visa cardsIran-Linked Cyberattack Hits UK Power Facility, ShinyHunters Phish ReliaQuest, LockBit Claims US Bancorp, Teams Blocks Bots, Expired Visa Card Flaw Cyber Security Today host David Shipley reports a UK power facility was taken offline for four days in July by a cyberattack linked …CYBERSECURITYTODAY.LIBSYN.COM
26 AugJADEPUFFER: An End-to-End Agentic-Led Ransomware AttackIn this episode of the Microsoft Threat Intelligence Podcast, we are joined by Sysdig’s Michael Clark and Crystal Morin to discuss ⁠JADEPUFFER⁠, one of the first documented cases of an LLM conducting an end-to-end ransomware operation. They break down how the agent, and the direc…THECYBERWIRE.COM
26 AugSensitive Information Exposed in Nutex Health Data BreachNutex Health has informed the SEC that it recently detected unauthorized access and data exfiltration. The post Sensitive Information Exposed in Nutex Health Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
26 Aug88 ID Verification Breaches Show the Cost of Collecting Identity Data88 ID-verification breaches exposed billions of records, highlighting the growing risks of collecting sensitive identity and biometric data. A new report from Mysterium VPN compiles 88 documented incidents since 2011 where data collected specifically to verify someone’s ide…SECURITYAFFAIRS.COM
26 AugChoose your fighter: Balancing competing requirements to select models for your AI SOCSelecting a model for your security operations center (SOC) and digital forensics and incident response (DFIR) tasks is important, but selecting the best one is more involved than you might think. Here's how to choose.TALOSINTELLIGENCE.COM
26 AugWhat If Ransomware Never Encrypts Anything?Ransomware is no longer just about encrypting files and demanding payment for decryption keys. Attackers may instead focus on disrupting a critical service because they know the victim has strong incentives to restore operations quickly. Service disruption can create consequences…YOUTUBE.COM
26 AugBoston Scientific says cyberattack disrupted order processing, shippingThe medical device-maker says it cannot yet determine any financial impact from the attack it suffered this week.CYBERSECURITYDIVE.COM
26 AugUS disrupts Chinese hacking campaign that breached NASA, the DOJ, the DOE, the Senate, and others.Meta settles children's safety lawsuits for $16.68 billion. Business news: AI security firm Alice raises $140 million.THECYBERWIRE.COM
26 AugBoston Scientific says cyberattack disrupted operations globallyMedical technology company Boston Scientific has been targeted in a cyberattack that disrupted some of its IT systems, causing operational disruptions globally. [...]BLEEPINGCOMPUTER.COM
26 AugUS seizes domains of Chinese botnet used to hack NASA, Justice Department, and the SenateThe FBI has seized domains associated with a botnet that allowed Chinese-backed hackers to breach several U.S. government departments.TECHCRUNCH.COM
26 AugFBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical InfrastructureFBI seizes QScan and QTRouter, China-linked platforms used to hide intrusions and target U.S. critical infrastructure. The U.S. Department of Justice and the FBI have seized two platforms, QScan and QTRouter, used by a China-linked group to hide cyberattacks and target critical i…SECURITYAFFAIRS.COM
26 AugMedical device maker Boston Scientific says a cyberattack is causing a ‘global disruption’ to its operationsThe company won't say if medical devices are affected or if any customer data was exfiltrated.TECHCRUNCH.COM
26 AugOpenAI: Agent behavior that led to Hugging Face intrusion formed in MayThe company says the breach stemmed from a systemic failure of alignment and security, and has taken measures to prevent agents from independently orchestrating complex cyberattacks. The post OpenAI: Agent behavior that led to Hugging Face intrusion formed in May appeared first o…CYBERSCOOP.COM
26 AugMedical device firm Boston Scientific says cyberattack has disrupted shipment processesThe company released a statement and filed documents with the Securities and Exchange Commission (SEC) saying a cybersecurity incident was discovered on Tuesday.THERECORD.MEDIA
26 AugWhat If Your Vendor Goes Down?Third-party risk depends on more than the likelihood that a vendor experiences an incident. Organizations also need to understand their exposure: the data involved, the number of records affected, and the potential business impact. A major technology provider can create consequen…YOUTUBE.COM
25 AugReliaQuest Rejects Compromise Claims After ShinyHunters IncidentReliaQuest has detailed a social engineering attack linked to ShinyHunters, denying reports that the threat actor successfully compromised its systemsINFOSECURITY-MAGAZINE.COM
25 AugShinyHunters taunts ReliaQuest after its own employee falls for social engineering attackCybersecurity company ReliaQuest has confirmed that one of its own employees fell for a social engineering attack, handing attackers a password and a brief window into the company’s identity system. The admission came after the extortion group ShinyHunters posted screenshot…HELPNETSECURITY.COM
25 AugThe cybercrime supply chain has five stages, each with a priceIn this Help Net Security video, Chris Nyhuis, CEO at Vigilant, explains why the picture of a lone ransomware attacker is about 15 years out of date. He walks through the cybercrime supply chain and the five businesses inside it: harvesters who run infostealer malware, brokers wh…HELPNETSECURITY.COM
25 AugThe safety penalty: Reclaiming operational sovereignty in the age of AIAs frontier AI models become increasingly restrictive, security teams are facing a "safety penalty" that hampers real-time incident response. Discover how organizations can move toward operational sovereignty to ensure their defensive AI keeps pace with unconstrained adversaries.TALOSINTELLIGENCE.COM
25 AugMirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login FlowsThousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication. According to ANY.RUN research, 48% of targ…THEHACKERNEWS.COM
25 AugHands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity ConferenceHands-on Cyber Attack Methods course returns to SecurityWeek’s ICS Cybersecurity Conference, October 6–8 at the W Nashville. The post Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference appeared first on SecurityWeek .SECURITYWEEK.COM
25 AugHospital operator Nutex Health says data stolen in cyberattackHealthcare and services provider Nutex is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers. [...]BLEEPINGCOMPUTER.COM
25 AugThat fake Grand Theft Auto VI demo is actually just malwareGrand Theft Auto fans, eager for news about one of the most anticipated video games of all time, appear especially vulnerable to this new cyberattack.TECHCRUNCH.COM
25 AugIs Cyber Facing an Affordability Crisis?As breach costs reach record highs and defense spending nears $240 billion, small businesses are dangerously exposed, threatening supply chain security.DARKREADING.COM
25 AugNorway ’s Digital Government Infrastructure Hit by a new DDoS AttackNorway ’s shared government infrastructure suffered a third DDoS attack, disrupting digital services but showing no signs of data compromise. Norway ‘s shared digital government infrastructure has been hit by another distributed denial-of-service (DDoS) attack that disrupte…SECURITYAFFAIRS.COM
25 AugU.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure BreachesThe U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole-of-government, economic campaign" against the nation and its enablers. "We are launching an economic onslaught against Iran's financial con…THEHACKERNEWS.COM
25 AugLACMA data breach last year exposed social security and medical dataThe Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information. [...]BLEEPINGCOMPUTER.COM
25 AugA Cautionary Tale About Data Breach Claims, Verification and CarharttPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite You're not going to believe this, but turns out you can't always take criminals at their word. Actually, I'll walk that …TROYHUNT.COM
25 AugCarhartt - 12,933,413 breached accountsIn August 2026, clothing retailer Carhartt was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data allegedly obtained from the company including 12.9M unique email addresses, names, phone numbers and physical addresses. The publis…HAVEIBEENPWNED.COM
24 AugWeekly Update 518: IoT Doorlock Nirvana with UniFiPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite I genuinely think I've nailed the IoT door lock situation! Well, Ubiquiti has, but I think I've worked out how to put it all …TROYHUNT.COM
24 AugReliaQuest says claimed ShinyHunters attack was successfully blockedReliaQuest says it contained a social engineering attack that briefly gave a threat actor access to a single employee identity session but did not allow access to company applications, systems, or customer data. The attacker was not identified in the company’s report, altho…CYBERINSIDER.COM
24 AugPersonal Information Exposed in Apollo Global Data BreachThe private equity firm appears to have been targeted as part of a campaign focusing on major financial companies. The post Personal Information Exposed in Apollo Global Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
24 AugASOS credential-stuffing attack exposed data of 138,828 customersASOS is notifying US customers that attackers gained unauthorized access to accounts using credentials obtained outside the company. This access potentially exposed personal, contact, and partial payment card information. According to an investigation published by Srourian Law Fi…CYBERINSIDER.COM
24 AugWordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows PasswordsCybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Ste…THEHACKERNEWS.COM
24 AugSouth Korean startup platform breach exposes key management failuresA breach at South Korea's government-backed startup platform exposed encrypted personal data after an encryption key was included in an API. Penta Security explains why encryption keys must be securely managed and kept separate from the data they protect. [...]BLEEPINGCOMPUTER.COM
24 Aug24th August – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 24th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Latvia’s Road Traffic Safety Directorate (CSDD) has confirmed a breach affecting payment records of more than 1.2 million people &#…RESEARCH.CHECKPOINT.COM
24 AugUK power facility disabled for days after suspected state-linked cyberattackThe disruption took place amid a wave of attacks targeting vulnerable industrial devices in the water and energy sectors.CYBERSECURITYDIVE.COM
24 AugReliaQuest confirms failed data-theft attack after ShinyHunters breachCybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. [...]BLEEPINGCOMPUTER.COM
24 AugTricky 'SynkLoader' Multitool May Herald RansomwareAn advanced, multilingual malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with a slew of novel features.DARKREADING.COM
24 AugSlovakia finds Russian backdoors on traffic speed cameras.Canada's Hospital for Sick Children discloses breach. TikTok will pay $400 million to settle children's privacy case.THECYBERWIRE.COM
24 AugUS sanctions Iranian cyber actors as UK discloses power plant attackThe U.S. sanctioned several Iranian nationals for cyberattacks on critical infrastructure just days after reports emerged of a cyber intrusion on a small power plant in the United Kingdom.THERECORD.MEDIA
23 AugWelcoming the Sri Lankan Government to Have I Been PwnedPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite Today, we welcome the 48th government onboarded to Have I Been Pwned’s free gov service: Sri Lanka. Sri Lanka CERT now has acces…TROYHUNT.COM
23 AugWeek in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgsHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: Windows 11’s strongest security defenses can be bypassed without a screwdriver Researchers from the University of Birmingham and Durham University have found a way to knock down some…HELPNETSECURITY.COM
23 AugUK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water AttacksIran-linked hackers shut down a UK power plant for four days in the first confirmed attack of its kind, concurrent with water infrastructure attacks across 12 US states. Iran-linked hackers shut down a British power plant for four days in what The Telegraph describes as the most …SECURITYAFFAIRS.COM
23 AugSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 111Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Akira Hits Safe Mode: Ransomware Rebooting Around EDR  Multi-Functional Linux Botnet “Evooo1Bot”      …SECURITYAFFAIRS.COM
23 AugNIUS - 6,090 breached accountsIn July 2025, the German news service NIUS suffered a data breach which was subsequently leaked publicly . The data included 6k unique email addresses along with names, physical addresses and payment details for purchases including either IBANs or partial credit card data (masked…HAVEIBEENPWNED.COM
22 AugHackers infect Android car head units with proxy botnet malwareA supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [...]BLEEPINGCOMPUTER.COM
21 AugRust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million DownloadsThe Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation. The affec…THEHACKERNEWS.COM
21 AugSickKids data breach exposes employee and job applicant infoToronto's Hospital for Sick Children (SickKids) says a cybersecurity incident exposed the personal information of some current and former employees and job applicants, stemming from a flaw in third-party software. Clinical systems and patient records were not affected. (264) [...…BLEEPINGCOMPUTER.COM
21 AugMedical records, SSNs, and bank details exposed in CareCloud data breachHealthcare technology provider CareCloud confirmed that 3.75 million people were affected by a March data breach.MALWAREBYTES.COM
21 AugNorth Korean Hackers Tied to Rust Supply Chain AttackCybersecurity researchers have linked a malicious backdoor in compromised Rust packages to previous North Korean supply chain attacksINFOSECURITY-MAGAZINE.COM
21 AugPrivate equity firm Apollo confirms data breach amid hacking wave targeting financial giantsThe private equity giant confirms a breach, weeks after Google researchers said hackers were targeting financial companies.TECHCRUNCH.COM
21 AugRussian network monitoring firm confirms cyberattack claimed by pro-Ukraine hackersThe statement came a day after a hacking group calling itself Black Spark claimed it had spent more than a month inside Microolap’s network and gained access to its internal systems, including EtherSensor, the company's network traffic analysis platform.THERECORD.MEDIA
21 AugOpenAI Adds Controls That Should've Been There AlreadyThe new AI security controls follow the Hugging Face incident last month, though many of these additions perhaps should have been in place prior to the frontier models escaping.DARKREADING.COM
21 AugCanada’s Hospital for Sick Children attacked by cybercriminals again as employee data stolenThe Hospital for Sick Children — which was hit in a ransomware incident in 2022 that disabled some of its systems — released a statement on Thursday warning of a data theft incident they believe is tied to a third-party software application.THERECORD.MEDIA
21 AugIs Online Privacy Possible? How Digital Identities Can HelpUsing the same email, phone number, payment method, and other identifiers makes it easier for data brokers and attackers to profile your activity. Anonyome Labs explains how separate digital personas can reduce correlation and limit the impact of breaches, spam, and identity thef…BLEEPINGCOMPUTER.COM
21 AugU.S. Bank says breach claims related to fourth-party incidentThe bank said there is no evidence that its own systems, networks or data repositories were compromised.THERECORD.MEDIA
21 AugApollo discloses data breach from ongoing wave of attacks hitting financial sectorThe private equity firm said attackers broke into some of its cloud platforms during a five-day period in early July, compromising sensitive personal data. The post Apollo discloses data breach from ongoing wave of attacks hitting financial sector appeared first on CyberScoop .CYBERSCOOP.COM
20 AugStopAndProtect Turns 2,000 Hacked WordPress Sites Into a Criminal NetworkStopAndProtect turned nearly 2,000 hacked WordPress sites into a criminal network for malware delivery, data theft, surveillance and ransomware. Check Point Research uncovered a cybercrime operation, dubbed StopAndProtect, that has turned thousands of hacked WordPress websites in…SECURITYAFFAIRS.COM
20 AugNew Manic Android malware can exfiltrate data through nearby devicesA new Android malware named Manic targeting users in multiple European countries has a fallback data exfiltration mechanism that uses nearby infected devices. [...]BLEEPINGCOMPUTER.COM
20 AugOpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training PausesThe action taken by OpenAI comes in light of the Hugging Face incident and the discovery of the Astra model’s advanced capabilities. The post OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugFake Gemini installer delivers Vidar infostealer via Google Colab lureA malicious executable masquerading as a Google Gemini installer was used to deliver the Vidar infostealer on a company network in the EMEA region, according to Darktrace researchers who investigated the incident. “During the initial analysis, it was noted that the top search res…HELPNETSECURITY.COM
20 AugAI data giant Alation confirms cyberattackThe data search and AI giant confirmed unauthorized access to its systems during an incident on Tuesday, and said it was investigating the breach.TECHCRUNCH.COM
20 AugWhy "Shady AI" is Security's Next Big Governance ProblemIn March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company and user data was exposed to employees who weren’t authorized to access it.  The incident began when a Meta employee posted a technical question on an internal forum. An engineer…THEHACKERNEWS.COM
20 AugManic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected DevicesA new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused commun…THEHACKERNEWS.COM
20 AugOne Programmer Can Break EverythingA critical system becomes vulnerable when only one person knows how to restore or debug it. Matt Lea calls these people “lone wolf programmers” and connects the problem to the idea of a bus factor. The risk isn't just that someone leaves. People get sick, take vacation, burn out,…YOUTUBE.COM
20 AugPakistan's Transparent Tribe Refreshes Toolset for Afghan CyberattacksA nation-state threat actor is picking on immature organizations run by the Taliban, but failing against more prepared government agencies in India.DARKREADING.COM
20 AugFitch explains how water, healthcare organizations can keep strong credit ratings, despite cyberattacksResilience, not prevention, is key, analysts at the credit-rating agency said in a pair of new reports.CYBERSECURITYDIVE.COM
20 AugDetailed Timeline of OpenAI’s Cyberattack on Hugging FaceOpenAI presented details of its AI’s model’s cyberattack on Hugging Face at Black Hat last week. Simon Willison details the timeline. It’s really interesting to read through—and really impressive cyberoffense work.SCHNEIER.COM
20 AugHackers poison arrayref Rust crate to push infostealer malwareHackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers' systems during compilation. [...]BLEEPINGCOMPUTER.COM
20 AugManic: The Android Malware That Exfiltrates Data Even When the Phone Is OfflineManic Android malware combines banking fraud and spyware, using a Bluetooth relay to steal data even when devices are offline. ThreatFabric’s Mobile Threat Intelligence team has identified a new Android malware, dubbed Manic, which has been active in the wild since at least…SECURITYAFFAIRS.COM
20 AugChina Is Strapping ‘Digital Bombs’ to Civilian Infrastructure—Is the US Ready?This week on “Uncanny Valley,” Andy Greenberg discusses sitting in on a war game simulating a cyberattack from the Chinese hacking group Volt TyphoonWIRED.COM
19 AugOz Hair and Beauty - 1,988,331 breached accountsIn August 2026, Australian beauty retailer Oz Hair and Beauty was the target of an xpl0itrs extortion attack . The group subsequently published data allegedly obtained from the company, which included 2M unique email addresses along with names, phone numbers, geographic locations…HAVEIBEENPWNED.COM
19 AugFanlore - 144,520 breached accountsIn August 2026, the Organization for Transformative Works (OTW) identified unauthorised access to the Fanlore wiki it operates . The breach resulted in the exposure of 145k unique email addresses along with usernames and passwords stored as either MD5 or PBKDF2 hashes. OTW self-s…HAVEIBEENPWNED.COM
19 AugCareCloud Data Breach Impact Grows to 3.7 Million IndividualsThe data breach was initially believed to affect roughly 350,000 people, but the HHS breach tracker shows a far bigger impact. The post CareCloud Data Breach Impact Grows to 3.7 Million Individuals appeared first on SecurityWeek .SECURITYWEEK.COM
19 AugOver 500 Critical Infrastructure Organizations Hit by Medusa RansomwareThe FBI warned that the RaaS operation has significantly enhanced its tactics, techniques and procedures, making it harder for defenders to counterINFOSECURITY-MAGAZINE.COM
19 AugStopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal DataCybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the a…THEHACKERNEWS.COM
19 AugOpenAI Tightens AI Safeguards Following Hugging Face IncidentOpenAI is strengthening safeguards for its most advanced AI models, citing growing risks as frontier systems gain more powerful cyber capabilitiesINFOSECURITY-MAGAZINE.COM
19 AugCl0p Ransomware Group Names Over 40 Victims of PTC Windchill CampaignThe cybercrime gang has listed major companies such as Shell, Philips, Fiserv, Zebra, Mindray, and Largan Precision. The post Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign appeared first on SecurityWeek .SECURITYWEEK.COM
19 AugUS charges Iranians for sprawling hacking campaign on government agencies, universitiesThe Justice Department accused 17 alleged hackers with ties to the Iranian government of breaching email accounts at U.S. government agencies and stealing intellectual property from dozens of universities.THERECORD.MEDIA
19 AugCareCloud confirms 3.7M patients had their medical records stolen in data breachThe cyberattack at CareCloud resulted in one of the largest reported data breaches in the U.S. healthcare industry this year.TECHCRUNCH.COM
19 AugLatvian officials resign after cyberattack exposes data on 1.2 million peopleLatvia’s road traffic agency confirmed that hackers stole data connected to about two-thirds of the country’s population in a major cyberattack that has prompted calls for senior officials to resign.THERECORD.MEDIA
19 AugBackup Software Can Exfiltrate DataBackup software is designed to move and store large amounts of organizational data. If the destination or purpose changes, that same capability can potentially be used for data exfiltration. Because backup activity is expected and can generate substantial data movement, malicious…YOUTUBE.COM
19 AugMedusa ransomware affiliates have breached hundreds of critical infrastructure entities.US accuses 17 Iranians of hacking for Iran's IRGC. Business news: Fortinet acquires AI security firm Virtue AI.THECYBERWIRE.COM
19 AugRansomware disproportionately targets medium-sized firms, straining customer relationshipsThese companies often have the hardest time balancing their roles as suppliers and customers, according to the risk management firm Black Kite.CYBERSECURITYDIVE.COM
19 Aug2,000 WordPress sites hijacked by StopAndProtect malware operationA large-scale malware operation dubbed StopAndProtect uses thousands of compromised WordPress websites to distribute malware, issue commands, and store data stolen from infected computers. The campaign combines ransomware, credential theft, surveillance, lateral movement, and han…CYBERINSIDER.COM
19 AugT-Mobile ‘chopped a cable’ to expel Chinese hackers from its networkThe U.S. phone provider escaped a large-scale breach of its network after identifying Chinese-backed hackers early on.TECHCRUNCH.COM
19 AugInside Operation CameraSwarm: How One Actor Took Over 14,000 Dahua CamerasAn exposed operator directory reveals how one actor compromised 14,000+ Dahua cameras across Ukraine and Russia, no password needed for most. A researcher discovered an exposed directory containing the tools of an attacker who compromised more than 14,000 Dahua cameras between Ju…SECURITYAFFAIRS.COM
19 AugElectronic health record company CareCloud says 3.7 million people affected by breachHealthcare software firm CareCloud filed documents with the Department of Health and Human Services confirming that 3,756,469 people had information leaked after a hacker spent eight hours in one of the company’s electronic health record environments.THERECORD.MEDIA
19 AugHackers compromise 14,500 Dahua web cameras in 35-day campaignIn a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more than 14,500 Dahua IP cameras mostly in Ukraine and Russia. [...]BLEEPINGCOMPUTER.COM
19 AugRogue ransomware affiliate poses as data recovery firm to steal paymentsA suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]BLEEPINGCOMPUTER.COM
19 AugCybersecurity Needs Its Stop Drop RollCybersecurity is complex, but emergency response doesn't always have to be. The discussion compares cybersecurity's response problem with familiar basics like CPR and “stop, drop and roll.” A simple, memorable response playbook could help people act faster during an incident inst…YOUTUBE.COM
19 AugRogue ransomware affiliate poses as recovery firm to steal paymentsA suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]BLEEPINGCOMPUTER.COM
18 AugWeekly Update 517: Cyber RansomsPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite The current ransomware situation is a bit of a kludge (deep breath): a lot of ransomware (which often doesn't even involve "w…TROYHUNT.COM
18 AugHeights Finance Data Breach Impacts at Least 1.2 Million IndividualsHackers stole names, addresses, phone numbers, Social Security numbers, and financial information from a third-party platform. The post Heights Finance Data Breach Impacts at Least 1.2 Million Individuals appeared first on SecurityWeek .SECURITYWEEK.COM
18 AugOpenAI tightens defenses after AI agents breach research environmentFollowing the OpenAI-Hugging Face incident, in which an agentic collective autonomously penetrated OpenAI’s research infrastructure and another company’s production infrastructure by chaining together multiple weaknesses, OpenAI began strengthening its safety requirements. The we…HELPNETSECURITY.COM
18 AugHeights Finance data breach: What customers need to knowLeaked personal and financial data of around 750,000 US citizens, including SSNs and bank details, could put victims at risk of identity theft and phishing.MALWAREBYTES.COM
18 AugThree-quarters of Ransomware Attacks Target Mid-Market FirmsBlack Kite finds mid-market is the sweet spot for ransomware as manufacturers are most likely to be hitINFOSECURITY-MAGAZINE.COM
18 AugCyber Incident Disrupts Student Services at UT San AntonioUT San Antonio has taken IT systems offline following a cyber incident, disrupting student registration and tuition payments days before term is due to resumeINFOSECURITY-MAGAZINE.COM
18 AugDownload: 2026 Credential Risk Report85% of cybersecurity professionals consider compromised credentials a primary attack path, yet only 19% continuously monitor active credentials and automatically remediate exposure. The 2026 Credential Risk Report examines where credential security programs fall short and what it…HELPNETSECURITY.COM
18 AugGitHub suffers eight-hour outage affecting Actions, APIs, and CopilotGitHub suffered a widespread outage on August 17 that disrupted core services including its API, Actions, Pull Requests, Issues, Pages, Webhooks, and Copilot, with some repository downloads experiencing error rates of around 50%. The incident began at 1:40 p.m. UTC when GitHub sa…CYBERINSIDER.COM
18 Aug'Ransom Busters': Ransomware Actor Poses as Incident-Recovery ServiceA ransomware affiliate appears to be sidling up to victims with offers of aid, masking its true intention of diverting ransom payments.DARKREADING.COM
18 AugThousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtectResearch by: Jaromír Hořejší (@JaromirHorejsi) Key points Introduction We first noticed a ransomware family called StopAndProtect in the middle of May 2026. Further analysis of the infrastructure reveals that the infection chain starts with a ClickFix social-engineering technique…RESEARCH.CHECKPOINT.COM
18 AugClop created custom web shell for Windchill data theft attacksA custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. [...]BLEEPINGCOMPUTER.COM
18 AugRansom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000. "In these messages, the third-party off…THEHACKERNEWS.COM
18 AugOpenAI institutes new safeguards after Hugging Face breachThe new safeguards include more detailed monitoring of models during the development process, as well as greater emphasis on alignment and security during the post-training process.TECHCRUNCH.COM
18 AugHackers Expose Data of 1.2 Million Heights Finance CustomersA Heights Finance breach exposed personal and financial data of over 1.2 million people after hackers compromised a third-party cloud platform. Heights Finance is a U.S. consumer finance company that provides personal loans and related lending services, mainly to customers who ma…SECURITYAFFAIRS.COM
17 AugFortune 500 Companies Hit in Azure Data Theft CampaignA threat actor is claiming the exfiltration of millions of records from McDonald’s, TCS, Vodafone, and other large organizations. The post Fortune 500 Companies Hit in Azure Data Theft Campaign appeared first on SecurityWeek .SECURITYWEEK.COM
17 AugAfrica’s Cybersecurity Challenge Is Bigger Than Access to TechnologyGopan Sivasankaran is Rapid7's Regional Director, Middle East & Africa. Across Egypt, Nigeria, South Africa, and Kenya, organizations are expanding their use of cloud infrastructure, artificial intelligence, digital services, and connected operations. But more technology does not…RAPID7.COM
17 AugAkira Ransomware Uses Safe Mode to Bypass EDRAkira attackers used Safe Mode to disable EDR before deploying ransomware, but memory issues caused the encryptor to fail. An Akira ransomware affiliate broke into a company through an MFA-less SonicWall VPN on August 4, stole credentials and file shares, and then rebooted the co…SECURITYAFFAIRS.COM
17 AugSafePal Data Breach Hits Tens of Thousands of CustomersNearly 40,000 customers of hardware wallet provider SafePal have been impacted by a data breachINFOSECURITY-MAGAZINE.COM
17 AugNew macOS malware turns stolen browsers into attacker-controlled sessionsMac users are being freshly warned of suspicious websites asking them to open Terminal and install software. Jamf Threat Labs has uncovered a multi-stage macOS infostealer, dubbed AmnesiaStealer, that uses a ClickFix-style fake GitHub download page to trick victims into executing…CSOONLINE.COM
17 AugPhilips and GE investigating Clop ransomware data theft claimsTech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]BLEEPINGCOMPUTER.COM
17 Aug680,000 Impacted by French Tax Authority Data BreachHackers used compromised credentials to access enterprise and personal tax-related data. The post 680,000 Impacted by French Tax Authority Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
17 AugSogang University data breach exposes information of 180,000 peopleSogang University in Seoul has suffered a cyberattack that exposed personal information belonging to roughly 180,000 students, alumni, faculty members, and staff. The university said an unidentified external party gained unauthorized access to its integrated login system, resulti…CYBERINSIDER.COM
17 AugGeneral Electric, Philips, and Shell investigate alleged breaches.ShinyHunters leaks alleged RingCentral data. Police arrest seven suspects in connection with 2023 bank hack.THECYBERWIRE.COM
17 AugMajor genetic-testing firm says hack compromised sensitive patient dataThe June breach, which also exposed employees’ information, underscored the supply-chain risks facing the healthcare sector.CYBERSECURITYDIVE.COM
17 AugSafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impactedThe crypto hardware wallet company SafePal confirmed a data breach on Sunday, telling users that nearly 40,000 customers had information stolen during a recent security incident.THERECORD.MEDIA
17 AugIrregular faces criticism over ‘spin’ in AI hacking postmortemThe company at the center of a series of incidents in which AI models compromised real-world computer systems during security evaluations is facing criticism after the release of a report that security experts say leaves key questions unanswered.THERECORD.MEDIA
17 AugPoland probes MyDr healthcare software breach potentially affecting 19 million peopleMyDr, a privately-owned Polish company that supplies software to doctors, clinics and other healthcare providers, said on Friday that it had identified and removed the cause of the incident and introduced additional security measures.THERECORD.MEDIA
17 AugWill Cyber Insurance Stop Covering Fraud?Financial fraud is described as a leading category of cyber insurance claims, with Adrian Sanabria noting that it can exceed ransomware in claims paid by insurers. At the same time, insurers are changing what they consider covered cyber risk. Social engineering, “click fix,” and …YOUTUBE.COM
17 AugHacker claims 3.6 million Azure account records stolen from major companiesA threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials. [...]BLEEPINGCOMPUTER.COM
17 AugPokémon Center data breach exposes customer info, cancels some ordersPokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics. [...]BLEEPINGCOMPUTER.COM
17 AugNearly 750k had financial info, SSNs leaked in South Carolina loan company breachThe breach affected anyone who received a loan through the company or inquired about a loan product through a third party.THERECORD.MEDIA
17 AugDetails emerge on BlackFile’s recent attacks on financial companiesBlackFile’s four affiliate groups are still targeting victims, including medical technology organizations. Several potential victims received new extortion demands last week, according to Google. The post Details emerge on BlackFile’s recent attacks on financial companies a…CYBERSCOOP.COM
17 AugIrregular says ‘human oversight’ responsible for AI sandbox escape incidentsIn a post-mortem, the frontier AI testing company said internet access for models is necessary to fully test out their cybersecurity capabilities. The post Irregular says ‘human oversight’ responsible for AI sandbox escape incidents appeared first on CyberScoop .CYBERSCOOP.COM
16 AugAI, misinformation, and the future of cybersecurity.As AI products proliferate, they continue to introduce new concerns, which have subtly eroded trust in imagery and content created by space-based infrastructure. In this week's episode, host Maria Varmazis sits down with ⁠⁠⁠Dave Bittner and Brandon Karpf to look at Google's troub…THECYBERWIRE.COM
15 AugHow to tell if your AI platforms’ accounts have been hackedA guide on how to check if hackers have broken into your accounts on the most popular AI platforms.TECHCRUNCH.COM
14 Aug14,000 Trezor Customers Impacted by Data Breach at ShipMonkHackers stole the customers’ shipping information, including names, addresses, email addresses, and phone numbers. The post 14,000 Trezor Customers Impacted by Data Breach at ShipMonk appeared first on SecurityWeek .SECURITYWEEK.COM
14 AugChess.com Leak Exposes 7.3 Million Users – Evidence Points to Scraping7.3 million Chess.com profiles leaked online: the data is genuine, but evidence points to large-scale scraping, not a server breach. Free is a strange price for stolen data, and that’s exactly what makes this listing worth a second look. A 15.5 GB file containing over 7.3 m…SECURITYAFFAIRS.COM
14 AugOver 1,000 Charities Hit by Beacon CRM Data BreachThe root cause of the incident is believed to be a compromised AWS access key that was exposed in publicly available JavaScript build artifacts. The post Over 1,000 Charities Hit by Beacon CRM Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
14 AugRingCentral data breach exposed info of 1.6 million accountsThe ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned. [...]BLEEPINGCOMPUTER.COM
14 Aug1.6 Million Likely Impacted by RingCentral Data BreachThe hackers published the allegedly stolen information, including names, addresses, email addresses, and phone numbers. The post 1.6 Million Likely Impacted by RingCentral Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
14 AugShell investigates 'potential incident' after Clop data theft claimsOil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. [...]BLEEPINGCOMPUTER.COM
14 AugIn Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System VulnerabilitiesNoteworthy stories that might have slipped under the radar: government AI platform deal sparks outrage, North Korean IT worker breaches federal agency, DEF CON attendee blamed for Delta flight disruption. The post In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration…SECURITYWEEK.COM
14 AugFrance investigates tax authority breach after hacker claims 600,000 victimsFrench authorities confirmed that someone gained unauthorized access to systems at the Directorate General of Public Finances in late June after stealing or misusing someone’s identity.THERECORD.MEDIA
14 AugResearchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 OrganizationsResearchers have verified that ExfilSquad possesses sensitive data stolen from at least 13 victims after the extortion group published leaked datasets via torrentsINFOSECURITY-MAGAZINE.COM
14 AugResearchers confirm breach claims by data-extortion groupThe exfiltrated data may be related to misconfiguration of Microsoft Power Page portals, according to a new report.CYBERSECURITYDIVE.COM
14 AugCisco security revenue jumps 14% as agentic AI sharpens cyberattacksWith companies confronting more sophisticated threats, AI agents are driving demand for cybersecurity tools, CEO Chuck Robbins said.CYBERSECURITYDIVE.COM
14 AugScottish Govt Suffers Potentially Widening Data Breach at Prosecutor's OfficeOne Caledonian government agency reported a breach, thanks to a third party that may have serviced other agencies as well.DARKREADING.COM
14 AugRansomware Can Bypass Endpoint DefensesAn Akira ransomware attack reportedly used Safe Mode to help bypass endpoint defenses. The initial access came through an exposed SonicWall SSL VPN that did not have MFA enabled, followed by Active Directory enumeration and data staging. The attack demonstrates how basic weakness…YOUTUBE.COM
13 AugWhat do AI-driven ‘bank heist’ attacks mean for defenders?Attackers aren't just using AI to steal data; they're using it to fight back while you investigate them in real time. And once an adversary is inside, why would they ever want to leave? That's the unsettling reality Tom Kellermann, VP of AI Security and Threat Research at TrendAI…THECYBERWIRE.COM
13 AugICO Reprimands Criminal Records Office After 2023 BreachThe ICO has issued a formal reprimand to ACRO after patching and security monitoring failures led to a breachINFOSECURITY-MAGAZINE.COM
13 AugStorm-1175 Replaces Medusa With New StormEncryptor RansomwareMicrosoft says China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa in its latest attacks. Microsoft says China-linked, financially motivated threat actor Storm-1175 has begun using a new ransomware strain called StormEncryptor. The group prev…SECURITYAFFAIRS.COM
13 AugAkira Affiliate Crashes Ransomware After Attempting EDR EvasionHuntress documents how a ransomware affiliate sabotaged its own attack with an anti-EDR effortINFOSECURITY-MAGAZINE.COM
13 AugThe State of Ransomware Q2 2026For the past year, the ransomware conversation has centered on concentration: a handful of dominant RaaS operations controlling most of the damage, and a shrinking pool of active groups fighting over the same territory. The State of Ransomware Q2 2026 report from Check Point Rese…RESEARCH.CHECKPOINT.COM
13 AugRingCentral - 1,596,490 breached accountsIn July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data they claimed was obtained from the platform, which included 1.6M unique email addresses along with …HAVEIBEENPWNED.COM
13 AugIn a first, US will allow some private firms to carry out cyberattacksThe new order sweeps away decades of existing U.S. cybersecurity policy prohibiting private companies from conducting 'hack back' attacks or offensive cyber operations.TECHCRUNCH.COM
13 AugExposed AWS Access Key Linked to Data Breach Affecting 1500+ UK CharitiesCRM provider Beacon has revealed that a compromised AWS access key was the likely root cause of the breach of 1500 UK charities’ dataINFOSECURITY-MAGAZINE.COM
13 AugHackers breach govt webmail while running parallel crypto fraudThe Jewelbug hacker group has been carrying out espionage operations targeting governments and militaries while also engaging in cryptocurrency fraud. [...]BLEEPINGCOMPUTER.COM
13 AugAkira hackers disable EDR with Safe Mode, steal data but fail to encryptAn Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. [...]BLEEPINGCOMPUTER.COM
13 AugNation-State Hackers Target Hotel Wi-FiCaptive portals are the login pages you encounter when connecting to many hotel and public Wi-Fi networks. Larry Pesce describes a campaign in which a nation-state-level threat actor compromised these devices and controlled DNS. That control can allow attackers to redirect users …YOUTUBE.COM
12 AugWeekly Update 516: Live From VietnamPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite A little wind noise, a little connectivity flakiness, and a little lip-sync issues from YouTube, but look at that view! 🤩 Back …TROYHUNT.COM
12 Aug‘The Worst I’ve Ever Seen’: Cargo Thefts Have Turned Violent in Pursuit of AI HardwareExperts allege that two recent incidents in California show the extreme lengths that criminal organizations are willing to go to to steal servers and other gear meant for data centers.WIRED.COM
12 AugOver 2,500 Organizations Impacted by LiteLLM Supply Chain AttackLiteLLM was compromised through the Trivy hack and abused to distribute information-stealing malware to its users. The post Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugCeva Logistics Operations Disrupted by CyberattackAffecting European contract logistics operations at eight Ceva warehouses, the incident caused shipment delays for multiple customers. The post Ceva Logistics Operations Disrupted by Cyberattack appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugUber Freight reportedly investigating after hacking group claims data breachAn extortion gang known for targeting transportation companies and private equity firms has taken credit for a breach at Uber Freight.TECHCRUNCH.COM
12 AugYour AI Can Be Hacked Through TextThis clip describes an AI hijacking technique in which an external attacker places instructions into text that an AI agent is already processing, such as logs, alerts, or email. The danger is that the agent may interpret untrusted content as an instruction. That creates a new sec…YOUTUBE.COM
12 AugFBI: Hackers using social engineering to breach accounts and steal explicit contentLeaked passwords, social engineering and spoofed social media sites are among the tools hackers are using to gather individuals' private content and sell it online, the FBI said.THERECORD.MEDIA
12 AugLiteLLM breach data shows supply chain attack impacted 2,488 firmsA new analysis of data allegedly stolen during the March 2026 LiteLLM supply chain attack has linked nearly 2,500 corporate domains to exposed CI/CD environments, including those of major technology, industrial, financial, and telecommunications firms. Cybersecurity firm Hudson R…CYBERINSIDER.COM
12 AugChina-Linked Hackers Use AI Agents in Autonomous Attack on TaiwanChina-linked hackers reportedly used eight AI agents to breach a government network, steal data and compromise accounts with minimal human oversight. Israeli cybersecurity firm Dream documented what looks like the first fully autonomous, end-to-end AI hacking operation against a …SECURITYAFFAIRS.COM
12 AugCEVA Logistics Cyberattack Disrupts European Warehouses and ShipmentsCEVA Logistics suffered a cyberattack disrupting European operations, with eight warehouses affected and shipments halted at impacted sites. CEVA Logistics suffered a cyberattack on July 29 that disrupted parts of its European operations. The incident impacted impacted eight ware…SECURITYAFFAIRS.COM
11 AugHackers Breach Polish Power Plant Controls via Private Cellular Network and Shut TurbineAttackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment. The plant supplies heat to roughly 50,000 residents. Recover…THEHACKERNEWS.COM
11 AugOnly Half of UK Manufacturers Have a Cyber Incident Response PlanMake UK reveals major cyber resilience gaps as 30% of UK manufacturers report recent cyber incidentsINFOSECURITY-MAGAZINE.COM
11 AugUS and South Korea warn of Gunra ransomware targeting govt agenciesU.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. [...]BLEEPINGCOMPUTER.COM
11 AugLogistics Giant Ceva Suffers Data Breach Impacting European ClientsSupply chain attack and data breach at Ceva Logistics appears to have a large blast radiusINFOSECURITY-MAGAZINE.COM
11 AugSuisan City, California, Responds to Cyber Incident Amid Wave of US Local Government AttacksPolice and fire response has been impacted by the attack on Suisan City, while two other local authorities have been hit by cyber incidents in the past week alsoINFOSECURITY-MAGAZINE.COM
11 AugFBI warns Gunra ransomware targets critical sectors and governmentsUS authorities are warning organizations about Gunra, an emerging ransomware operation that has attacked victims worldwide, stolen as much as tens of terabytes of data in individual incidents, and opened ransom negotiations at amounts exceeding tens of millions of dollars. The gr…CYBERINSIDER.COM
11 AugMalicious SIMs can hijack smartphones, steal files, and lock them onto 2GResearchers have found that compromised or malicious SIM cards can issue commands to some smartphones and cellular-connected devices, allowing attackers to steal information, disrupt communications, downgrade connections to 2G, and in some cases execute code. Tomasz Piotr Lisowsk…HELPNETSECURITY.COM
11 AugLocal governments in four states dealing with cyberattacks that have shut down servicesMunicipalities in California, Oklahoma, Wisconsin and Texas are all recovering from disruptive cyberattacks that have affected government operations.THERECORD.MEDIA
11 AugThreat Hunting Case Study: The GentlemenAnalyzing The Gentlemen ransomware group's attack chain and how to hunt for their privileged group manipulation technique before they spread through the NETLOGON share folder on Windows domain controllers.INTEL471.COM
11 AugDelta investigating after someone set up fake Wi-Fi network mid-flightThe Delta flight crew switched off the aircraft's legitimate Wi-Fi network for around 30 minutes due to the incident, according to a spokesperson.TECHCRUNCH.COM
11 AugPoland’s CERT describes winter cyberattack against heat-and-power plant.US and South Korea warn of "Gunra" ransomware gang with North Korean ties. Chinese IP connections spark security review in UK Navy drones.THECYBERWIRE.COM
11 AugCyberattack on logistics giant Ceva hits retailers and Steam customers across EuropeOperations at eight European warehouses belonging to France's CEVA Logistics have reportedly been disrupted by a cyberattack, and several other companies are feeling the effects.THERECORD.MEDIA
11 AugWesco confirms security incident after ExfilSquad claims data theftGlobal supply chain and distribution giant Wesco has confirmed in a statement for BleepingComputer that it is investigating a cybersecurity incident. [...]BLEEPINGCOMPUTER.COM
11 AugIran-Linked Hackers Target More US Water Infrastructure in New Jersey and AlabamaIran-linked hackers targeted Water Infrastructure in New Jersey and Alabama, bringing confirmed attacks to at least 12 states, with limited disruption. The wave of cyberattacks targeting US water infrastructure has reached New Jersey and Alabama, bringing the confirmed count to a…SECURITYAFFAIRS.COM
11 AugRansomware group hijacks hospital system’s Facebook page amid ongoing cyberattack falloutThe hackers claimed to have exfiltrated 6 terabytes of data, including highly sensitive health information like records related to sexual assault, mental health, abortions and sexual harassment incidents.THERECORD.MEDIA
11 AugA private route to public risk.Poland’s CERT describes winter cyberattack against heat-and-power plant. Russian military hackers target Ukrainian IT workers in fake recruitment scheme. Chinese IP connections spark security review in UK Navy drones. US and South Korea warn of “Gunra” ransomware gang with North …THECYBERWIRE.COM
11 AugDeadLock ransomware uses blockchain to resist infrastructure takedownThe DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims and data-leak activity. [...]BLEEPINGCOMPUTER.COM
10 AugNewcastle University confirms data breach after ExfilSquad claims 440k recordsNewcastle University has confirmed that a configuration issue affecting a connection to one of its admissions systems allowed unauthorized access to personal information, including names, addresses, email addresses, and telephone numbers. The disclosure follows a claim by the Exf…CYBERINSIDER.COM
10 AugCorporate Data Stolen in Levi Strauss CyberattackUsing social engineering, a threat actor accessed the computers of three employees and exfiltrated data from them. The post Corporate Data Stolen in Levi Strauss Cyberattack appeared first on SecurityWeek .SECURITYWEEK.COM
10 AugThree interviews: system fragility, operational clarity, and Identity for AI agents - ESW #471Interview 1: Robin Macfarlane from RRMac Associats The Mattress Money Principle: What a 50-Year Veteran Knows About System Fragility In this interview, Robin and Adrian discuss how technology has evolved over the past 50 years. Despite massive technological changes over the decad…YOUTUBE.COM
10 AugValve notifies Steam hardware customers of a data breachVideo game publisher and digital distribution giant Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, CEVA Logistics. [...]BLEEPINGCOMPUTER.COM
10 AugNew Jersey, Alabama Join States Targeted in Water CyberattacksHackers linked to Iran targeted industrial control systems (ICS) at water facilities in at least a dozen US states. The post New Jersey, Alabama Join States Targeted in Water Cyberattacks appeared first on SecurityWeek .SECURITYWEEK.COM
10 AugValve warns Steam users in Europe of data breach at shipping partnerValve is warning Steam customers in Europe that their personal and delivery information may have been compromised in a cyberattack targeting CEVA Logistics, the company responsible for shipping Steam hardware to European buyers. According to a security notification sent by Valve,…CYBERINSIDER.COM
10 Aug9.2 Million Israeli Records Sold as a New Breach Are 20 Years OldA seller claims to offer Israel’s 2026 population registry, but checks show the 9.2 million records are authentic data dating back to 2005. A vendor on a well-known leak forum claims to have breached Israel’s Population and Immigration Authority and is selling the entire na…SECURITYAFFAIRS.COM
10 AugA data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyondCompanies that rely on Ceva Logistics for shipping their physical goods to customers say their personal data was taken during a recent cyberattack.TECHCRUNCH.COM
10 AugWordPress Plugins Compromised Without a Single File ChangePoisoned JSON feed let attackers backdoor WordPress sites without changing any plugin filesINFOSECURITY-MAGAZINE.COM
10 AugOpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack ConcernsThe current GPT-5.6-Sol has been assigned a ‘high’ cybersecurity threshold, but Astra could reach the maximum ‘critical’ threshold. The post OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns appeared first on SecurityWeek .SECURITYWEEK.COM
10 AugCyberattack on Steam hardware shipper leaks names, addresses, and order dataVideo game publisher Valve is alerting customers in Europe to a data breach at CEVA Logistics, its Steam hardware shipping partner. Reports from affected customers began surfacing on social media earlier today, after Valve started sending out data breach notification emails. R…HELPNETSECURITY.COM
10 AugDeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructureMicrosoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion tactics used to pre…MICROSOFT.COM
10 AugHackers Cross From IT to OT Through a Private APN in PolandAttackers breached a Polish CHP plant through a Fortinet device and private APN, reaching PLCs and disrupting turbine and water treatment systems. Poland’s CERT has described a second attack on the country’s energy sector, and this one matters for a simple reason: it shows how an…SECURITYAFFAIRS.COM
10 AugNew StormEncryptor ransomware used by former Medusa affiliateA financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. [...]BLEEPINGCOMPUTER.COM
10 AugFBI, South Korea warn of Gunra ransomware gang targeting critical infrastructureThe Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned.THERECORD.MEDIA
10 AugU.S., South Korean government agencies caution to be on lookout for Gunra ransomware gangThe ransomware-as-a-service outfit has gone after a range of critical infrastructure sectors across the globe. The post U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang appeared first on CyberScoop .CYBERSCOOP.COM
10 AugGym Booking Task Turns Into Real-World AI CyberattackAn AI agent hacked a gym booking system while trying to help a user, booking early and removing another person from the waitlist. An Australian man asked his AI assistant to book him into a gym class. He didn’t ask it to hack the booking software, and he definitely didnR…SECURITYAFFAIRS.COM
10 AugHackers breached a small Polish energy plant via private APN last yearHackers breached a heat-and-power plant facility in Poland, which supplies heat to about 50,000 residents, using a private APN (Access Point Name) to access an OT (Operational Technology) network. [...]BLEEPINGCOMPUTER.COM
9 AugU.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled DataIEH was breached by a phishing attack that exposed its Microsoft 365 inbox, including emails and potentially export-controlled military data. IEH Corporation is a U.S. defense and aerospace manufacturer based in Brooklyn, New York. The company specializes in high-reliability elec…SECURITYAFFAIRS.COM
8 AugA little help from your search engine.Today we are joined by ⁠Brian Hussey⁠, SVP of Howler Cell Threat Services at ⁠Cyderes⁠, discussing their work on "Bad Ads, Worse Binaries: Fake Claude Code Installer Drops Infostealer." Howler Cell identified an SEO poisoning campaign targeting people searching for Claude Code in…THECYBERWIRE.COM
8 AugFlock’s Plans for Rideshare Dashcams and Coaching Police, RevealedPlus: A judge rules cell tower dumps unconstitutional, water utility hacks spread to a dozen states, a phishing email opens a missile-parts supplier’s inbox, and a ransomware boss gets 16 years.WIRED.COM
8 AugBrinks Home - 732,162 breached accountsIn July 2026, Brinks Home was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data they alleged was taken from the company, including 732k unique email addresses and other personal information relating to leads, customers and Brinks …HAVEIBEENPWNED.COM
7 AugRisky Bulletin: A Meta AI model also escaped a testing sandboxA Meta AI model also escaped a testing sandbox, a cyberattack disrupts ports in North Carolina, the Philippines will establish a cybersecurity agency, and a Ransom Cartel admin gets 16 years in prison.RISKY.BIZ
7 AugExact Sciences - 10,869,543 breached accountsIn July 2026, Exact Sciences (now owned by Abbott Laboratories) was the target of a ShinyHunters "pay or leak" extortion campaign . The group claimed to have obtained data from the company's cancer diagnostics business, which they later published publicly. The breach contained 10…HAVEIBEENPWNED.COM
7 Aug3.8 Million Impacted by Unlimited Technology Systems Data BreachHackers stole personal, medical, and health insurance information from a company’s data center. The post 3.8 Million Impacted by Unlimited Technology Systems Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
7 AugRansomware Surges in July After Q2 LullFinance, technology and healthcare sectors were particularly heavily targeted in July, according to ComparitechINFOSECURITY-MAGAZINE.COM
7 AugHealthcare and Victim Support Charities Affected by Beacon Cyber IncidentBeacon has informed around 1500 customer charities that its CRM databases were accessed and likely exfiltrated by an unauthorized actorINFOSECURITY-MAGAZINE.COM
7 AugFrench rugby club Stade Français restores systems after cyberattack, probes data leakThe club said Thursday that it had already restored its IT environment from clean backups, allowing operations to continue normally. It added that its ticketing platform and online store were not affected and remain fully operational.THERECORD.MEDIA
7 AugUnlimited Technology Systems data breach impacts 3.8 million peopleUnlimited Technology Systems, a healthcare software and revenue cycle management provider, has suffered a data breach affecting more than 3.8 million people. The HHS Office for Civil Rights lists the Ohio-based company as a business associate and says the hacking incident affecte…CYBERINSIDER.COM
7 AugLevi Strauss says hackers breached employee computers, accessed corporate dataIntruders exfiltrated certain corporate information after gaining access to three company-issued computers through a social engineering attack, Levi Strauss reported.THERECORD.MEDIA
7 AugNorth Carolina Ports confirms cyberattack disrupting operationsThe North Carolina Ports Authority has confirmed that a cyberattack disrupted IT systems and slowed operations at Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. [...]BLEEPINGCOMPUTER.COM
7 AugCoast Guard says it is monitoring cyberattack that disrupted North Carolina’s portsThe cyberattack hit gate systems at all three North Carolina ports, as officials continue investigating the breach and its effects on operations. The post Coast Guard says it is monitoring cyberattack that disrupted North Carolina’s ports appeared first on CyberScoop .CYBERSCOOP.COM
7 AugReal emails, hijacked payments: Two H1 2026 attack chainsGen's H1 2026 Threat Report examines two separate attack chains. One used compromised business inboxes and browser manipulation in a banking-malware campaign, while the other used clipboard hijacking to redirect cryptocurrency payments. [...]BLEEPINGCOMPUTER.COM
7 AugIn Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall StreetNoteworthy stories that might have slipped under the radar: ban on Chinese data center tech, QuickFox VPN supply chain attack, IEH Corporation mailbox breached via phishing. The post In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall St…SECURITYWEEK.COM
7 AugIrregular, firm behind AI hacking incidents, won't say if there were moreA spokesperson said Irregular’s investigation into what happened with Anthropic, OpenAI and Meta's AI models was ongoing and that they could not “go into further details.”THERECORD.MEDIA
7 AugLevi Strauss & Co. says hackers stole corporate data in cyberattackLevi Strauss & Co. (Levi's) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines. [...]BLEEPINGCOMPUTER.COM
7 AugComputer maker Framework notifies ‘all customers’ of a data breachFramework told "all" of its customers that hackers accessed their names, email addresses, phone numbers, and physical addresses in a data breach.TECHCRUNCH.COM
7 AugSecuring your Amazon S3 buckets: Identifying and remediating over-permissioned accessMisconfigured Amazon Simple Storage Service (Amazon S3) buckets can expose your data to unauthorized access. Without proactive review, S3 bucket policies or Access Control Lists (ACLs) configured with broad access may go unnoticed in your environment. In this post, you learn how …AWS.AMAZON.COM
7 AugMilitary device manufacturer discloses cyber incident to SECIEH Corporation — which produces specialized products used in military satellites, missiles and fighter jets — said it discovered a cyberattack on Tuesday and immediately tried to contain it.THERECORD.MEDIA
7 AugHackers Impersonate IT Support to Breach Leading Financial CompaniesHackers used fake IT help desks to steal MFA credentials, targeting over 200 firms, including major financial companies. A hacking campaign operating under names including Redact, Pink, Falcon, and Helix has built credential-stealing websites targeting employees at Blackstone, Br…SECURITYAFFAIRS.COM
7 AugUNC6671 Vishing Attacks Target Personal Phones to Steal SaaS DataA recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671. "UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff fac…THEHACKERNEWS.COM
7 AugUnlimited Technology Systems breach impacts 3.8 million peopleHealthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025. [...]BLEEPINGCOMPUTER.COM
6 AugShai-Hulud strikes again: CHAINDROP worm hits 400+ npm packagesElastic Security Labs identified the return of Shai-Hulud. Attackers compromised the keyv maintainer and deployed CHAINDROP, a worm that uses stolen npm credentials to backdoor co-owned packages totaling over 1.3 billion monthly downloads.ELASTIC.CO
6 AugOpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking SpreeAt the Black Hat security conference, the AI giant revealed new details about how its agents went rogue, hacked several other companies—and did it all right under the company’s nose.WIRED.COM
6 AugTracking people, training AI.This week, Ben and Ethan discuss two major stories. The first involves an incident where a police officer was abusing his access to Flock camera databases to track a former partner's movement. The second looks at recent research that found that Chinese military research units hav…THECYBERWIRE.COM
6 AugSnowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million PeopleConnor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts. The intrusions reached at least 165 organizations and exposed records …THEHACKERNEWS.COM
6 AugSnowflake Hacker Pleads Guilty After Breaching 165 Companies and Stealing Billions of RecordsSnowflake hacker Connor Moucka pleads guilty after breaching 165 organizations, stealing billions of records, and extorting victims. Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty this week to a computer hacking conspiracy that compromised over 165 organizations, …SECURITYAFFAIRS.COM
6 AugRansom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-ServiceA federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel, the ransomware-as-a-service operation he stood up in 2021. Between 2021 and 2023, Ransom Cartel conspirators attacked at least 18 companies…THEHACKERNEWS.COM
6 AugThe water sector just got it’s wake-up call. Again.The attack on water systems across seven states was preventable. Utilities had the playbook. They didn't use it. The post The water sector just got it’s wake-up call. Again. appeared first on CyberScoop .CYBERSCOOP.COM
6 AugMeta AI Hacked External Systems During Cybersecurity TestingThe incident involved a testing environment set up by Irregular, similar to what Anthropic reported last week. The post Meta AI Hacked External Systems During Cybersecurity Testing appeared first on SecurityWeek .SECURITYWEEK.COM
6 AugOver 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack CitiesForescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network. Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, includin…THEHACKERNEWS.COM
6 AugBelarusian cybercriminal behind Ransom Cartel gets 16-year prison sentenceA Belarusian national active in the cybercriminal world for decades was sentenced to 16 years in U.S. prison for running the Ransom Cartel ransomware operation.THERECORD.MEDIA
6 AugMeta's AI escaped sandbox and hacked external systems.Researchers identify backdoor in Chinese-made routers. Snowflake hacker pleads guilty.THECYBERWIRE.COM
6 AugRansom Cartel Leader Sentenced to 16 Years in U.S.A U.S. court sentenced Ransom Cartel founder Maksim Silnikau to 16 years for running a ransomware-as-a-service operation. Maksim Silnikau (aka “J.P. Morgan,” “lansky,” and “xxx,”) built a ransomware business the way a franchise owner builds a c…SECURITYAFFAIRS.COM
6 AugMeta AI model hacked a company during misconfigured cyber testMeta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents continue to emerge following OpenAI'sOpenAI's initial disclosure that its agents breached Hugging Face. [...]BLEEPINGCOMPUTER.COM
6 AugCyberattack on North Carolina Ports ‘contained’ as Coast Guard, state officials investigateNorth Carolina Ports is recovering from a cyberattack after its IT system was “hacked by an outside actor or group,” requiring a switch to manual processing of operations.THERECORD.MEDIA
6 AugRoute Amazon Bedrock Guardrails interventions to Amazon Security LakeSecurity teams investigating AI-related incidents need guardrail intervention data alongside their existing security telemetry. Routing Amazon Bedrock Guardrails violations to Amazon Security Lake makes this possible. With this integration, you can query guardrail events alongsid…AWS.AMAZON.COM
6 AugChina researchers using US AI models for defense systems.US water system cyberattacks continue to grow.THECYBERWIRE.COM
6 AugHedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion groupA recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile campaign extortion group. [...]BLEEPINGCOMPUTER.COM
5 AugInside the North American Water Utility Hacking CrisisInside the North American Water Utility Hacking Crisis: Iran Links, PLC Tactics, Insurance Fallout, and Volunteer Fixes This special Cybersecurity Today episode examines the expanding wave of water utility intrusions across North America, including a WIRED-obtained memo linking a…CYBERSECURITYTODAY.LIBSYN.COM
5 AugWhat stops attackers wrecking industrial plants is knowing howEngineers at an Israeli food producer spent most of a week rebuilding a refrigeration system after an intruder switched the gas cooler and receiver valves to manual and pinned them open. Liquid CO2 flooded the compressors and destroyed them. The replacement units did not match th…HELPNETSECURITY.COM
5 AugFake Bank of America Phishing Scam Installs Remote Access MalwareCybercriminals are using a fake Bank of America phishing campaign to trick users into downloading a malicious script that installs ScreenConnect, enabling remote access and persistence on compromised systemsINFOSECURITY-MAGAZINE.COM
5 AugWater Sector Cyberattacks Reportedly Hit at Least 12 StatesGeorgia has been confirmed as one of the attacked states after Clayton County reported a pump station disruption. The post Water Sector Cyberattacks Reportedly Hit at Least 12 States appeared first on SecurityWeek .SECURITYWEEK.COM
5 AugAngola's Largest Telco Breached Hours Before IPOUnitel, Angola's dominant mobile operator, continues to recover from a cyberattack that caused outages the day of the government-owned telco's public offering.DARKREADING.COM
5 AugOver 400 NPM Packages Infected in ChainDrop Supply Chain AttackThe malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials. The post Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack appeared first on SecurityWeek .SECURITYWEEK.COM
5 AugChainDrop Worm Hits 400+ npm Packages with Two Billion Monthly InstallsA new npm worm has compromised packages with over two billion monthly installsINFOSECURITY-MAGAZINE.COM
5 AugOpen VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer DataA cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed. The "evil twin" extensions were uploaded to the repository b…THEHACKERNEWS.COM
5 AugPrompt Injection Remains Biggest LLM Risk, Despite Limited IncidentsPrompt injection remains the most dangerous security threat to LLMs, according to OWASP’s latest Top 10 LLM Applications listINFOSECURITY-MAGAZINE.COM
5 Aug311,000 Impacted by Brown Health Medical Group-MA Data BreachHackers stole personal information, medical records, and financial information from the organization’s server. The post 311,000 Impacted by Brown Health Medical Group-MA Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
5 AugCybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident DataThe guidelines are the work of the recently launched Open Secure AI Alliance, which now includes 120 organizations. The post Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data appeared first on SecurityWeek .SECURITYWEEK.COM
5 AugCyberattacks on water systems expand to 12 states as South Dakota, Georgia announce incidentsWater utilities in at least 12 states have reported cyberattacks on their operational technology, as the scope of a campaign allegedly linked to Iranian hackers continues to grow.THERECORD.MEDIA
5 AugDutch retailer De Bijenkorf warns customer data may be exposed after cyber incidentAmsterdam-based luxury goods chain De Bijenkorf is the latest retailer to announce a cyber incident involving a third-party logistics provider.THERECORD.MEDIA
5 AugBrown Health Medical Group-MA Data Breach Exposes Information of 311,000 IndividualsBrown Health Medical Group-MA breach exposed personal, medical, and financial data of over 311,000 individuals after hackers accessed its servers. Brown Health Medical Group-MA data breach exposed personal, medical, and financial data of over 311,000 individuals after hackers acc…SECURITYAFFAIRS.COM
5 AugDon't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)When you learn that a compromised package executed on one of your build hosts, muscle memory takes over: revoke the npm token, rotate the GitHub PAT, cycle the cloud keys. That reflex has been correct in almost every supply-chain incident I have worked. In the keyv / cacheable co…ISC.SANS.EDU
5 AugTom Cotton prods Treasury for tax code tweaks to modernize OTThe Senate Intel Committee chair wrote to Treasury Secretary Scott Bessent about changes to spur investment in aging technology to better guard against cyberattacks. The post Tom Cotton prods Treasury for tax code tweaks to modernize OT appeared first on CyberScoop .FEDSCOOP.COM
5 AugWestern government leaders call for a focus on infrastructure resilience, not AI hypeU.S. and allied officials said companies should start preparing now for a cyberattack that changes how they provide essential services.CYBERSECURITYDIVE.COM
5 AugCanadian man pleads guilty to Snowflake hacks that led to 165 breachesA 26-year-old from Ontario faces as many as 32 years in prison after pleading guilty to fraud, identity theft and conspiracy charges related to the 2024 hacks of cloud platform Snowflake.THERECORD.MEDIA
5 AugCSS: The Hidden Threat Lurking in Your InboxCSS was once just about design. Now researchers warn it's powerful enough to exfiltrate data from webmail — and some vendors aren't prepared.DARKREADING.COM
5 AugSnowflake hacker pleads guilty, faces up to 32 years in prisonConnor Moucka obtained almost $500,000 for playing a key role in one of the most widespread and damaging cyberattack sprees on record. The post Snowflake hacker pleads guilty, faces up to 32 years in prison appeared first on CyberScoop .CYBERSCOOP.COM
5 AugA Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks WorldwideFor nearly two years, researcher Vangelis Stykas has maintained access to North Korean hackers’ servers. His work shows they pulled off intrusions in a shocking number of systems across the globe.WIRED.COM
5 AugInter-Con Security - 276,114 breached accountsIn June 2026, Inter-Con Security was targeted in a ShinyHunters “pay or leak” extortion campaign . The group subsequently published data it alleged was taken from the company, including 276k unique email addresses along with names, physical addresses, job titles and phone numbers…HAVEIBEENPWNED.COM
4 Aug31,000 Records Compromised in Breach of Liechtenstein Companies and Foundations RegisterCyberattack exposed data of 31,000 people in Liechtenstein’s beneficial ownership register for companies and foundations. A cyberattack compromised data belonging to about 31,000 people in Liechtenstein’s register of beneficial owners linked to companies, foundations,…SECURITYAFFAIRS.COM
4 AugUK’s Police National Legal Database Reveals Data BreachThe UK’s Police National Legal Database and Ask the Police service have been breachedINFOSECURITY-MAGAZINE.COM
4 Aug150,000 Impacted by Madera Community Hospital Data BreachAn extortion group stole personal, financial, and medical information from the hospital’s network. The post 150,000 Impacted by Madera Community Hospital Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
4 AugAI makes costly spearphishing attacks easier, cyber insurer saysDive Brief: Ransomware extortion caused roughly three-quarters of business losses in the first half of 2026, the cyber insurance firm Resilience said in a recent report. At the same time, ransomware accounted for less than 6% of the incidents for which Resilience customers submit…CYBERSECURITYDIVE.COM
4 AugSwiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspectedThe Federal Office for Information Technology and Communications (BIT) said specialists detected anomalies in on-premises Microsoft servers. The Swiss agency could not confirm exactly how the hackers got in.THERECORD.MEDIA
4 AugLawmakers spring to save ID theft services for OPM breach victims, with expiration loomingSen. Mark Warner, D-Va., and Del. Eleanor Holmes Norton, D-D.C., hope to make the services permanent before they end next month. The post Lawmakers spring to save ID theft services for OPM breach victims, with expiration looming appeared first on CyberScoop .CYBERSCOOP.COM
4 AugNew Shai-Hulud campaign compromises popular npm packages.Samsung bans smart TV apps with residential proxy code. Liechtenstein discloses breach of its Register of Beneficial Owners.THECYBERWIRE.COM
4 AugTech industry alliance proposes AI agent safety reporting programThe information-sharing exchange is designed to widely share lessons learned from agentic AI security incidents.CYBERSECURITYDIVE.COM
4 AugMassive ChainDrop npm supply-chain attack infects hundreds of packagesSelf-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. [...]BLEEPINGCOMPUTER.COM
4 AugPolish convenience store chain Żabka hacked through third-party accountReports said intruders appeared to gain access to the Jira environment and other sensitive data of the Żabka retail chain. The company confirmed an intrusion occurred in late July.THERECORD.MEDIA
4 AugIran Cyberattacks Against Minnesota Water SystemsAttribution is preliminary , and so far it seems no real damage. And it seems like this is a campaign that has targeted at least seven states . And, because this is where the US is right now, Trump doesn’t believe it’s Iran and that Minnesota…I guess…hacke…SCHNEIER.COM
4 AugNew XCSSET variant targets macOS devs via compromised Xcode projectsA new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories. [...]BLEEPINGCOMPUTER.COM
4 AugSmoke#Screen RMM Takeover Gambit Exposes Threat Actor PlaybookThe attacks use diverse social engineering lures and rotating payloads to deliver ScreenConnect for persistent remote access to compromised networks.DARKREADING.COM
4 Aug128 Seconds to disruption: Microsoft Defender stops ransomware at QNETMicrosoft Defender automatically isolated a compromised QNET endpoint in 128 seconds, stopping a multi-stage attack before the payload could persist or spread. The post 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET appeared first on Microsoft Security Blo…MICROSOFT.COM
4 AugChainDrop credential stealing worm infects over 400 npm packagesA self-propagating worm-like attack is hitting the npm registry, having infected 444 packages from more than a dozen publishers so far. The impact is massive, with the packages affected amounting to more than 2 billion monthly downloads combined. The attack began with the comprom…CSOONLINE.COM
4 AugRansomware Changed Its First TargetThis discussion highlights a shift in ransomware tactics. Rather than relying primarily on phishing or endpoint compromises, attackers are increasingly targeting weaknesses in network infrastructure to gain trusted access. Compromising infrastructure can give attackers a stronger…YOUTUBE.COM
4 AugChainDrop supply chain compromise: Anatomy of a self-propagating wormA credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates. This analysis details the attack chain, affected environments, and practical guidance for detection, hunting, and remedia…MICROSOFT.COM
3 AugWeekly Update 515Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite Apparently, Aussies are so obsessed with coffee that it's referred to as the coffee capital of the world down here (some bits, at …TROYHUNT.COM
3 AugRisky Bulletin: Anthropic models also did the hacky-hackyAnthropic models also did the hacky-hacks, Coldcard was hacked for $70 million in Bitcoin, npm adds publish-time malware scanning, and Russia is behind the recent hotel WiFi hacks.RISKY.BIZ
3 AugProduct showcase: Guardio Mobile Security turns breach alerts into a recovery planGuardio Mobile Security brings several protection features to iPhone and Android, allowing users to monitor exposed personal information, identify phishing attempts, and receive alerts about emerging threats from a single application. It is available on smartphones and tablets, w…HELPNETSECURITY.COM
3 AugCrowdStrike: AI is now both the weapon and the target in cyberattacksAI generates 2.5 signals for every human-triggered signal CrowdStrike has to assess. Meanwhile, attackers are using AI to weaponize vulnerabilities faster than companies can patch them. The post CrowdStrike: AI is now both the weapon and the target in cyberattacks appeared first …CYBERSCOOP.COM
3 AugUS Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other StatesMichigan, South Dakota, and Georgia are reportedly on the list of states whose water systems have been targeted by Iran-linked hackers. The post US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States appeared first on SecurityWeek .SECURITYWEEK.COM
3 AugElastic Defend now covers 800+ vulnerable drivers, with automated troubleshooting and ARM supportAttackers reaching for kernel access on a Windows machine bring a driver Microsoft already trusts. It is signed, it loads, and it carries a known flaw. That flaw gives them enough room to tamper with memory or disable the security software watching the host. Once an attacker hold…HELPNETSECURITY.COM
3 AugRussian State APT Linked to Recent Public Wi-Fi Gateway HackingMidnight Blizzard has been stealing Microsoft account credentials via compromised Wi-Fi networks at hospitality organizations. The post Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking appeared first on SecurityWeek .SECURITYWEEK.COM
3 AugPNLD Breach Exposes U.K. Police and Government Contact Details on Dark WebThe Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web. The data included names, organisations and work email addresses belonging to police officers, police staff, criminal jus…THEHACKERNEWS.COM
3 AugKorea’s Largest Telco KT Fined $38m After Femtocell CampaignKorean telco KT has been fined $39m for a year-long breach linked to femtocell compromiseINFOSECURITY-MAGAZINE.COM
3 AugBrinks Home Discloses Data Breach as Hackers Leak FilesThe physical security firm says its alarm monitoring and system functionality have not been affected. The post Brinks Home Discloses Data Breach as Hackers Leak Files appeared first on SecurityWeek .SECURITYWEEK.COM
3 AugFOMO in the SOC: Where AI Platforms like Claude Actually FitAI is moving incredibly fast, and every security leader is feeling the pressure to keep up. AI platforms like Claude, Codex and Cursor are already helping security teams write detections, investigate alerts, summarize incidents, and automate repetitive work. The conversation has …THEHACKERNEWS.COM
3 AugRiver Bank Says Hackers Deleted Data Stolen in Ransomware AttackThe bank holding company was hacked in June, but the investigation into the incident continues. The post River Bank Says Hackers Deleted Data Stolen in Ransomware Attack appeared first on SecurityWeek .SECURITYWEEK.COM
3 AugBiotech giant Amgen says patient data stolen from third-party cloud systemsThe biotech giant Amgen informed regulators that patient information and proprietary company data were accessed through a breach of third-party cloud systems.THERECORD.MEDIA
3 Aug3rd August – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30 community water utilities across the state. The i…RESEARCH.CHECKPOINT.COM
3 AugChinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable serversA Chinese threat actor operating under the aliases “knaithe” and “KnYuan” used multiple LLMs to automate cyberattacks against internet-facing systems with limited human intervention. Researchers at Palo Alto Networks’ Unit 42 uncovered the operation …HELPNETSECURITY.COM
3 AugHorizon3.ai hits $2 billion valuation in $250 million funding roundHorizon3.ai has announced a $250 million Series E at a valuation of more than $2 billion, tripling its valuation from $650 million at Series D in just over a year. The oversubscribed round was co-led by existing investors NightDragon and NEA, with participation from seven new inv…HELPNETSECURITY.COM
3 AugAn analysis of incidents at Brazilian educational institutionsKaspersky expert provides statistics and details on several incident response cases at educational institutions in Brazil, as well as tips for schools and universities on how to stay safe.SECURELIST.COM
3 AugExfilSquad hackers leak info of over 100,000 UK police officers, staffA cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals. [...]BLEEPINGCOMPUTER.COM
3 AugRiver Bank obtained assurances from the attackers that the stolen data in the June attack was deletedRiver Bank says hackers deleted data stolen in its June ransomware attack, though the investigation into the incident is still ongoing. River Financial Corporation, the parent company of River Bank & Trust, says hackers deleted data stolen during a ransomware attack that hit …SECURITYAFFAIRS.COM
3 AugWho’s legally to blame for Anthropic and OpenAI’s autonomous AI hacks? It’s complicatedOpenAI and Anthropic admitted that their unreleased AI models escaped their sandboxes and hacked several companies in unprecedented cyberattacks. Who is legally to blame? Should prosecutors charge the two AI frontier labs? Can victims sue them? We spoke to lawyers who specialize …TECHCRUNCH.COM
3 Aug[Webinar] Tales from the Frontlines: An exclusive briefing on Q2 incidentsRegister for an exclusive, unrecorded 30-minute webinar to review the most high-impact incidents Talos IR faced in Q2.TALOSINTELLIGENCE.COM
3 AugHackers steal 31,000 records identifying people behind Liechtenstein companies, foundationsA cyberattack compromised tens of thousands of records related to companies, foundations and trusts in Liechtenstein, prompting the government to to form a “crisis unit” to address the breach.THERECORD.MEDIA
3 AugCyberattack Hits Liechtenstein’s Register of People Behind Companies and FoundationsThe list of people behind companies, foundations and trusteeships is part of efforts to combat money laundering and terror financing. The post Cyberattack Hits Liechtenstein’s Register of People Behind Companies and Foundations appeared first on SecurityWeek .SECURITYWEEK.COM
3 AugAnthropic: AI Attacks Result of Security Gaps, Not Model IssuesLast month's incidents in which Claude breached real-world systems derived from over-permissioning, especially with Internet access.DARKREADING.COM
3 AugNew Pass-ta-key attacks let malware hijack Google-synced passkeysSecurity researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys to take over accounts, bypass user verification, and extract passkey private keys. [...]BLEEPINGCOMPUTER.COM
3 AugHotel Wi-Fi attacks use custom malware to breach Microsoft 365 accountsMicrosoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. [...]BLEEPINGCOMPUTER.COM
1 AugHealthcare Cybersecurity in 2026: Healthcare CISO Matt Burke on AI, MFA, SOCs & Incident ReadinessOn Cybersecurity Today on the Weekend, host David speaks with Matt Burke, CISO of Bespoke Concierge MD, a telemedicine provider with doctors licensed in all 50 states, about defending patient data amid rising healthcare threats in 2026. Burke explains why healthcare is heavily ta…CYBERSECURITYTODAY.LIBSYN.COM
1 AugThe hidden risks in space supply chains.As the space ecosystem continues to expand, the sector has become increasingly filled with new suppliers, manufacturers, and operators. However, while this development has led to the introduction of new technologies, it has also greatly expanded space's cyberattack surface. In th…THECYBERWIRE.COM
1 AugSplitVPN - 865,336 breached accountsIn July 2026, the Russian VPN service SplitVPN (previously known as NotVPN) suffered a data breach . The incident exposed millions of customer records, including 865k unique email addresses. Other impacted data included IP addresses, the user's country, and partial payment card d…HAVEIBEENPWNED.COM
1 AugHackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer SitesAttackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and repor…THEHACKERNEWS.COM
1 AugNobody Knows if OpenAI’s and Anthropic’s AI Hacking Sprees Are IllegalBoth major AI labs’ models broke containment, escaped onto the internet, and hacked other companies. If a human had done that, the law would likely be against them. But a bot?WIRED.COM
1 Aug7 States’ Water Systems Hit by Cyberattacks Likely Tied to IranPlus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.WIRED.COM
31 JulAnthropic says its AI accidentally hacked three companies during safety testsFollowing OpenAI’s own incident, Anthropic reviewed its own evaluations and found three cases of Claude hacking external companies. The post Anthropic says its AI accidentally hacked three companies during safety tests appeared first on CyberScoop .CYBERSCOOP.COM
31 JulAnthropic Says Claude Hacked 3 Organizations During Cybersecurity TestsIn a review triggered by OpenAI’s Hugging Face incident, Anthropic discovered three of its AI models had breached real organizations during third-party evaluations.WIRED.COM
31 JulRisky Bulletin: Crime Stoppers puts bounty on INC ransomware groupA non-profit puts a $22,000 bounty on the INC ransomware group, hackers breach the UK Department for Education, Russia charges Telegram founder Pavel Durov, and the FCC bans foreign robots and power inverters.RISKY.BIZ
31 JulCareCloud Data Breach Impacts Over 350,000In March 2026, hackers stole personal, financial, and medical information from the company’s AWS environment. The post CareCloud Data Breach Impacts Over 350,000 appeared first on SecurityWeek .SECURITYWEEK.COM
31 JulAnthropic Reveals Claude Escaped Testing, Breaching Three CompaniesAnthropic has revealed that Claude AI models broke free of sandbox to compromise third-party organizationsINFOSECURITY-MAGAZINE.COM
31 JulPrompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 OrganizationsA security company’s systems were hacked after it installed a malicious Python package deployed by Claude. The post Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations appeared first on SecurityWeek .SECURITYWEEK.COM
31 JulAnthropic says its AI hacked real-world companies in three incidentsClaude maker Anthropic said its AI models escaped test environments and breached networks at three companies on the open internet.THERECORD.MEDIA
31 JulESET tracks rise in malicious AI skills and adaptable malwareAttackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET's new threat report examines the rise of malicious AI skills, AI-assisted malware, ClickFix attacks, record quishing activity, and ransomware tools designed to d…BLEEPINGCOMPUTER.COM
31 JulCyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian HackersIran has the “geopolitical motivations” and a recent history of targeting water systems, experts pointed out. The post Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers appeared first on SecurityWeek .SECURITYWEEK.COM
31 JulTrump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber worldThe president went against his intelligence agencies’ conclusions about Iran being the likely suspect in the campaign. The post Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world appeared first on CyberScoop .CYBERSCOOP.COM
31 JulRogue AI, the Bar, Breaches, BMC, Hugging Face, Helmuth von Multke, Ike, Shieldfont, - SWN #603Rogue AI, the Bar, Breaches, BMC, More Hugging Face, Helmuth von Multke, Ike, Shieldfont, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-603YOUTUBE.COM
31 JulOnline ad firm Adform’s script compromised to steal cryptocurrencyOnline advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones controlled by an attacker. [...]BLEEPINGCOMPUTER.COM
31 JulAmgen says cloud data breach exposed patient health, proprietary infoPharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. [...]BLEEPINGCOMPUTER.COM
30 JulDealing with AI-Generated ExtortionCombat AI-generated extortion and fake ransomware leaks. Learn how organizations can verify data authenticity using robust governance and threat intelligence.RECORDEDFUTURE.COM
30 JulAmazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire SleetAmazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as crypto theft: a maintainer phished through a lookalike npm domain and a wallet-draining script pushed into at least 18 packages c…THEHACKERNEWS.COM
30 JulToy Ghouls’ new toy: the GenieLocker ransomwareKaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks by Toy Ghouls, a financially motivated extortion group.SECURELIST.COM
30 JulSrsly Risky Biz: Chipping away at Chinese AI risksTom Uren and James Wilson talk about open-weight AI models and distillation. These topics have been subject to a lot of US government attention in recent weeks, but let’s not forget that America’s overriding goal is to remain ahead of China in the AI race. There are better ways t…RISKY.BIZ
30 JulCoordinated cyberattack hits more than 30 Minnesota water utilitiesA coordinated cyberattack on July 26 and 27 hit operational technology (OT) systems at more than 30 community water utilities across Minnesota, prompting an immediate response from Minnesota IT Services (MNIT) to contain the threat. MNIT confirmed the attack in a statement publis…HELPNETSECURITY.COM
30 JulOpenAI’s Hacking Debacle Was a Human MistakeIf the generative AI giant had followed well-known security best practices, it’s likely that its AI agent would never have escaped to the open internet and hacked multiple companies.WIRED.COM
30 JulSemiconductor Firm Analog Devices Discloses Data BreachHackers were detected on Analog Devices systems in June, and an investigation found that they stole files. The post Semiconductor Firm Analog Devices Discloses Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
30 JulThe Network Has Become the Control Plane for AI SecurityNetwork firewalls are the workhorses of modern cybersecurity. They are trusted to protect the network, blocking malicious traffic and preventing intrusions and breaches. And for decades, network security teams have built controls around a relatively stable model: users connect to…THEHACKERNEWS.COM
30 JulAfter the Break-In: What Attackers Do Once They're Already InsideAttackers rarely stop after gaining initial access. Huntress analyzes a real-world intrusion to show how threat actors establish persistence, disable defenses, and reshape compromised systems, and why defenders must investigate the original entry point rather than simply remove t…BLEEPINGCOMPUTER.COM
30 JulIn the Hugging Face breach, OpenAI’s hacker was noisy and fast — but not unstoppableCybersecurity experts told TechCrunch that one of the biggest lessons to be taken from the OpenAI hack against HuggingFace has nothing to do with AI, but traditional cybersecurity defense.TECHCRUNCH.COM
30 JulNorth Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warnCyberattack tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations — further evidence of deepening entanglement between Pyongyang-backed hackers and the ransomware ecosystem.THERECORD.MEDIA
30 JulHackers abuse Microsoft Teams in ransomware campaign through fake IT supportResearchers said dozens of US and Canadian firms have been targeted, however, the motivation appears to be financial rather than espionage.CYBERSECURITYDIVE.COM
30 JulMicrosoft Teams vishing attacks lead to Chaos ransomware attacksThreat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations. [...]BLEEPINGCOMPUTER.COM
30 JulAnalog Devices discloses data breach, says operations unaffectedAmerican semiconductor company Analog Devices announced that an unauthorized party accessed some of its systems and exfiltrated certain files. [...]BLEEPINGCOMPUTER.COM
30 JulChina lists open AI models as national security concern.Cyberattack on Minnesota water systems more extensive than original estimates.THECYBERWIRE.COM
30 JulSemiconductor chip titan Analog Devices reports data breachIn a filing for federal regulators, Massachusetts-based Analog Devices said intruders had exfiltrated data from its networks earlier this summer, but the scope of the incident is still under investigation.THERECORD.MEDIA
30 JulA Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to IranA memo obtained by WIRED, issued by the water utilities information sharing group WaterISAC, links dozens of cyberattacks against Minnesota water utilities to Tehran.WIRED.COM
30 JulSouth Korea fines telco giant KT $39 million for customer data breachSouth Korea's Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53.979 billion ($39 million) over data protection violations. [...]BLEEPINGCOMPUTER.COM
30 JulClaude uploaded malware to PyPI in Anthropic's botched testOne of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. [...]BLEEPINGCOMPUTER.COM
30 JulAnthropic's Claude breached 3 orgs, uploaded PyPI malware during testsOne of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. [...]BLEEPINGCOMPUTER.COM
29 JulOpenAI’s Rogue AI Agent Hacked More Than Just Hugging FaceIn a new disclosure, OpenAI says its agent used exposed logins to gain access to at least four “publicly available services” in its unhinged quest to solve a test.WIRED.COM
29 JulTwo Compromised joyfill npm Packages Run RAT When Imported Into Node.jsBeta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The list of affected packages is as follows - @joyfill/layouts@0.1.2-2773.beta.0 @joyfill/components@4.…THEHACKERNEWS.COM
29 JulThe energy sector’s OT cybersecurity talent is retiring faster than it can be replacedA ransomware hit lands a chemical plant in a safe state. Nobody is hurt, the site holds steady, and the operators begin the restart. The systems stay down. Every attempt to bring them online meets encrypted processes and altered configurations. The outage runs into weeks, and the…HELPNETSECURITY.COM
29 JulOpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face BreachOpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face's production environment, and also hacked multiple third-party accounts and services as part of the attack. The latest disclosure sho…THEHACKERNEWS.COM
29 JulRisky Business #846 -- OpenAI built a fireplace out of woodOn this week’s show special guest co-host Pete Ranks, the former director of the CIA’s Centre for Cyber Intelligence, joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover: Everyone signs the open weights open letter, except Anthropic… of course…RISKY.BIZ
29 JulRisky Bulletin: Cyberattack disrupts Minnesota water utilitiesA cyberattack has disrupted water utilities in more than 30 communities in Minnesota, Denmark tests a secondary banking system in case of a cyberattack, North Korea arrests bank hackers, and a new Chinese cyber contractor has been identified.RISKY.BIZ
29 JulVPN Breach Exposes 58 Million Connection Logs Despite “No-Logs” ClaimsA breached “no-logs” VPN exposed 58 million connection logs and millions of user, device, and payment records, contradicting its privacy claims. A threat actor on the Altenen cybercrime forum is distributing a 17 GB SQL database claimed to have been stolen from SplitV…SECURITYAFFAIRS.COM
29 JulOpenAI’s rogue AI agent shows why we need federal rules for autonomous systemsThe Hugging Face breach shows there is a gap in federal policy. The frameworks to govern autonomous AI already exist—there just needs to be the desire to apply them. The post OpenAI’s rogue AI agent shows why we need federal rules for autonomous systems appeared first on Cy…CYBERSCOOP.COM
29 JulOver 30 water systems in Minnesota hit by coordinated cyberattackMinnesota officials have activated a statewide cybersecurity response after a coordinated cyberattack targeted the operational technology (OT) of more than 30 community water systems across the state. Authorities say there is currently no indication that residents need to alter t…CYBERINSIDER.COM
29 JulOpenAI’s Rogue AI Agent Breached Second Company, Report SaysReuters says OpenAI’s rogue AI agent also breached a Modal customer, exposing a wider attack and raising fresh concerns over autonomous AI safety. Reuters reported that the OpenAI agent that hacked Hugging Face earlier this month also compromised a customer at a second comp…SECURITYAFFAIRS.COM
29 JulThe Average Cost of a Data Breach Rises to $5 MillionIBM Cost of a Data Breach Report warns that the global average cost of a data breach has reached a record high of $4.99m – and AI-backed attacks have played a roleINFOSECURITY-MAGAZINE.COM
29 Jul73% of Organizations Say They Are Not Fully Ready for a Major CyberattackMost organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the coordination, visibility, and executive alignment needed to withstand a serious cyberattack. According to The State of Incident Respon…THEHACKERNEWS.COM
29 JulCyberattack hits Angola’s largest telco hours before landmark stock debutAngola’s largest telecommunications operator, Unitel, was hit by a cyberattack that has left millions of people nationwide without voice services, mobile data, and internet access.THERECORD.MEDIA
29 JulStairwell launches Backstory, pioneering agentic investigation for malware blast radiusStairwell, the AI SOC that stops breaches no one else can, today announced the availability of Backstory, an agentic investigation platform that traces related malware variants, identifies affected systems, and maps the full blast radius of an incident in seconds, so enterprises …HELPNETSECURITY.COM
29 JulCoordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes OfflineA coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. Braham, Plymouth, South St. Paul and Maple Plain have publicly described a plant outage, communications fa…THEHACKERNEWS.COM
29 JulOpenAI explains how its AI agent breached Hugging FaceOpenAI has published an update on the incident in which one of its agents escaped its sandbox and accessed Hugging Face infrastructure.MALWAREBYTES.COM
29 JulAs data breaches grow costlier, ungoverned AI creates new risksMeanwhile, many companies still aren’t doing the basics to protect on-premises data, IBM found.CYBERSECURITYDIVE.COM
29 JulHackers target over 30 Minnesota water utilities in coordinated OT attackThe Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities across the entire state after hackers targeted more than 30 community water systems in "a coordinated cyberattack." [...]BLEEPINGCOMPUTER.COM
29 JulOpenAI agent used exposed credentials at 4 services in Hugging Face breachIn a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other organizations. [...]BLEEPINGCOMPUTER.COM
29 JulWho's Liable When AI Agents Escape? Hugging Face Breach Raises Hard QuestionsDark Reading walks through the many twists and turns in the bizarre story of how OpenAI's agent AI system broke out of its sandbox and decided to target Hugging Face, and what CISOs should be aware of.DARKREADING.COM
29 JulHackers Strike Minnesota Water Utilities, One Plant Briefly OfflineCoordinated OT cyberattacks hit 30+ Minnesota water utilities, briefly disrupting one plant. Backup procedures prevented major water service impacts. Minnesota just had its own live-fire lesson in what happens when someone targets water utilities at scale. Between Sunday and Mond…SECURITYAFFAIRS.COM
28 JulFor Some, So-Called ‘Skynet Day’ Came too Close to Sci-Fi After a Rogue Agent Hacked Into a StartupDecades after it appeared in “The Terminator,” Skynet looks more like a forecast of the cyber incident in which a rogue AI system hacked into another AI company on its own. The post For Some, So-Called ‘Skynet Day’ Came too Close to Sci-Fi After a Rogue Agent Hacked Into a Startu…SECURITYWEEK.COM
28 JulOrigin Energy Data Breach Affects 900,000 AustraliansThe hacker claimed to have stolen the information of 2 million Origin Energy customers after breaching its systems. The post Origin Energy Data Breach Affects 900,000 Australians appeared first on SecurityWeek .SECURITYWEEK.COM
28 JulShadow AI incident response begins with logs that may already be goneIn this Help Net Security interview, Brandy Wityak, VP of Complex Matters at LevelBlue, explains what happens in the hours after a shadow AI incident. She describes how quickly logs roll over, why firewall records of outbound traffic to AI platforms are often gone before responde…HELPNETSECURITY.COM
28 JulHouston City College - 831,642 breached accountsIn June 2026, Houston City College was the target of a ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from the college was later published publicly and included 832k unique email addresses along with names, addresses, phone numbers, academic records, and …HAVEIBEENPWNED.COM
28 JulCoca-Cola confirms hackers stole data in Fairlife ransomware attackCoca-Cola has confirmed that the ransomware attack on its dairy subsidiary Fairlife involved the theft of company data, weeks after the incident temporarily halted production at its US facilities. Fairlife is a Coca-Cola-owned dairy brand that makes ultra-filtered milk and protei…HELPNETSECURITY.COM
28 JulCoca-Cola Reveals Subsidiary Fairlife Suffered Data BreachCoca Cola claims data was stolen from its Fairlife business after a recent ransomware attackINFOSECURITY-MAGAZINE.COM
28 JulVERITAS project could change the way scientists secure AIThe AI models, datasets, and automated systems researchers depend on can be compromised in ways conventional cybersecurity tools aren’t designed to detect. A new project called VERITAS (VERified Infrastructure for Trustworthy AI in Science) aims to close that gap by establi…HELPNETSECURITY.COM
28 JulTeam Cymru unveils Pure Signal Command for AI-powered threat intelligence and incident responseTeam Cymru has announced Pure Signal Command, the connected operating environment for analysts, security teams, applications, and AI agents to access and act on Team Cymru’s internet infrastructure intelligence. Command unlocks Team Cymru’s globally observed threat intelligence d…HELPNETSECURITY.COM
28 JulPhishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion TechniquesAnalysis of real-life incident response cases by Cisco Talos warns that phishing remains a powerful method of initial compromiseINFOSECURITY-MAGAZINE.COM
28 JulIs Your SSO Protected Against Modern Credential Attacks?A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening help secure modern SSO environments and the applications they protect. [...…BLEEPINGCOMPUTER.COM
28 JulIndia’s Bank of Baroda confirms cyber incident after hackers claim data theftAn employee's email account had been compromised, allowing unauthorized access to "certain data," Bank of Baroda reported.THERECORD.MEDIA
28 JulHugging Face breach reignites open-weights debate, raises liability questionsThe first publicly documented cyberattack run end-to-end by an autonomous AI was an OpenAI benchmark test that escaped its sandbox and breached Hugging Face. In an incident post-mortem compiled with the input from Hugging Face and several hundred members of Cloud Security Allianc…HELPNETSECURITY.COM
28 JulCoordinated cyberattack disrupts water utilities in 30+ Minnesota communitiesA cyberattack of undetermined origin disrupted water treatment plants in at least 30 communities in Minnesota, according to the state's technology bureau. The post Coordinated cyberattack disrupts water utilities in 30+ Minnesota communities appeared first on CyberScoop .STATESCOOP.COM
28 JulYou've been disconnected.A senator targets legacy VPNs. Minnesota water systems come under cyberattack. A 20-year-old flaw exposes 24,000 servers. Microsoft debuts its first cybersecurity AI model. A critical VeloCloud bug is under active attack. The Dysphoria botnet tops 200,000 devices. Apple faces a l…THECYBERWIRE.COM
28 JulStack Sports warns users after payment card data exposed through malicious codeSports technology provider Stack Sports is notifying users of a cybersecurity incident that may have exposed payment card information entered through its Sports Affinity web application platform. According to a data breach notification sent to affected individuals, Stack Sports d…CYBERINSIDER.COM
28 JulAuthorities investigating a coordinated cyberattack against Minnesota water systemsThe two-day attack comes days after federal officials warned of state-linked threat groups targeting a wider set of industrial devices.CYBERSECURITYDIVE.COM
27 JulMCBS Data Breach Affects 1.2 Million IndividualsThe PEAR ransomware group claimed to have stolen 3 TB of information from the medical business management company. The post MCBS Data Breach Affects 1.2 Million Individuals appeared first on SecurityWeek .SECURITYWEEK.COM
27 JulWhat the identity attack surface looks like when trust becomes the targetIn this Help Net Security video, Joel Moses, VP, Strategic Engineering at F5, explains how attackers use identity instead of breaking through it. He walks through MFA fatigue, session token theft, and consent given to malicious applications, using the 2022 Uber breach as an examp…HELPNETSECURITY.COM
27 JulLockBit5 and Qilin Lead Ransomware Attacks Against Italian OrganizationsA new report links 148 ransomware attacks to Italian organizations in H1 2026, with manufacturing the most targeted sector. Six months, 148 confirmed ransomware claims against Italian targets, and one sector taking the brunt of it. That’s the headline number from a new semi…SECURITYAFFAIRS.COM
27 JulRansomware Groups Increasingly Deploy EDR Kill TechniquesHalcyon’s latest quarterly ransomware report showed that while ransomware attacks are declining, obfuscation techniques are getting harder to fight againstINFOSECURITY-MAGAZINE.COM
27 JulDentaQuest Data Breach Potentially Impacts Over 23 Million PeopleIn May 2026, hackers stole personal and dental health information from DentaQuest’s computer network. The post DentaQuest Data Breach Potentially Impacts Over 23 Million People appeared first on SecurityWeek .SECURITYWEEK.COM
27 JulHacked Public Wi-Fi Gateways Used to Harvest Corporate CredentialsA threat actor has been using the compromised appliances to target the Microsoft 365 accounts of traveling corporate employees. The post Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials appeared first on SecurityWeek .SECURITYWEEK.COM
27 JulCoca-Cola Confirms Data Breach After Fairlife Ransomware AttackThe Anubis cybercrime group has taken credit for the attack and is threatening to leak data. The post Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack appeared first on SecurityWeek .SECURITYWEEK.COM
27 JulMedusaHVNC Malware Uses Hidden Windows Desktops to Evade DetectionThe malware-as-a-service operation launches legitimate browsers on an invisible desktop, giving attackers persistent and covert remote access to compromised Windows systems. The post MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection appeared first on SecurityWeek…SECURITYWEEK.COM
27 JulOperation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams UpdateCybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote monitoring and management (RMM) tools. "The victim was directed through compromised web infrastructure to a counterfeit Microsoft St…THEHACKERNEWS.COM
27 JulDynatrace Intelligence automates incident triage and remediation with AI agentsDynatrace has announced major advancements to Dynatrace Intelligence that help automatically resolve incidents, prevent disruptions, and accelerate operations while maintaining the human oversight and governance enterprises require. Building on the introduction of Dynatrace Intel…HELPNETSECURITY.COM
27 JulCoca-Cola restores most production capacity at dairy unit after ransomware attackThe company said it does not expect the Fairlife disruption to have a material impact on financial performance or operations. CYBERSECURITYDIVE.COM
27 Jul27th July – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Nichirei, a Japan-based frozen-food supplier and logistics company, has experienced a ransomware attack that disrupted shipping opera…RESEARCH.CHECKPOINT.COM
27 JulCoca-Cola confirms data theft in Fairlife ransomware attackThe Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. [...]BLEEPINGCOMPUTER.COM
27 JulHealth system in South Carolina, Georgia closes offices after malware affects networksOn Sunday, AnMed published a statement online saying they were “experiencing a cybersecurity disruption involving malware” and were working to restore systems and determine the scope of the incident.THERECORD.MEDIA
27 JulDid an AI Really Escape?Reports about AI models escaping sandboxes and using external systems have sparked debate within the cybersecurity community. At the same time, some practitioners argue that safety guardrails can interfere with legitimate security and incident response workflows. The tension betw…YOUTUBE.COM
27 JulNew Dysphoria DDoS botnet spreads to 200k devices worldwideA botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. [...]BLEEPINGCOMPUTER.COM
27 JulReuters: OpenAI Agent Hacked Hugging Face for Days Before Being DetectedReuters says OpenAI failed to detect its AI agent hacking Hugging Face for days, discovering the breach only after FBI involvement. Reuters reported that the OpenAI agent responsible for the Hugging Face breach operated undetected for over a week before OpenAI realized what had h…SECURITYAFFAIRS.COM
26 JulSecurity Affairs newsletter Round 587 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Iran-Linked Actors Breach Are…SECURITYAFFAIRS.COM
26 JulHackers Hijack Hotel Wi-Fi to Steal Microsoft 365 CredentialsHackers compromised hotel Wi-Fi gateways to redirect users to fake Microsoft 365 login pages and steal credentials. ReliaQuest’s threat research team just documented attackers compromising the Wi-Fi gateways at hotels and conference centers, then quietly rerouting guests to…SECURITYAFFAIRS.COM
26 JulSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 107Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter UAC-0145 Primary Compromise Vectors as of July 2026 SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyG…SECURITYAFFAIRS.COM
26 JulHugging Face CEO calls for ‘radical transparency’ after ‘unprecedented’ OpenAI hack"The first autonomous agent cyberattack is an unprecedented event. It deserves an unprecedented response!"TECHCRUNCH.COM
25 JulDavid Shiply Interviews Pratim Datta, PhD from Kent StateAI, Cybersecurity, and Public Policy: Export Controls, Arms Races, and the "New Radium" On Cyber Security Today (Weekend), the host interviews Pratim Datta, a Kent State University professor and former global consultant, about the past six months of AI and public policy as it int…CYBERSECURITYTODAY.LIBSYN.COM
25 JulThe OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for DaysPlus: Russian hackers are trying to steal US nuclear scientists’ emails, the State Department bans known scammers from entering the United States, and more.WIRED.COM
25 JulCTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account HijackingFor years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an opportunity arose. That model is changing. Recen…THEHACKERNEWS.COM
25 JulAI Now Picks Cybercrime TargetsSome malware operations reportedly include AI-powered profiling features that analyze compromised systems and rank victims based on characteristics that may indicate higher financial value or operational importance. This helps attackers decide where to focus their efforts. Automa…YOUTUBE.COM
25 JulShinyHunters data leaks fuel $2,000 sextortion email scamThreat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. [...]BLEEPINGCOMPUTER.COM
25 JulThe hacker who humiliated spyware makers and was never caughtAn awe-inspiring hacktivist who hacked two controversial government spyware makers may be the most prolific hacker to have never gotten caught. What do we know about Phineas Fisher?TECHCRUNCH.COM
24 JulData Breach Confirmed After Australian Energy Giant Origin Is HackedA hacker claims to have stolen the information of 2 million Origin Energy customers and is threatening to leak it. The post Data Breach Confirmed After Australian Energy Giant Origin Is Hacked appeared first on SecurityWeek .SECURITYWEEK.COM
24 JulRansomware gangs go after EMEA healthcare’s supply chainA ransomware attack against a hospital makes headlines, while attacks on the rest of the ecosystem around it tend to stay quiet despite doing damage that can be just as bad. Flare researcher Assaf Morag analyzed ransomware leak-site activity tied to healthcare organizations in th…HELPNETSECURITY.COM
24 JulClop ransomware targets Windchill, FlexPLM in data theft attacksThe Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. [...]BLEEPINGCOMPUTER.COM
24 JulRansomware Attacks Targeting Universities on the RiseComparitech’s analysis of incidents in the first half of 2026 finds that the emergence of The Gentlemen ransomware has resulted in surge in attacks against higher educationINFOSECURITY-MAGAZINE.COM
24 JulHotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials From VisitorsResearchers at ReliaQuest warned of widespread DNS poisoning attacks targeting the hospitality sector as part of a cyber espionage campaignINFOSECURITY-MAGAZINE.COM
24 JulChick-fil-A data breach affects more than 13,000 customersChick-fil-A has confirmed that over 13,000 customers had their accounts breached in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19. [...]BLEEPINGCOMPUTER.COM
24 JulIn Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel FlawsNoteworthy stories that might have slipped under the radar: Siemens ROX II industrial switch vulnerabilities, Russian Zimbra webmail espionage campaign, Stadler Rail ransomware extortion attempt. The post In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 40…SECURITYWEEK.COM
24 JulBlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware DeliveryThe North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malwar…THEHACKERNEWS.COM
24 JulDespite multiple takedowns, botnets continue to growRoughly 1 in 4 of those compromised IPs are based in the United States, Lumen’s Black Lotus Labs said. Botnets like IPIDEA have also rebounded quickly, surpassing their pre-disruption footprint. The post Despite multiple takedowns, botnets continue to grow appeared first on Cyber…CYBERSCOOP.COM
23 JulRansomware Attack Puts a Chill On Japanese Frozen-Food ChainA cyberattack on a food and logistics firm disrupts the supply of frozen food to thousands of clients, including major franchises like Kentucky Fried Chicken.DARKREADING.COM
23 JulTwo-Thirds of Ransomware Victims Say AI Boosted Attack EffectivenessA new study of organizations which have fallen victim to ransomware suggests the rise of AI-tools being used by hackers is making life harder for defendersINFOSECURITY-MAGAZINE.COM
23 JulSwiss rail manufacturer Stadler refuses to pay $12.3 million ransom after cyberattackCybercriminal group Everest is demanding 10 million Swiss francs ($12.3 million) from Swiss rail vehicle manufacturer Stadler after breaching a data exchange platform shared with one of its suppliers through compromised credentials. Stadler operates 16 production and component pl…HELPNETSECURITY.COM
23 JulNew msaRAT malware uses Chrome, Edge browsers to route C2 trafficThe Chaos ransomware gang is using a new backdoor dubbed msaRAT that hides command-and-control (C2) communication by routing it through the Chrome or Edge browsers. [...]BLEEPINGCOMPUTER.COM
23 JulPyPI hardens package security with new upload restrictionsThe Python Package Index (PyPI) now rejects uploads of new files to releases older than 14 days to prevent attackers from poisoning long-stable releases if a project’s publishing tokens or release workflows are compromised. “This change will protect Python users and reduce …HELPNETSECURITY.COM
23 JulChaos ransomware's msaRAT: Living off the browser to build a covert C2 channelThe Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.TALOSINTELLIGENCE.COM
23 JulUpbound Group Says Data Breach Led to $13 Million in Fraudulent Contract LossesHackers recently obtained non-sensitive customer information and other documents from the company. The post Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses appeared first on SecurityWeek .SECURITYWEEK.COM
23 JulChaos ransomware msaRAT hides its C2 channel inside a legitimate browser processCisco Talos has identified a Rust-based remote access trojan it attributes to the Chaos ransomware group, named msaRAT after four of the binding names left in the binary. The tool starts its own instance of Chrome or Edge on the victim machine and controls it through Chrome DevTo…HELPNETSECURITY.COM
23 JulAttackers Weaponize GitHub Actions Runners to Target cPanel and WHM ServersCybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager (WHM) instances. The activity involves malicious Packagist development versions…THEHACKERNEWS.COM
23 JulWhen the "Autonomous Attacker" Is Your Own AI Model, (Thu, Jul 23rd)Two disclosures, five days apart, described the same intrusion from opposite ends — one from the victim, one from the party that turned out to be responsible — and together they make one of the more instructive incidents of th…ISC.SANS.EDU
23 JulMajor Australian energy supplier confirms customer data compromisedOrigin Energy said it was working to figure out how many Australians were affected by a recent data breach.THERECORD.MEDIA
23 JulChaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and EdgeThe Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor. The implant never opens an outbound connection of its own. …THEHACKERNEWS.COM
23 JulAustralian energy provider Origin says data breach exposes client dataOrigin Energy has confirmed that an unauthorized party accessed and subsequently leaked customer data online, exposing sensitive personally identifiable information (PII), among others. [...]BLEEPINGCOMPUTER.COM
22 JulRisky Business #845 -- OpenAI's Skynet momentOn this week’s show special guest co-host Chris Krebs joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover: Oopsie daisy! OpenAI agents went rogue and hacked Hugging Face US and China trade AI model ban threats Iran has been using SS7 queries t…RISKY.BIZ
22 JulOpenAI says its AI models hacked Hugging Face during testingOpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment. [...]BLEEPINGCOMPUTER.COM
22 JulOpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat BenchmarkOpenAI on Tuesday said a combination of its artificial intelligence (AI) models, including GPT-5.6 Sol and an "even more capable pre-release model," was behind the security incident that targeted Hugging Face's production infrastructure last week. The AI company said the models w…THEHACKERNEWS.COM
22 JulChick-fil-A discloses data breach after credential stuffing attacksAmerican fast food restaurant chain Chick-fil-A is notifying customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks. [...]BLEEPINGCOMPUTER.COM
22 JulRansomware Group Threatening to Leak Data Stolen From Coca-Cola’s FairlifeThe Anubis ransomware group claims to have stolen 1 TB of confidential data from the Coca-Cola subsidiary. The post Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulOpenAI confirms its AI agent autonomously breached Hugging FaceOpenAI has revealed that an autonomous AI agent powered by GPT-5.6 Sol and a more capable unreleased model escaped its intended testing environment, gained internet access, and compromised parts of Hugging Face's production infrastructure while attempting to obtain benchmark answ…CYBERINSIDER.COM
22 JulPaidwork breach exposes data of 23 million users: Check if you&#8217;re affectedA reported breach at microtask platform Paidwork exposed personal and financial data of more than 23 million users. Here's how to check if you're affected.MALWAREBYTES.COM
22 JulOpenAI models behind breach of Hugging Face systems, companies sayOpenAI announced that its models were behind a breach of the AI platform Hugging Face, which had earlier detected an attack carried out by "by an autonomous AI agent."THERECORD.MEDIA
22 JulSuno, Paidwork Data Breaches Affect Tens of Millions of AccountsHackers leaked names, email addresses, phone numbers, passwords, and financial information stolen from the two platforms. The post Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulFlaw in Adobe Extension With 300M Installs Enabled WhatsApp Data TheftAn attacker only needed to convince the targeted user to visit a malicious website to exfiltrate WhatsApp messages and contacts. The post Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulJapanese food logistics giant recovers as extortion group claims cyberattackNichirei Logistics Group said warehouse operations and frozen food shipments are returning to normal. A cybercrime gang said it caused the disruption.THERECORD.MEDIA
22 JulOpenAI models escaped containment and hacked a major AI application libraryThe attack is the first known instance of frontier models autonomously breaking out of a testing environment and into another company’s servers.CYBERSECURITYDIVE.COM
22 JulHow enterprise GenAI can amplify ransomware risk — and how to contain itEnterprise AI can accelerate ransomware attacks when AI assistants and agents inherit excessive permissions or compromised identities. Acronis explains how identity controls, governance, and least-privilege access help reduce AI-enabled ransomware risk while supporting secure AI …BLEEPINGCOMPUTER.COM
22 JulNew Kimsuky campaign compromised South Korean software vendorsA North Korean advanced persistent threat (APT) group recently targeted vendors of collaborative-work software, South Korean researchers said.THERECORD.MEDIA
22 JulSwiss rail giant Stadler rejects $12.3M ransom demand after cyberattackSwiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. [...]BLEEPINGCOMPUTER.COM
22 JulReal world incident response: Microsoft and AXA XL strengthen cyber resilienceOur collaboration with AXA XL brings Microsoft Incident Response services directly to cyber insurance policyholders, helping organizations coordinate technical, business, and insurance decisions. The post Real world incident response: Microsoft and AXA XL strengthen cyber resilie…MICROSOFT.COM
21 JulPR3TACK preemptive framework maps threats before attackers use themDefensive frameworks in cybersecurity record what attackers have already done. Analysts study a breach, document the method, and build detections around confirmed activity. This cycle leaves a gap between the moment an attacker invents a technique and the moment defenders learn t…HELPNETSECURITY.COM
21 JulThe air gap is a myth and other OT security truthsBenjamin Bachmann, Director Group Information Security at Bilfinger, speaks with Help Net Security about defending industrial plants. He explains why attackers want to control operations instead of stealing data, and why the air gap is mostly a myth. Bachmann covers how containme…HELPNETSECURITY.COM
21 JulData breach at AI music service Suno exposed 55 million accountsAI music generation platform Suno suffered a data breach that exposed the personal information of more than 55 million users, according to Have I Been Pwned (HIBP). The incident exposed phone numbers and tens of thousands of Stripe purchase records containing customer names, phys…CYBERINSIDER.COM
21 JulUkraine warns fake CAPTCHAs are being used to make you hack yourselfUkraine's computer emergency response team, CERT-UA, has warned that the Kremlin-backed Sandworm hacking group is leveraging fake CAPTCHA checks on compromised websites that persuade users to run malicious code. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
21 JulA Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It NowDealerships installed alarms in millions of vehicles—and left them in even if the buyer didn’t want them. Now researchers warn they can be hacked to unlock, track, and disable cars.WIRED.COM
21 JulClover Health Investments Discloses Data BreachUsing social engineering, hackers compromised employee accounts with access to personal and health information. The post Clover Health Investments Discloses Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulNew HollowGraph Malware Abuses Microsoft 365 Calendar for C&C CommunicationPart of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop. The post New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulKenya probes hack of president's website after bitcoin ransom demandThe website was hacked on Saturday, when its homepage was replaced with a message displaying a cryptocurrency wallet address and threatening to publish unspecified information about President William Ruto unless the ransom was paid.THERECORD.MEDIA
21 JulA New Ransomware Threat Actor Emerges Every Week, Warns ReportAnalysis by Black Kite warns that ransomware ecosystem is becoming bigger and more fragmentedINFOSECURITY-MAGAZINE.COM
21 JulClosing the Identity Gaps in Critical Infrastructure SecurityCritical infrastructure attacks often begin with stolen credentials, compromised devices, or trusted accounts. Specops Software explains why Zero Trust should verify both user identities and device trust before granting access to critical systems. [...]BLEEPINGCOMPUTER.COM
21 JulJadePuffer returns with ransomware built to target AI models and infrastructureJadePuffer, the threat actor behind the recently documented extortion operation executed end-to-end by an AI agent, is now attempting to leverage ENCFORGE, novel ransomware created to target AI and machine learning (ML) infrastructure. The extortion contact embedded in the ransom…HELPNETSECURITY.COM
21 JulAI music generator Suno breach affects 55M users, per Have I Been PwnedA hacker took names, phone numbers, and physical addresses of millions of customers who used AI music generator Suno.TECHCRUNCH.COM
21 JulRansomware victims fail to fix flaws that exposed themMany organizations still aren’t securing their email or patching vulnerabilities after recovering from attacks, a new report found.CYBERSECURITYDIVE.COM
21 JulSpain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hackThe Agencia Española de Protección de Datos (AEPD) announced the fine on Friday, saying in its decision that more than 2,600 Spaniards were impacted by a breach affecting 6.9 million people worldwide.THERECORD.MEDIA
21 JulAnubis ransomware claims Coca-Cola Fairlife attack, threatens data leakThe Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola's Fairlife dairy subsidiary, threatening to publish allegedly stolen corporate data unless the company pays a ransom. [...]BLEEPINGCOMPUTER.COM
21 JulThe defense against the AI arts.Trump's latest AI leader resigns. The Army burns through its AI tokens. Scammers impersonate IC3 personnel.HollowGraph malware uses a compromised Microsoft 365 calendar for C2. Qilin ransomware targets a critical Palo Alto Networks flaw. A North Korean campaign targets Web3 and c…THECYBERWIRE.COM
21 JulRansomware Is Accelerating, But It's Not Because of AIResearchers pointed to fragmentation of the ransomware ecosystem, the emergence of new attackers, and expansion of attacks on less defended organizations.DARKREADING.COM
21 JulOpenAI says model test was behind Hugging Face hackAt the time, Hugging Face said it wasn’t clear which LLM was used in the attack. OpenAI confirmed it was one of their models being tested for “maximal” cyber capabilities. The post OpenAI says model test was behind Hugging Face hack appeared first on CyberScoop .CYBERSCOOP.COM
20 JulMore alerts are making your team slower, and an outcome-based SOC fixes thatIn this Help Net Security video, Thom Langford, EMEA CTO, Rapid7, explains why piling on more security alerts makes a SOC slower to respond. Attackers log in with stolen credentials and use trusted tools like PowerShell instead of custom malware. He shares a case where attackers …HELPNETSECURITY.COM
20 JulHugging Face Hacked in Autonomous AI AttackTargeting production infrastructure, the attack compromised internal datasets and service credentials. The post Hugging Face Hacked in Autonomous AI Attack appeared first on SecurityWeek .SECURITYWEEK.COM
20 JulErnst & Young Data Breach Affects Personal, Financial InformationHackers stole names, addresses, Social Security numbers, credit/debit card numbers, and other information from a third-party management platform. The post Ernst & Young Data Breach Affects Personal, Financial Information appeared first on SecurityWeek .SECURITYWEEK.COM
20 JulHugging Face confirms breach affected internal datasets and credentials, urges users to take actionHugging Face is urging users to rotate any access tokens stored on the platform and review account activity.TECHCRUNCH.COM
20 JulSoftware provider to more than 2,000 US hospitals says hackers stole employee and customer dataCraneware, which is headquartered in Edinburgh and listed on London's AIM market, told investors it detected unauthorized access to a “subset” of its data environment and has since brought in outside forensic investigators.THERECORD.MEDIA
20 JulJadePuffer Returns With Ransomware Designed to Wipe AI ModelsJadePuffer follow-up campaign deployed ENCFORGE locker built to destroy AI model artifactsINFOSECURITY-MAGAZINE.COM
20 JulHackers stole ‘significant’ amount of data from tech firm relied on by thousands of US hospitals and pharmaciesEdinburgh-based tech firm Craneware said customer data was stolen during a cyberattack. The company makes software that thousands of U.S. hospitals, pharmacies, and clinics rely on for billing patients, potentially exposing health data.TECHCRUNCH.COM
20 JulHealthcare giant Abbott probes two cyber incidents amid extortion claimsExtortion groups ShinyHunters and ShadowByt3$ claim they stole vast amounts of patient data. Those allegations have not been verified.MALWAREBYTES.COM
20 JulRomania races to restore land registry after cyberattack disrupts property marketRomania's land registry agency is still recovering from a cyberattack it called "the most serious technical incident in the institution's history."THERECORD.MEDIA
20 JulPaidwork breach exposes sensitive data of 23 million userData belonging to more than 23 million users has been exposed following a breach at Paidwork, a platform that pays people for completing online microtasks. Paidwork markets itself as a way to earn money through simple tasks like watching ads, testing apps, and completing surveys,…HELPNETSECURITY.COM
20 JulHollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named the malware HollowGraph, say…THEHACKERNEWS.COM
20 JulHugging Face discloses an autonomous agentic breach.Abbott Laboratories investigates another alleged breach. FBI arrests a Florida man accused of spreading malware through video games.THECYBERWIRE.COM
20 JulHackers steal customer data from major hospital software vendorThe breach is another reminder of how vulnerable the healthcare industry is to supply-chain attacks.CYBERSECURITYDIVE.COM
20 JulNew HollowGraph malware uses Microsoft Graph for stealthy C2 commsA malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. [...]BLEEPINGCOMPUTER.COM
20 JulSuno - 55,282,226 breached accountsIn November 2025, AI music generation tool Suno suffered a data breach that later came to light in July the following year . The data contained over 55M unique email addresses. Phone numbers were also present where they had been used as the sign-up method. Although representing a…HAVEIBEENPWNED.COM
20 JulJadePuffer agentic attacks now target AI model data with ransomwareThe JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints. [...]BLEEPINGCOMPUTER.COM
19 JulSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 106Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter CrashStealer: C++ macOS infostealer posing as crash reporter Lucide Proxy: Turning Student Web Proxies into DDoS Bots …SECURITYAFFAIRS.COM
19 JulPaidwork - 23,272,765 breached accountsIn March 2026, hackers claimed they had obtained data from the gig economy platform Paidwork which they then listed for sale . Almost 11GB of data allegedly obtained from the platform was subsequently posted publicly in July and contained over 23M unique email addresses. The brea…HAVEIBEENPWNED.COM
18 JulWhen trusted sites turn.Lauren Fievisohn⁠, Ph.D, Senior Threat Researcher from ⁠Silent Push⁠, is sharing their work on "Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites." Silent Push researchers have identified a newly named threat act…THECYBERWIRE.COM
18 JulYour Period Tracker Is (Probably) Spying on YouPlus: Russian cyberspies turn to infrastructure hacking, DHS repeatedly fails to realize it’d been hacked, a breach exposes an AI music generator’s scraping ways, and more.WIRED.COM
18 JulDaxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s NetworkResearchers found China’s Daxin rootkit and a new Stupig backdoor on a Taiwan firm’s network, suggesting a stealthy intrusion dating back to 2013. Symantec’s Threat Hunter Team found Daxin running on a compromised host at a Taiwan-based subsidiary of a multinati…SECURITYAFFAIRS.COM
17 JulCoca-Cola Suspends US Fairlife Production Due to Ransomware AttackThe company says the incident has not affected product quality and safety, nor Fairlife’s Canada production. The post Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack appeared first on SecurityWeek .SECURITYWEEK.COM
17 JulThe Gentlemen Overtakes Qilin as Most Prolific Ransomware ThreatAnalysis of ransomware incidents by ReliaQuest indicates a shift in the ransomware landscapeINFOSECURITY-MAGAZINE.COM
17 JulCyberattack Disrupts Operations of Japanese Frozen Food Giant NichireiThe company disconnected its systems on July 13 and is starting to gradually restore operations. The post Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei appeared first on SecurityWeek .SECURITYWEEK.COM
17 JulNew GoSerpent Malware Targets Southeast Asian Governments and Diplomats for EspionageCybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting entities in Southeast Asia since late 2025 with a focus on long-term access and intelligence gathering. Russian cybersecurity company K…THEHACKERNEWS.COM
17 JulEY says client tax data exposed in third-party IT software breachErnst & Young (EY) is notifying affected individuals that personal and financial information was exposed after attackers breached a third-party IT service management platform used by the firm's tax practice. The professional services giant says the incident resulted in unaut…CYBERINSIDER.COM
17 JulArmenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong ManArmenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov. His wife, Maria Yurova, told REN TV that border officers pulled him out of the departure hall at Y…THEHACKERNEWS.COM
17 JulShark vacuum flaw exposes cameras, home maps and Wi-Fi passwordsOne compromised Shark robot vacuum could unlock remote access to many others.MALWAREBYTES.COM
17 JulSpirals ransomware locks down victim systems in under 24 hoursA previously unknown ransomware strain called Spirals was used last month in an attack against an IT services company in South Asia, where attackers went from initial access to data theft and encrypting the network in less than 24 hours, according to Symantec’s Threat Hunte…HELPNETSECURITY.COM
17 JulDairy company Fairlife suspends production in US after cyber incidentFairlife’s U.S. operation includes plants in Michigan, New York and Arizona, and the company's retail sales passed $1 billion in 2022.THERECORD.MEDIA
17 JulWhen Patching Is Already Too LateThe discussion makes a bold claim: many organizations no longer have enough time to patch before attackers compromise vulnerable systems. Instead of treating prevention as the primary strategy, the emphasis shifts toward detecting intrusions quickly and responding before attacker…YOUTUBE.COM
17 JulGovernment Agencies Falling Victim to Ransomware Daily, Warns StudyGovernment organizations are targeted by attackers who know agencies cannot afford disruption to public servicesINFOSECURITY-MAGAZINE.COM
17 Jul23andMe Faces New Security Mandates in $18m Data Breach Settlement23andMe has agreed to an $18m settlement with 42 US attorneys general over its 2023 data breach, including enhanced data protection requirementsINFOSECURITY-MAGAZINE.COM
17 JulErnst & Young discloses data breach after support system hackErnst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel. [...]BLEEPINGCOMPUTER.COM
17 JulAbbott discloses cyberattack on cancer diagnostics businessThe cyberattack follows Abbott’s recent $21 billion purchase of Exact Sciences. Abbott did not disclose what kind of information was accessed.CYBERSECURITYDIVE.COM
17 JulGoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate TheftCybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, a…THEHACKERNEWS.COM
17 JulA cyberattack hit Nichirei, one of Japan’s largest food companiesA cyberattack hit one of Japan’s largest food companies, Nichirei, disrupting logistics and shipments. The company is gradually restoring operations. Nichirei is one of Japan’s largest food companies, best known for its frozen food business. Founded in 1942 and headqu…SECURITYAFFAIRS.COM
17 JulAbbott Laboratories probes two cyber incidents amid extortion claimsAbbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and…BLEEPINGCOMPUTER.COM
17 JulAI Becomes The Supply ChainAI tools are increasingly being used to recommend code, libraries, and scripts. The clip explores the possibility that a compromised AI system could influence those recommendations. Software supply chains already depend on trust between developers, tools, and dependencies. Adding…YOUTUBE.COM
16 JulUnpacking the AsyncAPI npm supply chain compromise and import-time payload deliveryThreat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This analysis breaks down the attack chain, payload delivery, and recommended defenses. The post Unpacking the AsyncAPI npm supply chain compromise and import-tim…MICROSOFT.COM
16 JulRansom demands are down, email is the top way attackers get inAn employee opens an email that looks like any other, clicks a link, and gives up a password without noticing. A stolen login opens a door deeper in the network. Files stop opening a few days later. That chain now sits at the front of most ransomware cases. Malicious email and ph…HELPNETSECURITY.COM
16 JulPolice Disrupt a €140M Cyber Fraud Ring in SpainIberian hackers carried out a variety of cyberattacks and laundered the winnings through complex financial networks.DARKREADING.COM
16 JulClaude Code and DeepSeek Powered Chinese Cyber Espionage CampaignChinese actors used Claude Code and DeepSeek to automate attacks that breached government systems and targeted financial firms. Hunt.io researchers stumbled onto an active intrusion campaign in June 2026 while pivoting on known TencShell command-and-control infrastructure. A sing…SECURITYAFFAIRS.COM
16 JulNew Spirals ransomware encrypts victim network in under 24 hoursA new ransomware actor called Spirals completed a corporate intrusion, from initial access to data theft and encryption, in less than 24 hours. [...]BLEEPINGCOMPUTER.COM
16 JulGoSerpent: a persistent threat evolves with sophisticated data collection and exfiltrationTwo-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia.SECURELIST.COM
16 JulScattered Spider hackers sentenced to 5.5 years over £29 million Transport for London hackTwo leading members of the Scattered Spider cybercrime collective have been sentenced to more than five years in prison for carrying out the 2024 cyberattack against Transport for London (TfL).THERECORD.MEDIA
16 Jul23andMe to pay $18 million in new genetics data breach settlementGenetic testing company 23andMe has agreed to pay $18 million to settle claims from a coalition of 43 attorneys general that it failed to protect customers' genetic data. [...]BLEEPINGCOMPUTER.COM
16 JulTwo Scattered Spider Hackers Sentenced to Jail in UKThalha Jubair and Owen Flowers were prosecuted over a 2024 cyberattack targeting Transport for London (TfL). The post Two Scattered Spider Hackers Sentenced to Jail in UK appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulScattered Spider members jailed over Transport for London hack that cost £29 millionTwo members of the notorious “Scattered Spider” hacking collective have been sentenced to five years and six months in prison each for a cyberattack on Transport for London (TfL) that disrupted services for thousands of commuters and cost the transport authority an es…HELPNETSECURITY.COM
16 JulThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More StoriesA lot of this week’s trouble starts with something that looks close enough. A familiar repo. A useful installer. A harmless sync setting. Then the handoff goes bad, the box starts talking to someone else, and the damage moves faster than the explanation. Old bugs are back, weak d…THEHACKERNEWS.COM
16 Jul23andMe agrees to a $18 million settlement over 2023 data breachA bipartisan coalition of 43 attorneys general has secured an $18 million settlement with genetic testing company 23andMe over its failure to adequately protect customer data before the company's 2023 breach. The agreement also requires new cybersecurity and governance measures f…CYBERINSIDER.COM
16 JulRussian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrimeOfficials accused three Russian nationals, Media Land and ML.Cloud of supporting cyberattacks spanning 21 U.S. states and other countries, resulting in losses surpassing $62 million. The post Russian trio indicted for allegedly running bulletproof hosting providers that spurred c…CYBERSCOOP.COM
16 JulTwo Scattered Spider Members Sentenced to Prison Over £29 Million TfL CyberattackTwo members of the Scattered Spider cybercrime group received jail sentences in the UK for the 2024 cyberattack on Transport for London. A UK court sentenced two Scattered Spider members, Thalha Jubair (20) and Owen Flowers (18), for their role in the 2024 cyberattack on Transpor…SECURITYAFFAIRS.COM
16 JulCoca-Cola suspended production at its Fairlife dairy after a ransomware attackCoca Cola said dairy production at its Fairlife unit will "remain suspended" in the United States following a hack.TECHCRUNCH.COM
16 JulAnubis ransomware: what you need to knowThe Anubis ransomware-as-a-service (RaaS) operation has hit some healthcare organisations hard - but they are not the only ones at risk. Read more in my article on the Fortra blog.FORTRA.COM
16 JulAI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response ReportExplore Unit 42's perspectives on AI's impact on cybersecurity, including key updates since the 2026 Incident Response Report. The post AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
15 JulWeekly Update 512: IoT Lockout FailPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite "Build a smart home", they said. "It'll make life so much better", they said. Well, life wasn't very bloo…TROYHUNT.COM
15 JulBehind the Book: Threat-Driven Software DevelopmentIn this episode of the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠⁠Sherrod DeGrippo⁠ is joined by co-authors Michael Howard, Lee Holmes, and Shawn Hernan for a discussion on their new book, ⁠Threat-Driven Software Development: Defending Online Services from Modern Threat Acto…THECYBERWIRE.COM
15 JulUS charges alleged operators of Russian bulletproof hosting serviceU.S. federal prosecutors have unsealed charges against three Russian nationals, accusing them of providing bulletproof hosting (BPH) services to ransomware gangs that caused over $62 million in damages to victims worldwide. [...]BLEEPINGCOMPUTER.COM
15 JulFluke - 821,100 breached accountsIn July 2026, electronic test and measurement equipment company Fluke was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published more than 100GB of data allegedly taken from the company. The corpus contained largely corporate contact inform…HAVEIBEENPWNED.COM
15 JulOkoBot: new sophisticated malware framework targets cryptocurrency usersKaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users. This complex framework employs TookPS, exfiltrates seed phrases, monitors Chromium-based browsers, and installs various malware strains, including the Rilide stealer.SECURELIST.COM
15 JulGoose Creek data breach exposes 6.6 million customer recordsGoose Creek Candle Company has suffered a data breach exposing the personal information of 6.6 million customers, according to a new entry published by Have I Been Pwned (HIBP). The breach was added to the service earlier today after HIBP received a copy of the dataset from the p…CYBERINSIDER.COM
15 JulUS charges Russian ‘bulletproof’ web hosts over cyberattacks that netted $62M from cybercrime victimsThe 2024 indictment, now unsealed, accuses three Russians and two web hosts of aiding hackers and profiting from cybercrime.TECHCRUNCH.COM
15 Jul23andMe reaches $18 million settlement with states for massive breachA coalition of 42 state attorneys general reached an $18 million settlement with 23andMe for cybersecurity failings that led to a data breach.THERECORD.MEDIA
14 JulYour vendor’s vendor might be the real breach riskIn this Help Net Security video, Chris Boehm, Field CTO, Zero Networks, breaks down how a vendor breach can become your breach. He explains that attackers now target the subcontractors behind your trusted vendors. A compromised credential at a company you have never heard of can …HELPNETSECURITY.COM
14 JulThe ransomware negotiator who was working for the other sideWhen a company falls victim to a ransomware attack, it is not uncommon for it to turn to experts for help. Specialist ransomware negotiation firms handle communications with criminal gangs on a victim's behalf. What victims don't expect is that their trusted negotiator might be s…BITDEFENDER.COM
14 JulU.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware SupportThe U.S. Treasury Department's Office of Foreign Assets Control (OFAC) has designated two individuals and a VPN service provider for enabling ransomware actors' and other cybercriminals' malicious activities, including ransomware attacks against Americans. The VPN, named First VP…THEHACKERNEWS.COM
14 JulCrashStealer: New macOS Infostealer Uses Signed Apps to Evade GatekeeperNew macOS infostealer CrashStealer uses a signed app to bypass Gatekeeper, steals credentials and wallets, then AES-encrypts stolen data. Jamf Threat Labs first spotted CrashStealer in early May 2026 as a suspicious macOS sample uploaded to VirusTotal. By early July, in-the-wild …SECURITYAFFAIRS.COM
14 JulPhishing for dummies: Forg365 lowers barrier to M365 account takeoversA newly documented phishing-as-a-service platform distributed through Telegram is lowering the technical barrier to Microsoft 365 account takeovers by giving less-skilled attackers automated tools to evade some authentication controls and retain access after compromise. The platf…CSOONLINE.COM
14 JulLidl Notifies Customers of Third-Party Data BreachSupermarket giant Lidl has revealed details of a supplier breach impacting customer dataINFOSECURITY-MAGAZINE.COM
14 JulUS sanctions VPN, malware providers for enabling ransomware attacksThe U.S. Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned two individuals and one entity for enabling ransomware attacks against U.S. organizations. [...]BLEEPINGCOMPUTER.COM
14 JulUS, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure RoutersMultiple state-sponsored APTs are compromising poorly secured devices across critical infrastructure sector networks. The post US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulAttacker Used AI to Build Custom PowerShell Recon MalwareHuntress found an AI-generated PowerShell script used for AD reconnaissance, showing attackers are using AI to create custom, evasive tools. During an incident response investigation on June 3, 2026, Huntress analyst Jevon Ang recovered a PowerShell script from a compromised Wind…SECURITYAFFAIRS.COM
14 JulPentagon suspends CMMC Phase II requirements.US Treasury Department sanctions VPN provider that allegedly assisted criminals. Lidl discloses breach affecting customer information.THECYBERWIRE.COM
14 JulHealthcare sector faces persistent supply-chain security, identity management challengesA new report says doctors and nurses should train for cyberattacks the way firefighters train for major blazes — even if they expect them to be rare.CYBERSECURITYDIVE.COM
14 JulCanada’s Electronic Spy Agency Conducted Cyberattacks on Criminals Brokering Fentanyl Ingredients, Report SaysResearch fellow Bill Robinson speaks with The Globe and Mail about CSE spending. The post Canada’s Electronic Spy Agency Conducted Cyberattacks on Criminals Brokering Fentanyl Ingredients, Report Says appeared first on The Citizen Lab .CITIZENLAB.CA
14 JulCyberattack at KFC Japan impacting online orders and deliveriesKFC Japan has announced that a cyberattack affecting one of its third-party logistics providers is disrupting food deliveries to restaurants nationwide, raising the possibility of product shortages, reduced operating hours, and temporary store closures. The company has suspended …CYBERINSIDER.COM
14 JulFinland issues wanted notice for hacker behind massive psychotherapy data breachThe defendant's lawyer told Finnish media that he does not know where his client is but believes Kivimäki is outside Finland.THERECORD.MEDIA
14 JulSynopsys Finds No Evidence of Data Breach Amid Bosch Hack ClaimsThe D1R cybercrime group claimed to have stolen valuable data from Synopsys and Bosch, threatening to leak it unless a ransom is paid. The post Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulU.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware LossesU.S. sanctions hit VPN provider 1VPNS and a cryptor seller for enabling ransomware gangs behind billions in losses to critical infrastructure. The U.S. Treasury’s Office of Foreign Assets Control sanctioned two individuals and one entity on July 13 for supplying tools and i…SECURITYAFFAIRS.COM
14 JulWhen the Negotiator Helps HackersA ransomware negotiator was sentenced to federal prison after prosecutors said he secretly worked with the BlackCat ransomware group while negotiating on behalf of victims. According to court filings, he shared insurance limits, negotiating positions, and internal settlement thre…YOUTUBE.COM
13 JulCenters Laboratory Data Breach Affects 540,000 IndividualsThe WorldLeaks extortion group claimed to have stolen 720 GB of data from the healthcare testing and laboratory services provider. The post Centers Laboratory Data Breach Affects 540,000 Individuals appeared first on SecurityWeek .SECURITYWEEK.COM
13 JulHacker Extradited from Ukraine Pleads Guilty to Ryuk Ransomware ChargesAn Armenian man has pleaded guilty to his role in the infamous Ryuk ransomware operationINFOSECURITY-MAGAZINE.COM
13 JulFastNetMon eliminates third-party bgp lookups with NetomicsFastNetMon is introducing Netomics, a self-hosted BGP routing intelligence platform that combines live routing data, registry information, RPKI validation, routing history and AI-assisted querying into a single application. Built for internet service providers (ISPs), cloud provi…HELPNETSECURITY.COM
13 JulDutch Nationals Suspected in Odido Hack That Exposed Six Million CustomersDutch police suspect local hackers behind the Odido breach that exposed 6M customers after a phishing attack and seek public help identifying them. Dutch police have identified strong indications that Dutch nationals were involved in the February 2026 cyberattack on telecom provi…SECURITYAFFAIRS.COM
13 JulEU sanctions Russian GRU military hackers over cyberattacksThe European Union and the United Kingdom jointly sanctioned dozens of Russian individuals and entities and accused Russia of coordinating a network of hacking groups responsible for attacks across Europe. [...]BLEEPINGCOMPUTER.COM
13 JulBreach at the Beach: Play the Ultimate Entra ID CTFLearn how attackers abuse Entra ID through a free hands-on Capture the Flag. Varonis created the Breach at the Beach CTF to teach defenders how to investigate Entra ID attack techniques using realistic scenarios. [...]BLEEPINGCOMPUTER.COM
13 JulLidl discloses online shop breach after service provider hackGerman discount supermarket chain Lidl notified customers in Germany, Belgium, and the Netherlands that attackers stole their personal information in a breach at a service provider. [...]BLEEPINGCOMPUTER.COM
13 Jul⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and MoreSomewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That's supposed to be the good news. The catch is that the attackers have the same tools, pointed the other way, and they don't file tickets. That's the shape of this week. Trusted co…THEHACKERNEWS.COM
13 JulEurope strikes out against Russia’s Turla over espionage, ‘destructive attacks’The EU, its members and the U.K. took action against Russian government officials and others while attributing the winter cyberattacks against Poland’s energy grid to the FSB. The post Europe strikes out against Russia’s Turla over espionage, ‘destructive attacks’ appeared first …CYBERSCOOP.COM
13 JulHackers breach Lidl’s IT service provider, steal customer dataGerman discount supermarket chain Lidl has notified customers in Germany, Belgium, and the Netherlands that customer data was stolen after attackers breached one of its IT service providers. In notices published on its support websites in Belgium and the Netherlands, Lidl said it…HELPNETSECURITY.COM
13 JulCrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper ChecksCybersecurity researchers have flagged a new macOS information stealer called CrashStealer that's capable of harvesting sensitive data from compromised systems. Unlike other information stealers that are built on AppleScript droppers or Objective-C-based wrappers, CrashStealer is…THEHACKERNEWS.COM
13 JulRussian celebrity journalist Ksenia Sobchak says hackers accessed Telegram channels via email breachFollowing the breach of several of her Telegram channels, controversial Russian journalist Ksenia Sobchak claimed published screenshots of her correspondence with political figures were fake.THERECORD.MEDIA
13 JulState of the router.The U.S. and its allies warn of Russian cyber threats targeting critical infrastructure as Europe rolls out new sanctions. Apple sues OpenAI over alleged trade secret theft. Progress investigates a potential ShareFile security incident, Zimbra patches a critical flaw, and researc…THECYBERWIRE.COM
13 JulJapan's largest taxi operator shuts systems after cyberattackJapan's largest taxi operator, Nihon Kotsu, announced that its systems were compromised in a cyberattack, forcing the company to shut down part of its infrastructure. [...]BLEEPINGCOMPUTER.COM
13 JulWeak Security Continues to Fuel Russian CyberattacksIn a first, the UK and the EU jointly impose sanctions on Russian individuals and entities for cyberattacks and disinformation campaigns in the region.DARKREADING.COM
12 JulRyuk Ransomware Member Pleads Guilty Over Attacks on U.S. OrganizationsAn alleged Ryuk ransomware member pleaded guilty in the U.S. for helping deploy attacks on American companies and faces up to 15 years in prison. Armenian national Karen Serobovich Vardanyan (34) pleaded guilty in the U.S. for his role in Ryuk ransomware attacks targeting America…SECURITYAFFAIRS.COM
11 JulConti-versal opinions.Today we are joined by ⁠Geoff White⁠, host of Cyber Hack and ⁠BBC⁠ journalist, taking a deep dive into the Conti ransomware gang. Geoff explores an in-depth investigation into the notorious Conti ransomware gang, drawing from thousands of leaked internal messages to reveal how th…THECYBERWIRE.COM
11 JulGlendale Community College - 793,925 breached accountsIn June 2026, Glendale Community College was the target of a ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from Glendale was later published online and included almost 800k unique email addresses along with various other data fields, including names, add…HAVEIBEENPWNED.COM
11 JulCompromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During InstallVersion 8.14.0 of the jscrambler npm package shipped with a malicious preinstall hook that silently drops and runs a native infostealer during installation, one build each for Windows, macOS, and Linux. Published on July 11, 2026, it needs no import and no CLI…THEHACKERNEWS.COM
10 JulDormant GitHub Accounts Help Attackers Blend In While Mapping Corporate OrgsDatadog Security Labs is warning of "several overlapping campaigns" that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the GitHub API. "Operators rely on automated scraping tooling with custom or legitimate-sounding us…THEHACKERNEWS.COM
10 JulRisky Bulletin: NSA Tailored Access Operations is backThe NSA’s Tailored Access Operations team is back, India bans an app used to hack e-rickshaws, Accenture has another data breach, and a leak exposes a suspected Chinese cyber contractor. The Risky Bulletin newsletter and podcast will be on an editorial break until July 20.RISKY.BIZ
10 JulNHS Warns Staff Over Unauthorized Access to Patient DataNHS tells staff they could face prison for “inappropriate” access to patients’ medical recordsINFOSECURITY-MAGAZINE.COM
10 JulFormer ransomware negotiator gets 4 years for BlackCat attacksA former employee of cybersecurity incident response company DigitalMint was sentenced to 70 months in prison for targeting U.S. companies in BlackCat (ALPHV) ransomware attacks. [...]BLEEPINGCOMPUTER.COM
10 JulRansomware Negotiator Gets 70 Months in Prison for Aiding BlackCat AttacksA 41-year-old former ransomware negotiator has been sentenced to nearly six years (i.e., 70 months) in prison in the U.S. for their role in conspiring with the now-defunct BlackCat ransomware operators to extort multiple victims and working with two other cybersecurity profession…THEHACKERNEWS.COM
10 JulGigaWiper Combines Multiple Malware for System-Level SabotageThe backdoor’s destructive capabilities include a standalone wiper, ransomware encryption, and a multi-pass wiping command. The post GigaWiper Combines Multiple Malware for System-Level Sabotage appeared first on SecurityWeek .SECURITYWEEK.COM
10 JulGigaWiper Merges Three Malware Families Into One Destructive BackdoorMicrosoft uncovered GigaWiper, a modular Go backdoor combining three malware families with espionage, remote control, and destructive wiping features. In October 2025, Microsoft’s threat intelligence team identified destructive wiping activity inside compromised environment…SECURITYAFFAIRS.COM
10 JulFormer Ransomware Negotiator Sentenced to 70 Months in Prison for Secretly Helping BlackCat GangA former ransomware negotiator was sentenced to nearly six years for secretly helping BlackCat extort victims while betraying his clients. A U.S. court sentenced former ransomware negotiator Angelo Martino, 41, to 70 months in prison for conspiring with the BlackCat ransomware ga…SECURITYAFFAIRS.COM
10 JulThird US Security Expert Sentenced to Prison for Helping Ransomware GangAngelo Martino, a former ransomware negotiator, was sentenced to 70 months for helping the BlackCat/Alphv group. The post Third US Security Expert Sentenced to Prison for Helping Ransomware Gang appeared first on SecurityWeek .SECURITYWEEK.COM
10 JulRansomware Never Stopped: Over 9,000 Confirmed Attacks Since 2018Ransomware remains above 1,400 attacks yearly since 2023. Qilin leads in 2026, while the U.S. remains the main target. Ransomnews has independently confirmed 9,291 ransomware attacks worldwide between January 2018 and July 2026, tracking incidents only when verified through victi…SECURITYAFFAIRS.COM
10 JulFlorida ransomware negotiator convicted for helping ransomware gang extort US companiesA third ransomware negotiator has been jailed for helping a notorious ransomware group extort American victim companies into paying the hackers.TECHCRUNCH.COM
10 JulIn Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware OpsOther noteworthy stories that might have slipped under the radar: Abnormal AI sued by Anthropic, AssuranceAmerica data breach affects 7 million people, NSA brings back TAO. The post In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops app…SECURITYWEEK.COM
10 JulPolice suspects Dutch hackers were involved in Odido breachThe Dutch National Police (Politie) says it has found "strong indications" that Dutch hackers have been involved in a February breach at the telecommunications provider Odido. [...]BLEEPINGCOMPUTER.COM
10 JulCybercriminals Flock to Healthcare Businesses as Attacks SurgeWhile cyberattacks against hospitals and clinics grew modestly in the first half of 2026, attacks on service providers and other healthcare businesses more than doubled.DARKREADING.COM
10 JulInjective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm PackagesUnknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases. The compromised version, @injectivelabs/sdk-ts@1.20.21, …THEHACKERNEWS.COM
10 JulRyuk operator pleads guilty; Blackcat/AlphV conspirator gets nearly 6-year sentenceOne man accused of deploying Ryuk ransomware pleaded guilty Wednesday in an Oregon federal court to conspiracy and computer fraud, while another man received a 70-month federal prison sentence in a Florida court for helping the Blackcat/AlphV gang extort multiple victims.THERECORD.MEDIA
10 JulRyuk ransomware member pleads guilty in the US, faces 15 years in prisonA 34-year-old Armenian man has pleaded guilty to hacking U.S. companies and deploying the infamous Ryuk ransomware to encrypt their systems. [...]BLEEPINGCOMPUTER.COM
10 JulArmenian national pleads guilty to Ryuk ransomware attacksKaren Vardanyan faces up to 15 years in federal prison and agreed to pay nearly $1.2 million in restitution. The post Armenian national pleads guilty to Ryuk ransomware attacks appeared first on CyberScoop .CYBERSCOOP.COM
10 JulNo Manners Here: The Ruthless Rise of The Gentlemen RansomwareUnit 42 explores The Gentlemen ransomware operations, revealing the affiliate model driving its rapid growth. Learn more here. The post No Manners Here: The Ruthless Rise of The Gentlemen Ransomware appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
9 Jul'GodDamn' Ransomware Uses BYOVD to Smite US CompaniesMicrosoft co-signed a malicious kernel driver, and now it's being used to kill security software in ransomware attacks.DARKREADING.COM
9 JulThe Language of AI Could Change How Humans SpeakLast week, national security agencies from the Five Eyes—that’s the rich, English-language-speaking countries club—jointly released a statement warning of the increasing cyber risks of AI models: in particular, their ability to autonomously hack into systems and…SCHNEIER.COM
9 JulMount Royal University Confirms Data Stolen in Ransomware AttackHackers accessed the institution’s internal network and deleted two drives containing employee, student, and university data. The post Mount Royal University Confirms Data Stolen in Ransomware Attack appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulGodDamn Ransomware Uses PoisonX Driver to Disable Endpoint DefensesCybersecurity researchers have flagged a new ransomware family called GodDamn that employs the PoisonX kernel driver to neutralize security software as part of its defense evasion strategy. According to a new report published by the Threat Hunter Team from Symantec, the ransomwar…THEHACKERNEWS.COM
9 JulAI Gateways Offer Attackers the Keys to the KingdomA cryptomining incident highlights how AI gateways can provide access to AI models, cloud infrastructure, and identity and access management (IAM) data.DARKREADING.COM
9 JulAssuranceAmerica Breach Exposes 7 Million Driver’s Licenses After Employee Account HackAssuranceAmerica confirmed a breach exposing nearly 7 million driver’s licenses after hackers compromised an employee account and stole customer data. U.S. auto insurer AssuranceAmerica has confirmed a data breach affecting nearly 7 million people, making it the largest kno…SECURITYAFFAIRS.COM
9 JulLatvian forestry company still restoring systems weeks after ransomware attackA foreign, financially motivated group was responsible for a cyberattack on state-owned forestry company Latvijas Valsts Mezi (LVM), officials said.THERECORD.MEDIA
9 JulData breach hits car insurance providerHackers gained access to more than 6.9 million records at AssuranceAmerica by targeting a company employee.CYBERSECURITYDIVE.COM
9 JulRansomware ecosystem grows, but ‘four-headed monster’ dominatesAI is helping hackers, a new report finds, but mostly by automating very human behaviors.CYBERSECURITYDIVE.COM
9 JulGigaWiper: Anatomy of a destructive backdoor assembled from multiple malwareGigaWiper is a destructive backdoor that combines multiple wiping and ransomware-like capabilities into a single operational platform. This blog analyzes how the malware incorporates code from several previously separate malware families and provides guidance to help defenders de…MICROSOFT.COM
9 JulNew GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and SpywareMicrosoft has taken apart a destructive Windows backdoor it calls GigaWiper. What stands out is how it is built: not one tool but three older destructive programs bolted into one, offered as commands the operator can choose from. Each is a different way to break a machine: wipe t…THEHACKERNEWS.COM
9 JulGodDamn Ransomware Uses PoisonX to Blind Security SoftwareGodDamn ransomware uses the signed PoisonX driver to disable security tools, marking a more advanced version of the Beast ransomware family. Symantec’s Threat Hunter Team found a new ransomware family called GodDamn that first appeared in the wild on May 21, 2026, and analy…SECURITYAFFAIRS.COM
9 JulInjective SDK on npm infected with cryptocurrency wallet stealerHackers compromised the Injective Labs SDK project's GitHub repository and used it to publish a malicious package on the Node Package Manager (npm) that stole cryptocurrency wallet private keys and mnemonic seed phrases. [...]BLEEPINGCOMPUTER.COM
8 JulOrbia CISO Miranda Ritchie on building security into sustainable infrastructureIn this interview with Help Net Security, industrial cybersecurity, CISO at Orbia, talks about protecting industrial systems where software runs water, chemical and manufacturing processes. She explains why a cyber incident in these settings can harm people, equipment and the env…HELPNETSECURITY.COM
8 JulOnlyFans Models Are Accidentally Making Hacked Government Websites DisappearScammers are hijacking government websites to upload ads for “leaked” OnlyFans content. Thousands of copyright complaints from adult creators are helping people avoid malicious links.WIRED.COM
8 JulCybersecurity and the Gap Between Skill and AbilityLast week, national security agencies from the Five Eyes—that’s the rich, English-language-speaking countries club—jointly released a statement warning of the increasing cyber risks of AI models: in particular, their ability to autonomously hack into systems and…SCHNEIER.COM
8 JulTelco giant KDDI says data breach affects over 12 million peopleJapanese telecommunications giant KDDI says that millions of people had their email addresses and passwords exposed after attackers breached an email platform used by five internet service providers (ISPs) in the country. [...]BLEEPINGCOMPUTER.COM
8 JulWeekly Update 511: Live from my Riad in MarrakechPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite How's this for a location?! I mean, last week was nice with Scott in Mallorca, but Marrakech is, well, wow 😮 Anyway, about…TROYHUNT.COM
8 JulAccenture confirms a data breach.Australian telecom outage attributed to software bug. Business news: Keyfactor secures more than $1 billion in a growth funding round.THECYBERWIRE.COM
8 JulAnother massive data breach exposed millions of driver’s license numbersThe cyberattack targeting a U.S. insurance giant is the largest known breach of driver's license numbers so far in 2026.TECHCRUNCH.COM
8 JulMount Royal University confirms breach as hackers claim attackMount Royal University in Calgary says hackers stole and then deleted data from its file storage systems after breaching the university's network. [...]BLEEPINGCOMPUTER.COM
8 JulSmashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itselfA 15-year-old boy asked a chatbot for help - and cancelled nearly 47,000 anime streaming subscriptions in under four hours. Meanwhile, researchers have documented the first fully autonomous, agentic AI-driven ransomware attack, "JadePuffer". What does this tell us about the futur…GRAHAMCLULEY.COM
7 JulNothing left to StealC.Welcome in! You’ve entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today’s most interesting threats. Your host is ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Selena Larson⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Proofpoint⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ intelligence analyst and host of their podcas…THECYBERWIRE.COM
7 JulIran-Linked Hackers Using Modular C&C Framework in CyberattacksResearchers say the Iran-linked threat actor used an adaptable modular malware framework and compromised IT service providers to reach high-value targets in Israel. The post Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks appeared first on SecurityWeek .SECURITYWEEK.COM
7 JulHacktivists call out Trump by hacking and defacing US Army websitesThe U.S. Army has fixed two of its websites that were hacked to display messages calling President Trump a "pedophile" and a "thief."TECHCRUNCH.COM
7 JulMajor Japanese telco says cyberattack exposed 12 million emailsThe company said the breach affected an email system used to manage customer email accounts, webmail services and email storage for five Japanese internet service providers.THERECORD.MEDIA
7 JulCounty Government Reportedly Paid $1 Million to Cyber Extortion GroupThe alleged victim, believed to be a small Ohio county, reportedly paid the extortion group to prevent the public release of sensitive stolen data. The post County Government Reportedly Paid $1 Million to Cyber Extortion Group appeared first on SecurityWeek .SECURITYWEEK.COM
6 JulHow to prioritize AI agent security by business impactYour CEO calls about an AI agent security incident in finance. He wants to know whether money moved, whether financial data was exposed, who owned the agent and why it had this level of access. The agent was connected to a spend management application to reconcile invoices, summa…HELPNETSECURITY.COM
6 JulResearchers Claim First Fully Agentic Ransomware: JadePufferResearchers have revealed JadePuffer, the first agentic AI-powered ransomware campaign, highlighting how autonomous agents can automate cyber-attacksINFOSECURITY-MAGAZINE.COM
6 JulICE’s Internal Watchdog Is Now Investigating Online CriticsThe Office of Professional Responsibility has opened more than 100 cases over what ICE officials call “incidents of doxing and threats” against ICE employees.WIRED.COM
6 JulSuspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRATA suspected China-nexus threat activity cluster has been observed targeting Indian taxpayers, tax professionals, and corporate finance teams to deliver a remote access trojan designed to steal sensitive data from compromised hosts. The multi-stage campaign, codenamed Operation Dr…THEHACKERNEWS.COM
6 Jul6th July – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 6th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES River Bank & Trust, a US financial institution, has experienced a ransomware incident after an unauthorized actor accessed the net…RESEARCH.CHECKPOINT.COM
6 JulFBI disrupts residential proxy network used by botnet.New macOS infostealer poses as a clipboard manager. AdaptHealth discloses data breach affecting patient information.THECYBERWIRE.COM
6 JulSysdig clocks first documented case of agentic ransomwareThe AI agent didn’t accomplish every step in the late June 2026 attack, but it allowed the threat actor to significantly reduce complexity, speed up the tempo and gain operational advantages. The post Sysdig clocks first documented case of agentic ransomware appeared first on Cyb…CYBERSCOOP.COM
6 JulMajor medical device manufacturer notifies nearly 4 million of breachInformation like Social Security numbers and health-related data was accessed, but the company said it had “no evidence that impacted information has been publicly posted or exposed on the internet.”THERECORD.MEDIA
6 JulBlogspot-Hosted Payloads Delivered in ‘Veil#Drop’ AttacksSecuronix says the sophisticated framework abuses compromised websites, Blogspot, PowerShell, and fileless techniques to evade detection and deploy the PureLog information stealer. The post Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks appeared first on Se…SECURITYWEEK.COM
6 JulCanadian spy agency reports hacking three criminal groups in 2025A ransomware-as-a-service gang, an online foreign extremist group and drug traffickers were separately the targets of offensive operations in 2025, according to Canada's Communications Security Establishment.THERECORD.MEDIA
6 JulThe ‘first’ AI-run ransomware attack still needed a humanAn AI agent carried out the technical execution of a real-world ransomware attack for the first known time, but new details show a human still chose the victim, set up the infrastructure, and supplied stolen credentials — meaning it wasn't quite the fully autonomous cybercrime de…TECHCRUNCH.COM
5 JulSecurity Affairs newsletter Round 584 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. U.S. Government Agency Paid $…SECURITYAFFAIRS.COM
5 JulMedtronic Notifies 3.8 Million After ShinyHunters Data BreachMedtronic says a ShinyHunters attack exposed the personal and medical data of over 3.8 million people. Products and operations were unaffected. Medtronic is notifying 3,834,294 individuals after a cyberattack by the ShinyHunters extortion group exposed personal and medical inform…SECURITYAFFAIRS.COM
4 JulNew Avalon Malware Framework Packs CrownX Ransomware CapabilitiesCybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that's distributed by means of a multi-stage phishing chain capable of bypassing traditional security controls. Avalon combines credential collection, lateral movement, …THEHACKERNEWS.COM
4 JulU.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion CaseA U.S. government entity paid about $1 million to keep stolen files from being leaked, according to a new case study by Rakesh Krishnan for Ransom-ISAC, built on a leaked negotiation chat and the blockchain trail the payment left. The odd part: the group that took the money …THEHACKERNEWS.COM
4 JulJadePuffer ransomware used AI agent to automate entire attackResearchers identified what they believe is the first documented case of a ransomware operation, JadePuffer, conducted entirely by a large language model (LLM) agent. [...]BLEEPINGCOMPUTER.COM
4 JulU.S. Government Agency Paid $1M to Data Extortion Group KairosA U.S. government agency paid $1M to Kairos, a group focused on data theft and extortion rather than ransomware, Ransom-ISAC reports. A new case study from Ransom-ISAC reconstructs a complete data-extortion incident involving a U.S. government body and a threat actor called Kairo…SECURITYAFFAIRS.COM
3 JulCyberWire Daily at 10: The vulnerabilities, zero‑days, and hardware flaws over the last decade.In this special edition of CyberWire Daily’s 10th anniversary series, N2K CyberWire's ⁠Maria Varmazis⁠ and ⁠Dave Bittner⁠ discuss 10 years of vulnerabilities, zero‑days, and hardware flaws. Together they reflect on the last decade of cybersecurity vulnerabilities, exploring key s…THECYBERWIRE.COM
3 JulRisky Bulletin: FatFs bugs enable physical access attacks on a load of devicesFatFs bugs enable physical access attacks on industrial equipment, a clever password spraying attack bypasses M365 MFA, an AI agent is deploying ransomware in live attacks, and a webinar platform sues two security firms over bad IOCs.RISKY.BIZ
3 JulPolitician who investigated spyware abuses had his phone hacked with Pegasus spywareA government customer of NSO Group used the company's Pegasus spyware to hack into the phone of a European politician, who at the time was serving on an EU committee tasked with investigating the spyware industry.TECHCRUNCH.COM
3 JulSwimming Pools, Pee, and Trying to Delete Your Data From the InternetPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite I can't recall if someone else originally came up with this saying or if I said it in some off-the-cuff comment and it just propag…TROYHUNT.COM
3 JulMedtronic Data Breach Impacts 3.8 Million PeopleMedical technology giant Medtronic is notifying more than 3.8 million individuals that their personal and medical information was compromised in a recent data breach. The incident occurred in April 2026, when the infamous extortion group ShinyHunters accessed the company’s corpor…SECURITYWEEK.COM
3 JulGoogle, FBI Disrupt NetNut Residential Proxy Network Powered by Millions of DevicesNetNut rented access to millions of compromised devices, allowing cybercriminals and nation-state actors to mask their identities during attacks. The post Google, FBI Disrupt NetNut Residential Proxy Network Powered by Millions of Devices appeared first on SecurityWeek .SECURITYWEEK.COM
3 JulEuropean Parliament Member Investigating Spyware Was Hacked With PegasusA new report from the Citizen Lab has revealed that former Member of the European Parliament Stelios Kouloglou had his mobile device repeatedly hacked with the notorious Pegasus spyware while serving on a committee that was tasked with investigating the abuse of such commercial s…THEHACKERNEWS.COM
3 JulWarning Over “Industrialized” Cyber-Attacks After Ransomware Gang Partners With TeamPCPResearchers warn that collaboration could lead to “unprecedented” ransomware attacks, as FBI also issues warningINFOSECURITY-MAGAZINE.COM
3 JulQilin Dominates Ransomware Market Amid Growing Cybercrime ConsolidationThe ransomware landscape is reconsolidating around major players, with Qilin emerging as the leading RaaS operation, researchers sayINFOSECURITY-MAGAZINE.COM
3 JulArmored Likho Targets Government Agencies, Power Sector with BusySnake StealerA previously undocumented threat actor known as Armored Likho has been attributed to cyber attacks targeting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan. "Armored Likho blends financially motivated campaigns targeting private individual…THEHACKERNEWS.COM
3 JulNew macOS malware PamStealer uses PAM to validate stolen dataA previously undocumented macOS infostealer dubbed PamStealer validates victims' macOS passwords through the OS’s Pluggable Authentication Modules (PAM) before stealing them. Jamf Threat Labs researchers, who analyzed a two-stage attack chain combining AppleScript, JavaScript for…CYBERINSIDER.COM
3 JulNetNut proxy network disrupted, 2 million infected devices cut offA joint operation involving Google has disrupted NetNut, a residential proxy network that gave access to millions of compromised Android devices, including smart TVs and streaming boxes. [...]BLEEPINGCOMPUTER.COM
3 JulMoody Bible Institute - 2,303,416 breached accountsIn June 2026, Moody Bible Institute was targeted by a ShinyHunters "pay or leak" extortion campaign . Over 2.3M unique email addresses and other personal data were later published publicly, including names, physical addresses, phone numbers, dates of birth and other information r…HAVEIBEENPWNED.COM
3 JulPegasus Used Against MEP Investigating Pegasus, Citizen Lab FindsA former EU lawmaker was hacked with Pegasus spyware while investigating its use, according to Citizen Lab. The Citizen Lab published a report documenting one of the more darkly ironic findings in recent surveillance research: former Member of the European Parliament Stelios Koul…SECURITYAFFAIRS.COM
2 JulMedtronic notifies customers impacted by ShinyHunters data breachHealthcare device firm Medtronic is notifying affected customers about a data breach that exposed their personal data to an unauthorized third party. [...]BLEEPINGCOMPUTER.COM
2 JulCatching ransomware on the wire before it locks the file serverCorporate networks keep sensitive files off individual workstations and store them on shared servers that staff reach through mapped network drives. That arrangement hands ransomware operators a target worth chasing. A single compromised laptop can begin encrypting files that liv…HELPNETSECURITY.COM
2 JulThe endpoint recovery gap many teams discover during an incidentIn this interview with Help Net Security, IGEL CTO Matthias Haas explains why backups alone do not equal recovery. He makes the case that endpoint recovery is often overlooked, leaving organizations exposed when thousands of devices go down at once. Haas walks through what a well…HELPNETSECURITY.COM
2 JulOpera blocks ClickFix attacks with new clipboard protection featureOpera has launched Paste Protect, a clipboard protection feature designed to prevent clipboard-based attacks such as hijacking and pastejacking. Paste Protect includes built-in protection and warnings against ClickFix-based cyberattacks, which accounted for more than half of malw…HELPNETSECURITY.COM
2 JulAlleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime ChargesAlleged Scattered Spider member Peter Stokes, 19, was extradited from Finland to the U.S. over hacking, fraud, and extortion charges. Peter Stokes, 19, an alleged Scattered Spider member known online as “Bouquet,” has been extradited from Finland to the U.S. to face h…SECURITYAFFAIRS.COM
2 JulMissed incidents, persistent threats, and response gaps: Insights from compromise assessment projectsKaspersky Compromise Assessment specialists analyze trends from the service's 2025 projects and provide tips on how to enhance your organization's security.SECURELIST.COM
2 JulFortiBleed Credential Theft Linked to INC and Lynx Ransomware OperationsThe recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were intended for follow-on intrusions. "An operator tied to FortiBleed's infrastructure was found activel…THEHACKERNEWS.COM
2 Jul‘BioShocking’ Attack Tricks AI Browsers Into Stealing CredentialsResearchers show how context manipulation can cause agentic browsers to abandon safety guardrails and exfiltrate sensitive credentials. The post ‘BioShocking’ Attack Tricks AI Browsers Into Stealing Credentials appeared first on SecurityWeek .SECURITYWEEK.COM
2 Jul430,000 FortiGate Devices Exposed in FortiBleed Ransomware LinkFortiBleed exposed 430,000 FortiGate firewalls, linked to INC Ransom and Lynx, enabling domain compromise and at least 12 ransomware attacks. SOCRadar’s Threat Research Unit has connected FortiBleed, a large-scale campaign that harvested credentials from over 430,000 FortiG…SECURITYAFFAIRS.COM
2 JulCybercriminals Pose as Interpol in Phishing Emails to Infect Victims With RansomwareBitdefender researchers warned of curious ransomware campaign which has targeted businesses around the worldINFOSECURITY-MAGAZINE.COM
2 JulFortiBleed Campaign Linked to INC, Lynx Ransomware AttacksResearchers say credentials harvested from hundreds of thousands of FortiGate firewalls are being used to facilitate ransomware attacks by the INC and Lynx operations. The post FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
2 JulScattered Spider suspect extradited over $8 million ransom schemeA suspected Scattered Spider member has been extradited to the United States to face charges linked to cyberattacks against U.S. companies, including the breach of a luxury jewelry retailer that led to an $8 million cryptocurrency ransom demand after attackers stole company data.…HELPNETSECURITY.COM
2 JulUS government says it got hacked — againA top Democrat on the Senate's Intelligence Committee warned that the information accessed on a Homeland Security intelligence-sharing network may risk national security.TECHCRUNCH.COM
2 JulMost cybersecurity workers have been told to conceal a breach, report findsThe security firm Bitdefender’s annual survey also found that U.S. companies were simultaneously more confident and more strained on cyber defense than foreign peers.CYBERSECURITYDIVE.COM
2 JulThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 StoriesThis week’s security news is mostly about weak spots. Browsers, bots, sandboxes, AI systems, and email flows all show the same problem in different ways. Everything looks normal until someone tests a small gap and finds a way through. This is not one big break. It is small permis…THEHACKERNEWS.COM
2 JulThe Gentlemen ransomware: what you need to knowWho Are The Gentlemen? Despite the impeccably polite name, there is nothing polite or refined about this particular gang of cybercriminals. Read more in my article on the Fortra blog.FORTRA.COM
2 JulRansomware Thugs Masquerade as Interpol to Entice Small BizThe ransomware campaign relies on basic social engineering and stretches across multiple regions, including the US, Europe, Middle East, and elsewhere.DARKREADING.COM
2 JulFBI Seizes NetNut Proxy Platform, Popa BotnetThe Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes ro…KREBSONSECURITY.COM
1 JulChina-Linked Group Targets Southeast Asia Critical SystemsThe group compromised at least 10 regional organizations, including two state-owned entities, and deployed a new backdoor.DARKREADING.COM
1 JulUS puts $10m bounty on Russian hackers, new phish hunts hotels, Supreme Court reins in geofencingUS Puts $10M Bounty on Russian Hackers, Supreme Court Limits Geofence Warrants, New phishing campaign targets hotels, AI Coding Agents Tricked into Malware and Canada's Electronic Spies Go After Ransomware Gangs. The episode covers the US State Department's up to $10 million rewa…CYBERSECURITYTODAY.LIBSYN.COM
1 JulWhy Ask Credentials If There Are Secret Codes&#x3f;, (Wed, Jul 1st)This morning, an interesting phishing email hit my mailbox. It targets Metamask[ 1 ], a cryptocurrency wallet, available as a browser extension and a mobile app, that lets users store, send, and receive crypto money. It's pretty popular, so a juicy target for crimin…ISC.SANS.EDU
1 JulInsurance Giant Aflac Discloses Data Breach Impacting MillionsAflac Japan has notified regulators that policy details and personal and banking information have been compromisedINFOSECURITY-MAGAZINE.COM
1 JulBrowser-Only Ransomware: From LLM Hallucinations to a Practical Attack TechniqueResearch by: Alexey Bukhteyev Key Takeaways Introduction Over the past several years, large language models have reshaped software development, and malware development has followed the same path. Check Point Research has documented this trend from early experiments showing t…RESEARCH.CHECKPOINT.COM
1 JulARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365Talos has identified "ARToken," a phishing-as-a-service platform that targets Microsoft 365. The ARToken panel exposes 80+ API endpoints for device code phishing, Primary Refresh Token persistence, email access, BEC operations, and SharePoint exfiltration.TALOSINTELLIGENCE.COM
1 JulThe SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaignKaspersky experts have uncovered a malicious network infrastructure for delivering AsyncRAT. The Trojan is dropped via compromised ScreenConnect software. In this post, we break down the infection chain and analyze the C2 infrastructure.SECURELIST.COM
1 JulJapanese insurer, brewer, manufacturer and telecom disclose cyber breachesAflac's Tokyo arm and brewer Sapporo are among the major Japanese companies to recently notify the public about data breaches.THERECORD.MEDIA
1 JulAI-Generated Browser Ransomware Abuses Chromium API on Windows and AndroidCybersecurity researchers have flagged a new malware artifact generated using DeepSeek that constructed a novel attack path combining "unrealistic browser-malware concepts with a real browser capability" to turn it into a working ransomware technique that runs entirely inside the…THEHACKERNEWS.COM
1 JulAzure CLI Targeted in LSHIY Password Spray Campaign Across 64 Orgs81 Million Login Attempts, 78 Compromised Accounts: The LSHIY Password Spray Hitting Azure CLI Huntress researchers have been tracking a massive automated password spray campaign against Microsoft Azure CLI environments since June 12, 2026. A password spray attack is when attacke…SECURITYAFFAIRS.COM
1 JulFake Interpol investigation emails deliver custom ransomware worldwideThreat actors impersonate Interpol to trick small businesses into launching ransomware disguised as evidence in a fake cybercrime investigation. The campaign has targeted organizations across Europe, Asia, the Middle East, and the United States, relying on convincing social engin…CYBERINSIDER.COM
1 JulDHS confirms hackers breached HSIN info-sharing platformThe Department of Homeland Security is investigating a cyberattack that compromised the Homeland Security Information Network (HSIN), a sensitive information-sharing platform used by federal, state, local, and private-sector partners. [...]BLEEPINGCOMPUTER.COM
1 JulTeen suspect in Scattered Spider hacks is extradited to USA complaint unsealed this week accuses a 19-year-old of participating in incidents including a breach of a "luxury-jewelry retailer" in 2025.THERECORD.MEDIA
1 JulFortiBleed credential-theft campaign linked to Lynx ransomwareThe massive FortiBleed credential theft campaign has been linked to the INC and Lynx ransomware operations, suggesting the stolen Fortinet credentials were intended to fuel future network intrusions. [...]BLEEPINGCOMPUTER.COM
30 JunProduct showcase: Scam calls, phishing, and data breaches? Meet AVG Mobile SecurityAVG Mobile Security for iOS helps protect users against online threats with features including Web Guard, VPN, Scam Guardian Pro, Hack Alerts, and Photo Vault. It also identifies suspicious calls and scam text messages and helps keep personal information private while using Wi-Fi…HELPNETSECURITY.COM
30 JunOver 300 UK Firms Hit by Ransomware in a YearReport Fraud data reveals that more than half of 323 UK ransomware victims last year were SMEsINFOSECURITY-MAGAZINE.COM
30 JunBlackfield ransomware asks Nidec Corporation for $2 million ransomThe Blackfield ransomware gang is asking for a $2 million ransom from Nidec Corporation, a large Japanese manufacturer of electronic components for automotive and computing applications. [...]BLEEPINGCOMPUTER.COM
30 JunNissan Employee Data Breached in Oracle PeopleSoft HackOnly a handful of the 100 organizations targeted in the PeopleSoft campaign have been confirmed. The post Nissan Employee Data Breached in Oracle PeopleSoft Hack appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunAflac Japan Data Breach Impacts 4.38 MillionHackers accessed the insurance giant’s policyholder portal multiple times between June 15 and June 25. The post Aflac Japan Data Breach Impacts 4.38 Million appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunLessons from the Underground: How to Combat Business Email CompromiseBusiness Email Compromise is more than an email scam. It's a coordinated operation involving compromised accounts, financial research, and cash-out networks. Flare explores how underground forums reveal how BEC attacks are planned and executed. [...]BLEEPINGCOMPUTER.COM
30 JunStop Policing AI PromptsAI security is changing. Instead of focusing only on preventing bad responses or prompt abuse, organizations increasingly need to control what AI agents are actually allowed to do inside real systems. As AI agents gain access to identities, applications, and workflows, the bigges…YOUTUBE.COM
30 JunWeekly Update 510: Live From Mallorca with Scott HelmePresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite How's the view?! Back to business, it's now 8 years ago that Scott and I thought it would be a cool idea to build Why no HTTP…TROYHUNT.COM
30 JunMicrosoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak DataNew Microsoft research shows how attackers can hijack AI agents that act on a user's behalf, using nothing more than a poisoned tool description to make the agent quietly hand over company data to an outsider. The trick is that the agent never breaks a rule. Every step …THEHACKERNEWS.COM
30 JunMalicious PyPI packages give hackers control of Telegram bot serversA campaign active since last November has been targeting Python developers building Telegram bots with trojanized Pyrogram forks that allow attackers to read arbitrary files on compromised servers. [...]BLEEPINGCOMPUTER.COM
29 JunSycophantic chatbots and the harms that build over many chatsPeople use AI chatbots for company, advice, and emotional support, and these systems answer in ways meant to hold their attention. Researchers describe the resulting risks as affective safety, a class of harm that exists because humans are emotional beings and because the systems…HELPNETSECURITY.COM
29 JunHijacked npm and Go Packages Use VS Code Tasks to Deploy Python InfostealerCybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages that are designed to deploy a Python-based information stealer on compromised Windows, Linux, and macOS hosts. "This attack avoids the most common npm execution paths through lifecycle…THEHACKERNEWS.COM
29 JunThe Gentlemen are knocking: сustom backdoors and evolving tacticsKaspersky researchers analyze incidents related to The Gentlemen RaaS group, disclose their tools and TTPs, and find a new ransomware variant.SECURELIST.COM
29 JunTop Google Security Staff Warn Search Data Could Be Hacked if EU Rules ChangeEurope’s pro-competition proposals could see Google Search and Android systems opened up. The company claims there are serious privacy flaws.WIRED.COM
29 JunRussian Hackers Accused of Destructive Cyber-Attack on Jaguar Land RoverExperts warn the Jaguar Land Rover breach bears hallmarks of Kremlin-backed hackers, citing novel ransomware, strategic timing and efforts to obscure attributionINFOSECURITY-MAGAZINE.COM
29 JunPrivacyHawk Enterprise helps organizations find shadow IT and minimize third-party cyber riskPrivacyHawk has announced the general availability of PrivacyHawk Enterprise, a solution that identifies and eliminates the shadow IT accounts, abandoned SaaS subscriptions, and forgotten third-party services quietly exposing organizations to breach risk. Every organization has a…HELPNETSECURITY.COM
29 Jun29th June – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 29th June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Polymarket, a large cryptocurrency-based prediction market, has confirmed a supply chain attack after a third-party frontend vendor b…RESEARCH.CHECKPOINT.COM
29 JunFrom Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver AkiraKey Takeaways This case was first reported to customers in a threat brief released in July 2025 and in a public flash alert in August 2025 in partnership with Swisscom B2B CSIRT, which observed another intrusion tied to the same campaign. This report contains data from both intru…THEDFIRREPORT.COM
29 JunWhite House eases restrictions on Mythos.FBI issues updated warning on Russian phishing attacks targeting messaging apps. Japanese telecommunications giant discloses breach.THECYBERWIRE.COM
29 JunInsurance body confirms hackers posted Oracle PeopleSoft breach dataNAIC warned that some ratings agencies have suspended data feeds as a precaution. CYBERSECURITYDIVE.COM
29 JunOne Hack, Fifty VictimsA single breach can trigger many others when attackers compromise widely used software, infrastructure, or suppliers. The speakers describe this as a cascading breach, while also comparing it to hack amplification. Rather than attacking companies one by one, attackers may focus o…YOUTUBE.COM
29 JunWhat the June 2026 Threat Technique Catalog update means for your AWS environmentThe AWS Customer Incident Response Team (AWS CIRT) encounters patterns that repeat across engagements when helping customers respond to security incidents. We’re passionate about making sure that information is accessible so that everyone can improve their security posture and th…AWS.AMAZON.COM
29 JunIran, Russia, China Target Water Systems for SabotageNation-state attackers breach water systems through weak passwords, exposed PLCs, and poor segmentation — not sophisticated malware.DARKREADING.COM
28 JunSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 103Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter More Than 4,000 Legacy Routers Compromised by AryStinger, Turned into Global Attack Proxies for Hackers   A VBScript …SECURITYAFFAIRS.COM
27 JunKubernetes forensics 1/3: what the container ?In 2025, Synacktiv CSIRT observed a significant rise in attacks and compromises targeting Kubernetes environments. The consensus is that these attacks are bound to keep expanding as much as the technology itself. To better understand how a Kubernetes cluster works and how to inve…SYNACKTIV.COM
27 JunOSX/MacRansom; analyzing the latest ransomware to target macsLooks like somebody on the 'dark web' is offering 'Ransomware as a Service'...that's designed to infect Macs!OBJECTIVE-SEE.ORG
27 JunHandBrake Hacked! OSX/Proton (re)AppearsThe website of a popular application was hacked, and the application trojaned with a new variant of osx/proton.OBJECTIVE-SEE.ORG
27 JunTowards Generic Ransomware DetectionBy monitoring file I/O events and detecting the rapid creation of encrypted files by untrusted processes, can ransomware be generically detected?OBJECTIVE-SEE.ORG
27 JunThird-Party Breaches Teach Education Sector a Costly Lesson in Vendor RiskRising threats from third-party actors are forcing institutions to play defense to protect student data from ransomware and other attacks.DARKREADING.COM
27 JunHospitality Sector Hit by Phishing Campaign Using Fake Guest Complaint EmailsMicrosoft warns of a phishing campaign targeting the hospitality sector with fake guest emails that install TonRAT using resilient persistence. Microsoft Threat Intelligence published a detailed analysis on an ongoing hacking campaign against hospitality organizations that has be…SECURITYAFFAIRS.COM
27 JunUkraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging CredentialsThe Security Service of Ukraine (SSU) said it, together with the U.S. Federal Bureau of Investigation (FBI), uncovered a long-running campaign orchestrated by Russian intelligence services to break into the messaging accounts of government officials, military personnel, politicia…THEHACKERNEWS.COM
26 JunAmerican Tower - 216,601 breached accountsIn June 2026, telecommunications tower infrastructure company American Tower was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data allegedly taken from the company containing more than 200k unique email addresses belonging to em…HAVEIBEENPWNED.COM
26 JunCMC Releases Analysis and Guidance for Education Sector After Canvas Data BreachThe UK Cyber Monitoring Centre reviews the Canvas breach affecting 160 UK universities, highlighting data theft risks and financial impacts of cyber incidentsINFOSECURITY-MAGAZINE.COM
26 JunSIM-swapping gang busted in international police operationOfficers from Poland’s Central Bureau for Combating Cybercrime (CBZC) arrested four suspected members of an organized cybercrime group accused of SIM swap attacks, cryptocurrency theft, and money laundering. The operation involved agents from the U.S. Federal Bureau of Inve…HELPNETSECURITY.COM
26 JunHealthcare leaders see a fatal cyber incident as inevitableHealthcare practices run on a chain of outside vendors. An EMR system holds clinical records, a billing platform processes claims, a telehealth tool supports remote visits, and a cloud provider stores data. Every one of those connections gives an outside company a path into the p…HELPNETSECURITY.COM
26 JunOne Million Passports Leaked OnlineA database of almost a million passports from around the world was leaked online. Note what happened. A high-value credential—a passport—was used in an ancillary low-value authentication system: ID verification for cannabis dispensaries. And it’s the low-value s…SCHNEIER.COM
26 JunMiasma Malware Targets npm Packages and GitHub Actions in Supply Chain AttackCybersecurity researchers have flagged yet another evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware family that has compromised a new set of npm packages, even as it has propagated to the Go ecosystem. "The latest activity includes mal…THEHACKERNEWS.COM
26 JunPolymarket suffers supply chain attack leading to $3 million crypto theftPolymarket says it has contained a supply chain attack that injected malicious code into its website after a compromised third-party vendor exposed some users to a phishing campaign. This resulted in roughly $3 million in cryptocurrency theft, which the company says will be fully…CYBERINSIDER.COM
26 JunMystery hackers use novel SharkLoader dropper against governments, software devsKaspersky researchers have uncovered a previously unknown cyberattack campaign that has compromised government organizations and software development companies in multiple countries. They first stumbled onto the campaign while investigating an attack on a diplomatic organization …HELPNETSECURITY.COM
26 JunRussia used social engineering to breach prominent messaging accounts, Ukraine saysUkraine's SBU described a long-running Russian operation that used fake tech-support workers to persuade people to hand over credentials to their messaging apps.THERECORD.MEDIA
26 JunIn Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk LayoffsOther noteworthy stories that might have slipped under the radar: Russia used Cellebrite to hack activist’s phone, Five Eyes issue urgent AI threat warning, macOS Gaslight backdoor, Scattered Spider guilty pleas. The post In Other News: Chinese Mythos-Like AI, Tata Electronics Br…SECURITYWEEK.COM
26 JunChinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia CampaignA Chinese-speaking advanced persistent threat (APT) actor has been linked to a new custom backdoor called TinyRCT as part of cyber attacks aimed at government entities and critical infrastructure in Southeast Asia. The activity, particularly aimed at state-owned enterprises in th…THEHACKERNEWS.COM
26 JunNew SharkLoader Malware Deploys Cobalt Strike in StrikeShark CyberattacksA newly discovered cyber attack campaign has been observed delivering a previously undocumented malware family called SharkLoader that acts as a loader for deploying Cobalt Strike Beacon on compromised hosts. Kaspersky, which is tracking the activity under the moniker StrikeShark…THEHACKERNEWS.COM
26 JunPolymarket customers lose $3 million in supply-chain attackPolymarket says it will fully reimburse customers who lost an estimated $3 million after hackers injected a malicious script into the platform's frontend following a breach at a third-party vendor. [...]BLEEPINGCOMPUTER.COM
25 JunSurviving the Mythos Era: Richard Bejtlich on the Case for NDRDespite the abundance of telemetry at analysts’ disposal, many security operations teams struggle to answer a few basic questions during incident investigation: What happened? What evidence do we have? How do we know we’re seeing it all, in context? Answering these questions requ…THEHACKERNEWS.COM
25 JunPolymarket says hackers stole users’ fundsThe prediction market giant Polymarket said it's refunding users who had funds stolen due to a third-party breach.TECHCRUNCH.COM
25 JunHacked Klue says criminals are deleting stolen customer data, but now other hackers are making threatsMarket research company Klue told customers that it believes the hacking group that stole their data is now deleting it. The company, however, warned about a second group of hackers wanting ransom.TECHCRUNCH.COM
25 JunCellebrite said it cut off Russia, but Russia used its tools anywaySecurity researchers found evidence that Russian authorities hacked the iPhone of a political opponent using a phone-unlocking device made by Cellebrite, even after the company said it would stop selling to Putin’s government.TECHCRUNCH.COM
25 JunGamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliancesESET Research analyzes Gamaredon’s new toolset and the group’s growing reliance on legitimate online services to hide its C&C infrastructure and exfiltrate stolen dataWELIVESECURITY.COM
25 JunEvaluating Mexico’s New Cybersecurity PlanExplore an analysis of Mexico’s 2025–2030 National Cybersecurity Plan. Discover how Mexico is addressing critical threats like ransomware, organized crime, and AI-driven attacks while preparing its digital infrastructure for the 2026 FIFA World Cup and beyondRECORDEDFUTURE.COM
25 JunElite network says it was hacked after members&#8217; personal data was left exposedPersonal data belonging to politicians, military leaders, and executives was left publicly accessible in what looks like a security misconfiguration.MALWAREBYTES.COM
25 JunGone with the command.International operation disrupts Amadey and StealC malware infrastructure. Australian spy chief warns nation-state hackers are prepositioning for future sabotage. Stealthy new backdoor may be tied to initial access broker. Researchers uncover "Cordyceps" supply chain flaw. Iran-l…THECYBERWIRE.COM
25 JunAnother Russian dairy company reportedly disrupted by cyberattackA dairy products manufacturer in Russia's republic of Bashkortostan is the latest such company to have its operations snarled by a cyberattack.THERECORD.MEDIA
25 JunUkraine's state postal operator reports app disruption after cyberattackUkraine's state-owned postal operator said it was experiencing disruptions to some of its app services due to a suspected cyberattack, but did not say who was behind it.THERECORD.MEDIA
25 JunMinnesota man known as ‘Snoopy’ sentenced in DraftKings hackNathan Austad, who sold access to compromised accounts through a criminal storefront, is the third and final defendant sentenced in the 2022 breach The post Minnesota man known as ‘Snoopy’ sentenced in DraftKings hack appeared first on CyberScoop .CYBERSCOOP.COM
25 JunMajor Increase in Ransomware Attacks Targeting Europe, Warns New ReportAnalysis of ransomware incidents by researchers at Black Kite found that attacks have risen by over 50% in the last year, with supply chain attacks increasingINFOSECURITY-MAGAZINE.COM
25 JunPoland busts SIM-swapping gang tied to millions in crypto theftAuthorities in Poland have arrested four members of an organized cybercrime group accused of breaching telecommunications partners and hijacking email accounts to carry out SIM-swapping attacks. [...]BLEEPINGCOMPUTER.COM
25 JunWebinar: Why account takeovers remain one of the hardest threats to stopAccount takeover attacks continue to challenge security teams because attackers often operate through legitimate accounts and trusted services. This webinar explores how behavioral AI can help organizations identify compromised accounts faster and automate response workflows. [..…BLEEPINGCOMPUTER.COM
25 JunEurope Evolves Into Ransomware's Favorite RegionAfter a global lull, ransomware gangs are setting sights on a rich new arena: attacking EU organizations and their suppliers.DARKREADING.COM
25 JunStealthy new backdoor surfaces in attacks on multiple sectorsA relatively new backdoor called Mistic has been deployed in multiple attacks since April 2026 targeting organizations in the insurance, education, IT, and professional services sectors, according to Symantec. The malware appears to be associated with Woodgnat, also known as Kong…HELPNETSECURITY.COM
24 JunFortiBleed: Fortinet Says It's Not a BugFortinet finally weighs in on FortiBleed - it's not a bug. Plus a healthcare AI firm loses 1.4 million people's data to a single phishing email, a trading bot built to prey on others gets played for $15 million, and LastPass lands back on a breach list it didn't cause. 00:00 Head…CYBERSECURITYTODAY.LIBSYN.COM
24 JunWeekly Update 509Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite I know enough about home cinema audiovisual to know there's a lot I don't know. It's conscious incompetence, if you like…TROYHUNT.COM
24 JunStealthy Mistic backdoor linked to ransomware access broker KongTukeA new backdoor dubbed Mistic has been observed in financially motivated attacks targeting organizations in the insurance, education, IT, and professional services sectors. [...]BLEEPINGCOMPUTER.COM
24 JunIran-Linked MuddyWater Poses as Ransomware Gang to Mask Cyber EspionageAn NCC Group report warns state-backed hackers are attempting to hide activity by posing as ransomware groups and deploying commercially available malwareINFOSECURITY-MAGAZINE.COM
24 JunNew ‘Mistic’ RAT Opens Door to Several Ransomware FamiliesMistic is used by Woodgnat, an initial access broker working with Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta. The post New ‘Mistic’ RAT Opens Door to Several Ransomware Families appeared first on SecurityWeek .SECURITYWEEK.COM
24 JunKDDI Breach Affects Six Japanese ISPs, Exposes 14.2 Email CredentialsCustomers of the affected Japanese email services are “strongly advised” to change their email passwordsINFOSECURITY-MAGAZINE.COM
24 JunPhishing attack on healthcare firm Xsolis impacts 1.4 million peopleHealthcare technology company Xsolis confirmed that a phishing attack resulted in unauthorized access to its network. The company develops AI-powered software for hospitals, health systems, and health plans and serves more than 600 hospitals and health insurers. “On January…HELPNETSECURITY.COM
24 JunIndian auto giant Bajaj Auto hit by ransomware incidentThe company said in a regulatory filing that it became aware of the incident on Tuesday morning and had taken precautionary measures to contain its impact.THERECORD.MEDIA
24 JunMadison Square Garden Sports - 9,796,738 breached accountsIn June 2026, the sports and entertainment company Madison Square Garden Sports was the target of a ShinyHunters "pay or leak" extortion campaign . The group later published the alleged data, which included almost 10M unique email addresses spanning staff and customers, along wit…HAVEIBEENPWNED.COM
24 JunAmadey, StealC malware operations disrupted in Operation Endgame actionMicrosoft, Europol, and international partners have disrupted infrastructure used by the Amadey and StealC malware operations as part of Operation Endgame, which targets cybercriminal services and ransomware gangs. [...]BLEEPINGCOMPUTER.COM
24 JunRansomware attacks grew in 2025 as traditional data breaches fell, Bitsight saysIn a new report, the company also charted a massive surge in internet-exposed AI services.CYBERSECURITYDIVE.COM
24 JunMicrosoft, Europol lead global takedown of infostealer malwareCybercriminals used Amadey and StealC to infect thousands of computers worldwide, leading to ransomware and other digital crimes.CYBERSECURITYDIVE.COM
24 JunSmashing Security podcast #473: How a hacker could have Rickrolled the entire World CupA polite caller from your bank says there is a problem with your account. Don't worry - they'll send someone round to help. They'll even take your cards away to keep them safe. The scam has run rampant, until Dutch police plastered blurred photos of 100 suspects across billboards…GRAHAMCLULEY.COM
24 JunDraftKings hacker 'Snoopy' sentenced to 18 months in prisonA 21-year-old using the alias "Snoopy" was sentenced to 18 months in prison for his role in hacking DraftKings accounts in the November 2022 cyberattack. [...]BLEEPINGCOMPUTER.COM
24 JunMalicious Edge extension abuses Native Messaging as bridge to malwareA malicious Microsoft Edge extension dubbed 'Edgecution' has been used in a ransomware attack to escape the browser sandbox and deploy a Python-based backdoor. [...]BLEEPINGCOMPUTER.COM
23 JunXsolis Data Breach Affects 1.4 Million IndividualsThreat actors gained access to personal and protected health information that Xsolis received from its clients. The post Xsolis Data Breach Affects 1.4 Million Individuals appeared first on SecurityWeek .SECURITYWEEK.COM
23 JunCanadian Electricity Provider London Hydro Discloses Data BreachHackers stole customers’ names, addresses, email addresses, phone numbers, and account information. The post Canadian Electricity Provider London Hydro Discloses Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
23 JunHackers steal passport and driver&#8217;s license data of 3 million TexansA breach at a Texas Parks and Wildlife Department vendor exposed personal information belonging to more than three million Texans.MALWAREBYTES.COM
23 JunTwo Scattered Spider hackers plead guilty over Transport for London cyberattackTwo members of the notorious hacker group Scattered Spider have pleaded guilty to charges related to a 2024 cyberattack on Transport for London (TfL) that resulted in £29 million in loss and recovery costs. Thalha Jubair, 20, from London, and Owen Flowers, 18, from Walsall, plead…HELPNETSECURITY.COM
23 JunAnthropic’s Fable 5 Model Jailbroken Within DaysFable 5 is the supposed safe version of Anthropic’s Mythos Preview, with guardrails to ensure that it can’t be used to create cyberattacks. Well, that restriction was bypassed within days.SCHNEIER.COM
23 JunTwo Scattered Spider members plead guilty over cyberattack that crippled London transitA 20-year-old and an 18-year-old admitted to infiltrating the network of Transport for London in 2024, disrupting public transportation services for months.THERECORD.MEDIA
23 JunPassword manager maker LastPass says hackers stole customer support case data during Klue breachThis is the second data breach to affect LastPass customers in recent years, after one of the password manager's tech partners was recently breached.TECHCRUNCH.COM
23 JunScattered Spider Hackers Plead Guilty on Day 1 of TrialTwo men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members of a prolific cyber…KREBSONSECURITY.COM
23 JunTata Electronics confirms cybersecurity incident after World Leaks dumps Apple dataTata Electronics has confirmed that it recently experienced a cybersecurity incident after the World Leaks extortion group listed the company on its leak portal and published what it claims is stolen corporate data. The company says it detected the incident weeks ago and that its…CYBERINSIDER.COM
23 JunKlue says hackers stole credential from 2022 that led to customer data breachesIt's unclear why Klue had not revoked the credential after the limited pilot, which hackers then used to breach a system holding keys for accessing customers' data.TECHCRUNCH.COM
23 JunDialog Claims It Was Hacked. A Misconfigured Website Left Its Members ExposedThe private events group, cofounded by Peter Thiel, says a “criminal” hacker is behind a breach that exposed members’ personal details. WIRED found no evidence a break-in was needed to access the files.WIRED.COM
23 JunHealthtech firm Xolis suffers data breach impacting 1.4 million peopleHealthcare technology company Xsolis says that sensitive data belonging to nearly 1.4 million individuals was compromised in a phishing attack that gave attackers access to its network. [...]BLEEPINGCOMPUTER.COM
23 JunYour Breach Plan Is DelusionalCybersecurity teams often repeat the phrase: “It’s not if, it’s when.” But according to this conversation, many organizations still behave as if breaches are completely preventable. Budgets continue flowing into detection tools, dashboards, and perimeter defenses while resilience…YOUTUBE.COM
23 JunTata Electronics confirms cyberattack as hackers leak dataTata Electronics has confirmed in a statement to BleepingComputer that it was the target of a cyberattack that impacted parts of its IT infrastructure. [...]BLEEPINGCOMPUTER.COM
22 JunTexas Parks & Wildlife Data Breach Affects 3 Million IndividualsHackers stole personal information after breaching the systems of a third-party license vendor serving TPWD. The post Texas Parks & Wildlife Data Breach Affects 3 Million Individuals appeared first on SecurityWeek .SECURITYWEEK.COM
22 JunINTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-PacificA new report from INTERPOL has revealed a "dramatic increase" in cybercrime in Asia and the South Pacific, fueled by rapid digitalization, internet penetration, new technologies, organized criminal networks, and a disparity in cybersecurity maturity. According to INTERPOL's 2025/…THEHACKERNEWS.COM
22 JunInfrastructure downtime has a $50k-per-hour price tag. It’s time to turn hours into minutes.Threats move at machine speed. Network incident response still doesn't. What’s standing in the way?CYBERSECURITYDIVE.COM
22 JunWhatsApp users targeted by ongoing VBScript malware campaignKaspersky researchers have uncovered an ongoing malware campaign that uses compromised WhatsApp accounts to distribute malicious VBScript attachments. The attachments install ManageEngine Endpoint Central, a legitimate remote management tool that can provide attackers with remote…CYBERINSIDER.COM
22 Jun⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and MoreIt’s Monday again. This week’s threat list looks painfully familiar: abused integrations, fake tools, poisoned websites, ransomware crews trying to shut down security tools, and mobile malware asking for way too much control. The annoying part is how little of this feels new. Wea…THEHACKERNEWS.COM
22 JunKlue hack results in data breach at several cybersecurity firmsHuntress, HackerOne, Jamf, Recorded Future, and Tanium are among the cybersecurity companies that had data stolen following an earlier breach at market research firm Klue.TECHCRUNCH.COM
22 JunSuspected cyberattack triggers false emergency alerts across parts of BrazilThe incident occurred early Saturday when at least a dozen unauthorized alerts were sent through Brazil's Civil Defense Alert system, a platform designed to warn residents about imminent threats such as floods, landslides and other natural disasters.THERECORD.MEDIA
22 JunGentleKiller Framework Disables Victims' Security SoftwareESET details GentleKiller, the EDR-killer framework the Gentlemen ransomware gang gives affiliatesINFOSECURITY-MAGAZINE.COM
22 JunPrevent data exfiltration: AWS egress controls for cloud workloadsWhen securing an Amazon Web Services (AWS) environment, teams naturally prioritize inbound controls, firewalls, WAFs, and access policies, because that’s where the most visible threats originate. Outbound traffic, on the other hand, tends to get less attention. It’s often left op…AWS.AMAZON.COM
22 JunKlue supply-chain attack impacts cybersecurity firms.Brand-new Prinz Eugen ransomware is surprisingly polished. Brazil investigates suspected hack of emergency alert system. Texas data breach affects hunting and fishing licensees.THECYBERWIRE.COM
22 Jun22nd June – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 22nd June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Texas Parks and Wildlife Department has been affected by a third-party data breach involving its license system vendor. The incident …RESEARCH.CHECKPOINT.COM
22 JunOne intrusion, two cyberattackers: Uncovering parallel threat activityRansomware case reveals two parallel threat actors, blending tactics and evasion—showing why isolated signals can often miss modern, overlapping cyberattacks. The post One intrusion, two cyberattackers: Uncovering parallel threat activity appeared first on Microsoft Security Blog…MICROSOFT.COM
22 JunShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain AttackMultiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official release channels and push backdoor code. "Attackers compromised the vendor's build and distribution pipeline, injecting backdoor …THEHACKERNEWS.COM
22 JunTata Electronics, a major tech supplier to Apple and Tesla, confirms data breachThe incident comes as Tata Electronics expands its role in global technology supply chains.TECHCRUNCH.COM
22 JunFortiBleed campaign used custom FortiGate sniffer to steal credentialsSecurity firm SOCRadar says the large-scale FortiBleed campaign targeting Fortinet FortiGate devices used custom sniffers to harvest authentication secrets from compromised firewalls and steal credentials. [...]BLEEPINGCOMPUTER.COM
22 JunThe Klue is in the data trail.Klue supply-chain attack impacts cybersecurity firms. Brand-new Prinz Eugen ransomware is surprisingly polished. ShinyHunters leak exposes sensitive data of 10,000 Council of Europe employees. Security agencies sound alarm over FortiBleed credential harvesting operation. Texas da…THECYBERWIRE.COM
22 JunJaredFromSubway MEV bot hacked in $15 million crypto theftThe JaredFromSubway Ethereum MEV (Maximal Extractable Value) bot suffered a $15 million loss after an attacker manipulated the opportunity-detection logic by creating fake cryptocurrency trading opportunities. [...]BLEEPINGCOMPUTER.COM
21 JunAryStinger botnet infected thousands of D-Link routers worldwideA previously undocumented malware botnet named AryStinger has compromised more than 4,000 outdated routers to turn them into proxies for malicious traffic. [...]BLEEPINGCOMPUTER.COM
20 JunThe Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security ProcessesThe Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and maintaining a suite of endpoint detection and response (EDR) killers that it hands out to affiliates for impairing system defenses before deploying the encryptor. This mature portfolio of EDR-termin…THEHACKERNEWS.COM
20 JunYou Don’t Need Perfect SecurityThis clip compares cybersecurity deterrence to choosing between two identical Ferraris — except one has a rabid pit bull in the back seat. The point is simple: attackers often look for the easiest target, not necessarily a perfect target. The conversation also references the clas…YOUTUBE.COM
20 JunMicrosoft links Mastra AI supply chain attack to North Korean hackersMicrosoft has attributed a recent Mastra AI supply chain attack that compromised more than 140 npm packages to the North Korean hacking group Sapphire Sleet, also known as BlueNoroff. [...]BLEEPINGCOMPUTER.COM
20 JunNew Prinz Eugen ransomware prioritizes recent files for encryptionA new ransomware operation named 'Prinz Eugen' prioritizes recently modified files for encryption and leaves no ransom note on the system. [...]BLEEPINGCOMPUTER.COM
19 JunFrom Assistive to Agentic: The AI Shift That's Redefining Threat ManagementIntroduction The average enterprise security team has 40 or more security tools, giving a lot of visibility into internal telemetry and asset data. But often, these tools are working in siloes, generating (overlapping) alerts and data. And yet, breach dwell times remain stubbornl…THEHACKERNEWS.COM
19 JunOperation Endgame Disrupts Malware Network Linked to Major Ransomware GangSocGholish malware has been removed from 15,000 sites associated with Evil Corp hackersINFOSECURITY-MAGAZINE.COM
19 JunWebinar: How attackers bypass MFA and how defenders can respondModern phishing attacks, including Device Code phishing, can undermine MFA protections and grant attackers access to corporate accounts without stealing passwords. This webinar explores how behavioral AI can help security teams detect compromised accounts faster and automate resp…BLEEPINGCOMPUTER.COM
19 JunFortiBleed: 86,000 Fortinet Device Credentials CompromisedThe large-scale credential theft campaign hit roughly half of the internet-accessible Fortinet firewalls and VPNs. The post FortiBleed: 86,000 Fortinet Device Credentials Compromised appeared first on SecurityWeek .SECURITYWEEK.COM
18 JunHow security teams are getting credential visibility into developer endpointsAs we noted in our earlier analysis, attackers already know secrets are on your developers’ machines, the only question is whether security teams do. The supply chain attack calendar of 2026 has been relentless. Megalodon backdoored 5,500 GitHub repositories in six hours. T…HELPNETSECURITY.COM
18 JunKodak Admits Data Breach After ShinyHunters Hack ClaimsKodak told SecurityWeek it believes there is no threat to its systems or operations as a result of the cybersecurity incident. The post Kodak Admits Data Breach After ShinyHunters Hack Claims appeared first on SecurityWeek .SECURITYWEEK.COM
18 Jun5 new security operations roles the AI-SOC will createFor years we’ve heard the frightening prediction that AI will take jobs away from people. It will and it already is , but that doesn’t mean it won’t also create new jobs and skills demands — like every other labor trend driven by technology advances. Take security operations for …CSOONLINE.COM
18 JunGentleKiller targets more than 400 security processes across 48 productsMost ransomware operations leave the work of disabling endpoint security software to their affiliates. The ransomware-as-a-service gang Gentlemen runs a different model. Its operators develop and maintain a set of tools for shutting down endpoint detection and response (EDR) prod…HELPNETSECURITY.COM
18 JunKodak confirms breach as ShinyHunters&#8217; leak threat reaches deadlineThe photography giant confirmed a data breach after ShinyHunters claimed it stole 2.2 million records and threatened to leak them.MALWAREBYTES.COM
18 JunMoody Bible Institute investigates potential data breach incidentMoody Bible Institute (MBI) says it is investigating claims that its systems were breached after the institution appeared on the dark web extortion site operated by the ShinyHunters threat group, which alleges it stole more than 23 GB of sensitive data from the Chicago-based Chri…CYBERINSIDER.COM
18 JunShapedPlugin update flow hacked to infect WordPress sitesMultiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack that distributed infected releases to paying customers via the vendor's official update system. [...]BLEEPINGCOMPUTER.COM
18 JunINC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023Cybersecurity researchers have charted the evolution of INC from an nascent ransomware-as-a-service (RaaS) operation to one of the most prolific cybercrime groups in 2026, claiming no less than 830 victims since August 2023. "The disruption of LockBit and the shutdown of BlackCat…THEHACKERNEWS.COM
18 JunAustralian sugar producer works to restore operations as ransomware group claims attackMackay Sugar said it was "working urgently" to verify claims that a highly active ransomware group was behind a cyberattack that shut down harvesting and milling operations.THERECORD.MEDIA
18 JunICO Cautions Healthcare Worker After Princess of Wales IncidentHospital insider escapes criminal prosecution after attempting to sell royal’s medical recordsINFOSECURITY-MAGAZINE.COM
18 JunTexas government data breach allowed hackers to steal 3 million driver’s licenses and passportsA data breach involving government-issued ID documents affects over three million people in Texas.TECHCRUNCH.COM
18 JunNintendo confirms data stolen in WebMD subsidiary cyberattackNintendo of America has confirmed to BleepingComputer that threat actors stole survey data from the third-party TinyPulse service used internally, but its systems were not compromised. [...]BLEEPINGCOMPUTER.COM
18 JunNovo Nordisk Breach Exposes Software Development Pipeline RiskA leaked GitHub token underscores what most organizations get wrong: Treating secrets management as a tooling problem rather than an identity problem.DARKREADING.COM
18 JunCybersecurity Focused On The Wrong ThingTraditional cybersecurity frameworks often prioritize confidentiality — protecting sensitive information from unauthorized access. But attacks against critical infrastructure introduce a different kind of risk. In many scenarios, the bigger danger is not stolen data, but failures…YOUTUBE.COM
18 JunGentlemen ransomware uses multiple EDR killers to disable defensesThe Gentlemen ransomware-as-a-service (RaaS) is actively developing and maintaining a suite of endpoint detection and response (EDR) killers to help affiliates evade detection in attacks. [...]BLEEPINGCOMPUTER.COM
17 JunNavigating SEC, NIS2, and DORA incident disclosure timelines under pressureIn this Help Net Security video, Rick Goud, Global Field CTO at Kiteworks, discusses how to handle SEC, NIS2, and DORA disclosure timelines during a security incident. He opens with a 3.47 a.m. call: the team cannot confirm whether customer data left the environment, yet three re…HELPNETSECURITY.COM
17 Jun3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker CrosshairsSOCRadar has detected 30,000 compromised Fortinet firewalls that expose networks to hacking. The post 3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs appeared first on SecurityWeek .SECURITYWEEK.COM
17 JunKodak confirms data breach claimed by ShinyHunters extortion gangKodak has confirmed that it's working with external cybersecurity experts to investigate a security breach after hackers gained access to some of the company's data. [...]BLEEPINGCOMPUTER.COM
17 JunMalicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot ChatsCybersecurity researchers have flagged a "coordinated malware campaign" on the JetBrains Marketplace that has published no less than 15 malicious plugins capable of exfiltrating artificial intelligence (AI) provider keys. "Every plugin poses as an AI coding assistant built on Dee…THEHACKERNEWS.COM
17 JunEU Security Experts to Support Ukrainian Organizations in Case of Cyber-AttacksUkraine has been added to the EU Cybersecurity Reserve, which provides incident response services against large-scale incidentsINFOSECURITY-MAGAZINE.COM
17 JunVelocityEHS uses QR codes to speed up incident reporting and risk responseVelocityEHS has announced the launch of QR Codes for Incident Management, a new feature designed to eliminate friction in safety reporting and help organizations surface incidents and near misses, identify risks, and take action. By enabling instant, mobile access to reporting to…HELPNETSECURITY.COM
17 JunSweeping Credential-Harvesting Heist Compromises +30K Fortinet DevicesAttackers actively are targeting various sectors across nearly 200 countries and have already compiled a list of working credentials for tens of thousands of compromised devicesDARKREADING.COM
17 JunWebinar Today: How Modern Breaches Bypass MFA and Evade DetectionAttendees will learn how attackers evade conventional detection methods, why legacy MFA alone is no longer sufficient, and how organizations can strengthen their defenses. The post Webinar Today: How Modern Breaches Bypass MFA and Evade Detection appeared first on SecurityWeek .SECURITYWEEK.COM
17 JunCalifornia water utility probes breach claim by Iran-linked actorThe group Handala said it attacked one of the nation’s largest water companies.CYBERSECURITYDIVE.COM
17 JunCanada introduces privacy law with GDPR-like penalties for data breachesThe Canadian government has introduced Bill C-36, a major privacy reform package that would recognize privacy as a fundamental right, expand consumer control over personal information, strengthen protections for children's data, and create a new regulator with the power to impose…CYBERINSIDER.COM
17 JunLow-skilled attacker used Claude, Codex to breach 14 companiesResearchers have long warned that AI agents could lower the skill floor for offensive cyber operations, and a recent report by OALABS (Open Analysis) researchers bears that out. After recovering and analyzing over 1,000 agent sessions from a compromised server on which an attacke…HELPNETSECURITY.COM
17 JunEU grants Ukraine access to cybersecurity reserve for major attacksAs Kyiv takes steps toward formal accession to the EU, the bloc is integrating Ukraine with its pool of pre-approved cybersecurity incident response companies.THERECORD.MEDIA
17 JunCybercriminals allegedly hacked tens of thousands of Fortinet firewalls used by major companies all over the worldAn alleged Russian-speaking group of cybercriminals is reportedly compromising and targeting several major companies that use Fortinet Firewalls and VPNs through previously known passwords.TECHCRUNCH.COM
17 JunAI is accelerating cyberattacks—here’s how to stay aheadSee how Microsoft unifies identity and security signals to help teams prevent, detect, and respond to AI-accelerated attacks faster. The post AI is accelerating cyberattacks—here’s how to stay ahead appeared first on Microsoft Security Blog .TECHCOMMUNITY.MICROSOFT.COM
17 JunINC Ransomware Thrives by Mastering the BasicsAnd one of those basics is focusing on sectors where a ransomware disruption creates immediate pressure to pay up, like with healthcare.DARKREADING.COM
16 JunChinese Hackers Abused Google Workspace Rules to Steal Research and Defense EmailsA China-linked espionage group hid inside North American medical, academic, and military research networks for more than a year, quietly stealing sensitive research and defense email. The way in was a backdoor on their REDCap research servers that stole login credentials. The exf…THEHACKERNEWS.COM
16 JunSurvey: 94% of Incidents Involve Anonymized Infrastructure. Teams Are Still ReactiveSecurity teams have never had more IP data at their disposal. Every day, analysts ingest enrichment feeds, geolocation data, reputation scores, telemetry, and threat intelligence from a growing ecosystem of vendors and platforms. Yet despite this abundance of information, many or…THEHACKERNEWS.COM
16 JunImaging giant Kodak confirms hackers breached systems and stole dataKodak says it is investigating a cybersecurity incident after the ShinyHunters extortion group claimed to have stolen more than 2.2 million records containing customer personally identifiable information (PII) and internal corporate data. The company confirmed that an unauthorize…CYBERINSIDER.COM
16 JunUK to require ID or face scan before you can make social media accountsOpening a new social media account in the UK will soon mean proving you're over 16 with an ID upload or a facial age scan, under a government ban on under-16s taking effect in spring 2027. Security experts warn the age checks are easy to circumvent and create new data-breach risk…BLEEPINGCOMPUTER.COM
16 Jun'Lorem Ipsum' Malware Pivots to ClickFix DeliveryNew analysis shows the campaign, which uses compromised WordPress sites, may be linked to the ransomware and data extortion group Vice Society.DARKREADING.COM
16 JunAI adoption correlates with incident frequency, underscoring need for governanceEven organizations that haven’t yet been breached expect an AI-related incident in the near future, a new survey found.CYBERSECURITYDIVE.COM
16 JuniRhythm Confirms Data Stolen in HackThe digital health company said it learned of the breach on June 8 and the attackers demanded a ransom. The post iRhythm Confirms Data Stolen in Hack appeared first on SecurityWeek .SECURITYWEEK.COM
15 JunWeekly Update 508Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite Light switches. How on earth is it so hard to find decent light switches?! It sounds ridiculous until you actually spend enough time lo…TROYHUNT.COM
15 JunOne-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA CodesA single click on a trusted Microsoft link could have let an attacker pull emails, calendar details, and indexed files out of Microsoft 365 Copilot Enterprise Search. Researchers at Varonis Threat Labs chained three bugs into a one-click exfiltration path they call SearchLeak. Be…THEHACKERNEWS.COM
15 JunInfinite Campus - 137,123 breached accountsIn March 2026, the student information system Infinite Campus was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data they alleged was taken from Infinite Campus, containing 137k unique email addresses along with names, phone number…HAVEIBEENPWNED.COM
15 JunAnthropic suspends Fable and Mythos over US national security concerns.US state attorneys general open an investigation into OpenAI. Maine takes its breach reporting database offline.THECYBERWIRE.COM
15 JunMaine closes data breach portal to the public after fake reportsMaine is still allowing companies to report breaches, but won’t make the portal easily available to the public until after it completes an audit of its procedures to stop such incidents, according to a press release from the Maine attorney general’s office.THERECORD.MEDIA
15 JunAdriatic Port Cyber-Attack by Anubis Sparks Warning Over Maritime Security RisksHow the Anubis ransomware group stole and leaked an Italian Adriatic port authority's dataINFOSECURITY-MAGAZINE.COM
15 JunMaine Takes Breach Reporting Portal Offline After Fake EntriesThe Office of the Maine Attorney General has suspended its breach reporting portalINFOSECURITY-MAGAZINE.COM
15 Jun15th June – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 15th June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The University of Nottingham, a UK research university, has suffered a data breach after ShinyHunters accessed its student records sy…RESEARCH.CHECKPOINT.COM
15 JunAkira ransomware spotted using LimeWire service for data theftAn Akira ransomware affiliate used Easyupload.io, a file-sharing service operated by LimeWire, to exfiltrate stolen data during a recent attack. The incident was detected on May 29 after Huntress' SOC identified unauthorized remote access to a domain controller. Although the init…CYBERINSIDER.COM
15 JunOptinMonster WordPress plugin hacked in CDN supply-chain attackWordPress plugins OptinMonster, TrustPulse, and PushEngage have been compromised in a supply-chain attack impacting Awesome Motive-s content distribution network (CDN). [...]BLEEPINGCOMPUTER.COM
15 JunCouncil of Europe investigates ShinyHunters data breach claimsThe Council of Europe, the continent's oldest intergovernmental body, is probing claims of a data breach made by the ShinyHunters extortion group over the weekend. [...]BLEEPINGCOMPUTER.COM
15 JunChinese hackers breach REDCap servers, steal medical researchA China-linked espionage campaign targeted exposed REDCap servers to deploy the InfiniteRed malware and steal sensitive data from a medical institution in North America. [...]BLEEPINGCOMPUTER.COM
15 JunRansomware Attack Shuts Down Mills of Australia’s Second-Largest Sugar ProducerMackay Sugar was targeted in a cyberattack carried out by a threat group known as The Gentlemen. The post Ransomware Attack Shuts Down Mills of Australia’s Second-Largest Sugar Producer appeared first on SecurityWeek .SECURITYWEEK.COM
15 JunUkrainian Man Pleads Guilty in US to Conti Ransomware ChargesOleksii Oleksiyovych Lytvynenko admitted to working on the development of a loader for the Conti gang. The post Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges appeared first on SecurityWeek .SECURITYWEEK.COM
15 JunOzempic Maker Novo Nordisk Says Hackers Breached IT SystemsThe pharmaceutical giant says the attackers gained access to personal data stored on the compromised systems. The post Ozempic Maker Novo Nordisk Says Hackers Breached IT Systems appeared first on SecurityWeek .SECURITYWEEK.COM
15 JunFrench Government Messaging Platform Breached by Mysterious ‘Misere’ HackerFrench officials say roughly 73,000 government accounts were affected, while the threat actor claims to have stolen messages and user data from the sovereign Tchap platform. The post French Government Messaging Platform Breached by Mysterious ‘Misere’ Hacker appeared first on Sec…SECURITYWEEK.COM
15 JunMaine Disables Data Breach Portal Due to Fake SubmissionsSomeone posted fake VRChat and Discord data breach reports on the system, prompting the Maine AG to take action. The post Maine Disables Data Breach Portal Due to Fake Submissions appeared first on SecurityWeek .SECURITYWEEK.COM
15 JunChina-Nexus Actor Spy on US Researchers Undetected for a YearGoogle discovered and disrupted the sprawling campaign, which stole RedCAP credentials to target numerous institutions and exfiltrate sensitive data.DARKREADING.COM
15 JunThe Beginning of the End of Social EngineeringAI-native operating systems are shifting the responsibility to stay vigilant against social engineering cyberattacks from the user onto the system itself.DARKREADING.COM
15 JunUkrainian national pleads guilty in connection with Conti ransomwareA Ukrainian national pleaded guilty to conspiracy to commit wire fraud in connection with the deployment of Conti ransomware, which targeted more than 1,000 victims worldwide. According to the U.S. Department of Justice, 44-year-old Oleksii Oleksiyovych Lytvynenko joined the Cont…HELPNETSECURITY.COM
15 JunInside the Modern SOC: The 72-Minute RaceAttackers can move from access to exfiltration in 72 minutes. Learn how modern SOC teams close the speed gap with Unit 42's AI-driven automation, threat hunting, MDR and Managed XSIAM. The post Inside the Modern SOC: The 72-Minute Race appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
13 JunCyberTitan Champions: Inside Canada's National High School Cybersecurity Competition (and CyberPatriot)Cybersecurity Today on the Weekend interviews the winning Canadian CyberTitan team ("S-ores"/a regex-based name) along with coach Phil, educator Tim, and CyberTitan manager Sheena to explain how CyberTitan (run by ICTC) connects to the international CyberPatriot program. They des…CYBERSECURITYTODAY.LIBSYN.COM
13 JunThe FBI built its own replica small town to simulate real-world cyberattacksHidden inside a building in Alabama, the FBI has created its own small town as a dedicated cyber training ground for simulating cyberattacks.TECHCRUNCH.COM
13 JunEx-school district employee jailed for hacks on former employerA former IT employee at an Iowa school district was sentenced to 21 months in prison after conducting a prolonged cyberattack against the former employer that disrupted classroom operations, deleted accounts, and caused tens of thousands of dollars in damages. [...]BLEEPINGCOMPUTER.COM
12 JunEuropol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware GangsAuthorities in Europe have disrupted AudiA6, a cryptocurrency laundering service used by ransomware gangs and cybercriminal networks. Europol, in a statement issued Thursday, said the dismantling of AudiA6 cut off a "key financial pipeline used to wash hundreds of millions in ill…THEHACKERNEWS.COM
12 JunOver 73,000 French govt employees affected in Tchap messenger breachThe French government revealed that a recent breach of its Tchap encrypted messaging platform affects the accounts of over 73,000 employees in the French public sector. [...]BLEEPINGCOMPUTER.COM
12 JunRansomware Payment Crypto Laundering Platform Taken Out by FBI and EuropolDomain of dark web money laundering platform AudiA6 seized and suspects arrested in joint operation by the FBI, Europol and othersINFOSECURITY-MAGAZINE.COM
12 JunSouth Korea hits Coupang with record $409 million fine over data breachThe penalty is the largest ever issued by the commission for a personal data breach, surpassing the record 134.8 billion won ($88.8 million) fine levied against SK Telecom earlier this year.THERECORD.MEDIA
12 JunAgentic AI surges in financial sector even as many firms fail to manage security risksOne-fifth of firms aren’t even sure if they’ve been hacked through their AI tools, according to a new report.CYBERSECURITYDIVE.COM
12 JunIn Other News: Google Security Layoffs, AudiA6 Takedown, $400 Million Coupang FineOther noteworthy stories that might have slipped under the radar: ICS device exposure remains flat as attack surface widens, Microsoft issues incident response playbook for AI, IBM and AT&T accused of hack cover-ups. The post In Other News: Google Security Layoffs, AudiA6 Ta…SECURITYWEEK.COM
12 JunBankruptcy admin approves settlement fund of $47 million for 23andMe data breach victimsAbout 7 million customers of the genetics testing company had their data stolen by hackers starting in April 2023, and many had their information posted on the dark web.THERECORD.MEDIA
12 JunConti ransomware group member pleads guilty, faces up to 20 years in prisonOleksii Lytvynenko, a 44-year-old Ukrainian national, admitted to joining the prolific cybercrime group in 2021. Officials said he engaged in cybercrime up until his arrest in Ireland in 2023. The post Conti ransomware group member pleads guilty, faces up to 20 years in prison ap…CYBERSCOOP.COM
12 JunUkrainian national pleads guilty to role in Conti ransomware operationA Ukrainian national extradited from Ireland to the United States last year has pleaded guilty to conspiracy charges tied to the Conti ransomware operation. [...]BLEEPINGCOMPUTER.COM
12 JunOver 400 Arch Linux packages compromised to push rootkit, infostealerMore than 400 packages in the Arch User Repository (AUR) are distributing a Linux rootkit and infostealer malware targeting credentials and access tokens. [...]BLEEPINGCOMPUTER.COM
12 JunMaine disables data breach notification portal after fake disclosuresMaine has taken its public data breach reporting portal offline after fraudulent breach disclosures were published on the state's website, prompting a review of procedures to prevent abuse in the future. [...]BLEEPINGCOMPUTER.COM
11 JunPrompt injection still drives most agentic AI security failures in productionA backdoor sat on PyPI for three hours in March 2026. Nearly 47,000 downloads occurred during the window. The compromised package, LiteLLM, serves as the language-model gateway for CrewAI, DSPy, Microsoft GraphRAG, and dozens of other AI agent frameworks. Anyone pulling an update…HELPNETSECURITY.COM
11 JunNottingham University data breach affects over 450,000 studentsThe University of Nottingham confirmed on Wednesday that a hacking group gained access to its student records system in a breach affecting both current students and alums. [...]BLEEPINGCOMPUTER.COM
11 JunUniversity of Nottingham Confirms Breach After Hackers Leak DataThe ShinyHunters hacker group has taken credit for the attack, leaking more than 450,000 email addresses and other information. The post University of Nottingham Confirms Breach After Hackers Leak Data appeared first on SecurityWeek .SECURITYWEEK.COM
11 JunExtortion-Only Attacks Increase, With Data Theft Dominating Ransomware ClaimsExtortion-only attacks are increasing as data theft drives most ransomware claims, with many organizations unable to stop stolen data from being exposedINFOSECURITY-MAGAZINE.COM
11 JunCybersecurity Stars Awards 2026: Winners Announced Across 95 CategoriesMost good security work is invisible by design. Today is the exception. The 2026 Cybersecurity Stars Awards winners are announced across 95 subcategories in four main award categories. The reason is simple. Cybersecurity is full of work that deserves recognition and rarely gets i…THEHACKERNEWS.COM
11 JunSouth Korea hits Coupang with $400M+ fine for data breach that affected millionsSouth Korean authorities issued the record-breaking fine following a data breach that affected over 30 million customers.TECHCRUNCH.COM
11 JunUniversity of Nottingham confirms cyber incident as Shiny Hunters group claims data theftAccording to the university’s statement, it is still working to understand what data has been accessed and said it had already directly contacted affected students and alumni, potentially including those in its foreign campuses in Malaysia and China as well as in Nottingham.THERECORD.MEDIA
11 JunAI Is Upgrading Hackers FastAI is rapidly increasing the effectiveness of cyber attackers at every level. Tasks that once required deeper expertise can now be automated, accelerated, or simplified with AI-assisted tooling. That shift compresses the gap between inexperienced, mid-tier, and highly advanced th…YOUTUBE.COM
11 JunGerman court holds Google liable for AI-generated claims.OpenAI disrupts two China-linked influence operations. Cyberattack disrupts Australian sugar mills.THECYBERWIRE.COM
11 JunBritish high school sends students home following cyberattackGreat Marlow School, which has 1,428 pupils according to the Department for Education (DfE), said it was set to remain closed while it works with specialist IT and cybersecurity professionals to resolve the issue.THERECORD.MEDIA
11 JunRussian national charged in connection with Void Blizzard espionage campaignDenis Obrezko accused of orchestrating cyberattacks that compromised at least 11 U.S. companies as part of the Kremlin-linked group's sprawling espionage operation.\ The post Russian national charged in connection with Void Blizzard espionage campaign appeared first on CyberScoop…CYBERSCOOP.COM
11 JunThe court calls Google’s bluff.Google faces liability for AI-generated claims. Washington pauses public AI model assessments. Anthropic ships a safer AI model. OpenAI disrupts influence operations. Ransomware operators get a powerful new backdoor. Urgent patches land for Ivanti and Veeam. PyPI supply chain att…THECYBERWIRE.COM
11 JunMaine breach portal abused to publish fake data breach disclosuresIn an unusual misinformation campaign, fraudulent data breach disclosures were submitted to Maine's official breach portal and publicly posted before their legitimacy could be verified, prompting companies to deny the claims. [...]BLEEPINGCOMPUTER.COM
10 JunWeekly Update 507Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite 1,000 breaches is one hell of a milestone. It's not just the process of getting data, verifying it, loading it, sending notificati…TROYHUNT.COM
10 JunOver a Quarter of Identity Crime Victims Hit by Multiple Incidents, ITRC Data ShowsNearly 26% of identity crime victims faced multiple incidents in the past year, as ITRC warns of a growing "multi-layered crisis"INFOSECURITY-MAGAZINE.COM
10 JunWhy schools remain one of cybercriminals’ favourite targetsSchools on both sides of the Atlantic have been revealed in recent days to have been hit by hackers, reminding all of us that ransomware gangs see educational instituions as targets all year round. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
10 JunCyberattack shuts down major Australian sugar mills, disrupting harvestAustralia's second-largest sugar producer said on Wednesday that it was responding to a cybersecurity incident affecting parts of its operations and had engaged cybersecurity experts and local authorities to investigate the attack and restore its systems safely.THERECORD.MEDIA
10 JunUniversity of Nottingham confirms hackers accessed student dataThe University of Nottingham has confirmed to CyberInsider in a statement that it suffered a cyber incident resulting in unauthorized access to data stored in its student record system. The disclosure comes after ShinyHunters listed the university on its leak site, alleging it ha…CYBERINSIDER.COM
10 JunOracle PeopleSoft servers hacked in ShinyHunters data theft attacksOracle PeopleSoft servers are being targeted in ongoing data theft attacks by the ShinyHunters extortion gang, which claims to have stolen data from over 100 organizations. [...]BLEEPINGCOMPUTER.COM
10 JunBug Bounty Research Triggers ServiceNow Security AlertBug bounty research inadvertently led organizations to believe they were being breached through their ServiceNow instances.DARKREADING.COM
10 JunCybercriminals claim breach of Oracle PeopleSoft servers at 100-plus organizationsThe ShinyHunters hacking gang claims to have compromised the Oracle PeopleSoft servers of more than 100 organizations, including many universities.TECHCRUNCH.COM
10 JunUniversity of Nottingham - 454,635 breached accountsIn June 2026, the University of Nottingham was the target of a cyber attack , later linked to a ShinyHunters "pay or leak" extortion campaign. Tens of gigabytes of data were subsequently published online and included 455k unique email addresses along with extensive personal infor…HAVEIBEENPWNED.COM
9 JunOpenAI’s Lockdown Mode is trying to solve the problem that it createdOpenAI’s move to implement a Lockdown Mode that tries to limit data exfiltration by shutting down external capabilities is being seen as making the best out of a bad situation. But Lockdown Mode doesn’t block exfiltration as much as it slightly reduces it, and the reality of ente…CSOONLINE.COM
9 JunCybersecurity jobs available right now: June 9, 2026Application Security Architect INTENSITY Global Group | Israel | Hybrid – View job details As an Application Security Architect, you will design secure application architectures, perform threat modeling and security assessments, define security standards and contr…HELPNETSECURITY.COM
9 JunHades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential StealerThe Miasma supply chain campaign has sparked a fresh attack wave called Hades, this time involving 37 malicious wheel artifacts across 19 packages in the Python Package Index (PyPI) registry, as the Mini Shai-Hulud-style attacks continue to be refined and splintered to target spe…THEHACKERNEWS.COM
9 JunFrench govt messaging service breached in account hijacking attackDINUM, the digital affairs directorate of the French government, warned that hackers used a hijacked user account to breach Tchap, the French government's encrypted messaging platform. [...]BLEEPINGCOMPUTER.COM
9 JunElastic brings AI-driven incident investigation to Kubernetes and observability toolsElastic has introduced an agentic Kubernetes investigation workflow and MCP-based observability skills that diagnose incidents the moment an alert fires. By the time an SRE opens the alert, the root cause has already been identified, evidence has been assembled, and recommended n…HELPNETSECURITY.COM
9 JunAnthropic Offers Mythos Upgrade for Cyber Partners and a ‘Safe’ Version for the Rest of YouAnthropic is releasing Claude Mythos 5 to trusted organizations and Claude Fable 5 to the public, a version it says can’t be used for cyberattacks.WIRED.COM
9 JunMiasma Supply Chain Worm Burrows Into 73 Microsoft RepositoriesThe attacks stemmed from a GitHub account that was also compromised in a previous Miasmi attack on Microsoft last month.DARKREADING.COM
8 JunClaude Outage Data Leak, Microsoft GitHub Worm, IBM Hack, M Instagram Takeovers, Canada's Bill C-8TClaude Outage Data Leak Fears, Microsoft GitHub Worm, IBM Hack Allegations, Meta AI Instagram Takeovers, and Canada's Bill C-8 David Shipley reports that Anthropic's Claude suffered a roughly two-hour outage affecting models including Opus, during which a user alleged receiving …CYBERSECURITYTODAY.LIBSYN.COM
8 JunCybercriminals create 19,000 FIFA-themed domains ahead of 2026 World CupFans looking for tickets, accommodation and match broadcasts are already encountering scams tied to the 2026 FIFA World Cup. The 2026 FIFA World Cup will bring millions of visitors and an estimated 6 billion spectators to a tournament spread across 16 host cities in the United St…HELPNETSECURITY.COM
8 JunOver 20,000 Instagram accounts stolen in Meta AI support hackMeta has revealed that over 20,000 Instagram users had their accounts hijacked in a recent incident where attackers used Meta's AI-powered support system to reset passwords. [...]BLEEPINGCOMPUTER.COM
8 JunWhen attacks spread too far: Lessons from real cyber attack case studiesIn this Help Net Security video, Michael Adjei, Director, Systems Engineering at Illumio, explains three real world cyber attacks and what went wrong during detection. Adjei walks through a collaboration tool scam that copied Microsoft Teams, an identity phishing case used for pa…HELPNETSECURITY.COM
8 JunMeta Says 20,000 Instagram Accounts Hacked via AI Tool AbuseThe social media giant has informed authorities about the impact of the recent attack involving an account recovery support tool. The post Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse appeared first on SecurityWeek .SECURITYWEEK.COM
8 JunSilent Ransom Group Uses DNS Fast Flux in AttacksFocusing on hacking law firms in the US, the ransomware group relies on fast flux to hide its C&C infrastructure. The post Silent Ransom Group Uses DNS Fast Flux in Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
8 Jun174,000 Impacted by Lansing Community College Data BreachHackers accessed personal information stored on certain Lansing Community College systems in February 2025. The post 174,000 Impacted by Lansing Community College Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
8 JunNew Shai-Hulud attack trojanizes 19 science-focused PyPI packagesHackers compromised 19 packages on the PyPI, collectively downloaded hundreds of thousands of times, in a new Shai-Hulud supply-chain attack that delivered malware designed to steal developer secrets. [...]BLEEPINGCOMPUTER.COM
8 JunSoFi confirms third-party data breach at Hong Kong subsidiarySoFi Hong Kong is warning that it suffered a data breach after hackers gained access to a database at a third-party vendor containing customer information. [...]BLEEPINGCOMPUTER.COM
8 JunNew Apple feature automatically changes your compromised passwordsAt WWDC 26, Apple announced an Apple Intelligence-powered feature that can automatically fix weak and compromised passwords. This works in Safari, and it's rolling out with iOS 27. [...]BLEEPINGCOMPUTER.COM
6 JunNew ChatGPT Lockdown Mode Limits Tools That Could Enable Data ExfiltrationOpenAI has begun rolling out a new Lockdown Mode to ChatGPT for eligible personal accounts to reduce the risk of data exfiltration arising from prompt injection attacks. The feature is primarily designed for people and organizations that handle sensitive data and require stricter…THEHACKERNEWS.COM
5 JunPCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay NetworkThe threat actor known as PCPJack has hijacked cloud servers associated with Amazon Web Services (AWS), Google Cloud, and Microsoft Azure to create a covert SMTP email relay network. "Compromised business servers across the U.S., Europe, and Asia were quietly converted into SMTP …THEHACKERNEWS.COM
5 JunBCD Travel - 396,313 breached accountsIn May 2026, the corporate travel management company BCD Travel was claimed as a victim of the ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from BCD was subsequently published publicly in early June and contained 396k unique email addresses. Other expos…HAVEIBEENPWNED.COM
5 JunNightclub Giant RCI Says Data Breach Affects 40,000 IndividualsThe company detected a network intrusion in March and an investigation showed that some files were stolen during the attack. The post Nightclub Giant RCI Says Data Breach Affects 40,000 Individuals appeared first on SecurityWeek .SECURITYWEEK.COM
5 JunAI is helping low-skill hackers pull off advanced cyberattacksAnthropic has published an analysis of cyber-related misuse of its AI systems, examining 832 accounts that were banned for malicious cyber activity between March 2025 and March 2026. The company mapped the observed behavior to the MITRE ATT&CK framework, which documents tact…HELPNETSECURITY.COM
5 JunNSA said to be readying Anthropic’s Mythos for use in cyber operationsThe U.S. eavesdropping agency is reportedly preparing Anthropic's Mythos for use in cyberattacks, despite a federal ban on using the AI model maker.TECHCRUNCH.COM
5 JunGoogle and FBI warn of ransomware group that sends fake IT workers to hack victims in personCybercriminals, part of a gang known as Silent Ransom Group, have sent people pretending to be IT support employees to law firms' offices, where the criminals have stolen data using USB drives or remote access tools.TECHCRUNCH.COM
5 JunMicrosoft identifies seven new ways AI agents can be hackedMicrosoft has identified seven new failure modes in agentic AI systems, in addition to those it identified last year in its first Taxonomy of Failure Modes in Agentic AI Systems . Four things contributed to the growing list of ways agentic AI can go wrong : the speed at which the…CSOONLINE.COM
5 JunChinese APT deploys new malware to keep access to hacked networksA Chinese espionage group tracked as UNC5221 has been accessing Microsoft 365 environments using the Brickstorm backdoor and previously undocumented malware named Plenet and AgentPSD. [...]BLEEPINGCOMPUTER.COM
5 JunFormer cyber executive turned whistleblower accuses IBM of covering up several data breachesIBM and two of its subsidiary companies were allegedly breached during the mid-2010s, which a lawsuit filed by a former cybersecurity executive accuses IBM of not disclosing and actively covering up.TECHCRUNCH.COM
5 JunExposed Fuel Tank Gauges Under Attack in the USThreat actors are taking advantage of Internet-exposed tank gauges by breaching gas stations, opening the door to disruption.DARKREADING.COM