SecurityWeek Aug 7, 2026, 10:00 AM (UTC)
Read
NMFTA research shows a Bendix EC80 brake controller safety recall also patched remote code execution and DoS vulnerabilities. The post Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix appeared first on SecurityWeek.
Infosecurity Magazine Aug 7, 2026, 09:40 AM (UTC)
Read
BlackFile has rebranded as Redact after an alleged affiliate hijack, with Google linking the group to ongoing vishing and extortion campaigns
The Hacker News Aug 7, 2026, 09:32 AM (UTC)
Read
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. Presented at…
SecurityWeek Aug 7, 2026, 09:24 AM (UTC)
Read
Companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas. The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 4) appeared first on SecurityWeek.
SecurityWeek Aug 7, 2026, 09:09 AM (UTC)
Read
Microsoft fixed critical vulnerabilities across Azure, Entra, and SharePoint, while Apple patched a high-severity authentication bypass. The post Microsoft, Apple Release Fresh Security Updates appeared first on SecurityWeek.
The Hacker News Aug 7, 2026, 08:52 AM (UTC)
Read
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, disclose victim IP addresses and mapped ports, and exhaust…
Infosecurity Magazine Aug 7, 2026, 08:20 AM (UTC)
Read
Finance, technology and healthcare sectors were particularly heavily targeted in July, according to Comparitech
The Hacker News Aug 7, 2026, 08:18 AM (UTC)
Read
A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough to hijack the next agent run. Novee Security ran the attack…
SecurityWeek Aug 7, 2026, 07:22 AM (UTC)
Read
Hackers stole personal, medical, and health insurance information from a company’s data center. The post 3.8 Million Impacted by Unlimited Technology Systems Data Breach appeared first on SecurityWeek.
SecurityWeek Aug 7, 2026, 06:56 AM (UTC)
Read
The browser refresh eliminates over two dozen memory safety bugs, including critical use-after-free flaws. The post Critical Vulnerabilities Patched With Chrome 151 Update appeared first on SecurityWeek.
The Hacker News Aug 7, 2026, 06:50 AM (UTC)
Read
A new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training their sights on the software…
BleepingComputer Aug 6, 2026, 10:48 PM (UTC)
Read
OpenAI is rolling out a more reliable version of ChatGPT GPT-5.6 Sol for Plus and Pro users, while Free users are getting unlimited text chats with GPT-5.6 Luna. [...]
BleepingComputer Aug 6, 2026, 10:37 PM (UTC)
Read
A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. [...]
BleepingComputer Aug 6, 2026, 08:07 PM (UTC)
Read
A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile threat actors. [...]
BleepingComputer Aug 6, 2026, 06:14 PM (UTC)
Read
Switzerland's federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. [...]
BleepingComputer Aug 6, 2026, 06:03 PM (UTC)
Read
Researchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines. [...]
The Hacker News Aug 6, 2026, 05:58 PM (UTC)
Read
Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests.…
The Hacker News Aug 6, 2026, 05:13 PM (UTC)
Read
Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review. The security issues affect Cisco Catalyst SD-WAN Software, regardless of devic…
Krebs on Security Aug 6, 2026, 05:00 PM (UTC)
Read
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake.…
The Hacker News Aug 6, 2026, 04:17 PM (UTC)
Read
An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using it, re-poisoning the predictor after the defense has run. MIT CSAIL researchers Daniël Trujillo and Mengjia…
BleepingComputer Aug 6, 2026, 04:11 PM (UTC)
Read
Meta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents continue to emerge following OpenAI'sOpenAI's initial disclosure that its agents breached Hugging Face. [...]
Infosecurity Magazine Aug 6, 2026, 03:30 PM (UTC)
Read
Attackers used SQL injection to compile a post-exploitation toolkit inside an Oracle database
The Hacker News Aug 6, 2026, 03:24 PM (UTC)
Read
Apparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF can finish the job. This week runs on cheap leverage: exposed servers, recycled bugs, poisoned agent instructions…
SecurityWeek Aug 6, 2026, 02:56 PM (UTC)
Read
Connor Riley Moucka was extradited to the United States in July 2025 after he was arrested in Canada. The post Snowflake Hacker Pleads Guilty in US Court appeared first on SecurityWeek.
Infosecurity Magazine Aug 6, 2026, 02:15 PM (UTC)
Read
Oligo Security has linked TeamPCP to ShadowRay 2.0 and to cryptojacking infrastructure dating back to 2020
BleepingComputer Aug 6, 2026, 02:02 PM (UTC)
Read
AI did not create a new browser security problem. It exposed one that enterprises have long been able to ignore. Skyhigh Security explains why browsers have become a critical control point for governing data movement, AI interactions, and modern work. [...]
Infosecurity Magazine Aug 6, 2026, 01:40 PM (UTC)
Read
One of Meta’s AI models exploited a third-party security flaw during an evaluation, the latest in a series of similar incidents involving advanced AI systems
Cybersecurity Ventures Aug 6, 2026, 01:03 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 6, 2026 – Cybersecurity VC Deal Flow Tracker During Black Hat USA 2026 at the Mandalay Bay Convention Center in Las Vegas this week, outdoor daytime high temperatures r…
SecurityWeek Aug 6, 2026, 12:54 PM (UTC)
Read
Zenity researchers reported the findings to Anthropic and OpenAI in late 2025 and early 2026, but they remain unpatched. The post Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts appeared first on SecurityWeek.
The Hacker News Aug 6, 2026, 12:16 PM (UTC)
Read
Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network. Its August 3 scan counted 4,407 exposed Rockwell controllers…
SecurityWeek Aug 6, 2026, 12:00 PM (UTC)
Read
(Video) In this podcast, we share insights from Edna Conway, a recognized leader in cybersecurity and supply chain resilience with over 40 years of experience in the field. The post Podcast: Compliance Won’t Save You: The Future of Cyber Risk with Edna Conway…
Infosecurity Magazine Aug 6, 2026, 12:00 PM (UTC)
Read
So-called “wrench attacks” have resulted in $30m in losses so far in 2026, says Chainalysis
The Hacker News Aug 6, 2026, 11:49 AM (UTC)
Read
Coinspect has identified CryptoJS.lib.WordArray.random() as the weak random number generator behind the Ill Bloom wallet drains. Introduced in the JavaScript cryptography library 12 years ago, the function supplied weak entropy that affected wallet apps used t…
The Hacker News Aug 6, 2026, 11:33 AM (UTC)
Read
Cybersecurity researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address. Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to ensure users' privacy by routing their Sa…
The Hacker News Aug 6, 2026, 11:30 AM (UTC)
Read
A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses a standard feature built into almost every major AI assistant: pre-filled deep links. We observed product…
SecurityWeek Aug 6, 2026, 11:09 AM (UTC)
Read
An attacker could self-register, sign in for board-level API access, and import a new company for code execution. The post Critical Paperclip Flaw Allowed Admin Access, Code Execution appeared first on SecurityWeek.
Infosecurity Magazine Aug 6, 2026, 10:15 AM (UTC)
Read
A Canadian hacker has admitted involvement in the widespread compromise of 165 Snowflake customer accounts used to steal data and extort victims
SecurityWeek Aug 6, 2026, 09:56 AM (UTC)
Read
The incident involved a testing environment set up by Irregular, similar to what Anthropic reported last week. The post Meta AI Hacked External Systems During Cybersecurity Testing appeared first on SecurityWeek.
The Hacker News Aug 6, 2026, 09:19 AM (UTC)
Read
Attackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Oracle comp…
The Hacker News Aug 6, 2026, 08:57 AM (UTC)
Read
Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent's tools with no check that a model turn had authorized them. In several of the attack paths, the model never ran at al…
Infosecurity Magazine Aug 6, 2026, 08:30 AM (UTC)
Read
The Open Secure AI Alliance has announced plans for the Shared AI Findings Exchange (SAFE)
The Hacker News Aug 6, 2026, 08:05 AM (UTC)
Read
Cybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models from Zbtlink. According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtli…
The Hacker News Aug 6, 2026, 07:19 AM (UTC)
Read
A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel, the ransomware-as-a-service operation he stood up in 2021. Between 2021 and 2023, Ransom Cartel conspirators attacked a…
The Hacker News Aug 6, 2026, 06:51 AM (UTC)
Read
A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The vulnerability in question is CVE-2026-63077 (CV…
The Hacker News Aug 6, 2026, 06:04 AM (UTC)
Read
Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts. The intrusions reached at least 165 organizations…
BleepingComputer Aug 5, 2026, 11:00 PM (UTC)
Read
Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide. [...]
BleepingComputer Aug 5, 2026, 09:53 PM (UTC)
Read
A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. [...]
BleepingComputer Aug 5, 2026, 07:55 PM (UTC)
Read
Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. [...]
The Hacker News Aug 5, 2026, 06:44 PM (UTC)
Read
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks. The server-side…
The Hacker News Aug 5, 2026, 06:33 PM (UTC)
Read
OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that end, it banned a coor…
BleepingComputer Aug 5, 2026, 05:49 PM (UTC)
Read
A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. [...]
BleepingComputer Aug 5, 2026, 03:51 PM (UTC)
Read
The U.S. Cybersecurity and Infrastructure Security Agency is giving federal agencies three days to mitigate vulnerabilities in IBM Langflow, N-central, and Apache Tomcat, all actively exploited. [...]
The Hacker News Aug 5, 2026, 03:36 PM (UTC)
Read
Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms. One such service, Poison Claude, claims to offer access…
Infosecurity Magazine Aug 5, 2026, 03:30 PM (UTC)
Read
77 counterfeit Open VSX extensions beaconed to one domain, 19 harvesting git and CI identity
The Hacker News Aug 5, 2026, 03:14 PM (UTC)
Read
Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent a…
BleepingComputer Aug 5, 2026, 02:59 PM (UTC)
Read
Google has locked hundreds of Blogger websites after a false positive claimed they violated its "Malware and Similar Malicious Content" policy, with some sites deleted from the platform. [...]
Infosecurity Magazine Aug 5, 2026, 02:30 PM (UTC)
Read
3 Paperclip flaws exposed data & allowed unauthenticated command execution in two deployment modes
The Hacker News Aug 5, 2026, 02:27 PM (UTC)
Read
HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious: An unauthenticated flaw in Veeam's console that hands over a managed agent's c…
BleepingComputer Aug 5, 2026, 02:01 PM (UTC)
Read
AI is helping attackers create disposable phishing infrastructure and rapidly evolving toolkits that blocklists cannot track fast enough. Push Security explains why browser-level, technique-based detection offers a more durable defense than relying on domains,…
The Hacker News Aug 5, 2026, 01:41 PM (UTC)
Read
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer. The new dead drop re…
Cybersecurity Ventures Aug 5, 2026, 01:02 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 4, 2026 – Watch the YouTube short “ILOVEYOU“, sometimes referred to as the Love Bug or Loveletter, was a computer worm that infected tens of millions of Windows compute…
The Hacker News Aug 5, 2026, 11:43 AM (UTC)
Read
A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel builds. The vulnerabilit…
The Hacker News Aug 5, 2026, 11:43 AM (UTC)
Read
Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft's real authentication page. Once access and refresh tokens are i…
The Hacker News Aug 5, 2026, 11:04 AM (UTC)
Read
An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Org-mode markup are enough. The flaw i…
Infosecurity Magazine Aug 5, 2026, 11:00 AM (UTC)
Read
Prompt injection remains the most dangerous security threat to LLMs, according to OWASP’s latest Top 10 LLM Applications list
The Hacker News Aug 5, 2026, 10:35 AM (UTC)
Read
GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software vulnerability. We scanne…
Infosecurity Magazine Aug 5, 2026, 10:00 AM (UTC)
Read
A new npm worm has compromised packages with over two billion monthly installs
The Hacker News Aug 5, 2026, 09:23 AM (UTC)
Read
A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed. The "evil twin" extensions were uploaded…
Infosecurity Magazine Aug 5, 2026, 08:45 AM (UTC)
Read
Anthropic and OpenAI models attacked “real people and organizations” during AI Security Institute tests
Infosecurity Magazine Aug 5, 2026, 08:00 AM (UTC)
Read
Cybercriminals are using a fake Bank of America phishing campaign to trick users into downloading a malicious script that installs ScreenConnect, enabling remote access and persistence on compromised systems
The Hacker News Aug 5, 2026, 07:53 AM (UTC)
Read
An agent running Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber evaluation by the UK's AI Security Institute. When a bystander publicly warned that the code was malicious, the ag…
The Hacker News Aug 5, 2026, 07:40 AM (UTC)
Read
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The list of vulnerabilities is as follows - CVE-202…
The Hacker News Aug 5, 2026, 05:47 AM (UTC)
Read
Cybersecurity researchers have disclosed what has been described as a "long-standing supply chain attack" on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users. According to Fortinet FortiGuard Labs, the…
BleepingComputer Aug 4, 2026, 11:39 PM (UTC)
Read
OpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incidents that resulted in a real website being breached and social engineering attacks against people outside the intended te…
The Hacker News Aug 4, 2026, 05:27 PM (UTC)
Read
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass M…
Infosecurity Magazine Aug 4, 2026, 02:30 PM (UTC)
Read
WhatsApp scam abused the Linked devices feature to hijack accounts without stealing any passwords
The Hacker News Aug 4, 2026, 01:30 PM (UTC)
Read
A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep verified 353 poisoned versions across 79 package names in the np…
Infosecurity Magazine Aug 4, 2026, 01:30 PM (UTC)
Read
Talos read attacker prompt logs and found guardrails fell to task splitting and ownership claims
The Hacker News Aug 4, 2026, 01:11 PM (UTC)
Read
Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Moni…
Cybersecurity Ventures Aug 4, 2026, 01:08 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 4, 2026 – Listen to the podcast “This wasn’t someone behind the keyboard using AI as a tool to write malware,” says Heather Engel, guest expert on the Cybercrime Magazi…
The Hacker News Aug 4, 2026, 11:30 AM (UTC)
Read
The cybersecurity industry has spent decades assuming that offensive capability scales with technical expertise. That assumption is starting to break. Security teams have long estimated risk by ranking attacker sophistication. Nation-state actors sat at one en…
Infosecurity Magazine Aug 4, 2026, 11:30 AM (UTC)
Read
Cloud and SaaS are now the preferred operating environments for threat actors, amid a continued shift to identity attacks
The Hacker News Aug 4, 2026, 11:16 AM (UTC)
Read
Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing agent. The researchers said the public ag…
The Hacker News Aug 4, 2026, 10:36 AM (UTC)
Read
cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity. It shipped in a targeted security relea…
Infosecurity Magazine Aug 4, 2026, 10:00 AM (UTC)
Read
Interpol claims AI is driving a surge in cybercrime in Africa, with related losses doubling
The Hacker News Aug 4, 2026, 09:03 AM (UTC)
Read
A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceM…
Infosecurity Magazine Aug 4, 2026, 08:40 AM (UTC)
Read
The UK’s Police National Legal Database and Ask the Police service have been breached
The Hacker News Aug 4, 2026, 07:00 AM (UTC)
Read
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild. The vulnerabili…
The Hacker News Aug 3, 2026, 06:43 PM (UTC)
Read
Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-spea…
The Hacker News Aug 3, 2026, 04:24 PM (UTC)
Read
Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim's screen. Unit 42 detailed three attack paths against Chrome's Google Password…
The Hacker News Aug 3, 2026, 04:15 PM (UTC)
Read
The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the…
Infosecurity Magazine Aug 3, 2026, 03:00 PM (UTC)
Read
Chinese actors exploited the critical React2Shell exploit inside a day, while 88% of exploited vulnerabilities in H1 2026 were compromised within 48 hours of disclosure
Infosecurity Magazine Aug 3, 2026, 02:30 PM (UTC)
Read
Russian actor Storm-2945 hijacked hotel captive portals to push fake updates and steal tokens
The Hacker News Aug 3, 2026, 02:03 PM (UTC)
Read
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most…
Cybersecurity Ventures Aug 3, 2026, 01:04 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 3, 2026 – Read the full story in Reddit The Cybercrime Magazine Podcast stands out as a leading resource for CISOs looking to stay updated on cybersecurity trends in 20…
The Hacker News Aug 3, 2026, 11:30 AM (UTC)
Read
AI is moving incredibly fast, and every security leader is feeling the pressure to keep up. AI platforms like Claude, Codex and Cursor are already helping security teams write detections, investigate alerts, summarize incidents, and automate repetitive work. T…
Infosecurity Magazine Aug 3, 2026, 11:26 AM (UTC)
Read
New HollowFrame loader hid Go code in a fake Python DLL after pre-staging Defender exclusions
The Hacker News Aug 3, 2026, 10:49 AM (UTC)
Read
An unknown Chinese-speaking threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit. Attack surface management platform Censys said it identified the threat actor runnin…
Infosecurity Magazine Aug 3, 2026, 09:36 AM (UTC)
Read
Korean telco KT has been fined $39m for a year-long breach linked to femtocell compromise
The Hacker News Aug 3, 2026, 09:13 AM (UTC)
Read
The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web. The data included names, organisations and work email addresses belonging to police officers, police…
Infosecurity Magazine Aug 3, 2026, 08:40 AM (UTC)
Read
A hacker has drained nearly $89m from Coldcard Bitcoin wallets after exploiting a legacy bug
The Hacker News Aug 3, 2026, 08:05 AM (UTC)
Read
Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them. The vendor's July 31 security bulletin says nearly undetectable changes to .fs…
The Hacker News Aug 3, 2026, 06:41 AM (UTC)
Read
N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers. Its first fix was incomplete. CVE-2026-18577 affects N-central builds prior to 2026.3.1.7.…
The Hacker News Aug 3, 2026, 06:40 AM (UTC)
Read
Three high-severity security flaws have been disclosed in Hugging Face's Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) supply chain to secur…
Infosecurity Magazine Jul 31, 2026, 03:00 PM (UTC)
Read
A Chinese-speaking threat actor has been using DeepSeek’s AI models to orchestrate cyber-attacks targeting Asian organizations
Cybersecurity Ventures Jul 31, 2026, 01:11 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 31, 2026 – Listen to the podcast “The exploit lands before the fix even ships,” says John Vecchi, CMO at Mitiga, a leader in zero-impact breach prevention for cloud, Sa…
Infosecurity Magazine Jul 31, 2026, 09:50 AM (UTC)
Read
AWS has linked North Korea to the axios campaign to other attacks on npm libraries
Infosecurity Magazine Jul 31, 2026, 08:35 AM (UTC)
Read
Anthropic has revealed that Claude AI models compromised third-party organizations
Krebs on Security Jul 30, 2026, 04:49 PM (UTC)
Read
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking…
Infosecurity Magazine Jul 30, 2026, 02:30 PM (UTC)
Read
Cryptomining crew abandoned root to impersonate low-privileged Linux users and evade SOC alerts
Infosecurity Magazine Jul 30, 2026, 02:00 PM (UTC)
Read
AiTM phishing is now the top entry point into law firms, with identity behind 56% of threats
Infosecurity Magazine Jul 30, 2026, 01:00 PM (UTC)
Read
Action1 report finds sysadmins overestimated their use of AI in predictions made two years ago
Infosecurity Magazine Jul 30, 2026, 12:00 PM (UTC)
Read
Check Point researchers detail phishing attack as an example of attackers dropping fake Microsoft login pages in favor of abusing Microsoft’s legitimate authentication infrastructure
Infosecurity Magazine Jul 30, 2026, 09:15 AM (UTC)
Read
The new version of Chrome, 151, comes with 370 vulnerability patches, including for seven critical flaws
Infosecurity Magazine Jul 30, 2026, 08:25 AM (UTC)
Read
The UK’s National Cyber Security Centre wants network device makers to improve forensic observability
Infosecurity Magazine Jul 29, 2026, 04:00 PM (UTC)
Read
LogoKit now builds per-victim phishing pages using live screenshots of the target's real website
Infosecurity Magazine Jul 29, 2026, 03:10 PM (UTC)
Read
TA488 returned with OWA half-click exploit deploying OWAReaper implant that survived re-imaging
Cybersecurity Ventures Jul 29, 2026, 12:57 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 29, 2026 – Listen to the podcast Bent is the story of John J. Boseak’s phenomenal life of crime. Inked from head to toe, with an addiction to strippers and fast Cadilla…
Infosecurity Magazine Jul 29, 2026, 11:00 AM (UTC)
Read
IBM Cost of a Data Breach Report warns that the global average cost of a data breach has reached a record high of $4.99m – and AI-backed attacks have played a role
Infosecurity Magazine Jul 29, 2026, 10:15 AM (UTC)
Read
For now, the use of AI benefits vulnerability research more than vulnerability exploitation, a VulnCheck researcher said
Infosecurity Magazine Jul 29, 2026, 09:30 AM (UTC)
Read
AI is dramatically reducing the barriers to entry for scam phone farm operators, Human Security warns
Infosecurity Magazine Jul 29, 2026, 08:30 AM (UTC)
Read
The National Cyber Security Centre has released a detailed framework to assist with incident response and recovery
Infosecurity Magazine Jul 28, 2026, 03:15 PM (UTC)
Read
Three CVEs in Hugging Face diffusers let a malicious model repo run code on any machine that loads it
Infosecurity Magazine Jul 28, 2026, 02:45 PM (UTC)
Read
AI-assisted research uncovered Linux kernel use-after-free allowing root escalation
Infosecurity Magazine Jul 28, 2026, 01:00 PM (UTC)
Read
Analysis of real-life incident response cases by Cisco Talos warns that phishing remains a powerful method of initial compromise
Cybersecurity Ventures Jul 28, 2026, 12:50 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 28, 2026 – Listen to the podcast Meta is facing penalties of up to a massive $1.4 trillion from four U.S. states that sued the company over the addictive designs of The…
Infosecurity Magazine Jul 28, 2026, 12:45 PM (UTC)
Read
Microsoft has launched a new agentic security system for cyber defenders as well as its first cyber-focused AI model
Infosecurity Magazine Jul 28, 2026, 11:00 AM (UTC)
Read
Coca Cola claims data was stolen from its Fairlife business after a recent ransomware attack
Infosecurity Magazine Jul 28, 2026, 09:40 AM (UTC)
Read
NVIDIA has launched a new Open Secure AI Alliance to build an “open defense stack for agents”
Infosecurity Magazine Jul 28, 2026, 08:57 AM (UTC)
Read
CREST’s new AI standards are optional add-on requirements for cybersecurity service providers wishing to demonstrate responsible AI usage
Cybersecurity Ventures Jul 27, 2026, 12:50 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 27, 2026 – Listen to the podcast By the end of the nearly yearlong romance scam that began on LinkedIn, Anola Johnson, 67, a Utah-based travel specialist, was out aroun…
Infosecurity Magazine Jul 27, 2026, 11:30 AM (UTC)
Read
Impersonating well-known cryptocurrency and trading sites, SourTrade has developed a novel technique to drop infostealers to victims
Infosecurity Magazine Jul 27, 2026, 10:01 AM (UTC)
Read
Halcyon’s latest quarterly ransomware report showed that while ransomware attacks are declining, obfuscation techniques are getting harder to fight against
Cybersecurity Ventures Jul 24, 2026, 12:51 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 24, 2026 – Watch the YouTube video Black Hat USA 2026, the premier cybersecurity event of the year, returns to Mandalay Bay in Las Vegas with a re-engineered, six-day p…
Infosecurity Magazine Jul 24, 2026, 12:00 PM (UTC)
Read
Researchers at ReliaQuest warned of widespread DNS poisoning attacks targeting the hospitality sector as part of a cyber espionage campaign
Infosecurity Magazine Jul 24, 2026, 11:15 AM (UTC)
Read
OpenAI’s chatbot tool ChatGPT ranked among the top 10 most impersonated brands in phishing attacks for the first time