BleepingComputer Aug 3, 2026, 08:01 PM (UTC)
Read
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windo…
BleepingComputer Aug 3, 2026, 07:25 PM (UTC)
Read
Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information. [...]
The Hacker News Aug 3, 2026, 06:43 PM (UTC)
Read
Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-spea…
BleepingComputer Aug 3, 2026, 05:00 PM (UTC)
Read
N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers. [...]
The Hacker News Aug 3, 2026, 04:24 PM (UTC)
Read
Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim's screen. Unit 42 detailed three attack paths against Chrome's Google Password…
The Hacker News Aug 3, 2026, 04:15 PM (UTC)
Read
The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the…
SecurityWeek Aug 3, 2026, 03:50 PM (UTC)
Read
Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas. The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 1) appeared first on SecurityWeek.
SecurityWeek Aug 3, 2026, 03:32 PM (UTC)
Read
The payments giant says BioCatch’s behavioral and device intelligence will help financial institutions combat account takeovers, scams and other forms of digital fraud. The post Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion appeared first o…
SecurityWeek Aug 3, 2026, 03:15 PM (UTC)
Read
The list of people behind companies, foundations and trusteeships is part of efforts to combat money laundering and terror financing. The post Cyberattack Hits Liechtenstein’s Register of People Behind Companies and Foundations appeared first on SecurityWeek.
BleepingComputer Aug 3, 2026, 03:04 PM (UTC)
Read
A cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals. [...]
Infosecurity Magazine Aug 3, 2026, 03:00 PM (UTC)
Read
Chinese actors exploited the critical React2Shell exploit inside a day, while 88% of exploited vulnerabilities in H1 2026 were compromised within 48 hours of disclosure
BleepingComputer Aug 3, 2026, 02:45 PM (UTC)
Read
Flare researchers analyzed thousands of underground posts to examine how the BTMOB Android malware operation evolved into a fragmented ecosystem of resellers, source-code vendors, custom versions, and competing sales channels. [...]
Infosecurity Magazine Aug 3, 2026, 02:30 PM (UTC)
Read
Russian actor Storm-2945 hijacked hotel captive portals to push fake updates and steal tokens
The Hacker News Aug 3, 2026, 02:03 PM (UTC)
Read
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most…
Cybersecurity Ventures Aug 3, 2026, 01:04 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 3, 2026 – Read the full story in Reddit The Cybercrime Magazine Podcast stands out as a leading resource for CISOs looking to stay updated on cybersecurity trends in 20…
SecurityWeek Aug 3, 2026, 01:02 PM (UTC)
Read
The bank holding company was hacked in June, but the investigation into the incident continues. The post River Bank Says Hackers Deleted Data Stolen in Ransomware Attack appeared first on SecurityWeek.
SecurityWeek Aug 3, 2026, 01:00 PM (UTC)
Read
Venture financing has become an essential factor in growing new business in today’s fast moving economy. Horizon3’s latest funding explains how and why. The post Horizon3 Raises $250 Million to Fund Continuing Growth appeared first on SecurityWeek.
SecurityWeek Aug 3, 2026, 12:34 PM (UTC)
Read
The N‑central vulnerability CVE-2026-18577 has been exploited in the wild after threat actors found a patch bypass. The post N‑able Patches Vulnerability Exploited to Hack N-central Servers appeared first on SecurityWeek.
SecurityWeek Aug 3, 2026, 11:45 AM (UTC)
Read
The physical security firm says its alarm monitoring and system functionality have not been affected. The post Brinks Home Discloses Data Breach as Hackers Leak Files appeared first on SecurityWeek.
The Hacker News Aug 3, 2026, 11:30 AM (UTC)
Read
AI is moving incredibly fast, and every security leader is feeling the pressure to keep up. AI platforms like Claude, Codex and Cursor are already helping security teams write detections, investigate alerts, summarize incidents, and automate repetitive work. T…
Infosecurity Magazine Aug 3, 2026, 11:26 AM (UTC)
Read
New HollowFrame loader hid Go code in a fake Python DLL after pre-staging Defender exclusions
The Hacker News Aug 3, 2026, 10:49 AM (UTC)
Read
An unknown Chinese-speaking threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit. Attack surface management platform Censys said it identified the threat actor runnin…
SecurityWeek Aug 3, 2026, 10:39 AM (UTC)
Read
The INC Ransomware gang has been targeting vulnerable SMA1000 appliances for root access and lateral movement. The post Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks appeared first on SecurityWeek.
Infosecurity Magazine Aug 3, 2026, 09:36 AM (UTC)
Read
Korean telco KT has been fined $39m for a year-long breach linked to femtocell compromise
SecurityWeek Aug 3, 2026, 09:17 AM (UTC)
Read
Midnight Blizzard has been stealing Microsoft account credentials via compromised Wi-Fi networks at hospitality organizations. The post Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking appeared first on SecurityWeek.
The Hacker News Aug 3, 2026, 09:13 AM (UTC)
Read
The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web. The data included names, organisations and work email addresses belonging to police officers, police…
SecurityWeek Aug 3, 2026, 08:48 AM (UTC)
Read
Michigan, South Dakota, and Georgia are reportedly on the list of states whose water systems have been targeted by Iran-linked hackers. The post US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States appeared first on SecurityWeek.
Infosecurity Magazine Aug 3, 2026, 08:40 AM (UTC)
Read
A hacker has drained nearly $89m from Coldcard Bitcoin wallets after exploiting a legacy bug
The Hacker News Aug 3, 2026, 08:05 AM (UTC)
Read
Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them. The vendor's July 31 security bulletin says nearly undetectable changes to .fs…
The Hacker News Aug 3, 2026, 06:41 AM (UTC)
Read
N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers. Its first fix was incomplete. CVE-2026-18577 affects N-central builds prior to 2026.3.1.7.…
The Hacker News Aug 3, 2026, 06:40 AM (UTC)
Read
Three high-severity security flaws have been disclosed in Hugging Face's Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) supply chain to secur…
BleepingComputer Aug 2, 2026, 10:31 PM (UTC)
Read
OpenAI has revealed Astra, an unreleased model designed to tackle complex, long-running tasks, after an internal version produced ten significant advances in mathematics and theoretical computer science. [...]
BleepingComputer Aug 2, 2026, 09:14 PM (UTC)
Read
A vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator. [...]
BleepingComputer Aug 2, 2026, 02:17 PM (UTC)
Read
Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. [...]
The Hacker News Aug 1, 2026, 05:17 PM (UTC)
Read
An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm…
BleepingComputer Aug 1, 2026, 02:20 PM (UTC)
Read
A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]
The Hacker News Aug 1, 2026, 09:03 AM (UTC)
Read
Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. Adform detected the incident on July 27, 2026, removed the malicious code, notified affecte…
The Hacker News Aug 1, 2026, 07:12 AM (UTC)
Read
Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carrie…
The Hacker News Aug 1, 2026, 06:29 AM (UTC)
Read
A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report. Researchers track the operation as Ca…
BleepingComputer Jul 31, 2026, 10:16 PM (UTC)
Read
Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. [...]
BleepingComputer Jul 31, 2026, 09:38 PM (UTC)
Read
The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages. [...]
BleepingComputer Jul 31, 2026, 09:09 PM (UTC)
Read
Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones controlled by an attacker. [...]
BleepingComputer Jul 31, 2026, 06:52 PM (UTC)
Read
OpenAI says it has reduced the price of two GPT-5.6 models, cutting Luna's API price by 80% and Terra's by 20% as it works to make its models more efficient. [...]
The Hacker News Jul 31, 2026, 06:52 PM (UTC)
Read
A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, sinc…
BleepingComputer Jul 31, 2026, 05:35 PM (UTC)
Read
A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. [...]
BleepingComputer Jul 31, 2026, 04:49 PM (UTC)
Read
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector. [...]
The Hacker News Jul 31, 2026, 04:39 PM (UTC)
Read
Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing messag…
Infosecurity Magazine Jul 31, 2026, 03:00 PM (UTC)
Read
A Chinese-speaking threat actor has been using DeepSeek’s AI models to orchestrate cyber-attacks targeting Asian organizations
The Hacker News Jul 31, 2026, 02:45 PM (UTC)
Read
Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers named the operation Fuyao and attributed i…
Cybersecurity Ventures Jul 31, 2026, 01:11 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 31, 2026 – Listen to the podcast “The exploit lands before the fix even ships,” says John Vecchi, CMO at Mitiga, a leader in zero-impact breach prevention for cloud, Sa…
The Hacker News Jul 31, 2026, 12:51 PM (UTC)
Read
Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions were released last month. In its latest patc…
The Hacker News Jul 31, 2026, 11:55 AM (UTC)
Read
An academic study has disclosed a "widespread class" of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and even session hijacking, allowing an attacker to seize control…
The Hacker News Jul 31, 2026, 11:24 AM (UTC)
Read
Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved from a niche red-team technique to an industrial-scale threat in under six months. Designed for input-constrained devices like smart TVs, printers…
The Hacker News Jul 31, 2026, 11:21 AM (UTC)
Read
Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. After an initial Telegram instruction, the agent found internet-facing systems and selected public exp…
Infosecurity Magazine Jul 31, 2026, 09:50 AM (UTC)
Read
AWS has linked North Korea to the axios campaign to other attacks on npm libraries
Infosecurity Magazine Jul 31, 2026, 08:35 AM (UTC)
Read
Anthropic has revealed that Claude AI models compromised third-party organizations
The Hacker News Jul 31, 2026, 06:41 AM (UTC)
Read
Anthropic on Thursday became the latest artificial intelligence (AI) company to reveal that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, had breached three unnamed organizations during cybersecurity testing without i…
The Hacker News Jul 30, 2026, 06:18 PM (UTC)
Read
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of…
Krebs on Security Jul 30, 2026, 04:49 PM (UTC)
Read
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking…
The Hacker News Jul 30, 2026, 03:25 PM (UTC)
Read
A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abu…
Infosecurity Magazine Jul 30, 2026, 02:30 PM (UTC)
Read
Cryptomining crew abandoned root to impersonate low-privileged Linux users and evade SOC alerts
Infosecurity Magazine Jul 30, 2026, 02:00 PM (UTC)
Read
AiTM phishing is now the top entry point into law firms, with identity behind 56% of threats
The Hacker News Jul 30, 2026, 01:34 PM (UTC)
Read
A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chain CosmosEscape, said…
Infosecurity Magazine Jul 30, 2026, 01:00 PM (UTC)
Read
Action1 report finds sysadmins overestimated their use of AI in predictions made two years ago
Infosecurity Magazine Jul 30, 2026, 12:00 PM (UTC)
Read
Check Point researchers detail phishing attack as an example of attackers dropping fake Microsoft login pages in favor of abusing Microsoft’s legitimate authentication infrastructure
The Hacker News Jul 30, 2026, 11:54 AM (UTC)
Read
Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. Håkon Måløy disclosed the technique on July 28, 144 days after reporting it to Microsoft. In his proof of…
The Hacker News Jul 30, 2026, 11:32 AM (UTC)
Read
Network firewalls are the workhorses of modern cybersecurity. They are trusted to protect the network, blocking malicious traffic and preventing intrusions and breaches. And for decades, network security teams have built controls around a relatively stable mod…
The Hacker News Jul 30, 2026, 10:33 AM (UTC)
Read
South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIG…
The Hacker News Jul 30, 2026, 10:32 AM (UTC)
Read
The Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver (BYOVD) attacks targeting a Japanese organization in the industrial manufacturing sector to ultimately deliver ValleyRAT (aka Winos…
Infosecurity Magazine Jul 30, 2026, 09:15 AM (UTC)
Read
The new version of Chrome, 151, comes with 370 vulnerability patches, including for seven critical flaws
Infosecurity Magazine Jul 30, 2026, 08:25 AM (UTC)
Read
The UK’s National Cyber Security Centre wants network device makers to improve forensic observability
The Hacker News Jul 30, 2026, 07:40 AM (UTC)
Read
The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as wel…
The Hacker News Jul 30, 2026, 07:28 AM (UTC)
Read
The Federal Communications Commission (FCC) added foreign-produced mobile robots and networked power inverters to its Covered List on July 28. The move generally prevents new models from receiving the equipment authorization required for import, marketing, or…
The Hacker News Jul 30, 2026, 06:05 AM (UTC)
Read
Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as crypto theft: a maintainer phished through a lookalike npm domain and a wallet-draining script pushed into at…
The Hacker News Jul 30, 2026, 05:08 AM (UTC)
Read
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero…
The Hacker News Jul 29, 2026, 06:10 PM (UTC)
Read
Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose…
Infosecurity Magazine Jul 29, 2026, 04:00 PM (UTC)
Read
LogoKit now builds per-victim phishing pages using live screenshots of the target's real website
The Hacker News Jul 29, 2026, 03:39 PM (UTC)
Read
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-5…
The Hacker News Jul 29, 2026, 03:31 PM (UTC)
Read
Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of the three critical-rated flaws is CVE-2026-59309 (CVSS s…
Infosecurity Magazine Jul 29, 2026, 03:10 PM (UTC)
Read
TA488 returned with OWA half-click exploit deploying OWAReaper implant that survived re-imaging
The Hacker News Jul 29, 2026, 01:48 PM (UTC)
Read
A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. Braham, Plymouth, South St. Paul and Maple Plain have publicly described a plant outag…
The Hacker News Jul 29, 2026, 01:42 PM (UTC)
Read
Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years. According to Russian cybersecur…
Cybersecurity Ventures Jul 29, 2026, 12:57 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 29, 2026 – Listen to the podcast Bent is the story of John J. Boseak’s phenomenal life of crime. Inked from head to toe, with an addiction to strippers and fast Cadilla…
The Hacker News Jul 29, 2026, 12:15 PM (UTC)
Read
AI is compressing exploit timelines. The real question isn't whether your vulnerability management playbook needs to change, it's which part of it you've been getting wrong all along. The conversation happening in security circles right now goes something like…
The Hacker News Jul 29, 2026, 11:57 AM (UTC)
Read
Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. M…
The Hacker News Jul 29, 2026, 11:13 AM (UTC)
Read
Most organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the coordination, visibility, and executive alignment needed to withstand a serious cyberattack. According to The Stat…
The Hacker News Jul 29, 2026, 11:00 AM (UTC)
Read
The Federal Security Service of the Russian Federation (FSB) on Wednesday said it charged Telegram founder Pavel Durov for allegedly facilitating terrorist activities and for failing to remove prohibited information in violation of Russian law. The principal s…
Infosecurity Magazine Jul 29, 2026, 11:00 AM (UTC)
Read
IBM Cost of a Data Breach Report warns that the global average cost of a data breach has reached a record high of $4.99m – and AI-backed attacks have played a role
Infosecurity Magazine Jul 29, 2026, 10:15 AM (UTC)
Read
For now, the use of AI benefits vulnerability research more than vulnerability exploitation, a VulnCheck researcher said
Infosecurity Magazine Jul 29, 2026, 09:30 AM (UTC)
Read
AI is dramatically reducing the barriers to entry for scam phone farm operators, Human Security warns
The Hacker News Jul 29, 2026, 08:58 AM (UTC)
Read
Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the…
Infosecurity Magazine Jul 29, 2026, 08:30 AM (UTC)
Read
The National Cyber Security Centre has released a detailed framework to assist with incident response and recovery
The Hacker News Jul 29, 2026, 07:51 AM (UTC)
Read
OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face's production environment also hacked multiple third-party accounts and services as part of the attack. The latest…
The Hacker News Jul 29, 2026, 07:47 AM (UTC)
Read
Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account. T…
The Hacker News Jul 29, 2026, 07:07 AM (UTC)
Read
Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced matching control panels and certificates to 170 internet servers. They linked t…
The Hacker News Jul 29, 2026, 04:20 AM (UTC)
Read
Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The list of affected packages is as follows - @joyfill/layouts@0.1.2-2773.beta.0 @j…
The Hacker News Jul 28, 2026, 06:59 PM (UTC)
Read
Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously unused symmetry in the lattice behind the signature…
Infosecurity Magazine Jul 28, 2026, 03:15 PM (UTC)
Read
Three CVEs in Hugging Face diffusers let a malicious model repo run code on any machine that loads it
The Hacker News Jul 28, 2026, 03:01 PM (UTC)
Read
A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process. If that happens, Tengu's other persistence mechanisms get another chance to relaunch it. Nozomi Networks La…
Infosecurity Magazine Jul 28, 2026, 02:45 PM (UTC)
Read
AI-assisted research uncovered Linux kernel use-after-free allowing root escalation
The Hacker News Jul 28, 2026, 02:41 PM (UTC)
Read
Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol to the public internet. Of the 36,872 internet-exposed…
Infosecurity Magazine Jul 28, 2026, 01:00 PM (UTC)
Read
Analysis of real-life incident response cases by Cisco Talos warns that phishing remains a powerful method of initial compromise
Cybersecurity Ventures Jul 28, 2026, 12:50 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 28, 2026 – Listen to the podcast Meta is facing penalties of up to a massive $1.4 trillion from four U.S. states that sued the company over the addictive designs of The…
Infosecurity Magazine Jul 28, 2026, 12:45 PM (UTC)
Read
Microsoft has launched a new agentic security system for cyber defenders as well as its first cyber-focused AI model
Infosecurity Magazine Jul 28, 2026, 11:00 AM (UTC)
Read
Coca Cola claims data was stolen from its Fairlife business after a recent ransomware attack
Infosecurity Magazine Jul 28, 2026, 09:40 AM (UTC)
Read
NVIDIA has launched a new Open Secure AI Alliance to build an “open defense stack for agents”
Infosecurity Magazine Jul 28, 2026, 08:57 AM (UTC)
Read
CREST’s new AI standards are optional add-on requirements for cybersecurity service providers wishing to demonstrate responsible AI usage
Cybersecurity Ventures Jul 27, 2026, 12:50 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 27, 2026 – Listen to the podcast By the end of the nearly yearlong romance scam that began on LinkedIn, Anola Johnson, 67, a Utah-based travel specialist, was out aroun…
Infosecurity Magazine Jul 27, 2026, 11:30 AM (UTC)
Read
Impersonating well-known cryptocurrency and trading sites, SourTrade has developed a novel technique to drop infostealers to victims
Infosecurity Magazine Jul 27, 2026, 10:01 AM (UTC)
Read
Halcyon’s latest quarterly ransomware report showed that while ransomware attacks are declining, obfuscation techniques are getting harder to fight against
Cybersecurity Ventures Jul 24, 2026, 12:51 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 24, 2026 – Watch the YouTube video Black Hat USA 2026, the premier cybersecurity event of the year, returns to Mandalay Bay in Las Vegas with a re-engineered, six-day p…
Infosecurity Magazine Jul 24, 2026, 12:00 PM (UTC)
Read
Researchers at ReliaQuest warned of widespread DNS poisoning attacks targeting the hospitality sector as part of a cyber espionage campaign
Infosecurity Magazine Jul 24, 2026, 11:15 AM (UTC)
Read
OpenAI’s chatbot tool ChatGPT ranked among the top 10 most impersonated brands in phishing attacks for the first time
Infosecurity Magazine Jul 24, 2026, 09:15 AM (UTC)
Read
Comparitech’s analysis of incidents in the first half of 2026 finds that the emergence of The Gentlemen ransomware has resulted in surge in attacks against higher education
Infosecurity Magazine Jul 23, 2026, 03:50 PM (UTC)
Read
International agencies issue joint alert over state-backed campaign exploiting a critical vulnerability in the Zimbra Collaboration Suite
Infosecurity Magazine Jul 23, 2026, 02:00 PM (UTC)
Read
CoreView research finds that security leadership is concerned about AI Assistant exposing confidential data
Infosecurity Magazine Jul 23, 2026, 01:30 PM (UTC)
Read
US government agencies have warned that Iranian cyber actors are targeting US-based Siemens and Schneider industrial equipment
Cybersecurity Ventures Jul 23, 2026, 12:27 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 23, 2026 – Listen to the podcast Jim Rutt, CISO at The Dana Foundation, a private philanthropic organization in New York City that is dedicated to advancing neuroscienc…
Infosecurity Magazine Jul 23, 2026, 11:30 AM (UTC)
Read
Sophos report warns that the rapid adoption of AI by businesses is leaving them vulnerable to a new source of cyber threats
Infosecurity Magazine Jul 23, 2026, 10:19 AM (UTC)
Read
Dolphin X is a new infostealer that uses AI to sort and rank victims, giving cybercriminals a faster way to identify lucrative targets
Infosecurity Magazine Jul 23, 2026, 08:00 AM (UTC)
Read
A new study of organizations which have fallen victim to ransomware suggests the rise of AI-tools being used by hackers is making life harder for defenders
Infosecurity Magazine Jul 22, 2026, 03:00 PM (UTC)
Read
New TrickBot variant hides C2 communication inside DNS queries, replacing decade-old HTTP pattern
Cybersecurity Ventures Jul 22, 2026, 12:41 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 22, 2026 – Watch our Videos at Cybercrime.TV CISOs and security leaders have spoken up on our hottest content and the award-winning Cybercrime Magazine YouTube Channel…
Infosecurity Magazine Jul 22, 2026, 11:40 AM (UTC)
Read
Hugging Face recently disclosed a security breach. OpenAI has now said that it was its AI models which broke containment and hacked Hugging Face themselves
Infosecurity Magazine Jul 22, 2026, 10:50 AM (UTC)
Read
New Ubuntu snap-confine race condition lets local users escalate to root on default installs
Infosecurity Magazine Jul 22, 2026, 10:30 AM (UTC)
Read
CodeMender actively builds and runs exploits in customer-managed sandboxes to verify if vulnerabilities are truly exploitable
Krebs on Security Jul 22, 2026, 01:10 AM (UTC)
Read
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 perc…
Cybersecurity Ventures Jul 21, 2026, 02:15 PM (UTC)
Read
AI Delivers Value Only When It’s Built Into the Security Workflow – Christophe Briguet, Sr. Director of Product Management – AI & Security Analytics, Stellar Cyber San Jose, Calif. – Jul. 21, 2026 Every security leader has heard the promise by now: AI will tra…
Infosecurity Magazine Jul 21, 2026, 02:00 PM (UTC)
Read
Russian-speaking actor Trim built a commercial offensive AI pentest tool on jailbroken Claude models
Infosecurity Magazine Jul 21, 2026, 01:00 PM (UTC)
Read
Analysis by Black Kite warns that ransomware ecosystem is becoming bigger and more fragmented
Cybersecurity Ventures Jul 21, 2026, 12:38 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 21, 2026 – Read the full story in StationX Nathan House, founder and CEO at StationX, one of the UK’s first cybersecurity companies founded in 1999 and trusted by more…
Infosecurity Magazine Jul 21, 2026, 12:00 PM (UTC)
Read
FBI warned of deepfake videos of IC3 leadership directing users to spoofed complaint sites
Infosecurity Magazine Jul 21, 2026, 09:38 AM (UTC)
Read
Craneware, a provider of financial software for US healthcare organizations, has disclosed a cyber incident involving unauthorized access and data theft
Infosecurity Magazine Jul 21, 2026, 09:30 AM (UTC)
Read
In a new campaign, North Korean hacking group Famous Chollima targeted crypto professionals through ClickFix lures to deliver Windows and macOS trojans