The MerchantStore
DirectoryAbout UsLink to Us

2,106 Internet — Security Issues Entries

Internet — Security Issues — September 25th, 2026

Abnormal AI brings governance, cloud security, and threat investigation into one suite
Abnormal AI has unveiled the newest additions to its AI Security suite, designed to help enterprises adopt AI securely while protecting against new threats created or accelerated by AI.
September 25th, 2026 — Source

Another week, another data breach for Revolut customers
DriveWealth coughs up historic customer info after attackers socially engineer their way inside
September 25th, 2026 — Source

CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks
Homeland Security Secretary Markwayne Mullin tasked CISA with developing the plan in July.
September 25th, 2026 — Source

Connected Data Alone Won't Make AI a Better Decision-Maker
Teach AI How Businesses Operate Before Optimizing Them, Says Aily Labs' Anghelina
September 25th, 2026 — Source or Source or Source or Source

Dataiku Agent Management reveals unmonitored AI agents
Dataiku has announced the launch of Agent Management, a standalone product that finds every AI agent an enterprise is running, regardless of which platform built it, measures the business and technical performance, and flags agents that pose the greatest risk.
September 25th, 2026 — Source

Docker introduces OCI-based Kits to package agents and their guardrails
Docker has announced Docker Cloud Sandboxes, a new solution for secure, isolated AI agent execution that enables complex agentic workflows to continue running in the cloud long after a developer's laptop shuts down. Launched at WeAreDevelopers North America, Docker Cloud Sandboxes let organizations run agentic workloads at scale without tying up developers' hardware, provisioning their own infrastructure, or paying for unused capacity.
September 25th, 2026 — Source

Documentation placeholder domain used in ClickFix attacks
Following instructions can lead to bad things, as this increasingly common attack method can bypass Windows protections.
September 25th, 2026 — Source

Dyfed-Powys Police cops to cyberattack, staff data potentially nicked
Force says public data appears untouched, but investigators looking into whether crims grabbed employee information
September 25th, 2026 — Source

Fake payroll desktop apps hand attackers a route to company paychecks
An attacker has been offering "desktop apps” for three large US payroll and HR platforms that have never released one, Allure Security have found. Anyone who runs the installer gets a copy of ScreenConnect, a legitimate remote access tool, configured to let the attacker control the computer without the user knowing.
September 25th, 2026 — Source

GitLab issue email's only security is obscurity
A long-lived token embedded in GitLab's issue-creating email address means anyone with the address, not just the project owner, can push code and trigger CI/CD jobs subject to the account's existing permissions.
September 25th, 2026 — Source

In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure
Noteworthy stories that might have slipped under the radar: BragJack attack against browser AI assistants, TDengine flaw threatens industrial telemetry uptime, Ubuntu update overhaul.
September 25th, 2026 — Source

Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court
Ardit Kutleshi created and operated Rydox, which allowed miscreants to trade PII and cybercrime tools and services.
September 25th, 2026 — Source

MacSync info-stealing malware hides malicious commands in an iCloud calendar
A new MacSync variant targets Mac users with an infostealer and persistent backdoor designed to steal credentials, crypto wallet data, and files, according to Kaspersky.
September 25th, 2026 — Source

Realizing Value From AI Starts With Redesigning the Business
OpenAI's Colin Jarvis on Workflow Redesign, Trust Frameworks and Human Oversight
September 25th, 2026 — Source or Source or Source or Source

'SalesBleed' Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration
Three vulnerabilities in Salesforce Agentforce allowed hackers to hijack trusted agents, steal data, and launch phishing attacks.
September 25th, 2026 — Source

SentinelOne extends Wayfinder coverage across endpoints, identities, and cloud workloads
SentinelOne has announced the expansion of Wayfinder Threat Hunting to the major public cloud services: AWS, Azure, and Google Cloud. It's the latest offering from SentinelOne's Wayfinder team and combines the power of SentinelOne's AI-powered Singularity Platform telemetry with expert human-led hunting to protect the attack surface across AI, endpoints, identities, and cloud workloads.
September 25th, 2026 — Source

Threat detection dashboards are masking security coverage gaps
A detection rule can show up as deployed on a coverage dashboard and still never fire when an attacker uses the technique it was built to catch.
September 25th, 2026 — Source

Why 'Cappuccino ROI' Keeps AI Gains From the Bottom Line
Deloitte's Costi Perricos on AI-Centered Process Design and New Business Models
September 25th, 2026 — Source or Source or Source or Source

Why Enterprises Must Own, Not Rent, Their Intelligence
Uniphore CEO Umesh Sachdev on Proprietary Data, Trade Secrets and Sovereign AI
September 25th, 2026 — Source or Source or Source

Windows, Linux, Android File Notification Systems Leak User Activity
Researchers show that file-change notification systems can leak keystroke timing, browsing activity, and WhatsApp media events.
September 25th, 2026 — Source

Internet — Security Issues — September 24th, 2026

AI-Powered Campaign Targets Hundreds of Online Retailers
A threat actor is using three AI harnesses for vulnerability research, exploitation, and attack orchestration.
September 24th, 2026 — Source

Airties adds router-level cybersecurity protection for ISPs
Airties has launched new integrated cybersecurity capabilities that enable ISPs to detect and remediate threats to connected homes and small businesses. As part of Airties' Connectivity Experience Management Platform, these new capabilities turn the router into an additional security layer that safeguards every device on the network, giving ISPs a powerful baseline of protection for their entire subscriber base.
September 24th, 2026 — Source

Apple's new iOS 27 feature looks for signs you're being scammed
Apple introduced a scam-prevention feature called Impersonation Risk Detection with iOS 27 and iPadOS 27. The feature allows supported apps to request a risk assessment when a user takes an action that could be connected to an active social engineering scam.
September 24th, 2026 — Source

Astrana Health Data Breach Impacts Private, Confidential Information
Hackers impersonated the company's personnel and contacted its employees to gain access to Astrana Health's servers.
September 24th, 2026 — Source

Azul AI Assistant helps teams find Java licensing and security risks
Azul has announced Azul Intelligence Cloud AI Assistant, a natural-language query interface that tells IT, DevOps and security teams where licensing and security risk is hiding in their production Java estate.
September 24th, 2026 — Source

Begin at the End: How to Enable Agentic Remediation
Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk.
September 24th, 2026 — Source

CISA: Ransomware gangs now exploiting critical TeamCity flaw
​The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July.
September 24th, 2026 — Source

Claude.ai is about 3x faster after 3,000+ changes
Anthropic engineers made claude.ai and the Claude desktop app roughly three times faster during a two-week sprint in August, with Claude finding the bottlenecks and writing the fixes. The team merged more than 3,000 changes and says none of them caused a customer-facing incident or rollback.
September 24th, 2026 — Source

Cloud Range lets SOCs benchmark AI agents against human defenders
Cloud Range has announced the official launch of its AI Validation Range and Cloud Range AI Readiness Framework. They give organizations a structured way to test AI models and agents in realistic environments, validate their readiness for operational responsibility and safety, and determine which roles and tasks are best handled by AI versus human experts.
September 24th, 2026 — Source

Critical WordPress Vulnerability Exploited Immediately After Disclosure
Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code.
September 24th, 2026 — Source

Cryptohack Roundup: US Sanctions BitBank
Also: South Korea Books 26 Polymarket Users for Alleged Illegal Gambling
September 24th, 2026 — Source

Decades-old file security flaws found in Android, Linux, macOS, and Windows
Security researchers report that Microsoft considers the side-channel leak of file events to be by design
September 24th, 2026 — Source

DriveWealth breach exposes data of Revolut customers who traded US stocks
Attackers got into DriveWealth, the US broker behind Revolut's US stock trading, on 4 and 5 September. Revolut says in Europe the DriveWealth breach only involves data from before December 2023.
September 24th, 2026 — Source

GNOME 50.5 security fixes patch a gvfs CVE and Epiphany code injection
GNOME 50.5, which the GNOME Release Team shipped on September 24, patches a CVE in the gvfs file system layer, a JavaScript injection flaw in the Epiphany web browser and a use-after-free bug in the librsvg image library.
September 24th, 2026 — Source

Google plans to give Private AI Compute a memory that follows users across devices
Google plans to add private, server-side memory to Private AI Compute, enabling AI assistants to maintain continuity across devices while providing privacy protections normally associated with on-device processing.
September 24th, 2026 — Source

Google to critical infra orgs: Our AI scanners won't be evil, promise
Gemini 3.8 Flash Cyber and Wiz's Red Agent team up to protect hospitals, public transit, and tech
September 24th, 2026 — Source

Government contractor exposed path to immigration records
IT took a shortcut when the boss was away, and it led to danger!
September 24th, 2026 — Source

Gurucul connects AI activity to identity data for faster threat response
Gurucul has announced the general availability of Gurucul AI Risk and Response, bringing behavioral AI to the growing attack surface created as AI moves from assistant to actor. With hundreds of AI detections connecting activity to identity, access, data and broader security telemetry, the solution helps SOC and Insider Risk teams see who or what is acting, recognize threats as they develop, investigate the evidence and respond before risk escalates.
September 24th, 2026 — Source

Hackers now exploit critical Roundcube flaw in code injection attacks
A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security.
September 24th, 2026 — Source

Hotspot Shield 12.17.1 released
Hotspot Shield has released version 12.17.1 of its VPN service, which is designed to enhance online privacy and security. By creating a virtual private network, Hotspot Shield allows users to browse the internet anonymously, safeguarding them against various vulnerabilities associated with unsecured networks. When accessing public Wi-Fi, such as at a cafe or restaurant, users risk exposing sensitive information, including unencrypted passwords. Cybercriminals can exploit these unsecured connections, using tools like packet sniffers to capture personal information, such as email addresses and passwords.
September 24th, 2026 — Source

Island Raises $400 Million at $6.4 Billion Valuation
The enterprise security firm has raised more than $1 billion since its launch in 2020; Evolution Equity Partners led the latest funding round.
September 24th, 2026 — Source

ISMG Security Report: AI Doesn't Wait for Patch Tuesday
AI Bug Discovery Forces Security Teams to Rethink Vulnerability Management
September 24th, 2026 — Source or Source or Source or Source

LatticeFlow AI offers managed risk assessments for enterprise AI systems
LatticeFlow AI has announced the LatticeFlow AI Risk Center, an AI governance managed service that continuously assesses and controls AI risk, giving enterprises the technology, evidence, and expertise to scale AI with confidence and accelerate time to value.
September 24th, 2026 — Source

Meta ads steered Polish Android users into a premium-rate billing trap
CERT Polska linked 852 promotions to 17 Google Play apps capable of sending costly texts or starting recurring subscriptions
September 24th, 2026 — Source

Meta locks itself out of user data on its AI glasses
Meta is expanding Private Processing to its AI glasses, extending their security protections into cloud data centers. The system runs AI models inside confidential virtual machines (CVMs) designed to prevent Meta from accessing users' data.
September 24th, 2026 — Source

New Android malware RemControl steals banking PINs and blocks removal attempts
A new Android banking trojan called RemControl tricks victims into installing a fake TV app, then takes control of their phones to steal banking PINs, Group-IB has found.
September 24th, 2026 — Source

OpenAI agent bypasses blocks to breach Australian Medicare portal
Australia demands answers after discovering an autonomous AI research model accessed non-public government files.
September 24th, 2026 — Source or Source

OpenAI agent hacking spree widens to Australia, targeting government website
Before the Hugging Face and RubyGems hacks, autonomous OpenAI agents attempted to hack into three other websites, including an Australian government public health website, independent research lab Transluce revealed on Wednesday.
September 24th, 2026 — Source

OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators
Revision 4 of NIST's operational technology security guide is open for public comments until November 30.
September 24th, 2026 — Source

SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted
The vulnerabilities, tracked as CVE-2026-28324 and CVE-2026-28325, can be exploited without authentication.
September 24th, 2026 — Source

Someone went shopping in ASUS's eShop -- for customer data
Contact details and order records accessed, but PC maker is keeping schtum on how many customers are affected
September 24th, 2026 — Source

Sweden launches campaign telling people to be ruder as scammers exploit good manners
Don't be afraid to tell a scammer where to go
September 24th, 2026 — Source

There's a new way to break RSA that's faster than anything we've seen before
The world has known for decades that the RSA cryptosystem's days are numbered. Once quantum computing becomes practical (estimates for that range from 3 to 20 or more years), the foundational security it provides will crumble. New research has revealed a novel method that uses classical computing to reduce the current RSA security level to an unacceptably low threshold.
September 24th, 2026 — Source

UK gears up for fight against Russia's disinformation machine
The UK government will create a new body to track and disrupt disinformation campaigns run by hostile states, Prime Minister Andy Burnham announced at the United Nations General Assembly in New York.
September 24th, 2026 — Source

US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks
Karen Vardanyan has also been ordered to pay over $1.2 million in restitution to victims.
September 24th, 2026 — Source

WireGuard Beats OpenVPN for UniFi Dream Machine Performance
When configuring a remote access VPN for your UniFi Dream Machine, the choice between WireGuard and OpenVPN can significantly impact performance, management and user experience. WireGuard, with its lightweight design and high-speed capabilities, is ideal for scenarios requiring efficient data transfer and scalability. On the other hand, OpenVPN offers robust security features and a simpler setup process, making it a versatile option for environments with diverse user needs. SpaceRex explores these two protocols in detail, highlighting their unique strengths and trade-offs to help you determine which aligns best with your network requirements.
September 24th, 2026 — Source

Internet — Security Issues — September 23rd, 2026

A Look at AI Doomsday Scenarios That Researchers Say Could Put Humanity at Risk
Debates over the plausibility of these doomsday scenarios have heated up since several executives endorsed slowing the technology's development for safety reasons.
September 23rd, 2026 — Source

AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft
The cybercrime platform leveraged AI at every step of the attack chain, including writing social engineering messages and deciding targets.
September 23rd, 2026 — Source

Adobe Patches Critical Flaws in Connect, AEM Forms
The nine critical security defects could be exploited for arbitrary code execution and privilege escalation.
September 23rd, 2026 — Source

Arista patches actively exploited VeloCloud Orchestrator zero-day
Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments.
September 23rd, 2026 — Source

Arista Urges Immediate Patching of Exploited VCO Zero-Day
Remote attackers could trigger the critical-severity flaw to access privileged internal functionality.
September 23rd, 2026 — Source

Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances
Check Point Software has released emergency fixes for a critical Check Point Management Server vulnerability (CVE-2026-93616) that has been exploited as far back as July 23, 2026.
September 23rd, 2026 — Source

Barracuda brings AI security and governance within reach of smaller organizations
Barracuda Networks has launched Barracuda AI Data Security, the AI security and governance solution purpose-built for resource-constrained organizations and managed service providers (MSPs). The solution enables businesses to accelerate AI adoption by protecting sensitive data, enforcing responsible AI use and demonstrating compliance.
September 23rd, 2026 — Source

Chrome 154 Patches 108 Vulnerabilities
The browser update resolves several critical-severity memory safety and memory corruption flaws.
September 23rd, 2026 — Source

Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
Unauthenticated attackers could send malicious traffic to BIG-IP to achieve remote code execution.
September 23rd, 2026 — Source

DarkMe RAT trades zero-days for plain phishing emails
DarkMe, a remote access trojan and info-stealer that has previously been associated with a threat group that targeted financial market traders and cryptocurrency users, has been spotted again.
September 23rd, 2026 — Source

ExpressVPN 14.3.1.15429 released
ExpressVPN has released version 14.3.1.15429, enhancing its capabilities as a robust virtual private network (VPN) service. This VPN allows users to bypass geographical restrictions, granting unlimited access to various online content such as videos, music, and social media from any location globally.
September 23rd, 2026 — Source

F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
F5 has released security updates to address a critical BIG-IP APM zero-day vulnerability being exploited in remote code execution attacks.
September 23rd, 2026 — Source

Fake Claude Max giveaway tricks users into handing over their Google account credentials
A fake Claude Max giveaway uses a spoofed Google sign-in window to steal users' login credentials, Malwarebytes researchers have found.
September 23rd, 2026 — Source

FBI investigating claims that ShinyHunters stole data on its agents
The cybercrime group says the hack was retaliation for an FBI alert about its tactics.
September 23rd, 2026 — Source

Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare
Only 21% of industrial security leaders report a complete OT asset inventory, even as 88% call their programs mature.
September 23rd, 2026 — Source

Lookout targets smishing, voice cloning, and vishing with real-time mobile protection
Lookout has launched Social Engineering Protection (SEP), a new module within the Lookout Mobile AI Security Platform. SEP provides automated, real-time protection against the next generation of AI-driven mobile threats, including linkless smishing attacks, synthetic voice cloning, and other voice phishing (vishing) techniques.
September 23rd, 2026 — Source

Meta acts against 3.7 million scammers' accounts with Singapore police help
Meta has disrupted more than 3.7 million scam-linked accounts, pages and other content this year based on information provided by Singapore police, the company said Wednesday.
September 23rd, 2026 — Source

Microsoft 365 Passkeys Replace Passwords to Stop Phishing
Passkeys are emerging as a secure, passwordless authentication method within Microsoft 365, offering a robust alternative to traditional approaches like SMS-based multi-factor authentication (MFA). By using public-private key pairs, passkeys eliminate the need for users to remember passwords, reducing the risk of phishing and adversary-in-the-middle (AITM) attacks. In a detailed breakdown by T-Minus365, administrators are guided through the essentials of passkey functionality, including how to configure them in the Microsoft Entra Admin Center and enforce device attestation using Authenticator Attestation Identifiers (AAIDs).
September 23rd, 2026 — Source or Watch Video

Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes
The EvilTokens phishing service, which compromised more than 12,000 inboxes at over 10,000 organizations, has been disrupted by a coalition of law enforcement and private-sector partners led by Microsoft.
September 23rd, 2026 — Source

Microsoft takes down EvilTokens phishing service that used AI to mine hacked inboxes for payment fraud
The platform compromised 12,000 accounts across 10,000 organizations using device-code phishing
September 23rd, 2026 — Source

Microsoft: September Windows updates break Always On VPN connections
Microsoft has notified IT administrators that users may experience Always On VPN connection issues after installing the September 2026 Windows 11 security updates.
September 23rd, 2026 — Source

Outerlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm
Emerging from stealth with $16 million in pre-seed funding, Outerlimit offers a decentralized authorization layer designed to discover, observe, and block harmful autonomous AI actions.
September 23rd, 2026 — Source

Researchers found malware that uses four different AI chatbots to run itself, no human hacker needed
The malware shows how LLMs are moving from an attacker productivity tool into attack infrastructure
September 23rd, 2026 — Source

Ryuk ransomware member sentenced to 24 months in prison
An Armenian man was sentenced to 24 months in prison and 3 years of supervised release for hacking U.S. companies and encrypting their systems in Ryuk ransomware attacks.
September 23rd, 2026 — Source

ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report
The cybercrime group is unhappy with its description in an FBI report and threatens to leak stolen information.
September 23rd, 2026 — Source

Stocking masks making a criminal comeback
You may recall the scene in the comedy Raising Arizona in which Nicolas Cage pulls a pair of pantyhose over his head before attempting, with limited success, to rob a convenience store of a pack of diapers.
September 23rd, 2026 — Source

Swedish celebs campaign for public rudeness ... to prevent cyber scams
The campaign follows a highly profitable year for crooks targeting the over-60s
September 23rd, 2026 — Source

Update to WordPress 7.1.2 to fix a critical security flaw
WordPress has released an important update to address a serious security issue. The release of WordPress 7.1.2 fixes a critical unauthenticated path traversal vulnerability which is tracked as s CVE-2026-87902 and has a CVSS v4.0 score of 9.2 (Critical).
September 23rd, 2026 — Source

Whisky merchant Master of Malt confirms customer data spilt
Attackers had four days to drink in names, addresses, emails and phone numbers
September 23rd, 2026 — Source

WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)
WordPress released version 7.1.2 to fix a critical flaw that lets an unauthenticated attacker make the software load a PHP file of the attacker's choosing from outside the site's active theme folders. On sites where the server and the active theme meet certain conditions, the attacker can go on to run code on the server.
September 23rd, 2026 — Source

Internet — Security Issues — September 18th, 2026

23 Million User Records Compromised in Gyazo Data Breach
Gyazo maker Helpfeel said the attacker exploited a vulnerability in its image upload server to gain unauthorized access.
September 18th, 2026 — Source

A zero-click RCE flaw in AI coding agents could have exposed enterprise systems
By exploiting how AI coding agents retrieve and verify plugins, researchers were able to execute malicious code even when the agent was told to use a trusted, approved version.
September 18th, 2026 — Source

AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
Hacktron researchers earned a bug bounty after demonstrating access to OpenAI employee accounts.
September 18th, 2026 — Source

Android apps can now check security patches down to individual device components
New AndroidX Security State libraries provide a more granular way to determine how securely patched an Android device is. The stable Security State v1.1.0 and Security State Provider v1.0.0 libraries allow developers to check the security status of individual device components and determine whether security updates are ready to be downloaded and installed on a specific device.
September 18th, 2026 — Source

Arcjet brings security controls and audit trails to AI agents
Arcjet has launched agent runtime security, a new product that helps engineering teams secure the AI agents they are building while giving security teams the governance and compliance evidence they need. Arcjet brings observability, enforcement, and audit capabilities across agent workflows so teams can discover which agents are running, control what they can do, and understand what happened and why.
September 18th, 2026 — Source

Bots with good manners are better at fooling people on social media
Most people can't tell a bot from a human online, and the bots most likely to fool them are the polite ones, according to a new Surfshark study.
September 18th, 2026 — Source

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts.
September 18th, 2026 — Source

Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges.
September 18th, 2026 — Source

Critical infrastructure resilience and escalated threat navigation initiative
As geopolitical instability accelerates cyber threats to critical infrastructure (CI), the Canadian Centre for Cyber Security (Cyber Centre) has designed the Critical Infrastructure Resilience and Escalated Threat Navigation (CIREN) initiative to drive immediate preparedness across organizations to reinforce and protect Canada's sovereignty and essential services.
September 18th, 2026 — Source

Critical Orkes Conductor Vulnerability Exploited in Attacks
CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions.
September 18th, 2026 — Source

Fake calendar invites can infect your system, and they're surging -- how to protect yourself
These invites sneak past your security software to embed themselves in your calendar. But you can thwart them before they do any damage.
September 18th, 2026 — Source

Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel.
September 18th, 2026 — Source

FBI, Coast Guard boarded hacked oil tankers heading toward US coast
Cybersecurity teams with the U.S. Coast Guard and the FBI boarded two U.S.-bound oil tankers last month after hackers reportedly compromised at least one of the ship's networks and took control of its navigation, propulsion, and cargo systems.
September 18th, 2026 — Source

FBI: Fake cop and government impersonation scams cost victims $1.6B
AI, fake uniforms, and mock offices help crooks sell the con
September 18th, 2026 — Source

Gyazo server flaw exploited to steal 23.6 million user records
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records.
September 18th, 2026 — Source

Google Asks Users to Take Video Selfies to Help Recover Their Accounts
And to "improve facial recognition, age estimation, and other verification methods," apparently.
September 18th, 2026 — Source

Hacker turns 25 cents into 46 billion fake Bitcoins to steal $770,000 — Symbiosis DeFi exchange bit by lack of basic bounds checking in smart contract
I, too, would love for my bank to charge me negative fees.
September 18th, 2026 — Source

Hackers breach OpenAI using Claude tools, gaining access to employee accounts and the company's internal codebase — attackers initiated a 'harmless' pull request as proof of the hack
Researchers receive a $6,500 bounty after reporting the vulnerabilities
September 18th, 2026 — Source

In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
Noteworthy stories that might have slipped under the radar: Mandiant's 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug exploited.
September 18th, 2026 — Source

Introducing the AndroidX Security State Libraries: A Unified View of Device Security
At Android, we are constantly working to provide developers and enterprise partners with the data they need to keep devices protected. Today, we're thrilled to announce the stable release of the AndroidX Security State version 1.1.0 and Security State Provider version 1.0.0 libraries which provides a centralized mechanism designed to bring further transparency to the comprehensive security posture and pending updates across the Android ecosystem.
September 18th, 2026 — Source

Microsoft fixes bug behind 'Defender Antivirus is turned off' alerts
Microsoft has resolved a known issue that causes incorrect alerts warning that Defender Antivirus was turned off after installing recent updates.
September 18th, 2026 — Source

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority.
September 18th, 2026 — Source

Microsoft Teams will let admins block custom file extensions
Microsoft Teams will soon let administrators tweak the list of file extensions commonly associated with malware and security threats to meet their company's security requirements.
September 18th, 2026 — Source

MIND Secures $72 Million for AI-Powered DLP
The company will use the funding to accelerate platform development and expand its presence in key enterprise markets.
September 18th, 2026 — Source

New Check Point flaw lets hackers execute code with root privileges
Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems.
September 18th, 2026 — Source

NightmareStresser DDoS Service Disrupted in International Operation
Active since at least 2022, NightmareStresser was one of the longest-running DDoS-for-hire services in the world.
September 18th, 2026 — Source

North Korea's fake job interviews infected 30,000 devices
WaterPlum recruiters used bogus coding tests to backdoor jobseekers and raid more than 7,000 crypto wallets
September 18th, 2026 — Source

Passwd Enterprise Review: Features, Pricing & Security
Review Passwd Enterprise pricing, security, Google Workspace integration, and private Google Cloud deployment to see if it fits your organization.
September 18th, 2026 — Source

Researchers used Anthropic's Claude to hack into OpenAI
In a twist that captures the strange new state of AI security, independent security researchers have used Anthropic's Claude to break into OpenAI, exposing cracks in the ChatGPT-maker's defenses, The Wall Street Journal reported on Thursday evening.
September 18th, 2026 — Source

Researchers used Claude to hack OpenAI
Researchers used Claude to reach an OpenAI employee account and sensitive GitHub data.
September 18th, 2026 — Source or Source

Secure enterprise sharing with access reviews for Microsoft 365
Collaboration suites like M365 offer unparalleled convenience. Millions of teams rely on them to quickly share documents with coworkers, clients and business partners. Yet when sharing is this easy, data security becomes a lot harder.
September 18th, 2026 — Source

Third tanker in a month hit by a suspected cyber incident, this time carrying US gas to Europe
An LNG tanker carrying American liquefied natural gas to Italy stopped short of its destination this month, after its crew found they could no longer reach some of the ship's internal control systems.
September 18th, 2026 — Source

Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched
Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an attacker the same reach into a company's systems and data as the employee running the agent, according to AIR.
September 18th, 2026 — Source

Internet — Security Issues — September 17th, 2026

A fake ChatGPT billing email is after your OpenAI password
A fake ChatGPT billing email is steering users to a copy of the OpenAI login page that keeps whatever username and password they type. Josh Varden of Cofense's Phishing Defense Center traced the email's payment button through a Google redirect to the attacker's page.
September 17th, 2026 — Source

AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals
New research from Irregular shows AI agents can retrain and redeploy their own underlying models during routine maintenance tasks.
September 17th, 2026 — Source

Avast Free Antivirus Is Actually Really Good, Here's How to Make It Less Annoying
I have been using and recommending antivirus programs for a long time, and Avast One Free Edition is one of those programs that gets a bit of an unfair reputation.
September 17th, 2026 — Source

Chinese hackers use SparroWocky malware in govt espionage attacks
The China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks on government organizations in Latin America.
September 17th, 2026 — Source

CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses
Complementing Zero Trust models, decoys enable organizations to detect, observe, and block malicious activity in their environments.
September 17th, 2026 — Source

CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoys
Cyber deception has long been the domain of well-resourced security teams, but CISA's latest guidance, titled "Using Cyber Decoys to Strengthen Detection and Response”, is an attempt to try and change that.
September 17th, 2026 — Source

Cisco drops another exploited zero-day, this time a perfect 10
ISE authentication bypass under active attack just days after another Cisco zero-day sent admins scrambling to patch
September 17th, 2026 — Source

Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard
The vulnerabilities may lead to root access, command execution, bypasses, SQL injection, and remote code execution.
September 17th, 2026 — Source

Cisco warns of max severity ISE zero-day exploited in attacks
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild.
September 17th, 2026 — Source

Comp AI Raises $34 Million for AI-Native Compliance and Security
The company plans to expand into continuous cybersecurity, offering security testing across applications and infrastructure.
September 17th, 2026 — Source

DoesNotBelong 12.1.6 released
DoesNotBelong, formerly known as Furtivex Malware Removal, is a newly updated script designed to complement your antivirus software by offering a free, on-demand scanning tool. This tool serves as an additional protective layer that effectively identifies and removes malware threats.
September 17th, 2026 — Source

Druva expands identity resilience with ransomware detection
Druva has announced new capabilities for Druva Identity Resilience alongside the launch of Ransomware Detection, a new feature fueled by a proprietary AI threat pipeline. Powered by Dru MetaGraph, the new offerings use behavioral intelligence and built-in validation to turn suspicious behavior into actionable evidence, definitively confirm impact, and accelerate precise containment and clean recovery.
September 17th, 2026 — Source

Fake AI trading agent steals crypto wallet passwords
Attackers built a website for a fake AI crypto trading agent and used it to install Needle Stealer, malware that replaces a victim's browser wallet with a copy that sends the wallet password to the attacker. HP caught the campaign between April and June 2026.
September 17th, 2026 — Source

FBI takes down one of the longest-running DDoS-for-hire services
The FBI has seized the domains behind NightmareStresser, a DDoS-for-hire service officials call one of the longest running "booter” operations in existence.
September 17th, 2026 — Source

Google's new agent security system detects tool misuse, loops and rogue behavior
Google's Agent Anomaly Detection is a reasoning-based oversight and audit layer for autonomous agents deployed on Agent Runtime in the Gemini Enterprise Agent Platform and built with the Agent Development Kit (ADK) for Python 1.2 or later. Google recommends ADK 2.1.0 or later. It is available in Private Preview.
September 17th, 2026 — Source

Grandmother jailed for six months after facial recognition mistake launches $10 million lawsuit against Fargo and detective
She lost her home, car, and dog while jailed for a crime committed more than 1,200 miles away
September 17th, 2026 — Source

Hackers find encryption keys stored on stolen Flock camera despite company's denials — group extracts more than 27,000 clips, 1.6 million images captured in a span of 21 days from the device
Flock claims that images are only briefly stored on its cameras before being forwarded to the company's servers, but a group of hackers determined that this wasn't the case.
September 17th, 2026 — Source

Hackers stole a Flock camera and found 27,321 video clips, 1.6 million images, and an encryption key
The findings appear to contradict Flock's previous claims about stored footage
September 17th, 2026 — Source

Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE
Six months after Iranian drone strikes tore through its Middle East infrastructure, Amazon Web Services (AWS) has acknowledged the permanent loss of customer data in Bahrain and the UAE.
September 17th, 2026 — Source

ISC Patches 14 Vulnerabilities in BIND 9 Security Update
Attackers could exploit the flaws to increase resource usage, trigger an unexpected program exit, or terminate the named process.
September 17th, 2026 — Source

Ofcom discovers issuing Online Safety Act fines is easier than collecting them
Platforms comply just enough to avoid being blocked, leaving the regulator chasing debt
September 17th, 2026 — Source

Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows
Research shows attacks on manufacturers rose 40% in early 2026, as ransomware groups increasingly exploit the supply-chain disruption caused by operational shutdowns.
September 17th, 2026 — Source

Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Revolut allegedly fed customer information to hackers impersonating an Italian government agency for five months.
September 17th, 2026 — Source

Scammers leave AI fingerprints all over fake antivirus renewal page
AI appears to be helping scammers with little web development skill build convincing fake antivirus-renewal pages, Malwarebytes found.
September 17th, 2026 — Source

Spain reports first data breach involving autonomous AI agent
Spain's data protection authority (AEPD) has reported its first data breach blamed on an AI agent acting on its own, after the system reportedly logged into a company's network, found a way to alter personal records, and pulled invoice data.
September 17th, 2026 — Source

Test environment let anyone access live customer data
Even a temporary staging server needs to be locked down.
September 17th, 2026 — Source

Unauthenticated attackers are bypassing Cisco ISE's management interface (CVE-2026-76460)
Two days after it warned customers about an actively exploited email gateway zero-day, Cisco confirmed one more flaw is being targeted: CVE-2026-76460, an authentication bypass bug in an API of Cisco Identity Services Engine (ISE).
September 17th, 2026 — Source

US takes down NightmareStresser DDoS-for-hire platform
On Tuesday, the U.S. Federal Bureau of Investigation (FBI) seized the domains used by NightmareStresser, one of the world's longest-running distributed denial-of-service (DDoS) platforms.
September 17th, 2026 — Source

What Recent AI-Powered Attacks Mean for Your Identity Security
In one credential-harvesting campaign, a threat actor first compromised an organization's cloud infrastructure, then built and deployed a multi-agent attack framework. The operation took less than six hours in total and resulted in thousands of third-party credentials being compromised.
September 17th, 2026 — Source

Internet — Security Issues — September 14th, 2026

A Vulnerability in GitLab Could Allow for Disclosure of Sensitive Data
A vulnerability has been discovered in GitLab, which could allow disclosure of sensitive data. GitLab GitLab is a DevOps platform that provides source code management, CI/CD pipelines, issue tracking, and collaboration tools in a single application for software development teams. Successful exploitation of this vulnerability could allow for path traversal, leading to disclosure of potentially sensitive information such SSH keys, database credentials, deploy tokens. Depending on the sensitive information retrieved via this technique, the attacker may gain further access to the appliance or systems.
September 14th, 2026 — Source

Anthropic CEO warns AI botnet swarms could soon take over the internet as Musk and Altman back slowdown
The theoretical botnet could cause hundreds of billions of dollars in damage0
September 14th, 2026 — Source

Airrived adds Agentic Observability to track AI agent actions and risks
Airrived will reveal Agentic Observability, a major expansion of its enterprise Agentic OS built to give organizations end-to-end visibility into how AI agents behave, from the moment enterprise data enters the platform, through agent reasoning and execution, to the final business outcome.
September 14th, 2026 — Source

Bitsight connects threat intelligence and exposure monitoring across the supply chain
Bitsight access to a broad risk dataset, combining threat intelligence and continuous exposure monitoring to help teams mitigate risk across the supply chain.
September 14th, 2026 — Source

Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution
The Chinese-language input method editor for Windows can allow attackers to execute arbitrary code remotely.
September 14th, 2026 — Source

CISA: Hackers now exploit max severity GitLab flaw in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity GitLab vulnerability in attacks.
September 14th, 2026 — Source

CISOs Race to Control AI Agents Without Destroying Their Value
Security leaders are struggling to modernize cyber hygiene and prevent over-privileged agents from causing unintended harm.
September 14th, 2026 — Source

ClickFix Malware Is Going Viral, Infecting PCs And Macs With CAPTCHA Prompts
Remember over a year ago when we reported on the ClickFix malware that uses fake CAPTCHA mechanisms to dupe unwitting victims into pwning their own machines? Well, apparently not enough people shared that post, because the problem has grown to an epic scale. Security researcher Kevin Beaumont remarked this past Thursday that Reddit is filled with "post after post" of people getting their computer infected via ClickFix.
September 14th, 2026 — Source

ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks
The flaw allows attackers to send files and execute them without authorization through an active remote session.
September 14th, 2026 — Source

Cyber threat actors use artificial intelligence in an active global campaign to disrupt internet-exposed programmable logic controllers
The Canadian Centre for Cyber Security (Cyber Centre) is warning Canadian organizations of an active global campaign in which cyber threat actors are targeting and attempting to disrupt programmable logic controllers (PLCs) that are exposed to the internet. The Cyber Centre and its partners have previously warned that cyber threat actors are targeting internet-accessible industrial control systems and operational technologies (ICS/OT) to disrupt water facilities and other critical services in Canada and abroad. This cybersecurity advisory describes how threat actors are using artificial intelligence (AI) to find and attack these devices.
September 14th, 2026 — Source

Cyberattack sends International Meteor Organization crashing back to Earth
Attack dealt a 'critical blow' to aging infrastructure, with several weeks of disruption expected
September 14th, 2026 — Source

Dataminr uses agentic AI to predict and verify security threats
Dataminr has announced Dataminr Advanced for Corporate Security, delivering agentic AI capabilities that give corporate security teams the confidence to protect their people, sites, and operations before risk escalates. With Agentic Corroboration, Agentic Context, and Near-Term Predictive Intelligence, corporate security teams know what happened first, why it matters, and what may happen next as an event unfolds, closing the gap between detecting a threat and acting on it.
September 14th, 2026 — Source

Debian 13.7 ships the fixes behind 92 security advisories, updates 106 packages
The Debian project shipped Debian 13.7 codenamed "trixie.” The project folded in 92 security advisories it had already published separately, added corrections to 106 source packages, and rebuilt the installer around both.
September 14th, 2026 — Source

ENISA launched the CRA Single Reporting Platform for actively exploited vulnerabilities
The EU Agency for Cybersecurity switched on the Cyber Resilience Act's Single Reporting Platform on 11 September 2026, the same day the law's reporting obligations started binding manufacturers. ENISA built the tool and runs its day-to-day operations, a job Article 16(1) of the CRA hands to the agency.
September 14th, 2026 — Source

Entrust turns cryptographic inventory data into security action
Entrust has unveiled new capabilities for its Cryptographic Security Platform (CSP) that help organizations turn Cryptographic Bill of Materials (CBOMs) data into action.
September 14th, 2026 — Source

Hackers target exposed Vite dev servers to steal AWS, Azure secrets
A mass-scanning campaign targeting internet-exposed Vite development servers is attempting to steal cloud credentials and configurations from AWS and Azure deployments.
September 14th, 2026 — Source

Harder, better, safer, stronger: Three-way AI improves cybersecurity
A new deep-learning architecture could deflect cyberattacks by combining several methods for analyzing network traffic, according to research published in the International Journal of Business Intelligence and Data Mining. The approach addresses a weakness in standard intrusion-detection systems, which struggle with the volume and complexity of modern network traffic.
September 14th, 2026 — Source

How to Disable the Run Dialog in Windows 10 & 11
Windows has had the run dialog for many years. Did you know that Windows 10 & 11 allow you to disable the Run dialog if you have a reason to stop people from using it? Here's how.
September 14th, 2026 — Source

In-the-Wild Attacks Hit Popular DevSecOps Platform GitLab
Recently Patched Flaw Is Being Actively Exploited to Steal Files and Credentials
September 14th, 2026 — Source or Source or Source or Source

Independent Investigation of Hugging Face Incident Reveals How Agents Collaborated and Behaved
After six days of on-site investigation at OpenAI, a small team of METR and Redwood Research researchers provided an account of how OpenAI agents behaved during their hack of Hugging Face earlier this year. According to the researchers, roughly 700 agents that were meant to be isolated from one another found a way to communicate and coordinate to pursue goals they could not have achieved working individually.
September 14th, 2026 — Source

Lux 1.50.0 released
Lux has released version 1.50.0 of its VPN service, which aims to enhance online security by protecting users from trackers, adware, and other digital threats. This service provides a reliable solution for safeguarding personal information and improving the overall browsing experience.
September 14th, 2026 — Source

Mullvad VPN 2026.5 released
Mullvad VPN has launched its 2026.5 version, providing users with a straightforward and highly secure way to navigate the internet while protecting their identities. This VPN service is available for multiple platforms, including Windows, Mac, Linux, and Android.
September 14th, 2026 — Source

Music distributors agree to new anti-fraud measures
The Streaming Integrity Initiative aims to combat fraud in music streaming.
September 14th, 2026 — Source

New Warnings About the Risks of AI to Humanity Revive a Long-Running Debate
Concerns over the potential risks of the technology are rising as new AI models become more powerful, heightening both the potential for misuse by people with criminal aims.
September 14th, 2026 — Source

Organizational cyber security and privacy risk management activities - ITSP.10.036
Organizational cyber security and privacy risk management activities (ITSP.10.036) is an unclassified publication issued under the authority of the Head, Canadian Centre for Cyber Security (Cyber Centre).
September 14th, 2026 — Source

Perfect-10 GitLab bug under attack days after patch lands
CISA confirms active exploitation as watchTowr spots miscreants probing internet-facing servers
September 14th, 2026 — Source

Personal, Financial Info Exposed in Revolut Data Breach
The company unintentionally disclosed users' information to a third party impersonating a government agency.
September 14th, 2026 — Source

Revolut falls for fake government requests, hands over customer data
Passports, selfies, transaction histories exposed as self-proclaimed culprits demand 10,000 Bitcoin
September 14th, 2026 — Source

Revolut Reveals Data Breach Tied to Faked Official Request
Financial Platform Was Socially Engineered Into Disclosing Sensitive Customer Data
September 14th, 2026 — Source or Source or Source or Source or Source

SecretDNS 4.0.4 released
SecretDNS 4.0.4 has been released, offering enhanced security for Domain Name Server (DNS) resolution via the HTTPS protocol. This encryption protects the data transmitted between clients and DNS resolvers, ensuring a secure and private online experience. Key features include robust privacy protection, customizable DNS settings using CloudFlare, advanced SNI (Server Name Indication) fragmentation for specified domains, and comprehensive reporting capabilities for monitoring DNS activities. SecretDNS not only prevents unauthorized interception of DNS queries but also improves overall network performance by addressing common issues faced during traditional DNS resolution.
September 14th, 2026 — Source

Telus Warns Customers of Account Breaches
Stolen credentials were used in a multi-month campaign to access subscriber personal data and billing records.
September 14th, 2026 — Source

The Race to Control AI and Protect What Makes Us Human
As researchers warn that misaligned AI could threaten human survival, even beneficial systems may erode the critical thinking that defines our humanity.
September 14th, 2026 — Source

The Vietnam APIS Leak Put 220 Million Passport Records Online, and No One Will Say Whose Database It Was
An Elasticsearch cluster holding nine years of airline passenger manifests sat reachable from the open internet. Three months after it was closed, nobody has admitted to running it.
September 14th, 2026 — Source

Three JFrog Artifactory Flaws Exploited for Backdoor Deployment
The vulnerabilities can allow attackers to bypass authentication and elevate their privileges to administrator.
September 14th, 2026 — Source

UK.gov begins killing off passwords for 23 million users
Passkeys promise fewer phishing headaches -- and £600 a day off Whitehall's SMS bill
September 14th, 2026 — Source

What we know about the Revolut data breach so far
Someone impersonating a government agency, using an email address on that agency's domain, obtained sensitive customer records from Revolut. The bank confirmed the incident on Saturday, September 12.
September 14th, 2026 — Source

Why Patch Automation Needs Brakes, Not Just an Accelerator
The pace at which software changes is increasing, while the time available to IT teams to evaluate those changes is not.
September 14th, 2026 — Source

Your PC knows your age. Your TV knows what you watch. Privacy is disappearing
Privacy used to be a default feature of technology. Computers didn't know who you were. Nor did any of the other appliances and devices living in our homes.
September 14th, 2026 — Source

Internet — Security Issues — September 11th, 2026

153M+ driver's licenses were leaked and put up for sale online - FBI on the case
Over 153 million driver's licenses, medical cards, and travel documents from victims in the United States and Canada recently ended up on the dark web, available to purchase through a service called Nexus. The company claimed the scanned documents were obtained through an identity verification company breach. Companies collecting scans of identifying documents-- which often include things like an individual's full name, ID number, and address — is fairly commonplace these days.
September 11th, 2026 — Source

AI agents exploited PaperCut flaws to breach 395 organizations
A threat actor built a working exploit for PaperCut print management software, then handed the job of breaking into hundreds of organizations to AI agents that did most of the work on their own, according to GreyNoise.
September 11th, 2026 — Source

Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion
Anthropic reveals how criminal groups are increasingly targeting AI vendors' own infrastructure, including to steal a pre-release Claude model.
September 11th, 2026 — Source

Anthropic spent this week in hot water over cybersecurity
A researcher's resignation letter went viral, just before the company released details about four models going rogue.
September 11th, 2026 — Source

Artifactory flaws chained in attacks deploying backdoor malware
Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers.
September 11th, 2026 — Source

Automox Mitigation Worklets cut endpoint exposure to unpatchable flaws
Automox has announced its AI-speed Mitigation Worklet Pipeline, which automates mitigation to reduce risk from the increased volume and velocity of frontier-model AI vulnerabilities. Now the time from vulnerability disclosure to exposure mitigation is shortened from days or weeks to minutes or hours.
September 11th, 2026 — Source

Check Point Patches Critical VPN Vulnerabilities
Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution.
September 11th, 2026 — Source

ClickFix attacks infecting PCs and Macs are going viral
Simplicity—combined with the difficulty of getting stuff done—makes ClickFix ideal.
September 11th, 2026 — Source

Cold TAKE: Amazon's New Encryption Method Still Doesn't Deliver Real Privacy
Amazon recently debuted a new feature for its Ring cameras that the company is calling Throw Away the Key Encryption (TAKE). The idea is to cut back on the amount of video content available to the company, and thus potentially available to law enforcement. But while it might technically add a speed bump to accessing full video content, it doesn't deliver nearly the level of privacy we should be demanding from video doorbells and other security cameras.
September 11th, 2026 — Source

EU's Cyber Resilience Act starts the 24-hour vulnerability clock
Manufacturers must now disclose actively exploited flaws and severe security incidents through ENISA's new reporting platform
September 11th, 2026 — Source

European Union forces strict exploit reporting under new law
The EU Cyber Resilience Act takes effect, imposing strict timelines for tech vendors to report active vulnerabilities and incidents.
September 11th, 2026 — Source

Florida sues Netflix, alleging it built its ad business on families' data
Florida's attorney general has sued Netflix, alleging it collected detailed viewing data on families and children and used it to build an advertising business it had promised never to run. The state seeks penalties and data deletion. Netflix says the lawsuit lacks merit.
September 11th, 2026 — Source

GitLab urges users to patch max severity path traversal flaw
GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706.
September 11th, 2026 — Source

GitLab Vulnerability Exploited One Day After Disclosure
The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server.
September 11th, 2026 — Source

How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface
As AI platforms become part of daily workflows, attackers have found a new way in: the platforms themselves. The Huntress Security Operations Center (SOC) says the bigger day-to-day risk comes from threat actors abusing the AI features people already trust and rely on, rather than attacks on the AI companies or models themselves.
September 11th, 2026 — Source

IDScan confirms breach after 153 million driver's licenses leak on dark web
Days after reports linked IDScan to a dark web database holding more than 153 million driver's license scans, the identity verification company has confirmed hackers accessed customer data stored on its cloud platform.
September 11th, 2026 — Source

In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review
Noteworthy stories that might have slipped under the radar: Invisible Unicode slips past phishing filters, US puts $10 million bounty on Iranian cyber official, military ties of Chinese hacking group QTFY.
September 11th, 2026 — Source

Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance
Financials have not been disclosed, but the estimated cost is in the tens of millions of dollars.
September 11th, 2026 — Source or Source

New fuzzing tool finds security vulnerabilities in WordPress plugins
WordPress is one of the most widely used content management systems for websites. Plugins are very popular among developers and users because they allow websites to be customized with functionality tailored to individual needs.
September 11th, 2026 — Source

PaperCut Flaws Exploited in AI-Powered Attacks
A Russian threat actor used AI to build, test, and deploy exploits against hundreds of organizations worldwide.
September 11th, 2026 — Source

Proton Pass 1.40.2 released
Proton Pass 1.40.2 has been released, enhancing its position as an open-source password and identity manager that prioritizes user privacy. Developed by Proton AG in Switzerland, Proton Pass securely stores logins, two-factor authentication (2FA) codes, email aliases, secure notes, and files, all protected by end-to-end encryption. It operates seamlessly across major operating systems and browsers, making it accessible for a wide range of users.
September 11th, 2026 — Source

ProtonVPN 5.1.8 released
ProtonVPN has released version 5.1.8 of its cross-platform, subscription-based VPN service, which is known for its reliability and stability. Unlike most free VPNs that compromise user experience by throttling speeds, displaying ads, or selling user data, ProtonVPN offers a trustworthy free version that stands out in the crowded market.
September 11th, 2026 — Source

Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider
Hardware crypto wallet maker Trezor is warning customers for the second time in as many months that one of the companies it relies on was hacked, exposing the data of Trezor's customers to hackers.
September 11th, 2026 — Source

Surfshark Systems Targeted by Hackers
A misconfigured test server containing engineering material, including internal configurations, was accessed by threat actors.
September 11th, 2026 — Source

Thailand's Cloud Security Standard Is Now in Force: What Providers and CII Operators Must Review
Thailand's two-year runway for cloud security compliance has ended. The country's Cloud Security Standard took effect Sept. 10, 2026, two years after its publication in the Royal Gazette.
September 11th, 2026 — Source

The ClickFix Attack Gets You to Paste the Malware Yourself, and It Now Speaks Mac
There is a class of attack that sandboxing cannot fix, because the victim performs the dangerous step voluntarily. The ClickFix attack is the current champion of that class, and it is having an extremely good year.
September 11th, 2026 — Source

Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack
Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking.
September 11th, 2026 — Source

Trezor: 347,000 users targeted in phishing attacks after Brevo breach
Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link.
September 11th, 2026 — Source

Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison
Oleksii Oleksiyovych Lytvynenko has been sentenced to 4 years in prison after he was arrested in Ireland in 2023.
September 11th, 2026 — Source

Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars
Swapping legal work for malware development ended in extradition and a guilty plea
September 11th, 2026 — Source

Internet — Security Issues — September 10th, 2026

4.1 Million Impacted by AdaptHealth Data Breach
In June 2026, hackers stole personal, health, and insurance information from AdaptHealth's systems.
September 10th, 2026 — Source

Anthropic Researcher Resigns With Warning About the Dangers of AI Development
An Anthropic researcher said he is resigning from the company over concerns the artificial intelligence firm and its competitors are not acting responsibly in AI development, echoing concerns raised inside and outside of the industry about the technology's potential to elude human control.
September 10th, 2026 — Source

Apple is building photo verification for the people who need it most
Apple has introduced Apple Reference Image, an opt-in feature designed to verify the authenticity of photos taken with iPhone 18 Pro models.
September 10th, 2026 — Source

Attackers call employees' personal phones to break into Microsoft 365 accounts
Attackers are calling or texting employees on their personal phones, posing as internal IT staff, in a social engineering campaign that tricks them into handing over access to corporate cloud accounts. Once inside, they pull files and email from Microsoft 365 apps, SharePoint, OneDrive, and inboxes, for weeks at a time, according to Microsoft Security Research.
September 10th, 2026 — Source

BitDefender Antivirus Free Edition 27.0.62.355 released
Bitdefender Antivirus Free Edition 27.0.62.355 has been released, providing users with a lightweight and effective solution for antivirus protection without any cost. This basic freeware version is a simplified alternative to BitDefender Antivirus Plus and Total Security, delivering essential features to safeguard systems against viruses, malware, and online threats.
September 10th, 2026 — Source

Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)
State-sponsored and financially-motivated attackers are actively exploiting CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC), which is used for centrally managing multiple Cisco Secure Firewall devices across a network.
September 10th, 2026 — Source

Critical NetScaler Vulnerability Exploited in Attacks
Tracked as CVE-2026-19490, the authentication bypass flaw has been exploited in the wild since at least September 3.
September 10th, 2026 — Source

Cryptohack Roundup: Trezor's Phishing Warning
Also: 'White-Hat' Hackers Withdraw $320M From Liquid
September 10th, 2026 — Source

Cybersecurity M&A Roundup: 33 Deals Announced in August 2026
Significant cybersecurity M&A deals announced by Brinqa, Cribl, Echo, Fortinet, Kiteworks, Palo Alto Networks, and Visa.
September 10th, 2026 — Source

Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews
Deceptive apps in Early Access are being used by dishonest developers for their own benefit.
September 10th, 2026 — Source

Dental contractor set up secret account with access to 4,000 patient records then left the company
PWNED Welcome back to PWNED, the weekly column where we highlight examples of how not to handle your security. This week's tale of woe comes from a very unhealthy part of the healthcare sector.
September 10th, 2026 — Source

ExpressVPN versus NordVPN: Clash of the heavyweight titans
In the red corner we have ExpressVPN and in the blue corner we have NordVPN.
September 10th, 2026 — Source

Fake GTA 6 download delivers malware-packed bundle to impatient gamers
Grand Theft Auto VI (GTA 6) is still three months from release, but cybercriminals are not waiting for the launch date. Security firm Huntress found malware disguised as a leaked copy of the game, aimed at fans hoping to get their hands on it early.
September 10th, 2026 — Source

Hacker Conversations: Vinnie Liu, Performer Turned Ringmaster
Vinnie Liu was recruited by the NSA when he was just 17 years old. He is now the CEO of Bishop Fox.
September 10th, 2026 — Source

ID verification giant IDScan confirms data breach with more than 150 million driver's licenses stolen
ID verification service IDScan has confirmed that a data breach involved the theft of driver's licenses from its systems, a week after a report said the identity document checker had been breached during a year-long hack.
September 10th, 2026 — Source or Source

IPVanish 4.3.33.1487 released
IPVanish has recently released version 4.3.33.1487, enhancing its reputation as a high-speed, cross-platform VPN service. Key features of IPVanish include a strict zero-logging policy, which guarantees users' privacy and security while browsing online. This commitment to privacy is complemented by several protective measures, such as a kill switch that halts all internet traffic if the VPN connection is lost, ensuring that no data is exposed during disconnections. Additionally, IPVanish offers IPv6 Leak Protection, which prevents the leakage of IPv6 addresses by forcing traffic to use IPv4. For users on shared networks, LAN Blocking is implemented to secure device communications.
September 10th, 2026 — Source

Microsoft Patches a Record 974 Security Flaws in Biggest Update Ever
If you add 25 non-Microsoft CVEs with Microsoft fixes, the total reaches 999.
September 10th, 2026 — Source

MSNightmare drops ShieldCrash zero-day after Windows 11 patch
Security researcher MSNightmare publishes a proof-of-concept bypassing Microsoft's ShieldBreak patch for Windows Defender.
September 10th, 2026 — Source

New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws
Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon” that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome.
September 10th, 2026 — Source

New 'ShieldCrash' Zero-Day Exploit Targets Microsoft Defender
The exploit provides full System privileges on Windows machines running the September 2026 patches.
September 10th, 2026 — Source

NextGen Mirth Connect Flaws Expose Downstream System Logins
Attackers Could Steal Credentials Used to Reach Connected Hospital Systems
September 10th, 2026 — Source or Source or Source or Source

Organizations Warned of Cisco Secure FMC Exploitation
Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026.
September 10th, 2026 — Source

Scytale expands vendor risk management with AI-powered TPRM tools
Scytale has announced the launch of their latest AI-powered third-party risk management (TPRM) capabilities within its Vendors module. The release further extends vendor risk management from a periodic review exercise into a continuously updated vendor risk intelligence engine, giving security and GRC teams a current view of every vendor in their ecosystem.
September 10th, 2026 — Source

ShieldCrash proof of concept claims to bypass Microsoft Defender patch
An anonymous researcher using the handle Nightmare Eclipse released a proof-of-concept exploit called ShieldCrash on September 8, 2026, hours after Microsoft shipped its September Patch Tuesday security updates. The exploit is presented as a bypass of a fix Microsoft issued weeks earlier for a Microsoft Defender flaw known as ShieldBreak. Microsoft has not confirmed the bypass and did not respond to a request for comment before ShieldCrash went public.
September 10th, 2026 — Source

ShinyHunters expose 6.4M in attack on medical supplier McKesson
Have I Been Pwned logs leaked records spanning patients, staff, and providers
September 10th, 2026 — Source

The Top 4 Threats We Found by Investigating Every Alert for a Quarter
Tl;dr: Identity was the target in roughly half of all confirmed malicious activity. Prophet Security breaks down the four main attack patterns seen across customer environments between May and July 2026, and explains why some attacks succeeded while others were blocked.
September 10th, 2026 — Source

Trezor, BitBox users targeted in newsletter phishing spree
Attackers exploit legitimate mailing channels to demand crypto wallet backups
September 10th, 2026 — Source

US CISA Hires Stalled in Red Tape
About 250 Qualified New Hires for the Nation's Cyber Agency Are in Limbo
September 10th, 2026 — Source or Source or Source or Source

Widened Scan Turns Up Fourth Rogue Claude Cyber Incident
Anthropic is most concerned about Claude Mythos 5's reckless behavior after recent incidents in which real systems were hacked.
September 10th, 2026 — Source

WordPress adds automated security checks to block risky plugin releases
WordPress' automated security review will now assess every plugin release before it is distributed through the WordPress.org update API. Releases considered a potential security risk will be blocked automatically.
September 10th, 2026 — Source

Internet — Security Issues — September 9th, 2026

$245 million in stolen crypto funded racketeering crew's lavish lifestyle
A 22-year-old man built his fortune by breaking into strangers' digital wallets, then spent it on nightclub tabs, private jets, and a fleet of cars worth millions.
September 9th, 2026 — Source

A Vulnerability in SAP Extended Passport (EPP) Processing Could Allow for Remote Code Execution
A vulnerability has been discovered in SAP Extended Passport (EPP) Processing that could allow for remote code execution. SAP Extended Passport (EPP) Processing is a core system data structure and tracing mechanism within SAP Kernel code used to track, log, and monitor end-to-end communication across distributed SAP and non-SAP landscapes. It is created automatically when a new user session opens and travels via communication protocols like RFC (Remote Function Call) and HTTP from the client to the server. Onapsis explained that, because EPP processing is shared kernel code, the vulnerability is reachable from the SAP GUI layer every end user connects to, and from the RFC layer that links SAP systems to one another. The bug is remotely exploitable without authentication and exists by default in a range of SAP components.
September 9th, 2026 — Source

AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns
Criminal and state-sponsored adversaries are increasingly using AI to automate and scale their attacks, according to GTIG.
September 9th, 2026 — Source

Akeyless adds real-time enforcement for AI agents in production
Akeyless has announced the general availability of Akeyless Agentic Runtime Authority, the real-time identity control layer for AI agent actions. It works on top of Akeyless SecretlessAI, a credential protection layer that keeps credentials out of AI agents and brokers access to enterprise systems. Runtime Authority adds the next layer of control, enforcing intent based access control restricting what agents actually do once they have access.
September 9th, 2026 — Source

Android's September 2026 Updates Patch 180 Vulnerabilities
The security updates resolve critical flaws across Android's Framework, System, and Kernel components.
September 9th, 2026 — Source

Best VPNs for torrenting: 5 top picks for speed, privacy, and security
Stay safe while torrenting with these top VPN picks.
September 9th, 2026 — Source

Boston Scientific Flags Financial Hit From Cyberattack
Nearly 2-Week Production and Shipping Pause Puts Sales Targets Out of Reach
September 9th, 2026 — Source or Source or Watch Video

Chinese AI firms are siphoning capabilities from American models, CISA warns
Knowledge distillation is a standard AI training technique that uses outputs from a more capable model to help train another model. The agencies say companies in China have used it at industrial scale to extract restricted capabilities including reasoning, coding and other specialized functions, making distillation a core part of their model development strategies.
September 9th, 2026 — Source

Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories
Major chipmakers announced patches for vulnerabilities recently discovered in their products.
September 9th, 2026 — Source

Chrome 153 Patches Seventh Zero-Day of 2026
The Chrome update includes 230 security fixes, and users are advised to update their browsers as soon as possible.
September 9th, 2026 — Source

Claude Hackers Are Hijacking Tokens From Paying Subscribers
Diligent token tracking makes them easy to spot, though.
September 9th, 2026 — Source

Cryptocrook ringleader, 22, who met crew on Minecraft admits role in $245M heist
Stolen funds bought mansions, private jets, and supercars -- now he faces up to 20 years
September 9th, 2026 — Source

Digital Sovereignty: What It Is, What It Could Be
The term "digital sovereignty” has become ubiquitous. European officials invoke it in debates about cloud infrastructure, AI, semiconductors, and platform regulation. Governments throughout the global majority use it to argue for greater control over data and communications infrastructure and boost their economies. Companies market "sovereign cloud” products designed to reassure their customers that their information stays under local jurisdiction. But digital sovereignty could be something more: an opportunity for users around the world to build more resilient, open systems and the skills and infrastructure to maintain them.
September 9th, 2026 — Source

Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension
The critical, unauthenticated bugs allow attackers to bypass authentication and proxy a user's browser traffic.
September 9th, 2026 — Source

France's Mistral AI Touts Its Europeanism, But Faces Limits
'Made in France' Can Only Get Mistral So Far in AI Race
September 9th, 2026 — Source or Source or Source or Source

Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491)
Google has fixed 230 vulnerabilities in Chrome, including a zero-day flaw, CVE-2026-87491, with an in-the-wild exploit.
September 9th, 2026 — Source

Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory
A rootkit found on hacked F5 BIG-IP APM devices skips the usual step of writing a web shell to disk, hiding it in memory instead, according to Sophos.
September 9th, 2026 — Source

HelmGuard Raises $7.3 Million for Agentic GRC and Security
The company will increase its US market presence and will expand its engineering and go-to-market teams.
September 9th, 2026 — Source

ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws
AVEVA and Rockwell Automation also released patches for vulnerabilities affecting industrial control system products.
September 9th, 2026 — Source

Ivanti Patches Critical Flaws Across Enterprise Security Products
Six critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches for authentication bypass flaws.
September 9th, 2026 — Source

LG strongly denies TV spying claims, says tracking and snooping concerns 'not true' — online investigation claims 216,000,000 TVs spy and record audio
TVs were also said to be recording, scanning local area networks, logging data, and recording audio while in standby.
September 9th, 2026 — Source

Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy
Muse runs on a dedicated, secure virtual machine that houses both the agent and the user's data.
September 9th, 2026 — Source

MFA's Weakest Link: Account Recovery Is the New Attack Path
For years, security teams have been making account takeover harder. Multi-factor authentication (MFA) added crucial protection to password-only authentication, while conditional access and device trust add further checks before users can reach sensitive systems.
September 9th, 2026 — Source

Microsoft's September updates fix a record 973 security flaws
September's Patch Tuesday sets a record with nearly 1,000 fixes. Two vulnerabilities are already being exploited, so update your PC now.
September 9th, 2026 — Source

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access
An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates.
September 9th, 2026 — Source

New Phishing Attack Creates Malicious Pages Inside the Victim's Browser
Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block.
September 9th, 2026 — Source

Orchid Security targets AI agent risk with drift detection and kill switches
Orchid Security has announced identity drift detection and application-level kill switches for AI agents. They can complete authorized objectives beyond their initial privilege level within seconds. AI agents do not need to "break” security controls or workflow guardrails.
September 9th, 2026 — Source

Over 36,000 exposed Plex servers vulnerable to recent flaws
Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks.
September 9th, 2026 — Source

Preventing IAM Template Injection in EKS Authentication Pipelines
The aws-auth ConfigMap remains the default identity-mapping mechanism for a large number of production Amazon EKS clusters. CI/CD pipelines that programmatically render aws-auth entries through Helm value interpolation, Kustomize replacements, Terraform templatefile() calls, or shell-based envsubst are particularly susceptible to IAM template injection—a commonly overlooked privilege escalation risk in cloud-native infrastructure today.
September 9th, 2026 — Source

Researcher reverse-engineers infamous Stuxnet malware source code, publishes it on Github for all — attack targeted Iranian nuclear facilities and was the first software of its type to cause physical damage
Be sure to test this in a virtual machine.
September 9th, 2026 — Source

Securin Platform helps security teams prove when attack paths are closed
Securin has announced the general availability of the Securin Platform, an AI-native Preemptive Exposure Management platform designed to answer three questions security teams struggle with every day: What can attackers actually exploit? What should we fix first? And did the fix actually work?
September 9th, 2026 — Source

or Source

Security boffin claims airport group left API keys in client-side JavaScript for four years
Researcher believes overprivileged Iterable creds exposed 8.8M customer records -- and could have enabled mass deletion
September 9th, 2026 — Source

September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor
September 2026 Patch Tuesday is here, with Microsoft delivering another record-breaking number of patches, including those for two vulnerabilities that have been exploited as zero-days.
September 9th, 2026 — Source

SoftEther VPN Client + VPN Gate Client Plugin 2026.09.09 Build 9807 released
The SoftEther VPN Client + VPN Gate Client Plugin has recently been updated to version 2026.09.09 Build 9807. This product serves as an open-source alternative to both OpenVPN and Microsoft's VPN servers, offering users a gateway to a secure and unrestricted internet experience. Developed as part of a global initiative by the University of Tsukuba in Japan, it aims to enhance internet accessibility and freedom.
September 9th, 2026 — Source

Someone might be in your PayPal account. Here's a quick way to check
Suspicious PayPal activity? Here's how to quickly check for unauthorized access and lock hackers out of your account in minutes.
September 9th, 2026 — Source

This Key Will Self-Destruct: An Open Standard for Revocable API Keys
Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default.
September 9th, 2026 — Source

US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities
Distillation is an 'attack' against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model.
September 9th, 2026 — Source

US says Chinese firms extracted billions of tokens from frontier AI models
U.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted industrial-scale distillation attacks on American frontier AI models since at least late 2024.
September 9th, 2026 — Source

Veradigm warns of patient data breach after ransomware gang claims attack
Veradigm warns of patient data breach after ransomware gang claims attack
September 9th, 2026 — Source

WeChat worm could pwn a friend before they even answered the call
Calif says AI helped turn a VoIP memory bug into cross-platform RCE before Tencent shut it down
September 9th, 2026 — Source

Zscaler Agentic SOC combines AI agents with zero trust telemetry
Zscaler has announced Zscaler Agentic SOC, a new approach to security operations built to proactively reduce exposures, scale human expertise and stop AI-driven attacks at machine speed. Simply layering in AI capabilities onto the existing security stack will not provide the protection needed. Zscaler is delivering a new solution to the security operations center (SOC), purpose-built from the ground up with an AI-first approach to detect, investigate, and stop threats at machine speed.
September 9th, 2026 — Source

Internet — Security Issues — August 29th, 2026

I asked 100 companies for my data. Some deleted it instead.
I filed a request with McDonald's earlier this month to access all of the personal data the fast food company collected about me, and I received a stunning 515-page report a few days later that detailed my app interactions in granular detail and predicted I would never stop eating there.
August 29th, 2026 — Source

Fastest VPN of 2026: Improve Your Privacy Without Sacrificing Speed
The fastest VPNs let you stream movies, play online games and browse the web without making your internet connection unusably slow.
August 29th, 2026 — Source

Hasbro Data Breach Exposed Employee Personal Information
A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach.
August 29th, 2026 — Source

Internet — Security Issues — August 28th, 2026

AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?
AI can help us find vulnerabilities faster than ever. But what happens when the rest of the vulnerability management ecosystem can't keep up?
August 28th, 2026 — Source

Android 17 adds new protections against sneaky Wi-Fi tracking and web snooping
Google introduced a batch of network security changes coming in Android 17, aimed at making it harder for network operators, snoops, and scammers to track what you do on your phone.
August 28th, 2026 — Source

ATF Confirms Cyber Incident After Ransomware Group Claims Attack
The Bureau of Alcohol, Tobacco, Firearms and Explosives has described it as a 'major incident' and it's conducting an investigation with the DOJ.
August 28th, 2026 — Source

Authorities arrest 2 alleged members of prolific hacking group TeamPCP
Authorities in Australia said Wednesday that they arrested two men accused of participating in cybercrimes for TeamPCP, a prolific group of hackers that, over nine months, has carried out a relentless series of supply-chain attacks that infected more than 1,000 organizations worldwide.
August 28th, 2026 — Source

CISA: Most exploited vulnerabilities should have been eradicated decades ago
Organizational culture and systemic gaps in Secure by Design adoption blamed for sorry state of affairs
August 28th, 2026 — Source

Cyberattack on Three UK Airports Exposes Data of 8.7 Million Customers
A cyberattack on Manchester Airports Group exposed information belonging to about 8.7 million customers across three UK airports.
August 28th, 2026 — Source

How to protect yourself from identity theft: A complete safety guide
One data breach could be all it takes for someone to steal your identity. If you want to know how to protect yourself from identity theft, a handful of habits go a long way.
August 28th, 2026 — Source

In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions
Noteworthy stories that might have slipped under the radar: Manchester Airports Group cyberattack, Carhartt breach data was partly fake, U.S. Bank responds to ransomware gang's claims.
August 28th, 2026 — Source

Industry that built the problem offers to sell you the solution
100+ tech giants warn AI attacks are coming, skip the part where they pay for defenses
August 28th, 2026 — Source

Judge Orders Pentagon to Reverse Anthropic Blacklisting
Court Says DOD's Designation Was Illegal First Amendment Retaliation
August 28th, 2026 — Source or Source or Source or Source

Manchester Airports Group breached, millions of customers' data stolen
Someone broke into the systems of Manchester Airports Group (MAG) and walked away with a "quantity” of customer data from three UK airports, the company has confirmed.
August 28th, 2026 — Source

Multiple cameras can better track a person's identity using geometry and appearance
By combining two complementary clues—camera geometry and visual appearance—researchers at the Institute of Science Tokyo, Japan, developed a new approach for preserving identities across multiple cameras. The method uses epipolar geometry to identify spatially consistent candidate matches and appearance similarity to distinguish among possible identities. The approach can be integrated with existing single-camera tracking systems without requiring environment-specific retraining.
August 28th, 2026 — Source

North Korean remote workers are broadening their job hunt beyond IT
North Korean (DPRK) remote workers are expanding their job searches beyond IT, according to Huntress. Recent investigations have identified suspected DPRK workers employed in sales and marketing and the medical profession.
August 28th, 2026 — Source

OpenAI Agents Exploited Linux Kernel Flaw on Company's Own Systems
CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.
August 28th, 2026 — Source

Over 8,300 Gitea servers vulnerable to code execution attacks
Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver.
August 28th, 2026 — Source

PaperCut Releases Emergency Patch for Exploited Zero-Day
A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.
August 28th, 2026 — Source

Rubrik: Firms Want Joint Agent Identity, Visibility, Recovery
Managing artificial intelligence agents' identities and monitoring their activity in one place has become a new business driver for cloud and data security firm Rubrik, CEO Bipul Sinha said Thursday.
August 28th, 2026 — Source or Source or Source or Source

Security researchers find surveillance implants in Chinese-made routers sold worldwide — three different backdoor-like implants hidden in firmware
The surveillance seems aimed at the domestic market, but it knocks huge holes in the security of the devices it's found in.
August 28th, 2026 — Source

ServiceNow warns of three max severity security vulnerabilities
ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection, and privilege escalation attacks.
August 28th, 2026 — Source

Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge
Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated.
August 28th, 2026 — Source

The peach emoji can actually make your Wi-Fi safer
Who knew the peach emoji could be so powerful?
August 28th, 2026 — Source

Think You've Eliminated Chinese AI? Check the Model's Lineage, Cisco Says
New research shows that country-of-origin labels can obscure an AI model's upstream dependencies, inherited behaviors and potential security risks.
August 28th, 2026 — Source

Toy-making giant Hasbro disclose data breach affecting employees
Hasbro, one of the world's largest toy and game companies, has disclosed that attackers have accessed the personal and financial information of an undisclosed number of employees.
August 28th, 2026 — Source

US government snitch-finder pleads guilty to leaking state secrets to foreign spies
The IT specialist began contacting a foreign government within days of being assigned to the DIA's Insider Threat Division
August 28th, 2026 — Source

Internet — Security Issues — August 25th, 2026

AI Agents Are a Cybersecurity Nightmare That's Only Just Begun
Those AI agents going rogue? It's not Skynet, but security experts are a little freaked out for far more mundane reasons.
August 25th, 2026 — Source

Alice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails
The company, previously known as ActiveFence, has raised a total of $280 million from investors.
August 25th, 2026 — Source

BMC Vulnerabilities Put Thousands of Servers at Risk of Hardware-Level Compromise
Security researchers are warning that thousands of enterprise servers could be exposed to compromise through vulnerabilities in their Baseboard Management Controllers (BMCs) - specialized processors embedded in server motherboards that provide administrators with remote, out-of-band control. Research highlighted by Ars Technica shows that weaknesses in BMC firmware and long-standing management protocols can allow attackers to gain control beneath the operating system, potentially giving them a foothold that conventional endpoint security tools cannot see.
August 25th, 2026 — Source

CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw
Disclosed in January and honeypots buzzed soon after, CISA says it's finally time for the USG to plug the gap
August 25th, 2026 — Source

CISA Warns of Exploited Oracle WebLogic Vulnerability
The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers.
August 25th, 2026 — Source

Citrix UniconOS dual boot turns Windows endpoints into their own recovery device
Citrix announced Citrix UniconOS dual boot, a new endpoint resiliency capability designed to help organizations recover access to work in minutes — without spare hardware, central reimaging or prolonged business downtime.
August 25th, 2026 — Source

Crooks push Mac malware through fake OpenAI Codex ads
Sponsored search results lead developers straight into a ClickFix malware trap
August 25th, 2026 — Source

ESET AV Remover 1.6.17.0 released
ESET has released version 1.6.17.0 of its ESET AV Remover, a specialized tool designed to help users uninstall existing antivirus programs from their computers prior to installing ESET antivirus software. While it is tailored for ESET installations, the tool is versatile enough to remove any antivirus software, making it a useful asset for tech professionals to have on hand
August 25th, 2026 — Source

Fake OpenAI Codex download tricks macOS users into installing malware
A malware campaign using a sponsored search ad and a fake OpenAI Codex download page to trick macOS users into pasting a malicious command into Terminal has been uncovered by Cato Networks.
August 25th, 2026 — Source

Fideo Lens reveals connections across identities, accounts and devices
Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices.
August 25th, 2026 — Source

First Malware Built Specifically for Car Head Units Fuels Botnet
Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices.
August 25th, 2026 — Source

From Fake Workers to Account Recovery: The Growing Identity Verification Risk
Security teams have spent years hardening authentication, with controls like multi-factor authentication (MFA) and conditional access now commonplace. While stronger authentication can make traditional credential theft less effective, it doesn't solve every identity problem.
August 25th, 2026 — Source

Hackers breached over 270 Zimbra servers in ongoing attacks
Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability.
August 25th, 2026 — Source

Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference
Hands-on Cyber Attack Methods course returns to SecurityWeek's ICS Cybersecurity Conference, October 6--8 at the W Nashville.
August 25th, 2026 — Source

Hospital operator Nutex Health says data stolen in cyberattack
Healthcare and services provider Nutex is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers.
August 25th, 2026 — Source

INTERPOL crackdown on West African crime rings uncovers troubling new trend
Police across 22 countries arrested 58 people and identified 263 suspects during an eight-month INTERPOL operation targeting West African organized crime groups.
August 25th, 2026 — Source

Login AlertX 3.7.8 released
Login AlertX is an innovative security tool designed to enhance user protection by notifying individuals whenever their computer is accessed. This feature adds a crucial layer of security for personal information, enabling users to quickly respond to any unauthorized access and potential threats.
August 25th, 2026 — Source

Massive DDoS attack disrupts Norway's government digital services
A large distributed denial-of-service (DDoS) attack has disrupted Norway's shared government digital infrastructure since Monday, affecting services used by the public sector.
August 25th, 2026 — Source

Most Organizations Declare Victory Over a Breach Too Early
Why Bringing Systems Back Online Is Not the Same as Breach Recovery
August 25th, 2026 — Source or Source

Police arrests dozens of suspects in global cybercrime crackdown
Law enforcement agencies from 22 countries helped identify 263 suspects and arrested 58 individuals linked to cybercrime networks coordinated by African crime groups.
August 25th, 2026 — Source

RegRun Security Suite Platinum 18.65.2026.824 released
RegRun Security Suite Platinum version 18.65.2026.824 has been released, offering a comprehensive solution for PC security. This advanced suite is designed to effectively identify and eliminate various types of malware, including Trojans, viruses, worms, spyware, adware, and rootkits. Beyond its malware detection capabilities, RegRun also simplifies computer management by optimizing the Windows startup process, which can lead to reduced boot times.
August 25th, 2026 — Source

ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack
Cybersecurity company ReliaQuest has confirmed that one of its own employees fell for a social engineering attack, handing attackers a password and a brief window into the company's identity system.
August 25th, 2026 — Source

Silent Patches Don't Stop Attackers -- They Blind Defenders
Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk.
August 25th, 2026 — Source

Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff
AI infrastructure, including advanced semiconductors mostly made in Taiwan, has become a key point of competition between the U.S. and China.
August 25th, 2026 — Source

That fake Grand Theft Auto VI demo is actually just malware
In the long wait for the highly anticipated Grand Theft Auto VI, an open-world game about crime, some in the gaming community are being targeted by cybercriminals in the real world.
August 25th, 2026 — Source

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks
At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday.
August 25th, 2026 — Source

WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update
When Android users get a call from a non-contact, they will see more information about the caller, including their country.
August 25th, 2026 — Source or Source

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities
CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin.
August 25th, 2026 — Source

Internet — Security Issues — August 23rd, 2026

BitDefender Antivirus Free Edition 27.0.62.352 released
Bitdefender Antivirus Free Edition 27.0.62.352 has been released, serving as a streamlined, no-cost alternative to Bitdefender's paid offerings, such as Antivirus Plus and Total Security. This free version provides essential antivirus protection and guards against online threats, making it an appealing choice for users seeking reliable security without financial commitment.
August 23rd, 2026 — Source

Fake GTA VI ISO circulates on the internet a few days after leak, internet sleuths claim 113GB download is padded malware — testers claim file is 99.99% empty zeroes with 50KB virus embedded
Beware downloading unreleased pirated games folks.
August 23rd, 2026 — Source

SoftEther VPN Client + VPN Gate Client Plugin 2026.08.24 Build 9807 released
The SoftEther VPN Client combined with the VPN Gate Client Plugin has recently been updated to version 2026.08.24 Build 9807. This innovative software serves as an open-source alternative to traditional VPN services like OpenVPN and Microsoft's VPN offerings, providing users with a secure and unrestricted internet experience. Developed by the University of Tsukuba in Japan, SoftEther VPN aims to promote a more accessible internet for everyone.
August 23rd, 2026 — Source

ToxicPanda Android malware uses VPN permissions to block Google Play
The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands.
August 23rd, 2026 — Source

Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs
Here's an overview of some of last week's most interesting news, articles, interviews and videos:
August 23rd, 2026 — Source

Internet — Security Issues — August 22nd, 2026

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight
The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware.
August 22nd, 2026 — Source

Hackers infect Android car head units with proxy botnet malware
A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud.
August 22nd, 2026 — Source

If you're not using AI to attack your own systems, your adversaries will
Agents are also the new attack surface - cue defenders' existential angst
August 22nd, 2026 — Source

Named Pipes Under Attack: Securing Windows Interprocess Communication
Named pipes are a common choice for communication between applications running on the same Windows computer. They are fast, supported directly by the operating system, and work well for communication between Windows services, desktop applications, tray processes, command-line utilities, and background agents.
August 22nd, 2026 — Source

Resonance: A Plague Tale Legacy Cracked Ahead of Launch-Pirates Warn Against Malware
Modders say that the game runs fine, although there are reports that the currently available pirated packages may contain malware, since the repacker responsible for the pre-release pirated version of the game allegedly has a history of packaging Hypervisor scripts in some of their downloads. Aside from the screenshots from the leaked version of the game, the prequel game's install size was reported to be around 75 GB. It's unclear how the game repackers got hold of a pre-release version of Resonance, and neither Focus Entertainment nor Asobo Studios have responded to the leak.
August 22nd, 2026 — Source

Internet — Security Issues — August 21st, 2026

6 Tips for Protecting Your Identity Online
Identity theft can cause serious financial and emotional damage, but there are simple ways to reduce your risk online.
August 21st, 2026 — Source

$10K phishing kit claims it can plant rogue passkeys for persistent access to pwned accounts
Seller's demos show a browser-in-the-middle attack adding credentials seconds after authentication
August 21st, 2026 — Source

Best VPN services: 7 top picks for every VPN need
We tested the field and picked the best VPN overall plus the best options for budget, free use, privacy, and travel.
August 21st, 2026 — Source

CISA orders feds to patch actively exploited TrueConf Server flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform.
August 21st, 2026 — Source

Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)
Citrix has patched two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw tracked as CVE-2026-19490, and is urging customers to upgrade affected appliances as soon as possible.
August 21st, 2026 — Source

Contractors' CMMC Confidence Rises as Ability to Prove It Falls Behind
Two industry surveys released this week by Kiteworks and CyberSheath paint a consistent picture of the defense industrial base.
August 21st, 2026 — Source

Critical Isolated-vm Vulnerability Leads to RCE on Host
The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process.
August 21st, 2026 — Source

Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini
Researchers say the new 'Cryptographic Context Injection' technique conceals malicious instructions until they are decrypted inside a trusted execution environment.
August 21st, 2026 — Source

Former NSA Director Paul Nakasone Launches National Security Advisory Firm
The newly-formed Nakasone Group will counsel government leaders, corporations, prominent families, and other private clients confronting cybersecurity, geopolitical, and personal security risks.
August 21st, 2026 — Source

Genetic algorithms test cybersecurity defenses against adaptive malware
The COVID-19 pandemic changed the way many people approached their work across the globe. For Carnegie Mellon University Africa's Jema Ndibwile, it changed the way he viewed a completely different type of virus: a computer virus.
August 21st, 2026 — Source

GitLab 19.3 helps enterprises scale agentic development securely
GitLab has announced updates that give enterprises more control as they scale agentic software development. GitLab Dedicated customers, who already run their most sensitive software delivery workloads on GitLab, can now run GitLab Duo Agent Platform inside that same single tenant environment and region, connect their own models for inference, and keep AI-processed data inside their existing security boundary.
August 21st, 2026 — Source

GTA 6 leaker may have access to a playable build as fake downloads spread malware
New footage suggests the leaker could be playing the game directly
August 21st, 2026 — Source

Hackers abuse FTP server banners to deliver new Windows malware
Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE.
August 21st, 2026 — Source

Hackers found a way into 140 banking apps. Here's how you might be helping them
This Android banking Trojan has returned with new ways to steal your credentials and more.
August 21st, 2026 — Source

Hackers poison popular Rust crates to steal developers' credentials
Malicious updates turned routine builds into a delivery system for infostealer malware
August 21st, 2026 — Source

Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it
Ukrainian hacktivists exploiting the bugs, but TrueConf's reach stretches well beyond home turf
August 21st, 2026 — Source

How to join the awesome password-free future and use passkeys
Managing passwords is and always has been a giant pain, but passkeys offer a better way. They are an advanced system that automatically signs you in to online services using your phone's Face ID (or Touch ID) or your computer's password.
August 21st, 2026 — Source

Hundreds of leaked AWS keys give full control over corporate accounts
More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid.
August 21st, 2026 — Source

In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug
Other noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST certification.
August 21st, 2026 — Source

Is Online Privacy Possible? How Digital Identities Can Help
Over the last two decades, the internet quietly rebuilt itself around a business model that depends on knowing everything about you. Every app you install or use, every account you create, every website you visit, and every form you fill out becomes another data point feeding a system designed to track, profile, and monetize you and your identity.
August 21st, 2026 — Source

Microsoft patches critical Entra ID vulnerability (CVE-2026-69836)
Microsoft has patched a critical remote code execution vulnerability (CVE-2026-69836) in Entra ID, initially reported to have been exploited in the wild.
August 21st, 2026 — Source or Source

Microsoft patches max severity code execution, privilege escalation flaws
Microsoft has patched multiple maximum-severity vulnerabilities in Entra ID, Azure Arc, and Exchange Online that allowed attackers to gain remote code execution and escalate privileges.
August 21st, 2026 — Source

MLflow Flaw Opens a Path to Cloud Credentials Theft
CISA Sets Sept. 2 Deadline to Patch, Amid Active Exploitation
August 21st, 2026 — Source or Source

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets
Researchers say iAuthFlow V2 can register an attacker-controlled passkey, enabling persistent access even after passwords are changed and active sessions revoked.
August 21st, 2026 — Source

Nine Million Photos of People's Faces Discovered in Exposed Database
A website that helps to identify people using just a photo was found to have a massive database of images unsecured on the web.
August 21st, 2026 — Source

Quantum Masterclass: Cryptography's Enterprise Blind Spot
IBM's Jai Singh Arun on Mapping Cryptography Risk Before Quantum Threats
August 21st, 2026 — Source or Source or Source or Source

SickKids children's hospital bandages up careers website after intruder breaks in
Toronto org says it wasn't the only one to be affected by the third-party software vulnerability
August 21st, 2026 — Source or Source

Slovakia Speed Cameras Ship With an SMS Backdoor Tied to 12 Russian Numbers
An EU-funded traffic enforcement rollout has turned into a hardware supply-chain problem.
August 21st, 2026 — Source or Source

Wi-Fi 7's WPA3 protections come with a compatibility catch
CableLabs wants hardware makers to embrace a workaround that keeps legacy kit connected
August 21st, 2026 — Source

Internet — Security Issues — August 19th, 2026

3 Lessons for Securing Large-Scale Events: Inside FIFA World Cup 2026
FIFA's World Cup 2026 (FWC26) drew millions of fans, spectators, and athletes from around the world for a 39-day tournament that spanned three countries and 16 host cities.
August 19th, 2026 — Source

943 Patches Rolled Out With Oracle's August 2026 Security Update
The fixes resolve over 1,000 vulnerabilities across two dozen products, including over 460 remotely exploitable bugs.
August 19th, 2026 — Source

Brinqa acquires PlexTrac to bring validated remediation to exposure management
Brinqa has announced its acquisition of PlexTra, adding the ability to verify that remediation efforts have actually worked. The combined capabilities uniquely position Brinqa to identify and prioritize the exposures that matter most, drive remediation, and validate that fixes hold, closing the CTEM loop.
August 19th, 2026 — Source

CareCloud confirms 3.7M patients had their medical records stolen in data breach
Hackers have stolen the personal information and medical records of more than 3.75 million people in a data breach at health data giant CareCloud, the company has confirmed with federal regulators. The disclosure marks the first confirmation of the scale of the data breach, which is now confirmed to be the fifth-largest theft of health data in 2026 so far.
August 19th, 2026 — Source

Chrome, Firefox Updates Patch Dozens of Vulnerabilities
The bugs could lead to code execution, privilege escalation, sandbox escape, and information disclosure.
August 19th, 2026 — Source

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities
The flaws can be exploited for remote code execution, authentication bypass, and device takeover.
August 19th, 2026 — Source

CISA: Medusa ransomware hit over 500 critical infrastructure orgs
The Cybersecurity and Infrastructure Security Agency (CISA) said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021.
August 19th, 2026 — Source

Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign
The cybercrime gang has listed major companies such as Shell, Philips, Fiserv, Zebra, Mindray, and Largan Precision.
August 19th, 2026 — Source

Comcast gives its Wi-Fi motion detector a security makeover
Rebranded feature promises household alerts without video, but mind the small print
August 19th, 2026 — Source

Critical RCE flaw in Windows IKE Extension now actively exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component.
August 19th, 2026 — Source

DoD Regulatory Pause: No Excuse to Weaken Supply Chain Trust
IonQ CIO Katie Arrington on Unclassified Info, CMMC's Third-Party Supplier Audits
August 19th, 2026 — Source

Flock surveillance backlash mounts as fiendish Halloween plans circulate
CEO apologizes for police misuse as activists call for vandal action against license plate cameras
August 19th, 2026 — Source

Google's AI security agents found 100+ critical software vulnerabilities in just two days
Google's Mandiant has disclosed the workings of an internal tool that uses chains of AI agents to hunt for vulnerabilities in source code, saying it found over 100 verified, high-severity flaws in just two days during a live investigation into stolen corporate repositories.
August 19th, 2026 — Source

Hacker leaks GTA VI gameplay and map to protest digital-only release — claims pre-orders are a legacy of physical game releases
The hacker wants Rockstar to stop pre-selling digital games.
August 19th, 2026 — Source

How attackers persuade AI agents to break the rules
Today, most of us interact with AI assistants—reactive bots that wait for human instructions. Yet AI assistants are rapidly being replaced by agentic AI agents that can interact with external tools, browse the web, generate images, send emails and perform increasingly complex workflows on behalf of users.
August 19th, 2026 — Source

Intezer adds native response automation without separate SOAR
Intezer has announced Workflows, a native automation and response builder that enables security teams to create and customize response workflows directly inside the Intezer platform.
August 19th, 2026 — Source

Is Microsoft Defender crashing on your PC? A bad update is breaking scans
A recent update breaks Full and Quick Scans in Microsoft Defender, but a new security intelligence patch fixes the problem.
August 19th, 2026 — Source

Medusa ransomware gang has hit over 500 organizations, CISA warns
Medusa ransomware has breached more than 500 organizations since it first appeared in June 2021, the FBI, CISA, and the Department of Health and Human Services (HHS) said in an updated joint advisory.
August 19th, 2026 — Source

Microsoft fixes known issue causing Windows Defender crashes
Microsoft has resolved a bug that caused Windows Defender to crash after a recent security update, resulting in 0xc0000005 access violation errors on some affected systems.
August 19th, 2026 — Source

Microsoft's warning mail for unsupported Entra voice and SMS auth misses key info
Microsoft will make passkeys default, but admins can temporarily delay migration until February 2027. Here's how.
August 19th, 2026 — Source

Multiple Vulnerabilities in Oracle Products Could Allow for Arbitrary Code Execution
Multiple vulnerabilities have been discovered in Oracle products, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.
August 19th, 2026 — Source

NordVPN review: More than just a VPN, it's a privacy powerhouse
Packed with powerful features and blazing-fast speeds
August 19th, 2026 — Source

OpenAI puts major frontier AI training run on hold over cyber risks
OpenAI temporarily paused reinforcement learning (RL) training on its latest models intended for deployment for two weeks while it hardened and red-teamed research environments and expanded monitoring.
August 19th, 2026 — Source or Source

Password spraying attacks surge 155x as hackers exploit MFA gaps
Huntress has observed a 155x increase in password spraying attacks in the first half of 2026. Brute force is old news, but the spin driving that spike is new.
August 19th, 2026 — Source

PixelReel Minecraft mod exposes Plex server API keys
Redditors have discovered that the PixelReel Minecraft mod leaks API keys and server URLs for Jellyfin, Plex, and Emby as of August 19, 2026.
August 19th, 2026 — Source

Prevalent AI Raises $22 Million to Expand Data Fabric Platform
The previously bootstrapped company helps organizations securely and reliably operate AI agents at scale.
August 19th, 2026 — Source

The emerging threat of violent, exploitative digital 'com networks': what do we need to know?
For many parents, keeping their children safe online is a top priority. But now there's an emerging threat: "com networks." Com networks (short for community networks) are online groups that mostly target vulnerable young people in the online spaces they use every day, including gaming platforms and social media.
August 19th, 2026 — Source

US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them
The 17 members of the Mabna Institute targeted hundreds of universities and organizations in the US and abroad.
August 19th, 2026 — Source or Source

Virtual Event Today: CodeSecCon -- Secure Your Code and Applications
CodeSecCon is the premier virtual event bringing together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.
August 19th, 2026 — Source

Internet — Security Issues — August 18th, 2026

300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw
Tracked as CVE-2026-15748, the arbitrary file upload bug allows unauthenticated attackers to upload executable files.
August 18th, 2026 — Source

AI-Driven Vulnerability Surge Breaks the Traditional Patching Model
Rapid7 warns that traditional patch cycles cannot keep pace with soaring vulnerability disclosures and faster exploitation, forcing defenders to prioritize exposure over severity scores.
August 18th, 2026 — Source

Apple plugs image-processing hole ripe for spyware abuse
Patch batch spans current kit, older iGadgets, Macs, and Vision Pro
August 18th, 2026 — Source

Apple Warns Users in 110 Countries of Mercenary Spyware as iPhone Alerts Get Harder to Miss
Apple sent a new wave of mercenary spyware threat notifications to targeted users in 110 countries, while making the warnings more visible on iPhones. The alerts signal suspected targeting, not confirmed compromise, and Apple is urging affected users to verify the warning, consider Lockdown Mode, and seek expert help.
August 18th, 2026 — Source

As water systems face cyberattacks, research points to solutions
Recent cyberattacks on municipal water systems across the United States have renewed concerns about the cybersecurity of the operational technology that supports critical infrastructure.
August 18th, 2026 — Source

Avast Clear 26.8.11125 released
Avast has released version 26.8.11125 of its uninstall utility, Avast Clear, which is designed to completely remove Avast software when the standard Add/Remove programs feature fails to work effectively. This tool is particularly useful for users facing issues with uninstalling the antivirus program.
August 18th, 2026 — Source

Avast One Free Edition 26.8.11125 released
Avast One Free Edition 26.8.11125 is the latest release of Avast's comprehensive security application designed to protect users from malware, phishing, and various online threats while maintaining system performance. This free antivirus software is ideal for everyday users who frequently engage in activities like browsing, shopping, or emailing, and wish to have reliable protection without any associated costs.
August 18th, 2026 — Source

Avast Premium 26.8.11125 released
Avast Premium Security, now in version 26.8.11125, offers an all-inclusive suite of applications designed to protect your devices from malware, viruses, and other cyber threats. While a free edition is available, the premium version acts like a dedicated security team, ensuring your important files and personal data remain secure. By utilizing additional data backup utilities alongside Avast, users can further safeguard against potential data loss.
August 18th, 2026 — Source

AVG Clear (Remover) 26.8.11125 released
AVG Clear (Remover) version 26.8.11125 has been released, providing users with a tool to thoroughly uninstall their current AVG installation. This comprehensive removal process eliminates not only the application itself but also associated registry items, installation files, and user data. AVG Clear is recommended as a last resort for situations where other uninstall attempts have failed, such as during repairs, reinstalls, or complete removals.
August 18th, 2026 — Source

AVG Internet Security 26.8.11125 released
AVG Internet Security 26.8.11125 has been released, providing users with comprehensive multi-layer protection against various online threats such as identity theft, spam, and viruses. This updated version utilizes advanced technologies, including the innovative LinkScanner, which offers real-time protection against malicious websites. The software also features Identity Protection technology, ensuring that users can safely conduct online banking and shopping without the risk of identity theft.
August 18th, 2026 — Source

CISA gives feds 3 days to fix actively exploited Ray RCE bug
Phishing, malvertising attacks could target devs to gain access to private corporate networks
August 18th, 2026 — Source

CISA: Windows Task Host flaw now exploited by ransomware gangs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April.
August 18th, 2026 — Source

CISO Conversations: Nico Waisman -- From Self-Taught Hacker to AI-Driven Offensive Security at XBOW
With no formal training and no career plan, Waisman built a path from Argentina's early hacking scene to leading security at an AI-powered offensive security firm.
August 18th, 2026 — Source

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)
GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication.
August 18th, 2026 — Source

FBI Pegasus Records Expose a Blind Spot in US Spyware Oversight
Federal court records show how far the FBI's Pegasus review progressed — and why new US spyware reporting will still leave major gaps in government hacking transparency.
August 18th, 2026 — Source

Fortinet Acquires AI Security Company Virtue AI
Fortinet will use Virtue AI technology to enhance its AI security portfolio, including for AI models, applications, and agentic systems.
August 18th, 2026 — Source

GEEKOM Removes Legacy Mini PC Driver Package Flagged as Malware
GEEKOM has removed an outdated LAN driver package after Microsoft Defender and several online security services flagged a file inside the archive as potentially malicious. The legacy download was reportedly associated with the GEEKOM A7, A8, AE7, AX7 Pro, and AX8 Pro mini PCs. The issue initially surfaced through reports from GEEKOM users. Microsoft Defender classified the questionable file as a Trojan capable of executing commands from an attacker. Subsequent checks using VirusTotal, FileScan, and MetaDefender reportedly produced further detections, indicating that the warning was not limited to one security engine. GEEKOM has now issued an official response and apologized for leaving the affected resource online.
August 18th, 2026 — Source

GitLab Patches Critical Code Injection Vulnerability
The security defect allows unauthenticated attackers to modify or delete user data and public projects.
August 18th, 2026 — Source

Google's $10,000 refund test shows why AI agents need zero trust
Google's open-source autonomous Customer Support & Returns Agent, built using the Agent Development Kit (ADK) and Gemini, demonstrates how developers can apply zero-trust security principles to AI agents that interact with sensitive systems and take real-world actions.
August 18th, 2026 — Source

Hacker claims millions of records stolen from corporate Azure tenants
A threat actor known as "TheHatman” claims to have obtained millions of employee records from the Azure environments of several Fortune 500 companies, including McDonald's, Vodafone, Kyndryl, and Tata Consultancy Services (TCS), according to Hudson Rock.
August 18th, 2026 — Source

Hackers Tricked a Major Retailer's AI Shopping Bot to Do Something It Was Never Supposed To
At the cybersecurity conference Black Hat, researchers showed how an AI assistant at one of America's largest retailers could be tricked into following hidden instructions and exposing sensitive system information.
August 18th, 2026 — Source

Hackers want your nudes. Here's how to keep your privates, private
Sexploitation isn't a new concept. Long before the internet, people blackmailed others over sexually explicit photos or videos. But this week, the US Federal Bureau of Investigation released a fresh warning around hackers and sexortion—an alert aimed at both adults and children.
August 18th, 2026 — Source

Heights Finance Data Breach Impacts at Least 1.2 Million Individuals
Hackers stole names, addresses, phone numbers, Social Security numbers, and financial information from a third-party platform.
August 18th, 2026 — Source

Microsoft Copilot reveals secret input that allowed it to be hacked
It's not every day that attackers can force a frontier AI model to cough up user passwords and other sensitive data without user confirmation. That's exactly what researchers recently did to Microsoft 365 Copilot for enterprise. Even more unusual is the source they tapped to discover the critical vulnerability that made their exploit possible. Rather than employing reverse engineering or other traditional vulnerability-hunting methods, they asked Copilot. The LLM assistant readily complied.
August 18th, 2026 — Source

NETSCOUT expands Adaptive DDoS Protection with outbound attack mitigation
NETSCOUT has announced an extension of its Adaptive DDoS Protection (ADP) solution enabling service providers to automatically detect and mitigate outbound DDoS attack traffic. By extending protection from the attack target towards its source, NETSCOUT helps operators prevent compromised subscriber devices from disrupting their own networks, consuming costly capacity and attacking customers and organizations across the internet.
August 18th, 2026 — Source

Norton 360 Remover 26.8.11404.0 released
Norton 360 Remover version 26.8.11404.0 has been released as a dedicated tool for efficiently uninstalling the Norton device security product from Windows systems. This application is designed to thoroughly eliminate all associated files and settings, ensuring a clean slate for users who wish to reinstall Norton software afterward. By utilizing Norton 360 Remover, users can enhance the performance and reliability of their security setup by removing any remnants from previous installations.
August 18th, 2026 — Source

OpenAI tightens defenses after AI agents breach research environment
Following the OpenAI-Hugging Face incident, in which an agentic collective autonomously penetrated OpenAI's research infrastructure and another company's production infrastructure by chaining together multiple weaknesses, OpenAI began strengthening its safety requirements. The weaknesses included previously unknown vulnerabilities and credentials leaked online.
August 18th, 2026 — Source

Synthesized builds Test Data Agent to validate AI agents with production-like data
Synthesized has announced its Test Data Agent, a new agentic infrastructure capability being developed to create and provision the realistic data, business context, and system states enterprises need to validate AI agents safely before production deployment.
August 18th, 2026 — Source

Xpander Raises $7.5 Million for AI Management and Governance
Xpander's platform uses a universal agent harness that executes AI agents as portable workloads and securely renders interfaces on demand.
August 18th, 2026 — Source

Your Controls Block Known Attacks. What About the Behavior?
A prevention score tells you what a control recognizes. It doesn't tell you what that control stops.
August 18th, 2026 — Source

Internet — Security Issues — August 17th, 2026

40,000 Impacted by SafePal Data Breach
Hackers exploited a vulnerability in the order-tracking function of a plugin to access SafePal customer information.
August 17th, 2026 — Source

Apple Sounds Mercenary Spyware Alarm For Millions Of iPhone Users
Apple has issued high-confidence threat notifications to targeted users across 110 countries, warning that their devices may have been targeted by sophisticated mercenary spyware attacks.
August 17th, 2026 — Source

Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer
A recently patched security flaw in Apple macOS is being actively exploited by hackers to bypass authentication, gain root access, and install a cryptominer, the Netherlands' National Cyber Security Centre (NCSC) warns.
August 17th, 2026 — Source

Black Hat and DEF CON are AI conferences now, too
On this week's episode of The Reg's Kettle podcast, we revisit 'hacker summer camp,' where the hottest topic was ... sigh... agentic AI
August 17th, 2026 — Source

Certighost and the Privilege Hiding in Your Certificate Authority
Every mature Active Directory environment has a component that quietly holds more power than the people running it usually admit: the Certification Authority (CA). The thing your entire estate has agreed to believe.
August 17th, 2026 — Source

Code fixers have fired up the AI warp drive. Strange new worlds await
With more patches per month than at a pirate convention, the bug must be an endangered species. Well, about that
August 17th, 2026 — Source

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure
The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components.
August 17th, 2026 — Source

Crypto hardware wallet owners face fresh security risks after recent spate of personal data thefts
Data breaches at two shipping companies has put cryptocurrency owners with physical hardware wallets at greater risk of having their funds stolen, highlighting weaknesses in the broader tech ecosystem relied on by the crypto industry.
August 17th, 2026 — Source

Fortinet expands AI security portfolio with Virtue AI acquisition
Fortinet has acquired Virtue AI, strengthening its broader Security for AI strategy and its vision for securing the agentic enterprise. The acquisition builds on Fortinet's existing AI security portfolio, which includes the FortiGate Hyperscale Firewall.
August 17th, 2026 — Source

France's tax authority admits hackers made off with data on 678,000 individuals
France's tax authority has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems, saying the intrusion exposed data on 678,000 individuals and professionals.
August 17th, 2026 — Source

French tax authority data breach affects 678,000 individuals
The French Ministry of the Economy and Finance has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems and stole data belonging to 678,000 individuals.
August 17th, 2026 — Source

Hackers exploit macOS Screen Sharing vulnerability — update your Mac ASAP
A macOS Screen Sharing vulnerability that Apple patched earlier this month is now being actively exploited by hackers. Attackers use the flaw to seize control of Macs and install cryptocurrency miners.
August 17th, 2026 — Source

HestiaCP 1.10.3 Released: Fixes FileGator and Firewall Bugs
HestiaCP 1.10.3 has been released to address critical bugs in the FileGator file manager and firewall rules following the earlier 1.10.0 feature update. The update resolves a missing Symfony dependency that caused errors in the FileGator and fixes a bug related to the reordering of firewall rules that could lead to configuration issues. Additional improvements include CSS fixes for DNS records, routine locale updates, and a significant code cleanup that streamlined the codebase. The quick turnaround time for this release, just two days after the initial issue was reported, highlights the efficiency of the small team maintaining the project
August 17th, 2026 — Source

Irregular Details How a Naming Error Let AI Models Attack a Real Company
The AI security testing firm has shared information on a recently disclosed incident involving Anthropic AI models.
August 17th, 2026 — Source

Malwarebytes 5.26.0.4151 / 5.6.3.284 released
Malwarebytes has recently released versions 5.26.0.4151 and 5.6.3.284, enhancing its reputation as a comprehensive antivirus solution designed to protect users from a wide range of threats, including malware, ransomware, and harmful websites. The software is favored among technology enthusiasts and professionals for its effective malware detection and removal capabilities, offering both a free and a premium version.
August 17th, 2026 — Source

Microsoft Faces Fresh Nightmare Eclipse Zero-Day
Attack Manipulates Defender Cloud Hydration to Install an Attacker DLL
August 17th, 2026 — Source

Microsoft working on Defender patch for ShieldBreak zero-day
On Friday, Microsoft confirmed it has begun working on a security patch for a Defender zero-day vulnerability named "ShieldBreak."
August 17th, 2026 — Source

Mullvad VPN 2026.4 released
Mullvad VPN has launched its 2026.4 version, available for Windows, Mac, Linux, and Android users, providing a reliable way to browse the internet while safeguarding your identity. This VPN stands out as a straightforward privacy solution, prioritizing security and anonymity over marketing gimmicks and complex subscription models.
August 17th, 2026 — Source

Philips and GE investigating Clop ransomware data theft claims
Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data.
August 17th, 2026 — Source

Police bust cybercrime ring accused of stealing €30 million in four-day spree
German and Brazilian police dismantled an international bank fraud ring blamed for a €30 million cyberattack on a German financial institution, arresting four people in Brazil and pursuing three more suspects in Spain and Bulgaria.
August 17th, 2026 — Source

Public Wi-Fi just got riskier. Follow these 4 security tips
Hackers are targeting Wi-Fi networks at hotels and other locales in ever sneakier ways.
August 17th, 2026 — Source

Recent macOS Screen Sharing Vulnerability Exploited in Attacks
Threat actors gained root access to the vulnerable systems and deployed a Monero miner.
August 17th, 2026 — Source

SafePal breach affects 39,798 customers, data allegedly for sale
Cryptocurrency wallet maker SafePal disclosed a data breach that exposed order information for 39,798 customers, including names, email addresses, shipping addresses, phone numbers and purchase details.
August 17th, 2026 — Source

Signal-based system brings end-to-end encryption to shared documents
Researchers from the Max Planck Institute for Security and Privacy, EPFL and the CASA Cluster of Excellence have developed a new approach that provides end-to-end encryption for collaborative online documents throughout the entire process, combining high security standards with the requirements of modern collaboration.
August 17th, 2026 — Source

This hidden Windows 11 setting runs Defender scans you missed
If your PC is off during a scheduled Windows Security scan, it'll get skipped. Use this simple registry tweak to force scans afterwards.
August 17th, 2026 — Source

Told to book a gym class, an AI agent hacked the website instead, in Australia's first known autonomous cyberattack
An Australian man asked his AI assistant to do something entirely mundane, book him into a gym class, and it answered by carrying out the country's first known autonomous cyberattack.
August 17th, 2026 — Source

What actually happens when you let apps track your activity?
And does it even matter?
August 17th, 2026 — Source

Internet — Security Issues — August 13th, 2026

153GB of stolen credentials surface after LiteLLM supply chain attack
A massive 153GB archive stolen during the LiteLLM supply chain attack exposes credentials and other sensitive data linked to thousands of corporate domains, including AWS, Samsung, Cisco, and Salesforce.
August 13th, 2026 — Source

A10 Networks introduces AI Gateway to secure and manage enterprise AI
A10 Networks has announced the general availability of the A10 AI Gateway, a centralized, intelligent control plane that gives organizations unified routing, cost management, and governance across every AI agent, application and large language model (LLM) they use.
August 13th, 2026 — Source

Adobe Commerce Bug Targeted Immediately After Disclosure
The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches.
August 13th, 2026 — Source

As passkeys become default in Entra ID, IT admins may have to worry more about security
Microsoft Entra ID is making passkeys the default in September, but experts warn attackers could exploit unfamiliarity to target users.
August 13th, 2026 — Source

Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)
Threat actors have begun exploiting a critical Microsoft SharePoint flaw following the release of proof-of-concept (PoC) exploit code by Rapid7.
August 13th, 2026 — Source

Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)
A high-severity vulnerability (CVE-2026-20349) is being leveraged by attackers to temporarily interrupt the operation of Cisco firewalls, the company has confirmed.
August 13th, 2026 — Source

Cisco Sees AI Fueling Network Upgrade Supercycle
Customers Are Reprioritizing Budgets for AI, Security and Quantum Readiness
August 13th, 2026 — Source or Source or Source or Source

Coin-sized device can hack a Boeing 737's Flight Management Computer, mess with takeoff weights, or even divert an aircraft — gadget connects to an easily accessible port that overrides commands from the pilots, uses in-flight Wi-Fi
While it does not let hackers control the plane remotely, it could potentially confuse pilots and add to their workload while in-flight.
August 13th, 2026 — Source

Critical VMware vCenter Vulnerability in Attackers' Crosshairs
Tracked as CVE-2026--59310, the directory traversal bug allows remote attackers to execute arbitrary code.
August 13th, 2026 — Source

Critical 'Zoomsday' flaw enables total device takeover during Zoom calls — AI-assisted research only used 20 prompts to find an exploit to hack hundreds of millions of people.
And two of those prompts were probably "no bugs plz" and "kk thx."
August 13th, 2026 — Source

Cybersecurity M&A Roundup: 21 Deals Announced in July 2026
Significant cybersecurity M&A deals announced by Barracuda, CrowdStrike, Cyera, Okta, Palo Alto Networks, and Qualcomm.
August 13th, 2026 — Source

DataGrout helps enterprises control AI usage, governance and LLM costs
SelectHub has announced the launch of DataGrout, its specialized AI research lab introducing an LLM inference optimization platform and AI governance solution for enterprises. DataGrout's mission is to drive token reduction for agentic workflows, chatbots and AI tools, while equipping IT and FinOps leadership with a policy-driven, auditable LLM payload and cost monitoring system to track company-wide AI utilization.
August 13th, 2026 — Source

Flock CEO: 'We got this one wrong'
After reports that some cops misused tracking data it collects, Flock is rolling out policy changes.
August 13th, 2026 — Source

Fortinet Patches Authentication Flaws in FortiWeb and FortiManager
The vulnerabilities could allow attackers to log in with random usernames and passwords or impersonate any FortiGate appliance.
August 13th, 2026 — Source

In a first, US will allow some private firms to carry out cyberattacks
The U.S. government will for the first time allow vetted private companies to launch offensive cyber operations against international criminal gangs and hackers, the White House said on Wednesday.
August 13th, 2026 — Source

IPVanish 4.3.30.12 released
IPVanish has released version 4.3.30.12 of its high-speed, cross-platform VPN service, which emphasizes user privacy and security through a strict zero-logging policy. This ensures that users can browse the internet with confidence, knowing their activities and connection data are not recorded. The VPN is equipped with essential features such as a kill switch that halts all network traffic if the VPN connection drops, preventing any data leaks. Additionally, IPVanish includes IPv6 Leak Protection to ensure that internet traffic is routed through IPv4, thereby preventing any potential exposure of IPv6 addresses. For users sharing a local area network, LAN Blocking is a feature that effectively stops device communications, enhancing security.
August 13th, 2026 — Source

Microsoft is killing off SMS login codes, citing AI-powered hacking
Microsoft Entra ID to phase out SMS authentication on February 1,2027
August 13th, 2026 — Source

Mystery attacker spent a year raiding Salesforce and ServiceNow portals
Custom tools harvested whatever over-permissioned guest accounts would surrender
August 13th, 2026 — Source

NightmareEclipse strikes again at Windows 11 exploit with ShieldBreak proof of concept
NightmareEclipse has released another Windows exploit after Microsoft released its Patch Tuesday updates. ShieldBreak gives attackers admin power.
August 13th, 2026 — Source or Source

Passwords stored in public Google Doc then showed up in search results
Developer spotted hostname and credential string lurking in autocomplete
August 13th, 2026 — Source

Patched SharePoint vulnerability now being exploited in the wild, here's why
Rapid7 released a proof-of-concept exploit a month after Microsoft fixed an issue in SharePoint. Now attackers are using it to hit unpatched targets.
August 13th, 2026 — Source

Rsync 3.5 Fixes 33 Security Issues at Once — and Most of Them Start With a Symlink
The maintainers call it an "extraordinary release.” The changelog reads more like an audit report than a version bump.
August 13th, 2026 — Source

Searchlight Cyber combines exposure and threat intelligence in new PTEM platform
Searchlight Cyber has launched its Preemptive Threat Exposure Management (PTEM) platform, combining exposure visibility with real-world attacker intelligence to help organizations prioritize and reduce the exposures most likely to be exploited.
August 13th, 2026 — Source

The 3 best VPNs we've tested in 2026
Here's who to trust with your privacy (and money).
August 13th, 2026 — Source

Uncle Sam Seeks Private Hackers to Disrupt Criminal Networks
White House Program Will Tap Private Sector for Surveillance and Cyber Operations
August 13th, 2026 — Source or Source or Source or Source

Venture Firm Team8 Secures Additional $365 Million
The Israeli company has nearly $2 billion in total assets under management since 2014.
August 13th, 2026 — Source

WhatsApp rolls out new feature that flags potential scam messages
WhatsApp has begun rolling out a new optional "Scam Alert" feature, which uses a local machine learning model to warn users when scammers are targeting them.
August 13th, 2026 — Source

White House taps security firms for offensive hack-back operations
A new White House memo signed by U.S. President Donald Trump instructs the National Coordination Center (NCC) to establish a program that would allow private security companies to apply for approval to hack foreign cybercrime organizations.
August 13th, 2026 — Source or Source or Source

Zoom Fixes Bug That Let Call Participants Take Control of Other Devices
Attackers just needed to join a meeting to run code on attendees' devices without their knowledge or consent.
August 13th, 2026 — Source

Internet — Security Issues — August 12th, 2026

A severe ASUS Armoury Crate vulnerability affects laptops, handhelds, and desktop PCs — Here's how to check if you're in the clear
It's an 8.4 out of 10 on the CVSS scale, so it shouldn't be taken lightly.
August 12th, 2026 — Source

A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months
Most security stories start with something broken. This one starts with everything working as designed.
August 12th, 2026 — Source

After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug
A security researcher has published details of a new vulnerability in the latest versions of Windows that allows hackers to gain system-wide access to the user's device and data, despite facing a legal threat from Microsoft weeks earlier over the release of previously unknown software flaws.
August 12th, 2026 — Source

Akira ransomware scum blocked victim's security tools -- and broke their own encryptor
Gives a whole new meaning to Safe Mode
August 12th, 2026 — Source

AMD Acknowledges TPM Vulnerability, but Everything Is Now Patched
AMD has acknowledged today that a new vulnerability in the trusted platform module has been found, but fortunately, it was patched before the public announcement. According to AMD, a potential out-of-bounds (OOB) read was present in the TPM 2.0 reference implementation, which could send malicious commands to TPM 2.0 and completely bypass its functionality. If an attacker were able to access and even disable the TPM, all digital signing and encryption would be compromised, earning this vulnerability a very high severity score. Reported under CVE-2026-6726 with a CVSS score of 8.5, and the second being CVE-2026-6727 with a CVSS score of 8.3, these attacks affected every AMD Ryzen CPU from the 3000 to 9000 series of desktop processors.
August 12th, 2026 — Source

Brit rail cops bring live facial recognition to the London Underground
Victoria is the first stop as privacy campaigners warn the technology is becoming routine
August 12th, 2026 — Source

California Puts AI Inside Critical Infrastructure Defenses
California Bets on AI Defense as Federal Cyber Funding Dries Up
August 12th, 2026 — Source or Source or Source or Source

CBTS brings continuous penetration testing to enterprise security
CBTS has launched Penetration Testing as a Service (PTaaS), combining autonomous penetration testing with security expertise to help organizations continuously identify exploitable risks, validate attack paths, and prioritize remediation as their environments evolve.
August 12th, 2026 — Source

Ceva Logistics Operations Disrupted by Cyberattack
Affecting European contract logistics operations at eight Ceva warehouses, the incident caused shipment delays for multiple customers.
August 12th, 2026 — Source

Chipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combined
Intel has informed customers about several high-severity vulnerabilities that can lead to privilege escalation and even code execution.
August 12th, 2026 — Source

Chrome's anti-abuse protections block 7 billion unwanted Android notifications daily
Google Chrome's latest measures against abusive web push notifications include automatically revoking notification permissions for inactive and suspicious websites, helping reduce scams, phishing attempts, and other deceptive content.
August 12th, 2026 — Source

Cloudflare Report Shows Massive Spike in High-Volume DDoS Attacks: Here Is What the Data Shows
Cloudflare says 805 DDoS attacks topped 1 Tbps in Q2 2026 as high-bandwidth attacks surged, raising new concerns for network defenses.
August 12th, 2026 — Source

ConnectSecure helps MSPs automate Microsoft 365 security remediation
ConnectSecure has announced that Microsoft 365 Auto Remediation and AI-powered Training Assessments are now live on the ConnectSecure platform. The capabilities help managed service providers (MSPs) address supported M365 security findings, create and measure assessments, support client training and strengthen security posture from one platform.
August 12th, 2026 — Source

Crytica's RDAi detects OT device tampering from within
Crytica Security has developed a patented solution that delivers rapid, deterministic threat detection for operational technology (OT), protecting the embedded systems and connected devices that underpin critical infrastructure, national security, and healthcare without disrupting operations.
August 12th, 2026 — Source

Deloitte strengthens AI governance to support trusted enterprise adoption
Deloitte has expanded AI Controls and Assurance services and solutions designed to help organizations confidently adopt, scale and govern AI across the enterprise.
August 12th, 2026 — Source

Exposed: Woeful security at UK criminal records office that led to sensitive data leak
Nobody patched the CMS or read the alerts, and ACRO still cannot tell whether info was exfiltrated
August 12th, 2026 — Source

FBI: Hackers target online accounts to steal nude photos
The FBI warns that cybercriminals are targeting adults' and children's social media and other online accounts to steal sexually explicit images or videos.
August 12th, 2026 — Source or Source or Source

Fresh Windows Zero-Day Exploited in North Korean Cyberattacks
The bug allowed attackers to gain full control of the victims' systems and deploy the ForestTiger backdoor.
August 12th, 2026 — Source

ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact
CISA has also published several advisories describing vulnerabilities in ICS and other OT products.
August 12th, 2026 — Source

Ivanti EPM Update Patches Remotely Exploitable Flaws
The vulnerabilities could be exploited to leak credentials for external SQL connections or crash an agent service.
August 12th, 2026 — Source

Joint guidance on opportunities for artificial intelligence in cyber defence
The Canadian Centre for Cyber Security (Cyber Centre) has joined the Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) and the following international partners in releasing cyber security guidance on opportunities for artificial intelligence (AI) in cyber defence:
August 12th, 2026 — Source

Lazarus hackers exploited Windows zero-day to target defense firms
North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign.
August 12th, 2026 — Source or Source

Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)
Microsoft's August 2026 Patch Tuesday delivered security fixes for 400+ vulnerabilities, including one that has been exploited in zero-day attacks (CVE-2026-68820) and three that were publicly disclosed prior to the release of the patches.
August 12th, 2026 — Source

Microsoft releases KB5120249 as the latest Windows 10 extended security update
Microsoft has released the eighth extended security update for Windows 10 since mainstream support for the operating system came to an end toward the end of last year.
August 12th, 2026 — Source

Mindgard Raises $30 Million to Protect AI Systems
The cybersecurity startup will use the fresh investment to scale its product, engineering, sales, and marketing teams.
August 12th, 2026 — Source

New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges
A security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldBreak" after Microsoft released the August 2026 Patch Tuesday security updates.
August 12th, 2026 — Source

Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack
LiteLLM was compromised through the Trivy hack and abused to distribute information-stealing malware to its users.
August 12th, 2026 — Source

Passenger returning from DEF CON 34 spoofs Delta Wi-Fi network while in flight using pentest tool — pilots tell ground crew to alert corporate security after attendee from hacking conference brings the party to the sky
"We believe they are trying to scam the other passengers.”
August 12th, 2026 — Source

Researchers found a way to hijack devices through Zoom screen sharing
A public AI tool found the dangerous Zoom flaw in under 20 prompts.
August 12th, 2026 — Source

ScienceLogic delivers secure AI deployment and smarter IT operations with Skylar AI 2.5
ScienceLogic has announced Skylar AI 2.5, expanding secure deployment options for organizations with stringent security, sovereignty, and compliance requirements, while introducing enhancements that strengthen AI performance, operational intelligence, and enterprise integrations. The release further improves AI accuracy, platform performance, and natural language user experience across the ScienceLogic AI Platform.
August 12th, 2026 — Source

SharePoint Vulnerability Exploited Shortly After PoC Release
The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild.
August 12th, 2026 — Source

Signal adds new security feature to thwart man-in-the-middle attacks
Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven't been intercepted.
August 12th, 2026 — Source or Source

Smooth-talking fraudsters clone contactless cards, authorize payments in just 13 minutes
Social engineering and malware combine to enable financial fraud before banks have time to act
August 12th, 2026 — Source

Stealthy 'City-Forum' Attacks Target Salesforce and ServiceNow With Custom Toolset
Researchers observed the novel campaign exploiting unauthenticated guest access to quietly enumerate and exfiltrate exposed data from both platforms.
August 12th, 2026 — Source

Suspected China-linked hackers used AI to run the first-ever end-to-end autonomous cyberattack on Taiwan's government, Israeli firm says — open-source-built tool continuously devised effective hack strategies in real-time
Experts warn that every government should now assume it is under permanent automated assault.
August 12th, 2026 — Source

The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In
For many security teams, the expected route into the corporate network begins with a phishing email or exploited vulnerability. Certain techniques differ, exploiting the hiring process to gain legitimate access.
August 12th, 2026 — Source

These Clothing Patterns Can Help You Hide From Surveillance Cameras
Don't want your identity recorded? It's time to become acquainted with swirls.
August 12th, 2026 — Source

Uber Freight keeps on trucking after extortion crew breaks in
Helix claims nearly a million files, while the logistics biz says operations never hit the brakes
August 12th, 2026 — Source

WhatsApp Unveils New Scam Alert Feature
Signal has also made a security announcement: an automatic key verification feature to complement its safety number system.
August 12th, 2026 — Source

Internet — Security Issues — August 9th, 2026

A new attack slips past the latest defenses built into your computer's processor
Chipmakers and operating system developers have spent years building defenses. A new study from MIT's Computer Science and Artificial Intelligence Laboratory (CSAIL) shows that a key assumption behind many of them doesn't hold.
August 9th, 2026 — Source

Farbar Recovery Scan Tool 09.08.2026 released
The Farbar Recovery Scan Tool (FRST) has released its version 09.08.2026, a free and portable application designed to assist users in diagnosing malware-related issues on Windows systems. This tool is available for both 32-bit and 64-bit architectures. Users can run FRST not only on their regular Windows environment but also within the Windows Recovery Environment, which is particularly useful for diagnosing and resolving boot problems.
August 9th, 2026 — Source

Framework's Data Breach Revealed Customer Data: Here's What to Know
The computer company has notified all customers of a data breach.
August 9th, 2026 — Source or Source

iDefender 6.0.1.0 released
iDefender 6.0.1.0 has been released as an advanced security solution tailored for home users, combining an Intrusion Prevention System (HIPS) and Real-time Endpoint Detection and Response (EDR). This integrated platform is designed to protect devices from various cyber threats by actively monitoring and responding to suspicious activities, thereby ensuring safety and integrity.
August 9th, 2026 — Source

Ransomware gangs skip the CEO, head straight for the 40-something IT manager
Gen Xers who feel triggered by this should remember to unplug the network cable and call the cops
August 9th, 2026 — Source

SoftEther VPN Client + VPN Gate Client Plugin 2026.08.10 Build 9807 released
The recently released SoftEther VPN Client + VPN Gate Client Plugin (2026.08.10 Build 9807) is a powerful open-source alternative to popular VPN services like OpenVPN and Microsoft's SSTP VPN. Developed by the University of Tsukuba in Japan, this tool provides users with a secure and unrestricted internet experience, making it easier to bypass censorship, protect connections on public Wi-Fi, and access geo-blocked content.
August 9th, 2026 — Source

The AI safety test is becoming a safety risk
Over the past few months, AI agents undergoing cybersecurity evaluations have escaped their boundaries, accessed the internet, and, in some cases, hacked into real-world systems. The incidents have involved models from OpenAI, Anthropic, Meta, and, most recently, Chinese AI lab Moonshot AI, with testing conducted by several different organizations, including a cyber evaluation startup called Irregular.
August 9th, 2026 — Source

This 'adversarial' pattern can prevent surveillance cameras from detecting you
Bill Swearingen has spent the past year running largely the same test, over and over again. The goal was to produce a computer-generated pattern that could block the surveillance cameras lining America's streets from detecting it.
August 9th, 2026 — Source

Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026
Here's an overview of some of last week's most interesting news, articles, interviews and videos:
August 9th, 2026 — Source

Internet — Security Issues — August 8th, 2026

Critical One-Click Vulnerability in Atlassian's Rovo AI Exposed Enterprise Data
The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data.
August 8th, 2026 — Source

Hackers breach TrueConf to trojanize client installers with backdoors
The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors.
August 8th, 2026 — Source

OpenAI Is Watching Astra Think. Can It See Trouble?
Chain-of-Thought Monitoring Faces a Tougher Cyber Test
August 8th, 2026 — Source

Internet — Security Issues — August 7th, 2026

200 accounts compromised in Swiss government's Microsoft SharePoint breach
Hackers exploited vulnerabilities in Microsoft SharePoint servers belonging to Switzerland's Federal Office of Information Technology, Systems and Telecommunication (BIT), compromising the login credentials of around 200 accounts.
August 7th, 2026 — Source

3.8 Million Impacted by Unlimited Technology Systems Data Breach
Hackers stole personal, medical, and health insurance information from a company's data center.
August 7th, 2026 — Source

Are Ray-Ban Meta glasses a privacy risk? Here's what you should know
Not all features are equal when it comes to securing your data.
August 7th, 2026 — Source

Attacker phished way into US defense supplier's Microsoft 365 account
Intruder gained access to engineering files and potentially export-controlled technical data
August 7th, 2026 — Source

Black Hat USA 2026 -- Summary of Vendor Announcements (Part 4)
Companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas.
August 7th, 2026 — Source

Chinese AI model Kimi escaped its cybersecurity testing environment, researchers say
Kimi K3, the latest AI model made by Chinese company Moonshot, escaped an environment set up to test its cyber capabilities, researchers said in a blog post published on Friday.
August 7th, 2026 — Source

Cloudflare Rides Surge in Bot Traffic and AI Workloads
CEO Matthew Prince Says Non-Human Traffic Could Reach 1,000 Times Human Use
August 7th, 2026 — Source

Computer maker Framework notifies 'all customers' of a data breach
Framework, a company that makes modular repairable computers, said it has notified all of its customers that hackers stole their names, email addresses, phone numbers, and physical addresses, due to an incident at a company that provides business intelligence.
August 7th, 2026 — Source

Flock's biggest investor also backs a company that can rewrite camera footage
Andreessen Horowitz backs both Flock Safety and camera-hacking firm Toka
August 7th, 2026 — Source

Framework customer information was accessed as part of a data breach
The company says payment details weren't exposed.
August 7th, 2026 — Source

In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street
Noteworthy stories that might have slipped under the radar: ban on Chinese data center tech, QuickFox VPN supply chain attack, IEH Corporation mailbox breached via phishing.
August 7th, 2026 — Source

Intrusion at US healthcare software provider puts 3.8M people's data at risk
Unlimited Technology Systems says names, Social Security numbers, diagnoses, and insurance details may have been swiped
August 7th, 2026 — Source

Keepit AI Truth Cloud protects the data behind enterprise AI
Keepit announced AI Truth Cloud, transforming backup from a compliance requirement into the strategically valuable data asset an organization can hold.
August 7th, 2026 — Source

Kimi K3 AI broke out of its cybersecurity test sandbox, firm says
Moonshot AI's Kimi K3 model broke out of an isolated cybersecurity testing sandbox by exploiting a network misconfiguration, Frontier Security researchers Paul Kassianik and Yaron Singer said in a blog post published Aug. 7, 2026. The Beijing-based Moonshot AI model was being tested on its defensive cybersecurity skills using a benchmark built on a framework from the UK's AI Security Institute when it located the gap and used it instead of solving the assigned problem.
August 7th, 2026 — Source or Source or Source or Source or Source

Levi Strauss & Co. says hackers stole corporate data in cyberattack
Levi Strauss & Co. (Levi's) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines.
August 7th, 2026 — Source

Mastering Enterprise Security in Microsoft Power Platform
Learn how environments, DLP policies, Dataverse roles, and a Center of Excellence keep Power Platform secure without slowing teams down.
August 7th, 2026 — Source

Microsoft starts sending out emails to warn about big Entra ID change to authentication
Microsoft has started emailing its customers to set up passkeys for users to login with. In February, SMS and voice authentication will be gone.
August 7th, 2026 — Source

Microsoft, Apple Release Fresh Security Updates
Microsoft fixed critical vulnerabilities across Azure, Entra, and SharePoint, while Apple patched a high-severity authentication bypass.
August 7th, 2026 — Source

MIT boffins' TONTOU attack slips through Spectre defenses on Intel and AMD CPUs
Timer interrupts reopen branch predictor poisoning window, with a working Zen 2 exploit to prove it
August 7th, 2026 — Source

New N-able Zero Day Puts MSPs on Defensive
Second Hotfix Issued for RMM Technology Widely Used by Managed Security Providers
August 7th, 2026 — Source or Source or Source or Source

North Carolina Ports confirms cyberattack disrupting operations
The North Carolina Ports Authority has confirmed that a cyberattack disrupted IT systems and slowed operations at the Port of Wilmington, Port of Morehead City, and Charlotte Inland Port.
August 7th, 2026 — Source

Scot NHS trust probes access to medical records of 9-year-old girl after man arrested on suspicion of murder
Investigation into whether staff improperly accessed Minnie Merriman's file after she was named for the first time this week
August 7th, 2026 — Source

ShinyHunters called cancer diagnostics biz and tricked staffers into giving them access. Now they've dumped 10.9M email addresses
Cancer diagnostics breach spills personal and health info as extortion crew says healthcare giant 'should've paid the ransom'
August 7th, 2026 — Source

Snowflake attacker pleads guilty to hack of 165 companies' data
Connor Riley Moucka faces between 2 and 30 years in prison for the hacks.
August 7th, 2026 — Source

The best free VPNs: 5 no-cost top picks
VPNs are best when they're paid for, but the top free VPNs can still keep you private without breaking the bank.
August 7th, 2026 — Source

This VPN Ad Blocker Is So Good, I Can't Go Back to Anything Else
Windscribe's ROBERT gives you unparalleled control for content and ad blocking bliss.
August 7th, 2026 — Source

Time for GPS Spoofing-Resistant Quantum Clocks, Says DARPA
Optical Clocks Could Maintain Precise Timing When GPS Signals Are Disrupted
August 7th, 2026 — Source or Source or Source or Source

Truck Brake Controller's Safety Recall Doubled as Hidden Security Fix
NMFTA research shows a Bendix EC80 brake controller safety recall also patched remote code execution and DoS vulnerabilities.
August 7th, 2026 — Source

Weak Passwords Just Exposed Our Water Supply to Iranian Hackers
Our critical utility infrastructure can make the same classic mistakes as we do with our everyday connected devices.
August 7th, 2026 — Source

When security becomes a risk factor—privacy risks of public URL-scanning services
URL scanning services are now a common component of modern security workflows. They help detect phishing websites or malware early and warn users before they visit a URL. However, the practice of some of these services—publishing scanned URLs—can inadvertently expose sensitive user data. CISPA researcher Ali Mustafa, together with colleagues from the Max Planck Institute for Security and Privacy and Ca' Foscari University of Venice, conducted the first systematic investigation of the risks arising from this practice.
August 7th, 2026 — Source

Why 'America First' in AI Shouldn't Mean 'America Only'
Former US Cyber Director on Cooperation, AI Supply Chains and National Security
August 7th, 2026 — Source or Source or Source or Source

Internet — Security Issues — August 5th, 2026

15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera traffic
TP-Link prints the serial number of an Omada router on its packaging and on a label attached to the device. Those numbers run in sequence, and feeding a guessed one to the Omada cloud service returns the matching device's MAC address and model. Serials beginning 22460J500 appear to be ER605 routers, and serials beginning 224608100 appear to be the ER7206.
August 5th, 2026 — Source

311,000 Impacted by Brown Health Medical Group-MA Data Breach
Hackers stole personal information, medical records, and financial information from the organization's server.
August 5th, 2026 — Source

AI agent deception moves from theory to reality in UK cyber tests
"During a routine cyber evaluation, AI agents took sustained, unsanctioned action directed at real people and organisations,” UK's AI Security Institute (AISI) disclosed on Tuesday.
August 5th, 2026 — Source

AI Agents Targeted Real People and Projects During Cybersecurity Tests
AI Security Institute reports Anthropic and OpenAI models going rogue against real people, organizations, and open source projects.
August 5th, 2026 — Source

ArmorCode enhances attack path analysis with new AI agents and Context Risk Graph
ArmorCode has announced a major expansion of its Agentic Control Plane. Four new Anya AI agents help security teams analyze cloud risks, assess vulnerability exploitability, identify mitigation strategies, and coordinate patch orchestration.
August 5th, 2026 — Source

Bank of America impersonators weaponize ScreenConnect, then make it hard to remove
A phishing campaign impersonating Bank of America (BoA) is underway, trying to trick Windows users into installing ScreenConnect remote access software and then making it difficult to uninstall it.
August 5th, 2026 — Source

CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities
The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass.
August 5th, 2026 — Source

Cloudflare gives AI agents wallets with built-in spending controls
Cloudflare's Wallets will give AI agents running on its platform a human-readable wallet handle for paying APIs and online content within limits set by their creator. Handle reservations have opened, while the service will become available in the coming months. It will include two types of digital wallets: Account Wallets and Virtual Wallets.
August 5th, 2026 — Source

Code review used to be the only way to catch these bugs
An automated system called NOVA read the source code of 3,915 open-source projects over two months and came back with 14,090 vulnerabilities, each one confirmed through the system's validation pipeline.
August 5th, 2026 — Source

CrowdStrike Warns AI Adoption Is Creating 'Underdefended' Attack Surfaces
CrowdStrike warns that AI adoption, rapid vulnerability exploitation, cloud attacks, and malicious npm packages are creating new enterprise security risks.
August 5th, 2026 — Source

Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data
The guidelines are the work of the recently launched Open Secure AI Alliance, which now includes 120 organizations.
August 5th, 2026 — Source

Enhanced Phishing Protection: Is It Worth Turning On?
You've probably seen Windows Defender SmartScreen at work before: it's that occasional, annoying pop-up that prevents you from running "unrecognized" apps. SmartScreen's other, lesser-known function is Enhanced Phishing Protection. In short, it keeps your Microsoft work or school passwords safe from phishing attempts, malicious apps, and websites.
August 5th, 2026 — Source

How AI-powered phishing killed blocklists for good
Blocklists were already losing ground before AI entered the picture. Phishing domains have been getting shorter-lived for years, campaigns have been burning infrastructure faster, and the gap between blocklists and attacker campaigns keeps getting wider. AI just finished the job.
August 5th, 2026 — Source

How hackers attack municipal water systems—and why the utilities are so vulnerable
The attackers did not try to infiltrate the computers that utility offices use. Instead, they tried to seize control of small computers in equipment like pumps and valves that deliver drinking water to millions of people.
August 5th, 2026 — Source

How the Canadian Centre for Cyber Security used frontier AI to accelerate detection engineering
An introduction to the Communications Security Establishment Canada's work on artificial intelligence in cyber defence
August 5th, 2026 — Source

Human-aware robots adapt to partners, reducing back strain during team lifting
When people work in pairs or teams, they can often solve a wider range of problems, completing some tasks faster and more efficiently than they would alone. To assist users similarly to how other humans would, robots should be able to rapidly interpret human behaviors and commands, using their predictions to plan and precisely execute helpful actions.
August 5th, 2026 — Source

INTERPOL flags AI as the new engine of African cybercrime
Africa's growing digital economy is exposing governments, businesses and internet users to a rising wave of cybercrime. The continent recorded more than 1.1 billion mobile subscriptions and over $1.1 trillion in digital transactions in 2025, while more than 570 million people relied on the internet for banking, government services, healthcare and education.
August 5th, 2026 — Source

Introduction to Post-training
How post-training transformed language models with raw intelligence into the AI assistants used by billions of people today
August 5th, 2026 — Source

London cops handed victim's new address and number to her stalker, watchdog says
Met ordered to improve safeguards after two preventable data breaches
August 5th, 2026 — Source

Lumu launches live threat intelligence platform for real-time cyber defence
Lumu has announced the release of Lumu Threat Observatory as part of Maltiverse, its threat intelligence solution. Lumu Threat Observatory is Maltiverse's live, personalized threat-intelligence experience, providing organizations with a complete, live view of the active threats targeting their specific sector, helping them spot malicious adversaries early, prioritize vulnerabilities, and automatically block them.
August 5th, 2026 — Source

New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts
Palo Alto Networks researchers have demonstrated attacks against Google's synced passkey implementation.
August 5th, 2026 — Source

Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials.
August 5th, 2026 — Source

SEC bought access to over a billion airline records to track travelers, no warrant required
Records included passenger names, itineraries, and credit card numbers
August 5th, 2026 — Source

Tenable broadens AI visibility across major LLMs and AI tools
Tenable has announced enhanced AI security capabilities within the Tenable One Exposure Management Platform. Tenable One AI Exposure now delivers expanded platform coverage with support for Google Gemini, extending its coverage across major LLMs: Google Gemini, Anthropic Claude, OpenAI ChatGPT Enterprise and Microsoft Copilot.
August 5th, 2026 — Source

The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict
CrowdStrike co-founder Dmitri Alperovitch discusses how cyber operations support kinetic warfare, signal coming conflicts, and reshape the global battlefield.
August 5th, 2026 — Source

Tuskira expands exposure management with Agentic Control Plane
Tuskira has launched its Agentic Control Plane for Exposure Management, a new capability within the Tuskira platform that governs AI-discovered vulnerabilities from scan to verified closure. The capability extends Tuskira's existing zero-day and exposure-response capabilities to frontier-model scanning.
August 5th, 2026 — Source

Water Sector Cyberattacks Reportedly Hit at Least 12 States
Georgia has been confirmed as one of the attacked states after Clayton County reported a pump station disruption.
August 5th, 2026 — Source

Internet — Security Issues — August 3rd, 2026

AI Is Expanding Your Attack Surface. Identity Is Where Security Starts.
Artificial intelligence is changing the way organizations operate, but it is also transforming how attackers gain access. Every AI agent, cloud workload and automated process introduces new identities that must be secured, monitored and governed. As identity becomes the common thread across users, systems and AI, it is rapidly emerging as the foundation of enterprise security.
August 3rd, 2026 — Source or Source or Source

Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577)
Attackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) in N-able N-central, a remote monitoring and management (RMM) solution widely used by managed service providers, to gain access to managed endpoints.
August 3rd, 2026 — Source

Brinks Home Discloses Data Breach as Hackers Leak Files
The physical security firm says its alarm monitoring and system functionality have not been affected.
August 3rd, 2026 — Source

Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers
A Chinese threat actor operating under the aliases "knaithe” and "KnYuan” used multiple LLMs to automate cyberattacks against internet-facing systems with limited human intervention.
August 3rd, 2026 — Source

CISA lays out new guidance for using open-source software
The US Cybersecurity and Infrastructure Security Agency (CISA) has published the Open Source Software: Security Principles and Practices guide, which provides federal agencies with recommendations for managing the security of open source software, contributing to OSS projects, and evaluating open source AI systems.
August 3rd, 2026 — Source

EFF at BSidesLV, Black Hat, and DEF CON 👨‍??
It's time. Time for tinkerers, security researchers, hackers, and fellow nerds to gather together in signature black hoodies and utilikilts to beat the heat in Las Vegas for the summer security conferences: BSidesLV, Black Hat USA, and DEF CON.
August 3rd, 2026 — Source

ExfilSquad hackers leak info of over 100,000 UK police officers, staff
A cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals.
August 3rd, 2026 — Source

Google Earth Pulls AI Image Generator After Users Created Misleading Images
The speedy U-turn is because users were generating images that "violated” Google's policies. These included making misleading satellite images like the Eiffel Tower in Paris toppled over, fake nuclear plants in Iran, and streams of refugees at the Mexico-U.S. border.
August 3rd, 2026 — Source

Horizon3 Raises $250 Million to Fund Continuing Growth
Venture financing has become an essential factor in growing new business in today's fast moving economy. Horizon3's latest funding explains how and why.
August 3rd, 2026 — Source or Source

Inside the Underground Business of the Android BTMOB RAT malware
The Android RAT's official operation is surrounded by cheaper resellers, alleged source-code vendors, independent server owners, and possible impersonators.
August 3rd, 2026 — Source

KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)
A critical security vulnerability (CVE-2026-66066) in Ruby on Rails (aka Rails), one of the most widely used frameworks for building websites and web apps, may allow attackers to read sensitive files off a server and, in some cases, take full control of it.
August 3rd, 2026 — Source

Mimecast introduces AI agent governance and managed threat response
Mimecast has unveiled Agent Risk Center, a beta capability for discovering, monitoring, and governing AI agents, alongside Managed Threat Response, a redesigned 24/7 service that combines AI-assisted triage with analyst-confirmed remediation.
August 3rd, 2026 — Source

N‑able Patches Vulnerability Exploited to Hack N-central Servers
The N‑central vulnerability CVE-2026-18577 has been exploited in the wild after threat actors found a patch bypass.
August 3rd, 2026 — Source

OpenAI reveals how criminals used ChatGPT to run scams
OpenAI banned a coordinated network of ChatGPT accounts that likely originated in Cambodia's Preah Sihanouk province, a region reports have linked to online scam compounds and human trafficking operations.
August 3rd, 2026 — Source

Police National Legal Database confirms data theft after dark web leak
ExfilSquad claims 135,000 contact records weeks after hitting the Department for Education
August 3rd, 2026 — Source

Qodana 2026.2 adds post-quantum crypto checks for JVM code
Qodana 2026.2 shipped with new security inspections, published benchmark results, post-quantum cryptography checks, and coverage reporting that no longer has to be pointed at the reports.
August 3rd, 2026 — Source

Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks
The INC Ransomware gang has been targeting vulnerable SMA1000 appliances for root access and lateral movement.
August 3rd, 2026 — Source

River Bank Says Hackers Deleted Data Stolen in Ransomware Attack
The bank holding company was hacked in June, but the investigation into the incident continues.
August 3rd, 2026 — Source

Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking
Midnight Blizzard has been stealing Microsoft account credentials via compromised Wi-Fi networks at hospitality organizations.
August 3rd, 2026 — Source

SentinelOne expands security operations automation with governed AI
SentinelOne has today announced governed, closed-loop response across the Singularity Platform, delivering trustworthy automation for security operations. Purple AI and Singularity Hyperautomation now autonomously investigate alerts, reach verdicts, and execute responses.
August 3rd, 2026 — Source

Simbian adds AI threat hunting agent to expand autonomous SecOps platform
Simbian has released its autonomous AI Threat Hunt Agent, that investigates potential threats and identifies malicious activity across enterprise environments.
August 3rd, 2026 — Source

Three AI security mistakes that will haunt enterprises
The enterprise AI nightmare is not a killer robot, but an erosion of our ability to see and control what's running in our own environments.
August 3rd, 2026 — Source

UK government investment arm cops to 40-hour leak of officials' contact details
Employee failed to follow security policy, leaving internal management file open to the public
August 3rd, 2026 — Source

US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States
Michigan, South Dakota, and Georgia are reportedly on the list of states whose water systems have been targeted by Iran-linked hackers.
August 3rd, 2026 — Source

Water system cyberattacks spread to Georgia, Michigan amid US-Iran conflict
Trump rejects Tehran theory, blames 'grossly incompetent' governor of Minnesota instead
August 3rd, 2026 — Source

Internet — Security Issues — July 31st, 2026

8 Things to Know About Staying Safe When Using ChatGPT, Gemini and Other AI Tools
Using AI like ChatGPT, Copilot, Claude, Perplexity or Gemini? Here's how to protect yourself.
July 31th, 2026 — Source

AI scammers outperform humans when it comes to building trust
The AI chatbot was more effective at creating "exploitable trust” than the humans.
July 31th, 2026 — Source

Amazon: Custom Frontier Model Can Cut Costs, Target Niches
AWS Wants Greater Control Over Training Priorities and Model Economics
July 31th, 2026 — Source or Source or Source

Anthropic's Claude breached three companies during security tests
Anthropic has disclosed that its AI model Claude gained unauthorized access to the systems of three different organizations during cybersecurity evaluations.
July 31th, 2026 — Source

Anthropic's Opus 4.7 and Mythos 5 attacked real companies online
OpenAI's bots aren't the only ones attacking real targets online, Anthropic has revealed three of its models also attacked real entities online.
July 31th, 2026 — Source

AttackIQ targets CTEM execution with AVA Agentic OS
AttackIQ has announced AVA Agentic OS, an agentic operating system designed to operationalize Continuous Threat Exposure Management.
July 31th, 2026 — Source

Best Password Manager for 2026
Whether you need a password manager for a single user or entire company, these services will protect your identity without sacrificing your sanity.
July 31th, 2026 — Source

Bitwarden Review: The Best Free Password Manager for 2026
You'll sacrifice some nice-to-have features by going with a free password manager, but Bitwarden doesn't skimp on the ones that matter.
July 31th, 2026 — Source

CareCloud Data Breach Impacts Over 350,000
In March 2026, hackers stole personal, financial, and medical information from the company's AWS environment.
July 31th, 2026 — Source

CEO of OpenAI says we're 'in the singularity' with AI: Is he right?
"We are now, like, in the singularity." These are the words of Sam Altman, CEO of OpenAI, speaking on the Relentless podcast on July 25.
July 31th, 2026 — Source

Charities remain locked out of CAF Bank online accounts
A week into shutdown, 14,000 customers still have no restoration date and some are struggling to pay staff
July 31th, 2026 — Source

Criminals used AI and children's coding software to build a multimillion-dollar ad fraud empire
A security investigation into inexpensive Android TV boxes led researchers to an ad fraud operation that had remained unnoticed for several years.
July 31th, 2026 — Source

Critical Flaw Allowed to Azure Cosmos DB Pwnage
Named CosmosEscape, the vulnerability exposed the primary key for Cosmos DB accounts, granting full read and write access.
July 31th, 2026 — Source

Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers
Iran has the "geopolitical motivations” and a recent history of targeting water systems, experts pointed out.
July 31th, 2026 — Source

Cybercrime goes subscription: AI, malware and infrastructure on demand
Cybercrime has become a commercialized ecosystem where criminals can buy or rent nearly every capability needed to launch sophisticated attacks. These services provide anonymity, plausible deniability, and access to short-lived infrastructure that is difficult to detect, attribute, and disrupt, enabling low-skilled actors to operate at scale, according to the Infoblox 2026 Threat Landscape Report.
July 31th, 2026 — Source

EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels
When the AI Act comes into force, AI companies will be required to make clear to consumers with labels or digital watermarks that chatbots or imagery are generated with AI.
July 31th, 2026 — Source

ESET tracks rise in malicious AI skills and adaptable malware
The first half of 2026 shows how attackers continue to improve the efficiency and scalability of their operations. Rather than relying on entirely new methods and tools, they are quickly adapting established techniques to new platforms, technologies, and user behaviors.
July 31th, 2026 — Source

Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace
The internet giant has built an agent harness to find vulnerabilities across Chrome's codebase.
July 31th, 2026 — Source

Horizon3.ai expands NodeZero with automated web application attack path testing
Horizon3.ai has expanded its NodeZero platform with AI-powered web application pentesting. The platform can now autonomously test web applications and identify attack paths that chain application vulnerabilities, credential theft, lateral movement, cloud access, and data exposure.
July 31th, 2026 — Source

JetBrains says a crafted HTTP request could break TeamCity
The company has patched a critical pre-authentication flaw in TeamCity that could let attackers execute arbitrary commands, expose credentials, and compromise supply chains on self-hosted servers.
July 31th, 2026 — Source

Record AI Bug Fixes Push Google To Twice-Weekly Chrome Updates
Google has begun piloting a twice-weekly update cadence for its massively popular Chrome web browser, a decision it made in the wake of fast-moving, AI-powered attacks. And for major Chrome milestones, the company is aiming to deliver new builds twice a month, along with weekly security updates, to ensure billions of users stay protected from surging AI threats.
July 31th, 2026 — Source

Resecurity expands threat intelligence integration ecosystem with IBM QRadar
Resecurity has announced the availability of native integration with IBM QRadar SIEM, a widely used Security Information and Event Management (SIEM) platform used by the leading Fortune 100 corporations worldwide. The plugin is available for activation via IBM Application Exchange.
July 31th, 2026 — Source

Scotland's university procurement center confirms cybercrooks broke in
APUC investigating after criminals claim historical data theft
July 31th, 2026 — Source

Sports venues are offering facial recognition to let people in: What are the risks?
Queues at sports events can be very long, even at large venues with many entrance gates. To speed things up, Geelong Football Club recently introduced an "express lane" option for club members.
July 31th, 2026 — Source

The Stuff of Nightmares: Windows App That Scans User Files, Incorporates Biometrics, Doesn't Need an Account, and Can't Be Uninstalled
Oh, Windows 11, we barely know thee, but it seems you may know far more about us than we ever wanted you to, and your hunger for more personal data is as insatiable as ever. Perhaps the biggest contribution of cell phone technology isn't its ability to provide mobile communication, tracking no matter who is using it or where they are, or the countless hours spent crushing candy; it's actually the ability to help create an unfathomable number of photos. Well, Microsoft is aware of this and has made accessing photos on PCs a top priority, no matter how invasive it may be, or asking users if they want this service or giving them the means to remove it.
July 31th, 2026 — Source

This Week in AI: Agents, Gatekeepers, and World Models
Plus pressure on the open web and what publishers are doing about it
July 31th, 2026 — Source or Watch Video

Traefik Labs introduces Distro Zero secure runtime for API and AI gateways
Traefik Labs has introduced the Distro Zero image, a hardened, vendor-supported secure runtime delivered as Traefik Hub in proxy mode. It gives platform and security teams a container whose entire executable content is a single memory-safe binary, with validated cryptography built inside it and every advanced capability, from API gateway to AI and MCP gateway to full API management, unlocked by license on that same binary. No binary swap, no migration, no re-validation as needs grow.
July 31th, 2026 — Source

Internet — Security Issues — July 29th, 2026

1Password targets standing privileges with new access management capabilities
1Password has launched 1Password Privileged Access, extending the 1Password Unified Access platform with privileged access management (PAM). It enables just-in-time, least-privilege access to critical infrastructure and is accompanied by the public preview of 1Password Credential Broker for GitHub Actions and new Enterprise Password Manager capabilities for developer and AI security.
July 29th, 2026 — Source

Accuris uses AI to improve BOM decisions and supply chain resilience
Accuris has announced new AI capabilities for BOM Intelligence, part of its Supply Chain Intelligence suite. The launch gives engineering, procurement and supply chain teams a clearer way to move from spotting component risk to acting on it: catching obsolescence early, closing compliance gaps and governing sourcing decisions across programs.
July 29th, 2026 — Source

Claude and ChatGPT's latest models are nitpicky and burning tokens. Here's the fix
Claude Opus 5 and GPT-5.6 keep flagging minor issues as major flaws, burning through usage limits fast. Here's a prompt that fixes it.
July 29th, 2026 — Source

Cloudflare reveals what's behind major internet outages
Storms, earthquakes, and infrastructure failures disrupted internet access throughout the second quarter, while governments deliberately shut networks down, according to Cloudflare's latest Internet Disruption Summary.
July 29th, 2026 — Source

Contrast CVE Shield aims to protect applications while security teams deploy patches
Contrast Security has announced Contrast CVE Shield, designed to help organisations defend against the growing number of exploits generated with advanced AI models such as Claude Mythos.
July 29th, 2026 — Source

Critical VM Escape Vulnerability Patched in VMware ESXi
A total of five vulnerabilities have been patched in VMware ESXi, vCenter, Workstation, and Fusion.
July 29th, 2026 — Source

Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks
State and federal agencies respond after intrusions disrupt automated controls at municipal water and wastewater utilities.
July 29th, 2026 — Source

FortiGate 1200G brings FortiSASE Outpost to customer-controlled environments
Fortinet has announced the FortiGate 1200G series, the newest addition to the FortiGate G series with FortiSASE Outpost, which brings cloud-delivered security services into customer-controlled environments.
July 29th, 2026 — Source

Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack
The Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities across the entire state after hackers targeted more than 30 community water systems in "a coordinated cyberattack.”
July 29th, 2026 — Source

How to Protect Your AI Agents from Prompt Injection Attacks: An Active Defense Approach
Stop just blocking prompt injections. Learn how to use MIRAGE to trap AI agents in honeypots and force them to burn their own API tokens.
July 29th, 2026 — Source

Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems
More than 30 facilities disrupted in 'coordinated cyberattack,' though officials have yet to name a culprit
July 29th, 2026 — Source

JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack
The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given.
July 29th, 2026 — Source

Joint guidance on minimum elements for a software bill of materials
The Canadian Centre for Cyber Security (Cyber Centre) has joined the United States' Cybersecurity and Infrastructure Security Agency (CISA) and other international partners in issuing guidance on the minimum elements for a software bill of materials (SBOM).
July 29th, 2026 — Source

Mate Security Raises $35 Million for Agentic SOC
The startup will use the investment to expand its customer support, sales, and R&D teams.
July 29th, 2026 — Source

MIND AI DLP Agents automate DLP classification, investigations and remediation
MIND has announced MIND AI DLP Agents with capabilities focused on classification, investigation, policies, remediation and exception management. MIND also includes a Model Context Protocol (MCP) interface that enables security teams to direct data security work through any MCP-connected client using natural language.
July 29th, 2026 — Source

Online Cyber Scams Cost Americans $150 Billion Last Year
A recent report has highlighted the massive financial toll that online scams are taking on individuals across the country. The Consumer Federation of America just released new estimates showing that Americans lost almost $150 billion to cyber fraud last year. This new figure reveals a staggering truth about the problem: the actual damage is about seven times higher than the official numbers reported to law enforcement.
July 29th, 2026 — Source

OpenAI says rogue AI agent attack hit other companies
ChatGPT-maker OpenAI has revealed that an autonomous artificial intelligence agent that hacked a popular platform for computer programmers also attempted to breach four other companies during the incident.
July 29th, 2026 — Source

OpenAI's rogue AI agent did more than hack Hugging Face -- it compromised accounts across four services
The model spent more than four days loose on the internet
July 29th, 2026 — Source

OpenAI's Rogue AI Ventured Beyond Hugging Face
Hugging Face has published an anatomy of the attack and OpenAI has shared additional information from its investigation.
July 29th, 2026 — Source

ShutterGap: Aryon Security finds 3.7M AWS cloud resources exposed beyond CSPM/CNAPP visibility
Research from Aryon reveals that each year, 3,731,699 short-lived cloud resources containing highly sensitive information are publicly exposed. This impacts any organization using AWS services that support public sharing.
July 29th, 2026 — Source

Spur Raises $200 Million for IP Intelligence Platform
The IP intelligence company will use the fresh investment to accelerate and scale its operations.
July 29th, 2026 — Source

Stairwell launches Backstory, pioneering agentic investigation for malware blast radius
Stairwell, the AI SOC that stops breaches no one else can, today announced the availability of Backstory, an agentic investigation platform that traces related malware variants, identifies affected systems, and maps the full blast radius of an incident in seconds, so enterprises know what happened, where it spread, and what needs to be contained before precious time is lost.
July 29th, 2026 — Source

Stolen Meta and Google ad accounts are worth more than the money they hold
Ad account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy complete with tiered pricing, escrow services, and money-back warranties for stolen accounts.
July 29th, 2026 — Source

Supply Chain SecurityUS Bans Foreign-Made Humanoid Robots, Targeting China Over National Security
The agency said imports of advanced robots pose cybersecurity and other national security risks.
July 29th, 2026 — Source

Tengu botnet reboots Linux devices to survive removal
A new Mirai-derived IoT botnet can force an infected Linux device to reboot once its main process is killed, giving its persistence mechanisms another opportunity to relaunch it, Nozomi Networks Labs has found.
July 29th, 2026 — Source

ThreatLocker Raises $190 Million in Series F Funding
The company was previously valued at $1.6 billion, and the latest raise has significantly increased that valuation.
July 29th, 2026 — Source

US, Australia Release OT Isolation Guidance for Critical Infrastructure
The guidance details steps organizations can take to isolate vital OT and supporting systems, and operate in isolation for an extended period.
July 29th, 2026 — Source

What really happens to your data when you click 'delete'?
Deletion is a common part of modern life. We send files and folders to the recycle bin all the time and often get rid of unwanted personal accounts. But do you know what really happens when you hit the "delete" button?
July 29th, 2026 — Source

WhatsApp brings end-to-end encrypted voice and video calls to the web
WhatsApp has launched support for voice and video calls on the web, allowing users to make and receive calls directly from their browser without installing the desktop app.
July 29th, 2026 — Source

Internet — Security Issues — July 27th, 2026

7AI expands platform with Federated SIEM and AI workflow builder
7AI has announced two major platform capabilities: 7AI Federated SIEM, which lets security teams query, investigate, and act on data wherever it lives, including within 7AI, and 7AI Build, which lets enterprises and partners define agentic workflows, skills, and AI-native security services on top of the 7AI platform.
July 27th, 2026 — Source

Anthropic's Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on Exploits
Binary-based vulnerability scanning, penetration testing, and exploit generation are blocked in Opus 5.
July 27th, 2026 — Source

AWS gives DevOps teams an AI investigator for firewall incidents
AWS DevOps Agent helps administrators inspect logs, review firewall rules and network paths, identify configuration changes that caused AWS Network Firewall to block traffic, and restore connectivity.
July 27th, 2026 — Source

Beelzebub Raises $3.4 Million for Hacker-Trapping Platform
The company plans to expand its research team, open new offices in Rome and San Francisco, and acquire new clients.
July 27th, 2026 — Source

Booz Allen expands Vellox Suite with AI-driven threat detection platform
Booz Allen Hamilton has announced an expansion of its powerful suite of AI-powered cyber defense products. Now generally available, Vellox Ranger provides automated, environment-specific threat detections, developed on Booz Allen's proprietary agentic AI framework, that identify exploitable paths and vulnerabilities based on the actual state of an enterprise's infrastructure.
July 27th, 2026 — Source

C1 adds shadow AI discovery to its identity governance platform
C1 has launched shadow AI discovery to eliminate the massive security blind spots created by unauthorized AI agents, tools, and credentials. By automatically discovering and folding every AI-adjacent identity into C1's existing identity governance platform, organizations can finally ensure that the governed path is the fastest path to safe AI adoption.
July 27th, 2026 — Source

ChatGPT joins the most impersonated brands in phishing attacks
Microsoft continued to be the most impersonated brand in Q2 2026, accounting for 23% of all brand phishing attempts. LinkedIn, Google, Apple, and Amazon followed, with the five brands together making up more than half of all brand phishing attempts tracked during the quarter, according to Check Point's Q2 2026 Brand Phishing Report.
July 27th, 2026 — Source

Coca-Cola confirms data theft in Fairlife ransomware attack
The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month.
July 27th, 2026 — Source or Source

DentaQuest Data Breach Potentially Impacts Over 23 Million People
In May 2026, hackers stole personal and dental health information from DentaQuest's computer network.
July 27th, 2026 — Source

Designing Secure REST APIs With Spring Boot
Learn how to secure Spring Boot REST APIs with JWT validation, method-level authorization, input validation, rate limiting, CORS, secure logging, and more.
July 27th, 2026 — Source

Dynatrace Intelligence automates incident triage and remediation with AI agents
Dynatrace has announced major advancements to Dynatrace Intelligence that help automatically resolve incidents, prevent disruptions, and accelerate operations while maintaining the human oversight and governance enterprises require.
July 27th, 2026 — Source

Ernst & Young data breach claimed by ShinyHunters extortion gang
The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company's systems via a supply-chain attack.
July 27th, 2026 — Source

Google changes how it names cyber threat actors
Google Threat Intelligence Group (GTIG) has started using a new naming system for the threat actors it tracks. The change comes after Mandiant and Google's Threat Analysis Group (TAG) merged into one unit, leaving the company with two separate naming schemes built up over years.
July 27th, 2026 — Source

Google goes it alone with a new cybercrime crew taxonomy
So much for Microsoft and CrowdStrike's plans for consistent names across the industry
July 27th, 2026 — Source

Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials
A threat actor has been using the compromised appliances to target the Microsoft 365 accounts of traveling corporate employees.
July 27th, 2026 — Source

Hugging Face is billing OpenAI $100mn for hacking it
Hugging Face was broken into by an OpenAI model this month. Its chief executive has now told OpenAI what he wants in return: every execution trace from the agents, and $100mn worth of compute. OpenAI has agreed to neither, and the two companies have just landed on opposite sides of a new industry alliance.
July 27th, 2026 — Source

Illinois Man Gets Six Years For Hacking Women's Snapchat Accounts
A federal judge recently sentenced an Illinois man to more than six years in prison after he set up a large scam to steal private photos from hundreds of women. The 27-year-old used fake text messages to trick his victims into handing over their account security codes. Once inside their private profiles, he locked the actual owners out and sold their personal pictures across various internet forums.
July 27th, 2026 — Source

JetStream Security enables on-demand shutdown of compromised AI agents
JetStream Security has announced the release of an AI Kill Switch that allows organizations to shut down compromised AI agents on-demand without impacting other AI operations. This new control plane for AI agents solves the inability to stop a single agent that falters, begins overspending, or needs to be taken offline for compliance reasons without affecting other agents.
July 27th, 2026 — Source

Keyfactor Expands Into AI Agent Identity With Cofide Deal
Deal Extends Certificate-Based Trust Framework to AI Agents and Software Workloads
July 27th, 2026 — Source or Source or Source or Source

Malware found hidden inside popular 'Meccha Chameleon' game maps
An infected system engineer's PC also led to attackers seizing control of the game's nearly 100,000-member Discord server.
July 27th, 2026 — Source

MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection
The malware-as-a-service operation launches legitimate browsers on an invisible desktop, giving attackers persistent and covert remote access to compromised Windows systems.
July 27th, 2026 — Source

New GitHub, PyPI Policies Boost Supply Chain Security
Dependabot gets a three-day cooldown window before opening pull requests, and PyPI rejects file uploads to releases older than 14 days.
July 27th, 2026 — Source

Nvidia and Tech Giants Launch AI Security Alliance
The Nvidia-led coalition aims to give defenders more open tools for testing, auditing and protecting AI models and agents.
July 27th, 2026 — Source

Older people's media literacy can be boosted in just 60 minutes—new study
An influential political commentator posts a reel on social media, cherry-picking facts to manipulate a situation for political gain. His post gets no likes, no shares and no angry emojis from users.
July 27th, 2026 — Source

Origin Energy Data Breach Exposes Customer and Partial Card Details
Origin Energy confirms hackers stole customer and partial payment-card data, but the number affected and the method of access remain unknown.
July 27th, 2026 — Source

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)
Security researchers who discovered and reported CVE-2026-54121 (aka "Certighost”), a critical privilege elevation vulnerability in Active Directory Certificate Services (AD CS), have released a proof-of-concept (PoC) exploit for and technical details related to the flaw.
July 27th, 2026 — Source

Protect your devices from SMS blasters (ITSAP.00.104)
Text messages (SMS) have become one of the most common ways for threat actors to try and scam victims. SMS blasters are a type of cell site simulator, which are portable devices that impersonate legitimate mobile networks to trick nearby devices to connect to them. Threat actors use SMS blasters to carry out SMS phishing attacks (known as smishing) and other malicious activities designed to steal sensitive or financial information or spread disinformation. This publication offers information on the threats posed by SMS blasters and how to best protect yourself.
July 27th, 2026 — Source

PTC Windchill Vulnerability Exploited in Ransomware Campaign
The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication.
July 27th, 2026 — Source

Scammers are setting up fake websites to download Windows applications in latest operation
Scammers are impersonating popular Windows app websites, raising fears of a coordinated malware campaign targeting unsuspecting users.
July 27th, 2026 — Source

Tech giants form alliance to put open AI in cyber defenders' hands
NVIDIA and a group of tech companies have formed an alliance to promote the use of open AI models in cybersecurity, days after OpenAI disclosed that one of its own AI models breached Hugging Face's systems during an internal security evaluation.
July 27th, 2026 — Source

usbliter8 lawsuit forces 'unpatchable' iPhone hack offline
Digital forensics firm Magnet Forensics says a former engineer stole its confidential iPhone-hacking research and gave it away to a rival company. That rival company — Paradigm Shift — then published the research as an original discovery.
July 27th, 2026 — Source

Your Claude conversations may have leaked online if you did this
Claude's sharing feature allowed search engines to index private-looking chats, prompting Google to begin removing the exposed pages.
July 27th, 2026 — Source

What's Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out
The new Mobile Security Exposure Center creates SBOMs for enterprise mobile apps to uncover vulnerable components, dependencies and hidden risks.
July 27th, 2026 — Source

Zenity advances AI governance with Runtime Boundaries
Zenity has announced a major expansion of its platform, making it the AI security platform for autonomous AI built around a new security architecture designed to govern AI decisions before they become enterprise actions, including those made by long-horizon agents operating autonomously across extended, multi-step workflows.
July 27th, 2026 — Source

Internet — Security Issues — July 24th, 2026

AegisAI Raises $36 Million for AI-Powered Email Security
The company has raised a total of $49 million in funding, including from Battery Ventures, Accel and Foundation Capital.
July 24th, 2026 — Source

Chick-fil-A data breach affects more than 13,000 customers
American fast food restaurant chain Chick-fil-A has confirmed that over 13,000 customers had their data stolen in a recent wave of credential stuffing attacks.
July 24th, 2026 — Source

Clop ransomware targets Windchill, FlexPLM in data theft attacks
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign.
July 24th, 2026 — Source

Europol flags 4,340 URLs for removal in 'The Com' crackdown
Europol has flagged 4,340 URLs for removal during a multi-week operation targeting online content linked to "The Com," a loosely organized network of nihilistic violent extremist groups.
July 24th, 2026 — Source or Source or Source or Source or Source

Google gives developers an AI bug hunter that also writes patches
Google has launched a preview of CodeMender, an AI agent built to scan code for security flaws, confirm they are exploitable, and generate fixes for developers to review.
July 24th, 2026 — Source

Google's newest sign-in method asks you to look at the camera
Google's selfie video sign-in option verifies that an account owner is a real person and that the account wasn't created or used by computer programs or bots for the purpose of abuse, such as spamming. It is not available for all regions, accounts, or devices.
July 24th, 2026 — Source

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages.
July 24th, 2026 — Source

In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws
Noteworthy stories that might have slipped under the radar: Siemens ROX II industrial switch vulnerabilities, Russian Zimbra webmail espionage campaign, Stadler Rail ransomware extortion attempt.
July 24th, 2026 — Source

Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday
Industry professionals debate whether it represents a lab containment failure or an unprecedented agentic capability milestone.
July 24th, 2026 — Source

Meta is making its AI chatbot more like an assistant
The latest Meta AI update allows it to pull from your calendar to generate daily briefings.
July 24th, 2026 — Source

Meta tackles AI-generated accounts with a free Facebook verification badge
Meta has introduced Facebook Verified, a free badge meant to show that a person behind a profile has completed identity verification through a selfie check.
July 24th, 2026 — Source

Meta wins dismissal of WhatsApp privacy suit as judge questions whistleblower detai
The ruling found insufficient detail about the whistleblowers' knowledge but did not call the case frivolous, denied Meta's request for sanctions, and gave plaintiffs until August to refile
July 24th, 2026 — Source

Microsoft tightens Windows enterprise activation security
Microsoft is making Trusted Platform Module (TPM)-backed attestation a requirement for Windows Key Management Service (KMS), the on-premises service used for Windows volume activation, replacing the software-only trust model with hardware-backed verification to strengthen enterprise activation security.
July 24th, 2026 — Source

OpenAI's HuggingFace breach heralds an unprecedented age of AI cyber warfare — contemporary LLMs have caused massive upheaval in cybersecurity, and it's only going to get worse
Can the rest of us keep up?
July 24th, 2026 — Source

Patient Sues Abbott Labs, Exact Sciences in Data Theft
Class Action Suit Claims Labs Failed to Safeguard Data in ShinyHunters Hack
July 24th, 2026 — Source or Source or Source

Russian hackers exploit unpatched Zimbra servers to steal emails
Russian state-backed hacker group Laundry Bear has been breaking into government and commercial networks for at least a year by exploiting a vulnerability in the Zimbra Collaboration Suite (ZCS) webmail platform.
July 24th, 2026 — Source or Source or Source or Source

Securing Model Context Protocol Servers: 4 Gates From Code to Production
Secure MCP servers against prompt injection, data leaks, and denial-of-wallet with four practical, OWASP-aligned gates from code to production. Runnable code.
July 24th, 2026 — Source

Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack
Three attacks, three names, and one identical flaw: AI coding agents treat a hallucinated identifier as a verified command.
July 24th, 2026 — Source

Uncle Sam tells overseas cybercrooks their visas are canceled
Policy targets online scammers, sextortionists, and potentially their immediate families
July 24th, 2026 — Source

When the Sandbox Won't Hold: Lessons From Hugging Face
Experts Call for Hard Stops at Every New Privilege and Network Boundary
July 24th, 2026 — Source or Source or Source or Source

Internet — Security Issues — July 23rd, 2026

Abstract Raises $25 Million to Expand Composable Security Operations Platform
The latest investment round brings the total raised by Abstract to nearly $50 million.
July 23rd, 2026 — Source

AegisAI, founded by former Google security execs, lands $36M to stop AI-driven spear phishing
Hackers are increasingly using AI to launch attacks on a massive scale, with email emerging as a primary target. AI can quickly aggregate personal information — such as information about co-workers, active projects, and recent travel itineraries — allowing bad actors to instantly craft convincing messages that look authentic.
July 23rd, 2026 — Source

AI arms race in line for a reckoning after OpenAI hacking incident
Aggressive training techniques sharpens threat of bad behavior by leading models.
July 23rd, 2026 — Source

Assaf Keren Appointed New CISO of Meta
He replaces Guy Rosen, who announced his retirement from the company after 13 years.
July 23rd, 2026 — Source

Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)
Attackers are exploiting a critical authentication bypass vulnerability (CVE-2026-16232) that affects Check Point Security Management and Multi-Domain Security Management, the management servers that push policy to Check Point security gateways (i.e., firewalls).
July 23rd, 2026 — Source

Axonius expands Asset Cloud with Cyber Assets and Exposures enhancements
Axonius has announced new capabilities across the Axonius Asset Cloud to better address asset intelligence and exposure management use cases. The enhancements make it easier than ever to address CMDB visibility gaps and respond to vulnerabilities, while extending asset intelligence capabilities to IoT and OT devices.
July 23rd, 2026 — Source

Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process
Cisco Talos has identified a Rust-based remote access trojan it attributes to the Chaos ransomware group, named msaRAT after four of the binding names left in the binary. The tool starts its own instance of Chrome or Edge on the victim machine and controls it through Chrome DevTools Protocol, a debugging interface built into both browsers. The browser then carries the command-and-control traffic over a WebRTC channel.
July 23rd, 2026 — Source

Check Point warns of SmartConsole zero-day exploited in attacks
Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company's SmartConsole graphical user interface (GUI) admin panel.
July 23rd, 2026 — Source

Chick-fil-A Accounts Get Fried in Credential Stuffing Attack
hreat actors used credentials obtained from other companies to hack into Chick-fil-A One accounts.
July 23rd, 2026 — Source

Cobalt adds Autonomous Pentest to scale application security testing
Cobalt has introduced Cobalt Autonomous Pentest, a new offering that enables continuous offensive security across an organization's application portfolio by delivering actionable penetration testing results in as little as 24 hours.
July 23rd, 2026 — Source

Cryptohack Roundup: BitMex Shuts Down
Also: BitShine Fraudster Jailed, Upbit Sanctions Begin
July 23rd, 2026 — Source or Source or Source or Source

FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires
I spent years on the offensive side of security performing red and purple team assessments, bypassing controls that GRC teams, and often times even auditors, were convinced were working.
July 23rd, 2026 — Source

GitHub revamps bug bounty program with new VIP tier, payout changes
GitHub is changing its bug bounty program to reward higher-quality vulnerability reports and reduce low-effort submissions, including AI-generated reports.
July 23rd, 2026 — Source or Source

Hackers abuse Notepad++ plugins to stealthily install malware
Ukraine's CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence.
July 23rd, 2026 — Source

How attackers hosted a fake Claude download page on the claude.ai domain
A threat actor abused Anthropic's Claude Artifacts feature to funnel users toward malware, Huntress researchers have disclosed.
July 23rd, 2026 — Source

If you get knocked on the head and get all your devices stolen and have amnesia, Google will let you back in with a selfie
You'll need to be able to move your head side to side to make sure you're not a deepfake
July 23rd, 2026 — Source

Is Patching Dead? Vulnerability Management in the Post-Mythos Era
You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win.
July 23rd, 2026 — Source

Joint cyber security advisory on Russian state-sponsored phishing campaign targeting Zimbra webmail
The Canadian Centre for Cyber Security (Cyber Centre) has joined the United States National Security Agency (NSA) and other international partners in releasing a cyber security advisory warning of a Russian state-sponsored phishing campaign targeting users of Zimbra Collaboration Suite (ZCS).
July 23rd, 2026 — Source

Microsoft Warns Critical SharePoint Flaw Is Under Active Attack
Another new vulnerability for Microsoft SharePoint, tracked as CVE-2026-50522, is now being actively exploited in the wild, Microsoft warns. Security team watchTowr found evidence of exploits in use, and noted that attacks started the same day, July 20th, as when a Proof of Concept (PoC) attack was published. Another security company, Defused, detected attacks as early as July 17th, which points to private versions of the attack developed in parallel rather than the published PoC version of the attack.
July 23rd, 2026 — Source

Millions of California-bought cars can be hijacked via Bluetooth
Aftermarket dealer-installed KARR/SWDS security systems all use the same secure key, say UCSD researchers
July 23rd, 2026 — Source

Mobile Synthetic Identity Scams Can Outscore Real Borrowers
Point Predictive's Matt Vega on Detecting Identity Fraud and $30 Liveness Kits
July 23rd, 2026 — Source or Source or Source or Source

New Check Point Zero-Day Vulnerability Exploited in the Wild
The vulnerability tracked as CVE-2026-16232 has been exploited against customers with certain configurations.
July 23rd, 2026 — Source

Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models
SentinelOne's new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot.
July 23rd, 2026 — Source

One ChatGPT link could smuggle a rogue AI agent into your company
Researchers say OpenAI flaw let phishing bait create an autonomous corporate mole armed with employee access
July 23rd, 2026 — Source

Oracle drops 1,449 security patches like it's the new normal
Experts say the era of AI bug hunting is here, so defenders will simply have to adapt to busier workloads
July 23rd, 2026 — Source

PyPI hardens package security with new upload restrictions
The Python Package Index (PyPI) now rejects uploads of new files to releases older than 14 days to prevent attackers from poisoning long-stable releases if a project's publishing tokens or release workflows are compromised.
July 23rd, 2026 — Source

Russian hackers exploit Zimbra zero-click flaw for email theft
CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability.
July 23rd, 2026 — Source

Stop! 7 ways you're making your personal info public online
You don't have to stop using the internet to protect your privacy. But you probably need to stop making these common mistakes.
July 23rd, 2026 — Source

Swiss train maker tells ransomware crooks to get off at the next stop
Stadler refuses $12.3M demand after thieves swipe technical data through supplier platform
July 23rd, 2026 — Source

Swiss rail manufacturer Stadler refuses to pay $12.3 million ransom after cyberattack
Cybercriminal group Everest is demanding 10 million Swiss francs ($12.3 million) from Swiss rail vehicle manufacturer Stadler after breaching a data exchange platform shared with one of its suppliers through compromised credentials.
July 23rd, 2026 — Source

Talking smack about a doctor got him access to private medical files
Who needs a working security badge when you know how to talk your way into the records room?
July 23rd, 2026 — Source

Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses
Hackers recently obtained non-sensitive customer information and other documents from the company.
July 23rd, 2026 — Source

US government says Iran-linked hackers are disrupting American water and energy providers
The U.S. government is warning that Iranian state-backed hackers are actively breaking in and disrupting industrial control systems at American water and energy providers. This new alert comes months after federal agencies warned of an escalation in hacking from Iranian actors amid the ongoing war.
July 23rd, 2026 — Source

Why AI-Generated Code Fails Security Reviews 45% of the Time
AI coding tools produce security flaws in 45% of outputs, yet developers trust the code more despite no security gains in two years.
July 23rd, 2026 — Source

Year-long Russian attacks infect users as soon as they look at an email
Kremlin cyber goons have been breaking into government and commercial networks for at least a year by exploiting a Zimbra bug with a novel twist on Russia's usual phishing expeditions: this attack occurs as soon as the victim looks at an email, with no need to even click on a link or open a file.
July 23rd, 2026 — Source

You can now sign in to your Google Account with a selfie video
Google is rolling out selfie video sign-ins for some accounts, using facial checks and liveness detection to verify your identity.
July 23rd, 2026 — Source

Internet — Security Issues — July 22nd, 2026

Adobe Chrome extension flaw let sites access private WhatsApp chats
The Adobe Acrobat extension for Chrome could be used to access conversations and data rendered in WhatsApp Web without any form of authentication.
July 22nd, 2026 — Source

AI is rewriting cybersecurity's rules
AI is giving cybercriminals new speed and scale, but researchers say the technology could also become one of cybersecurity's strongest defenses.
July 22nd, 2026 — Source

AI Models Caught Cheating in Cyber Evaluations
OpenAI, Anthropic Models Broke Test Rules, Left Few Reasoning Clues
July 22nd, 2026 — Source or Source or Source

Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)
Attackers are exploiting a critical SharePoint remote code execution (RCE) vulnerability (CVE-2026-50522) to extract the servers' IIS machine keys.
July 22nd, 2026 — Source

Anubis Ransomware Halts Fairlife Milk Production in the US
Gang Claims 1TB of Stolen Data and Sets Deadline for Ransom Talks
July 22nd, 2026 — Source or Source or Source or Source

Arista adds AI-driven zero trust to VeloCloud SD-WAN
Arista Networks has announced the launch of its new AI-driven Edge Threat Management (ETM) for VeloCloud SD-WAN, delivering integrated zero trust security for enterprise branch offices. Customers can leverage this integration to simplify the branch, collapsing multiple disparate boxes into a single unified secure SD-WAN edge platform.
July 22nd, 2026 — Source

As Ransomware Blackmail Surges, Governments Mull a Ban on Paying Up
With AI-powered ransomware, attackers are becoming ever more sophisticated.
July 22nd, 2026 — Source

Astelia extends reachability analysis with agentic AI for vulnerability management
Astelia has added agentic capabilities to its reachability analysis platform as organizations face shrinking exploit windows and the growing challenge of managing vulnerabilities.
July 22nd, 2026 — Source

Best Password Manager for 2026
Whether you need a password manager for a single user or entire company, these services will protect your identity without sacrificing your sanity.
July 22nd, 2026 — Source

Box expands enterprise AI governance with new agent security featuresox
Box has announced new security capabilities designed to give organizations greater control over AI agents working with enterprise content. With new agent guardrails, third-party agent activity oversight, prompt injection detection, agent classification-based access policies, and more, customers will be able to extend Box's security controls to both Box Agents and third-party agents, such as Claude, ChatGPT, and Gemini.
July 22nd, 2026 — Source

CISA orders urgent action on actively exploited Langflow RCE flaw
The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents.
July 22nd, 2026 — Source

EU Huawei Ban Backlash Report Exaggerated, Says Critic
GSMA Intelligence Says Ejecting Huawei Equipment Will Cost Up to 40B Euros
July 22nd, 2026 — Source or Source or Source

Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation
Using AI, the startup provides adaptive prevention through environment mapping, risk analysis, and automated policy enforcement.
July 22nd, 2026 — Source

Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft
An attacker only needed to convince the targeted user to visit a malicious website to exfiltrate WhatsApp messages and contacts.
July 22nd, 2026 — Source

Fourth SharePoint Vulnerability Exploited in Past Month's Wave of Attacks
CVE-2026-50522 is being exploited by threat actors to steal machine keys and retain long-term access.
July 22nd, 2026 — Source

Glow emerges from stealth at $1.2B valuation to challenge endpoint security in the AI era
Glow, a cybersecurity startup founded by former Meta and Snowflake executives, emerged from stealth as a unicorn, betting that artificial intelligence is reshaping how enterprises secure employee devices.
July 22nd, 2026 — Source or Source

Glow Launches With $180M to Thwart AI Risk at the Endpoint
Startup Platform Combines Endpoint Activity, Business Context and Security Policies
July 22nd, 2026 — Source or Source or Source or Source

Google's Gemini 3.5 Flash Cyber becomes a vulnerability hunter
Google's Gemini 3.5 Flash Cyber model finds, validates, and patches vulnerabilities before they can be exploited while helping mitigate broader misuse. It is part of a limited-access pilot program that will soon be available to governments and trusted partners through CodeMender, Google DeepMind's AI coding agent, with broader access planned over time.
July 22nd, 2026 — Source

Greedy ransomware crews return for seconds after victims cough up first extortion payments
Some never saw their files again either, infosec biz Proofpoint finds
July 22nd, 2026 — Source

Hackers stole Estee Lauder staff's bank and health data. The company took nearly a year to say so.
Estee Lauder has told employees that hackers took their most sensitive records, from social-security numbers to bank details to health data. The break-in happened in August 2025. The company only worked that out this June. It is the latest name on a very long list.
July 22nd, 2026 — Source

How enterprise GenAI can amplify ransomware risk — and how to contain it
Generative AI is rapidly becoming part of everyday business operations. Employees use AI assistants to summarize documents, search enterprise knowledge, draft content and automate routine tasks. Organizations are also beginning to deploy AI agents that interact with business applications and execute workflows with minimal human intervention.
July 22nd, 2026 — Source

How OpenAI's human mistake led to the AI-powered hack on Hugging Face
On Tuesday, OpenAI revealed that one of its models went rogue during a test and hacked the systems of AI dataset platform Hugging Face in a fully AI-enabled attack, a dramatic example of the dangers posed by advanced AI models.
July 22nd, 2026 — Source

If you pay a hacker's ransom, chances are that they'll come back for more
Governments have long warned not to pay a hacker's ransom demands, arguing that doing so only lets criminals profit from their cyberattacks and funds the next one. There's also another reason: The hackers are unlikely to leave you alone if you pay up once, and many will come back demanding more.
July 22nd, 2026 — Source

Lookout identifies exploitable vulnerabilities in mobile apps
Lookout has announced the launch of the Lookout Mobile Software Exposure Center (MSEC). Integrated natively into the Lookout Mobile Endpoint Security platform, MSEC enables organizations to continuously detect, validate, prioritize, and remediate exploitable vulnerabilities across their mobile software ecosystem.
July 22nd, 2026 — Source

Microsoft Confirms Windows Has a Global Device ID You Can't Turn Off
It's designed to manage software licensing, but Microsoft can also use it to identify individual users.
July 22nd, 2026 — Source

Microsoft to stop Exchange 2016 / 2019 security updates in October
Microsoft has reminded customers that it will stop shipping security updates for Exchange 2016 and 2019 through the Extended Security Update (ESU) program in October.
July 22nd, 2026 — Source

New Data Shows Suno Breach Affected 55M Accounts
New data shows 55.3 million Suno accounts were affected in a breach exposing contact details, purchases, and partial payment card information.
July 22nd, 2026 — Source

New InfraTrust report reveals infrastructure flaws admins should patch first
Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices.
July 22nd, 2026 — Source

Nvidia's AI Detector Can Tell Whether a Video Is AI-Generated in Milliseconds
Accuracy is said to hover between 85% and 92%.
July 22nd, 2026 — Source

OpenAI helps address a terrible AI security flaw following Hugging Face incident
The AI was able to breach its isolation and gain access to the internet.
July 22nd, 2026 — Source

OpenAI Presence connects AI agents to enterprise data with built-in guardrails
OpenAI has introduced Presence, a product designed to help companies deploy AI agents that handle customer support and internal service requests across voice and chat.
July 22nd, 2026 — Source

OpenAI says its AI agent broke out of testing sandbox to hack Hugging Face
"This is day one for cybersecurity in the age of agents," Hugging Face CEO says.
July 22nd, 2026 — Source

OpenAI: Our models breached Hugging Face during a cyber capability test
The recent Hugging Face breach was the work of several OpenAI models, the AI research company claimed in a blog post.
July 22nd, 2026 — Source or Source

Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates
Many of the vulnerabilities fixed with the July 2026 Critical Patch Update were likely discovered by AI.
July 22nd, 2026 — Source

Oracle's July update fixes ten 10.0 vulnerabilities in Fusion Middleware
The record number of fixes in this quarter's Critical Patch Update cover 32 product families.
July 22nd, 2026 — Source

Origin Energy investigates potential breach of customer data
Australia's largest energy retailer has confirmed a breach of customer data, with names, contact details, and partial card and bank account numbers among the information taken.
July 22nd, 2026 — Source

Palo Alto Networks to Acquire Observability Platform Provider Embrace
Acquisition follows January's Chronosphere deal, deepening Palo Alto Networks' push beyond core security into observability.
July 22nd, 2026 — Source

Pixels Tracking Every Loan You Take on EU Bank Websites
Jscrambler Detects Cookies Exporting Detailed View of Customer Financial Intent
July 22nd, 2026 — Source or Source or Source or Source

Police dismantle Kratos phishing platform behind 15,000 monthly campaigns
German and US law enforcement have dismantled the infrastructure behind Kratos, a notorious phishing-as-a-service (PhaaS) platform. Its alleged developer and administrator was arrested in Indonesia by local police.
July 22nd, 2026 — Source

Ransomware Group Threatening to Leak Data Stolen From Coca-Cola's Fairlife
The Anubis ransomware group claims to have stolen 1 TB of confidential data from the Coca-Cola subsidiary.
July 22nd, 2026 — Source

Refresh Token Rotation in Node.js: Stopping Token Theft Without Logging Users Out
Implementing refresh token rotation with reuse detection, a pattern that limits the damage of a stolen token while keeping legitimate users logged in.
July 22nd, 2026 — Source

Sneaky Windows stealer targets 300+ apps, gives crims an AI profiler to maximize profits
Move over Flipper. There's a new Dophin X in town
July 22nd, 2026 — Source

South Korea discloses data breach impacting diplomats worldwide
South Korea disclosed that hackers breached the National Diplomatic Academy's online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats.
July 22nd, 2026 — Source

Still on Windows 10? You're carrying 3x the security risk of Windows 11
A new study finds Windows 10 PCs average 1,903 active vulnerabilities versus 652 on Windows 11—nearly triple the security risk.
July 22nd, 2026 — Source

StrongestLayer Raises $4.1 Million in Seed Funding Extension
The startup will use the fresh investment to accelerate its go-to-market strategy and to expand its platform.
July 22nd, 2026 — Source

Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts
Hackers leaked names, email addresses, phone numbers, passwords, and financial information stolen from the two platforms.
July 22nd, 2026 — Source

Swimlane AI SOC automates security operations for MSSPs
Swimlane has announced the launch of Swimlane AI SOC for MSSPs, which the company says is designed to empower managed security service providers through agentic AI automation rather than compete for their customers.
July 22nd, 2026 — Source

Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers.
July 22nd, 2026 — Source

Third-Party SDKs Raise Privacy Questions for Apps Marketed to U.S. Military
Researchers found Chinese and Russian SDKs in Android apps marketed to U.S. military users, highlighting software supply chain and enterprise privacy risks.
July 22nd, 2026 — Source

This Malware Kills Your Apps 5 Times a Second Until You Give Up Your Password
It collects data from eight web browsers, some cryptocurrency wallet extensions, password managers, FTP clients, and shell history—then sends it to the attackers.
July 22nd, 2026 — Source

ThreatDown expands security visibility to AI tools and machine identities
ThreatDown has announced a synchronized expansion of its AI and identity security capabilities to protect organizations from emerging, unmanaged risks. The company launched AI visibility, giving security and managed service provider (MSP) teams a full inventory of the AI tools running across their environments, while simultaneously extending its ITDR capabilities to secure non-human identities (NHI).
July 22nd, 2026 — Source

or Source

Vibe-Coded Apps Riddled With Exploitable Security Flaws
Analysis found 434 exploitable flaws in AI-generated apps, with denial-of-service, authorization and secrets exposure risks among the most common issues.
July 22nd, 2026 — Source

When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover
Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge.
July 22nd, 2026 — Source

Internet — Security Issues — July 16th, 2026

2 Young Hackers Jailed for Disrupting London Underground
Police Say Arrests 'Effectively Halted' Scattered Spider Cybercrime Collective
July 16th, 2026 — Source or Source or Source or Source

23andMe to pay $18 million in new genetics data breach settlement
Genetic testing company 23andMe (now Chrome Holding Co.) has agreed to pay $18 million to settle claims from a coalition of 43 attorneys general that it failed to protect customers' genetic data.
July 16th, 2026 — Source

Adaptiva simplifies secure patch management for air-gapped networks
Adaptiva has announced AirGap for OneSite Patch, a new capability that extends autonomous patch management to air-gapped environments. Developed in response to growing demand from government agencies, critical infrastructure operators, and large enterprises managing highly secure environments, AirGap for OneSite Patch enables organizations to securely patch isolated systems without compromising the physical separation those environments require.
July 16th, 2026 — Source

AI Agents Broke the Security Playbook. Here's What Replaces It.
For most of the last two decades, enterprise security ran on a workable assumption: the environment was knowable. Security teams could buy tools, inventory users, map systems, define policies, and rely on vendor-built dashboards and workflows to manage most of what happened next.
July 16th, 2026 — Source

AI Leaders Are Pulling Ahead on Quantum Readiness
Strong Data Foundations Give AI Leaders an Edge in Quantum Security
July 16th, 2026 — Source or Source

China's Top Cybersecurity Firms Hit by Mounting Military Procurement Bans
Chinese cybersecurity firms are facing action from the country's military, but it's not due to product or technical failures.
July 16th, 2026 — Source

CISA folds its own hard-won lessons into coordinated vulnerability disclosure guidance
On Wednesday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and four allied cyber authorities published a guide telling software vendors how to build a coordinated vulnerability disclosure (CVD) program.
July 16th, 2026 — Source

CISA orders feds to patch actively exploited Oracle flaw by Saturday
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to secure their systems by Saturday against ongoing attacks exploiting a critical vulnerability in the Oracle E-Business Suite (EBS) financial application.
July 16th, 2026 — Source

Claude for Chrome Flaw Puts Gmail at Risk From Rogue Extensions
Researchers say a Claude for Chrome flaw lets rogue extensions trigger Gmail, Docs, and Calendar tasks, with greater risk in unattended mode.
July 16th, 2026 — Source

'ClickLock Stealer' Bypasses macOS Security With Social Engineering, Process Killing
The new macOS malware has targeted at least 100 users to steal their passwords and cryptocurrency.
July 16th, 2026 — Source

Cribl Targets TTP-Based Detection With CardinalOps Purchase
Startup Maps Detections Against MITRE ATT&CK and Recommends Missing Protections
July 16th, 2026 — Source or Source

F5 Patches Multiple NGINX, BIG-IP Vulnerabilities
Attackers could exploit the bugs to modify configurations, terminate or restart processes, cross security boundaries, leak memory, and execute code.
July 16th, 2026 — Source

Facial movement analysis detects deepfake videos with more than 95% accuracy
So-called deepfakes, that is, images and videos generated with the help of artificial intelligence, are becoming increasingly difficult to detect. An international research team from the University of Tokyo and the Max Planck Institute for Informatics in Saarbrücken, Germany, has developed a method that identifies manipulated videos more reliably than previous approaches—not by searching for visual artifacts, but by analyzing the naturalness of facial expressions. In tests on established benchmark datasets, the approach achieved an average detection accuracy of more than 95 percent and successfully identified manipulations that caused many existing detectors to fail.
July 16th, 2026 — Source

Google Makes Security Objections to EU Order Opening Android
EU Forces Google to Give Rival AI Services Android Access and to Share Search Data
July 16th, 2026 — Source or Source or Source or Source

How data brokers get your information, even if you're careful
Being careful online only goes so far. Learn where data brokers get their information and the best ways to limit what they collect.
July 16th, 2026 — Source

Intruder brings AI-powered, on-demand penetration testing to web applications
Intruder has announced the launch of AI Pentesting for web applications, providing on-demand penetration testing. Following its initial release of issue-level investigations last quarter, the platform now allows organizations to securely connect their codebases via GitHub or GitLab to automatically scope and launch penetration tests in minutes, with results and audit-ready reporting in hours.
July 16th, 2026 — Source

Law firm insisted on one password to rule them all
Using the admin password, you could be anyone and see anything
July 16th, 2026 — Source

Legacy Systems, Real-World Impacts: The Reality of OT Security
Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts.
July 16th, 2026 — Source

Lineation.ai focuses on runtime security for autonomous AI agents
Lineation.ai has announced the public launch of its comprehensive agentic security platform. Delivering a solution at the intersection of genAI application security and runtime defense, lineation introduces a zero trust unified control plane and a lightweight endpoint daemon that secures autonomous AI agents directly at execution.
July 16th, 2026 — Source

Microsoft is rebuilding its security business around AI, and cutting hundreds
Microsoft is overhauling its security business around AI and cutting several hundred jobs, as it races to win back spending flowing to OpenAI and Anthropic.
July 16th, 2026 — Source

Microsoft makes Windows SSO prompts easier to manage
Microsoft is introducing a new registry-based policy that lets IT administrators automatically accept Windows SSO permissions on Windows 11 versions 24H2 and 25H2 devices managed with Microsoft Entra ID.
July 16th, 2026 — Source

Microsoft's latest Patch Tuesday fixes 570 security bugs, but some Dell PCs will have to wait
AI is finding more Windows bugs than ever, but patches still aren't reliable
July 16th, 2026 — Source

New Spirals ransomware encrypts victim network in under 24 hours
A new ransomware actor called Spirals completed a corporate intrusion, from initial access to data theft and encryption, in less than 24 hours.
July 16th, 2026 — Source

'No company is going to go to jail for you': Proton's CTO on balancing privacy, policy, and trust
Bart Butler on encryption, child safety, and why there's no such thing as a backdoor for only the good guys.
July 16th, 2026 — Source or Watch Video

Node.js security starts before CI
Modern JavaScript teams do not just need more vulnerability reports. They need dependency decisions that developers can understand before risky code becomes part of the application.
July 16th, 2026 — Source

Oak Emerges From Stealth Mode With $60 Million in Funding
The startup has built an AI-powered Identity Operating System that governs all identities across an organization's environment.
July 16th, 2026 — Source

Old UEFI Shims Expose Systems to Secure Boot Bypass
Signed by Microsoft, the vulnerable UEFI shim bootloaders could be abused on any system, regardless of the OS.
July 16th, 2026 — Source

Police take down investment fraud network that stole €100 million a month
Dutch police, working alongside Belgian authorities and Europol, have dismantled a major criminal network accused of operating a global investment fraud scheme through dozens of fraudulent call centers.
July 16th, 2026 — Source

Researcher Drops 9th Windows Zero-Day
LegacyHive Is a Local Privilege Escalation Bug
July 16th, 2026 — Source or Source

Romania's land registry hit by cyber attack, data allegedly for sale
Romania's National Agency for Cadastre and Land Registration (ANCPI) suffered a major disruption on Tuesday, July 14, when its e-Terra cadastre and land registry app became unavailable to users.
July 16th, 2026 — Source

Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes
A Russian-speaking threat actor known as "bandcampro" used a jailbroken Gemini CLI, Google's open-source terminal-based AI agent, to deploy and operate a small command-and-control (C2) botnet, according to TrendAI.
July 16th, 2026 — Source

Russian hackers trojanize WebEx, Zoom apps to push Starland malware
A financially motivated Russian threat actor tracked as UAT-11795 is using trojanized software to steal credentials and cryptocurrency by deploying a new backdoor called Starland RAT.
July 16th, 2026 — Source

Scattered Spider members behind TfL hack get five years in prison
Two leading members of the Scattered Spider cybercrime collective were sentenced to five years and six months in prison each for hacking Transport for London (TfL) in 2024.
July 16th, 2026 — Source or Source

Splunk, Zoom Patch Critical Vulnerabilities
The flaws could allow attackers to access credentials and data, take over accounts, and escalate their privileges.
July 16th, 2026 — Source

Telegram shortlinks knocked offline over sanctioned VPN connection
t.me borked for a day until platform proved it had no ties to service favored by cybercriminals
July 16th, 2026 — Source

Tenable One unifies code risks with enterprise exposure data
Tenable has announced the expansion of the Tenable One Exposure Management Platform, unifying application security risks with all other exposure data. By integrating static code vulnerability data, Tenable One delivers complete, code-to-runtime visibility across the entire attack surface.
July 16th, 2026 — Source

The Biggest Data Breaches of 2026 So Far, Ranked by Impact
The biggest data breaches of 2026 so far, ranked by impact, with details on exposed data, affected users, and what readers should do next.
July 16th, 2026 — Source

UK cops say arrest of two young hackers disrupted the operations of an infamous hacking group
Owen Flowers, 18, and Thalha Jubair, 20, pleaded guilty earlier this year to hacking Transport of London (TfL), the government body overseeing the U.K. capital's public transit system, in 2024. The two were sentenced to five years and six months in prison on Thursday.
July 16th, 2026 — Source

UK Sees Data Infrastructure, Water System Cyberattack Risks
National Risk Assessment Cites CrowdStrike Lessons Learned, Hybrid Warfare Risks
July 16th, 2026 — Source or Source or Source or Source

ValorC3 extends SaaS protection with immutable cloud backups
ValorC3 Data Centers today announced the general availability of Backup as a Service, a fully managed offering that protects the SaaS data businesses rely on most, including Microsoft 365, Entra ID and Salesforce. Every backup is immutable, so data stays recoverable after deletion, corruption or a ransomware attack.
July 16th, 2026 — Source

VS Code agent host runs Copilot, Claude, and Codex in a dedicated process
Developers who lean on AI coding agents often keep several editor windows open at once, each tied to its own session. The 1.129 release of Visual Studio Code reworks that setup with a dedicated agent host.
July 16th, 2026 — Source

Why AI in Healthcare Demands Stronger Data Oversight
Attorney Jordan Cohen of Akerman on AI Challenges Ahead
July 16th, 2026 — Source or Source

Windows 10 refuses to die, and the security bill is coming due
One in six machines still run the old OS as migration stalls and patch deadlines creep closer
July 16th, 2026 — Source

Internet — Security Issues — July 12th, 2026

Microsoft's patch for a Windows Defender 0-day may have created a new attack path
Exploiting the bug could let attackers quarantine massive files until a system's storage is completely full
July 12th, 2026 — Source

Week in review: Accenture data breach, great open-source cybersecurity tools
Here's an overview of some of last week's most interesting news, articles, interviews and videos:
July 12th, 2026 — Source

Internet — Security Issues — July 11th, 2026

A VPN Can Only Protect Your Privacy So Much. Here's What to Consider
A VPN is a powerful privacy tool, but knowing what one can and can't do is important for protecting yourself online.
July 11th, 2026 — Source

Australia warns of global campaign targeting vulnerable CMS platforms
The Australian Cyber Security Centre (ACSC) issued an alert about a global exploitation campaign targeting vulnerable content management systems (CMS) and plugins.
July 11th, 2026 — Source

Fake Go DNS scanner spread malware through over 200 GitHub repos — 'Operation Muck and Load' has published 700 malicious modules since January
Socket traced the module to 222 repos across 190 accounts staging Vidar, RATs, and XMRig miners, with encrypted payload locations hidden on Pastebin, Telegram, and YouTube.
July 11th, 2026 — Source

'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
Researchers have built a pull request that steals a repository's secrets by hiding the malicious instruction inside a PNG that AI code reviewers never open.
July 11th, 2026 — Source

The 6 biggest cybersecurity breaches of 2026 so far
The year is only halfway through, yet 2026 has already been filled with data breaches, hacks, and cybersecurity incidents.
July 11th, 2026 — Source

US Cyber Agency Built Its Incident Playbook During A Live Hack
The federal group in charge of protecting government networks recently admitted a surprising fact about its own planning. The US cybersecurity agency CISA had to build its incident playbook during the incident, the agency reveals in a new public report. Instead of having a ready plan to follow, the team figured out their response steps in real time when a data leak occurred.
July 11th, 2026 — Source

Internet — Security Issues — July 10th, 2026

AI Coding Tools Can Fake Approval Prompts
Old Unix Symlink Trick Lets Malicious Code Bypass User Checks
July 10th, 2026 — Source or Source or Source or Source

Anthropic Tops AI Safety Index, Despite a C+ Grade
AI Firms Weakened Safety Pledges as Risks Grow, Says Report
July 10th, 2026 — Source or Source or Source or Source

Android 17 Root Exploit Chains Firefox Bug with 15-Year Kernel Vulnerability (By pressing a Link)
Security researchers have disclosed a proof-of-concept exploit capable of obtaining root access on Android 17 by combining vulnerabilities in Firefox for Android and the Linux kernel. The exploit chain, called IonStack, demonstrates how two individually patched security flaws can be linked together to achieve complete system compromise after a user simply opens a specially crafted link. According to Nebula Security, the attack begins with a vulnerability in Firefox for Android affecting versions up to 151.0.3. The flaw resides in the browser's JavaScript engine and provides the initial code execution needed to launch the second stage of the exploit.
July 10th, 2026 — Source

Chat Control 1.0 sneaks through the EU Parliament, letting companies scan user data without warrants — legal tactic used to force a majority-required re-vote on eve of Parliament break
Opponents to the rule suggest the maneuver is unprecedented.
July 10th, 2026 — Source

China, India-Linked Hackers Both Targeted Same Pakistani Police Force
Both foes and allies have targeted the Balochistan Police force in Pakistan for at least two years, according to SentinelOne.
July 10th, 2026 — Source

CrowdStrike identifies five new AI prompt injection threats
Awareness of all the ways prompt injection can be effected will help security teams spot a new generation of attacks.
July 10th, 2026 — Source

Fashion mart Miinto unzips breach details, warns shoppers to watch for phisherfolk
Copenhagen company 'sorry' after 'perpetrator' pops order management system
July 10th, 2026 — Source

Florida ransomware negotiator convicted for helping ransomware gang extort US companies
Florida man Angelo Martino has been sentenced to more than five years in prison for conspiring with hackers to deploy ransomware during his job as a ransomware negotiator for a U.S. cybersecurity company.
July 10th, 2026 — Source

Former ransomware negotiator gets 4 years for BlackCat attacks
A former employee of cybersecurity incident response company DigitalMint was sentenced to 70 months in prison for targeting U.S. companies in BlackCat (ALPHV) ransomware attacks.
July 10th, 2026 — Source

GigaWiper Combines Multiple Malware for System-Level Sabotage
The backdoor's destructive capabilities include a standalone wiper, ransomware encryption, and a multi-pass wiping command.
July 10th, 2026 — Source

Hackers exploit critical auth bypass in Gitea Docker image
Hackers are actively exploiting a critical vulnerability in the official Docker image for the Gitea self-hosted Git service that allows attackers to impersonate any user, including administrators.
July 10th, 2026 — Source

'HalluSquatting' Turns AI Hallucinations Into Botnet Delivery Mechanism
Researchers demonstrate adversarial hallucination squatting against popular AI assistants to achieve remote code execution.
July 10th, 2026 — Source

In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops
Other noteworthy stories that might have slipped under the radar: Abnormal AI sued by Anthropic, AssuranceAmerica data breach affects 7 million people, NSA brings back TAO.
July 10th, 2026 — Source

Incode brings on-device processing to age estimation for privacy-focused verification
Incode has launched On-Device Age Estimation, an age verification capability that performs age estimation and liveness detection directly on the user's device, without transmitting facial data off the device. The company's age estimation models are now available to run entirely on-device. The solution combines on-device age estimation with deepfake and spoofing detection.
July 10th, 2026 — Source

Is Microsoft Teams really going to start tracking employee locations?
A new "Workspace Check-in" feature rolled out last month.
July 10th, 2026 — Source

July 2026 Patch Tuesday forecast: Is CVE tracking still practical?
I was off by a month in my forecast of record-setting CVE releases from Microsoft. In June, we saw the deluge of over 200 reported CVEs that I expected in May. There were 116 CVEs for Windows 11 and 104 for Windows 10. In addition, we saw large numbers in both common applications like Office and SharePoint Server as well as the host of development tools and libraries like Visual Studio and .NET. Will the trend continue this month?
July 10th, 2026 — Source

Microsoft is now using AI to fix Windows bugs before hackers exploit them
As AI helps hackers find exploits faster, Microsoft says it's now using AI as well. Expect more security fixes in future Windows patches.
July 10th, 2026 — Source

Money launderer accused of stealing seized crypto while in prison
A Bulgarian national has been charged with stealing $290,000 in government-seized cryptocurrency while serving 121 months in prison for helping launder millions stolen from American fraud victims.
July 10th, 2026 — Source

Network of 200 GitHub Repositories Used for Malware Infection
A Go module is used to load PowerShell code that fetches a resolver from public dead drops to execute Windows malware.
July 10th, 2026 — Source

Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers
The attackers call victims to direct them to phishing websites mirroring Microsoft Entra ID login pages.
July 10th, 2026 — Source

RoguePlanet let hackers take over your PC. Microsoft just patched it
Microsoft has patched RoguePlanet—a Defender zero-day vulnerability that lets hackers gain full access to your PC—via Windows Update.
July 10th, 2026 — Source

SharpViewStateKing: The stealthy implant framework
The Canadian Centre for Cyber Security (Cyber Centre) is actively tracking a compromise that exploited several web shell payloads, enabling multiple hacking techniques. Following incident response activities, analysis revealed that the web shell was part of a stealthy implant framework called SharpViewStateKing
July 10th, 2026 — Source

The EU just revived a law that lets Meta and Google scan your messages -- critics call it mass surveillance
Encrypted messaging services are currently exempt, but a proposed stricter version could change that
July 10th, 2026 — Source

The open source library holding up your stack might have one maintainer
Every serious software product runs on code that someone else wrote and released for free. A web service leans on a cryptography library, a data pipeline pulls in a parser, and a mobile app ships a handful of small utilities that one person maintains in spare time. All of it carries the same label. A new paper argues that the single label hides differences large enough to change how each piece behaves once it lands in production.
July 10th, 2026 — Source

Third US Security Expert Sentenced to Prison for Helping Ransomware Gang
Angelo Martino, a former ransomware negotiator, was sentenced to 70 months for helping the BlackCat/Alphv group.
July 10th, 2026 — Source

Why you should never sell old electronics without checking them first
Anyone selling old smartphones, SSDs or printers often unwittingly reveals passwords, photos and sensitive documents. We'll show you which devices pose the greatest risk and how to delete your old digital data securely.
July 10th, 2026 — Source

Workato expands Agent Studio with Headless API, AI guardrails
Workato has announced two new capabilities for Agent Studio: Headless API and Agent Guardrails. Headless API lets Genies, Workato's AI agents built on Agent Studio, be embedded into any business application surface, on web, mobile, or inside another agent's own environment.
July 10th, 2026 — Source

Zimbra urges customers to patch critical web client XSS flaw
The Zimbra security team urged customers to patch a critical vulnerability affecting the Classic Web Client used to access the Zimbra Collaboration suite.
July 10th, 2026 — Source

Internet — Security Issues — July 9th, 2026

5,811 arrests, $293 million seized over social engineering scams
Criminals who pose as police officers, romantic partners, and business suppliers have built fraud operations that reach across continents. A four-month enforcement campaign against these schemes wrapped up, and police in 97 countries and territories took part.
July 9th, 2026 — Source

AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique
Wiz has disclosed the details of a new AI coding assistant attack method it has dubbed GhostApproval.
July 9th, 2026 — Source

AssuranceAmerica data breach exposes records of 6.9 million drivers
American insurance company AssuranceAmerica has disclosed a data breach impacting nearly 7 million drivers after attackers gained access to its systems earlier this year.
July 9th, 2026 — Source

AWS centralizes access, spending, and governance for Claude
Claude apps gateway for AWS is a self-hosted control plane that gives organizations a single point of control over access, costs, and policies for Claude Code and Claude Desktop. It replaces per-developer cloud credentials, manual distribution of managed settings to developer laptops, and centralizes usage attribution and spending controls. The gateway can be deployed with Amazon Bedrock or Claude Platform on AWS, providing the same capabilities in either environment.
July 9th, 2026 — Source

Hidden Backdoor Found in Tenda Router Firmware
Unauthenticated Flaw Allows Full Router, Network Takeover
July 9th, 2026 — Source or Source or Source or Source

I argued with a security expert about guest Wi-Fi... and won
Context matters.
July 9th, 2026 — Source

Meta CTO says employee-tracking data landed 'where it wasn't supposed to go'
Andrew Bosworth offers new detail on why Meta paused its keystroke-logging AI training programme, insisting there was no breach.
July 9th, 2026 — Source

Microsoft Patches Defender 'RoguePlanet' Vulnerability
The privilege escalation vulnerability tracked as CVE-2026-50656 has been patched with a Microsoft Malware Protection Engine update.
July 9th, 2026 — Source

Mount Royal University Confirms Data Stolen in Ransomware Attack
Hackers accessed the institution's internal network and deleted two drives containing employee, student, and university data.
July 9th, 2026 — Source

NetSPI pairs AI pentesting with expert-validated security findings
NetSPI has announced the expansion of its AI-powered continuous pentesting platform, broadening the suite of services that organizations can use to ensure critical assets are always protected. The new services comprise continuous web application penetration testing, continuous AI penetration testing, continuous internal penetration testing and continuous AI findings validation which applies expert human judgement to AI-generated security findings.
July 9th, 2026 — Source

New hack exploits AI hallucinations to trick agents into running malicious code — 'HalluSquatting' attack exploits a fundamental weakness in every available model
Today, a tale from the book of We Told You So.
July 9th, 2026 — Source

Police arrests 5,800 suspects in global anti-fraud crackdown
Law enforcement agencies have arrested 5,811 suspects and seized $293 million in illicit assets in a global anti-fraud operation spanning 97 countries.
July 9th, 2026 — Source

Thief posed as Wi-Fi fixing hero, then stole priceless trophy
If people think you are doing a legitimate job, you can get away with anything
July 9th, 2026 — Source

Your coding agent says no in chat and yes in the code
Millions of developers share their keyboard with GitHub Copilot. Inside Visual Studio Code, it opens their files, writes and edits code, runs scripts, and reworks its own output across many turns. The safety testing that vets these agents still runs on chatbot rules: one harmful prompt, one response, graded alone. That rulebook misses where the real danger sits, according to a study from the Alan Turing Institute in London.
July 9th, 2026 — Source

Internet — Security Issues — July 8th, 2026

3 Ways AI Powers Service Desk Attacks and How to Prevent Them
IBM's 2025 Cost of a Data Breach Report found that 16% of breaches studied involved attackers using AI tools, most often for phishing or deepfake impersonation attacks. For security teams, that has direct implications for the service desk.
July 8th, 2026 — Source

Accenture acknowledges security incident following 35GB data theft claim
Accenture appears to have suffered a data breach, the extent of which is currently unknown.
July 8th, 2026 — Source

American Hackers-for-Hire Proposal Sparks Heavy Criticism
US Senate Committee Approves Private Sector Hacking Pilot
July 8th, 2026 — Source or Source

Attackers using Langflow flaw for credential harvesting (CVE-2026-55255)
The US Cybersecurity and Infrastructure Security Agency (CISA) is warning about yet another Langflow vulnerability (CVE-2026-55255) leveraged by attackers in the wild.
July 8th, 2026 — Source

Attestiv DeepScan combines AI and forensic analysis for file validation
Attestiv announced the launch of DeepScan, a new platform built to help organizations automatically validate submitted files before they drive critical business decisions.
July 8th, 2026 — Source

Automox MCP Server adds visual reviews and AI-driven patch policy creation
The "Rogue Agent" vulnerability could have enabled attackers to silently manipulate AI conversations, exfiltrate data, and compromise every Dialogflow CX agent within the same Google Cloud project.
July 8th, 2026 — Source

Blackpoint AI SOC Agent autonomously contains identity-based attacks
Blackpoint Cyber has unveiled the generally available autonomous response capability, Blackpoint AI SOC Agent for identity threat detection and response (ITDR). Using an AI + human hybrid model, the AI SOC Agent acts on high-confidence threats targeting Microsoft 365 and Google Workspace accounts, enabling Blackpoint to contain credential-based attacks in less than two minutes on average and in as little as 21 seconds.
July 8th, 2026 — Source

Bug in top AI coding agents shows that Unix-era security headaches never really die
'GhostApproval' problem highlights human-in-the-loop fails
July 8th, 2026 — Source

Censys Internet Map links real-time DNS data to internet infrastructure
Censys has announced the expansion of the Censys Internet Map to include real-time DNS visibility. Security teams can now seamlessly pivot between domains, names, and the Internet infrastructure behind them on the Censys Platform. With active DNS data now part of the Internet Map, security teams can replace workflows that relied on multiple datasets and investigative interfaces with a single cohesive platform.
July 8th, 2026 — Source

China tells devs to ditch Claude Code over 'backdoor code' fears
National vulnerability database claims monitoring mechanism can forward Chinese users' data to remote servers
July 8th, 2026 — Source

CISA orders feds to prioritize patching Langflow auth bypass flaw
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) gave federal agencies until Friday to patch an actively exploited vulnerability in the Langflow visual framework for building AI agents.
July 8th, 2026 — Source

CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws
Two newly disclosed critical vulnerabilities in Adobe ColdFusion and Langflow join two Joomla extension flaws in CISA's Known Exploited Vulnerabilities catalog, with federal agencies given until July 10 to patch.
July 8th, 2026 — Source

Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection
Researchers show how attackers can use a crafted public GitHub Issue to trick AI-powered workflows into exposing data from private repositories without authentication.
July 8th, 2026 — Source

Crusoe brings serverless fine-tuning to AI model development
Crusoe has announced Serverless Fine-Tuning and Self-Serve Deployments in Crusoe Intelligence Foundry, the managed AI platform for Crusoe Cloud. These capabilities give data scientists and ML engineers a complete path from proprietary data to production-ready models, on purpose-built AI infrastructure, without the overhead of managing it.
July 8th, 2026 — Source

DNSFilter makes its DNS threat protection available to OEM partners
DNSFilter has launched an Original Equipment Manufacturing (OEM) program that lets external ISPs, cybersecurity firms, device makers, and other consumer app developers to embed their DNS threat protection, domain analysis, and privacy solutions into their own platforms and solutions.
July 8th, 2026 — Source

FalconStor Cloud Clean Room enables validated recovery without dedicated infrastructure
FalconStor has announced FalconStor Cloud Clean Room, an on-demand infrastructure platform designed to let organizations perform validated recovery testing in a persistent secure enclave. Each test starts from a known state, reducing the risk of carrying issues over from previous recovery exercises.
July 8th, 2026 — Source

First Recon AI Security Runtime helps enterprises govern AI with audit-ready evidence
First Recon AI has announced the public launch and general availability of First Recon's AI Security Runtime, a security platform that both governs and secures how enterprises use artificial intelligence across an organization. First Recon's runtime inspects every AI interaction (human to model, agent to tool, and agent to agent), applies policy inline before data reaches a model, and records every decision as audit-ready evidence, so organizations can adopt AI quickly and govern it with confidence.
July 8th, 2026 — Source

Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations
The "Rogue Agent" vulnerability could have enabled attackers to silently manipulate AI conversations, exfiltrate data, and compromise every Dialogflow CX agent within the same Google Cloud project.
July 8th, 2026 — Source

Hackers can use 9 of the most popular AI tools to assemble massive botnets
"HalluSquatting" weaponizes LLMs' inability to say "I don't know."
July 8th, 2026 — Source

Hidden backdoor in Tenda routers goes unpatched as company ignores warnings from cybersecurity researchers — Chinese company's firmware allows admin access without a password
The CERT Coordination Center (CERT/CC), a U.S. government-backed cybersecurity group at Carnegie Mellon University's Software Engineering Institute, disclosed a firmware flaw on July 6 that can hand attackers full administrative control over several Tenda networking devices. The vulnerability, tracked as CVE-2026-11405, is an undocumented authentication backdoor in the affected models' firmware that bypasses the normal login process and grants access to the devices' web management interface without valid credentials. Compounding the risk, there is currently no security patch available, as Tenda — a Shenzhen-based budget networking brand with a large presence in India and other markets — is yet to respond despite CERT/CC reaching out on the issue.
July 8th, 2026 — Source

Online Privacy Shouldn't Be So Much Effort and So Expensive
Commentary: Protecting your personal data often requires more time, energy and money than the average person might be able to invest.
July 8th, 2026 — Source

Solo GP Ashley Smith announces second $25M fund to back startups in AI, security and more
Vermilion Cliffs Ventures announced Wednesday the close of a $25 million Fund II. The firm was founded in 2023 by operator-turned-investor Ashley Smith, who runs it as one of the few solo women GPs in venture capital. Speaking to TechCrunch, Smith said this fund will continue the firm's thesis of backing technical founders, specifically those building in AI infrastructure, security, and dev tools.
July 8th, 2026 — Source

Telco giant KDDI says data breach affects over 12 million people
Japanese telecommunications giant KDDI revealed that millions of people had their email addresses and passwords exposed after attackers breached an email platform used by five internet service providers (ISPs) in the country.
July 8th, 2026 — Source

Ubiquiti warns of new max severity UniFi OS vulnerability
Ubiquiti has released security updates to patch seven critical vulnerabilities in UniFi OS, including a maximum-severity flaw tracked as CVE-2026-50746 that can be exploited in command injection attacks.
July 8th, 2026 — Source

Internet — Security Issues — July 4th, 2026

Confidential computing's trust mechanism is broken. The fix may not exist
Attested TLS: the handshake that can't prove who's on the other end
July 4th, 2026 — Source

JadePuffer ransomware used AI agent to automate entire attack
Researchers identified what they believe is the first documented case of a ransomware operation, JadePuffer, conducted entirely by a large language model (LLM) agent.
July 4th, 2026 — Source

Internet — Security Issues — July 2nd, 2026

Alleged Scattered Spider hacker extradited to the United States
19-year-old Peter Stokes (who used the online handles "Bouquet," "Spencer," and "Jordan") was arrested in Finland on April 10 while attempting to board a flight to Japan at Helsinki's airport and is accused of having helped extort millions of dollars from multiple high-profile companies worldwide.
July 2nd, 2026 — Source

Apple's Hide My Email service reportedly reveals users' actual email addresses with little effort — Cupertino has seemingly known about the problem for a year but has yet to fix it
Millions of users risk having their real email addresses exposed
July 2nd, 2026 — Source

Best Data Removal Services of 2026: Reduce Your Online Presence
Data brokers and people-finder sites are everywhere, but the top data removal services could help you clean up your online footprint.
July 2nd, 2026 — Source

CISA Warns of Actively Exploited Microsoft SharePoint Vulnerability
CISA says threat actors are exploiting a recently patched SharePoint remote code execution vulnerability (CVE-2026-45659).
July 2nd, 2026 — Source

CISA: Microsoft SharePoint RCE flaw now actively exploited
Cisco finally confirms attackers exploiting Unified CM flaw
July 2nd, 2026 — Source

Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability
A PoC exploit has been available since public disclosure, and the first exploitation attempts were observed last week.
July 2nd, 2026 — Source

Cisco finally confirms attackers exploiting Unified CM flaw
Unified CM (formerly known as Cisco CallManager) is the central control system for Cisco IP telephony systems, handling call routing, device management, and telephony features.
July 2nd, 2026 — Source

Cloudflare changes AI crawler access rules
Cloudflare introduced new controls that let website owners manage AI traffic across three categories: Search, Agent, and Training. The feature is available to all Cloudflare customers, including those on the Free plan, and gives website owners more control over how different types of AI crawlers access their content.
July 2nd, 2026 — Source

ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds
It can start with something as mundane as dragging a link into your browser. Three seconds later, a threat actor has the tokens needed to take over your Microsoft 365 account, and you never did anything that traditional security awareness training would flag. You just followed what looked like a normal set of instructions.
July 2nd, 2026 — Source

Cryptohack Roundup: Chinese Fraudster Gets 30 Years in Prison
Also: Hollywood Director Jailed for $11M Fraud
July 2nd, 2026 — Source or Source or Source or Source

Ctrl+Alt+Oops: FortiBleed criminal's logins stitch two gangs together
Researchers scoured logs, finding opsec fail for at least one person who was working with INC and Lynx simultaneously
July 2nd, 2026 — Source

DeleteMe Review: The Swiss Army Knife of Data Removal Services
A tried and tested data removal service that has a few more tricks up its sleeve than its younger competitors.
July 2nd, 2026 — Source

EasyOptOuts Review: A Budget-Friendly Service You Can Set and Forget
EasyOptOuts performs just as well as other data removal services at a fraction of the price, but you give up some transparency and regular security audits.
July 2nd, 2026 — Source

EFF and Allies: X's FTC Petition to Waive Privacy Violation Order Should be Rejected
X Corp. should not be able to escape privacy compliance because it changed its name.
July 2nd, 2026 — Source

FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks
Researchers say credentials harvested from hundreds of thousands of FortiGate firewalls are being used to facilitate ransomware attacks by the INC and Lynx operations.
July 2nd, 2026 — Source

Governance in the Age of AI: Navigating the Mirror Maze
Security Leaders Need to Act Now to Set Guardrails, Seize Opportunities
July 2nd, 2026 — Source or Source or Source or Source

Hackers shoveled snow for company, were rewarded with network admin access
Fortunately, they were professional red teamers. Unfortunately, they pwned the network
July 2nd, 2026 — Source

How to Conduct a Successful Audit of AI-Driven Software Development
As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production.
July 2nd, 2026 — Source

Incogni Review: Comprehensive and Transparent Data Removals
Incogni has wide-reaching coverage, but it lacks third-party efficacy testing data.
July 2nd, 2026 — Source

India gives WhatsApp three days to defend username rollout amid security fears
Government of the messenger's largest market demands a pause while Meta explains how it plans to stop impersonators
July 2nd, 2026 — Source

Kanary Review: A Data Removal Service Aimed at Tackling Serious Modern Issues Like Doxxing
Alongside data removals, Kanary offers niche but useful features to combat issues like reputation abuse and doxxing. It's also beta-testing the removal of your information from AI chatbots and LLMs.
July 2nd, 2026 — Source

Microsoft Flags MCP Tool Descriptions as Hidden AI Agent Attack Path
Microsoft warns that poisoned MCP tool descriptions can steer AI agents into leaking sensitive data through approved tool calls.
July 2nd, 2026 — Source

Microsoft said exploitation was 'less likely' ... but CISA just added SharePoint RCE to KEV list
Attackers need little more than a valid SharePoint account to execute code on vulnerable on-prem servers
July 2nd, 2026 — Source

New Chrome Update Fixes 382 Security Bugs Across Desktop, Mobile
Google released a Chrome update addressing 382 security bugs, including sandbox-escape risks. Users and IT teams should update quickly.
July 2nd, 2026 — Source

New malicious clipboard clone raises serious security concerns for Mac users
Malware disguises itself as this clipboard manager utility to steal your information.
July 2nd, 2026 — Source

Opera's new security feature stops copy paste attacks from malicious websites
Paste Protect offers the first native defense against 'ClickFix clipboard attacks.
July 2nd, 2026 — Source or Source or Source

Optery Review: An Effective, but Expensive, Data Removal Service
Optery is one of the best data removal services out there, but it comes with a hefty price tag.
July 2nd, 2026 — Source

Oracle E-Business Suite was under attack via critical flaw before the public exploit code was even released
Attackers appear to have reverse-engineered Big Red's patch
July 2nd, 2026 — Source

OWASP CRS v4.28.0 Drops With Critical Security Fixes and First LTS Track
OWASP Core Rule Set v4.28.0 released today delivers critical security patches including XML attribute inspection across attack rules and the elimination of catastrophic backtracking in Unix shell evasion detection. The update adds new protections for quote-based SQL injection evasion, ORM lookup operator injection, and RCE evasion prefixes while removing exponential backtracking from several performance-critical rules. The project also announced v4.25.0 as its first Long-Term Support release, providing enterprise stability as legacy CRS 3.3.x support wraps up in Q3 2026.
July 2nd, 2026 — Source

Pacemaker manufacturer Medtronic warns patients cybercrooks may have swiped health data
Company that also makes insulin pumps and other devices tells users what was exposed months after ShinyHunters attack
July 2nd, 2026 — Source

Proton Introduces Lumo 2.0 With Privacy-Focused Upgrade to Its AI Assistant
On Tuesday, Proton introduced Lumo 2.0, the second iteration of its privacy‑first AI assistant. The company says Lumo 2.0 uses new reasoning models that respond faster and handle complex, multi‑step queries better than the previous version.
July 2nd, 2026 — Source

Scattered Spider Suspect Extradited From Finland to US
FBI Says Peter Stokes, 19, 'Exhibited Substantial Wealth for a Person of His Age'
July 2nd, 2026 — Source or Source or Source or Source or Source

Smooth AI criminal drives 'first' end-to-end agentic ransomware attack
Don't count on the LLM to return your data - even if you pay up
July 2nd, 2026 — Source

Why a Windows Hello PIN Beats a Password for Enterprise Security
As phishing campaigns, AI-driven identity attacks, and Windows migration planning raise authentication stakes, IT teams should recheck how Windows Hello PIN security works.
July 2nd, 2026 — Source

You Won't Buy the New Meta Glasses After Reading About Their Bizarre Subscription Model
Some of the smart glasses' offline features are behind a paywall, because of course they are.
July 2nd, 2026 — Source

Internet — Security Issues — June 28th, 2026

AI coding agents can be tricked into installing malware via 'clean' GitHub repositories — Mozilla's 0din team shows how Claude Code can be exploited by its own helpfulness
Three levels of indirection, all with seemingly innocuous steps, will catch a bot off-guard.
June 28th, 2026 — Source

Data breach exposes up to 14.2 million email logins at six ISPs
Japanese telecommunications operator KDDI Corporation disclosed a data breach where threat actors gained access to one of its email systems used by five other internet service providers (ISPs) in the country.
June 28th, 2026 — Source

FBI Warns That Traffic Distribution Systems Are Being Used to Spread Malware and Scams
The FBI just dropped a Public Service Announcement warning that cybercriminals are abusing Traffic Distribution Systems (TDS platforms) to silently redirect users to phishing pages, malware downloads, ransomware, and financial scams. The kicker? The redirect happens before you ever realize anything is wrong. You click what looks like a legitimate ad or search result and end up somewhere completely different.
June 28th, 2026 — Source

Week in review: Fortibleed campaign's impact on orgs, Cisco Unified CM flaw exploited
Encrypted DNS runs across much of the Internet. DNS over TLS, HTTPS, and QUIC keep the contents of a query away from anyone watching a network link. The encryption covers the message inside each packet. The packet still carries plaintext headers, and those values mark a flow as DNS.
June 28th, 2026 — Source

Internet — Security Issues — June 27th, 2026

Apple Helps Tata Electronics Fix Security After A Huge Data Leak
Apple is stepping in to help one of its main suppliers clean up a massive security mess. Tata Electronics, a major partner that builds iPhones in India, just confirmed a serious cybersecurity incident that exposed tons of secret client files on the dark web. In response to the breach, the tech giant sent its own security team to work directly with the manufacturer to lock down its internal systems and stop further leaks.
June 27th, 2026 — Source

Chinese Framework Powers 200,000 Scam Sites
Threat actors are selling investment scam templates created using the legitimate DCloud Uni-App toolkit.
June 27th, 2026 — Source

Clean GitHub repo tricks AI coding agents into running malware
An agentic coding tool tasked with cloning and setting up a seemingly benign GitHub repository could execute a malicious payload that remains invisible to security scanners, AI agents, and human reviewers.
June 27th, 2026 — Source

FBI says Russian intelligence hackers have a new trick for reading your Signal messages, and it works even after you change phones
An updated FBI and CISA advisory names two Russian hacking groups, UNC5792 and UNC4221, and warns that handing over a Signal backup key gives attackers persistent access to an account's entire message history
June 27th, 2026 — Source

Internet — Security Issues — June 26th, 2026

$3 Million Reportedly Stolen in Polymarket Hack
The decentralized prediction market said hackers targeted some of its users through a compromise of a third-party vendor.
June 26th, 2026 — Source

Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories
AWS has patched the vulnerability and published its own advisory to inform customers about the potential impact.
June 26th, 2026 — Source

Apple supplier Tata Electronics tightens security after data breach
Tata Electronics, a major Indian supplier to Apple, has restricted internal access to sensitive systems while it investigates a leak of thousands of confidential client files on the dark web, according to a Tata source and two industry officials, Reuters reports.
June 26th, 2026 — Source

Critical open-source projects get a new security framework
Open source software projects are getting a new framework for handling security vulnerabilities as AI shortens the time between flaw discovery and exploitation.
June 26th, 2026 — Source

Cybersecurity firms targeted by fraudulent OpenAI organization invites
Threat actors are creating OpenAI tenants that impersonate legitimate companies and inviting employees to join them, in what appears to be a ploy to trick targets into submitting sensitive company information in chats and projects.
June 26th, 2026 — Source

First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild
Threat actors have successfully exploited a vulnerability in PTC Windchill in the wild, marking the first confirmed real-world abuse of the popular product lifecycle management (PLM) platform.
June 26th, 2026 — Source

How Accenture Acquisition Could Push Dragos Beyond Energy
Forrester: Transaction Reflects Move From Services Toward Owning Security Technology
June 26th, 2026 — Source or Source or Source

ISMG Editors: Prep Now, Hackers Will Soon Wield Frontier AI
Also: AI Model for Drug Development Allegedly Stolen; Accenture's Dragos Deal
June 26th, 2026 — Source or Source or Source or Source

Miasma campaign poisons 20-plus npm packages, hunts for developer secrets
Microsoft says latest attack targets Leo Platform and RStreams packages, harvesting creds and going after more maintainersz
June 26th, 2026 — Source

Microsoft Quietly Gives Windows 10 Home Users an Extra Year of Free Security Updates
We didn't see this one coming.
June 26th, 2026 — Source

Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials
Mirage2FA, a phishing kit that combines short-lived HTML smuggling with obfuscated JavaScript loaders to deliver fake Microsoft 365 login pages and steal credentials during MFA prompts, has been identified by researchers at Fortra.
June 26th, 2026 — Source

More Klue Breach Victims Identified as Hackers Get Hacked
Roughly two dozen companies have notified their customers of the Klue-Salesforce incident impact.
June 26th, 2026 — Source

Mystery hackers use novel SharkLoader dropper against governments, software devs
Kaspersky researchers have uncovered a previously unknown cyberattack campaign that has compromised government organizations and software development companies in multiple countries.
June 26th, 2026 — Source

Nebulock Raises $25 Million for AI-Native Contextual Security
The cybersecurity startup provides threat hunting, proactive detection, and behavioral security analytics.
June 26th, 2026 — Source

New Enterprise-Ready MCP Specification Brings New Security Challenges
A major overhaul of the Model Context Protocol shifts critical security responsibilities from the protocol itself to developers and platform operators.
June 26th, 2026 — Source

Proof's x401 establishes an open protocol for AI agent identity and authorization
With x401, a service can ask for the proof it requires: verified identity, age, membership, organizational affiliation, signing authority, proof of humanness, orf another trusted claim. The agent presents a compatible credential and authorization. The service verifies the issuer, claim, scope and action before proceeding.
June 26th, 2026 — Source

Ransomware gangs find Europe's weakest link in third-party suppliers
Ransomware attacks against European organizations increased during the first months of 2026, with third-party suppliers becoming a major entry point for attackers. Black Kite examined 2,066 ransomware incidents across 31 countries between January 2025 and April 2026 in its 2026 European Cyber Risk Report.
June 26th, 2026 — Source

Russian APT Deploys 'StockStay' Backdoor Against Ukrainian Targets
Turla has been using the backdoor against government and military organizations in Ukraine for espionage.
June 26th, 2026 — Source

Secukinumab rapidly reduces hidden joint inflammation in psoriasis patients
Before joints become painful, psoriatic arthritis (PsA) often begins silently as enthesitis - inflammation where tendons and ligaments attach to bone. This hidden condition is invisible to routine exams but detectable by ultrasound.
June 26th, 2026 — Source

SIM-swapping gang busted in international police operation
Officers from Poland's Central Bureau for Combating Cybercrime (CBZC) arrested four suspected members of an organized cybercrime group accused of SIM swap attacks, cryptocurrency theft, and money laundering.
June 26th, 2026 — Source

Synology issues critical fix for MailPlus Server vulnerabilities
Synology has has fixed critical vulnerabilities in MailPlus Server, a software package used to run private email infrastructure on Synology NAS devices.
June 26th, 2026 — Source

ThreatModeler introduces Nexus to automate threat modeling with AI governance
ThreatModeler introduces Nexus to automate threat modeling with AI governance
June 26th, 2026 — Source

Xprize founder says 'humans behave better when they're being watched'
Xprize Foundation founder Peter Diamandis has joined a growing list of tech executives who think that global surveillance is a good idea, saying, "[h]umans behave better when they're being watched."
June 26th, 2026 — Source

ZeroTier Quantum RC2 brings post-quantum security closer to general availability
ZeroTier has announced the release candidate 2 (RC2) for ZeroTier Quantum, its end-to-end quantum-secure networking platform. This milestone marks the final testing phase, positioning the platform one step away from general availability (GA).
June 26th, 2026 — Source

Internet — Security Issues — June 23rd, 2026

Algerian Man Extradited to US for Running Cybercrime Marketplaces
26-year-old Abdellah Belmili faces up to 30 years in prison for allegedly operating the marketplaces Market0Day and Spoxy.
June 23rd, 2026 — Source

Apple and Tesla trade secrets reportedly exposed following a Tata Electronics cyberattack
Up to 630GB of data was reportedly stolen by hackers, but Tata says its operations have not been impacted.
June 23rd, 2026 — Source

Canadian Electricity Provider London Hydro Discloses Data Breach
Hackers stole customers' names, addresses, email addresses, phone numbers, and account information.
June 23rd, 2026 — Source

CISO Conversations: Carl Froggett -- Combining CISO and CIO at Deep Instinct
Carl Froggett combines CISO and CIO. He currently occupies both positions at Deep Instinct. Before then, he was CISO at Citi for almost 17 years.
June 23rd, 2026 — Source

Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps
Attackers could abuse Dify's multi-tenant cloud service to read private chats, preview other tenants' documents, and reach internal APIs.
June 23rd, 2026 — Source

Don't Panic If You've Been Scammed. Here's What to Do Instead
Take these steps to minimize the damage -- and protect yourself from being scammed again.
June 23rd, 2026 — Source

Dragos unveils OT-native AI to help critical infrastructure teams prioritize threats faster
Dragos has announced the release of EmberAI, an OT-native AI built on the Dragos Intelligence Fabric. EmberAI gives every analyst immediate access to Dragos's OT-specific intelligence, gained from more than a decade of OT operations, activity, and expertise.
June 23rd, 2026 — Source

Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks
The high-severity use-after-free vulnerability in Samsung's KNOX security framework affected Android-powered Galaxy devices from the S9 through S25.
June 23rd, 2026 — Source

FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances
Attackers can send crafted media files to execute code in any application that uses FFmpeg's libavcodec library.
June 23rd, 2026 — Source

GTA 6 early access offers are taking gamers' crypto
Scam websites are circulating across the internet with a pitch aimed at millions of gamers: a way to play Grand Theft Auto VI before its release. The pages promise early access for a few hundred dollars in cryptocurrency, ask buyers to enter a payment code, and claim the game will then unlock.
June 23rd, 2026 — Source

Hack The Box adds crisis simulations and SOC training to strengthen cyber readiness
Hack The Box (HTB) has announced new capabilities to help security leaders gain greater visibility into skills, performance and operational readiness. As AI transforms cyberattacks and cybersecurity operations, HTB is expanding its cyber readiness platform to help organizations identify gaps, evaluate team performance and strengthen organizational resilience.
June 23rd, 2026 — Source

How To Manually Update Microsoft Defender in Windows 11
Windows Defender can't really do its job as an antivirus if it's outdated. So, if you suspect you're missing an update or two, you can manually check. It should only take a couple of minutes.
June 23rd, 2026 — Source

LastPass confirms data breach in Klue supply chain attack
LastPass announced that hackers accessed support cases containing customer data from its Salesforce environment after stealing the company's OAuth tokens in the Klue supply chain attack earlier this month.
June 23rd, 2026 — Source

Mavenir turns NOC knowledge into automation for autonomous networks
Mavenir has announced its Agentic Service Assurance Framework, a TM Forum IG1251/IG1453-aligned, multi-agent system that automates complex network operations across multiple domains without replacing existing systems.
June 23rd, 2026 — Source

New N-able feature gives IT teams visibility into AI usage across endpoints and networks
N-able has announced the availability of Shadow AI Visibility across its Unified Endpoint Management (UEM) solutions, N‑central and N‑sight, and its Security Operations platform, Adlumin. The new capability helps organizations identify, classify, and monitor AI tool usage across managed environments, providing IT and security teams with the visibility needed to address a rapidly growing operational and security blind spot.
June 23rd, 2026 — Source

North Korean Hackers Poison Mastra AI Framework
More Than 140 npm Packages Carried Credential-Stealing Code
June 23rd, 2026 — Source or Source or Source

Omada Identity Sovereign targets Europe's growing digital sovereignty demands
Omada has introduced Omada Identity Sovereign, a new solution that enables organizations to take direct control over where and how their identity governance is deployed. The solution addresses the digital sovereignty requirements, including data, operational, and jurisdictional control, that regulated organizations cannot meet with standard cloud deployments.
June 23rd, 2026 — Source

OpenAI Refocuses Cybersecurity Efforts on Patching Over Discovery
OpenAI has expanded its Daybreak cybersecurity initiative with a new suite of tools and partnerships.
June 23rd, 2026 — Source

OpenAI wants AI to fix vulnerabilities, not just find them
OpenAI expanded Daybreak, its cybersecurity initiative that combines AI models, Codex Security, security researchers, maintainers, industry partners, and access controls to support vulnerability discovery and remediation. Organizations can use the initiative to identify, validate, and fix software vulnerabilities, while developers, maintainers, and security teams can use its tools to strengthen defensive security capabilities.
June 23rd, 2026 — Source

Russian Initial Access Broker Behind FortiBleed Campaign
Using a custom sniffer, the threat actor has captured over 110 million credentials since at least February 2026.
June 23rd, 2026 — Source

Scattered Spider members plead guilty to hacking Transport for London
Two members of the 'Scattered Spider' cybercrime group pleaded guilty to hacking the Transport for London (TfL) systems in 2024.
June 23rd, 2026 — Source

The cybersecurity industry built a $200B business selling you problems. Nobody got paid to fix them.
Cybersecurity has never been better at finding risk. Organizations can identify vulnerable servers, dormant user accounts, excessive privileges, exposed cloud assets, and software flaws in near real time. The market has rewarded that capability handsomely, with global cybersecurity spending projected to exceed the half-trillion-dollar range as enterprises continue investing in tools that promise greater visibility into their environments.
June 23rd, 2026 — Source

The Exploit Doesn't Exist. You Can Still Prove It Works Against You
For thirty years, vulnerability management has run on what now looks like an impossible luxury: a buffer of months between when a vulnerability was found and when someone could figure out how to weaponize it. Triage by severity, schedule the fix, validate, move on.
June 23rd, 2026 — Source

Top Indian tech supplier reports 'cybersecurity incident'
A top Indian maker of iPhone parts has confirmed it was hit by a "cybersecurity incident," with media reports alleging that Apple supplier specifications had been leaked.
June 23rd, 2026 — Source

Trump Signs Executive Order Accelerating Post-Quantum Cryptography Migration
Trump Signs Executive Order Accelerating Post-Quantum Cryptography Migration
June 23rd, 2026 — Source

Two Scattered Spider hackers plead guilty over Transport for London cyberattack
Two members of the notorious hacker group Scattered Spider have pleaded guilty to charges related to a 2024 cyberattack on Transport for London (TfL) that resulted in £29 million in loss and recovery costs.
June 23rd, 2026 — Source

Using Reddit to manipulate AI search results is surprisingly easy
A Reddit comment that takes only a few seconds to write can end up influencing the answers generated by AI research tools.
June 23rd, 2026 — Source

What the Fortibleed campaign means for organizations running FortiGate firewalls
A massive credential-harvesting campaign targeting FortiGate firewalls has exposed thousands of organizations to potential network compromise, and a trove of attacker tools, scripts, and credentials left inadvertently exposed on a server has given researchers an unusually detailed look at how the operation worked.
June 23rd, 2026 — Source

Windows Secure Boot certificates expire tomorrow. Don't ignore this deadline
Windows Secure Boot certificates must be updated by June 24th. Here's how to check your status and what happens if you miss it.
June 23rd, 2026 — Source

Internet — Security Issues — June 22nd, 2026

23 ClawHub plugins squatting official scopes expose AI registry security gaps
Plugin registries for AI agents use npm-style scopes like @openclaw/ and @clawhub/ to signal who published a package. But on ClawHub, a registry whose plugins run with Claude, OpenClaw, and other agents, those official scopes weren't reserved to their owners for every package already published.
June 22nd, 2026 — Source

A Glimpse into the "Search Your Target" Market for Stolen Credentials
Threat actors are increasingly turning massive infostealer-derived credential collections into searchable underground services, allowing buyers to request credentials for a specific company, platform, domain, geography, or account type.
June 22nd, 2026 — Source

A Vulnerability in PAN-OS Could Allow for Authentication Bypass
A vulnerability has been discovered in the GlobalProtect portal and gateway of PAN-OS which could allow for authentication bypass. The PAN-OS GlobalProtect Portal acts as the central control plane for Palo Alto Networks VPN infrastructure. Successful exploitation of the vulnerability allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.
June 22nd, 2026 — Source

Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data
Vulnerable WordPress plugin iterations leak API keys, secrets, tokens, server information, and other data.
June 22nd, 2026 — Source

AWS Continuum offers devs help with securing code
Continuum is a new service intended to hep developers and security teams secure their own code and that of others too, with a goal of automating remediation.
June 22nd, 2026 — Source

Brazil probes emergency warning system after nationwide rogue alert
Severe weather event alert platform buzzed devices across the country with the word 'misanthropy'
June 22nd, 2026 — Source

Canadian utility fesses up to data breach, but key details remain off-grid
London Hydro says names, addresses, account details may have been exposed, but much about the intrusion is unknown
June 22nd, 2026 — Source

Crypto Clipper uses USB drives and Tor to steal wallet data
Microsoft Threat Intelligence and Microsoft Defender Experts have identified a Windows cryptocurrency clipper campaign that has affected users since February 2026. The malware targets clipboard data, wallet credentials and cryptocurrency addresses through Windows Script Host and ActiveX-driven logic.
June 22nd, 2026 — Source

Decades-Old Squid Proxy Flaw 'Squidbleed' Can Expose User Data
Squidbleed, discovered with the aid of Claude Mythos Preview, has been described as a Heartbleed-style vulnerability.
June 22nd, 2026 — Source

Europe Seeks to Advance 6G Security, Privacy
EU Projects Seek to Protect Fast New Network, Secure Information Sharing
June 22nd, 2026 — Source or Source or Source or Source

Five Eyes cyber security agencies statement on the AI shift in cyber risk: why leaders must act now
As the leaders of the Five Eyes cyber security agencies, we are united in our call to action: the evolving landscape of artificial intelligence (AI) is rapidly transforming cyber risk, and we must act swiftly to remain ahead.
June 22nd, 2026 — Source

Fortinet Responds to FortiBleed Campaign
A database of over 86,000 confirmed working credentials was created during the credential-harvesting campaign.
June 22nd, 2026 — Source

Gizmodo readers hit with ClickFix malware prompts after account compromise
Infosec buffs say Windows users could have been infected with a nasty trojan, while Mac users got off lightly
June 22nd, 2026 — Source

Health board apologizes for phishing staff with with bogus vacation day
IT thought a fake offer of extra time off for hard-pressed Canadian medical workers was the way to go
June 22nd, 2026 — Source

I Turned Off All Antivirus Protection for a Week. Here's What I Learned
Disabling my antivirus for a week taught me that the most important security tool you have isn't software.
June 22nd, 2026 — Source

Klue hack results in data breach at several cybersecurity firms
A hacking group has taken credit for a breach at market intelligence provider Klue that allowed hackers to steal reams of data from the company's corporate customers, which include some of the biggest names in cybersecurity.
June 22nd, 2026 — Source

Microsoft fixes AutoGen Studio flaw that enabled code execution
A vulnerability chain dubbed AutoJack in Microsoft's AutoGen Studio interface for prototyping AI agents could let attackers manipulate an agent into executing arbitrary commands on its host system simply by visiting a malicious webpage.
June 22nd, 2026 — Source

Microsoft scrambles to patch a Defender security flaw called RoguePlanet
A zero-day vulnerability in Microsoft Defender lets attackers gain full system access on up-to-date Windows 10 and 11 PCs. No fix yet.
June 22nd, 2026 — Source

More Cybersecurity Firms Disclose Impact From Klue Hack
HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, and Tanium are among the affected Klue customers.
June 22nd, 2026 — Source

New Exploit Bypasses Apple's Boot Defenses, Affects Millions of iPhones
The vulnerability exploited by the Usbliter8 exploit cannot be patched and a PoC exploit has been released by researchers.
June 22nd, 2026 — Source

North Korean Hackers Blamed for Mastra NPM Supply Chain Attack
A malicious dependency the attackers added to over 140 Mastra packages fetches a payload targeting cryptocurrency extensions.
June 22nd, 2026 — Source

Prinz Eugen Ransomware Hits Recent Files First and Skips Ransom Notes
Prinz Eugen ransomware prioritizes recently modified files and leaves no ransom note on disk, creating new pressure on backup windows, endpoint alerts, and incident response playbooks.
June 22nd, 2026 — Source

Protect yourself: How to make sure your VPN is shielding you
A VPN only protects you when it stays connected.
June 22nd, 2026 — Source

Internet — Security Issues — June 20th, 2026

Hackers are mass-exploiting a Gravity SMTP flaw to steal API keys from 100,000 WordPress sites
CVE-2026-4020 exposes a REST API endpoint with no authentication check, returning 365 KB of JSON containing email service credentials, database details, and the full software stack to anyone who asks
June 20th, 2026 — Source

Microsoft finds USB worm that steals cryptocurrency through clipboard hijacking and Tor
The malware, tracked as Trojan:Win32/CryptoBandits.A, spreads through .lnk files on USB drives, replaces wallet addresses for six cryptocurrencies, and uses a portable Tor client to hide its command-and-control traffic
June 20th, 2026 — Source

ShinyHunters published 45GB of Madison Square Garden data, including facial recognition surveillance records
The leaked data includes internal risk profiles of celebrities, customer emails about facial recognition concerns, and biometric surveillance logs from up to 26 million visitors
June 20th, 2026 — Source

The UK will scan asylum-seekers' faces for age checks—despite knowing the tech is flawed
Tests of age-verification technology show the risks of life-altering errors.
June 20th, 2026 — Source

Why Amazon hates 'human-in-the-loop' AI governance
VP Eric Brandwine explains people aren't all that great, actually
June 20th, 2026 — Source

Why you need to take back control of your synced passwords and how to go about doing that
In this editorial, I explain why I took back control of my synced passwords and share the software I used to accomplish this.
June 20th, 2026 — Source

Internet — Security Issues — June 19th, 2026

Accenture to buy Dragos, runZero, and NetRise in $4.2 billion cybersecurity deal
Accenture is expanding its position with the acquisition of a majority stake in Dragos and all of runZero and NetRise to deliver end-to-end operational technology (OT) security for the critical infrastructure and industrial operations underpinning power grids, pipelines, manufacturing, distribution facilities and data centers.
June 19th, 2026 — Source

BlackFog brings shadow AI visibility to macOS endpoints with ADX Vision
BlackFog has announced the general availability of ADX Vision for macOS, extending its shadow AI detection, governance, and prevention platform to Apple endpoints. With this release, enterprises can now apply a single, consistent AI data-loss policy across Windows and macOS devices to stop sensitive data from leaving the organization through unsanctioned LLMs.
June 19th, 2026 — Source

Britain's privacy watchdog quits after 'poor judgment' admission
John Edwards says his position had become 'untenable' following investigation into conduct including inappropriate attempts at humor
June 19th, 2026 — Source

Cisco to Acquire WideField Security to Boost Splunk's Agentic SOC
WideField will accelerate Agentic SOC capabilities by expanding the lens on threat investigation to include identity, credentials, sessions, and blast radius.
June 19th, 2026 — Source

Cybercriminals abused GitHub, YouTube and VirusTotal to push crypto-stealing malware
A cryptocurrency-stealing malware campaign used inflated GitHub activity, software reviews, YouTube tutorials and favorable VirusTotal comments to make malicious trading and gambling tools appear trustworthy, Check Point researchers found.
June 19th, 2026 — Source

Cybercrime Initial Access Service SocGholish Disrupted
Police Seize Evil Corp-Tied Group's Servers, Clean Subverted WordPress Sites
June 19th, 2026 — Source or Source or Source or Source

Cybersecurity Firms Impacted by Klue Supply Chain Attack
The hackers exfiltrated data from Salesforce instances of Klue customers, such as Huntress and Recorded Future.
June 19th, 2026 — Source

CryptoBandits Malware Doubles as a Backdoor, Abuses Tor
CryptoBandits uses a local SOCKS5 proxy for traffic routing, blending data theft with remote code execution.
June 19th, 2026 — Source

Everything's bigger and better in Texas -- even data breaches
Hunting and fishing license incident catches 3M residents
June 19th, 2026 — Source

Experts Warn of 'Mismatch' in US Response to OT Hacking
Cross Sector Dependencies in OT Hinders Attack Response
June 19th, 2026 — Source or Source or Source or Source

Forget traffic lights, Google's reCAPTCHA may ask for hand gestures
Google has introduced hand gesture verification for reCAPTCHA, a new method for verifying that a user is human.
June 19th, 2026 — Source

FortiBleed: 86,000 Fortinet Device Credentials Compromised
The large-scale credential theft campaign hit roughly half of the internet-accessible Fortinet firewalls and VPNs.
June 19th, 2026 — Source

France and Germany Boost Digital Sovereignty Push
Franco-German Plan Defines Digital Sovereignty, Paris Unveiles Tech Fund
June 19th, 2026 — Source or Source or Source or Source

From Reflection to Shadow: AI, Us and the Space in Between
When AI Partnerships Deepen, Security Leaders Can Access Powerful Joint Cognition
June 19th, 2026 — Source or Source or Source or Source

Frontier Airlines site leaks all personal info with just a glance at a boarding pass, researcher claims — booking number and last name nets you every passenger's personal info, including address, passport, TSA PreCheck, and most credit card info
Bob is a hacker. Just over three months ago, they found serious vulnerabilities in Frontier Airlines' API and website that would let anyone with a boarding pass code for a flight retrieve every passenger's personal information, including but not limited to home address, nearly all credit card info, full passport details, and even TSA PreCheck codes. The boarding pass code (called PNR) is written on the pass itself, or scannable via its barcode; plus, since it's only six digits, it's easy to loop through, something they replicated to find several passengers' full info.
June 19th, 2026 — Source

GitLab 19.0 Embeds Agentic AI in Secrets, Merge Requests, and Supply Chain Security
GitLab has released GitLab 19.0, moving its agentic AI from code generation into the work that surrounds it: securing credentials, reviewing and merging changes, and scanning released packages. The 21st May release adds a public beta of GitLab Secrets Manager, extends the Developer Flow agent across the full merge request lifecycle, and makes software bill of materials (SBOM) dependency scanning generally available.
June 19th, 2026 — Source

Google sets timeline for Android developer verification enforcement
Android's developer verification protections will take effect on September 30, 2026, starting with users in Brazil, Indonesia, Singapore, and Thailand. Developers distributing apps through participating stores in those markets must complete the verification process by the deadline. Google Play, HONOR App Market, OPPO App Market, Galaxy Store, Palm Store, V-Appstore, and GetApps will begin verifying app installations, with expansion to certified Android devices globally planned for 2027.
June 19th, 2026 — Source

Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin
Threat actors are exploiting an unauthenticated information disclosure vulnerability in the WordPress plugin Gravity SMTP, active on 100,000 sites.
June 19th, 2026 — Source

Hackers have stopped breaking in. They're abusing the things developers already trust.
Two campaigns this week tell the same story. A group called TeamPCP has poisoned more than 1,000 open-source packages, and other hackers turned Anthropic Claude's own 'Shared Chats' into a malware delivery system. Neither broke in. Both abused trust, and AI is making it easier.
June 19th, 2026 — Source

HIPAA's No Joke: Gag Gift Firm's Health Plan Pays $450K Fine
Investigation of Spencer's Gifts Ransomware Breach Unearths Data Privacy Violations
June 19th, 2026 — Source or Source

In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum
Other noteworthy stories that might have slipped under the radar: Android TV botnet Popa linked to Israeli firm, Velvet Ant maintained decade-long stealth, unpatched GCP Config Connector flaw enables takeover.
June 19th, 2026 — Source

Intel hires former SK hynix chief Seok-Hee Lee to lead Intel Foundry advanced packaging — company establishing section as 'focused business with dedicated leadership'
Intel has appointed Seok-Hee Lee, the former chief executive of memory maker SK hynix and battery maker SK On, as executive vice president of Intel Foundry, handing the semiconductor veteran control of advanced packaging, system integration, and all back-end technology development and manufacturing. Lee reports directly to CEO Lip-Bu Tan, and his arrival comes with a structural change at the foundry: Intel is splitting advanced packaging out as a dedicated business, with Naga Chandrasekaran narrowing his focus to front-end work on the Intel 18A and 14A nodes.
June 19th, 2026 — Source

Is That Call, Text or Email Real? Here's How to Identify Scams
Scams are more advanced than ever, in large part thanks to AI. But there are still ways to identify them.
June 19th, 2026 — Source

ISMG Editors: Cyber Backlash Over the US Ban on Anthropic AI
Also: Why Smaller AI Models Are Gaining Ground, CISOs Navigating the AI Trust Gap
June 19th, 2026 — Source or Source or Source or Source

Klue breach lead to Salesforce data theft, Huntress affected
Cybersecurity vendor Huntress was among multiple companies hit by a breach originating at Klue, a market intelligence platform used to integrate CRM and sales data across various business tools.
June 19th, 2026 — Source

Klue Confirms OAuth Token Theft Led to Salesforce Data Heist
'Compromised Legacy Credential' Wielded by Extortion Group Calling Itself Icarus
June 19th, 2026 — Source or Source or Source or Source

Mastodon 4.6 adds profile Collections and two-factor controls
People who run accounts on the open source social network Mastodon can now group profiles together and share those groups across the web. The 4.6 release centers on a feature called Collections, along with reworked profiles, email newsletters, server administration controls, and a set of accessibility changes.
June 19th, 2026 — Source

NY man charged after harassing college student with AI-generated nudes
A New York man faces cyberstalking charges after allegedly sharing AI-generated nude images and fabricated racist messages using fake social media profiles to harass a Georgia college student.
June 19th, 2026 — Source

Rights groups brand Home Office's AI age guesser for asylum-seekers as biased and inaccurate
Campaigners say tech is unable to reliably distinguish between kids and adults at the boundary where use is planned
June 19th, 2026 — Source

ShinyHunters Threatens to Leak Amazon One Medical Records
Extortion Gang Claims It Stole 8.8TB of Healthcare Firm's Data
June 19th, 2026 — Source

Texas govt data breach exposes over 3 million driver's licenses
The Texas Parks and Wildlife Department (TPWD) disclosed a data breach at its license system vendor that exposed personal information for more than three million individuals.
June 19th, 2026 — Source

Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253)
CISA has added CVE-2026-20253, a critical, remotely exploitable vulnerability in Splunk Enterprise, to its Known Exploited Vulnerabilities catalog, and ordered US federal civilian agencies to apply mitigations by June 21, 2026.
June 19th, 2026 — Source

Why Your Apple Account Needs Two-Factor Authentication Today
Two-factor authentication (2FA) is a crucial security feature designed to enhance the protection of your Apple account. It requires two forms of identification to verify your identity, making sure that even if someone obtains your password, they cannot access your account without completing an additional verification step. By combining your password with a six-digit verification code, 2FA establishes a multi-layered defense that significantly reduces the risk of unauthorized access.
June 19th, 2026 — Source

Windows Platform Security and the Race to Secure AI Agents
In a new Windows Developer Blog post titled "Windows platform security for AI agents", Microsoft positions Windows as the trustworthy operating system for autonomous agents and introduces the Microsoft Execution Containers (MXC) SDK as the core of that strategy. The post argues that containment, identity and manageability must be built into the operating system so that agents can be deployed and governed safely at scale. It describes a spectrum of isolation mechanisms, from process and session isolation through to planned micro virtual machines and Linux containers, all driven by MXC policy.
June 19th, 2026 — Source

Internet — Security Issues — June 16th, 2026

AI and Cybersecurity -- Everything You Wanted to Know, But Were Afraid to Ask
From defending networks to enabling attacks, artificial intelligence is changing every aspect of cybersecurity. Here's what dozens of experts say security leaders need to understand now.
June 16th, 2026 — Source

AppViewX extends machine identity security to AI agents and post-quantum environments
AppViewX has announced Agent Identity Security, a new product within the AppViewX platform that discovers, governs, secures, and monitors AI agents across the entire enterprise.
June 16th, 2026 — Source

Are Chrome extensions safe? This security expert advises caution
An ethical hacker explains how add-ons can leave you vulnerable to attack.
June 16th, 2026 — Source

Attackers are exploiting FortiSandbox vulnerabilities
Attackers have been spotted exploiting three vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) in FortiSandbox, a platform that other Fortinet security products depend on for threat verdicts to enforce blocking decisions and trigger automated responses.
June 16th, 2026 — Source

Attackers hijacked over 1,500 Arch Linux packages to steal developers' secrets, no hacking required
The malware never touched Arch Linux's official repositories. It didn't have to: the attackers simply adopted abandoned packages in the community-run AUR and rewrote their build scripts to plant a credential stealer, exposing the trust model the repo runs on.
June 16th, 2026 — Source

Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages
Arch Linux suspended account registrations in response to the wave of malicious packages being uploaded to AUR.
June 16th, 2026 — Source

Cal Water Investigating Iranian Hackers' Claims
California Water Service says there is no indication of operational disruptions to its water and wastewater systems.
June 16th, 2026 — Source

Can CISOs Trust Their Applications? TrustCloud Wants to Replace the Questionnaire
By continuously analyzing security, infrastructure, and governance data, TrustCloud aims to give CISOs a real-time view of application risk and board-ready assurance.
June 16th, 2026 — Source

Cardiac monitor maker's security skips a beat as data thieves go for the jugular
Attackers used social engineering to access third-party business apps and steal patient information
June 16th, 2026 — Source

Cisco discloses second exploited SD-WAN vulnerability in two weeks (CVE-2026-20262)
Cisco has revealed another Catalyst SD-WAN Manager vulnerability (CVE-2026-20262) that its Product Security Incident Response Team observed being exploited by attackers.
June 16th, 2026 — Source

CISA warns of another cPanel plugin flaw exploited in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. government agencies three days to secure their servers against an actively exploited vulnerability (CVE-2026-54420) in the LiteSpeed cPanel user-end plugin.
June 16th, 2026 — Source

Critical Copilot vulnerability allowed hackers to steal 2FA code from users
SearchLeak exploit shows why the industry's approach to LLM security fails over and over.
June 16th, 2026 — Source

Critical Fortinet FortiSandbox flaws now exploited in attacks
Attackers are now exploiting several critical vulnerabilities in Fortinet's FortiSandbox cyber threat detection platform, according to threat intelligence company Defused.
June 16th, 2026 — Source

Crooks found a new way to collaborate using Teams -- by hiding command-and-control traffic
Custom malware routed communications through legitimate Microsoft services, making malicious activity look like routine corporate collaboration
June 16th, 2026 — Source

Crypto scammers are sending couriers to victims' homes to collect cash
Scammers behind cryptocurrency investment schemes are dispatching couriers to pick up cash from victims in person, the FBI warns.
June 16th, 2026 — Source

Cyber Resilience Summit Dallas Prioritizes Risk Management
CISOs Discussed Governance, Security Operations and Cyber Risk
June 16th, 2026 — Source or Source or Source or Source

Cybercrime Group Claims Novo Nordisk Hack
The hack-and-leak group FulcrumSec claims to have stolen 1.3TB of data from the pharmaceutical giant.
June 16th, 2026 — Source

Cybercriminals mask malicious communications through Microsoft Teams relays
The DragonForce ransomware group used a custom malware called Backdoor.Turn to hide command-and-control traffic inside Microsoft Teams relay infrastructure during an intrusion at a U.S. services company, according to Symantec.
June 16th, 2026 — Source

Endpoint Security Startup Ent Emerges From Stealth With $100 Million Seed Round
Ent has developed an intent-aware platform designed to interpret user and agent behavior before risky actions are carried out.
June 16th, 2026 — Source

FTC warns of record $3.5 billion losses to imposter scams in 2025
The U.S. Federal Trade Commission (FTC) warned that Americans lost $3.5 billion to imposter scams in 2025, with reported losses nearly tripling since 2020.
June 16th, 2026 — Source

GhostTree Attack Abused Recursive Windows Junctions to Hide Malware
Most security teams think of NTFS junctions and symbolic links as niche file system features. They let one directory point to another, like a shortcut that the OS treats as real. They exist for backward compatibility, storage management, things that rarely come up in a SOC. But they have a property that makes them interesting from an offensive perspective: any user can create them.
June 16th, 2026 — Source

Google crushes massive AI scam ring to quiet your inbox
Chinese network used AI templates to impersonate popular brands and services.
June 16th, 2026 — Source

Hacker Conversations: Isira Adithya, the Evolution of an Ethical Hacker
From building LED bulbs to graduating college and buying a house with money earned from bug bounties.
June 16th, 2026 — Source

iRhythm Confirms Data Stolen in Hack
The digital health company said it learned of the breach on June 8 and the attackers demanded a ransom.
June 16th, 2026 — Source

Keep up with HIPAA Expectations amid Growing Cyber Threats
In the healthcare industry, a security failure isn't just an information technology (IT) problem. It's a patient safety problem that can result in non-compliance fines under the Health Insurance Portability and Accountability Act (HIPAA).
June 16th, 2026 — Source

Magnitude Emerges From Stealth Mode With $10 Million in Funding
The company is enhancing third-party risk management (TPRM) through autonomous AI agents.
June 16th, 2026 — Source

Radware AI Xploit Shield delivers virtual patching for newly identified application and API flaws
Radware has announced AI Xploit Shield, a new service that provides organizations with protection for their applications and APIs from exploitation of newly discovered vulnerabilities.
June 16th, 2026 — Source

Ransomware gang abuses Microsoft Teams relays to hide malicious traffic
DragonForce ransomware used a custom malware named 'Backdoor.Turn' to hide command-and-control traffic inside Microsoft Teams relay infrastructure.
June 16th, 2026 — Source

Scammers keep scoring: Brits fleeced for £1.3B as Americans lose $3.5B to impersonators
More reasons to love social media and AI
June 16th, 2026 — Source

ShinyHunters Claims Council of Europe HR Data, Threatens Leak
ShinyHunters claims it stole 297GB of data from the Council of Europe, including payroll and medical records, but the organization has not confirmed a breach.
June 16th, 2026 — Source

SimpleHelp RMM flaw could give attackers full access to managed endpoints (CVE-2026-48558)
A critical vulnerability (CVE-2026-48558) in SimpleHelp, a popular remote monitoring and management (RMM) tool, can be exploited remotely by unauthenticated attackers to create a new "Technician" account and use it to remote into managed endpoints, execute scripts, and more.
June 16th, 2026 — Source

Software supply chains are heading for a transparency test
Software supply chain visibility is becoming part of product security work as the EU Cyber Resilience Act (CRA) moves toward application in December 2027. ENISA's SBOM Adoption State of Play 2026 shows organizations preparing for CRA obligations through SBOM tooling, automation, and changes to software development practices.
June 16th, 2026 — Source

South Korea Fines Coupang $409M Over Massive Data Breach
Investigators Found Months of Unchecked Database Scraping Activity
June 16th, 2026 — Source or Source or Source or Source

TekStream launches Proactive Cyber Defense to counter AI-driven threats
TekStream has announced the launch of TekStream Proactive Cyber Defense, a new expert-operated security service powered by Cosmos, the company's cyber defense intelligence platform.
June 16th, 2026 — Source

Teleport adds LLM Proxy and Delegated Identity to secure AI agent actions and access
Teleport has announced the debut of two foundational capabilities of its Agentic Identity Framework in the public beta of Beams: LLM Proxy and Delegated Identity. These capabilities address a critical gap in how organizations deploy AI agents: the lack of identity, access control, and auditability at the two most consequential points in an agentic workflow—what the agent is instructed to do and what it is permitted to access.
June 16th, 2026 — Source

The Trust Problem in Modern SaaS: Why Your Authentication Succeeded, and You Still Got Breached
Modern SaaS breaches often happen after successful authentication. Learn how trust drift, weak authorization, and stale tokens create hidden risks.
June 16th, 2026 — Source

UK confirms social media ban for kids is coming -- Meta, YouTube, and Snapchat respond
Keir Starmer says he won't compromise on children's safety, but Australia's experience shows bans are hard to enforce
June 16th, 2026 — Source

UK to require ID or face scan before you can make social media accounts
The UK government will ban under-16s from social media, with regulations due before Christmas and the rules taking effect in spring 2027.
June 16th, 2026 — Source

White House Issues Memo to Bolster NSS Cybersecurity
NSPM-12 establishes a clear structure for NSS cybersecurity governance and accountability and reestablishes CNSS.
June 16th, 2026 — Source

Windows version of SprySOCKS Linux malware used to attack govt orgs
Windows variants for the SprySOCKS Linux malware have been used in attacks targeting government organizations in at least four countries.
June 16th, 2026 — Source

Internet — Security Issues — June 15th, 2026

1Password Buys Apono to Expand AI Access Governance
Buying New York Startup Adds Just-in-Time Authorization and Governance Controls
June 15th, 2026 — Source or Source or Source or Source

1Password Credential Broker reduces secret sprawl through identity-based credential delivery
1Password has announced 1Password Credential Broker, a new product that securely brokers credentials, tokens, and federated access from 1Password to trusted requesters. The 1Password Credential Broker is available in private beta today, with support for GitHub Actions and a roadmap that extends trusted access across humans, machine workloads, and AI agents through a common identity fabric.
June 15th, 2026 — Source

2021 Honda Civic infotainment system can be jailbroken via USB — flaw uses public Android test keys to install unauthorized apps, enables for 'EvilValet' attacks
This isn't a new issue at all, but it seems that automakers still don't care enough for cybersecurity on their vehicles.
June 15th, 2026 — Source

Administration's AI security order acknowledges risks but stops short of regulating industry
The new executive order focuses on using AI to boost the security of federal and private computer systems. It also aims to ensure that the federal government has access to major new AI models before they are released to the public to determine whether they pose a threat.
June 15th, 2026 — Source or Watch Video

AI vulnerability discovery is pushing 2026 CVEs toward 66,000
Vulnerability disclosures are piling up faster in 2026 than anyone expected at the start of the year. The running count for the first few months sits well above the original projection, and the Forum of Incident Response and Security Teams (FIRST) now expects the year to land near 66,000 CVEs.
June 15th, 2026 — Source

China-linked spies backdoored authentication stack to stay hidden for years
A China-linked cyber espionage group known as Velvet Ant spent nearly a decade inside the internal network of an unnamed organization without being detected, according to the results of a forensic investigation published by cybersecurity firm Sygnia.
June 15th, 2026 — Source

Chinese hackers breach REDCap servers, steal medical research
A China-linked espionage campaign targeted exposed REDCap servers to deploy the InfiniteRed malware and steal sensitive data from a medical institution in North America.
June 15th, 2026 — Source

Chinese Hackers Target Medical, Military, and AI Research in North America
Google's Threat Intelligence Group has been tracking the cyberespionage group as UNC6508 since early 2025.
June 15th, 2026 — Source

Cybersecurity vets protest 'dangerous' US government ban on Anthropic's most powerful models
A group made up of dozens of cybersecurity experts, including several well-known veterans of the industry, published an open letter to the U.S. government asking it to lift the export control order on Anthropic's Fable and Mythos models.
June 15th, 2026 — Source

Delinea and Cyera integrate for data-aware identity security
Delinea and Cyera announced a product integration that connects privileged access to sensitive data exposure, automatically correlating identities with the data they can access. Together, Delinea and Cyera help security teams identify, prioritize, and remediate the highest-risk access paths across every human, machine, and AI agent.
June 15th, 2026 — Source

FBI And Google Crush AI Scam Ring Behind 1.59 Million Phishing URLs
SMS spam has evolved far beyond the era of low-effort annoyances, transforming into a massive, industrialized ecosystem. Today, it's a highly calculated numbers game consisting of fake package notifications, urgent bank alerts, and non-existent security breaches designed to prey on everyday users. While these text alerts may appear random and disconnected on your phone, a look under the hood reveals a highly coordinated, centralized infrastructure.
June 15th, 2026 — Source

FBI: Fraudsters use couriers to steal money in crypto scams
Such scams usually start with the fraudsters reaching out to their targets via social media, dating sites, and messaging apps, building trust, and then luring victims into fake investment schemes. However, instead of investing their funds, the scammers will steal the money by moving it into accounts under their control.
June 15th, 2026 — Source

FBI, Google Dismantle 'Outsider Enterprise' Phishing Service
The platform used more than 9,000 phishing sites, stealing nearly 4 million credit cards and causing roughly $1.9 billion in losses.
June 15th, 2026 — Source

French Government Messaging Platform Breached by Mysterious 'Misere' Hacker
French officials say roughly 73,000 government accounts were affected, while the threat actor claims to have stolen messages and user data from the sovereign Tchap platform.
June 15th, 2026 — Source

I write about online scams. A fake Nvidia livestream still almost fooled me
The stream was fake. The warning signs were real.
June 15th, 2026 — Source

Infinite Campus data breach affects 137,000 school staff accounts
The ShinyHunters extortion gang stole personal information from more than 137,000 school staff accounts in a Salesforce data theft attack that targeted the widely used Infinite Campus K-12 student information system in March.
June 15th, 2026 — Source

Maine Disables Data Breach Portal Due to Fake Submissions
Someone posted fake VRChat and Discord data breach reports on the system, prompting the Maine AG to take action.
June 15th, 2026 — Source

Microsoft site throwing warnings after someone forgot to renew cert
Connectivity checker trips browser alarms thanks to lapsed security paperwork
June 15th, 2026 — Source

Modat enhances Magnify with Passive DNS for faster threat hunting and infrastructure analysis
Modat has launched native Passive DNS intelligence in Magnify, its internet intelligence platform, unifying IP, device fingerprint, certificate, and passive DNS into a single pivot-driven investigation flow.
June 15th, 2026 — Source

New attack turned Microsoft 365 Copilot into 1-click data theft tool
A critical vulnerability chain dubbed SearchLeak in Microsoft 365 Copilot Enterprise could allow attackers to steal sensitive data from a target's mailbox, OneDrive, or SharePoint account through a specially crafted URL.
June 15th, 2026 — Source

NewCore Emerges From Stealth Mode With $66 Million in Funding
The startup has built a security-first identity platform to protect humans, machines, and AI agents.
June 15th, 2026 — Source or Source

Omada Agent Governance helps organizations manage AI agent access, risk, and compliance
Omada has announced Omada Agent Governance, a new solution designed to help organizations bring the same governance discipline to AI agents and non-human identities that they already apply to people.
June 15th, 2026 — Source

Oracle Warns PeopleSoft Customers After Critical Zero-Day Exploited
Oracle issued emergency guidance for CVE-2026-35273, a critical PeopleSoft flaw exploited in a ShinyHunters-linked campaign targeting universities.
June 15th, 2026 — Source

Ozempic Maker Novo Nordisk Says Hackers Breached IT Systems
The pharmaceutical giant says the attackers gained access to personal data stored on the compromised systems.
June 15th, 2026 — Source

PhishLumos: Exposing phishing campaigns that evade detection by hiding content
Phishing remains one of the most stubbornly persistent threats in cybersecurity: humans are tired, distracted, trusting, and susceptible to urgency and authority in ways that no amount of awareness training can completely overcome.
June 15th, 2026 — Source

PRC-linked spies hid inside medical and military networks for more than a year, snooping through Gmail and stealing data
Google says the intruders were on the hunt for everything from drone tech to pathogens
June 15th, 2026 — Source

Ransomware Attack Shuts Down Mills of Australia's Second-Largest Sugar Producer
Mackay Sugar was targeted in a cyberattack carried out by a threat group known as The Gentlemen.
June 15th, 2026 — Source

Red Sift, GMO GlobalSign partnership simplifies email authentication and BIMI adoption
Red Sift has announced a partnership with GMO GlobalSign to provide organizations with a direct path from email authentication to verified brand visibility in the inbox. Red Sift OnDMARC is now available through GMO GlobalSign, enabling secure outbound email protection and the activation of Brand Indicators for Message Identification (BIMI) through a GMO GlobalSign Verified Mark Certificate (VMC) or Common Mark Certificate (CMC), all through a single trusted provider.
June 15th, 2026 — Source

ShinyHunters Claims Council of Europe Hack
The extortion group threatens to leak 297 GB of data allegedly stolen from the Council of Europe, including employee personal information.
June 15th, 2026 — Source

The FBI built a small town to simulate cyberattacks
The Kinetic Cyber Range has a fake hotel, a gas station, and even its own data center for people to protest.
June 15th, 2026 — Source

The FBI Warns That Chinese Spies Are Using Job Boards Like LinkedIn For Serious Scams
Today's job market can be tough to navigate, which is why many people use LinkedIn and other job search apps to help narrow down the hunt. Just be sure to be aware of some of the common scams that users need to watch out for. But while it can be a useful tool, it's also become the target of controversy. In a document entitled "Safeguarding Our Secrets," the FBI is warning that Chinese intelligence is using LinkedIn and other professional networking platforms to get access to sensitive information.
June 15th, 2026 — Source

Trust3 AI's AgentDOS monitors AI agent activity, data access, and token consumption
Trust3 AI has announced AgentDOS, an enterprise control plane that provides visibility into AI agents, including real-time token consumption monitoring across platforms such as Databricks Agent Bricks and Microsoft Copilot Studio.
June 15th, 2026 — Source

Ukrainian national pleads guilty in connection with Conti ransomware
A Ukrainian national pleaded guilty to conspiracy to commit wire fraud in connection with the deployment of Conti ransomware, which targeted more than 1,000 victims worldwide.
June 15th, 2026 — Source or Source

US Anthropic Export Controls Sparks Sharp EU Reaction
Decision to Restrict Access Exposes EU Dependency on US-Made Models
June 15th, 2026 — Source or Source or Source or Source

Internet — Security Issues — June 10th, 2026

After AI Reaches Production: 12 Ways Security Teams Can Take Control
Security teams need more than visibility into AI applications, they need a repeatable framework for monitoring, investigating, and defending them in production.
June 10th, 2026 — Source

AISLE Snapshot keeps source code under enterprise control during vulnerability scanning
AISLE has introduced AISLE Snapshot, a new offering that gives regulated and security-sensitive enterprises access to frontier-class vulnerability detection inside their own environments, at a fraction of the cost, with source code and security data that never leave their control.
June 10th, 2026 — Source

Anthropic's Claude Fable 5 is out for public use, with safeguards for high-risk requests
Days after publishing research on how advanced AI systems could amplify cyber operations in the wrong hands, Anthropic released Claude Fable 5, a Mythos-class model for general use.
June 10th, 2026 — Source

Apple extends Private Cloud Compute to third-party data centers
Apple is bringing its Private Cloud Compute (PCC) platform to Google Cloud, expanding the infrastructure behind Apple Intelligence to third-party data centers.
June 10th, 2026 — Source

Are Small Models Closing the Gap on Frontier AI Cyber Tools?
Fable 5 Release Fuels Debate Over Whether Frontier Models Are Worth the Higher Cost
June 10th, 2026 — Source or Source or Source or Source

Aryon Security Raises $29 Million in Series A Funding
In the post-Mythos era, the company's platform helps organizations enforce security controls across environments.
June 10th, 2026 — Source or Source

Best VPNs for torrenting: 5 top picks for speed, privacy, and security
Stay safe while torrenting with these top VPN picks.
June 10th, 2026 — Source

Building reusable workflows with custom agents in Copilot CLI
Developers spend much of their working time in the terminal, generating commands, debugging issues, and running scripts close to their systems. Repeated terminal work tends to pile up small steps such as re-running the same commands, re-explaining context, and translating logs into a form a team can act on. Custom agents in GitHub Copilot CLI address these patterns by turning repeated tasks into reusable workflows.
June 10th, 2026 — Source

China-linked JDY botnet expands targeting of U.S. military networks
The JDY botnet, a malware network previously associated with Chinese threat actors like Volt Typhoon, has significantly expanded its targeting scope and reconnaissance efforts.
June 10th, 2026 — Source

Critical HVAC and UPS Vulnerabilities Could Let Hackers Disrupt Data Centers
Claroty researchers have analyzed the security of Vertiv UPS network cards and the Trane Tracer SC+ HVAC controller.
June 10th, 2026 — Source

Critical Ivanti Sentry flaw allows root-level remote code execution (CVE-2026-10520)
Ivanti has patched two critical vulnerabilities (CVE-2026-10520 and CVE-2026-10523) in Ivanti Sentry and has urged customers to implement the fix right away.
June 10th, 2026 — Source

Critical Vulnerabilities Patched in Fortinet, Ivanti Products
Two OS command injection flaws can be exploited remotely, without authentication, for arbitrary code execution.
June 10th, 2026 — Source

Cybersecurity researchers aren't happy about the guardrails on Anthropic's Fable
Anthropic released its latest model Fable on Tuesday, billing it as a public and limited version of its powerful and much-hyped cybersecurity model Mythos.
June 10th, 2026 — Source

Cyera Raises $600 Million at $12 Billion Valuation
Cyera is positioned as one of the most valuable privately held cybersecurity firms in the world with total funding topping $2 billion.
June 10th, 2026 — Source

Data Center OT Flaws Could Help Hackers Kill Power and AC
Claroty Warns of Downtime, 'Devastating' Impact of Vulnerabilities in OT Systems
June 10th, 2026 — Source or Source or Source or Source

Drata brings visibility, control and auditability to enterprise AI agents
Drata has introduced AI Agent Governance, a new security category focused on managing the risks and oversight requirements of AI agents, while extending its trust platform to support enterprise adoption of autonomous AI systems.
June 10th, 2026 — Source

Election Systems Are Now a Persistent Cyber Target
Long Dwell Times and Persistent Footholds Are Redefining the Election Threat Model
June 10th, 2026 — Source or Source or Source or Source

EU rules on securing IT products could affect open source software users beginning this week
The EU's Cyber Resilience Act aims to make hardware and software more secure — but enterprises are still unaware of its implications for open-source software usage.
June 10th, 2026 — Source

Essential Cybersecurity Tools Every Developer Should Use in 2026
Security is no longer a concern you can hand off to a dedicated team at the end of a project. In 2026 developers are expected to think about security at every stage from writing the first line of code to deploying on a production framework.
June 10th, 2026 — Source

Every set of AI guardrails can be broken by the right prompt
Companies that build AI systems wrap them in guardrails meant to block harmful output, including deepfakes, malware, and instructions for making biological weapons or illicit drugs. When a user prompts the system for such content, the guardrails are designed to flag the request and refuse. A new mathematical proof sets a limit on how secure those guardrails can ever be.
June 10th, 2026 — Source

F5 adds AI-powered threat detection and API security for on-premises environments
F5 has introduced new web application and API protection (WAAP) capabilities for its Application Delivery and Security Platform. The company said the updates are intended to address a threat landscape in which AI models can accelerate the time between vulnerability discovery and exploitation, giving attackers faster access to offensive capabilities. The new features expand the AI-powered web application firewall (WAF) functionality in F5 Distributed Cloud Services.
June 10th, 2026 — Source

GitHub pulls pin on npm's auto-run scripts
Shai-Hulud worm exploited exactly this. Better late than never, says everyone except the malware authors
June 10th, 2026 — Source

Google Search knows where you live. Here's how to claw back some privacy
You probably can't disappear from Google completely, but you can make yourself much harder to find.
June 10th, 2026 — Source

ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact
In addition, Rockwell Automation announced some enhancements to its SecureOT cybersecurity solution for OT.
June 10th, 2026 — Source

Identity theft is turning into a chain reaction for victims
More than one in four people who contacted the Identity Theft Resource Center during the reporting period were dealing with multiple identity-related incidents, according to the organization's 2026 Trends in Identity Report.
June 10th, 2026 — Source

Infostealers Turn Millions of Devices Into Credential Theft Machines
As attackers increasingly favor stolen credentials over exploits, infostealers have become a primary source of access for ransomware and other cybercrime operations.
June 10th, 2026 — Source

Ivanti tells Sentry customers to patch now as critical bugs hit 10.0 and 9.9
Remote, unauthenticated RCE with root privileges is about as bad as it gets
June 10th, 2026 — Source

Microsoft patches Exchange Server zero-day exploited in attacks
Microsoft has patched an actively exploited Exchange Server vulnerability that allows threat actors to execute arbitrary JavaScript code in cross-site scripting (XSS) attacks targeting Outlook Web Access users.
June 10th, 2026 — Source

Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days
On Tuesday, Microsoft patched two zero-day vulnerabilities that let attackers gain SYSTEM privileges on fully patched Windows systems, and a third one that grants access to BitLocker-protected drives.
June 10th, 2026 — Source

Microsoft releases KB5094127 Extended Security Update for Windows 10 -- and it's causing problems
For anyone who has decided to stick with Windows 10 and has signed up for the Extended Security Updates program, Microsoft has released the KB5094127 update.
June 10th, 2026 — Source

Microsoft's June 2026 Patch Tuesday Smashes Record With Over 200 Security Fixes
Another month, another Patch Tuesday for Windows users. This one's a bit bigger than usual, though: Microsoft has released a record-breaking Windows 11 patch addressing a whopping 206 vulnerabilities. The former record-holder was this past October's Patch Tuesday, which fixed 175 vulnerabilities.
June 10th, 2026 — Source

New Browser-in-the-Browser phishing uses fake login popups to steal Microsoft 365 credentials
A new Browser-in-the-Browser (BitB) phishing campaign is targeting Microsoft 365 users with fake login popups designed to closely mimic legitimate browser authentication windows, according to Palo Alto Networks Unit 42.
June 10th, 2026 — Source

New Intel 471 assessment helps organizations measure CTI program maturity
Intel 471 has announced its new Cyber Threat Intelligence (CTI) Maturity Pulse Check, a free, lightweight self-assessment for practitioners based on the Cyber Threat Intelligence Capability Maturity Model (CTI-CMM v1.3).
June 10th, 2026 — Source

New Windows Zero-Day Exploit 'RoguePlanet' Released
Exploiting a race condition in Microsoft Defender, the exploit leads to local privilege escalation to SYSTEM.
June 10th, 2026 — Source

Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks
Oracle PeopleSoft servers are being targeted in ongoing data theft attacks by the ShinyHunters extortion gang, which claims to have stolen data from over 100 organizations.
June 10th, 2026 — Source

Record Microsoft Patch Tuesday, fresh zero-day
Microsoft marked its largest-ever Patch Tuesday this month, by shipping fixes for nearly 200 vulnerabilities.
June 10th, 2026 — Source

Rubrik launches Autonomous Business Recovery to rebuild cloud applications after cyberattacks
Rubrik has unveiled Autonomous Business Recovery (ABR) for Cloud Applications, the agentic cyber resilience solution that recovers cloud applications from data to network, identity and configurations. The end result is a rebuild of an organization's Minimum Viable Business (MVB) at machine speed.
June 10th, 2026 — Source

Scam Calls Have Gotten Out of Control. This One Strategy Actually Helps
Scam calls are smarter and more frequent than ever, but one targeted strategy can keep most of them from ever reaching you.
June 10th, 2026 — Source

ServiceNow Patches Vulnerability Exploited Against Some Customers
The company updated hosted customer instances to patch a security issue it reportedly had known about since April 7.
June 10th, 2026 — Source

Signal attacks UK plan to scan devices for nude images as "mass surveillance"
The UK says tech firms could face fines if they fail to adopt stronger protections for children
June 10th, 2026 — Source

The 5 Best Practices for Secure Identity Verification
The challenge for security teams has evolved from simply verifying identities to verifying them securely without creating friction for legitimate users. Weak onboarding processes, overreliance on static credentials, and inconsistent authentication policies all create opportunities for attackers to exploit.
June 10th, 2026 — Source

Windows Secure Boot deadline won't brick your PC, but don't ignore it
Microsoft clarifies the June 24 Secure Boot deadline isn't a hard cutoff. Here's what you should do before October.
June 10th, 2026 — Source

Your face is the ticket: Google's Gemini and biometric gates are the World Cup's quieter tech story
Two layers are rolling out across the 16 host cities: consumer AI from Google, and biometrics that turn a fan's face into a ticket. Both are aimed at fans, and both will outlast the tournament.
June 10th, 2026 — Source

Internet — Security Issues — June 8th, 2026

174,000 Impacted by Lansing Community College Data Breach
Hackers accessed personal information stored on certain Lansing Community College systems in February 2025.
June 8th, 2026 — Source

A Qilin ransomware affiliate exploited a Check Point VPN zero-day for a month before a patch existed
CVE-2026-50751 bypasses authentication on VPN gateways using the deprecated IKEv1 protocol, and the attackers are also hitting Palo Alto, Fortinet, and F5
June 8th, 2026 — Source

A Security Raises $37 Million for Autonomous Offensive Security Platform
The company founded by Yossi Torati, Omer Gull, and Yuval Itzchakov has emerged from stealth mode.
June 8th, 2026 — Source

AI Exploit Risks Pushing Healthcare Security Shift
MultiCare Health CISO Jason Elrod on Need for Faster Cyber Resilience
June 8th, 2026 — Source

AI-Powered Toys Spark Privacy Concerns in Australia
AI toys are finding their way into Australian homes and schools, raising new concerns about how children's data and safety are protected.
June 8th, 2026 — Source

Anthropic Calls for Pause on Frontier AI Development
Era of Self-Replicating AI Is Coming, Firm Says
June 8th, 2026 — Source or Source or Source or Source

Anthropic Urges Industry Coordination to Allow for a 'Pause' in AI Development if Risks Grow
The proposed coordination would let advanced AI labs verify that global rivals have actually stopped or slowed their work.
June 8th, 2026 — Source

Artificial Intelligence-Driven Phishing: How Phishing Technique Is Evolving and Implemented
The Microsoft Digital Defense Report 2025 provides an updated overview of the phishing landscape, marked by a significant increase in both the scale and efficiency of attacks in recent years. This phenomenon is largely attributable to the capabilities provided by artificial intelligence.
June 8th, 2026 — Source

Blockchain framework could curb credential fraud in online degrees, tests suggest
The researchers explain that these platforms usually rely on a single administrative infrastructure for authentication, records and content delivery. This, they suggest, creates a single point of failure, where disruption or compromise of the central system might affect the entire environment. This could open up the possibility of data tampering, credential fraud and unauthorized access, while undermining trust in online degrees.
June 8th, 2026 — Source

Check Point links VPN zero-day attacks to Qilin ransomware gang
Israeli cybersecurity company Check Point has released security updates to patch a critical flaw affecting Remote Access VPN and Mobile Access deployments, which was exploited in zero-day attacks.
June 8th, 2026 — Source

CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318)
A vulnerability (CVE-2026-28318) that can be exploited to crash SolarWinds Serv-U file transfer servers is being leveraged by attackers in the wild, the US Cybersecurity and Infrastructure Security Agency (CISA) confirmed on Friday.
June 8th, 2026 — Source

ConnectSecure's Patch 360 gives MSPs control over patch testing and deployment
ConnectSecure has announced the launch of Patch 360, a patch management solution built for managed service providers (MSPs) to reduce deployment risk while accelerating vulnerability remediation.
June 8th, 2026 — Source

Critical UniFi OS bug lets hackers gain root without authentication
Attackers can chain three already fixed vulnerabilities in the Ubiquiti UniFi OS server to execute remote code with root privileges and without authentication.
June 8th, 2026 — Source

Cybersecurity M&A Roundup: 26 Deals Announced in May 2026
Significant cybersecurity M&A deals announced by Akamai, Check Point, Cisco, Cyera, Dragos, WatchGuard and Zscaler.
June 8th, 2026 — Source

Edge's Master Password is gone. Your face now protects your passwords
Microsoft killed Edge's Master Password feature on June 4th. Now Windows Hello is the only way to protect your saved passwords and auto-fills.
June 8th, 2026 — Source

Everest Forms Vulnerability Exploited to Hack WordPress Sites
The flaw allows attackers to execute arbitrary code remotely and has been exploited in the wild for two months.
June 8th, 2026 — Source

Everybody Is Vibe Coding But Nobody Told the Security Team
AI-driven development is not something organizations can or should block. But it must be governed.
June 8th, 2026 — Source

For the 2nd time in weeks, Microsoft packages laced with credential stealer
73 packages run self-replicating stealer as soon as they're opened by an AI agent.
June 8th, 2026 — Source

Four suspects identified in Finland undersea cable damage investigation — criminal case referred to prosecutors for consideration of charges
It's the second Finnish anchor-drag incident to reach prosecution.
June 8th, 2026 — Source

From Verizon to Apple, a hidden texting flaw has finally been patched
A major security vulnerability that allows attackers to easily fake their identity in smartphone text conversations has been fixed in the United States thanks to a team of computer scientists at the University of California San Diego. The vulnerability affected both Android and Apple smartphones as well as all major wireless carriers, including Verizon, T-Mobile and Google Fi, and smaller independent operators such as Mint Mobile.
June 8th, 2026 — Source

Gogs patches critical zero-day enabling remote code execution
Gogs has patched a critical security zero-day flaw that can allow attackers to compromise Internet-facing instances and access any repositories (including private ones).
June 8th, 2026 — Source

Hackers likely hijacked over 20,000 Instagram accounts with Meta's AI chatbot
Meta blames a bug on an exploit that allowed hackers to ask its AI support bot to link a victim's account with their own email.
June 8th, 2026 — Source

Hackers used Meta's AI support system to hijack over 20,000 Instagram accounts
Meta has revealed that attackers hijacked 20,225 Instagram accounts by exploiting a flaw in the company's AI-assisted account recovery system.
June 8th, 2026 — Source

How I Built a 47-Signal Website Audit Tool That Runs in 15 Seconds
Every time I needed a complete picture of a site's health, I would open an SEO scanner, then a security checker, then an AEO validator, then something else for GEO signals. Each tool gave me a slice. None of them talked to each other. And the gaps between those slices were exactly where the real problems lived.
June 8th, 2026 — Source

How sex workers are protecting their digital futures — and yours
From Sheri's Ranch in Nevada to Australia, adult workers are fighting for online safety.
June 8th, 2026 — Source

GitHub nukes 70+ Microsoft repos, breaks CI/CD pipelines, following suspected worm infections
Miasma worm shapeshifts, but cloud secret-scouting remains the goal
June 8th, 2026 — Source

Massachusetts votes to pass new privacy rights bill that bans sale of precise location data
Massachusetts lawmakers have voted to pass privacy protections that grant the state's residents new rights over accessing and deleting their data held by big tech giants. The bill also bans companies from selling their users' precise location data.
June 8th, 2026 — Source

Meta claims NSO Group still targets WhatsApp users despite court order
Meta claims it disrupted spear-phishing attempts linked to NSO Group and is asking a US federal court to hold the spyware vendor in contempt for allegedly violating an injunction that bars it from targeting WhatsApp and its users.
June 8th, 2026 — Source

Meta is dragging NSO back to court, saying the spyware firm never stopped targeting WhatsApp
A year after winning a permanent injunction against the maker of Pegasus, Meta says it has foiled fresh NSO phishing attacks and is filing for contempt.
June 8th, 2026 — Source

Miasma Worm Hits Microsoft's AI Coding Ecosystem
Attackers Compromised More Than 70 Microsoft Repositories in Under 2 Minutes
June 8th, 2026 — Source or Source

Microsoft changes how Defender for Endpoint EDR updates are delivered on Windows
Microsoft will distribute Defender for Endpoint EDR updates through Microsoft Update, enabling EDR security improvements to be released independently of monthly Windows operating system updates.
June 8th, 2026 — Source

Microsoft making much needed change to Windows 11, 10 Patch Tuesday security updates
Microsoft will deliver Defender EDR updates via Microsoft Update, enabling faster security improvements independent of Windows patches.
June 8th, 2026 — Source

Microsoft's open source tools were hacked to steal passwords of AI developers
Microsoft has cut off access to dozens of its open source projects hosted on GitHub as it investigates how hackers apparently breached the projects and injected password-stealing malware into the code.
June 8th, 2026 — Source

Minimus Expands Enterprise Security Platform with General Availability of Advanced Supply Chain Controls
This article was provided by TechnologyWire and does not represent the editorial content of DZone.
June 8th, 2026 — Source or Source

New Relic expands observability into AI-assisted software development
New Relic has announced AI Coding Observability, an open-source tool for monitoring AI-assisted software development workflows. As organizations adopt AI coding assistants, these tools often operate outside existing observability systems, limiting visibility into their use. AI Coding Observability extends monitoring into the software development process, enabling organizations to track, analyze, and audit AI-assisted coding activities.
June 8th, 2026 — Source

New Shai-Hulud attack trojanizes 19 science-focused PyPI packages
Hackers compromised 19 packages on the PyPI, collectively downloaded hundreds of thousands of times, in a new Shai-Hulud supply-chain attack that delivered malware designed to steal developer secrets.
June 8th, 2026 — Source

NSO Group back in Meta's crosshairs after alleged WhatsApp targeting
Zuckercorp says surveillance-for-hire vendor was still running phishing operations after federal court told it to knock it off
June 8th, 2026 — Source

OpenAI is locking down parts of ChatGPT to reduce data theft risks
OpenAI has started rolling out Lockdown Mode for ChatGPT, an optional security setting that restricts access to external resources and several product capabilities. It is available for personal accounts, including Free, Go, Plus, and Pro plans, as well as self-serve ChatGPT Business accounts.
June 8th, 2026 — Source

OpenAI Rolling Out ChatGPT Account Security Controls
The Active Sessions and Lockdown Mode features are being made more broadly available by the AI giant.
June 8th, 2026 — Source

Oxford University discloses data breach after careers platform hack
The University of Oxford disclosed a new data breach last week after being informed by its third-party provider, Group GTI, that its CareerConnect career services platform had been compromised.
June 8th, 2026 — Source

Qilin ransomware affiliate exploited Check Point VPN zero-day (CVE-2026-50751)
A Qilin ransomware affiliate is believed to be exploiting CVE-2026-50751, an authentication bypass vulnerability in Check Point VPN Remote Access and Mobile Access, the company announced on Monday.
June 8th, 2026 — Source

Pinterest Uses Content Fingerprints for URL Deduplication across Millions of Domains
Pinterest Uses Content Fingerprints for URL Deduplication across Millions of Domains
June 8th, 2026 — Source

Post-Quantum Prep Should Start Now, Says German State
It May Already Be Too Late, Says Athene
June 8th, 2026 — Source or Source or Source or Source

Protocol Buffers schemas expose remote code execution risk
Researchers at Cyera found six vulnerabilities in protobuf.js, including a flaw that can turn attacker-controlled schema data into executable code and expose downstream software supply chains.
June 8th, 2026 — Source

Ransomware crims got a month-long head start on Check Point VPN 0-day that now has a fix
Scumbags, including a Qilin ransomware affiliate, began hitting this hole May 7
June 8th, 2026 — Source

Ransomware sends Illinois high school on an early summer vacation
Meanwhile, 13 schools in Wales affected by separate attack
June 8th, 2026 — Source

Reducing security operations complexity with Wazuh Cloud
Security teams today manage increasingly complex environments in which threats such as ransomware, advanced persistent threats, and supply chain attacks evolve rapidly. Organizations operate hybrid infrastructures spanning on-premises systems, multi-cloud platforms, containers, and Kubernetes clusters, all while navigating strict compliance requirements from frameworks including PCI DSS, HIPAA, GDPR, NIST 800-53, and CIS Benchmarks.
June 8th, 2026 — Source

RidgeBot 7.0 automates Active Directory attack simulations for security validation
RidgeBot 7.0 automates Active Directory attack simulations for security validation
June 8th, 2026 — Source

Samsung just made Galaxy phones more secure in One UI 9 beta
Samsung's One UI 9 beta integrates Lockdown mode into the power menu. This is the screen that contains Power off, Restart, and emergency options. Opening it initiates Lockdown mode, disabling biometric authentication.
June 8th, 2026 — Source

Secondary silylium ion drives one-pot ketone sulfonamidation, reaching 95% yields
A research team has developed a novel organocatalysis method based on a silylium Lewis acid. This technology employs an ion-pair catalyst combining a diethylsilylium ion with a weakly coordinating anion, enabling the direct installation of sulfonamide groups into functionalized ketone compounds, including &beta-ketoesters, which had previously been difficult to react using conventional catalytic methods.
June 8th, 2026 — Source

Silent Ransom Group Uses DNS Fast Flux in Attacks
Focusing on hacking law firms in the US, the ransomware group relies on fast flux to hide its C&C infrastructure.
June 8th, 2026 — Source

Social media accounts uncover how fake jobs trap people in cross-border scam compounds
Under the pretext of employment prospects, hundreds of thousands of job seekers are lured by scammers to cross the border into countries such as Myanmar, Laos or Cambodia. Instead of the promised lucrative positions, they are forced to work long hours in heavily guarded scam compounds, facing strict quotas and violence as punishment. Their main task is to fabricate online identities and defraud people, for example by operating "pig-butchering" scams, in which they introduce fraudulent investment schemes after establishing romantic relationships with random targets online.
June 8th, 2026 — Source

SolarWinds Serv-U Vulnerability Exploited in the Wild
Unauthenticated attackers can exploit the flaw via specially crafted POST requests that crash the Serv-U service.
June 8th, 2026 — Source

Supply Chain Attack Hits Microsoft GitHub Repos, AI Coding Tools
GitHub disabled 73 Microsoft repositories on June 5 after a malicious commit landed in an Azure project, in what researchers described as a supply chain attack aimed at developer workstations and AI coding environments.
June 8th, 2026 — Source

System designed to detect and track potential attacks on electric vehicle charging stations
The increasing adoption of electric vehicles is creating growing demand for charging infrastructure, driving a transformation in access to and use of energy through the controlled deployment of fast, efficient and secure charging stations.
June 8th, 2026 — Source

The wake-up call: How a secret 2025 meeting forced Apple to finally begin trying to catch up in AI
In early 2025, a group of Apple's top executives gathered in a conference room — without Tim Cook — and confronted a harsh reality: the company was dangerously behind in the AI race. That closed-door meeting sparked a dramatic turnaround, reshuffling leadership on Siri, pulling Cook deeper into the fray, and setting the stage for one of the most significant software overhauls in Apple's history.
June 8th, 2026 — Source

These fake World Cup websites are here to scam you
Here's how to avoid getting tricked.
June 8th, 2026 — Source

WhatsApp Catches Spyware Firm NSO Defying No-Hacking Court Order
The Meta-owned communications app is filing a federal court contempt order against NSO.
June 8th, 2026 — Source

WhatsApp says it disrupted new NSO spyware phishing attacks
WhatsApp has detected and stopped spear-phishing campaigns allegedly conducted by the NSO Group after investigating user reports of social engineering attacks.
June 8th, 2026 — Source

Why AI Is Making Malware Harder to Detect
Ray Canzanese of Netskope Threat Labs on AI-Generated Threats and Supply Chain Risk
June 8th, 2026 — Source

Why Tool Count Is the Wrong Security Metric
CybaVerse's Oliver Spence on Matching Tools to Business Outcomes
June 8th, 2026 — Source or Source or Source or Source

Internet — Security Issues — June 7th, 2026

C0XMO botnet spreads via DD-WRT router flaw, kills rival malware
A new variant of the Gafgyt botnet called C0XMO is targeting DD-WRT router firmware and can move to other device types with various CPU architectures.
June 7th, 2026 — Source

Emphere Raises $2.1 Million for AI-Powered Vulnerability Remediation
Emphere's solution delivers AI-driven remediation to software companies to speed up releases.
June 7th, 2026 — Source

Hacked, leaked, and held for ransom: The worst breaches of 2026 so far
If anything, 2026 has made clear that cybersecurity is no longer a background concern — it's front and center, woven into almost every major story of the year. Yes, wars are still raging, the climate keeps worsening, and we're seemingly one dodgy sneeze away from the next global pandemic.
June 7th, 2026 — Source

Signal, DuckDuckGo, and NordVPN threaten to exit Canada if metadata surveillance law passes
Canada's metadata retention bill is the latest government attempt to build surveillance into the internet's infrastructure
June 7th, 2026 — Source

Silent Ransom Group targets law firms with fake IT support calls
The Silent Ransom Group extortion gang is actively targeting U.S. law firms and professional services organizations in social engineering attacks that often lead to data theft within hours of initial contact, according to a new report by cybersecurity firm Mandiant.
June 7th, 2026 — Source

The Delivery You Didn't Order: Breaking Down the 'Free Phone' Scam
If a phone you didn't order arrives on your doorstep, there's a good chance someone's trying to scam you. Here's how to recognize this scam and make sure you don't get tricked.
June 7th, 2026 — Source

Week in review: Cisco SD-WAN 0-day exploited, Patch Tuesday forecast
Here's an overview of some of last week's most interesting news, articles, interviews and videos:
June 7th, 2026 — Source

Why Autonomous Robot Dogs Are Becoming a National Security Threat
Autonomous robot dogs are rapidly becoming a fixture in industries ranging from law enforcement to private security, but their rise comes with serious concerns. Benn Jordan examines how these machines, while technologically impressive, suffer from critical flaws that challenge their reliability and safety. For instance, many models struggle with basic tasks like navigating uneven terrain or carrying heavy loads, limiting their effectiveness in real-world scenarios. Compounding these issues are significant cybersecurity vulnerabilities, such as weak authentication protocols, which leave robot dogs susceptible to hacking and misuse.
June 7th, 2026 — Source

Internet — Security Issues — June 6th, 2026

Critical Everest Forms Pro flaw exploited to take over WordPress sites
Hackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro plugin, which lets them take complete control of a WordPress website.
June 6th, 2026 — Source

Finland deploys new system to detect threats to undersea cables — distributed acoustic sensors measure vibrations from the seabed and informs the authorities and operators of suspicious activities
This tech allows undersea cables to act as sonar sensors.
June 6th, 2026 — Source

Former IBM cybersecurity exec accuses company of covering up years of Chinese hacking
A newly unsealed lawsuit alleges IBM knew its network was breached more than 56,000 times by a Chinese state-linked group and told no one
June 6th, 2026 — Source

Gaming soundbar can be hijacked from over 16 yards away without touch or pairing — the company allegedly refuses to label the blatant security flaw a cybersecurity risk
It accepts unsigned firmware over an unauthenticated Bluetooth link.
June 6th, 2026 — Source

Google Chrome tests another massive change to Search that puts AI in front
The company's really pushing the limits of its search experience.
June 6th, 2026 — Source

Opal Security Raises $23 Million for AI-Native Identity Governance
Raising $59 million to date, Opal also announced five senior leadership appointments.
June 6th, 2026 — Source

Oxford Uni student data pwned yet again - this time via career platform breach
Totally different attack from the break-in last month. Oh so that's OK then
June 6th, 2026 — Source

Internet — Security Issues — June 5th, 2026

A Vulnerability in Cisco Products Could Allow for Server-Side Request Forgery
A vulnerability has been discovered in Cisco products that could allow for Server-Side Request Forgery. Cisco Unified Communications Manager (Unified CM) / Cisco Unified Communications Manager Session Management Edition (Unified CM SME) is Cisco's central, software-based call control and session management platform for enterprise communication.
June 5th, 2026 — Source

AI is helping low-skill hackers pull off advanced cyberattacks
Anthropic has published an analysis of cyber-related misuse of its AI systems, examining 832 accounts that were banned for malicious cyber activity between March 2025 and March 2026.
June 5th, 2026 — Source

Article Series: Securing the AI Stack: from Model to Production
AI has officially shifted from experimentation to production, outpacing legacy defenses and creating a volatile new security landscape. This challenge is defined by three critical frontiers: data poisoning, AI-driven phishing, and shadow cloud governance.
June 5th, 2026 — Source

Attackers obtained encrypted password vaults from some Dashlane user accounts
Dashlane has disclosed new details about a brute-force attack that let a threat actor access some customer accounts and copy encrypted vaults.
June 5th, 2026 — Source

Chrome 149 Patches 429 Vulnerabilities
Over 100 bugs are critical or high-severity, mainly use-after-free and insufficient validation of untrusted input flaws.
June 5th, 2026 — Source

Cisco SD-WAN 0-day exploited, no patch available (CVE-2026-20245)
A 0-day privilege escalation vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager that has yet to be patched by Cisco is being leveraged by attackers.
June 5th, 2026 — Source

Council in UK's City of York outs hundreds of disabled residents with a single email blunder
Blue Badge holders exposed to each other after BCC function proves too complex
June 5th, 2026 — Source

DentaQuest Cyberattack Tied to 2.6M Exposed Accounts
DentaQuest confirmed a cybersecurity incident after health data tied to 2.6 million accounts surfaced in a public breach listing.
June 5th, 2026 — Source

Ex-CISA CIO Breaks Down Trump's New AI Executive Order
Bob Costello on Voluntary Plan's Impact on Collaboration - and CISA's Pivotal Role
June 5th, 2026 — Source or Source or Source or Source

Five Eyes: Chinese Spies Target Government, Military Staff With Fake Job Opportunities
Posing as recruiters on online platforms, Chinese intelligence officers target personnel with access to classified or privileged information.
June 5th, 2026 — Source

Forget SEO: Spammers Push 'AI‑Engine Optimization' by Flooding Reddit to Shape AI Search
AI often mistakes Reddit posts for reliable sources.
June 5th, 2026 — Source

Google and FBI warn of ransomware group that sends fake IT workers to hack victims in person
A ransomware gang has escalated its attacks on law firms by sometimes sending fake IT workers in person to the victims' offices, where the imposters steal data directly from the victims' computers using USB drives or help other gang members connect to the computers remotely, according to Google and the FBI.
June 5th, 2026 — Source

Hackers Leak DentaQuest Information Impacting 2.6 Million
The ShinyHunters extortion group leaked roughly 234 GB of data allegedly stolen from the dental benefits administrator.
June 5th, 2026 — Source

How OpenAI Built a Secure Windows Sandbox for Codex Agents
OpenAI has published details of the Windows sandbox architecture that powers its Codex coding agent, highlighting the engineering tradeoffs required to balance security, usability, and developer productivity on Microsoft's operating system. The company explained that it built a custom sandboxing approach after finding that existing Windows isolation mechanisms did not fully satisfy the requirements of autonomous coding agents. As OpenAI noted, Windows does not provide a single primitive that cleanly maps to a safe execution environment for agentic workloads.
June 5th, 2026 — Source

In Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISA
Other noteworthy stories that might have slipped under the radar: Ultrahuman data leak, The Gentlemen ransomware analysis, Hola Browser bundles miner.
June 5th, 2026 — Source

Industry Reactions to New Trump AI Cybersecurity Executive Order: Feedback Friday
Experts commented on the EO's voluntary nature, the balance between innovation and security, and potential implementation gaps.
June 5th, 2026 — Source

ISMG Editors: Wrapping Up Infosecurity Europe 2026
Conference Highlights AI Maturity, Agentic Risks and Human Factors in Cybersecurity
June 5th, 2026 — Source or Source or Source or Source

Let's Encrypt works toward post-quantum certificates at web scale
Let's Encrypt plans to pursue a post-quantum-safe Web PKI through Merkle Tree Certificates (MTCs), a new approach that adds post-quantum authentication to the web without sacrificing the speed and reliability that have made TLS universal. The project is targeting late 2026 for a staging environment that issues MTCs, with a production-ready environment planned for 2027.
June 5th, 2026 — Source

Microsoft 365 Android Coding Error Put Account Tokens at Risk
A coding error in several Microsoft 365 Android apps could have allowed a malicious app on the same device to silently obtain account tokens and act as the signed-in user, according to new research from Enclave.
June 5th, 2026 — Source

Microsoft lists 15 new reasons to switch to the New Outlook but many users say it still isn't ready
Microsoft lists 15 new features shipping to the New Outlook, potentially making the jump from the Classic client sweeter.
June 5th, 2026 — Source

New CISA Warning: Hackers Are Targeting Fuel Tank Monitoring Systems
CISA warns attackers are targeting internet-exposed Automatic Tank Gauge systems used in fuel storage. Here's what operators should fix now.
June 5th, 2026 — Source

New WebAssembly memory layout could stop Heartbleed-style browser attacks with no visible slowdown
Google Earth, Zoom, Twitch.tv or Photoshop—thanks to the WebAssembly standard, many powerful applications now run directly in a browser without installation. However, some of these web apps have serious security vulnerabilities. Researchers from paluno—The Ruhr Institute for Software Technology at the University of Duisburg-Essen—have developed a solution to secure COTS applications by automatically reorganizing their memory.
June 5th, 2026 — Source

Nightclub Giant RCI Says Data Breach Affects 40,000 Individuals
The company detected a network intrusion in March and an investigation showed that some files were stolen during the attack.
June 5th, 2026 — Source

Outlook may have allowed unencrypted connections for decades, report claims — Fedora and Dovecot upgrade reveal protocol downgrade issue present since at least 2007
"Customers have likely been retrieving their emails in plaintext for over a decade, mistakenly believing encryption was enabled"
June 5th, 2026 — Source

Over 900 US gas station tank gauge systems exposed to attacks
Over 900 automatic tank gauge (ATG) systems across the United States, used to monitor fuel and chemical storage tanks across various critical infrastructure sectors, have been found exposed online and are vulnerable to ongoing attacks.
June 5th, 2026 — Source

Photos: Infosecurity Europe 2026
Infosecurity Europe 2026 is a cybersecurity event that took place from June 2 to 4 in London. Help Net Security was on-site and here's a closer look at the conference.
June 5th, 2026 — Source

Q&A: How organic glass scintillators could improve nuclear security
As the demand for nuclear security solutions grows, distinguishing a benign medical isotope from a potential threat is critical. Organic glass scintillators can help meet the need for accurate, cost-effective radiation detectors.
June 5th, 2026 — Source

Southeast Asia Scam Compounds Turn AI Into a Cybersecurity Threat
Scam compounds across Southeast Asia are using AI, malware, and automation to scale fraud, forcing APAC security teams to rethink phishing, identity, and mobile-risk controls.
June 5th, 2026 — Source

What 2026 DBIR Confirms: Attacks Are Living in the Browser
Every year, the Verizon Data Breach Investigations Report serves as a ground-truth benchmark for the industry. Its value comes not just from the headline numbers but from the convergence signals: when multiple independent data sources point to the same structural shift in how attackers operate, that convergence is worth paying attention to.
June 5th, 2026 — Source

World Food Programme breach exposes data of 600k vulnerable Gazan families
Those receiving aid in the famine-threatened, war-torn territory told support will remain
June 5th, 2026 — Source

Internet — Security Issues — May 30th, 2026

Exploit Code Published for Critical Flowise RCE Vulnerability
The one-click vulnerability allows attackers to execute arbitrary code on self-hosted Flowise servers by tricking users into importing a malicious chatflow.
May 30th, 2026 — Source

Meta's employee mouse tracking program could reportedly violate EU privacy laws
'Reuters' says the tracking tool could capture emails and chats by non-US employees.
May 30th, 2026 — Source

Microsoft is threatening legal action for disclosing exploits
The company is feuding with a security researcher publicly posting vulnerabilities.
May 30th, 2026 — Source

Microsoft threatened a security researcher with criminal prosecution. The cybersecurity community is furious.
The researcher says Microsoft revoked their vulnerability reporting account. Microsoft says publishing the bugs without coordination was irresponsible.
May 30th, 2026 — Source

Russian Spies Are Aggressively Seeking Western Technology as Sanctions Bite, Officials Say
Moscow's agents are building fake companies, recruiting middlemen and deploying cyber spies and hackers who gather information that could be used to attack key infrastructure.
May 30th, 2026 — Source

Yale's New Google-Friendly Smart Lock Makes a Great Security Starter. Here's Why
The new Matter-friendly Yale Smart Lock is especially great for Google Home users, but anyone will find it easy to get started.
May 30th, 2026 — Source

Internet — Security Issues — May 29th, 2026

A Complete Breakdown of the Claude Mythos 1 Leak and Features
The recent leak of Claude Mythos 1 has provided a rare look at Anthropic's advanced AI model, sparking discussions about its potential applications and implications. In a detailed hands-on review, World of AI examines the leaked outputs, including standout examples like solving Erdos Problem 90, a challenging geometry problem and generating a Python-based visualization titled Saturn spaceship pie art. These examples highlight the model's strengths in mathematical reasoning, creative problem-solving, and programming expertise, underscoring its potential to tackle complex, high-stakes challenges. Anthropic's cautious approach to a possible public release reflects its focus on safety, making sure that such capabilities are deployed responsibly.
May 29th, 2026 — Source

AI and ultralow-energy lasers enable an ultrafast authentication system
The security of modern communications heavily relies on systems that can rapidly and reliably verify users and the devices they are using. This process, known as authentication, essentially entails confirming that users or devices are legitimate (i.e., who or what they claim to be).
May 29th, 2026 — Source

Bluesky accounts hijacked in pro-Russia propaganda campaign
A Russian influence campaign hijacked hundreds of Bluesky accounts—many belonging to influential Americans—to spread propaganda, researchers said, in a striking disinformation tactic that weaponized authentic identities rather than relying on fake accounts.
May 29th, 2026 — Source

Anthropic launches Claude Opus 4.8, prepares Mythos-class models for all customers
Anthropic has released Claude Opus 4.8 and outlined plans for broader access to its Mythos-class models, which the company expects to make available to all customers in the coming weeks.
May 29th, 2026 — Source

California Sues 23andMe, Alleging It Failed to Protect User Data in 2023 Breach
Attorney General Rob Bonta filed the lawsuit against Chrome Holding Co., which 23andMe rebranded under after filing for bankruptcy last March.
May 29th, 2026 — Source

Charter Communications data breach affects 4.9 million accounts
The ShinyHunters extortion gang stole personal information from 4.9 million accounts after hacking the U.S. telecom giant Charter Communications in early April, according to data breach notification service Have I Been Pwned.
May 29th, 2026 — Source

ChatGPT blindly trusts browser content, turning the page into a payload
You and me go ChatGPhish-ing in the dark
May 29th, 2026 — Source

Chrome 148 Update Patches 151 Vulnerabilities
The browser update resolves critical-severity security defects that could potentially lead to remote code execution.
May 29th, 2026 — Source

Claroty targets cyber-physical system risks with AI-powered security agent
Claroty has launched Claroty Claire, a CPS-native AI security agent designed to help organizations defend mission-critical infrastructure. Claire is powered by a CPS language model trained on more than a decade of industry expertise and CPS-related data. The launch expands organizations' capabilities for supporting the safety, uptime, and availability of cyber-physical systems.
May 29th, 2026 — Source

Dutch cops wrest 17M devices from mystery botnet's clutches
Hosting provider pulled the plug after police traced 200 servers to the Netherlands
May 29th, 2026 — Source

Dutch govt disrupts malware botnet with 17 million infected devices
Dutch authorities have taken offline a massive botnet of 17 million devices and seized more than 200 servers at a local provider that supported the operation.
May 29th, 2026 — Source

Dutch police disrupts botnet composed of 17 million devices
The Dutch National Police and the country's National Cyber Security Center (NCSC) have taken offline 200 servers controlling a botnet of 17 million devices, the law enforcement agency announced on Thursday.
May 29th, 2026 — Source

From $5 Attacks to Botnet-Powered Platforms: Inside the DDoS-as-a- Service Market
You have probably experienced the following scenario yourself. A website suddenly stops loading, a login page times out, or an online service becomes unreachable at the worst possible moment. Sometimes the cause is not an internal outage, but a Distributed Denial-of-Service (DDoS) attack designed to overwhelm the service from the outside.
May 29th, 2026 — Source

Gogs Zero-Day Exposes Servers to Remote Code Execution
The critical-severity issue, assigned a CVSS score of 9.4, is an argument injection flaw that can be exploited by authenticated attackers via pull requests with malicious branch names.
May 29th, 2026 — Source

Humanix expands detection to identify live violations of security procedures
Humanix has announced a capability to identify live violations of organization-defined procedures governing IT support workflows. Designed to prevent unauthorized access, these procedures typically require help desk and service desk agents to follow identity verification steps before fulfilling sensitive requests, such as credential resets. Attackers have learned that pressuring agents to bypass these safeguards is among the fastest paths to a breach.
May 29th, 2026 — Source

LinkedIn-themed phishing abuses Adobe's A/B testing platform
A newly documented phishing campaign is targeting professionals with fake LinkedIn business emails and abusing a trusted service operated by Adobe.
May 29th, 2026 — Source

Man sent to prison for selling data of 7 millions elderly Americans
07.13.2013
May 29th, 2026 — Source

Microsoft 365 Copilot redesign brings context and actions into one workspace
Microsoft 365 Copilot, an AI assistant that helps people write, summarize, analyze information, and complete work tasks, has been redesigned. It now serves as a single, flexible entry point to Copilot across Microsoft 365 apps, suggesting relevant actions based on the user's work.
May 29th, 2026 — Source

Microsoft quietly removes a blog post claiming Windows 11 offers sufficient security
Microsoft recently made a pretty bold claim in saying that the security tools built into Windows 11 are enough to keep users protected. It was back in January that the company used an article in the Windows Learning Center to talk about the built-in security provided by Microsoft Defender Antivirus.
May 29th, 2026 — Source

Microsoft warns GPU mining malware is being spread to users through SEO poisoning and AI chatbots — cryptojacking campaign targets gamers and high-end PC users with downloads disguised as popular PC utilities
Malware avoids detention by monitoring GPU usage and shutting down during heavy activity
May 29th, 2026 — Source

MokN Raises $15 Million for Phish-Back Platform
MokN's platform deploys realistic decoy access points to lure attackers into revealing compromised credentials, enabling organizations to respond before abuse occurs.
May 29th, 2026 — Source

Netskope extends data localization capabilities with NewEdge updates
Netskope has enhanced its NewEdge Network infrastructure, expanding data sovereignty capabilities to more regions than any other SASE cloud provider.
May 29th, 2026 — Source

New infostealer reaches enterprise devices through FortiClient EMS vulnerability
Attackers are delivering a broad-spectrum infostealer to enterprise computers by exploiting a known vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS).
May 29th, 2026 — Source

Research investigation shows 'bossware' is spying on workers and sharing their data
A new investigation finds that workplace monitoring platforms are systematically sharing personal data about workers and online activity with hundreds of outside data brokers and big tech companies in ways that are not clearly disclosed and that, in some cases, may contradict the platforms' own privacy policies.
May 29th, 2026 — Source

Russia-linked threat group put ChatGPT to work from lure to payload
Researchers say 'GREYVIBE' crew used AI tools throughout a campaign targeting Ukrainian military and government
May 29th, 2026 — Source

ShinyHunters adds Charter to trophy shelf after 4.9M customer records leak
Telco giant says no sensitive data was taken, though names, addresses, phones, and emails are now out there
May 29th, 2026 — Source

This chip startup just raised $135M on a bet that AI's biggest bottleneck isn't compute — it's memory
Every time you ask ChatGPT a question, your request triggers a data relay race. Information leaves memory, passes through a CPU for preprocessing, travels to a GPU for heavy computation, and then makes its way back — and that entire journey repeats for every single word the AI generates.
May 29th, 2026 — Source

US charges Google security engineer with Polymarket insider trading
A Google security engineer was charged with insider trading after winning $1.2 million using confidential company data to place bets on the cryptocurrency-based Polymarket decentralized prediction market.
May 29th, 2026 — Source

Websites Can Now Peek at Your SSD to See What Else You're Up To
So far, this looks more practical in lab conditions than in the real world.
May 29th, 2026 — Source

Websites can spy on user activity by analyzing SSD behavior
Websites have spent years collecting information about visitors through browser fingerprinting, tracking scripts, and other techniques designed to identify devices and monitor behavior. Researchers have demonstrated another method that relies on something most users would never expect a website to observe: activity on their SSD (Solid-State Drive), the storage device where applications and files are stored.
May 29th, 2026 — Source

Internet — Security Issues — May 28th, 2026

A single typo could derail your World Cup plans
Cybercriminals are spoofing Federation Internationale de Football Association (FIFA) websites ahead of the 2026 FIFA World Cup, the FBI warns.
May 28th, 2026 — Source

AI Agents Are the New Insiders
Rethinking Insider Threats in the Age of Autonomous Systems
May 28th, 2026 — Source or Source or Source or Source

AI Agents Present Massive New Attack Surface
With Great Capabilities Comes Great Risk
May 28th, 2026 — Source or Source or Source or Source

Best Windows Antivirus 2026: Keep Your Devices Safe With These Anti-Malware Tools
We've tested top antivirus solutions -- and their accompanying digital security tools -- to help you find the best cybersecurity suite for your needs.
May 28th, 2026 — Source

Carnival confirms ShinyHunters cruised off with 6M customer records after April breach
Travel and leisure giant was just one of many victims of the cybercrooks' crime spree this year
May 28th, 2026 — Source

Carnival Cruise confirms data breach affecting nearly 6 million people
Carnival Corporation, the world's largest cruise line operator, has confirmed a data breach affecting nearly 6 million people claimed by the ShinyHunters extortion gang in April 2026.
May 28th, 2026 — Source

Carnival Data Breach Exposed 6 Million People
Data breach leaves nearly 6 million Carnival customers navigating identity theft risks.
May 28th, 2026 — Source

Checksum introduces Continuous Quality Agent for automated test generation and healing
Checksum has launched its Continuous Quality Agent, an autonomous system that runs nightly against deployed applications and automatically heals broken tests without waiting for an engineer to open a dashboard or write a prompt.
May 28th, 2026 — Source

Company CEO flooded file share with smut, called for help after he deleted it
Also, missing school iPad resurfaced after coach's kids uploaded video to YouTube
May 28th, 2026 — Source

Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks
Fortinet rolled out hotfixes for the security defect in April, warning that it had been exploited in the wild as a zero-day and urging immediate patching.
May 28th, 2026 — Source

Cryptohack Roundup: US Sanctions Hit Sinaloa Cartel Networks
Every week, ISMG rounds up cybersecurity incidents in digital assets. This week, the U.S. sanctioned Sinaloa Cartel-linked networks, the U.K. sanctioned a HTX-linked entity, Syndicate Labs shuttered, Missouri sued CoinFlip, Verus attacker took a bounty deal, StablR was exploited and malicious packages targeted crypto developer systems.
May 28th, 2026 — Source or Source or Source or Source or Source

Cybercriminals sail away with data from 6 million Carnival customers
Carnival Corporation, one of the world's largest cruise operators, confirmed a data breach weeks after the ShinyHunters hacking group claimed it had stolen millions of customer records.
May 28th, 2026 — Source

Detecting Advanced Persistent Threats Using Behavioral Analytics and Log Correlation
Behavior is the signal, correlation is the proof. Adaptive baselines plus time-windowed cross-plane correlation are limited by log quality, not model sophistication.
May 28th, 2026 — Source

Digimarc adds provenance, audit, and verification controls for AI agent workflows
Digimarc has announced new provenance and verification infrastructure designed to secure autonomous and AI-enabled workflows.
May 28th, 2026 — Source

FBI Urges Microsoft 365 Defenders To Watch for Kali365 Phishing Attacks
Quantum Unbreakable Breakthrough: 'Perfect Randomness' Could Revolutionize Data Encryption
May 28th, 2026 — Source or Source

Financial services firms have slowest response to cyberattacks despite being a prime target
A new report finds that 93 percent of financial services firms have been hit by a cyberattack, yet the sector continues to face the slowest response times of any critical industry.
May 28th, 2026 — Source

Gitea Vulnerability Exposed 30,000 Deployments to Attacks
The security flaw allowed attackers to pull private container images, exposing source code, credentials, and infrastructure.
May 28th, 2026 — Source

Google Unveils AI Threat Defense Platform to Fight AI-Powered Cyberattacks
New AI Threat Defense platform combines capabilities from Mandiant, Wiz and Gemini to help customers fight AI with AI.
May 28th, 2026 — Source

How Deno's New Firewall Stops AI Agents from Leaking Passwords
Deno has officially open-sourced Claw Patrol, a firewall designed to enhance the security of AI agents interacting with external systems. This framework addresses key challenges such as credential protection, action control, and real-time activity monitoring. By functioning as a gateway server, Claw Patrol ensures sensitive data like API keys and database passwords are securely managed while allowing developers to define strict rules for agent actions.
May 28th, 2026 — Source

How SIEM helps MSPs reduce noise and stop threats faster
MSPs are flooded with security alerts every day, yet many still struggle to separate operational noise from the threats that actually put customers at risk.
May 28th, 2026 — Source

"I have proof for every single word": This security researcher's GitHub and Microsoft accounts were deleted after claiming a Windows 11 exploit in BitLocker is by design
Microsoft seemingly bans a security researcher from GitHub, sparking threats of retaliation and a bug bounty controversy.
May 28th, 2026 — Source

IBM and Red Hat are betting $5 billion that open source needs a security guard
IBM and Red Hat announced Project Lightwell, a $5 billion commitment backed by new frontier AI capabilities and a global force of more than 20,000 engineers to help enterprises secure open source software. Together, these investments establish a new model for enterprise use of open source software, from upstream development through production environments.
May 28th, 2026 — Source or Source or Source

Ketch brings multi-agent AI orchestration to enterprise privacy programs
Ketch has unveiled its vision for agentic privacy with the Ketch Agent Network, a multi-agent orchestration layer for enterprise privacy programs. The platform is designed to continuously reason across legal obligations, internal policies, and operational realities within a unified AI-driven system.
May 28th, 2026 — Source

Microsoft is finally bringing All Accounts view to Outlook on Windows
The latest Microsoft 365 Roadmap entry says that Microsoft is finally bringing the All Accounts view to Outlook on Windows and the web.
May 28th, 2026 — Source

Microsoft's Copilot trust test: Zero findings, more models, wider oversight
Microsoft 365 Copilot and Copilot Chat (Copilot) have been recertified under ISO/IEC 42001:2023 by an independent auditor for the second consecutive year. Copilot first received ISO 42001 certification in March 2025. This year's recertification recorded zero non-conformities and zero improvement observations, resulting in a second audit in a row.
May 28th, 2026 — Source

Microsoft's new cloud PCs place AI agents under enterprise controls
Microsoft's Windows 365 for Agents, a cloud PC platform for agentic workloads, runs AI agents in secure environments. Organizations can direct agents with natural language to interact with applications, browsers, files, and enterprise systems. The platform is available in public preview.
May 28th, 2026 — Source

New BTMOB Android Malware Enables Full Device Takeover
Delivered via phishing lures, the malware combines financial theft with data exfiltration and remote access.
May 28th, 2026 — Source

New Edamame Platform Aims to Catch AI Coding Agents Going Off the Rails
New Edamame Platform Aims to Catch AI Coding Agents Going Off the Rails
May 28th, 2026 — Source

New Gogs zero-day flaw lets hackers get remote code execution
An unpatched zero-day vulnerability in the Gogs self-hosted Git service can allow attackers to gain remote code execution (RCE) on Internet-facing instances.
May 28th, 2026 — Source

Oil shipments, drone makers, and a poisoned code library targeted in recent APT campaigns
Geopolitical pressure drove much of the state-sponsored cyber activity recorded between October 2025 and March 2026, according to ESET's latest APT Activity Report. Espionage groups aligned with China, North Korea, Russia, and Iran adjusted their targets to match the economic and security concerns of their governments.
May 28th, 2026 — Source

Qevlar's new AI agents correlate CVEs, incident data, and active exploitation signals
Qevlar has announced a new set of AI agents designed to bridge the disconnect between Security Operations Centers (SOCs) and vulnerability management teams. The new capabilities help security teams correlate CVEs with live incident data for real-time risk prioritization, automatically identify asset owners to speed remediation, and autonomously hunt for active CVE exploitation. General availability is scheduled for Fall 2026.
May 28th, 2026 — Source

Quantum Unbreakable Breakthrough: 'Perfect Randomness' Could Revolutionize Data Encryption
The problem with most existing encryption methods is that since they are bound to machines reliant on binary code composed of 1s and 0s, and apparently-random sequences of numbers are not fully random. This reality makes a looming scenario of quantum computing "Q-Day" for compromising at least current encryption technologies inevitable. But what if computers could produce true, perfect randomness for the purpose of encryption, thereby mitigating this limitation and preventing a veritable encryption apocalypse?
May 28th, 2026 — Source

OpenAI prepares ChatGPT for the election misinformation wave
AI-generated election misinformation could shape public opinion and influence the lives of millions of people. To address those risks, OpenAI outlined a series of safeguards ahead of the 2026 election cycle.
May 28th, 2026 — Source

Qumulo NeuralProtect uses AI to detect and stop ransomware before encryption
Qumulo has unveiled Qumulo NeuralProtect, a ransomware resilience solution built to protect data at the storage layer by detecting and stopping threats before data is encrypted, corrupted, or lost.
May 28th, 2026 — Source

Raising the Cybersecurity Stakes: Ante up for the Agentic Era
CISOs are now facing machine-speed attacks and asking, "How do I agent?" The industry must provide remediation at scale.
May 28th, 2026 — Source

Researchers say they can spy on your browsing by measuring SSD activity through a browser API — claim FROST attack requires no permissions or user interaction to identify which apps and websites you're using
The technique correctly identified visited websites with roughly 89% accuracy and running applications with roughly 96% accuracy on a test Mac
May 28th, 2026 — Source

Romanian gets 5 years in prison for hacking Oregon govt network
A Romanian national was sentenced this week to 56 months in federal prison for breaking into an Oregon state government computer network and fr cyberattacks targeting dozens of other U.S. victims.
May 28th, 2026 — Source

Scammers are Exploiting GTA 6 Hype to Spread Malware
It's been 13 years since the last true GTA installment came out, and scammers are eager to take advantage of players' impatience.
May 28th, 2026 — Source

Wide-ranging 7-zip vulnerability with 8.8 CVE rating allows for code execution — hundreds of millions of machines potentially at risk
Everyone, get your update hats on immediately; we're at DEFCON 1
May 28th, 2026 — Source

XM Cyber enhances identity risk visibility with continuous exposure management capabilities
XM Cyber has announced platform enhancements aimed at helping organizations reduce identity risk, compounded by AI-enabled attackers. According to Gartner, "By 2028, 70% of CISOs will use identity visibility and intelligence capabilities to shrink the IAM attack surface, reducing the risks of credential compromise."
May 28th, 2026 — Source

Zapier exploit chain shows how known anti-patterns compose into critical risk
A five-stage exploit chain disclosed by Token Security researchers turned a free Zapier account into write access on Zapier's public developer SDK packages and on internal packages that load in every authenticated zapier.com session. Each link in the chain was a known anti-pattern. The composition across five systems was the finding.
May 28th, 2026 — Source

Internet — Security Issues — May 24th, 2026

Everyone is navigating AI security in real time — even Google
Everyone is navigating AI security in real time — even Google
May 24th, 2026 — Source

Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign
A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows.
May 24th, 2026 — Source

The AI security gap nobody wants to admit is already here
On March 31, 2026, Anthropic accidentally shipped the entire source code of Claude Code to the public npm registry. Around 512,000 lines of TypeScript across 1,906 files, including 44 hidden feature flags and references to an unreleased model codenamed Mythos, sat openly accessible on a Cloudflare storage bucket until a security researcher found it and posted the link on X. Within hours the codebase had been mirrored across GitHub, amassing thousands of stars before Anthropic could issue DMCA takedowns.
May 24th, 2026 — Source

Week in review: GitHub breached via poisoned VS Code extension, critical NGINX flaw exploited
Here's an overview of some of last week's most interesting news, articles, interviews and videos:
May 24th, 2026 — Source

Internet — Security Issues — May 23rd, 2026

AI eyes scanning for bugs create a worrisome Linux security trend
Dirty Frag, Copy Fail, and Fragesia show the new reality
May 23rd, 2026 — Source

How To Easily Backup and Import Windows Defender Firewall Rules
If you put in a lot of effort in setting up your Windows Defender Firewall rules, you'll probably want to back them up. You can then quickly import and restore all of your settings at once when needed. It will only take a couple of minutes.
May 23rd, 2026 — Source

Italy disrupts CINEMAGOAL piracy app that stole streaming auth codes
Italian authorities have dismantled a piracy ecosystem centered around the CINEMAGOAL app that provided access to various streaming platforms, including Netflix, Disney+, and Spotify.
May 23rd, 2026 — Source

These special phone and app features can help protect you from spyware
Spyware attacks on journalists, human rights defenders, and political dissidents are no longer rare or exotic. In early 2025, WhatsApp notified roughly 90 users — many of them journalists and civil society members across Europe — that they had been targeted by Israeli spyware company Paragon Solutions. Months later, Apple sent threat notifications to a new group of iOS users; forensic analysis confirmed two of them, both journalists, had been hit with Paragon's Graphite spyware using a zero-click attack, meaning they didn't even have to tap a link to be compromised. These aren't isolated incidents. They're the norm.
May 23rd, 2026 — Source

'Underminr' Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains
The stealthy vulnerability impacts roughly 88 million domains and can be exploited to bypass DNS filtering and hide command-and-control traffic.
May 23rd, 2026 — Source

Wi-Fi controlled hacking USB cable stealthily packs in a microcontroller, microSD storage, and more — cable executes remote payload execution, keystroke injection, and more, but is 'built for makers, developers, enthusiasts, and cybersecurity learners'
The $82 Hacknect 'looks like a normal USB cable' and its makers are enjoying a very successful crowdfunding campaign.
May 23rd, 2026 — Source

Internet — Security Issues — May 22nd, 2026

A hacker group is poisoning open source code at an unprecedented scale
GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks.
May 22nd, 2026 — Source

Canadian Man Arrested for Operating Kimwolf Botnet
Jacob Butler, 23, has been arrested in Canada and US authorities are seeking his extradition on computer hacking charges.
May 22nd, 2026 — Source

CISA's new KEV nomination form opens reporting to vendors and researchers
The Cybersecurity and Infrastructure Security Agency launched a new nomination form that lets researchers, vendors, and industry partners report known exploited vulnerabilities for possible inclusion in its KEV catalog.
May 22nd, 2026 — Source

Cybercrime'First VPN' Cybercrime Service Disrupted, Administrator Arrested
The FBI says First VPN has been used by dozens of ransomware groups for network reconnaissance and intrusions.
May 22nd, 2026 — Source

Deleted Google API keys keep working for up to 23 minutes, researchers warn
Google API keys are credentials that let applications access Google services, from Maps to the Gemini AI. If a key is leaked, an attacker can use it to make API calls, rack up charges, and, if Gemini is enabled, access uploaded files and cached conversations.
May 22nd, 2026 — Source

Drupal Vulnerability in Hacker Crosshairs Shortly After Disclosure
Drupal is warning users that it has already seen attempts to exploit CVE-2026-9082 and security firms are seeing attacks against thousands of websites.
May 22nd, 2026 — Source

Drupal: Critical SQL injection flaw now targeted in attacks
Drupal is warning that hackers are attempting to exploit a "highly critical" SQL injection vulnerability announced earlier this week.
May 22nd, 2026 — Source

Europol's Operation Saffron takes down First VPN service over ransomware attacks — 33 'bulletproof' servers spread across 27 countries seized
This particular case seems clear enough, but the slippery slope is getting steeper.
May 22nd, 2026 — Source

Everyone Suddenly Wants Claude's Audit Logs
27 Enterprises Integrate Claude's Compliance API
May 22nd, 2026 — Source or Source or Source or Source

FBI warns Kali365 phishing kit is stealing Microsoft OAuth tokens at scale
MFA? No problem, says crimeware that tricks users into handing attackers the keys to M365
May 22nd, 2026 — Source

Former US execs plead guilty to aiding tech support scammers
Two former executives of a call-tracking and analytics company pleaded guilty to concealing a years-long tech support fraud scheme that victimized individuals worldwide.
May 22nd, 2026 — Source

GitLab 19.0 adds AI workflows, secrets management, and self-hosted model support
GitLab released GitLab 19.0 with expanded secrets management, agentic merge request workflows, improved CI pipeline visibility, support for self-hosted open-source models, and supply chain visibility enhancements.
May 22nd, 2026 — Source

Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack
Hackers accessed Grafana's GitHub repositories after a token compromised in the TanStack attack was not rotated.
May 22nd, 2026 — Source

In Other News: Industrial Router Exploitation, CISA KEV Nomination Form, Gas Station Hacking
Other noteworthy stories that might have slipped under the radar: CISA contractor exposes credentials, Mythos testing and new features, Huawei router flaw triggered telecom blackout.
May 22nd, 2026 — Source

Kash Patel's clothing brand website shut down after reports it was hacked
The merchandise website of FBI director Kash Patel was taken offline on Friday after reports that it had been hijacked by hackers trying to infect visitors with malware, as first reported by Straight Arrow News.
May 22nd, 2026 — Source

Keepnet contributes voice and SMS phishing data to the 2026 Verizon DBIR
Keepnet, an Extended Human Risk Management (xHRM) platform, today announced that its voice and SMS phishing simulation data contributed to the 2026 Verizon Data Breach Investigations Report (DBIR). The 2026 edition is the first to include voice and SMS phishing simulation data at this scale. The DBIR records this as "an increase of 40% in the median click rate" between phone-centric and email-based simulations (Verizon 2026 DBIR, p. 50).
May 22nd, 2026 — Source

Kore.ai unveils AI-native platform for enterprise multiagent systems
Kore.ai has launched the new-generation Kore.ai Agent Platform Artemis edition, the AI-programmable, AI-native foundation that builds, governs, and optimizes the agents, systems, and workflows running across the enterprise. The platform launches initially on Microsoft Azure, with broader cloud availability to follow.
May 22nd, 2026 — Source

Media giant settles for $930k with FTC over allegations it lied about eavesdropping on conversations through smart devices
Cox Media Group allegedly sold a bogus AI-powered snoopfest service
May 22nd, 2026 — Source

Meet Fractal, an OS made for microarchitecture reverse engineering
Probing how a CPU isolates user code from kernel code is messy work. Researchers patch kernels, write drivers, or boot stripped-down bare-metal programs, and any of those choices change variables they were trying to hold still. Fractal, a new operating system from MIT CSAIL, was built to take that mess out of the loop, and its authors used it to surface previously undocumented behavior in the Apple M1 branch predictor.
May 22nd, 2026 — Source

Microsoft 365 users targeted by new phishing threat that bypasses MFA
Microsoft 365 access tokens are being targeted by an emerging Phishing-as-a-Service (PhaaS) platform called Kali365, the FBI is warning.
May 22nd, 2026 — Source

Most data breaches start with a stolen password. Here's how to fix that
Somewhere in your organisation right now, an employee is reusing a password they created in 2019. Another is sharing login credentials for a team account through a Slack DM. A third is storing client portal access in a browser's built-in autofill, synced to a personal Google account your IT team does not control. None of these people are careless. They are simply doing what most workers do when their company has no password infrastructure.
May 22nd, 2026 — Source

Proton Pass adds monitored credential sharing for AI agents
Proton Pass, a secure, end-to-end encrypted password manager, added credential sharing through AI access tokens, allowing users to give AI agents access to selected items and monitor activity. To gain access, an agent must provide a reason for the request so users can see what actions are being performed.
May 22nd, 2026 — Source

Suspected KimWolf botnet admin arrested over DDoS-for-hire operation
U.S. and Canadian authorities arrested and charged a Canadian man accused of operating the KimWolf DDoS botnet, a service linked to attacks that infected more than one million devices worldwide.
May 22nd, 2026 — Source

Techie claims Trump Mobile website was leaking thousands of people's data
Customers' info potentially handed to anyone who could send an HTTP request
May 22nd, 2026 — Source

TrendAI Patches Apex One Zero-Day Exploited in the Wild
CVE-2026-34926 is a directory traversal flaw that can be exploited against the on-premise version of Apex One.
May 22nd, 2026 — Source

Ubiquiti patches three max severity UniFi OS vulnerabilities
Ubiquiti has released security updates to patch three maximum severity vulnerabilities in UniFi OS that can be exploited by remote attackers without privileges.
May 22nd, 2026 — Source

US and Canada arrest and charge suspected Kimwolf botnet admin
U.S. and Canadian authorities arrested and charged a Canadian man with operating the KimWolf distributed denial-of-service (DDoS) botnet, which infected nearly two million devices worldwide.
May 22nd, 2026 — Source

Versa extends zero trust principles to AI agents and MCP workflows
Versa has introduced a patent-pending zero trust architecture for the Model Context Protocol (MCP), applying zero trust principles to AI execution. The company said every AI-generated action is validated against user identity, role-based access controls, and system policies before execution, with human approval required when defined by administrators.
May 22nd, 2026 — Source

Water, the Soft Underbelly of Critical Infrastructure
Fragmented Governance and Scarce Resources Make America's Water Sector Vulnerable
May 22nd, 2026 — Source or Source or Source or Source

Why Chargebacks are Just One Piece of the Fraud Puzzle
For most teams, fraud performance is still summed up in a single metric: chargeback rate. It is visible, painful, and tied directly to card network thresholds, so it naturally becomes the north star for fraud programs.
May 22nd, 2026 — Source

Why legacy security tools are missing AI-generated malware [Q&A]
Recent research from Deep Instinct suggests that legacy security tools have a high miss rate whenit comes to detecting AI-generated threats.
May 22nd, 2026 — Source

Xfinity Customers Still Have Time to Claim a Part of Comcast's $117.5M Data Breach Settlement
The settlement claim period has been extended. Here's how to file before the Sept. 14 deadline.
May 22nd, 2026 — Source

Internet — Security Issues — May 21st, 2026

AI Bug Reports Have Made Linux Security List Unmanageable, Creator Says
These reports duplicate the same issues over and over—including ones that have already been solved.
May 21st, 2026 — Source

AI is not your strategy: Author and business advisor Brian Evergreen explains why vision comes first
If someone showed up at your door with a saw and said "let's walk through your house and figure out how to make it better," you'd think you hired the wrong contractor. But that's how most companies are approaching AI — focusing on the capabilities of the tool rather than their vision for the work.
May 21st, 2026 — Source

Apple Rejected 2 Million App Store Submissions in 2025 for Security and Fraud Prevention
The company blocked over 1.1 billion accounts and $2.2 billion in potentially fraudulent transactions.
May 21st, 2026 — Source

ASAPP expands adversarial testing for enterprise AI systems
ASAPP has launched Continuous Red Teaming, a new capability that integrates adversarial AI testing directly into ASAPP's model evaluation framework. The new capability is built on Promptfoo, an AI security platform that helps enterprises detect and address vulnerabilities in AI systems during development.
May 21st, 2026 — Source

Attackers spill plaintext passwords of 46k Myspace93 users after 2021 breach
Leakage blamed on treacherous friends exposed unencrypted credentials, email addresses
May 21st, 2026 — Source

Chinese hackers target telcos with new Linux, Windows malware
A Chinese cyber-espionage campaign has been targeting telecommunications providers with newly discovered Linux and Windows malware dubbed Showboat and JFMBackdoor, respectively.
May 21st, 2026 — Source

Cisco Patches Critical Vulnerability in Secure Workload
Insufficient validation and authentication in the Secure Workload's REST APIs provide remote attackers with Site Admin privileges.
May 21st, 2026 — Source

Cryptohack Roundup: US Extradition of Accused in $340M Scam
Also: Hackers Stole From Verus Bridge, ThorChain and Echo Protocol
May 21st, 2026 — Source or Source or Source

CTERA brings AI insights and automation for unstructured data
CTERA has announced the launch of CTERA InsightAI, an agentic AI intelligence layer for the CTERA Intelligent Data Platform. The new capability is designed to help enterprises understand, manage, secure, and optimize unstructured data environments. CTERA InsightAI adds AI-driven insights and automation to data operations, expanding traditional data observability capabilities.
May 21st, 2026 — Source

Drupal Patches Highly Critical Vulnerability Exposing Websites to Hacking
CVE-2026-9082 can be exploited without authentication for information disclosure, privilege escalation, and remote code execution.
May 21st, 2026 — Source

Eight out of 10 organizations experience web-based security incidents
New research from network security platform NordLayer finds that 82 percent of surveyed IT professionals report that their organization experienced a web-based security incident in the past year, with half describing the impact as moderate or severe.
May 21st, 2026 — Source

Forward launches Predict to test network changes before deployment
Forward has unveiled Forward Predict, a new capability that allows organizations to evaluate the impact of network changes before deployment. By testing proposed changes against a digital twin of the production network, Forward Predict helps identify potential issues before they reach live environments and supports safer network operations at scale.
May 21st, 2026 — Source

Google's Surge in Chrome Vulnerability Discoveries Likely Driven by AI
More than 200 vulnerabilities patched in recent Chrome releases are marked as 'reported by Google'.
May 21st, 2026 — Source

Hollywood Secures Broad "Omnibus" Pirate Site Blocking Order in UK High Court
A recent UK High Court "omnibus" order reportedly grants Hollywood studios the power to block rotating networks of pirate sites, without the need to link them to known pirate brands. The order is a response to rapid domain-hopping and other evasion tactics of pirate site operators. However, aside from the Motion Picture Association's brief description in a WIPO submission, the order itself remains under wraps.
May 21st, 2026 — Source

Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet
In recent years, cryptocurrency theft operations have evolved far beyond isolated phishing pages and fake NFT mint scams. What once consisted mainly of individual actors running malicious wallet-connection pages has increasingly developed into a structured underground service economy built around "Drainer-as-a-Service" (DaaS) platforms.
May 21st, 2026 — Source

LLMs outperform humans for cybersecurity knowledge
New research carried out at the RSAC Conference challenged cybersecurity professionals to pit their domain knowledge against the capabilities of a battery of 39 different LLMs in a game we called 'AI Showdown.'
May 21st, 2026 — Source

Max severity Cisco Secure Workload flaw gives Site Admin privileges
Cisco has released security updates to address a maximum-severity Secure Workload vulnerability that allows attackers to gain Site Admin privileges.
May 21st, 2026 — Source

Microsoft Defender vulnerabilities exploited in the wild (CVE-2026-41091, CVE-2026-45498)
Attackers are exploiting two Microsoft Defender vulnerabilities (CVE-2026-41091 and CVE-2026-45498), Microsoft acknowledged and CISA confirmed by adding them to its Known Exploited Vulnerabilities catalog.
May 21st, 2026 — Source

Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days
The bugs could be exploited to elevate privileges to System or create a denial-of-service (DoS) condition.
May 21st, 2026 — Source

Microsoft storms RAMPART, adds Clarity to agentic AI safety
Redmond open sources two tools for building and maintaining safer agents
May 21st, 2026 — Source

Microsoft warns of new Defender zero-days exploited in attacks
CVE-2026-41091 is a Microsoft Defender local privilege escalation (LPE) flaw known as RedSun, and CVE-2026-45498 is known as UnDefend, a security flaw that can be exploited by standard users to block Microsoft Defender definition updates, according to a security researcher known as "Nightmare Eclipse" who disclosed them last month.
May 21st, 2026 — Source

Microsoft won't send you SMS texts for login anymore - why it's pushing passkeys instead
Text messages are a weak, vulnerable way to authenticate account logins. Soon, you'll have to switch to one of these safer, more secure methods.
May 21st, 2026 — Source

Ocean Emerges From Stealth With $28M for Agentic Email Security Platform
The company has developed a platform that uses specialized AI agents to inspect every incoming message.
May 21st, 2026 — Source

Police seize "First VPN" service used in ransomware, data theft attacks
A virtual private network service called 'First VPN,' used in ransomware and data theft attacks, has been taken offline in a joint international law enforcement operation.
May 21st, 2026 — Source

Riverbed introduces new Aternity tools for autonomous IT operations
Riverbed has announced new capabilities for Aternity designed to support autonomous IT operations for digital experience management. The updates help digital workplace teams move toward prevention-focused operations through broader visibility, context-aware intelligence, and governance controls that support automated workflows.
May 21st, 2026 — Source

Scammers are abusing an internal Microsoft account to send spam links
For months, scammers have been taking advantage of a loophole that allows them to send spammy emails from an internal Microsoft email address typically used for sending legitimate account alerts.
May 21st, 2026 — Source

Socket Raises $60 Million at $1 Billion Valuation
The company will invest in its firewall, certified patches, protection extensions, new products, and team expansion.
May 21st, 2026 — Source

Software supply chain attacks hit record highs thanks to AI development
A new report from JFrog reveals an unprecedented acceleration in enterprise software supply chain risk as threat actors expand strikes beyond traditional package registries into AI model registries and developer tooling, creating a blind spot in current software governance frameworks.
May 21st, 2026 — Source

Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility
New vulnerabilities are being discovered too fast, the time-to-exploitation is too short, and our visibility into them is largely lacking.
May 21st, 2026 — Source

Tenable Hexa AI automates remediation across attack surfaces
Tenable has announced the general availability of Tenable Hexa AI, the agentic AI engine of the Tenable One Exposure Management Platform. Tenable Hexa AI is an advanced agentic AI for cybersecurity solution, equipped with advanced multi-step reasoning and Model Context Protocol (MCP) support, enabling custom agent building and workflows that accelerate risk reduction at machine speed.
May 21st, 2026 — Source

Terra adds continuous network exploitation validation to its platform
Terra Security has announced the public preview of continuous exploitation validation for network infrastructure, now available to all customers through the Terra Platform. The launch expands Terra's offensive security capabilities from web applications to network infrastructure and extends coverage across three areas: web applications, AI, and network environments. Terra said the update expands its continuous offensive security capabilities across web applications, AI, and network infrastructure within a single platform.
May 21st, 2026 — Source

Virtru centers file collaboration around data-level protection
Organizations that handle sensitive data consistently face a dilemma: lock data down and lose productivity, or share it freely and lose control. Virtru unveiled Virtru Collaborate, a new offering that eliminates that tradeoff, a FedRAMP authorized space where sensitive files are encrypted and protected by the Trusted Data Format (TDF), and where that protection travels seamlessly with the data as teams work together across organizational boundaries.
May 21st, 2026 — Source

Internet — Security Issues — May 18th, 2026

7-Eleven Data Breach Confirmed After ShinyHunters Ransom Demand
The hackers claimed to have stolen more than 600,000 Salesforce records, including personal information and corporate data.
May 18th, 2026 — Source

201 arrested in INTERPOL disruption of phishing and fraud networks
Operation Ramz, a cybercrime initiative coordinated by INTERPOL across the MENA region, focused on disrupting phishing campaigns, malware activity, and cyber scams that caused substantial financial losses across the region. The operation resulted in the arrest of 201 individuals and the identification of an additional 382 suspects.
May 18th, 2026 — Source

Apple Is Losing Its Negotiation Prowess For DRAM Chips To Hyperscalers; New Goal Titled Towards Securing Supply, Not Getting The Best Prices
The latest-generation DDR5 RAM has broken records thanks to being slapped with a 400+ percent premium in overseas markets, as supply has been gobbled up by massive hyperscalers. The future is looking far too grim as NVIDIA's Rubin AI platform is expected to starve smartphone LPDDR supply like there's no tomorrow.
May 18th, 2026 — Source

Attackers accessed, downloaded code from Grafana Labs' GitHub
A threat actor has managed to access Grafana Labs' GitHub environment and download the company's codebase, the open-source observability and data visualization firm announced on Sunday.
May 18th, 2026 — Source

Attackers are exploiting critical NGINX vulnerability (CVE-2026-42945)
A critical NGINX vulnerability (CVE-2026-42945) disclosed last week is being exploited by attackers, VulnCheck security researcher Patrick Garrity revealed on Saturday.
May 18th, 2026 — Source

Attackers bypass traditional security tools with 'user driven' attacks
Cyber attackers are increasingly bypassing traditional security tools altogether, using sophisticated social engineering techniques to trick users into compromising their own organizations, according to a new report from Bridewell.
May 18th, 2026 — Source

Bridging Gaps in SOC Maturity Using Detection Engineering and Automation
SOC maturity is a feedback loop. Sigma rules, quality gates, and explicit telemetry contracts turn noise into a measurable, improvable signal.
May 18th, 2026 — Source

Bug bounty businesses bombarded with AI slop
"Never-ending" AI slop strains corporate hacking reward schemes.
May 18th, 2026 — Source

'Claw Chain' OpenClaw Flaws Allow Sandbox Escape, Backdoor Delivery
Four vulnerabilities in OpenClaw can be chained together to steal credentials, escape the sandbox, and pla nt persistent backdoors.
May 18th, 2026 — Source

Cybersecurity a priority for SMBs as AI exposes weaknesses
A new survey of over 2,000 SMBs finds 52 percent rank cybersecurity and data protection among their top business priorities for the next 12 months, second only to growth (59 percent) and well ahead of scaling AI adoption (33 percent).
May 18th, 2026 — Source

Dutch cops' shame game works wonders as most wanted scammers now turned in
Game Over?! gamified the identification of scammers who sought thrills from terrorising the elderly
May 18th, 2026 — Source

Exploit available for new DirtyDecrypt Linux root escalation flaw
A recently patched local privilege escalation vulnerability in the Linux kernel's rxgk module now has a proof-of-concept exploit that allows attackers to gain root access on some Linux systems.
May 18th, 2026 — Source

Exploitation of Critical NGINX Vulnerability Begins
The flaw leads to denial-of-service on default configurations and to remote code execution if ASLR is disabled.
May 18th, 2026 — Source

First Shai-Hulud Worm Clones Emerge
At least one threat actor has adopted the recently released malware source code in attacks against NPM developers.
May 18th, 2026 — Source

Grafana Confirms Breach After Hackers Claim They Stole Data
Grafana appears to have been targeted by Coinbase Cartel, a cybercrime group linked to ShinyHunters, Scattered Spider, and Lapsus$.
May 18th, 2026 — Source

Grafana says stolen GitHub token let hackers steal codebase
Grafana Labs disclosed that hackers have downloaded its source code after breaching its GitHub environment using a stolen access token.
May 18th, 2026 — Source

Microsoft acknowledges May 2026 Windows 11 security update install problems
Another month, another update for Windows which is problematic. This time around, it is the May 2026 Windows 11 security update -- or the KB5089549 update.
May 18th, 2026 — Source

Microsoft confirms Windows 11 security update install issues
Microsoft has confirmed that the May 2026 Windows 11 security update (KB5089549) fails to install on some systems and triggers 0x800f0922 errors.
May 18th, 2026 — Source

Millions Impacted Across Several US Healthcare Data Breaches
Several healthcare data breaches impacting hundreds of thousands and even millions were added to the HHS tracker.
May 18th, 2026 — Source

Most agentic AI projects fail to meet objectives
New research reveals a widening gap between agentic AI adoption and outcomes as 97 percent of organizations have deployed or are piloting AI agents, yet 57 percent of AI projects are not reported to be delivering their objectives.
May 18th, 2026 — Source

Mozilla warns UK: Breaking VPNs will not magically fix Britain's age-check mess
Firefox maker says the tools are basic security infrastructure, not teenage contraband
May 18th, 2026 — Source

NGINX Rift attackers waste no time targeting exposed servers
Researchers say 18-year-old flaw already being probed and exploited just days after disclosure
May 18th, 2026 — Source

NYC Health + Hospitals says hackers stole medical data and fingerprints during breach affecting at least 1.8 million people
New York public health provider NYC Health + Hospitals says a months-long data breach that allowed hackers to steal personal data, medical records, and fingerprints scans affects at least 1.8 million people.
May 18th, 2026 — Source

Poland directs officials to ditch Signal in favor of 'secure' state-developed alternative
Shift comes amid mounting reports of successful social engineering attacks targeting higher-ups in government
May 18th, 2026 — Source

Researcher Drops MiniPlasma Windows Exploit for Unpatched 2020 CVE
The researcher dropped the MiniPlasma exploit that uses the original proof-of-concept (PoC) code targeting the bug.
May 18th, 2026 — Source

SmartBear expands ReadyAPI with AI-powered API testing capabilities
SmartBear has announced ReadyAPI's new AI test generation capability that accelerates API testing by up to 80% while giving teams control to enable or disable AI.
May 18th, 2026 — Source

TanStack weighs invitation-only pull requests after supply chain attack
Shai-Hulud worm exploited GitHub Actions misconfiguration to poison shared cache, now project weighing nuclear option on unsolicited contributions
May 18th, 2026 — Source

Internet — Security Issues — May 17th, 2026

Crackdown in Southeast Asia pushes scam networks to Sri Lanka
A surge in arrests of suspected foreign scammers in Sri Lanka has authorities concerned that the island is fast becoming a hub for online crime, following sweeping crackdowns in hotspots Cambodia and Myanmar.
May 17th, 2026 — Source

Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing
The Tycoon2FA phishing kit now supports device-code phishing attacks and abuses Trustifi click-tracking URLs to hijack Microsoft 365 accounts.
May 17th, 2026 — Source

Wanted: Digital chief for England's schools. Must enjoy data, AI, and concrete problems
Are you ready to RAAC?
May 17th, 2026 — Source

Week in review: Cisco patches SD-WAN 0-day, unpatched Microsoft Exchange Server flaw exploited
Here's an overview of some of last week's most interesting news, articles, interviews and videos:
May 17th, 2026 — Source

Internet — Security Issues — May 16th, 2026

AI could steal fingerprints from high-resolution selfies, experts warn
Although fingerprint authentication has known security limitations, modern laptops, tablets, and smartphones continue to rely on it for device unlocking and passkey authentication. As phone cameras become increasingly powerful, security experts are warning that lifting fingerprints from ordinary photos is becoming more feasible.
May 16th, 2026 — Source

AI Doctors? Lawsuits Say No, Some Doctors Say Yes
Medical professionals are pushing back against artificial intelligence assuming the persona of a doctor, arguing it amounts to practicing without a license. One solution floated in the Journal of the American Medical Association would be to license AI as if it went to medical school.
May 16th, 2026 — Source or Source or Source or Source

First Apple M5 memory exploit discovered using Anthropic AI, gives root access on MacOS — Claude Mythos helps security researchers bypass Memory Integrity Enforcement
AI-assisted security research is producing exploits at a frightening rate.
May 16th, 2026 — Source

ISMG Editors: Should We Trust Ransomware Gangs?
In this week's panel, four ISMG editors discussed a ransomware case that once again raises questions about paying extortionists, why security leaders fear artificial intelligence is accelerating attacks faster than humans can respond and how the rise of instant payments is reshaping fraud programs at banks.
May 16th, 2026 — Source or Source or Source or Source

New Cisco SD-WAN Zero-Day Grants Admin Access
Broken vdaemon Peering Authentication Enables Unauthenticated Admin Access
May 16th, 2026 — Source or Source or Source or Source

PoC Code Published for Critical NGINX Vulnerability
Introduced in 2008, the critical-severity security defect was patched this week in NGINX Plus and NGINX open source.
May 16th, 2026 — Source

Russian hackers turn Kazuar backdoor into modular P2P botnet
The Russian hacker group Secret Blizzard has developed its long-running Kazuar backdoor into a modular peer-to-peer (P2P) botnet designed for long-term persistence, stealth, and data collection.
May 16th, 2026 — Source

SecurityScorecard Buys Driftnet for More Internet Visibility
Driftnet Acquisition Adds Real-Time Visibility Into Exposed Assets and AI Risks
May 16th, 2026 — Source or Source or Source or Source

Snap, YouTube, and TikTok settle school addiction lawsuit, leaving Meta to face trial alone
Snap, YouTube, and TikTok settled the first school district addiction trial. Only Meta heads to court on 12 June.
May 16th, 2026 — Source

Upscale versus Upskill: The Real Cybersecurity Gap
AI Adoption Is Accelerating, but Workforce Capability Isn't Keeping Pace
May 16th, 2026 — Source or Source or Source or Source

Internet — Security Issues — May 15th, 2026

Akamai to acquire LayerX for $205 million
Akamai has entered into a definitive agreement to acquire LayerX, a provider of browser-based AI usage control and secure enterprise browser (SEB) technology.
May 15th, 2026 — Source

American Lending Center Data Breach Affects 123,000 Individuals
The non-bank lender discovered a ransomware attack nearly one year ago, but only recently completed its investigation.
May 15th, 2026 — Source

Avada Builder WordPress plugin flaws allow site credential theft
Two vulnerabilities in the Avada Builder plugin for WordPress, with an estimated one million active installations, allow hackers to read arbitrary files and extract sensitive information from the database.
May 15th, 2026 — Source

Cisco patches another actively exploited SD-WAN zero-day (CVE-2026-20182)
Cisco has patched yet another Catalyst SD-WAN Controller authentication bypass vulnerability (CVE-2026-20182) that has been exploited as a zero-day by "a highly sophisticated cyber threat actor".
May 15th, 2026 — Source

Exchange Server has a "critical" security bug, but Microsoft does not have a proper fix yet
A newly disclosed Exchange Server vulnerability is forcing some admins into messy trade-offs, and not everyone will receive Microsoft's permanent fix.
May 15th, 2026 — Source

Exploited Exchange Server flaw turns OWA inboxes into script launchpads
Microsoft mitigation may bork inline images, calendar printing while admins wait for a proper patch
May 15th, 2026 — Source

How deep learning is reshaping cybersecurity in the age of AI-driven attacks [Q&A]
With the power of AI, attackers are smarter and stealthier than ever. They can exploit existing workflows, blend in with normal operations, and avoid detection for longer periods.
May 15th, 2026 — Source

In Other News: Big Tech versus Canada Encryption Bill, Cisco's Free AI Security Spec, Audi App Flaws
Other noteworthy stories that might have slipped under the radar: Nvidia cloud gaming data breach, Android 17 security upgrades, FBI warning after ShinyHunters hacks Canvas.
May 15th, 2026 — Source

Inside the REMUS Infostealer: Session Theft, MaaS, and Rapid Evolution
In recent months, a new infostealer malware known as REMUS has emerged across the cybercrime landscape, drawing attention from security researchers and malware analysts. Several technical analyses published in recent months focused on the malware's capabilities, infrastructure, and similarities to Lumma Stealer, including browser targeting mechanisms, and credential theft functionality and more.
May 15th, 2026 — Source

Keycard helps developers secure autonomous AI agents with scoped access
Keycard has announced Keycard for Multi-Agent Apps, extending its platform to support delegated, session-based access across systems of autonomous agents. Keycard lets developers build apps where every agent has its own identity, access is scoped to each task and every action is fully attributable across agents, users and systems.
May 15th, 2026 — Source

Microsoft warns of Exchange zero-day flaw exploited in attacks
On Thursday, Microsoft shared mitigations for a high-severity Exchange Server vulnerability exploited in attacks that allow threat actors to execute arbitrary code via cross-site scripting (XSS) while targeting Outlook on the web users.
May 15th, 2026 — Source

MPs want social media treated more like unsafe toys than harmless apps
Parliamentary committee tells ministers online safety regime is failing children and warns 'no action is not an option'
May 15th, 2026 — Source

Patch time for Cisco SD-WAN admins as vendor drops yet another make-me-admin zero-day
CISA hands feds super-tight deadline for this perfect-10, actively exploited flaw
May 15th, 2026 — Source

Rocky Linux launches opt-in security repository for urgent fixes
Rocky Linux has introduced a Security Repository that allows the distribution to ship urgent security fixes ahead of upstream Enterprise Linux when public exploit code exists and upstream patches are unavailable.
May 15th, 2026 — Source

Security researchers, aided by Anthropic's Mythos, claim to have breached macOS
Apple's operating systems are known for their security, especially compared to their rivals in mobile and computing. Now, security researchers from a Palo Alto-based company called Calif claim they were able to breach macOS after designing a privilege escalation exploit with help from Anthropic's Claude Mythos Preview. As The Wall Street Journal reports, the exploit could be used to access parts of the MacBook that should be inaccessible and, thus, allows the attacker to take control of a Mac computer.
May 15th, 2026 — Source

Thieves unlock stolen iPhones using cheap tools sold on Telegram
Helping a friend recover a stolen phone, Infoblox researchers uncovered a thriving Telegram-based underground marketplace selling unlocking tools and phishing infrastructure used to monetize stolen iPhones.
May 15th, 2026 — Source

Unpatched Microsoft Exchange Server vulnerability exploited (CVE-2026-42897)
A critical cross-site scripting (XSS) vulnerability (CVE-2026-42897) in Microsoft Exchange Server is being exploited by attackers, Microsoft warned on Thursday.
May 15th, 2026 — Source

Was Your Data Exposed in the Massive New Cyberattack?
Artificial intelligence is reshaping the cybersecurity landscape, creating both opportunities and challenges for organizations worldwide. As Wes Roth highlights, AI is not only allowing faster detection of vulnerabilities but also being weaponized by cybercriminals to launch increasingly sophisticated attacks. A recent example is the discovery of a critical macOS 26.4.1 vulnerability by the AI system Mythos, which allowed privilege escalation on Apple M5 hardware. While this demonstrates the potential of AI to enhance defensive measures, it also underscores the growing risk of AI-assisted exploitation, where attackers use the same technology to automate and accelerate their efforts.
May 15th, 2026 — Source

You can now explore Wikipedia through a Windows XP-esque desktop on the web
A clever web project turns Wikipedia into a nostalgic Windows XP-style filesystem you can actually browse and customize.
May 15th, 2026 — Source

Internet — Security Issues — May 14th, 2026

18-year-old NGINX vulnerability allows DoS, potential RCE
An 18-year-old flaw in the NGINX open-source web server, discovered using an autonomous scanning system, can be exploited for denial of service and, under certain conditions, remote code execution.
May 14th, 2026 — Source

A spyware investigator exposed Russian government hackers trying to hijack Signal accounts
Earlier this year, Donncha Ó Cearbhaill, a security researcher who investigates spyware attacks, found himself in an unusual position. For once, he became the target of hackers.
May 14th, 2026 — Source

AI cyber capability is speeding past earlier projections
AI cyber capability is improving faster than expected, with newer models surpassing earlier projections, according to the UK government's AI Security Institute (AISI).
May 14th, 2026 — Source

Akamai to Acquire AI and Browser Security Firm LayerX for $205 Million
The acquisition enables Akamai to expand its Zero Trust portfolio to add protection directly into the browser.
May 14th, 2026 — Source

Beyond Algorithms: The Human Element in AI-Driven Cybersecurity
AI is pushing cybersecurity from reactive defense to proactive intelligence — but human judgment, explainable AI, and ethical design remain essential.
May 14th, 2026 — Source

CERN's open source KiCad library gives the world 17,000 circuit board components
CERN has released its complete KiCad component library under an open source license, making it available to hardware designers anywhere in the world. The library, maintained by CERN's Design Office, contains more than 17,000 electronic components in the form of schematic symbols and printed circuit board footprints.
May 14th, 2026 — Source

Chinese APTs Expand Targets, Update Backdoors in Recent Campaigns
Salt Typhoon has hit an energy entity in Azerbaijan. Twill Typhoon has targeted Asian entities with an updated RAT.
May 14th, 2026 — Source

Cisco CEO Robbins Ties AI Push to Unpatchable Tech Risk
Chuck Robbins Warns Customers Face Growing Exposure From Equipment Past Support
May 14th, 2026 — Source or Source or Source

Cofense adds AI-powered campaign detection to stop phishing attacks
Cofense has announced new advancements to its Phishing Defense Platform aimed at improving detection and response to AI-powered phishing attacks. The updates include AI-driven phishing detection, enhanced triage automation, and AI-assisted training campaign creation designed to strengthen protection across the phishing lifecycle.
May 14th, 2026 — Source

Cyber-Enabled Cargo Crime: How Cybercrime Tradecraft is Used to Steal Freight
Working in cybersecurity, you are well aware of the playbook that ransomware operators use. Stolen credentials, established persistence, network recon, pivoting to a high-value target cash out. These techniques are well documented; we have attack frameworks and well-documented kill chains for their techniques. What you may not have been exposed to is that same playbook being used to steal freight.
May 14th, 2026 — Source

F5 Patches Over 50 Vulnerabilities
The company's latest quarterly advisory describes high and medium-severity issues in BIG-IP, BIG-IQ, and NGINX.
May 14th, 2026 — Source

G7 Countries Release AI SBOM Guidance
The goal of the guidance, which outlines minimum elements, is to help organizations enhance transparency in AI systems and supply chains.
May 14th, 2026 — Source

Hackers Targeted PraisonAI Vulnerability Hours After Disclosure
The first exploitation attempts were observed less than four hours after the authentication bypass was publicly disclosed.
May 14th, 2026 — Source

High-Severity Vulnerability Patched in VMware Fusion
The patch was announced as Broadcom is attending the Pwn2Own hacking competition in Berlin this week.
May 14th, 2026 — Source

HYCU aiR detects insider risk and AI activity from backups
HYCU has announced HYCU aiR (AI Resilience), an AI-native solution that turns backup data across dozens of applications into a live and actionable intelligence for security, compliance, and IT teams.
May 14th, 2026 — Source

KongTuke hackers now use Microsoft Teams for corporate breaches
Initial access broker KongTuke has moved to Microsoft Teams for social engineering attacks, taking as little as five minutes to gain persistent access to corporate networks.
May 14th, 2026 — Source

Kubernetes v1.36 Released: Security Defaults Tighten as AI Workload Support Matures
The Kubernetes project has released version 1.36, named Haru, marking the first major Kubernetes release of 2026. The release contains 70 enhancements: 18 graduating to Stable, 25 entering Beta, and 25 new Alpha features, with a strong emphasis on security hardening, AI and machine learning workloads, and API scalability at scale. The release blog, authored by editors Chad M. Crowell, Kirti Goyal, Sophia Ugochukwu, Swathi Rao, and Utkarsh Umre, describes the release as arriving "as the season turns and the light shifts on the mountain", with contributions from 106 companies and 491 individuals.
May 14th, 2026 — Source

Microsoft Faces New BitLocker Security Concerns With YellowKey
Security researcher Chaotic Eclipse, also known online as Nightmare-Eclipse, has disclosed two new Windows zero-day exploits named YellowKey and GreenPlasma. The vulnerabilities target BitLocker encryption and Windows privilege handling respectively, with YellowKey attracting particular attention because it reportedly allows access to BitLocker-protected drives under certain conditions. According to the published technical details, YellowKey works by placing specially prepared files onto a USB storage device with write access to the "System Volume Information" directory. After rebooting into the Windows Recovery Environment using a specific keyboard sequence, affected systems reportedly launch directly into an elevated command prompt with full access to the encrypted drive contents without requesting BitLocker recovery credentials.
May 14th, 2026 — Source

Microsoft Pushes Agentic AI Security with New Multi-Model Defense System
A new agentic AI security multi-model defense system built by Microsoft's Autonomous Code Security team helped researchers find 16 new vulnerabilities across the Windows networking and authentication stack.
May 14th, 2026 — Source

Microsoft turns Copilot Studio into an AI agent control center
The Microsoft Copilot Studio April 2026 updates improve visibility and governance for admins and expand workflow capabilities for managing agents.
May 14th, 2026 — Source

Microsoft's WinUI agent plugin trims token use by over 70% during development
Microsoft published a plugin on May 13 that lets GitHub Copilot CLI and Claude Code drive the full WinUI 3 development cycle, from project scaffolding through signed MSIX packaging. The WinUI agent plugin ships one agent, eight skills, and several supporting tools targeting the loop developers run dozens of times a day: scaffold, build, run, test, iterate.
May 14th, 2026 — Source

Mythos Proves Potent in Vulnerability Discovery, Less Convincing Elsewhere
Independent benchmarking finds Mythos highly effective for source code audits, reverse engineering, and native-code analysis, though its exploit validation and reasoning capabilities remain inconsistent.
May 14th, 2026 — Source

Over half of MSPs breached several times in the past year
According to a new report three quarters of managed service providers (MSPs) admit to suffering at least one breach in the last 12 months, with 54 percent reporting being breached two or more times and nearly a third (32 percent) of respondents admitting to experiencing three or more breaches.
May 14th, 2026 — Source

Researcher Drops YellowKey, GreenPlasma Windows Zero-Days
YellowKey is a BitLocker bypass that requires physical access. GreenPlasma enables elevation of privileges to System.
May 14th, 2026 — Source

The AI Trust Gap: How to Ensure Your Security Stack is Ready for Autonomous Agents
AI agents are moving at machine speed and most enterprises aren't ready. Shadow AI, over-permissioned agents, and autonomous systems that act on sensitive data are creating a new class of risk that siloed security tools just weren't built to handle.
May 14th, 2026 — Source

To gain root access at this company, all an intruder had to do was ask nicely
Human IT managers thought they were being nice to the boss, but were assisting a threat actor
May 14th, 2026 — Source

Two brothers deleted 96 federal databases after being fired -- one googled how to hide the evidence afterward
Government contractor unknowingly hired felons who hacked the government in 2015
May 14th, 2026 — Source

Understanding the Hidden Cost of Faster Payments
As Regulators Tighten Liability Rules, Banks Face Pressure to Justify Fraud Losses
May 14th, 2026 — Source or Source or Source or Source

Internet — Security Issues — May 11th, 2026

A million baby monitors and security cameras were easily viewable by hackers
Meari Technology: the Wi-Fi camera maker you've probably never heard of.
May 11th, 2026 — Source

AI Is Involved in Most Modern Security Breaches: Report
AI plays a major role in modern security breaches, as a new report from the cybersecurity firm Gigamon demonstrates. Attackers are increasingly using AI to write more convincing phishing emails, automate password attacks, tailor malware to targets, and more, making older tactics much more dangerous. And while AI is also used in defense, such as monitoring, detection, and response, companies often leave themselves open to attacks by rolling out AI tools faster than they can implement proper security protocols.
May 11th, 2026 — Source

Alation AI Governance creates a system of record for AI oversight
Alation has introduced Alation AI Governance, a new offering that gives enterprises the system of record they are missing for AI compliance.
May 11th, 2026 — Source

BWH Hotels guests warned after reservation data checks out with cybercrooks
Customers urged to keep an eye out for phisherfolk
May 11th, 2026 — Source

Build Application Firewalls Aim to Stop the Next Supply Chain Attack
Rather than scanning code alone, Build Application Firewalls inspect runtime behavior inside the software build pipeline.
May 11th, 2026 — Source

Canvas System Is Online After a Cyberattack Disrupted Thousands of Schools
Tens of thousands of students studying for final exams around the world have regained access to a key online learning system after a cyberattack had earlier knocked it offline.
May 11th, 2026 — Source

Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack
A malicious version of the plugin was published to the Jenkins Marketplace late last week.
May 11th, 2026 — Source

Checkmarx tackles another TeamPCP intrusion as Jenkins plugin sabotaged
Cybercrooks ruin engineers' weekends with Saturday attack
May 11th, 2026 — Source or Source

Claude Mythos Just Flagged 271 Hidden Vulnerabilities in Firefox
Mozilla's Claude Mythos AI experiment has unveiled a striking new chapter in software vulnerability detection. By employing advanced AI to analyze the Firefox 150 codebase, the project identified 271 vulnerabilities in a single release cycle, an extraordinary leap from the 22 issues found in a prior evaluation. This effort, as highlighted by Nate Jones, underscores the limitations of traditional manual code reviews, which often fail to catch critical flaws due to human oversight. The findings not only emphasize the precision of AI-driven analysis but also challenge long-standing assumptions about the reliability of human-written code in making sure software security.
May 11th, 2026 — Source

Cloudflare Lays Off 1,100 Employees in AI-Driven Restructuring
The company topped revenue and earnings forecasts for the first quarter of 2026, but its shares plunged more than 20%.
May 11th, 2026 — Source

Google Detects First AI-Generated Zero-Day Exploit
The zero-day was designed to bypass 2FA and it was developed by a prominent cybercrime group.
May 11th, 2026 — Source

Google researchers uncover criminal zero-day exploit likely built with AI
Google's threat intelligence researchers have linked a zero-day exploit to AI-assisted development by a criminal group.
May 11th, 2026 — Source

Google stopped a zero-day hack that it says was developed with AI
Google researchers found evidence in the exploit's code that it may have been created using AI, like a 'hallucinated' CVSS score.
May 11th, 2026 — Source

Google: Hackers used AI to develop zero-day exploit for web admin tool
Researchers at Google Threat Intelligence Group (GTIG) say that a zero-day exploit targeting a popular open-source web administration tool was likely generated using AI.
May 11th, 2026 — Source

How deepfakes are redefining digital identity security [Q&A]
Deepfakes are rapidly evolving from media curiosities to one of the biggest threats to digitalidentity, payments, and financial security.
May 11th, 2026 — Source

Instagram messaging encryption removed, and privacy advocates are pushing back
After introducing optional end-to-end encrypted messaging in 2023, Instagram announced in March 2026 that encryption for direct messages would be discontinued, and the feature was removed on May 8.
May 11th, 2026 — Source

Instructure confirms hackers used Canvas flaw to deface portals
Education technology giant Instructure has confirmed that a security vulnerability allowed hackers to modify Canvas login portals and leave an extortion message.
May 11th, 2026 — Source

Lyrie.ai Deploys Real-Time Zero-Day Tracking Across Global Enterprise Infrastructure
OTT Cybersecurity LLC announced several milestones that position the company as foundational security infrastructure for the agentic AI era.
May 11th, 2026 — Source

Malicious Hugging Face model masquerading as OpenAI release hits 244K downloads
The repository reached the #1 trending position on Hugging Face within 18 hours, highlighting how public AI repositories are becoming a new software supply chain attack vector.
May 11th, 2026 — Source

pCloud online backup review: An affordable lifetime of secure files
This online storage service doesn't mess around with monthly charges, it's yearly or lifetime only -- but very affordable as such, with top-notch local client software.
May 11th, 2026 — Source

Police take down relaunched criminal marketplace with 22,000 users, €3.6 million in revenue
German authorities shut down a relaunched version of the criminal marketplace Crimenetwork and arrested its suspected operator.
May 11th, 2026 — Source

Poor security left hackers inside water company network for nearly two years
The UK's data protection regulator, the Information Commissioner's Office (ICO), fined South Staffordshire Water's parent company £963,900 over security failures linked to a cyberattack that exposed the personal data of 633,887 people.
May 11th, 2026 — Source

Resurrected 'Crimenetwork' Marketplace Taken Down, Administrator Arrested
The second iteration of the German-speaking online crime marketplace had over 22,000 users and more than 100 sellers.
May 11th, 2026 — Source

SailPoint Agentic Fabric expands identity governance to autonomous AI agents
SailPoint has introduced SailPoint Agentic Fabric, a new platform designed to help enterprises secure AI agents and other non-human identities at scale.
May 11th, 2026 — Source

SailPoint Discloses GitHub Repository Hack
The incident occurred on April 20 and did not affect customer data in the company's production and staging environments.
May 11th, 2026 — Source

Skoda Data Breach Hits Online Shop Customers
Using a vulnerability in the portal, hackers accessed names, addresses, email addresses, and phone numbers.
May 11th, 2026 — Source

Taiwan's train cyber-trauma reveals a global system that's coming off the tracks
That's not a radio. THIS is a radio
May 11th, 2026 — Source

The questionnaire-based TPRM model is broken, and TrustCloud has a fix
TrustCloud announced a new version of TrustLens, its third party risk management (TPRM) solution. The new TrustLens agentic AI capabilities focus on delivering four requirements every CISO wants in their TPRM program: speed, accuracy, coverage, and proactive risk mitigation.
May 11th, 2026 — Source

The scam economy has found its AI upgrade
Scam attempts continue to reach consumers via email, text messages, social media, online advertising, and phone calls. The volume of exposure has remained stable over the past year, with more than half of consumers encountering scam attempts at least monthly, according to the F-Secure Scam Intelligence & Impacts Report 2026.
May 11th, 2026 — Source

The Threat Window Is Shrinking. The Response Gap Isn't
Patching Workflows Built for Weekly Cycles Can't Survive an Era of Hourly Exploits
May 11th, 2026 — Source or Source or Source or Source

TrickMo Android banker adopts TON blockchain for covert comms
A new variant of the TrickMo Android banking malware, delivered in campaigns targeting users across Europe, introduces new commands and uses The Open Network (TON) for stealthy command-and-control communications.
May 11th, 2026 — Source

Water company's leaky security earns near-£1M fine
Utility provider failed to detect Cl0p ransomware attack for nearly two years
May 11th, 2026 — Source

Why Changing Passwords Doesn't End an Active Directory Breach
Password resets are often the first response to a suspected compromise. It makes sense; resetting credentials is a quick way to cut off an attacker's most obvious path back in.
May 11th, 2026 — Source

Internet — Security Issues — May 10th, 2026

A cyberattack on Canvas knocked out access for students at Harvard, Columbia, and hundreds of other schools during finals
The breach is a case study in how a single platform compromise can take down an entire sector at once
May 10th, 2026 — Source

Police shut down reboot of Crimenetwork marketplace, arrest admin
German authorities have shut down a relaunch version of the criminal marketplace 'Crimenetwork' that generated more than 3.6 million euros, and arrested its operator.
May 10th, 2026 — Source

Russian Hackers Are Inside American Home Routers. The FBI Has a 5-Step Fix
A coordinated cyberattack by Russia's GRU targeted home and small office routers across 23 states. Here's how to check yours and lock it down.
May 10th, 2026 — Source

Week in review: cPanel vulnerability actively exploited, DigiCert breach, LinkedIn job scams
Here's an overview of some of last week's most interesting news, articles, interviews and videos:
May 10th, 2026 — Source

Internet — Security Issues — May 9th, 2026

A manual pentest costs 50,000 dollars. Intruder built an AI that does it in minutes.
Intruder, a GCHQ-accelerated UK cybersecurity startup, launched AI pentesting agents that replicate manual pen testing methodology in minutes. The broader market is racing to automate vulnerability discovery as AI compresses the gap between offence and defence.
May 9th, 2026 — Source

Anthropic's Mythos found thousands of zero-day vulnerabilities. The Fed chair called the banks.
Anthropic's Claude Mythos Preview found thousands of zero-day vulnerabilities across major operating systems and browsers, prompting the Fed chair and Treasury secretary to convene bank CEOs. The company warns of a six-to-twelve month window before adversaries replicate the capability.
May 9th, 2026 — Source

Canvas system is online after a cyberattack disrupted thousands of schools
Tens of thousands of students studying for final exams around the world Friday regained access to a key online learning system after a cyberattack had earlier knocked it offline, throwing schools and universities into turmoil.
May 9th, 2026 — Source

FCC reverses course, allows software updates for foreign-made drones and routers until 2029 — agency says blocking security patches could create cybersecurity risks
The FCC is extending a software lifeline for millions of already-deployed drones and routers.
May 9th, 2026 — Source

JDownloader site hacked to replace installers with Python RAT malware
The website for the popular JDownloader download manager was compromised earlier this week to distribute malicious Windows and Linux installers, with the Windows payload found deploying a Python-based remote access trojan.
May 9th, 2026 — Source

Meta has killed end-to-end encryption on Instagram
Starting today, end-to-end encryption (E2EE) is no longer available for direct messages on Instagram, as Meta has removed the privacy feature years after it began testing it.
May 9th, 2026 — Source

NVIDIA Confirms GeForce NOW Data Breach Affecting Regional Alliance Partner
Hackers have managed to infiltrate a regional GeForce NOW partner and make off with sensitive user information, including full names, email addresses, and other private data, NVIDIA confirmed. Fortunately, the data breach is limited to one specific region and does not affect GeForce NOW users worldwide, only a third-party Alliance partner in Armenia.
May 9th, 2026 — Source

UK wants fresh fingerprints on £300M biometrics platform
Home Office probes supplier interest as core police and immigration system heads for support shake-up
May 9th, 2026 — Source

Internet — Security Issues — May 8th, 2026

A Canvas outage tied to a cyberattack has wreaked havoc on colleges' final exam season
Schools and universities across the country are recovering from an outage that knocked down Canvas, an online platform that manages exams, course notes, lecture videos and grades. The disruption tied to a cyberattack hit in the middle of finals period for many colleges, a high-stress time when students and instructors rely heavily on the platform.
May 8th, 2026 — Source

AI Firm Braintrust Prompts API Key Rotation After Data Breach
Hackers accessed one of the company's AWS accounts and compromised AI provider secrets stored in Braintrust.
May 8th, 2026 — Source

Avantra's new AI can diagnose SAP failures in seconds
Avantra launched Avantra 26, an advancement in AI-driven operations, strengthening native integration with SAP Cloud ALM, and delivering automated visibility across SAP Business Technology Platform (BTP).
May 8th, 2026 — Source

'Dirty Frag' Linux flaw one-ups CopyFail with no patches and public root exploit
Broken disclosure embargo left admins facing a fresh root-level flaw with no CVE
May 8th, 2026 — Source or Source or Source

CISA gives feds four days to patch Ivanti flaw exploited as zero-day
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. federal agencies four days to secure their networks against a high-severity vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that has been exploited in zero-day attacks.
May 8th, 2026 — Source

Cyberattack Hits Canvas System Used by Thousands of Schools as Finals Loom
A system that thousands of schools and universities use went offline due to a cyberattack, creating chaos as students tried to study for finals
May 8th, 2026 — Source

Former govt contractor convicted for wiping dozens of federal databases
A 34-year-old Virginia man was found guilty of conspiring to destroy dozens of government databases after getting fired from his job as a federal contractor.
May 8th, 2026 — Source

Google is turning Android Studio into a policy watchdog
Google has expanded Play Policy Insights in Android Studio to help developers catch policy issues while coding, including warnings for common problems such as missing login credentials. Later this year, developers who connect their Play developer account directly to Android Studio will receive tailored insights.
May 8th, 2026 — Source

Hackers ate my homework: Educational SaaS Canvas down after cyberattack
ShinyHunters takes the credit and gives developer an F for security
May 8th, 2026 — Source

Helping North Korean IT remote workers is becoming a fast track to prison
Two U.S. nationals were sentenced to 18 months in prison for operating "laptop farms" that helped North Korean IT workers gain employment at nearly 70 American companies, generating more than $1.2 million for Pyongyang's government.
May 8th, 2026 — Source

How GitHub Is Securing Agentic Workflows in Modern CI CD Systems
GitHub has detailed the security architecture behind its agentic workflows, outlining a defense-in-depth approach to safely integrate autonomous AI agents into CI/CD pipelines. The design emphasizes isolation, constrained execution, and auditability to mitigate risks introduced by AI-driven automation.
May 8th, 2026 — Source

If you downloaded this popular software recently, you might have installed malware
Hackers exploited an unpatched security vulnerability on JDownloader's website and used it to serve malware-laced downloads.
May 8th, 2026 — Source

In Other News: Train Hacker Arrested, PamDOORa Linux Backdoor, New CISA Director Frontrunner
Other noteworthy stories that might have slipped under the radar: US gov targets 72-hour patch cycles, malware uses Windows Phone Link to steal OTPs, spy operation targets Eurasian drone industry.
May 8th, 2026 — Source

Instructure breach update: ShinyHunters claim second hack, deface school websites
The hackers are looking to 'negotiate a settlement.'
May 8th, 2026 — Source

Instructure hackers claim they stole data from nearly 9,000 schools
ShinyHunters, the extortion group that infiltrated cloud-based educational tech provider Instructure, claims to have stolen data from 8,809 schools around the world. Instructure is mostly known for Canvas, its cloud-based management system used by educational institutions to host course websites and readings, grade assignments, and provide discussion boards, among other uses. The bad actors said they have stolen 280 million records from teachers, students and staff members.
May 8th, 2026 — Source

Ivanti EPMM vulnerability exploited in zero-day attacks (CVE-2026-6973)
Ivanti has released fixes for 5 high-severity vulnerabilities in its Endpoint Manager Mobile (EPMM) solution, one of which (CVE-2026-6973) has being exploited as a zero-day by attackers.
May 8th, 2026 — Source

Kaspersky warns that passwords hashed with MD5 algorithm can be cracked in minutes using a GPU
Moving away from insecure passwords is now a critical priority
May 8th, 2026 — Source

Kids Are Using Fake Mustaches to Bypass Online Age Verification
It is only one of many simple tricks kids use to bypass the rules.
May 8th, 2026 — Source

macOS security spotlight: 3 new Tahoe features you should know
Apple made security changes to better secure your Mac experience.
May 8th, 2026 — Source

Meta fights Ofcom over how many billions count as billions
Social media biz says watchdog's fine formula is 'disproportionate' and should stop counting global revenue
May 8th, 2026 — Source

Meta U-turns on encryption push for Instagram as DMs go plaintext
After years of insisting end-to-end encryption was the future of online comms, Zuckcorp has handed itself full visibility into user chats once again
May 8th, 2026 — Source

Mothers bear the brunt of food insecurity, study shows
Lead author Dr Ioanna Katiforis, who completed the research at Otago's Department of Human Nutrition, says these women prioritized feeding their infants by stretching limited resources, sacrificing the quality of their own diets, and seeking support, despite the shame and embarrassment it caused them.
May 8th, 2026 — Source

NVIDIA confirms GeForce NOW data breach affecting Armenian users
NVIDIA has confirmed in a statement for BleepingComputer that GeForce NOW user information has been exposed in a data breach.
May 8th, 2026 — Source

Object First Fleet Manager simplifies distributed backup storage
Object First released Object First Fleet Manager, a cloud-based service that simplifies the management of distributed Ootbi backup storage deployments for Veeam Software environments.
May 8th, 2026 — Source

OpenAI tunes GPT-5.5-Cyber for more permissive security workflows
Trusted Access for Cyber is OpenAI's identity and trust-based access framework for cybersecurity users, designed to give verified defenders broader access to GPT-5.5's cybersecurity capabilities for defensive tasks while maintaining restrictions on requests that could contribute to real-world harm.
May 8th, 2026 — Source

'PCPJack' Worm Removes TeamPCP Infections, Steals Credentials
The malware framework targets web applications and cloud environments, including AWS, Docker, Kubernetes, and more.
May 8th, 2026 — Source

Polish Security Agency Reports ICS Breaches at Five Water Treatment Plants
The hackers gained the ability to modify equipment operational parameters, creating a direct risk to the public water supply.
May 8th, 2026 — Source

Ransomware Group Takes Credit for Trellix Hack
RansomHouse has published several screenshots to demonstrate access to internal Trellix services.
May 8th, 2026 — Source

Securonix launches AI threat research agent and ThreatWatch validation tool
Securonix announced the Securonix Threat Research Agent and ThreatWatch for ThreatQ, expanding how security teams research threats, validate exposure, and turn intelligence into documented action. Built on the ThreatQ platform and connected to Securonix security operations workflows, the new capabilities help teams generate role-specific intelligence, validate emerging threats against historical telemetry, and deliver explainable findings for analysts, SOC leaders, and executives.
May 8th, 2026 — Source

Snyk integrates Claude to advance AI-native application security
Snyk has announced it is leveraging Anthropic's Claude models to advance software security. Snyk has integrated Claude into the Snyk AI Security Platform, enabling automated vulnerability discovery, prioritization, and developer-ready fixes across code, dependencies, containers, and AI-generated artifacts.
May 8th, 2026 — Source

Transilience AI unveils Security Operating System for cloud remediation
New platform replaces fragmented tool sprawl with an agent-powered, human-guided second brain, moving security posture from Detected to Eliminated.
May 8th, 2026 — Source

Trellix source code breach claimed by RansomHouse hackers
The attack on the Trellix source code repository disclosed last week has been claimed by the RansomHouse threat group, which leaked a small set of images as proof of the intrusion.
May 8th, 2026 — Source

Why More Analysts Won't Solve Your SOC's Alert Problem
Your security spend has roughly doubled in six years. Your time-to-investigate and respond hasn't moved. Your CFO is asking why the security headcount keeps growing while the metrics that matter to the business don't.
May 8th, 2026 — Source

Why organizations need to close the 'cybersecurity culture gap' [Q&A]
As AI agents become embedded across the enterprise, and cyber teams face record levels of burnout, security leaders are confronting an uncomfortable reality, that human error isn't going away it's becoming harder to control.
May 8th, 2026 — Source

Zara data breach exposed personal information of 197,000 people
Hackers who gained access to the databases of Spanish fast-fashion retailer Zara stole data belonging to more than 197,000 customers, according to data breach notification service Have I Been Pwned.
May 8th, 2026 — Source

Internet — Security Issues — May 7th, 2026

$250M crypto-robbing gang's dirty work guy sentenced to 6.5 years behind bars
The then-teen was told to break in and steal what the keyboard warriors couldn't
May 7th, 2026 — Source

A data centre fire in Almere disabled a university, a transport emergency system, and the assumption that physical infrastructure is someone else's problem
A data centre fire in Almere disabled a university, a transport emergency system, and the assumption that physical infrastructure is someone else's problem
May 7th, 2026 — Source

A student halted multiple Taiwan bullet trains by spoofing the rail network's emergency radio signals
Police say the 23-year-old decoded rail radio parameters and used handheld devices to trigger an emergency alarm
May 7th, 2026 — Source

Americans sentenced for running 'laptop farms' for North Korea
Two U.S. nationals were sentenced to 18 months in prison each for operating so-called laptop farms that helped North Korean IT workers fraudulently obtain remote employment at nearly 70 American companies.
May 7th, 2026 — Source

Attackers Could Exploit AI Vision Models Using Imperceptible Image Changes
Cisco's AI security researchers have analyzed ways to target vision-language models (VLMs) using pixel-level perturbation.
May 7th, 2026 — Source

Best VPN for Utah residents in 2026
How to keep your browsing private and still access the website once it's blocked in the Beehive State.
May 7th, 2026 — Source

Boost Security Raises $4 Million for SDLC Defense Platform
The company is expanding its platform's capabilities with the acquisition of SecureIQx and Korbit.ai.
May 7th, 2026 — Source

Cisco Patches High-Severity Vulnerabilities in Enterprise Products
Successful exploitation of the flaws could lead to code execution, server-side request forgery attacks, and denial-of-service conditions.
May 7th, 2026 — Source

Claude AI Guided Hackers Toward OT Assets During Water Utility Intrusion
Dragos has published a report describing how threat actors used Claude AI in an attack on a water and drainage utility in Mexico.
May 7th, 2026 — Source

Claude Code OAuth Tokens Can Be Stolen Through Stealthy MCP Hijacking
Mitiga researchers say attackers can silently redirect Claude Code MCP traffic, intercept OAuth tokens, and maintain persistent access to connected SaaS platforms.
May 7th, 2026 — Source

College student hacks Taiwan high-speed rail line with software defined radios, stopping four trains — 19 years without crypto key rotation ends in predictable result as hacker sails through 7 layers of protection
Hacking an open barn door doesn't take effort, but it can be done responsibly.
May 7th, 2026 — Source

Crypto gang member gets 6.5 years for role in $230 million heist
A 20-year-old California man was sentenced to 78 months in prison for serving as a home invader and money launderer in a criminal ring that stole over $250 million in cryptocurrency.
May 7th, 2026 — Source

ESET Home Security Premium review: Simple protection with a complex heart
Power users will appreciate the app's granular settings.
May 7th, 2026 — Source

Fake Claude AI website delivers new 'Beagle' Windows malware
A fake version for the Claude AI website offers a malicious Claude-Pro Relay download that pushes a previously undocumented backdoor for Windows named Beagle.
May 7th, 2026 — Source

Gemini CLI Vulnerability Could Have Led to Code Execution, Supply Chain Attack
Attackers could inject prompts into a GitHub issue and take over the AI agent designed to automatically triage the issue.
May 7th, 2026 — Source

How Anthropic's Mythos has rewritten Firefox's approach to cybersecurity
When Anthropic unveiled its new Mythos model in April, it also delivered a stern warning to anyone developing software. The model was so powerful at sniffing out software vulnerabilities, the lab claimed, that it had discovered thousands of high-severity bugs that would need to be fixed before it could be made public.
May 7th, 2026 — Source

Hungarian cops cuff suspected swatter after two-year FBI probe
20-year-old fessed up after investigators found video of crime in progress
May 7th, 2026 — Source

Ivanti warns of new EPMM flaw exploited in zero-day attacks
Ivanti warned customers today to patch a high-severity remote code execution vulnerability in Endpoint Manager Mobile (EPMM) exploited in zero-day attacks.
May 7th, 2026 — Source

Operation Fake Mustache: Kids Bypass UK's Digital Age Barriers
Kids used to draw on their faces for fun. Now, they're doing it so they can play Roblox.
May 7th, 2026 — Source

Palo Alto Networks firewall zero-day exploited for nearly a month
Palo Alto Networks warned customers that suspected state-sponsored hackers have been exploiting a critical-severity PAN-OS firewall zero-day vulnerability for nearly a month.
May 7th, 2026 — Source

Palo Alto Zero-Day Exploited in Campaign Bearing Hallmarks of Chinese State Hacking
The cybersecurity firm has not explicitly accused China of being behind the attack, but the evidence suggests it was.
May 7th, 2026 — Source

Police arrest SMS blaster crew that sent malicious messages to thousands across Toronto
Police have arrested and brought 44 charges against three men for allegedly operating an SMS blaster in downtown Toronto. The scheme, which began in November 2025, is the "first known instance" of an SMS blaster operating in Canada, according to the police report.
May 7th, 2026 — Source

Security Lost The Speed War: Context Is How We Win
AI-Driven Attacks Compress Breakout Times, Forcing Defenders to Rely on Context Now
May 7th, 2026 — Source or Source or Source or Source

State-backed hackers hammer Palo Alto firewall zero-day before patch lands
Internet-facing PAN-OS firewalls are once again doing impressions of initial access brokers
May 7th, 2026 — Source

The Browser Is Breaking Your DLP: How Data Slips Past Modern Controls
Preventing sensitive data loss has historically been treated as an endpoint or network problem. Deploy an agent, inspect files, monitor traffic, and you have coverage—or so you think.
May 7th, 2026 — Source

The largest education data breach in history was not an attack on a school. It was an attack on a vendor.
ShinyHunters breached Instructure's Canvas learning management system, claiming 3.65 terabytes of data from 275 million users across 9,000 institutions worldwide, including private messages between students and teachers. Forty-four Dutch universities and schools are confirmed affected, and the breach, the second at Instructure in eight months, exposes the structural risk of vendor concentration in education technology.
May 7th, 2026 — Source

The network password was a key plot point in one of the most famous movies of all time
Fortunately, it was a legit contractor who guessed it
May 7th, 2026 — Source

Vendor Says Daemon Tools Supply Chain Attack Contained
The software developer has identified the impacted systems, removed potentially compromised files, and validated installation packages.
May 7th, 2026 — Source

What really happens to leaked credentials?
We all know that cybercriminals are keen to steal login credentials as a path to carrying out more destructive attacks in search of money or data. But what actually happens to passwords after they're stolen?
May 7th, 2026 — Source

World Password Day: Fix these 4 security mistakes before hackers find them
This holiday is worth attention, unlike most spun out of thin air.
May 7th, 2026 — Source

Internet — Security Issues — May 4th, 2026

5 Windows Defender settings I change ASAP on any new PC
All Windows PCs use Microsoft's antivirus by default.
May 4th, 2026 — Source

A Vulnerability in WHM cPanel and WP Squared Could Allow for Remote Code Execution
A vulnerability has been discovered in WHM, cPanel, and WP Squared that could allow for remote code execution. WHM, cPanel, and WP Squared are Linux-based web hosting control panels for server and website management. While WHM provides server-level control, cPanel provides administrator access to the website backend, webmail, and databases. Successful exploitation could allow unauthenticated remote attackers to bypass authentication and gain unauthorized administrative access to the affected systems, ultimately leading to remote code execution.
May 4th, 2026 — Source

Backdoored PyTorch Lightning package drops credential stealer
A malicious version of the PyTorch Lightning package published on the Python Package Index (PyPI) delivers a credential-stealing payload targeting browsers, environment files, and cloud services.
May 4th, 2026 — Source

Best free password managers 2026: Online security doesn't have to cost a thing
Shore up your defenses, stat.
May 4th, 2026 — Source

Canvas Breach May Put 275M Users, 9,000 Schools at Risk
Instructure confirms a Canvas breach involving user information and messages as hackers claim 275M users and nearly 9,000 schools were affected.
May 4th, 2026 — Source

CISA flags actively exploited 'Copy Fail' Linux kernel flaw enabling root takeover across major distros — unpatched systems may remain vulnerable to attack
Researchers released a working exploit before patches were ready.
May 4th, 2026 — Source or Source

Cloudflare Processes 10M+ Daily Insights with New Security Overview Dashboard
Cloudflare has launched a revamped Security Overview dashboard designed to consolidate fragmented security signals into a single interface that emphasizes actionable insights over raw data visibility. The update addresses a longstanding challenge in security operations, quickly identifying what requires immediate attention without navigating multiple tools or dashboards.
May 4th, 2026 — Source

Cybersecurity M&A Roundup: 33 Deals Announced in April 2026
Significant cybersecurity M&A deals announced by Airbus, Cyera, Fortra, Palo Alto Networks, Silverfort, and Socket.
May 4th, 2026 — Source

DigiCert Revokes Certificates After Support Portal Hack
Hackers delivered malware via a customer chat channel, infected an analyst's system, and accessed the internal support portal.
May 4th, 2026 — Source

Edtech Firm Instructure Discloses Data Breach Amid Hacker Leak Threats
Hackers disrupted services and stole names, email addresses, student ID numbers, and user messages.
May 4th, 2026 — Source

Europe Cuts Off Funding for Chinese Solar Inverters
Solar Energy Spurt Comes Freighted With Chinese Nation-State Hacking Worries
May 4th, 2026 — Source or Source

Europe's finance chiefs want Mythos access to defend their banks. Washington has so far said no.
An Anthropic AI model that can find zero-days in every major operating system has become a geopolitical and prudential question. The Eurogroup met in Brussels on Monday with no answer in hand.
May 4th, 2026 — Source

Exploitation of 'Copy Fail' Linux Vulnerability Begins
CISA has added the bug to its KEV list, and Microsoft has observed limited exploitation, mainly associated with PoC testing.
May 4th, 2026 — Source

Hospital websites are still leaking patient data to advertisers, four years after the warnings
A new Bloomberg-Feroot investigation finds that nine of the 10 largest US health companies are still loading advertising trackers on the very pages where patients log in and register. The story keeps repeating because nothing has stopped it.
May 4th, 2026 — Source

If the vote you rocked, your personal info can be grokked
If the vote you rocked, your personal info can be grokked
May 4th, 2026 — Source

Instructure data breach: ShinyHunters says it stole data and private messages from 275 million teachers and students
ShinyHunters has struck yet again.
May 4th, 2026 — Source

Mythos AI is a cybersecurity threat, but it doesn't rewrite the rules of the game
The cybersecurity community went on alert when Anthropic announced on April 7, 2026, that its latest and most capable general-purpose large language model, Claude Mythos Preview, had demonstrated remarkable—and unintended—capabilities. The artificial intelligence system was able to find and exploit software vulnerabilities—the most serious type of software bugs—at a rate not seen before.
May 4th, 2026 — Source

OpenAI Rolls Out Advanced Security for ChatGPT Accounts
Advanced Account Security provides stronger login methods, more secure account recovery, shorter sessions, and training exclusion.
May 4th, 2026 — Source

Over 40,000 Servers Compromised in Ongoing cPanel Exploitation
The attacks likely target CVE-2026-41940, a recently patched zero-day leading to administrative access.
May 4th, 2026 — Source

Progress warns of critical MOVEit Automation auth bypass flaw
Progress Software warned customers to patch a critical authentication bypass vulnerability in its MOVEit Automation enterprise-grade managed file transfer (MFT) application.
May 4th, 2026 — Source

Securing the IT and OT Boundary in Geospatial Enterprise Systems
Enterprise GIS platforms blend IT & OT, offering vital operational insight. To protect critical systems, secure the boundary with zero-trust principles and segmentation.
May 4th, 2026 — Source

They don't hack, they borrow: How fraudsters target credit unions
Threat actors across underground forums and chat groups are increasingly crafting structured fraud methods aimed at exploiting weaknesses in work processes of financial institutions. Rather than isolated or opportunistic scams, these discussions reflect an organized, process-driven approach that combines stolen identity data, social engineering, and knowledge of financial workflows.
May 4th, 2026 — Source

Think online ads are harmless? They could be revealing your private life, say researchers
A new study has uncovered a significant and largely invisible privacy risk in the online advertising ecosystem: the ads you see may be enough to reveal sensitive personal information.
May 4th, 2026 — Source

Trellix discloses data breach after source code repository hack
Cybersecurity firm Trellix disclosed a data breach after attackers gained access to "a portion" of its source code repository.
May 4th, 2026 — Source

Trellix Source Code Repository Breached
The cybersecurity firm's investigation has not found any impact on its source code release or distribution process.
May 4th, 2026 — Source

Utah just passed the first US law targeting VPN use for age verification
A new Utah law assumes websites can detect VPNs and find your real location. They can't.
May 4th, 2026 — Source

Internet — Security Issues — April 27th, 2026

Anthropic's magic code-sniffer: More Swiss cheese than cheddar, for now
AI vuln-hunter finds what humans taught it to find. Funny that
April 27th, 2026 — Source

Best antivirus for Windows PC in 2026: 7 apps to keep your PC safe
You need more than just prayer and luck—choose from our top antivirus software picks to stay safe.
April 27th, 2026 — Source

Bitdefender Total Security review: Great, easy to use protection
Not all of this security suite's features are useful, though.
April 27th, 2026 — Source

Burglar alarm biz burgled: ADT confirms cyber intrusion after ShinyHunters extortion attempt
Security giant says attackers grabbed 'limited set' of data. Crooks claim 10 million records
April 27th, 2026 — Source

China blocks Meta's $2 billion Manus deal over national security concerns
China is tightening its grip on homegrown AI tech
April 27th, 2026 — Source

Critical infrastructure giant Itron says it was hacked
American energy technology company Itron has confirmed it was hit by a cyberattack in mid-April and that hackers had gained access to some of its systems.
April 27th, 2026 — Source

Cybersec is a thankless job: expanding workload and shrinking pay packet
Global recruitment giant says 71% of human firewalls saw wages stagnate last year as threats and responsibilities grew
April 27th, 2026 — Source

Energy and Water Management Firm Itron Hacked
Itron, which serves utilities and cities around the world, discovered unauthorized access to its systems on April 13.
April 27th, 2026 — Source

FTC: Americans lost over $2.1 billion to social media scams in 2025
The U.S. Federal Trade Commission (FTC) warned of a massive increase in losses from social media scams since 2020, exceeding $2.1 billion in 2025.
April 27th, 2026 — Source

Home Security Firm ADT Breach: 5.5M Customers' Data Exposed
Prolific ShinyHunters Extortion Group Made 'Pay or Leak' Threat to Victim
April 27th, 2026 — Source or Source or Source

Incomplete Windows Patch Opens Door to Zero-Click Attacks
The initial vulnerability was exploited by Russia-linked APT28 in attacks against Ukraine and EU countries.
April 27th, 2026 — Source

Instagram Adds Artificial Intelligence Video Tools to Its Edits App
Instagram is introducing a new artificial intelligence video generation tool inside its standalone Edits application. It is designed this feature to help creators build video clips from scratch without needing to record original footage with a camera. Users across the United States can now simply type out a detailed text description or upload existing photos and videos to generate custom media directly on their mobile phones.
April 27th, 2026 — Source

Is Adult Friend Finder safe to use? What a cybersecurity expert says.
To better understand the risks of using AdultFriendFinder, we consulted an expert from Kaspersky.
April 27th, 2026 — Source

Is Your IAM Ready for AI?
The rapid evolution of Artificial Intelligence has created a dual-edged sword for IT and security leaders. While AI agents offer unprecedented opportunities for operational efficiency, they also introduce sophisticated threats and complex identity management challenges.
April 27th, 2026 — Source or Source or Source

Malicious AI Prompt Injection Attacks Increasing, but Sophistication Still Low: Google
The tech giant found that many indirect prompt injection attempts are harmless, but some malicious exploits have also been identified.
April 27th, 2026 — Source

Medtronic confirms breach after hackers claim 9 million records theft
Medical device giant Medtronic disclosed last week that hackers breached its network and accessed data in "certain corporate IT systems."
April 27th, 2026 — Source

Money launderer linked to $230M crypto heist gets 70 months in prison
​22-year-old Evan Tangeman of Newport Beach, California, was sentenced to 70 months in prison for laundering funds stolen in a massive $230 million cryptocurrency heist.
April 27th, 2026 — Source

OpenSSH Flaw Allowing Full Root Shell Access Lurked for 15 Years
A code reuse issue enabled comma characters in certificate principals to be interpreted as list separators.
April 27th, 2026 — Source

Security Readiness Checklist: From AI Threats to Software Supply Chain Defense
Detect APTs with behavioral analytics and log correlation, building baselines and linking events to turn weak signals into actionable security detections.
April 27th, 2026 — Source

Streamline User Journeys with Verified Email via Credential Manager
In the modern digital landscape, the first encounter a user has with an app is often the most critical. Yet, for decades, this initial interaction has been hindered by the friction of traditional verification methods. Today, we're excited to announce a new verified email credential issued by Google, which developers can now retrieve directly from Android's Credential Manager Digital Credential API.
April 27th, 2026 — Source

Sync.com review: Superb online device sync and backup
This online storage service syncs your files across multiple devices but also allows you to back up to its single device vault.
April 27th, 2026 — Source

The FBI Says Warrant-Proof Encryption Is A Public Safety Problem - Here's What It Means
The FBI is vocally upset that tech companies won't make it easier to seize your private messages and data. That's made clear in a blog post from the agency decrying what it refers to as "warrant-proof encryption." You may know this technology better as end-to-end encryption, or E2EE. It's the reason your texts on iMessage or Google Messages can't be stolen by attackers if Apple or Google get hacked. It's a tool that allows journalists to report on those in power while keeping sources protected, and it allows political dissidents living under oppressive regimes to organize.
April 27th, 2026 — Source

UNC6692 Uses Email Bombing, Social Engineering to Deploy 'Snow' Malware
The threat actor infected victims with the Snow malware family -- Snowbelt, Snowglaze, and Snowbasin -- for persistent access.
April 27th, 2026 — Source

US Launches Sweeping Crackdown on Southeast Asia Cyberscams and Sanctions Cambodian Senator
US conducts sweeping crackdown on Southeast Asian cyberscam operations as part of what officials say is a "new theater of war".
April 27th, 2026 — Source

Internet — Security Issues — April 26th, 2026

American utility firm Itron discloses breach of internal IT network
Utility technology company Itron, Inc. has disclosed that an unauthorized third party accessed some of its internal systems during a cyberattack.
April 24th, 2026 — Source

Chernobyl virus turned 27 today, and it could brick your PC in ways modern malware can't by overwriting BIOS firmware
CIH was one of the first viruses capable of destroying hardware by overwriting BIOS firmware.
April 24th, 2026 — Source

Internet — Security Issues — April 24th, 2026

Bitwarden NPM Package Hit in Supply Chain Attack
Tied to a fresh Checkmarx supply chain attack claimed by TeamPCP, the incident references the Shai-Hulud worm.
April 24th, 2026 — Source

Chrome 147 update fixes two high-risk security vulnerabilities
The latest Chrome 147 security update patches 19 security vulnerabilities, two of which are high risk and one medium risk.
April 24th, 2026 — Source

Copperhelm Raises $7 Million for Agentic Cloud Security Platform
The Israel-based company, which just emerged from stealth mode, was founded by cloud and security experts from RSA, McAfee, and Unity.
April 24th, 2026 — Source

DORA and operational resilience: Credential management as a financial risk control
When a threat actor walks into your network using a legitimate username and password, which control stops them?
April 24th, 2026 — Source

Flurry of Supply-Chain Software Library Attacks
Continuous Integration Has Its Downsides
April 24th, 2026 — Source or Source

Health Records of 500,000 UK Biobank Volunteers Listed Online in China
Health data from 500,000 UK Biobank participants was found listed for sale online in China, raising concerns over research access misuse and data security.
April 24th, 2026 — Source

How a cavalcade of blunders gave unauthorized users access to Claude Mythos — restricted model accessed by third parties, thanks to knowledge from data breach
It's hard for AI tools to prevent social engineering and third-party hacks.
April 24th, 2026 — Source

In Other News: Unauthorized Mythos Access, Plankey CISA Nomination Ends, New Display Security Device
Other noteworthy stories that might have slipped under the radar: Supreme Court hacker sentenced, Lovable exposed user data, Google expands enterprise security.
April 24th, 2026 — Source

Locked Shields 2026: 41 Nations Strengthen Cyber Resilience in World's Biggest Exercise
Locked Shields has grown significantly over the past 16 years, with only four nations participating in the first edition.
April 24th, 2026 — Source

McAfee Total Protection review: Top security undermined by a major feature
The interface could use a touch more refinement, too.
April 24th, 2026 — Source

Microsoft beefs up Remote Desktop security with ... hard-to-read messages
Ailing scaling blamed by Windows-maker for unreadable missives
April 24th, 2026 — Source

New BlackFile extortion group linked to surge of vishing attacks
A new financially motivated hacking group tracked as BlackFile has been linked to a wave of data theft and extortion attacks against retail and hospitality organizations since February 2026.
April 24th, 2026 — Source

Over 10,000 Zimbra servers vulnerable to ongoing XSS attacks
Over 10,000 Zimbra Collaboration Suite (ZCS) instances exposed online are vulnerable to ongoing attacks exploiting a cross-site scripting (XSS) security flaw, according to nonprofit security organization Shadowserver.
April 24th, 2026 — Source

Pre-Stuxnet Sabotage Malware 'Fast16' Linked to US-Iran Cyber Tensions
It targeted high-precision calculation software to tamper with results and packed a self-propagation mechanism.
April 24th, 2026 — Source

Ransomware groups are using "post-quantum" hype to intimidate victims
Quantum-resistant ransomware may be more marketing stunt than cryptographic leap
April 24th, 2026 — Source

Trump Administration Vows Crackdown on Chinese Companies 'Exploiting' AI Models Made in US
The Trump administration is vowing to crack down on foreign tech companies' exploitation of U.S. artificial intelligence models.
April 24th, 2026 — Source

US Federal Agency's Cisco Firewall Infected With 'Firestarter' Backdoor
The malware provides remote access and control of infected devices and maintains post-patching persistence.
April 24th, 2026 — Source

Vulnerabilities Patched in CrowdStrike, Tenable Products
CrowdStrike has fixed a critical LogScale vulnerability, while Tenable addressed a high-severity Nessus flaw.
April 24th, 2026 — Source

Weak IoT security could make EV chargers vulnerable to mass shutdowns
Predictable device IDs and weak authentication could let attackers knock public charging networks offline
April 24th, 2026 — Source

What Is Cloud Security? A 2026 Guide
Learn what cloud security is, why it matters in 2026, and the best practices for protecting data, identities, workloads, and cloud infrastructure.
April 24th, 2026 — Source

White House Warns of AI Model 'Extraction' Campaigns
Agencies Urged to Track and Disrupt Coordinated AI Extraction Campaigns
April 24th, 2026 — Source or Source or Source or Source

Why Cybersecurity Must Rethink Defense in the Age of Autonomous Agents
From autonomous code generation to decision-making systems that initiate actions without human intervention, the industry is entering a new phase.
April 24th, 2026 — Source

Internet — Security Issues — April 23rd, 2026

Age checks could turn internet into an ID checkpoint, complains Proton CEO
Push to protect minors risks hitting everyone online
April 23rd, 2026 — Source

AI Can Autonomously Hack Cloud Systems With Minimal Oversight: Researchers
Palo Alto Networks has developed Zealot, a multi-agent penetration testing PoC capable of reconnaissance, exploitation, and exfiltration.
April 23rd, 2026 — Source

Another customer of troubled startup Delve suffered a big security incident
The story of embattled compliance startup Delve keeps hitting twists and turns.
April 23rd, 2026 — Source

Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950)
Apple has rolled out security updates for iPhones and iPads that fix CVE-2026-28950, a logging issue in Notification Services that made devices unexpectedly retain notifications marked for deletion.
April 23rd, 2026 — Source

Apple Patches iOS Flaw Allowing Recovery of Deleted Chats
Apple rolled out the security patches for dozens of iPhone and iPad models and generations.
April 23rd, 2026 — Source

Apple Releases iOS 26.4.2 To Fix A Critical Settings Security Flaw
Apple released iOS 26.4.2 today for iPhone users in the United States and globally. This update arrives primarily to address lingering software bugs and close a significant security vulnerability. Minor point releases often focus purely on background optimization, but this specific download carries serious weight due to the nature of the patched exploit. You should install the update promptly to protect your personal data.
April 23rd, 2026 — Source

Aqua Compass MCP server enables real-time investigation and containment of runtime threats
Aqua Security has announced Aqua Compass, a Model Context Protocol (MCP) server that enables agentic investigation, containment and remediation of runtime incidents, and new runtime risk dashboards. These capabilities help security teams move beyond identifying risk and focus on containing threats in running applications.
April 23rd, 2026 — Source

Attackers adapt phishing tactics to avoid detection
As scanners become more effective at identifying newly created domains, cybercriminals are adapting their phishing tactics by relying more on familiar, reputable domains to avoid detection.
April 23rd, 2026 — Source

Chinese Cyersecurity Firm's AI Hacking Claims Draw Comparisons to Claude Mythos
360 Digital Security Group claims to have uncovered 1,000 vulnerabilities using AI, including at the Tianfu Cup hacking contest.
April 23rd, 2026 — Source

CISA orders feds to patch BlueHammer flaw exploited as zero-day
CISA has given U.S. government agencies two weeks to secure their Windows systems against a Microsoft Defender privilege escalation vulnerability that has been exploited in zero-day attacks.
April 23rd, 2026 — Source

Cloudsmith Raises $72 Million in Series C Funding
The company will use the investment to accelerate product development and grow go-to-market efforts.
April 23rd, 2026 — Source

Cosmetics giant Rituals discloses data breach affecting customers
Dutch cosmetics giant Rituals disclosed a data breach after attackers stole the personal information of an undisclosed number of customers from its "My Rituals" membership database.
April 23rd, 2026 — Source

Cryptohack Roundup: US-Sanctioned Grinex Hacked
Also: Updates in KelpDAO, Drift, Hyperbridge Hacks
April 23rd, 2026 — Source or Source

Device code phishing targets Microsoft 365 and Entra ID
New data from Barracuda Networks shows device code phishing is on the rise with seven million attacks detected in just four weeks. The EvilTokens phishing kit is driving this surge, targeting Microsoft 365 and Entra ID environments.
April 23rd, 2026 — Source

Google brings instant email verification to Android, no OTP needed
Google has introduced cryptographically verified email credentials for Android through the Credential Manager API. This API aligns with the W3C Digital Credential API standard. It provides a unified way for apps to request and retrieve user credentials for authentication and authorization.
April 23rd, 2026 — Source

GopherWhisper APT group hides command and control traffic in Slack and Discord
Attackers continue to lean on everyday collaboration platforms to hide command and control traffic inside normal enterprise noise. A newly identified China-aligned APT group pushes that trend further, running its operations through Slack workspaces, Discord servers, Outlook drafts, and the file.io sharing service.
April 23rd, 2026 — Source

Hacker with a special interest in breaching sports institutions ends behind bars
French police have arrested a suspected hacker linked to a series of data breaches affecting organizations in the country.
April 23rd, 2026 — Source

How McAfee Helped Me Tidy Up Decades of Digital Detritus
McAfee's online account cleanup tool makes it easy to eliminate accounts you're not using anymore -- even accounts you've forgotten exist.
April 23rd, 2026 — Source

Hybrid clouds have two attack surfaces and you're not paying enough attention to either
Windows Admin Center flaws mean on-prem can attack cloud, and vice-versa
April 23rd, 2026 — Source

If cyber espionage via HDMI worries you, NCSC built a device to stop it
A new cybersecurity device developed by the National Cyber Security Centre (NCSC) should be a helpful solution for protecting governments and businesses from malicious activity carried through display connections.
April 23rd, 2026 — Source

If malware via monitor cables is a matter of national security, this might be the gadget for you
Orgs can now buy UK cyber agency engineered commercial gadget, but details are slim
April 23rd, 2026 — Source

IP Fabric MCP server adds governance and control to enterprise AIOps workflows
IP Fabric has launched a new Model Context Protocol (MCP) server that removes key barriers to enterprise AIOps adoption, combining secure in-platform deployment with a built-in prompt library for network operations.
April 23rd, 2026 — Source

Is your Node.js project really secure?
JavaScript and Node.js teams do not lack security tools. What they still lack is a dependency security workflow that developers will actually use before release.
April 23rd, 2026 — Source

Luxury Cosmetics Giant Rituals Discloses Data Breach
The company is notifying My Rituals members that hackers downloaded part of their data, including names and addresses.
April 23rd, 2026 — Source

Master Claude AI Prompting: 4-Block Formula for Better Outputs
Claude's advanced AI capabilities can be unlocked with the right approach to prompt design, as demonstrated by AI Master. One key strategy highlighted is the Four-Block Formula, which organizes prompts into instructions, context, task and output format. This method ensures clarity and focus, allowing Claude to deliver more accurate and tailored responses. By addressing common pitfalls such as vague inputs or undefined context, users can significantly enhance the quality of their interactions with the model.
April 23rd, 2026 — Source

Medical data of 500k Biobank volunteers listed for sale on Alibaba, UK minister reveals
World's largest biomedical dataset lifted and shifted on Chinese mega marketplace
April 23rd, 2026 — Source

Microsoft launches hosted agents in Foundry with secure sandboxes
Microsoft has launched the preview of hosted agents within the Foundry Agent Service, to streamline the lifecycle of AI agents.
April 23rd, 2026 — Source

Microsoft taps Anthropic's Mythos to strengthen secure software development
The move is a clear signal that powerful AI models are making inroads into real software security work.
April 23rd, 2026 — Source

New Checkmarx supply-chain breach affects KICS analysis tool
Hackers have compromised Docker images, VSCode and Open VSX extensions for the Checkmarx KICS analysis tool to harvest sensitive data from developer environments.
April 23rd, 2026 — Source

New GopherWhisper APT group abuses Outlook, Slack, Discord for comms
A previously undocumented state-backed threat actor named GopherWhisper is using a Go-based custom toolkit and legitimate services like Microsoft 365 Outlook, Slack, and Discord in attacks against government entities.
April 23rd, 2026 — Source

Norton 360 Deluxe review: Excellent value and strong protection
Norton 360 Deluxe is a great product overall, but mid-range and budget PCs can see a dip in performance.
April 23rd, 2026 — Source

Offer customers passkeys by default, UK's NCSC tells enterprises
Developers of enterprise apps and websites will need to get to grips with passkeys: The UK's National Cyber Security Center the agency recommends them for their resistance to phishing and credential reuse, and warns that passwords are inherently vulnerable.
April 23rd, 2026 — Source

One Tech Tip: Logging on at a cafe? Privacy and security guidelines for remote workers
For digital nomads, logging on to work from a cafe, co-working space, hotel lobby or airport lounge is a way of life.
April 23rd, 2026 — Source

OpenAI tackles a bad habit people have when interacting with AI
Since people tend to paste personal data into AI tools such as ChatGPT, OpenAI has released Privacy Filter, an open-weight model designed to detect and redact personally identifiable information (PII) in text. The model is available under the Apache 2.0 license on Hugging Face and GitHub.
April 23rd, 2026 — Source

Pass the key, passwords have passed their sell-by date
NCSC passes judgment: passkeys pass muster, passwords fail
April 23rd, 2026 — Source

Recent Microsoft Defender Vulnerability Exploited as Zero-Day
The flaw allows attackers to access the SAM database, extract NTLM hashes, and gain System privileges.
April 23rd, 2026 — Source

Regular Password Resets Aren't as Safe as You Think
Research from Forrester estimates that every password reset costs around $70. As one of the most common helpdesk requests, many organizations have introduced self-service password reset (SSPR) tools to reduce the load. However, despite these tools, helpdesk teams still handle a significant number of password resets, whether it's supporting SSPR enrollment or dealing with edge cases.
April 23rd, 2026 — Source

Rilian Raises $17.5 Million for AI-Native Security Orchestration
The company will hire new talent and expand operations across the US and other allied countries.
April 23rd, 2026 — Source

Surveillance vendors caught abusing access to telcos to track people's phone locations, researchers say
Security researchers have uncovered two separate spying campaigns that are abusing well-known weaknesses in the global telecoms infrastructure to track people's locations. The researchers say these two campaigns are likely a small snapshot of what they believe to be widespread exploitation of surveillance vendors seeking access to global phone networks.
April 23rd, 2026 — Source

The Behavioral Shift: Why Trusted Relationships Are the Newest Attack Surface
New analysis from Abnormal AI reveals how attackers have abandoned technical exploits to weaponize routine workflows and internal trust.
April 23rd, 2026 — Source

UK spy agency releases malware-blocking gadget for HDMI and DisplayPort cables — SilentGlass blocks malicious traffic traveling between display and computer
This device is designed to protect against advanced cyberattacks that utilize video signals from the target computer.
April 23rd, 2026 — Source or Source

UK Cyber Spooks: 'Is Your Computer Monitor Spying On You?'
NCSC Designs 'SilentGlass' Gadget to Protect Overlooked Computer Peripheral
April 23rd, 2026 — Source or Source or Source or Source

Unwary Chinese Hackers Hardcoded Credentials into Backdoors
Eset Researchers Discover Trove of Go-Based Malware
April 23rd, 2026 — Source or Source or Source or Source

Using the password 'admin123' wasn't as bad as sharing it on Slack
Keeping it simple for the developers can lead to very complex headaches later
April 23rd, 2026 — Source

Vercel says some of its customers' data was stolen prior to its recent hack
App and website hosting giant Vercel on Thursday said hackers had accessed some of its customers' data before the company discovered its recent data breach, suggesting that this incident may have broader security implications than initially known.
April 23rd, 2026 — Source

Internet — Security Issues — April 21st, 2026

$290 Million Kelp DAO Crypto Heist Blamed on North Korea
The hackers targeted LayerZero's DVN, compromising certain RPCs and DDoSing others to trigger failover to the poisoned infrastructure.
April 21st, 2026 — Source

Adaptavist Group breach spawns imposter emails as ransomware crew claims mega-haul
Fake emails already doing the rounds as ransomware crew boasts about what it allegedly stole
April 21st, 2026 — Source

AI-assisted intruders pwned Vercel via OAuth abuse and a pilfered employee account
CEO suspects silicon sidekick behind 'surprising velocity' breach - cyber crims shop stolen data for $2M
April 21st, 2026 — Source

Actively exploited Apache ActiveMQ flaw impacts 6,400 servers
Nonprofit security organization Shadowserver found that over 6,400 Apache ActiveMQ servers exposed online are vulnerable to ongoing attacks exploiting a high-severity code injection vulnerability.
April 21st, 2026 — Source

CISA flags new SD-WAN flaw as actively exploited in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given government agencies four days to secure their systems against another Catalyst SD-WAN Manager vulnerability it flagged as actively exploited in attacks.
April 21st, 2026 — Source

Contrary to popular superstition, AES 128 is just fine in a post-quantum world
A stubborn misconception is hampering the already hard work of quantum readiness.
April 21st, 2026 — Source

Crook claims to leak 'video surveillance footage' of companies
Mexican IT services firm admits it was hacked, but says client operations weren't affected
April 21st, 2026 — Source

Data Breaches at Healthcare Organizations in Illinois and Texas Affect 600,000Data breaches were disclosed by Southern Illinois Dermatology, Saint Anthony Hospital, and North Texas Behavioral Health Authority.
The devices would reportedly record video and collect the biometric data of migrants and protesters.
April 21st, 2026 — Source

Even trusted apps can spread PC malware now
You can do everything properly and still get rolled by life.
April 21st, 2026 — Source

Former ransomware negotiator pleads guilty to BlackCat attacks
41-year-old Angelo Martino, a former employee of cybersecurity incident response company DigitalMint, has pleaded guilty to targeting U.S. companies in BlackCat (ALPHV) ransomware attacks in 2023.
April 21st, 2026 — Source

Homeland Security reportedly wants to develop smart glasses for ICE
The devices would reportedly record video and collect the biometric data of migrants and protesters.
April 21st, 2026 — Source

Met police trials snoop tech platform in push to cuff more London shoplifters
No facial recognition privacy intrusions either! Well, maybe a little
April 21st, 2026 — Source

NGate Android malware uses HandyPay NFC app to steal card data
A new variant of the NGate malware that steals NFC payment data is targeting Android users by hiding in a trojanized version of HandyPay, a legitimate mobile payments processing tool.
April 21st, 2026 — Source

Organizations Warned of Exploited Cisco, Kentico, Zimbra Vulnerabilities
CISA expanded the KEV catalog with eight flaws, but five of them have been flagged as exploited before.
April 21st, 2026 — Source

Panasonic creates device-locked QR codes to speed facial biometric capture
Admins are tired of taking photos, so this enables secure on-site unattended enrolment
April 21st, 2026 — Source

Progress Patches Multiple Vulnerabilities in MOVEit WAF, LoadMaster
The security defects could be exploited for remote code execution, OS command injection, and WAF detection bypass.
April 21st, 2026 — Source

Stopping Fraud at Each Stage of the Customer Journey Without Adding Friction
Fraud prevention and user experience have long been treated as opposing forces: tighten security, and you risk alienating legitimate customers; loosen it, and you open the door to account takeovers, synthetic identities, and payment fraud. But modern threat intelligence platforms are dismantling that false choice.
April 21st, 2026 — Source

Third US Security Expert Admits Helping Ransomware Gang
Angelo Martino of Florida has pleaded guilty to collaborating with the BlackCat cybercrime group while working as a ransomware negotiator.
April 21st, 2026 — Source

Unpatched Microsoft Defender Flaw Lets Hackers Gain Admin Access on Windows
The exploit takes advantage of the way Defender handles high‑privilege tasks.
April 21st, 2026 — Source

Unsecured Perforce Servers Expose Sensitive Data From Major Orgs
Things are improving, but a researcher has still identified over 1,500 Perforce P4 instances allowing attackers to read files on the server.
April 21st, 2026 — Source

UK probes Telegram, teen chat sites over CSAM sharing concerns
Ofcom, the United Kingdom's independent communications regulator, has launched an investigation into Telegram based on evidence suggesting it's being used to share child sexual abuse material (CSAM).
April 21st, 2026 — Source

Why Anthropic is Restricting Its New Mythos AI Model to Tech Giants
Anthropic's Mythos AI model represents a significant development in artificial intelligence, designed to handle complex reasoning, autonomous coding and extended task execution. A notable aspect of this system, as discussed by Dave Plummer in the video below, is its capacity to identify software vulnerabilities with remarkable accuracy, including intricate scenarios like privilege escalation and operating system escapes. This capability underscores the dual-use nature of the model, requiring careful consideration to balance its benefits for cybersecurity with the risks of potential misuse.
April 21st, 2026 — Source

With US spy laws set to expire, lawmakers are split over protecting Americans from warrantless surveillance
A long-running law that has allowed U.S. intelligence agencies to collect and analyze huge amounts of overseas communications without needing search warrants is set to expire April 30, and lawmakers are in a deadlock over whether to allow the Trump administration to extend it without any changes.
April 21st, 2026 — Source

Yet another ex-ransomware negotiator admits turning rogue after payoff from crimelords
Plus: Court papers reveal nonprofit paid a ransom worth nearly $26.8 million
April 21st, 2026 — Source

You don't need extra antivirus on Windows 11, Microsoft officially says
In a blog post, Microsoft says Defender is enough for most Windows 11 users. No extra antivirus needed if you keep defaults enabled and update regularly.
April 21st, 2026 — Source or Source

Internet — Security Issues — April 17th, 2026

Another DraftKings Hacker Sentenced to Prison
Kamerin Stokes sold stolen credentials through an online marketplace even after pleading guilty to his role in the DraftKings attack.
April 17th, 2026 — Source

CISA tells feds to patch 13-year-old Apache ActiveMQ bug under active attack
Bug hiding in plain sight for over a decade lands on KEV list
April 17th, 2026 — Source

Clothing Retailer Patches Website Flaw Exposing Customer Data
A clothing retailer patched a website flaw that exposed customer data via order links, highlighting risks associated with predictable URL structures.
April 17th, 2026 — Source

CoChat Launches AI Collaboration Platform to Combat Shadow AI
CoChat is fundamentally an AI collaboration platform designed for teamwork and to bring visibility and governance into enterprise AI shadows.
April 17th, 2026 — Source

Critical infrastructure resilience and escalated threat navigation initiative
As geopolitical instability accelerates cyber threats to critical infrastructure (CI), the Canadian Centre for Cyber Security (Cyber Centre) has designed the Critical Infrastructure Resilience and Escalated Threat Navigation (CIREN) initiative to drive immediate preparedness across organizations to reinforce and protect Canada's sovereignty and essential services.
April 17th, 2026 — Source

Cursor AI Vulnerability Exposed Developer Devices
An indirect prompt injection could be chained with a sandbox bypass and Cursor's remote tunnel feature for shell access to machines.
April 17th, 2026 — Source

Cyber Centre launches new initiative to help Canada's critical infrastructure prepare for severe cyber threats
Today, the Canadian Centre for Cyber Security (the Cyber Centre) launched the Critical Infrastructure Resilience and Escalated Threat Navigation (CIREN) initiative. CIREN helps critical infrastructure (CI) organizations understand, prepare for and practice responding to severe cyber incidents. Its purpose is to help organizations maintain essential services during worst-case scenarios, including widespread and prolonged cyber disruptions.
April 17th, 2026 — Source

Europe Spurs Digital Sovereignty With $213M Cloud Contract
The European Union Is Cutting Ties With US Tech Companies
April 17th, 2026 — Source or Source or Source or Source

GitLab 18.11 brings agentic AI to security fixes, CI pipelines, and delivery analytics
GitLab has released GitLab 18.11, expanding agentic AI across the entire software lifecycle with security remediation, pipeline configuration, and delivery analytics.
April 17th, 2026 — Source

Google wipes out 602 million scam ads with Gemini on duty
Google claims that its security teams work around the clock using its Gemini AI models to detect and stop harmful ads.
April 17th, 2026 — Source

Hackers are abusing unpatched Windows security flaws to hack into organizations
Hackers have broken into at least one organization using Windows vulnerabilities published online by a disgruntled security researcher over the last two weeks, according to a cybersecurity firm.
April 17th, 2026 — Source

In Other News: Satellite Cybersecurity Act, $90K Chrome Flaw, Teen Hacker Arrested
Other noteworthy stories that might have slipped under the radar: ShinyHunters targets Rockstar Games, ShowDoc vulnerability exploited in the wild, and EPA to boost cybersecurity budget to $19 million.
April 17th, 2026 — Source

ISMG Editors: Adapting to the Looming Mythos AI Onslaught
Also: NY State Regs Test Resilience versus Compliance, OT Security Nears Breaking Point
April 17th, 2026 — Source or Source or Source or Source

Lawmakers Gathered Quietly to Talk About AI. Angst and Fears of 'Destruction' Followed
Thursday's discussion comes as leaders on Capitol Hill grapple with the dizzying pace of global developments in which technology plays a central role.
April 17th, 2026 — Source

Liongard upgrades LiongardIQ with AI access, live asset data, and deeper discovery
Liongard has announced the expansion of LiongardIQ with new capabilities spanning programmatic AI integration, conversational querying, enhanced network discovery, and deeper identity mapping, extending its system of authority for asset intelligence across the full IT stack.
April 17th, 2026 — Source

Maximizing Mythos Returns Requires AI Cybersecurity Pipeline
Optimizing Value and Utility Hinges on AI Scaffolding, Says Aisle's Ondrej Vlcek
April 17th, 2026 — Source or Source or Source or Source

Moving Toward Identity Intelligence in Fraud Detection
Point Predictive's Frank McKenna on Detecting Hidden Signals in Synthetic IDs
April 17th, 2026 — Source or Source or Source or Source

Mozilla challenges enterprise AI providers with Thunderbolt, open-source AI client under your control
For organizations that want to keep company data within their own systems and have more control over how AI is deployed, Mozilla is offering an alternative to externally hosted AI services with Thunderbolt, an open-source AI client designed for self-hosted use.
April 17th, 2026 — Source

New Phishing Attack Turns n8n Into On-Demand Malware Machine
Hackers are abusing n8n workflows to deliver malware and evade detection, according to Cisco Talos, using trusted automation to bypass security defenses.
April 17th, 2026 — Source

Open source malware sees a 21 percent increase
A new report from Sonatype identifies 21,764 malicious open source packages in the first quarter of the year, up 21 percent from the same period last year and bringing the total logged since 2017 to 1,346,867.
April 17th, 2026 — Source

Recent advances push Big Tech closer to the Q-Day danger zone
Here's which players are winning the race to transition to post-quantum crypto.
April 17th, 2026 — Source

Recent Apache ActiveMQ Vulnerability Exploited in the Wild
The remote code execution vulnerability tracked as CVE-2026-34197 came to light in early April.
April 17th, 2026 — Source

Rejected By Microsoft, 3 Defender Zero-Days Are Now Actively Exploited
A cyber security expert that goes by the name Nightmare-Eclipse attempted to disclose three zero day exploits to Microsoft, but the first attempt went so poorly, he elected to release it into the wild. That first exploit was dubbed "BlueHammer". Shortly following BlueHammer's release, two more zero day exploits of Windows Defender, dubbed "RedSun" and "UnDefend", were also released by Nightmare-Eclipse.
April 17th, 2026 — Source

Report: Google Chrome lacks a very important feature Microsoft Edge, Firefox, Brave have
Here's how Microsoft Edge, Mozilla Firefox and Brave protect you against browser fingerprinting, a security feature Google Chrome lacks.
April 17th, 2026 — Source

Researcher drops two more Microsoft Defender zero-days, all three now exploited in the wild
The security researcher who earlier this month published a proof-of-concept (PoC) exploit for a zero-day privilege escalation vulnerability in Microsoft Defender is back with two more.
April 17th, 2026 — Source

Researchers warn Microsoft Defender vulnerability is already being exploited
The "Red Sun" flaw can overwrite system files and grant elevated access through Defender's file handling behavior
April 17th, 2026 — Source

Stealing Your Data Via TotalRecall Reloaded Is A Feature, Not A Bug?
From The Author of TotalRecall Comes A Terrifying New Sequel
April 17th, 2026 — Source

Two North Korean IT Worker Scheme Facilitators Jailed in the US
Kejia Wang and Zhenxing Wang compromised the identities of dozens of US persons to help land jobs at over 100 companies.
April 17th, 2026 — Source

White House Chief of Staff to Meet With Anthropic CEO Over Its New AI Technology
A White House official said the administration is engaging with advanced AI labs about their models and the security of software.
April 17th, 2026 — Source

With US spy laws set to expire, lawmakers are split over protecting Americans from warrantless surveillance
A long-running law that has allowed U.S. intelligence agencies to collect and analyze huge amounts of overseas communications without needing search warrants is set to expire April 30, and lawmakers are in a deadlock over whether to allow the Trump administration to extend it without any changes.
April 17th, 2026 — Source

Windows Recall's 'Titanium Vault' Under Fire Again as Researcher Shows New Way to Steal Users' PC History
It's the same researcher who exposed Recall when it was first revealed.
April 17th, 2026 — Source

ZionSiphon Malware Targets ICS in Water Facilities
The malware is configured to operate on systems associated with Israeli water treatment and desalination plants.
April 17th, 2026 — Source

Internet — Security Issues — April 14th, 2026

5 Ways Zero Trust Maximizes Identity Security
Stolen credentials accounted for 22% of known initial access vectors in 2025. It's the most common way for attackers to breach a network, and once inside, excessive permissions and limited visibility often allow them to escalate unchecked.
April 14th, 2026 — Source

AI adoption is outpacing the safeguards around it
AI is becoming part of professional and private life, reaching mainstream adoption faster than the personal computer or the internet. These systems are tested in reasoning, safety, and real-world tasks, but the reliability of those measurements remains uncertain.
April 14th, 2026 — Source

Basic-Fit hack compromises data of up to 1 million members
Basic-Fit, a European gym chain, disclosed that hackers breached one of its internal systems, exposing members' personal data in several countries. The company operates more than 2,150 clubs in 12 countries under two brands, with more than 5.8 million members.
April 14th, 2026 — Source

Best Free Antivirus 2026: Keep Your Devices Safe With These Free Tools
Check out these free antivirus tools for great malware protection and extra layers of digital security.
April 14th, 2026 — Source

Binary Defense expands NightBeacon with threat-aligned Detection Coverage Index
Binary Defense has announced the launch of NightBeacon Detect, a new module within NightBeacon, the company's AI-driven SOC platform. The first capability released is Detection Coverage Index, a confidence-based view of how well an organization is covered against specific threat actors, their tactics, techniques, and sub-techniques, and how that coverage changes over time.
April 14th, 2026 — Source

Booking.com data breach: Customer reservation data exposed
"Unauthorized third parties may have been able to access certain booking information associated with your reservation," email alerts sent out by Booking.com over the weekend warn.
April 14th, 2026 — Source

Claroty advances CPS security with Visibility Orchestration in xDome
Claroty has revealed new Visibility Orchestration capabilities in its Saas offering Claroty xDome, transforming visibility from a vague concept into a quantifiable measurement that proves the value of a strong CPS protection program.
April 14th, 2026 — Source

DataVisor brings conversational AI agents to fraud and AML operations
DataVisor has announced Vera, a suite of conversational AI agents designed to combat financial crime. Vera enables institutions to manage risk using natural language, allowing teams to issue instructions that AI agents execute across the fraud and AML lifecycle. By reducing manual workflows, the platform supports a more efficient and adaptive operating model for modern financial crime prevention.
April 14th, 2026 — Source

DavMail 6.6.0 patches a regex flaw and advances its Microsoft Graph backend
Organizations that run DavMail to bridge standard mail clients to Microsoft Exchange or Office 365 received an update this week. Version 6.6.0 addresses a code-scanning alert tied to a regex vulnerability, adjusts OAuth redirect handling to match a recent Microsoft change, and ships fixes across IMAP, SMTP, CalDAV, and CardDAV subsystems.
April 14th, 2026 — Source

Europe's Largest Gym Chain Says Data Breach Impacts 1 Million Members
Basic-Fit has reported that hackers have stolen names, dates of birth, and even bank account details.
April 14th, 2026 — Source

'Mythos-Ready' Security: CSA Urges CISOs to Prepare for Accelerated AI Threats
CISOs face a shrinking window to prepare as AI models like Mythos collapse the gap between vulnerability discovery and exploitation, driving a new era of high-velocity cyberattacks.
April 14th, 2026 — Source

New Rowhammer Attacks on NVIDIA GPUs Enable Full System Takeover
Security researchers have demonstrated a new class of Rowhammer attacks targeting NVIDIA GPUs that can escalate from memory corruption to full system compromise, marking a significant shift in hardware-level security risks. Detailed in recent academic research and highlighted by Ars Technica, the attacks, known as GDDRHammer and GeForce/GeForge, exploit vulnerabilities in GDDR6 GPU memory to gain arbitrary read and write access, ultimately allowing attackers to take control of the host CPU and system memory.
April 14th, 2026 — Source

Nightclub Giant RCI Hospitality Reports Data Breach
The company said in an SEC filing that an IDOR vulnerability affecting RCI Internet Services exposed contractor data.
April 14th, 2026 — Source

No honor among thieves as 0APT threatens rival ransomware gang Krybit
Honey, the skids are fighting again
April 14th, 2026 — Source

Oligo enables real-time exploit detection and blocking at application runtime
Oligo Security has unveiled Runtime Exploit Blocking, a new capability that stops exploit attempts at the application layer in real time. By providing visibility into how applications execute and behave, Oligo identifies and blocks malicious activity at the point of execution, without killing containers or processes, or impacting the application.
April 14th, 2026 — Source

Only a third of cybersecurity professionals plan to stay in their current role
A new report finds that only 34 percent of cybersecurity professionals plan to stay with their current employer, highlighting declining job satisfaction across the field and challenging CISOs to be aggressive and innovative in how they retain talent in a challenging labor market.
April 14th, 2026 — Source

Organizations Warned of Exploited Windows, Adobe Acrobat Vulnerabilities
The security defects allow attackers to escalate privileges and execute arbitrary code remotely.
April 14th, 2026 — Source

Google Adds Rust DNS Parser to Pixel Phones for Better Security
The parser is meant to mitigate the entire class of memory safety bugs in the low-level environment.
April 14th, 2026 — Source

Google to penalize sites that hijack the back button
Google is broadening its spam policies to crack down on "back button hijacking," a deceptive practice where websites interfere with browser navigation, blocking users from returning to the page they came from.
April 14th, 2026 — Source

SAP Patches Critical ABAP Vulnerability
The company has released 19 new security notes addressing flaws in over a dozen enterprise products.
April 14th, 2026 — Source

Triad Nexus Evades Sanctions to Fuel Cybercrime
The sprawling cybercrime operation abuses major providers to prevent takedowns and distance itself from sanctions.
April 14th, 2026 — Source

W3LL phishing service sold for $500 dismantled by the FBI
The W3LL phishing kit, a cybercrime tool used to impersonate legitimate login pages and steal usernames and passwords, has been dismantled by the FBI and Indonesian law enforcement authorities. Officials estimate the operation was tied to more than $20 million in attempted fraud.
April 14th, 2026 — Source

X.Org Server 21.1.22 Released Due To Five New Security Vulnerabilities
X.Org Server 21.1.22 is out today and driven by five new security vulnerabilities being disclosed for the aging codebase. In turn these vulnerabilities also impact XWayland too and thus necessitating the XWayland 24.1.10 release.
April 14th, 2026 — Source

Internet — Security Issues — April 13th, 2026

$12 million frozen, 20,000 victims identified in crypto scam crackdown
More than $12 million has been frozen, and over 20,000 victims have been identified in an international law enforcement operation targeting cryptocurrency and investment scammers.
April 13th, 2026 — Source

Adobe issues emergency fix for Acrobat Reader flaw exploited in the wild (CVE-2026-34621)
Adobe has pushed out an emergency security update for Adobe Acrobat Reader, patching a zero-day vulnerability (CVE-2026-34621) exploited in the wild since November 2025.
April 13th, 2026 — Source

Basic-Fit hit by hack affecting members across multiple countries, including 200,000 in the Netherlands
The breach exposed names, addresses, email addresses, phone numbers, dates of birth, and bank account details. No passwords or identity documents were accessed. The Dutch Data Protection Authority has been notified. Basic-Fit operates over 1,300 clubs across seven European countries.
April 13th, 2026 — Source

CPUID Hacked to Serve Trojanized CPU-Z and HWMonitor Downloads
Download links were replaced by a Russian-speaking threat actor to distribute a recently emerged malware named STX RAT.
April 13th, 2026 — Source

Fake Claude Website Distributes PlugX RAT
The malware mimics the legitimate Anthropic installation, relies on DLL sideloading, and cleans up after itself.
April 13th, 2026 — Source

Google finally extends Gmail end-to-end encryption to mobile devices
Google has now extended Gmail's end-to-end encryption to include iOS and Android devices. In bringing E2EE to mobile devices, Google is making it easier to send and receive encrypted messages without the need for third party tools.
April 13th, 2026 — Source

Google makes it harder to exploit Pixel 10 modem firmware
Google is working to improve the security of Pixel phones by focusing on the cellular baseband modem, a part of the device that handles communication with mobile networks and processes external data.
April 13th, 2026 — Source

Gym giant Basic-Fit confirms data on a million members stolen in cyberattack
Names, addresses, dates of birth, and bank details accessed, though not passwords
April 13th, 2026 — Source

Hackers hijacked CPUID downloads, served STX RAT to victims
If you tried to download software from CPUID's website late last week, you might have downloaded malware instead.
April 13th, 2026 — Source

International Operation Targets Multimillion-Dollar Crypto Theft Schemes
Law enforcement in the US, UK and Canada identified more than $45 million in cryptocurrency and froze $12 million.
April 13th, 2026 — Source

OpenAI Impacted by North Korea-Linked Axios Supply Chain Hack
The AI giant is taking action after determining that a macOS code signing certificate may have been compromised.
April 13th, 2026 — Source

PwC: Cybersecurity Risk Outpaces Corporate Ability to Manage
American Corporations Upping Spend on AI and Technology
April 13th, 2026 — Source or Source or Source

Quantum computers are coming to break our codes faster than anyone expected
Online data is generally pretty secure. Assuming everyone is careful with passwords and other protections, you can think of it as being locked in a vault so strong that even all the world's supercomputers, working together for 10,000 years, could not crack it.
April 13th, 2026 — Source

Rockstar Games gets a taste of grand theft data
ShinyHunters claims it accessed Snowflake metrics via third-party tool
April 13th, 2026 — Source

Rockstar Games receives "pay or leak" warning after cyberattack
Rockstar Games, the developer behind titles such as Grand Theft Auto and Red Dead Redemption, has confirmed a cyberattack claimed by hacking group ShinyHunters, which says it accessed the company's Snowflake environment and obtained data.
April 13th, 2026 — Source

Seized VerifTools servers expose 915,655 fake IDs, 8 arrested
On April 7 and 8, Dutch police arrested eight suspects in a nationwide operation targeting users of the VerifTools platform as part of an identity fraud investigation. The suspects, all men aged 20 to 34, are accused of identity fraud, forgery, and cybercrime-related offenses. During searches, officers seized smartphones, laptops, cash, cryptocurrency, and weapons or items resembling them.
April 13th, 2026 — Source

Siemens expands Industrial Automation DataCenter with edge AI and cybersecurity
Siemens will present the next generation of its Industrial Automation DataCenter, a custom-configured data center for IT needs in production, expanding its turnkey solution into an AI-ready platform.
April 13th, 2026 — Source

Surfshark Just Dropped a Next-Gen VPN Protocol That Could Be Faster and More Secure Than Other VPN Connections
The new Dausos connection protocol has been independently audited and includes a few key innovations not found in other VPNs.
April 13th, 2026 — Source

The changing role of SIEM in the SOC [Q&A]
Security information and event management (SIEM) has long been at the core of cybersecurity efforts. It allows organizations to gather and aggregate data from various systems to meet compliance requirements and guard against threats.
April 13th, 2026 — Source

YouTube Shorts Introduces AI-Generated Avatars That Mimic Real Creators
The platform will add AI labels and watermarks to clips that incorporate the avatars.
April 13th, 2026 — Source

Internet — Security Issues — April 12th, 2026

Critical Marimo pre-auth RCE flaw now under active exploitation
Hackers started exploiting a critical vulnerability in the Marimo open-source reactive Python notebook platform just 10 hours after its public disclosure.
April 12th, 2026 — Source

Week in review: Windows zero-day exploit leaked, Patch Tuesday forecast
Here's an overview of some of last week's most interesting news, articles, interviews and videos:
April 12th, 2026 — Source

Internet — Security Issues — April 11th, 2026

Alleged Supercomputer Hack Could Be The Biggest Breach In China's History
A hacker has allegedly stolen a massive amount of classified data from one of the nation's state-owned supercomputers. While it stopped short of revealing which of China's many supercomputers were affected by this breach, a CNN report claims that the stolen dataset contains more than 10 petabytes of data — enough to make it potentially the largest data breach in China's history. The affected supercomputer is believed to be housed at China's premier National Supercomputing Center (NSCC) in Tianjin, which has historically been home to several of the world's fastest supercomputers.
April 11th, 2026 — Source

Gmail encryption goes mobile, but email itself remains the weak link
Despite Google's best efforts, encrypted emails can still be a pain in the neck to deal with
April 11th, 2026 — Source

Over 20,000 crypto fraud victims identified in international crackdown
An international law enforcement action led by the U.K.'s National Crime Agency (NCA) has identified over 20,000 victims of cryptocurrency fraud across Canada, the United Kingdom, and the United States.
April 11th, 2026 — Source

Rockstar Games has confirmed it was hit by third-party data breach
The hacking group responsible has threatened Rockstar Games with a ransom that's due by April 14.
April 11th, 2026 — Source or Source

Two different attackers poisoned popular open source tools - and showed us the future of supply chain compromise
Time to start dropping SBOMs
April 11th, 2026 — Source

Internet — Security Issues — April 9th, 2026

5 AdultFriendFinder scams to avoid
It's easy to have a good time on the site, but it's also easy to get into trouble.
April 9th, 2026 — Source

8 phishing red flags hidden in everyday emails
Dare to resist phishing scams with these tips.
April 9th, 2026 — Source

10 petabytes of sensitive data stolen from China's National Supercomputing Center, hackers claim — daring heist would be largest ever China hack, covering 6,000 clients across science, defense, and beyond
A hacker (or hacker group) claims to have extracted more than 10 petabytes (1PB = 1000 TB) of highly sensitive information from China's National Supercomputing Center (NSCC) in Tianjin, which could be the largest known data breach involving Chinese infrastructure. Although the incident remains unverified, its nature and scale — data was stolen from 6,000 state-controlled entities — may point to a systemic weakness in China's critical infrastructure, which has serious implications, reports CNN.
April 9th, 2026 — Source

113,000 explicit prompts from AI girlfriend platform exposed, many linked to user IDs
MyLovely.AI, an AI girlfriend platform, suffered a data breach that exposed over 100,000 users.
April 9th, 2026 — Source

300,000 People Impacted by Eurail Data Breach
In December 2025, hackers stole names and passport numbers from the European travel company's network.
April 9th, 2026 — Source

$21 billion stolen from more than 1 million Americans due to cybercrime in 2025 — $11 billion come from stolen crypto, $8.6 billion taken from investment scams, while AI-related attacks cost $893 million
This is also the first time that the Internet Crime Complaint Center received more than a million complaints.
April 9th, 2026 — Source

A version of Windows 10 released a decade ago is now eligible for additional security patches
Windows 10 is dead, but its enterprise heart is still beating
April 9th, 2026 — Source

Acrobat Reader zero-day exploited in the wild for many months (CVE-2026-34621)
Unknown attackers have exploited a zero-day Adobe Acrobat Reader vulnerability since November 2025 and possibly even earlier, security researcher Haifei Li has discovered.
April 9th, 2026 — Source

Adobe Reader Zero-Day Exploited for Months: Researcher
Reputable researcher Haifei Li has come across what appears to be a PDF designed to exploit an unpatched vulnerability.
April 9th, 2026 — Source

Advenica's File Scanner Kiosk scans USB media for malware
Advenica announced the File Scanner Kiosk, a system that scans USB media for malware and helps businesses reduce infection risk.
April 9th, 2026 — Source

Apple Intelligence AI Guardrails Bypassed in New Attack
RSAC researchers hacked Apple Intelligence using the Neural Exect method and Unicode manipulation.
April 9th, 2026 — Source

Breach Roundup: German Police Expose REvil, GandCrab Boss
Also, Medusa Ransomware, Grafana Flaw, German Political Party Breach
April 9th, 2026 — Source or Source or Source or Source

Bug Management in the Mythos Era: 'Assume You're Unpatched'
Start Here: Strong Monitoring, Behavior-Based Controls, Virtual Patching
April 9th, 2026 — Source or Source or Source or Source

Can We Trust AI? No -- But Eventually We Must
From hallucinations and bias to model collapse and adversarial abuse, today's AI is built on probability rather than truth, yet enterprises are deploying it at speed without fully understanding the risks.
April 9th, 2026 — Source

Capita's pension portal exposes civil servants' private data
As if the backlog, the bugs, and the chatbot fixes weren't enough
April 9th, 2026 — Source

Chevin pulls the handbrake on FleetWave software after security scare
UK and US customers stuck waiting after fleet management SaaS vendor took affected environments offline
April 9th, 2026 — Source

Chrome 147 patch fixes 60 security flaws, including 2 critical ones
The latest update for Google Chrome patches 60 security vulnerabilities, including 2 critical buffer overflows in WebML.
April 9th, 2026 — Source

Claude helps researcher dig up decade-old Apache ActiveMQ RCE vulnerability (CVE-2026-34197)
In the latest demonstration of how AI assistants can help with bug hunting, Horizon3.ai researcher Naveen Sunkavally used Claude to unearth CVE-2026-34197, a remote code execution vulnerability in Apache ActiveMQ that's been introduced in the codebase 13 years ago.
April 9th, 2026 — Source

Claude Managed Agents bring execution and control to AI agent workflows
Anthropic's Claude Managed Agents are a suite of composable APIs for building and deploying cloud-hosted agents at scale, handling sandboxed code execution, checkpointing, credential management, scoped permissions, and end-to-end tracing for you.
April 9th, 2026 — Source

Claude Mythos Preview Creates Early Edge for Cyber Titans
Project Glasswing Strengthens Key Platforms, Leaves Broad Exposure Untouched
April 9th, 2026 — Source or Source or Source or Source

Court Backs Pentagon Anthropic Ban - But the Fight Continues
Ruling Keeps Claude Models Out of Defense Systems During Separate Legal Challenges
April 9th, 2026 — Source

Cryptographers place $5,000 bet whether quantum will matter
Quantum computing exists in a sort of superposition with regard to cryptography -- it's both a pending threat and a technology of no immediate consequence for decryption.
April 9th, 2026 — Source

Cryptohack Roundup: Bithumb's Recovery Plan
Also: Cambodia Moves to Combat Online Scam Networks
April 9th, 2026 — Source or Source or Source or Source

Eurail says December data breach impacts 300,000 individuals
Eurail B.V., a European travel operator that provides digital passes covering 33 national railways, says attackers stole the personal information of over 300,000 individuals in a December 2025 data breach.
April 9th, 2026 — Source

Fake QR codes make for easy scams—be careful what you scan out there
It's a simple thing we encounter many times every single week—often while in a hurry. You pull up at a parking spot, scan a QR code and pay within seconds. Or you sit down at a cafe, scan a code to view the menu and order your meal.
April 9th, 2026 — Source

German police identify REvil and GandCrab mastermind now living in Russia
They allege Daniil Shchukin ran two of the most prolific ransomware operations and helped rebuild them under a new name
April 9th, 2026 — Source

Go maintainer joins collective klaxon about encryption-breaking quantum computers — developer urges immediate switch to post-quantum methods to prevent worldwide disaster
Cryptographers see disaster looming — and nobody else is paying attention.
April 9th, 2026 — Source

Google API Keys in Android Apps Expose Gemini Endpoints to Unauthorized Access
Dozens of such keys can be extracted from apps' decompiled code to gain access to all Gemini endpoints.
April 9th, 2026 — Source

Google Warns of New Campaign Targeting BPOs to Steal Corporate Data
Tracked as UNC6783, the threat actor is likely linked to Mr. Raccoon, the hacker behind the alleged theft of Adobe data from a BPO.
April 9th, 2026 — Source

Hacker stole £700,000 from UK energy company by redirecting payment
British oil and gas company Zephyr Energy says someone stole £700,000 (close to $1 million) from one of its U.S.-based subsidiaries by redirecting a payment meant for a contractor into a hacker-controlled account.
April 9th, 2026 — Source

Hackers are turning home routers into tools to spy on Microsoft 365 users
Russian cyber-spies are back with a vengeance
April 9th, 2026 — Source

Hackers Exploit Adobe PDF Flaw for Months to Steal Data, No Fix Yet
A critical Adobe Acrobat zero-day has been exploited for months via malicious PDFs to steal data and potentially take over systems, with no patch yet available.
April 9th, 2026 — Source

Hackers steal $3.6 million from crypto ATM giant Bitcoin Depot
Bitcoin Depot, which operates one of the largest Bitcoin ATM networks, says attackers stole $3.665 million worth of Bitcoin from its crypto wallets after breaching its systems last month.
April 9th, 2026 — Source

Healthcare IT solutions provider ChipSoft hit by ransomware attack
Dutch healthcare software vendor ChipSoft has been impacted by a ransomware attack that forced the company to take offline its website and digital services for patients and healthcare providers.
April 9th, 2026 — Source

Intruder expands cloud security with agentless container image scanning
Intruder has announced the release of Container Image Scanning, a new upgrade to its cloud security capabilities that automatically scans container images for vulnerabilities, granting customers actionable insight into container risk without deploying and maintaining scanning agents across their estates.
April 9th, 2026 — Source

Iran-linked hackers are now targeting industrial controllers in US infrastructure
Attackers are exploiting internet-facing PLCs with legitimate tools, causing operational disruptions in energy, water, and government systems
April 9th, 2026 — Source

Massive Data Breach Exposes 337K LAPD-Linked Records
A massive breach exposed 337K LAPD-linked files, raising concerns over third-party risk, sensitive data exposure, and law enforcement cybersecurity gaps.
April 9th, 2026 — Source

Mallory brings contextual threat intelligence to security operations
Mallory is launching an AI-native threat intelligence platform, purpose-built to answer the questions CISOs and their teams are asking every day:
April 9th, 2026 — Source

Meta's Muse Spark takes AI a step closer to personal superintelligence
Meta Superintelligence Labs has introduced Muse Spark, a natively multimodal reasoning model with support for tool use, visual chain of thought, and multi-agent orchestration. The release includes a Contemplating mode, which is rolling out gradually and orchestrates multiple agents that reason in parallel.
April 9th, 2026 — Source

Microsoft Flags Fast-Moving Ransomware, Router-Based Espionage Threats
Microsoft is warning organizations about two active cybersecurity threats: a fast-moving ransomware campaign and a Russian espionage operation that abuses small office and home office routers to monitor victims' network traffic.
April 9th, 2026 — Source

Microsoft locks out VeraCrypt and WireGuard devs, blames verification process
No emails, no warnings, no humans -- just bots, catch-22s, and a 60-day appeals queue
April 9th, 2026 — Source

Mythos and Like AI Tools Raise Stakes for Healthcare Cyber
Experts Warn of Faster and Higher Volume Attacks, Rising Patient Safety Worries
April 9th, 2026 — Source or Source or Source

New 'LucidRook' malware used in targeted attacks on NGOs, universities
A new Lua-based malware, called LucidRook, is being used in spear-phishing campaigns targeting non-governmental organizations and universities in Taiwan.
April 9th, 2026 — Source

New VENOM phishing attacks steal senior executives' Microsoft logins
Threat actors using a previously undocumented phishing-as-a-service (PhaaS) platform called "VENOM" are targeting credentials of C-suite executives across multiple industries.
April 9th, 2026 — Source

Norton brings real-time AI Agent Protection to Norton 360
Norton has introduced a new AI Agent Protection feature to its Norton 360 software that monitors the actions of autonomous AI tools, reflecting growing concern over how much control these systems now have over personal devices and data.
April 9th, 2026 — Source

OPSWAT adds predictive AI engine to MetaDefender for pre-execution threat detection
OPSWAT has announced OPSWAT Predictive Alin AI, its first proprietary AI-based threat detection engine for the MetaDefender Platform. This AI-based innovation introduces a new category of capability within the MetaDefender Platform, a high-confidence predictive layer that works alongside existing detection and prevention engines to assess malicious intent before execution, driving greater efficiency across the platform. This enables organizations to act immediately, while minimizing the operational impacts of false positives.
April 9th, 2026 — Source

Over half of organizations have mobile devices with an out-of-date OS
According to the latest Security 360 report from Jamf 53 percent of organizations have at least one mobile device with a critically out-of-date operating system.
April 9th, 2026 — Source

Palo Alto Networks, SonicWall Patch High-Severity Vulnerabilities
The bugs could allow attackers to modify protected resources and escalate their privileges to administrator.
April 9th, 2026 — Source

Russia Behind Recent TP-Link Router Hacking, According to UK's Cyber Security Agency
Microsoft also identified several hundred organizations that were targeted in the attacks.
April 9th, 2026 — Source

Russian state hackers are hijacking TP-Link and MicroTik routers to steal Outlook credentials, cybersecurity center warns — APT28 group targets DNS and redirects traffic to attacker-controlled servers
Traffic is being redirected through attacker-controlled servers.
April 9th, 2026 — Source

Security researchers tricked Apple Intelligence into cursing at users. It could have been a lot worse
Wash your mouth out with digital soap
April 9th, 2026 — Source

'Several dozen' high-value corporations hit by new extortion crew in helpdesk phishing spree
Possible link to Mr. Raccoon's claimed Adobe break-in
April 9th, 2026 — Source

Smart Slider updates hijacked to push malicious WordPress, Joomla versions
Hackers hijacked the update system for the Smart Slider 3 Pro plugin for WordPress and Joomla, and pushed a malicious version with multiple backdoors.
April 9th, 2026 — Source

The Hidden ROI of Visibility: Better Decisions, Better Behavior, Better Security
Beyond monitoring and compliance, visibility acts as a powerful deterrent, shaping user behavior, improving collaboration, and enabling more accurate, data-driven security decisions.
April 9th, 2026 — Source

User Nearly Loses $15,000 After Calling Apple Pay Scam Number
You receive a message about a suspicious Apple Pay charge, and it looks urgent enough to make you act immediately, which is exactly how scammers pull people into a fast-moving situation where they control the conversation from the first call. That is what happened in a recent case where a simple text turned into a high-pressure scam attempt that nearly cost $15,000.
April 9th, 2026 — Source

WhatsApp brings long-awaited privacy feature to filter who can reach you
After years of waiting, WhatsApp is set to roll out a username feature that will allow people to connect and communicate without sharing their phone numbers. This means more privacy and better control over phone number visibility by choosing a unique username.
April 9th, 2026 — Source

When attackers already have the keys, MFA is just another door to open
The Figure breach exposed 967,200 email records without a single exploit. Understanding what that enables — and why your MFA cannot contain it — is an architectural problem, not a user education problem.
April 9th, 2026 — Source

Who Controls AI on Battlefields - the Military or the Model?
Former DoD CIO Beavers on Ethics, Reliability and AI as a National Security Tool
April 9th, 2026 — Source or Source or Source or Source

Why Anthropic is Secretly Holding Back the Claude Mythos Release
Anthropic, OpenAI and DeepSeek are navigating a pivotal moment in AI development, with each company unveiling or preparing significant advancements. Universe of AI explores the latest updates, including the leaked details of Anthropic's Claude Mythos, which reportedly excels in reasoning and cybersecurity, and OpenAI's GPT-6, code-named "Spud," featuring a rumored 2-million-token context window. Meanwhile, DeepSeek faces strategic decisions for its Version 4 release, balancing the need for innovation with resource constraints. These developments highlight not only technological progress but also the critical challenges of scalability and strategic planning in the AI sector.
April 9th, 2026 — Source

Yikes, Encryption's Y2K Moment is Coming Years Early
Google moved up its estimated deadline for quantum preparedness in cryptography to 2029—only 33 months from now. That's earlier than previous deadlines, and they proposed the new post-quantum migration deadline because of two new papers that comprise a big jump in the state of the technology. It's ahead of schedule, but not altogether unexpected. Cryptographers and engineers have been working on this for years, and as the deadline gets closer, it's not surprising to see more precise timeline estimates come up.
April 9th, 2026 — Source

Your TP-Link router is under attack from Russian state hackers
Russian hacking group Fancy Bear is targeting TP-Link routers worldwide. Update your router firmware now.
April 9th, 2026 — Source

Zephyr Energy loses £700K in cyber hit that rerouted contractor payment
Attackers slipped into the process and redirected funds, leaving the company scrambling to recover the cash
April 9th, 2026 — Source

Zero Days for the Masses: Mythos Presages Exploit Tsunami
Asymmetry Between Exploits Wielded by Nation-States and Hackers Will Disappear
April 9th, 2026 — Source or Source or Source or Source

Internet — Security Issues — April 8th, 2026

'BlueHammer' Exploit Targets Windows, Potentially Impacting 1 Billion+ Devices
A researcher released a working 'BlueHammer' Windows zero-day exploit that could impact over 1 billion devices, granting SYSTEM-level access and leaving no patch yet.
April 8th, 2026 — Source

Chaos malware expands from routers to Linux cloud servers
Chaos, Go-based malware first documented by Lumen's Black Lotus Labs, has historically targeted routers and edge devices. A new variant observed in March 2026 shows the malware operating against misconfigured Linux cloud servers, a category of infrastructure the botnet had not previously prioritized.
April 8th, 2026 — Source

Critical infrastructure devices exposed to online threats
A new study finds that some of the most critical infrastructure sectors, including power grids and railway networks, have exposed ICS devices.
April 8th, 2026 — Source

Cyber Defense for Education & SLTTs: Doing More with Less Using MDR
State, local, tribal, and territorial organizations are dealing with a tough reality. Cyber threats are increasing, but teams are often small, environments are complex, and budgets are tight. For many IT and security leaders, it can feel like you are constantly trying to keep up with more alerts than your team can realistically handle.
April 8th, 2026 — Source or Source or Source or Source

Data Leakage Vulnerability Patched in OpenSSL
A total of seven vulnerabilities, most of which can be exploited for DoS attacks, have been patched in OpenSSL.
April 8th, 2026 — Source

Dutch healthcare software vendor goes dark after ransomware attack
ChipSoft's website remains down but emails are functioning
April 8th, 2026 — Source

Enhancing Secure MCP Client--Server Communication With the Chain of Responsibility Pattern
A clean and common, yet decoupled, flexible, and open for extension solution when interacting with multiple API key-secured MCP servers.
April 8th, 2026 — Source

Evasive Masjesu DDoS Botnet Targets IoT Devices
Focused on persistence, the botnet does not engage in widespread infection and avoids blacklisted IPs and critical infrastructure entities.
April 8th, 2026 — Source

FBI: Cybercrime Losses Neared $21 Billion in 2025
The FBI received over 1 million complaints of malicious activity in 2025, with investment, BEC, and tech support scams causing the highest losses.
April 8th, 2026 — Source

Feds Are Still Assessing Proposed HIPAA Security Rule Update
HHS OCR Director Says Cost of Inaction May Outweigh Compliance Burdens
April 8th, 2026 — Source

Flatpak 1.16.4 fixes sandbox escape and three other security flaws
Flatpak, a Linux application sandboxing and distribution framework, released version 1.16.4, patching four security vulnerabilities.
April 8th, 2026 — Source

Hackers steal and leak sensitive LAPD police documents
Cybercriminals have allegedly stolen a large amount of sensitive internal documents from the Los Angeles Police Department and leaked the data online.
April 8th, 2026 — Source

Hackers Targeting Ninja Forms Vulnerability That Exposes WordPress Sites to Takeover
The vulnerability allows hackers to upload arbitrary files to a site's server and achieve remote code execution.
April 8th, 2026 — Source

Iranian cyber activity hits US energy, water, and government networks
U.S. government agencies on Tuesday warned American organizations about ongoing cyber activity targeting OT and PLC devices, including those manufactured by Rockwell Automation and Allen-Bradley, across multiple critical infrastructure sectors. The activity has been attributed to Iranian-affiliated APT actors seeking to disrupt operations in the United States.
April 8th, 2026 — Source

Is a $30,000 GPU Good at Password Cracking?
Compute power is growing at an extraordinary pace. The AI surge has driven massive investment in GPUs and specialized 'accelerators', with vendors building increasingly powerful hardware to train large language models.
April 8th, 2026 — Source

Massachusetts Hospital Diverts Ambulances as Cyberattack Causes Disruption
Signature Healthcare was forced to cancel some services, and pharmacies are unable to fill prescriptions due to the hacker attack.
April 8th, 2026 — Source

New Scam Alert: QR Codes Replace Links in Traffic Ticket Phishing
Scammers are using fake traffic violation texts with QR codes to steal personal and financial data, posing as state courts and government agencies.
April 8th, 2026 — Source

NHS Scotland-linked domains caught serving pr0n and dodgy sports streams
Two practice web addresses appear to have been compromised
April 8th, 2026 — Source

RCE Bug Lurked in Apache ActiveMQ Classic for 13 Years
The vulnerability requires authentication for successful exploitation, but another flaw exposes the Jolokia API without authentication.
April 8th, 2026 — Source

Russian state hackers are hijacking TP-Link and MicroTik routers to steal Outlook credentials, cybersecurity center warns — APT28 group targets DNS and redirects traffic to attacker-controlled server
Traffic is being redirected through attacker-controlled servers.
April 8th, 2026 — Source

Secureframe expands Comply with User Access Reviews for automated governance
Secureframe has announced the launch of User Access Reviews, a new capability within Secureframe Comply. Access reviews are the primary mechanism organizations use to validate that the right people have the appropriate access, but the process has historically been manual, fragmented, and difficult to audit. Most teams still conduct access reviews using exported spreadsheets and email threads, creating accountability gaps and leaving security incidents waiting to happen.
April 8th, 2026 — Source

Social engineering attacks on open source developers are escalating
North Korean hackers spent weeks socially engineering an Axios maintainer through a fake Slack workspace, a cloned company identity, and a fabricated Microsoft Teams call that tricked him into installing a RAT posings as a software update. They used the access they gained to inject malware into npm packages downloaded 100+ million times a week.
April 8th, 2026 — Source

Thousands of consumer routers hacked by Russia's military
End-of-life routers in homes and small offices hacked in 120 countries.
April 8th, 2026 — Source

Thousands of users got affected by OneDrive unstoppable spam on Windows, Android, Mac
This OneDrive bug leads to users getting spammed by hundreds of shared files and folders. Microsoft had admitted it's a real problem.
April 8th, 2026 — Source

US Disrupts Russian Espionage Operation Involving Hacked Routers and DNS Hijacking
The APT28 threat group exploited vulnerable TP-Link and MikroTik routers to conduct adversary-in-the-middle (AitM) attacks.
April 8th, 2026 — Source

Internet — Security Issues — April 6th, 2026

Attackers Target Zero-Day Flaw in Fortinet Security Software
Vendor Issues Hotfix for Critical Flaw in FortiClient Endpoint Management Server
April 6th, 2026 — Source or Source or Source or Source or Source

Best VPN Service for 2026: How to Choose the Right VPN for You
Streaming, gaming or traveling? You might want a virtual private network. Our expert testing team rigorously evaluated these top VPN services for privacy, speed and value.
April 6th, 2026 — Source

CISA orders feds to patch exploited Fortinet EMS flaw by Friday
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to secure FortiClient Enterprise Management Server (EMS) instances against an actively exploited vulnerability by Friday.
April 6th, 2026 — Source

Convicted spyware maker Bryan Fleming avoids jail at sentencing
The first convicted spyware maker in over a decade has avoided jail time after earlier pleading guilty to U.S. federal charges associated with running his surveillance company.
April 6th, 2026 — Source

Drift $280M crypto theft linked to 6-month in-person operation
The Drift Protocol says that the $280+ million hack it suffered last week was the result of a long-term, carefully planned operation that included building "a functioning operational presence inside the Drift ecosystem."
April 6th, 2026 — Source

Fortinet Rushes Emergency Fixes for Exploited Zero-Day
The improper access control bug in FortiClient EMS allows unauthenticated attackers to execute arbitrary code remotely.
April 6th, 2026 — Source

Google DeepMind Researchers Map Web Attacks Against AI Agents
A vulnerability named 'AI Agent Traps' allows attackers to manipulate, deceive, and exploit visiting agents via malicious web content.
April 6th, 2026 — Source

Guardarian Users Targeted With Malicious Strapi NPM Packages
Hackers published 36 NPM packages posing as Strapi plugins to execute shells, escape containers, and harvest credentials.
April 6th, 2026 — Source

Memristor chip combines security and compute-in-memory for edge devices
A cross-institutional research team has developed Co-Located Authentication and Processing (CLAP), a privacy-preserving system that overcomes the trade-off between security and performance in edge computing devices. The study, titled "Privacy-preserving data analysis using a memristor chip with co-located authentication and processing," is published in Science Advances.
April 6th, 2026 — Source

Microsoft links Medusa ransomware affiliate to zero-day attacks
Microsoft says that Storm-1175, a China-based financially motivated cybercriminal group known for deploying Medusa ransomware payloads, has been deploying n-day and zero-day exploits in high-velocity attacks.
April 6th, 2026 — Source

New Fortinet Flaw Allows Unauthorized Access to Enterprise Systems
Fortinet warns of a critical FortiClient EMS zero-day vulnerability that is currently being exploited, allowing attackers to bypass authentication and execute commands.
April 6th, 2026 — Source

North Korea's hijack of one of the web's most used open source projects was likely weeks in the making
A North Korean cyberattack that last Monday briefly hijacked one of the most widely used open source projects on the web took weeks to carry out as part of a long-running campaign to target the code's top developers.
April 6th, 2026 — Source

North Korean Hackers Target High-Profile Node.js Maintainers
The threat actor behind the Axios supply chain attack has been aiming at other maintainers in its social engineering campaign.
April 6th, 2026 — Source

Not Without My AI Agent: Models Break Rules to Save Peers
Researchers Find Frontier Models Defy Humans to Protect AI Peers
April 6th, 2026 — Source

The 2026 Guide to Ecommerce Security and Development
Ecommerce security is now a core business strategy. Companies must adopt security-by-design, zero trust, and AI-driven fraud detection to protect revenue and customers.
April 6th, 2026 — Source

Why Simple Breach Monitoring is No Longer Enough
In 2026, stolen credentials are a top-tier security priority. They are also a paradox: even though they are considered a significant risk, enterprises still opt for checkbox solutions and generic tools to mitigate the problem.
April 6th, 2026 — Source

Internet — Security Issues — April 3rd, 2026

Age-verification is hurting sex educators and sex workers, studies suggest
These laws aren't working to keep minors off adult sites, but they are hitting creators' incomes.
April 3rd, 2026 — Source

AI Breakthroughs, Security Breaches, and Industry Shakeups Define the Week in Tech
See what you missed in Daily Tech Insider from March 30--April 3.
April 3rd, 2026 — Source

AI's Achilles Heel is an Oil Shipping Strait
A Shipping Crisis in the Middle East Is Now a Chip Crisis Everywhere Else
April 3rd, 2026 — Source or Source or Source or Source

APERION releases SmartFlow SDK for secure, on-prem AI governance without cloud reliance
APERION launched SmartFlow SDK, providing a secure, on-premises path for enterprises migrating away from compromised cloud-based AI gateways. The launch coincides with a 200% increase in web traffic since the March 24 LiteLLM supply chain attack that compromised an estimated 36% of all cloud environments.
April 3rd, 2026 — Source

Application abuse and what to do about it [Q&A]
Using applications as an attack vector, in a DDoS campaign for example, is not new. But application abuse is evolving making it harder to spot.
April 3rd, 2026 — Source

CERT-EU blames Trivy supply chain attack for Europa.eu data breach
Attackers exploited a vulnerability scanner to steal 350GB of data that they then leaked on the dark web.
April 3rd, 2026 — Source

Cisco IMC auth bypass vulnerability allows attackers to alter user passwords (CVE-2026-20093)
Cisco has fixed ten vulnerabilities affecting its Integrated Management Controller (IMC), the most critical of which (CVE-2026-20093) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin.
April 3rd, 2026 — Source

Critical ShareFile Flaws Lead to Unauthenticated RCE
The vulnerabilities can be chained together to bypass authentication and upload arbitrary files to the server.
April 3rd, 2026 — Source

Crypto platform Drift suffers from hack suspected to total $270 million — firm goes into damage control mode, suspends deposits and withdrawals
This is an ongoing situation.
April 3rd, 2026 — Source

Die Linke German political party confirms data stolen by Qilin ransomware
The Qilin ransomware group has stolen data from Die Linke, a German democratic socialist political party, and is threatening to leak it.
April 3rd, 2026 — Source

Europe's cyber agency blames hacking gangs for massive data breach and leak
The European Union's cybersecurity agency said Thursday that a recent hack and data breach at the EU's executive body was the work of a cybercriminal group known as TeamPCP.
April 3rd, 2026 — Source

Evolution of Ransomware: Multi-Extortion Ransomware Attacks
In February 2026, the University of Mississippi Medical Center (UMMC) fell victim to a ransomware attack. The incident took the Epic electronic health record system offline across 35 clinics and more than 200 telehealth sites, forcing the cancellation of chemotherapy appointments and the postponement of non-emergency surgeries. Medical staff were required to revert to paper-based workflows, leaving countless patients to bear the consequences.
April 3rd, 2026 — Source

FBI Declares Surveillance System Breach a 'Major Incident'
China-linked hackers breached an FBI surveillance system, exposing sensitive investigation data and prompting a "major incident" classification.
April 3rd, 2026 — Source

Gen AI Stalls, Shadow AI Rises: A CISO Concern
Most organizations are exploring generative AI, but scaling it across the enterprise remains a challenge. According to Gartner, 60% of businesses are piloting M365 Copilot, yet only 6% have progressed to large-scale deployment, highlighting a critical gap between experimentation and operational impact.
April 3rd, 2026 — Source or Source or Source or Source

Hims & Hers warns of data breach after Zendesk support ticket breach
Telehealth giant Hims & Hers Health is warning that it suffered a data breach after support tickets were stolen from a third-party customer service platform.
April 3rd, 2026 — Source

In Other News: ChatGPT Data Leak, Android Rootkit, Water Facility Hit by Ransomware
Other noteworthy stories that might have slipped under the radar: Symantec vulnerability, anti-ClickFix mechanism added to macOS, FBI hack classified as major incident.
April 3rd, 2026 — Source

ISMG Editors: Vendor Breaches Expose Healthcare Risk
Also: RSAC Speakers Warn AI Is Outpacing Security, DoD's Zero Trust Reality Check
April 3rd, 2026 — Source or Source or Source or Source

Latest BreachForums Reboot Tied to Fake ShinyHunters Admin
After Hacker Site Gets Resurrected, Cybercrime Group Denies All Involvement
April 3rd, 2026 — Source or Source or Source or Source

LinkedIn secretly scans for 6,000+ Chrome extensions, collects data
A new report dubbed "BrowserGate" warns that Microsoft's LinkedIn is using hidden JavaScript scripts on its website to scan visitors' browsers for installed extensions and collect device data.
April 3rd, 2026 — Source

Man admits to locking thousands of Windows devices in extortion plot
A former core infrastructure engineer has pleaded guilty to locking Windows admins out of 254 servers as part of a failed extortion plot targeting his employer, an industrial company headquartered in Somerset County, New Jersey.
April 3rd, 2026 — Source

Mercor Breach Linked to LiteLLM Supply-Chain Attack
AI Dependency Attack Reportedly Exposes Data and Source Code
April 3rd, 2026 — Source or Source or Source or Source

Mobile Attack Surface Expands as Enterprises Lose Control
Shadow AI embedded in everyday apps, combined with outdated mobile devices and zero-click exploits, is creating a new and largely unseen mobile risk.
April 3rd, 2026 — Source

North Korean Hackers Drain $285 Million From Drift in 10 Seconds
The attackers prepared infrastructure and multiple nonce-based transactions, took over an admin key, and drained five vaults.
April 3rd, 2026 — Source

One-Time Passcodes Are Gateway for Financial Fraud Attacks
Report Reveals Growing Trend of Fraudsters Intercepting SMS-Based Verification
April 3rd, 2026 — Source or Source or Source or Source

Open Source Security Tool Trivy Hit by Supply Chain Attack, Prompting Urgent Industry Response
A major security incident affecting the widely used open source vulnerability scanner Trivy has exposed critical weaknesses in software supply chain security, after maintainers confirmed that a malicious release was briefly distributed to users. The incident, disclosed in a GitHub discussion by Aqua Security, revealed that attackers were able to publish a compromised version of the tool, potentially exposing downstream systems to credential theft and malicious code execution.
April 3rd, 2026 — Source

React2Shell Exploited in Large-Scale Credential Harvesting Campaign
Using automated scanning and the Nexus Listener collection framework, the hackers compromised over 750 systems.
April 3rd, 2026 — Source

Rowhammer Exploit Now Targets GDDR6 GPUs, Enables Full System Memory Access
Security researchers have demonstrated that the long-known Rowhammer vulnerability can now be applied to GPU memory, specifically targeting NVIDIA graphics cards equipped with GDDR6 VRAM. The findings show that disturbance-based attacks, previously limited to system DRAM, can be adapted to modern GPU architectures, including Ampere and Ada Lovelace.
April 3rd, 2026 — Source

Stryker Tells Customers Manufacturing Systems Restored
Device Maker Is Still Investigating March 11 Attack Claimed by Iranian Hacktivists
April 3rd, 2026 — Source or Source or Source or Source

T-Mobile Sets the Record Straight on Latest Data Breach Filing
The cybersecurity incident involved an insider and had a limited impact, the telecoms giant told SecurityWeek.
April 3rd, 2026 — Source

The FCC's Foreign Router Ban Has Security Experts Raising Alarms
A recent edict from the Federal Communications Commission has security experts bracing for the worst. On March 23, the agency announced a sweeping ban on all new "consumer-grade" routers produced outside the United States. The decision sent shockwaves through boardrooms and living rooms alike: Because no major wireless router brands manufacture in the U.S. -- including those headquartered stateside, such as Netgear -- a ban on foreign routers is difficult to differentiate from a ban on routers, period.
April 3rd, 2026 — Source

The Theranos Playbook Is Quietly Returning in Cybersecurity
Market Pressures Are Rewarding Storytelling More Than Validation, Operational Value
April 3rd, 2026 — Source

TrueConf Zero-Day Exploited in Asian Government Attacks
A Chinese threat actor exploited the video conferencing platform to perform reconnaissance, escalate privileges, and execute additional payloads.
April 3rd, 2026 — Source

What Happens When Data Centers Become Military Targets?
It's Time for CIOs to Rethink Business Continuity Plans and Cloud Resources
April 3rd, 2026 — Source or Source or Source or Source

Why I Use Additional Antivirus Protection on Top of Microsoft Defender
Microsoft Defender is good now, but I still treat it like a simple lock instead of a full security system.
April 3rd, 2026 — Source

Windows Security app gets Secure Boot certificate status indicators as 2026 expiration approaches
Microsoft's Secure Boot certificates, issued in 2011, are approaching expiration in 2026. To help IT administrators track whether devices have received replacement certificates, Microsoft has added new status indicators to the Windows Security app, under Device security > Secure Boot.
April 3rd, 2026 — Source

Internet — Security Issues — April 2nd, 2026

250,000 Affected by Data Breach at Nacogdoches Memorial Hospital
In January 2026, a threat actor hacked the hospital's internal network and stole personal and health information.
April 2nd, 2026 — Source

Adversaries Exploit Vacant Homes to Intercept Mail in Hybrid Cybercrime
Fraud operations have expanded beyond traditional hacking techniques to include methods that exploit legitimate services and real-world infrastructure. By combining publicly available data, weak identity verification processes, and operational gaps, threat actors are building scalable fraud workflows that are both low-cost and difficult to detect.
April 2nd, 2026 — Source

Apple Rolls Out DarkSword Exploit Protection to More Devices
Apple Rolls Out DarkSword Exploit Protection to More Devices
April 2nd, 2026 — Source

Axios npm Package Compromised in Supply Chain Attack
The npm ecosystem absorbed one of its most significant supply chain attacks on March 31, 2026, when two versions of Axios, the HTTP client library that sees over 100 million weekly downloads, were found to contain a fully functional Remote Access Trojan. The compromised releases, axios@1.14.1 and axios@0.30.4, were published to the npm registry via what appears to be a hijacked maintainer account and were live for a window long enough to reach an unknown number of developer environments before being removed.
April 2nd, 2026 — Source

Beehiiv expands into podcasting, taking aim at Patreon
Newsletter platform Beehiiv is introducing native podcast hosting, the company told TechCrunch exclusively. With this move, creators can now host, distribute, and monetize their podcast directly on Beehiiv. Users will be able to publish an episode, share it with subscribers, and track their analytics all on the platform.
April 2nd, 2026 — Source

Cisco Patches Critical and High-Severity Vulnerabilities
The bugs could lead to authentication bypass, remote code execution, information disclosure, and privilege escalation.
April 2nd, 2026 — Source

Critical Cisco IMC auth bypass gives attackers Admin access
Cisco has released security updates to address several critical and high-severity vulnerabilities, including an Integrated Management Controller (IMC) authentication bypass that allows attackers to gain Admin access.
April 2nd, 2026 — Source

Cybersecurity M&A Roundup: 38 Deals Announced in March 2026
Significant cybersecurity M&A deals announced by Airbus, Cellebrite, Databricks, Quantum eMotion, Rapid7, and OpenAI.
April 2nd, 2026 — Source

DarkSword exploit forces Apple to loosen its patching policy
Apple has extended security updates to a wider range of devices still running iOS 18, aiming to protect users from the DarkSword exploit kit.
April 2nd, 2026 — Source

Drift loses $280 million as North Korean hackers seize Security Council powers
The Drift Protocol lost at least $280 million after a threat actor took control of its Security Council administrative powers in a planned, sophisticated operation.
April 2nd, 2026 — Source

Even cybersecurity experts make simple mistakes. Here's the real lesson
No one's perfect.
April 2nd, 2026 — Source

Google now lets you direct avatars through prompts in its Vids app
Google on Thursday added new features to its video editor app Vids, including directing and customizing avatars through text prompts, Veo 3.1 support, the ability to export videos to YouTube, and recording with a Chrome extension.
April 2nd, 2026 — Source

Hasbro Cyberattack Knocks Systems Offline, Recovery Could Take Weeks
Hasbro is investigating a cyberattack that forced systems offline, warning recovery could take weeks as it works to contain the incident and assess the impact.
April 2nd, 2026 — Source

Hasbro Systems Nerfed by Data Breach; IT Recovery Underway
Transformers, Peppa Pig Toymaker Forecasts Delays, Says Product Shipping Continues
April 2nd, 2026 — Source or Source or Source or Source

ICE says it bought Paragon's spyware to use in drug trafficking cases
The acting head of U.S. Immigration and Customs Enforcement told lawmakers that it has bought and used spyware made by Paragon Solutions in drug trafficking cases, according to a letter seen by TechCrunch.
April 2nd, 2026 — Source

'Invisible' credential theft campaign targets senior executives
A new report from Abnormal AI uncovers a credential theft campaign that has been systematically targeting C-suite executives and senior officers at major global organizations over a five-month period from November 2025 through March 2026.
April 2nd, 2026 — Source

Medtech giant Stryker fully operational after data-wiping attack
Stryker Corporation, one of the world's leading medical technology companies, says it's fully operational three weeks after many of its systems were wiped out in a cyberattack claimed by the Iranian-linked Handala hacktivist group.
April 2nd, 2026 — Source

Mercor Hit by LiteLLM Supply Chain Attack
The AI recruiting firm is investigating the incident as Lapsus$ claimed the theft of 4TB of Mercor data.
April 2nd, 2026 — Source

New Rowhammer attacks give complete control of machines running Nvidia GPUs
GDDRHammer, GeForge and GPUBreach hammer GPU memory in ways that hijack the CPU.
April 2nd, 2026 — Source

New Progress ShareFile flaws can be chained in pre-auth RCE attacks
Two vulnerabilities in Progress ShareFile, an enterprise-grade secure file transfer solution, can be chained to enable unauthenticated file exfiltration from affected environments.
April 2nd, 2026 — Source

OpenSSH 10.3 patches five security bugs and drops legacy rekeying support
OpenSSH 10.3 shipped carrying five security fixes alongside feature additions and a set of behavior changes that will break compatibility with older SSH implementations that do not support rekeying.
April 2nd, 2026 — Source

Over 14,000 F5 BIG-IP APM instances still exposed to RCE attacks
Internet threat-monitoring non-profit Shadowserver has found over 14,000 BIG-IP APM instances exposed online amid ongoing attacks exploiting a critical-severity remote code execution (RCE) vulnerability.
April 2nd, 2026 — Source

Pentagon Commits to Reform of Cyber Talent Management System
Panel Calls for Modernization of Recruiting Processes for About 225,000 Cyber Jobs
April 2nd, 2026 — Source or Source or Source or Source

Quantum computers might crack today's encryption far sooner than we thought
Encrypted banking information, cryptocurrency wallets, and other sensitive data may be in danger
April 2nd, 2026 — Source

Reengineering AML in the Era of Instant Payments
Financial Institutions Are Rethinking Controls to Ensure Frictionless Transactions
April 2nd, 2026 — Source or Source or Source or Source

Residential proxies evaded IP reputation checks in 78% of 4B sessions
Researchers warn that residential proxies used to route malicious traffic are a big problem for IP reputation systems, as there is no clear distinction between attackers and legitimate users.
April 2nd, 2026 — Source

Software supply chain hacks trigger wave of intrusions, data theft
After linking the Axios npm supply chain attack to North Korean hackers, Google researchers warned that "hundreds of thousands of stolen secrets could potentially be circulating" as a result of this and the Trivy, KICS, LiteLLM, and Telnyx supply chain attacks (linked to TeamPCP).
April 2nd, 2026 — Source

Sophisticated CrystalX RAT Emerges
The malware can spy on victims, steal their information, and make configuration changes on devices.
April 2nd, 2026 — Source

Startup Linx Secures $50M as Identity Threats Intensify
AI-Native Platform Targets Identity Governance Gaps and Automation
April 2nd, 2026 — Source or Source

State AG Sues Change Healthcare in 2024 Ransomware Attack
Iowa Seeking Civil Monetary Fines, Damages for Alleged Violations
April 2nd, 2026 — Source or Source or Source or Source or Source

Suggested organizational security and privacy control and activity profile — Medium impact (ITSP.10.033-01)
This publication is part of a series of guidelines published by the Canadian Centre for Cyber Security (the Cyber Centre) under Cyber security and privacy risk management: A lifecycle approach.
April 2nd, 2026 — Source

Telehealth giant Hims & Hers says its customer support system was hacked
Hims & Hers, the telehealth company that sells weight-loss drugs and sexual health prescriptions, has confirmed a data breach affecting its third-party customer service platform.
April 2nd, 2026 — Source

The Best Way to Check Where Your Home Address Shows Up Online
Your home address almost certainly shows up on the web. Here's how to find out exactly where -- and how take action.
April 2nd, 2026 — Source

The company's biggest security hole lived in the breakroom
Connected devices can leave an otherwise secure network vulnerable
April 2nd, 2026 — Source

They thought they were downloading Claude Code source. They got a nasty dose of malware instead
Source code with a side of Vidar stealer and GhostSocks
April 2nd, 2026 — Source

TrueConf zero-day vulnerability exploited to target government networks
Suspected China-nexus attackers have leveraged a zero-day vulnerability (CVE-2026-3502) in the TrueConf client application to distribute malware within government networks in Southeast Asia, Check Point researchers discovered.
April 2nd, 2026 — Source

Variance Raises $21.5M for Compliance Investigation Platform Powered by AI Agents
Variance has raised a total of $26 million in funding and the latest investment will fuel platform growth.
April 2nd, 2026 — Source

Windows Security App Gains Secure Boot Certificate Status Ahead of Major Certificate Refresh
On your Windows PC, the Unified Extensible Firmware Interface (UEFI) uses Secure Boot certificates to ensure that only trusted software initiates the startup sequence. The certificates currently in use were originally issued in 2011 and are set to expire in late June 2026. To address this, Microsoft has been quietly rolling out updated certificates through Windows Update. Starting in April 2026, users can check their device's status via a new indicator in the Windows Security app. By navigating to Device security and then Secure Boot, a color-coded badge will show whether your device is fully updated, awaiting an update, or requires immediate attention.
April 2nd, 2026 — Source

Internet — Security Issues — April 1st, 2026

AI systems lack a fundamental property of human cognition: Understanding this gap may matter for safety
When a person reaches across a table to pass the salt, their brain is doing something far more complex than recognizing a request and executing a movement. It is drawing on a lifetime of bodily experience—where their hand is in space, what a saltshaker feels like, the social awareness of who asked and why. In a fraction of a second, their body and brain are working as one.
April 1st, 2026 — Source

Axios NPM Package Breached in North Korean Supply Chain Attack
A long-lived NPM access token was used to bypass the GitHub Actions OIDC-based CI/CD publishing workflow and push backdoored package versions.
April 1st, 2026 — Source

CIS Benchmarks March 2026 Update
The following CIS Benchmarks and CIS Build Kits have been updated or recently released. We've highlighted the major updates below. Each Benchmark and Build Kit includes a full changelog that references all changes.
April 1st, 2026 — Source

Egnyte expands Content Cloud with AI Governance and built-in Assistant
Egnyte has announced two major additions to the Egnyte Content Cloud: AI Safeguards, which give organizations granular control over how AI interacts with sensitive content, and an AI Assistant that acts as a built-in collaborator across Egnyte workspaces.
April 1st, 2026 — Source

Exabeam expands ABA to detect AI agent threats across ChatGPT, Copilot, and Gemini
Exabeam has announced the expansion of Exabeam Agent Behavior Analytics (ABA). Without direct visibility into how employees use AI assistants, what they query, what data they share, how frequently they interact, and from where, organizations cannot establish a baseline for normal AI behavior, investigate potential misuse, or detect emerging agentic insider threats.
April 1st, 2026 — Source

Exploited Zero-Day Among 21 Vulnerabilities Patched in Chrome
Google has announced fixes for CVE-2026-5281, a zero-day affecting Chrome's Dawn component.
April 1st, 2026 — Source

FBI Warns of Data Security Risks From China-Made Mobile Apps
The agency has not named the problematic foreign-made applications, but TikTok and Temu come to mind.
April 1st, 2026 — Source or Source

Google Addresses Vertex Security Issues After Researchers Weaponize AI Agents
Palo Alto Networks has disclosed the details of its analysis of Google Cloud Platform's Vertex AI.
April 1st, 2026 — Source

Google fixes Chrome zero-day with in-the-wild exploit (CVE-2026-5281)
Google has fixed 21 vulnerabilities affecting its popular Chrome browser, among them a zero-day (CVE-2026-5281) with an in-the-wild exploit.
April 1st, 2026 — Source

Google Warns Quantum Computers Could Crack Crypto Sooner Than Expected
Google warns that quantum computers could break crypto sooner than expected, heightening the urgency for post-quantum security across blockchain networks.
April 1st, 2026 — Source

Google research suggests encryption technique used by Bitcoin will be cracked by quantum computers around 2029 — search giant says quantum attacks need to be prepared for now
Cryptocurrencies aren't the only application at risk.
April 1st, 2026 — Source

Hacker charged for stealing $53 million in crypto, faces up to 30 years in prison — Uranium Finance thief spent $2 million of illicit funds on Magic: The Gathering, $1 million on Pokemon cards
The hacker used some of the proceeds to buy rare Magic: The Gathering and Pokemon cards and booster packs.
April 1st, 2026 — Source

Hasbro says it was hacked, and may take 'several weeks' to recover
American toy-making giant Hasbro has confirmed a cyberattack, and the company says it may take "several weeks" before the incident is resolved.
April 1st, 2026 — Source or Source

Microsoft: Hackers Are Using WhatsApp to Deliver Malware to Windows PCs
Hackers are using WhatsApp messages to deliver malware to Windows PCs, exploiting user trust and attachments to trigger stealthy, multi-stage attacks.
April 1st, 2026 — Source

New DeepLoad Malware Dropped in ClickFix Attacks
The malware steals credentials, installs a malicious browser extension, and can spread via USB drives.
April 1st, 2026 — Source

North Korean hackers linked to Axios npm supply chain compromise
The software supply chain attack that resulted in the compromise of npm packages of Axios, an extremely popular HTTP client library, is believed to be the work of financially-motivated North Korean attackers.
April 1st, 2026 — Source or Source

Routine Access Is Powering Modern Intrusions, a New Threat Report Finds
Remote access and trusted administrative tools play a central role in how organizations operate today. According to Blackpoint Cyber's 2026 Annual Threat Report, they are also increasingly central to how intrusions begin.
April 1st, 2026 — Source

Shift-Left Isn't Enough: Why Security Governance Must Be Baked Into Your CI/CD Pipeline From Day One
Shift-left alone won't protect your pipeline. Learn all about how security governance, policy-as-code, and SBOMs create a CI/CD pipeline built to last.
April 1st, 2026 — Source

Single antenna can steal AI model blueprints through walls
The ModelSpy attack system reconstructs deep learning architectures from GPU electromagnetic emissions at up to six meters, even through walls.
April 1st, 2026 — Source

Slack's upgraded AI can analyze how you work
It's part of Salesforce's broader pivot to AI.
April 1st, 2026 — Source

UK manufacturers under cyber fire with 80% reporting attacks
ESET says factory outages, lost revenue, and supply chain disruption are becoming routine
April 1st, 2026 — Source

US Charges Uranium Crypto Exchange Hacker
Jonathan Spalletta exploited smart contract vulnerabilities to steal approximately $55 million in cryptocurrency and cause Uranium to shut down.
April 1st, 2026 — Source

Why Would a Business Need to Use a Proxy Server?
Proxy servers offer critical benefits in security and competitive intelligence, but they introduce new complications and risks.
April 1st, 2026 — Source

Internet — Security Issues — March 31st, 2026

95 percent of organizations don't trust their cybersecurity vendors
As businesses rely more and more on data, trust ought to be a defining factor in cybersecurity decision-making. Yet new research from Sophos reveals that nearly all organizations lack full confidence in their cybersecurity vendors, and many struggle to assess vendor trustworthiness in the first place.
March 31st, 2026 — Source

2026 SANS State of Identity Threats & Defenses
New research from the 2026 SANS Identity Threats & Defenses Survey shows that 55% of organizations experienced an identity-related compromise last year, while 26% reported MFA fatigue as a factor in identity attacks.
March 31st, 2026 — Source

All Google users in the US can now change their Gmail address
Your old email will still be available as an alternate address.
March 31st, 2026 — Source

Android developers just got a new verification layer
To help prevent malicious actors from spreading harmful apps while hiding behind anonymity, Google is rolling out developer verification to all Android developers. The company is also introducing app registration, which links apps to verified developer identities.
March 31st, 2026 — Source

Apple counters ClickFix attacks with macOS Terminal warning
Apple has added a new security feature in macOS Tahoe 26.4 that warns users before they enter commands in Terminal that could cause harm. The goal is to stop ClickFix attacks, a social engineering trick that gets users to run malicious commands themselves.
March 31st, 2026 — Source

Axios npm packages backdoored in supply chain attack
An unknown attacker has compromised the GitHub and npm accounts of the main developer of Axios, a widely used HTTP client library, and published npm packages backdoored with a malicious dependency that triggered the installation of droppers and remote access trojans.
March 31st, 2026 — Source

Censys Raises $70 Million for Internet Intelligence Platform
The latest funding round brings the total venture capital investment in Censys to $149 million.
March 31st, 2026 — Source

CISA orders feds to patch actively exploited Citrix flaw by Thursday
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch their Citrix NetScaler appliances against an actively exploited vulnerability by Thursday.
March 31st, 2026 — Source

Cloudflare Adds Active API Vulnerability Scanning to Its Edge
Cloudflare has announced the open beta of its Web and API Vulnerability Scanner. This Dynamic Application Security Testing (DAST) tool is part of the API Shield platform. The first release focuses solely on Broken Object Level Authorization (BOLA), ranked first in the OWASP API Top 10. Future updates will expand to cover the wider OWASP Web Top 10, including SQL injection and cross-site scripting.
March 31st, 2026 — Source

Codenotary AgentMon monitors agentic AI activity and behavior
Codenotary launched AgentMon, an enterprise-grade monitoring designed specifically for agentic networks, providing organizations with real-time visibility into the security, performance and cost of AI-driven agents operating across the enterprise.
March 31st, 2026 — Source

CrewAI Vulnerabilities Expose Devices to Hacking
Attackers can exploit the bugs through prompt injection, chaining them together to escape the sandbox and execute arbitrary code.
March 31st, 2026 — Source

DoControl provides security coverage for Google Gemini Gems
DoControl announced new capabilities that provide visibility, monitoring, and automated control for Google Gemini Gems, a newly introduced feature within Google Gemini that enables teams to create customizable AI GPTs.
March 31st, 2026 — Source

Dutch Finance Ministry takes treasury banking portal offline after breach
The Dutch Ministry of Finance took some of its systems offline, including the digital portal for treasury banking, while investigating a cyberattack detected two weeks ago.
March 31st, 2026 — Source

EtherHiding: The trojan in your toolchain
The Canadian Centre for Cyber Security (Cyber Centre) is actively tracking a campaign exploiting blockchain technology to covertly host and distribute malware . This campaign leverages a technique known as EtherHiding.
March 31st, 2026 — Source

Event-Driven Patterns for Cloud-Native Banking: Lessons from What Works and What Hurts
When discussing event-driven architectures in the context of cloud platforms and highly regulated industries, it helps to start with a shared foundation. This topic attracts people with very different backgrounds, from engineers who have lived through the realities of distributed systems to those encountering these ideas for the first time. That shared foundation matters because event-driven architecture introduces concepts that sound simple at first, but are easy to misuse if they are not clearly understood from the outset.
March 31st, 2026 — Source

EvilTokens ramps up device code phishing targeting Microsoft 365 users
Security researchers report a notable increase in device code phishing activity aimed at Microsoft 365 users, and have attributed this rise to the availability of EvilTokens, a new, specialized phishing toolkit that's being offered as-a-service via Telegram.
March 31st, 2026 — Source

Exploitation of Critical Fortinet FortiClient EMS Flaw Begins
The SQL injection vulnerability allows unauthenticated attackers to execute arbitrary code remotely, via crafted HTTP requests.
March 31st, 2026 — Source

Failure As a Means to Build Resilient Software Systems: A Conversation with Lorin Hochstein
In this podcast Michael Stiefel spoke to Lorin Hochstein about how real-world failures provide insight into how software systems actually work. Our first topic was understanding that while automated fault injection tools can introduce basic robustness into a system, they cannot replicate the understanding that comes from mitigating complicated software failures in the real world. We then pondered how do we get this information to software architects so that they can learn from failure. Ironically, in reliable systems, adding more reliability can often lead to complexity which can lead to new failures.
March 31st, 2026 — Source

Foxit flags hidden security risks in PDFs with new tool
The update is led by PDF Action Inspector, a new tool that proactively scans documents for embedded JavaScript and self-modifying behaviors — threats that can bypass redaction, expose sensitive data, or alter document output without detection. As organizations rely on PDFs to share critical infrastructure, these risks have become a growing but often overlooked attack surface.
March 31st, 2026 — Source

Google Drive now detects ransomware and auto-restores your files
No more paying hackers to restore your data.
March 31st, 2026 — Source

Google Slashes Quantum Resource Requirements for Breaking Cryptocurrency Encryption
Google researchers have shown that breaking the encryption of Bitcoin and Ethereum requires 20x fewer qubits.
March 31st, 2026 — Source

Hacker charged with stealing $53 million from Uranium crypto exchange
U.S. prosecutors have charged a Maryland man with stealing more than $53 million after hacking the Uranium Finance crypto exchange twice and laundering the proceeds through a cryptocurrency mixer.
March 31st, 2026 — Source

Hacker stripped more than $50 million from Uranium crypto exchange, spent it on trading cards
US prosecutors have charged a Maryland man in connection with two hacks of the Uranium Finance cryptocurrency exchange that led to losses exceeding $50 million.
March 31st, 2026 — Source

Hackers compromise Axios npm package to drop cross-platform malware
Hackers hijacked the npm account of the Axios package, a JavaScript HTTP client with 100M+ weekly downloads, to deliver remote access trojans to Linux, Windows, and macOS systems.
March 31st, 2026 — Source

Hackers Shun Malware for Social Engineering in Recent Trends
It's good to know systems are more secure, but humans remain the weakest link in the chain.
March 31st, 2026 — Source

Health data giant CareCloud says hackers accessed patients' medical records
Healthcare technology giant CareCloud has confirmed that hackers accessed one of its stores of patients' electronic health records during a data breach earlier this month.
March 31st, 2026 — Source

How to Categorize AI Agents and Prioritize Risk
AI is entering a new phase. Enterprises have been experimenting with AI through chatbots and copilots that answered questions or summarized information. Now, the shift is toward implementing AI agents that can reason, plan, and take actions across enterprise systems on behalf of users or organizations.
March 31st, 2026 — Source

Iran's hackers are on the offensive against the US and Israel
Tehran hopes to stoke fear and extract intel in a series of cyber attacks.
March 31st, 2026 — Source

Lloyds Data Security Incident Impacts 450,000 Individuals
A faulty software update led to the exposure of mobile banking users' transactions to other users of the application.
March 31st, 2026 — Source

Meta reportedly tests way to secretly watch Instagram stories
It's a limited test right now.
March 31st, 2026 — Source

National Cyber Resilience Demands Unified Defense
UK NCSC's Richard Horne on Strengthening Cyber Defense and Incident Response
March 31st, 2026 — Source or Source or Source or Source

New Bitdefender assessment helps organizations identify and eliminate hidden internal attack paths
Bitdefender has announced the Bitdefender Internal Attack Surface Assessment, a complimentary evaluation that helps organizations identify and reduce hidden internal cyber risks caused by unnecessary user access to applications, tools, and operating system utilities commonly exploited in attacks. The assessment provides organizations with a data-driven view of their internal attack surface and offers actionable guidance to help prioritize and remediate exposure.
March 31st, 2026 — Source

North Korean hackers blamed for hijacking popular Axios open source project to spread malware
A suspected North Korean hacker has hijacked and modified a popular open source software development tool to deliver malware that could put millions of developers at risk of being compromised.
March 31st, 2026 — Source

One of JavaScript's most popular libraries compromised by hackers — Axios npm package hit in supply chain attack that deployed a cross-platform RAT
The hijacked maintainer account was used to publish two malicious versions of one of JavaScript's most popular libraries.
March 31st, 2026 — Source

Rspamd 4.0.0 ships memory savings, a new scan protocol, and a required migration step
The open-source spam filtering platform Rspamd released version 4.0.0, delivering infrastructure changes across its scan protocol, memory model, hash storage, and configuration system. Several of the changes are breaking, and at least one requires a migration step before upgrade.
March 31st, 2026 — Source

Supply chain blast: Top npm package backdoored to drop dirty RAT on dev machines
Hijacked maintainer account let attackers slip cross-platform trojan into 100M-downloads-a-week Axios
March 31st, 2026 — Source

Stolen Logins Are Fueling Everything From Ransomware to Nation-State Cyberattacks
Report shows how industrialized credential theft underpins ransomware, SaaS breaches, and geopolitical attacks, shifting security focus from prevention to detecting misuse of legitimate access.
March 31st, 2026 — Source

StrongSwan Flaw Allows Unauthenticated Attackers to Crash VPNs
Remotely exploitable, the integer underflow vulnerability impacts StrongSwan releases spanning 15 years.
March 31st, 2026 — Source

TeamPCP Moves From OSS to AWS Environments
After validating stolen credentials using TruffleHog, the hacking group started AWS services enumeration and lateral movement activities.
March 31st, 2026 — Source

The Next Cybersecurity Crisis Isn't Breaches—It's Data You Can't Trust
Data integrity shouldn't be seen only through the prism of a technical concern but also as a leadership issue.
March 31st, 2026 — Source

Venom Stealer Raises Stakes With Continuous Credential Harvesting
Licensed malware with built-in persistence and automation enables attackers to continuously siphon credentials, session data, and cryptocurrency assets.
March 31st, 2026 — Source

Vibrations in your skull may be your next password
A team led by Rutgers University researchers has developed a security system that could change how people log in to virtual and augmented reality platforms by eliminating passwords, personal identification numbers and eye scans and replacing them with something far more seamless.
March 31st, 2026 — Source or Source

Why 'Emerging Threats' Are Harder to Prioritize in the AI Era
Increased Speed, Scale and Automation Overwhelm Security Teams, Strategies
March 31st, 2026 — Source

Internet — Secuirty Issues — Miscellaneous

Adaptive Research & Design Co.
data recovery from crashes, viruses, electrical surges, and sabotage, on hard and floppy drives under any operating system.
Provides a Service — Source

Anti-Phishing Working Group
Committed to wiping out Internet scams and fruad.
An Article — Source

Catapult Integrated Systems
is a premier systems integrator and commercial managed Internet services provider serving northern California since 1992.
Provides a Service — Source

Data Security
Seclore is an information rights management company which helps to protect documents and information by preserving enterprise rights management.
Provides a Service — Source

European Institute for Computer Anti-Virus Research (EICAR)
leads task forces, organizes conferences, and publishes documents.
Provides Information — Source

Leprechaun Software
develops VirusBUSTER, an anti-virus software that protects PCs from boot, program, macro, and email based viruses.
Provides Information — Source

Packet Analytics
Net/FSE, Packet Analytics' network data search engine, puts the power of real time searches over terabytes of NetFlow data in the hands of security analysts. Employing sophisticated algorithms, Net/FSE reduces exposure to significant business risk by enabling security specialists to quickly and determine the extent of a network alert.
Provides a Service — Source

PhishTank
Out of the Net, into the Tank.
Provides a Service — Source

Remove Windows Script Hosting
completely from your system.
Provides Information — Source

SecureList
Kaspersky Lab presents Lab Matters, a series of webcasts that get right to the heart of some of the IT security industry's hottest topics. in the first program, two of the company's leading antimalware experts, Costin Raiu and Magnus Kalkuhl, will be giving viewers the complete lowdown on targeted attacks and discussing a host of other fascinating topics.
Provides Information — Source

Stiller Research
We provide current anti-virus news, a list of myths regarding viruses, a virus information list and a list of in-the-wild viruses.
Provides Information — Source

Symantec Security Updates
library of documents on computer viruses including the top ten list of most common viruses and new viruses to be on the alert for, as well as general virus Q&Amp;A.
Provides Information — Source

Virus Alert
for GOOD TIMES, read about these fake viruses.
Provides Information — Source

VirusTotal
VirusTotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines.
Provides a Service — Source

The MerchantStore © 1997 — 2026