access ai android api apple attack authentication backdoor breach business ceo china cisa cisco ciso cloud compliance control credentials crypto cve cyber cyberattack cybercrime cybersecurity data data-breach defense detection email exploit finance flaw framework fraud google governance government group hacker hacking healthcare identity infrastructure injection intelligence Internet jobs law leak linux malicious malware microsoft monitoring network open-source password phishing privacy ransomware remote-code-execution resilience risk russia scam service software strategy supply-chain technology theft threat tool unclassified update usa vulnerability windows zero-day
-
Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
Today is Microsoft’s August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-august-2026-patch-tuesday-fixes-400-flaws-3-zero-days/ also interesting: Microsoft fixes 2 zero-days in massive July Patch Tuesday URGENT: Microsoft Patches 57 Security Flaws, Including 6…
-
Microsoft releases Windows 10 KB5120249 extended security update
Microsoft has released Windows 10 KB5120249 Extended Security Updates for versions 22H2 and 21H2 to fix security vulnerabilities and bugs. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/windows-10-kb5120249-cumulative-update-released-with-fixes/ also interesting: Microsoft Security Update Summary (11. Februar 2025) Microsoft Patch Tuesday security updates for February 2025 ficed 2 actively exploited bugs July Patch Tuesday: 14 critical…
-
OpenAI, Anthropic, and Meta AI Breaches Shared the Same Testing Vendor
OpenAI, Anthropic, and Meta AI incidents reportedly shared one testing vendor, exposing third-party and containment risks in AI security evaluations. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cloud-security/news-openai-anthropic-meta-ai-incidents-irregular/ also interesting: Cybersecurity Snapshot: NIST Offers Zero Trust Implementation Advice, While OpenAI Shares ChatGPT Misuse Incidents 13 cybersecurity myths organizations need to stop believing Five steps to…
-
CEVA Logistics Breach Triggers Customer Data Alerts Across Europe
CEVA Logistics’ data breach exposed customer and order information across European clients, raising phishing and third-party security concerns. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-ceva-data-breach-emea-eu/ also interesting: China-linked hackers target Japan’s national security and high-tech industries Adidas customers’ personal information at risk after data breach North Korean Kimsuky Hackers Suffer Data Breach as Insiders…
-
Zoom Patches “Zoomsday” Zero-Click Flaw Enabling Remote Code Execution
Zoom patches a zero-click flaw that could let a meeting participant execute code on another user’s computer through the annotation feature. Zoom has patched four vulnerabilities, including a critical zero-click flaw, tracked as CVE-2026-53413, in its annotation feature. CVE-2026-53413 is a memory corruption issue found by A Security that could allow a meeting participant to…
-
Delta investigates in-flight Wi-Fi spoofing on post-DEF CON flight from Las Vegas
The airline deactivated the network after the crew realized someone was messing with the in-flight system. The feds are investigating. First seen on cyberscoop.com Jump to article: cyberscoop.com/delta-flight-rogue-wifi-investigation-def-con-las-vegas/ also interesting: Extreme startet mit der NFL in die 12. Saison als offizieller Ausstatter von WiFi-Lösungen und Analytics Privacy Roundup: Week 11 of Year 2025 Travelers Beware:…
-
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
Tags: blockchain, communications, data, extortion, group, infrastructure, leak, microsoft, network, ransomware, service, threatThe ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience.”Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process,” the Microsoft Threat First seen on thehackernews.com Jump…
-
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent.The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft’s First…
-
Windows 11 KB5121003 & KB5120240 cumulative updates released
Microsoft has released Windows 11 KB5121003 and KB5120240 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/windows-11-kb5121003-and-kb5120240-cumulative-updates-released/ also interesting: Microsoft Unveils European Security Effort to Disrupt Cybercrime Networks Microsoft Patch Tuesday security updates for September 2025 fixed two zero-day flaws Microsoft’s September Security Update…
-
The inconvenient truth about AI pentesting: someone has to check all the work
AI pentesting can flood teams with findings they cannot validate. The real challenge is managing “validation debt” as discovery scales. AI pentesting has a ‘Sorcerer’s Apprentice’ problem. Enchant a broom to fetch water, and it will fetch water, relentlessly, long after the workshop has flooded. The industry is busy measuring how fast AI finds vulnerabilities…
-
Iran-Linked Hackers Target More US Water Infrastructure in New Jersey and Alabama
Iran-linked hackers targeted Water Infrastructure in New Jersey and Alabama, bringing confirmed attacks to at least 12 states, with limited disruption. The wave of cyberattacks targeting US water infrastructure has reached New Jersey and Alabama, bringing the confirmed count to at least 12 states since late July. The attacks are linked to Iranian hackers targeting…
-
ExfilSquad Targets New Victims, Shares Data via Torrents
ExfilSquad targets 13 organizations, exploiting cloud portals for data theft and using torrents to spread stolen information and amplify damage. Resecurity is tracking the activity of ExfilSquad the group announced new victims this week. ExfilSquad is a new cybercrime group that emerged in mid-2026. Instead of using ransomware, it steals data and threatens to […]…
-
Shattering the Dream When a Job Offer Becomes a Zero-Day Attack
ey Points Introduction Since early 2026, Check Point Research has tracked a wave of theOperation Dream Jobcampaign. This wave primarily targeted the defense sector worldwide, with a particular emphasis on companies operating in the aerospace and aviation industries. We observed the threat actor distributing modified PDF viewers designed to execute malicious payloads embedded within specially…
-
QA: Ransomware is now a ‘fully fledged industry’, says cybercrime journalist Geoff White
Cybercrime no longer divides neatly between lone hackers, organised gangs and state-backed operations. These groups exchange tactics and tools, while stolen data gives them an asset that can be sold, used for fraud, held to ransom or weaponised for political damage. Geoff White is an award-winning investigative journalist whose reporting has taken him inside global…
-
Alert: Unpatched Fortinet Devices Fall to Gunra Ransomware
Tags: access, cybersecurity, firewall, fortinet, government, group, infrastructure, korea, north-korea, ransomware, vpnUS and South Korea Tie Initial Access to Unpatched Firewalls and VPN Gateways. Critical infrastructure organizations running unpatched firewalls and VPN gateways – including Fortinet gear not updated since early 2025 – and getting hit hard by a ransomware group with possible ties to the North Korean government, warns a joint U.S.-South Korean cybersecurity alert.…
-
Cisco Warns of Seven ClamAV Flaws, Two With Public PoCs
Cisco warns that seven ClamAV flaws affect Secure Endpoint Connector products, with two having public PoCs that could enable remote DoS attacks. Cisco warned that seven ClamAV vulnerabilities affect its Secure Endpoint Connector on Windows, macOS and Linux. ClamAV is an open-source antivirus engine widely used to scan files and emails for malware. The company…
-
Steam-Versandpartner gehackt Phishing-Angriffe zu erwarten
Steam, die Videospiel-Vertriebsplattform von Valve, hat begonnen, Kunden per E-Mail zu warnen. Laut Valve haben Angreifer zwischen dem 29. Juli und dem 1. August CEVA Logistics attackiert das Unternehmen, das den Versand von Steam-Hardware an Kunden in ganz Europa abwickelt. Für diese Aufgabe erhält CEVA Lieferdaten von Steam und die Angreifer haben vermutlich […] First…
-
Wesco confirms security incident after ExfilSquad claims data theft
Global supply chain and distribution giant Wesco has confirmed in a statement for BleepingComputer that it is investigating a cybersecurity incident. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/wesco-confirms-security-incident-after-exfilsquad-claims-data-theft/ also interesting: What is the cost of a data breach? Cybersecurity Snapshot: Prompt Injection and Data Disclosure Top OWASP’s List of Cyber Risks for GenAI LLM…
-
Verschlüsselte KI-Denkprotokolle geknackt Schwachstelle bei OpenAI, Anthropic und Google
Forscher haben eine gravierende Schwachstelle bei der Absicherung sogenannter Reasoning-Logs entdeckt. Verschlüsselte Denkprotokolle moderner KI-Modelle lassen sich demnach unter bestimmten Bedingungen über ein schwächeres Modell desselben Anbieters entschlüsseln. Besonders brisant: In öffentlich zugänglichen Datensätzen fanden die Forscher bereits personenbezogene Daten, Zugangsdaten, API-Schlüssel und Passwörter. Forscher von MATS Research, dem Max-Planck-Institut für intelligente Systeme, dem ELLIS…
-
Delta investigating after someone set up fake Wi-Fi network mid-flight
The Delta flight crew switched off the aircraft’s legitimate Wi-Fi network for around 30 minutes due to the incident, according to a spokesperson. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/11/delta-investigating-after-someone-set-up-fake-wi-fi-network-mid-flight/ also interesting: One Simple Trick to Knock Out the Wi-Fi Network CyRC advisory: Vulnerability in Broadcom chipset causes network disruption and client disconnection on…
-
NIST wants to overhaul its vulnerability database for the AI age
NIST is seeking public input to modernize the National Vulnerability Database to keep pace with AI-driven cyber threats and machine-scale security data. First seen on cyberscoop.com Jump to article: cyberscoop.com/nist-national-vulnerability-database-ai-overhaul/ also interesting: Cybersecurity Snapshot: CISA’s Best Cyber Advice on Securing Cloud, OT, Apps and More Cybersecurity Snapshot: Industrial Systems in Crosshairs of Russian Hackers, FBI…
-
Cyberattack on logistics giant Ceva hits retailers and Steam customers across Europe
Tags: cyberattackOperations at eight European warehouses belonging to France’s CEVA Logistics have reportedly been disrupted by a cyberattack, and several other companies are feeling the effects. First seen on therecord.media Jump to article: therecord.media/ceva-logistics-cyberattack-bol-steam-debijenkorf-ace-tate also interesting: Cyberangriff auf eine Baumarkt-Kette in der Ukraine Hohe Wahrscheinlichkeit eines Angriffs – Cyberangriffe auf Watchguard Firebox-Appliances laufen Ukrainian hacker charged…
-
CVE Program eyes automation and globalization to weather AI ‘vulnpocalypse’
The vulnerability-coordination project has had a rocky few years, but a key leader says it will “flourish and improve.” First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/cve-program-ai-black-hat-def-con/827477/ also interesting: CVE-2025-58434: Critical FlowiseAI Flaw Enables Full Account Takeover TDL 019 – The Psychology Behind a Cyber Breach and the Leaders Who Survive It – Nim Nadarajah…
-
Former BlackFile affiliates linked to extortion campaign targeting private equity
Researchers warned that hackers are using voice-phishing attacks to pressure company employees under the guise of providing IT help desk services. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/former-blackfile-extortion-campaign-private-equity/827574/ also interesting: Cybersecurity Snapshot: Top Advice for Detecting and Preventing AI Attacks, and for Securing AI Systems The cybercrime industry continues to challenge CISOs in 2026…
-
Ransomwaregruppe – 19-jähriger als mutmaßliches Scattered-Spider-Mitglied verhaftet
Tags: unclassifiedFirst seen on security-insider.de Jump to article: www.security-insider.de/scattered-spider-verdaechtiger-usa-ausgeliefert-gdid-a-55b7623458325e933f702770a0b9ee5d/ also interesting: How to tell if your online accounts have been hacked Netze: So will die EU Huawei & Co. bei Seekabeln stärker außen vor halten DriveLock Hypersecure Platform A week in security (March 23 March 29)
-
Cursor Security Bug Allowed Repositories to Execute Commands Before Trust Verification
Tags: unclassifiedCursor fixed a pre-trust code execution path in three days then closed the report as informative First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cursor-security-bug-command/ also interesting: Crimemarket: Amazon für Kriminelle geschlossen Tornado Cash Developer Sentenced to 5 Years in Prison Now there’s a species of crayfish named after Edward Snowden FBI Apprehends Alleged LulzSec Member…
-
Cursor Security Bug Allowed Repositories to Execute Commands Before Trust Verification
Tags: unclassifiedCursor fixed a pre-trust code execution path in three days then closed the report as informative First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cursor-security-bug-command/ also interesting: Deutsche Bahn: Betrugsfälle durch Bankkonto-Bestätigung zurückgegangen Zusammengetragen von Pure Storage – Die 10 größten Datenpannen 2024 Trump’s ouster of NSA, Cybercom chief receives bipartisan backlash Synology Protokoll-Center – Zentrale…
-
Six npm Packages Read C2 Addresses From Ethereum Wallet
Tags: infrastructureSix npm packages queried an Ethereum wallet to locate C2 infrastructure First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/npm-packages-ethereum-wallet-c2/ also interesting: Traffic Distribution System (TDS) abuse What’s hiding behind the veil? Alibaba Cloud can’t deploy servers fast enough to satisfy demand for AI Authorities Dismantle IoT Botnet Linked to Record-Shattering 30 Tbps DDoS Campaigns Hugging…
-
Ransomware Attacks Are Targeting Managers and other Business Leaders
Zscaler findings show ransomware attackers increasingly target managers and business leaders. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/ransomware-attacks-are-targeting-managers-and-other-business-leaders/ also interesting: Cybersecurity Snapshot: Study Raises Open Source Security Red Flags, as Cyber Agencies Offer Prevention Tips Against Telecom Spying Attacks Cybersecurity Snapshot: New Standard for AI System Security Published, While Study Finds Cyber Teams Boost…
-
AI Helps Researchers Uncover Zoom Zero-Click RCE in Less Than a Day
Researchers used public AI models to uncover ZOOMSDAY, a critical Zoom zero-click RCE exploit chain, in less than 24 hours. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/ai-helps-researchers-uncover-zoom-zero-click-rce-in-less-than-a-day/ also interesting: Claude Identifies Critical 13-Year-Old RCE Vulnerability in Apache ActiveMQ From SQLi to RCE Exploiting LangGraph’s Checkpointer Langflow RCE Exploited to Deploy Monero Miner on Exposed…
-
Blumira Unveils AI Command Center for Cybersecurity Tools
Blumira today unfurled a command center that makes it simpler to integrate cybersecurity tools based on artificial intelligence (AI) that were developed by different vendors. Mike Toole, head of security and IT for Blumira, said Hearth makes it possible to integrate cybersecurity tools from different vendors through a common interface. Additionally, cybersecurity teams will find..…
-
OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development
OpenAI on Monday unveiled a new cybersecurity-focused model called GPT”‘5.6″‘Cyber that it said is focused on vulnerability research, penetration testing, and incident response.”Built on GPT”‘5.6 Sol, it is trained to improve capabilities on several specialized cybersecurity tasks (e.g., finding zero-day vulnerabilities and developing exploit chains) and to reduce refusals for certain higher-risk First seen on…
-
Sherlock Holmes Was the ‘OG’ Social Engineer
The crime solver wore disguises, spied on targets, and built intelligence networks long before modern-day tactics emerged. He has lessons for today’s ethical- and nonethical-hat hackers. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/sherlock-holmes-was-the-og-social-engineer also interesting: Unusual attack linked to Chinese APT group combines espionage and ransomware Threat-informed defense for operational technology: Moving from information…
-
DDoS attacks over 1 Tbps surged fivefold in the second quarter
Cloudflare says it mitigated more than 800 network-layer distributed denial-of-service (DDoS) attacks exceeding 1 Tbps in the second quarter of the year. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ddos-attacks-over-1-tbps-surged-fivefold-in-the-second-quarter/ also interesting: CryptoDNA: AI-Powered Cryptojacking Defense Against DDoS Threats in Healthcare IoT 9 things CISOs need know about the dark web 2025 Threat Landscape in…
-
Vague Task, Total Access: When AI Delegation Becomes a Security Risk
AI agents can improvise beyond the intended scope of a task when they are given broad access to enterprise systems and data. Token Security explains why organizations need to define agent intent and continuously enforce permissions around what each agent was actually created to do. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/vague-task-total-access-when-ai-delegation-becomes-a-security-risk/ also interesting:…
-
Mozilla updates GPG signing key for Firefox releases after exposure
Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/mozilla-updates-gpg-key-for-signing-firefox-thunderbird-releases-after-exposure/ also interesting: Privacy Roundup: Week 6 of Year 2025 Privacy Roundup: Week 9 of Year 2025 Google to Patch 23-Year-Old Chrome Bug That Leaked…
-
Drei KI-Vorfälle in vierzehn Tagen Von der Evaluierung zum Ernstfall
Innerhalb von vierzehn Tagen haben OpenAI, Anthropic und das britische AI Security Institute (AISI) jeweils offengelegt, dass KI-Agenten im Rahmen interner Sicherheitsprüfungen den vorgesehenen Testrahmen verlassen und auf reale Systeme sowie reale Personen eingewirkt haben. Weniger bemerkenswert als die Einzelfälle ist dabei die Geschwindigkeit, mit der sich die Fähigkeiten dieser Agenten entwickeln und der […]…
-
95 Prozent der Unternehmen verschieben KI-Projekte aufgrund von Hürden in der Datenarchitektur
Tags: aiCloudera veröffentlicht seine neueste globale Studie ‘The Great AI Re-Architecture”. Diese zeigt einen grundlegenden Wandel in der Unternehmens-IT. So überarbeiten immer mehr Betriebe ihre Datenarchitekturen, um den Anforderungen von KI gerecht zu werden. Denn obwohl die KI-Nutzung zum Standard geworden ist, schränken veraltete Datenarchitekturen zunehmend die Fähigkeit von Unternehmen ein, KI sicher, effizient und kostengünstig zu…
-
North Korean remote IT staffer worked for US government agency, says FBI
The investigation shows that North Koreans are able to infiltrate government agencies, as well as private organizations and crypto exchanges. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/11/north-korean-remote-it-staffer-worked-for-us-government-agency-says-fbi/ also interesting: 7 biggest cybersecurity stories of 2024 US, Japan and S. Korea urge crypto industry to take action against North Korean hackers North Korean APT43 Uses…
-
Local governments in four states dealing with cyberattacks that have shut down services
Municipalities in California, Oklahoma, Wisconsin and Texas are all recovering from disruptive cyberattacks that have affected government operations. First seen on therecord.media Jump to article: therecord.media/cyberattacks-ransomware-local-governments also interesting: US government contractor ENGlobal says operations are ‘limited’ following cyberattack Öffentliche Verwaltung im Visier von Cyberspionen China-Linked APT31 Launches Stealthy Cyberattacks on Russian IT Using Cloud Services…
-
New surveillance tech links your phone to your license plate
Phone and Bluetooth signals could turn roadside cameras into far richer tracking tools. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/08/new-surveillance-tech-links-your-phone-to-your-license-plate/ also interesting: Privacy Roundup: Week 4 of Year 2025 Commercial spyware “Landfall” ran rampant on Samsung phones for almost a year Beyond silos: How DDI-AI integration is redefining cyber resilience Research: Predator spyware can…
-
A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
A malicious SIM card can order the device it sits in to run commands of the attacker’s choosing. On the cellular modules built into electric-vehicle chargers, industrial routers, and car telematics units, that is enough to take the whole device over.Researchers at the University of Birmingham and the security firm Fuzzware tested 26 phones and…
-
Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers
Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording.The onboarding paperwork is the part hiring teams can use. The first hire claimed to live in Pasadena, Texas, then sent a California driver’s license and a New York…
-
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo
Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake to one of the company’s own private code repositories.That key is how a user, or a Linux distribution packaging the browser, confirms a downloaded Firefox tarball came from Mozilla and was not…
-
Microsoft SharePoint flaw now exploited in ransomware attacks
CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-flaw-now-exploited-in-ransomware-attacks/ also interesting: The 2024 cyberwar playbook: Tricks used by nation-state actors Frequently Asked Questions About Iranian Cyber Operations Microsoft Patch…
-
LiteLLM Attack Shows AI Infrastructure Is Becoming a Strategic Software Supply Chain Target
Tags: ai, attack, breach, cloud, credentials, cyber, infrastructure, malicious, pypi, software, supply-chain, theftThe March 2026 compromise of LiteLLM was more than a short-lived malicious PyPI upload. It demonstrated how an upstream breach in developer tooling can turn AI infrastructure into a high-value conduit for credential theft, cloud intrusion, and downstream software supply chain abuse. The packages were available for roughly 40 minutes before quarantine, but their brief…
-
Plug Pwn Attack Exploits Windows PnP to Gain SYSTEM Access With Zero Clicks
Security researchers Alejandro Hernando, also known as 0xedh, and Borja MartÃnez have unveiled a research project titled >>Plug & Pwn.<< This project demonstrates how the Windows Plug and Play (PnP) driver installation workflows can be exploited to execute vendor-supplied code with NT AUTHORITY\SYSTEM privileges. Presented at DEF CON 34, the research explores the risky intersection…
-
A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call
Researchers say it took fewer than 20 prompts for a public AI tool to find a flaw (now fixed) allowing anyone on a Zoom call to hijack another participants’ device. First seen on wired.com Jump to article: www.wired.com/story/a-zoom-screen-sharing-bug-let-anyone-take-over-other-devices-on-a-call/ also interesting: U.S. CISA adds Langflow flaw to its Known Exploited Vulnerabilities catalog ThreatsDay Bulletin: AI Tools…

