access ai android api apple attack authentication backdoor breach business ceo china cisa cisco ciso cloud compliance control credentials crypto cve cyber cyberattack cybercrime cybersecurity data data-breach defense detection email exploit finance flaw framework fraud google governance government group hacker hacking healthcare identity infrastructure injection intelligence Internet jobs law leak linux malicious malware microsoft monitoring network open-source password phishing privacy ransomware remote-code-execution resilience risk russia scam service software strategy supply-chain technology theft threat tool unclassified update usa vulnerability windows zero-day
-
Swiss government SharePoint breach compromised 200 accounts
Switzerland’s federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/swiss-government-sharepoint-breach-compromised-200-accounts/ also interesting: The 2024 cyberwar playbook: Tricks used by nation-state actors The 2024 cyberwar playbook: Tricks used by nation-state actors The most notorious and damaging ransomware of all…
-
Tangled Up Photons on Offer in New Mexico QKD Testbed
Tags: cryptographyNext Generation Cryptography Showcased Over Leased Albuquerque Fiber. An advantage of quantum key distribution is that – despite it being a symmetric key – eavesdroppers can’t intercept the key without changing it. That’s due to the observer effect, a property of quantum physics in which observation collapses superposition into a single, definite state. First seen…
-
Ransom Cartel creator sentenced to 16 years in prison
Maksim Silnikau participated in cybercrime since at least 2005. He ran Ransom Cartel from 2021 until his arrest in 2023. First seen on cyberscoop.com Jump to article: cyberscoop.com/ransom-cartel-creator-sentenced-to-16-years-in-prison/ also interesting: Japanese game and anime publisher reportedly pays $3 million ransom to Russia-linked hackers Japanese game and anime publisher reportedly pays $3 million ransom to Russia-linked…
-
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review.The security issues affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and Cisco IOS XE Software when it is running in autonomous or controller mode.”These vulnerabilities were found First…
-
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests.The flaw is tracked as CVE-2026-64561 and affects KVM/x86’s shadow memory management unit (MMU), which…
-
New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes
Researchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-tontou-cpu-attack-bypasses-spectre-v2-fixes-leaks-linux-password-hashes/ also interesting: What to Know About CyberAv3ngers: The IRGC-Linked Group Targeting Critical Infrastructure The most notorious and damaging ransomware of all time…
-
Photos: Black Hat USA 2026, part two
Tags: usaRound two from Black Hat USA 2026. This set covers the parts of the show floor that did not make the first gallery. Scroll through below. Featured vendors: BlackCloak, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/06/black-hat-usa-2026-business-hall-photos/ also interesting: Cyberangriff auf einen Anbieter von Medizinprodukten aus den USA DragonForce Ein Ransomware-Kartell sichert seine Stellung…
-
1Password Finds AI Security Patches Fail More Than Half the Time
A 1Password study found AI-generated security patches failed to fully fix vulnerabilities in more than half of tested cases. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/artificial-intelligence/1password-finds-ai-security-patches-fail-more-than-half-the-time/ also interesting: Ring’s Search Party ‘Dystopia’ Debate Claude Zero-Click RCE Vulnerability Most Google Cloud Attacks Start With Bug Exploitation US government agency to safety test frontier AI models…
-
Why AI Governance Requires Continuous Compliance Assurance
Schellman CEO Avani Desai on Building Governance Before Technology Enforcement. Artificial intelligence governance must evolve as agentic AI systems make decisions at machine speed. Schellman CEO Avani Desai explains why organizations need continuous auditing, unified controls and multiple frameworks to prove AI trustworthiness without slowing innovation. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/ai-governance-requires-continuous-compliance-assurance-a-32438 also…
-
Why Open-Weight AI Models Are Key to US Strategy
Rain Capital’s Chenxi Wang on Why Closed AI Models Risk US Competitiveness. Machine-scale AI attacks demand machine-scale defenses, says Rain Capital’s Chenxi Wang. She says America’s edge depends on backing open-weight models and using the world’s top AI researchers, not retreating behind closed systems that cede ground to competitors. First seen on govinfosecurity.com Jump to…
-
Why Passkeys Are Closing the Account Takeover Gap
HealthEquity’s Ajit Gaddam on Passwordless Security, Fraud Signals, Cyber Defense. Passwords remain a weak point in account security, especially when attackers can buy stolen credentials and exploit recovery workflows. Ajit Gaddam explains how passkeys, biometrics and device signals can strengthen identity assurance while reducing login friction. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/passkeys-are-closing-account-takeover-gap-a-32442 also…
-
Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance Records
An exposed SISVISA database leaked 102,215 Brazilian health records, exposing IDs, tax data, and regulatory documents without authentication. Researcher Jeremiah Fowler found a publicly accessible database that turned out to belong to SISVISA, Brazil’s Health Surveillance Information System, and alerted ExpressVPN, which later shared the findings with Hackread. The exposed instance held exactly 102,215 files,…
-
Day 2 at Black Hat: Check Point Research Takes the Stage
ay two at Black Hat, and Check Point Research brought two talks to the stage that gave the room plenty to think about. One dug into afifteen year oldblind spot sitting inside Windows itself. The other pulled apart the agent frameworks powering today’s AI products and found familiar bugs wearing new clothes. Here’swhat our researchers…
-
Why metaphor may dictate your security strategy
In this week’s newsletter, Martin looks at how the metaphors we use to describe AI “escaping” its sandbox can completely change how we react to the threat. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/ also interesting: Inside the AI-driven threat landscape AI programming copilots are worsening code security and leaking more secrets Identity-First Security:…
-
Cyberattack on North Carolina Ports ‘contained’ as Coast Guard, state officials investigate
North Carolina Ports is recovering from a cyberattack after its IT system was “hacked by an outside actor or group,” requiring a switch to manual processing of operations. First seen on therecord.media Jump to article: therecord.media/cyberattack-north-carolina-ports also interesting: Der Raspberry-Pi-Weckruf für CISOs Der Raspberry-Pi-Weckruf für CISOs TDL 019 – The Psychology Behind a Cyber Breach…
-
New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs
An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using it, re-poisoning the predictor after the defense has run.MIT CSAIL researchers Daniël Trujillo and Mengjia Yan named the technique INTERRUPT INJECTION. On an AMD Zen 2 machine running Linux 6.14…
-
Meta AI model hacked a company during misconfigured cyber test
Meta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents continue to emerge following OpenAI’sOpenAI’s initial disclosure that its agents breached Hugging Face. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/meta-ai-model-hacked-a-company-during-misconfigured-cyber-test/ also interesting: TDL001 – Cybersecurity Explained: Privacy, Threats, and the…
-
Meta AI model hacked a company during misconfigured cyber test
Meta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents continue to emerge following OpenAI’sOpenAI’s initial disclosure that its agents breached Hugging Face. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/meta-ai-model-hacked-a-company-during-misconfigured-cyber-test/ also interesting: The AI race: Dark AI is in the…
-
Meta AI model hacked a company during misconfigured cyber test
Meta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents continue to emerge following OpenAI’sOpenAI’s initial disclosure that its agents breached Hugging Face. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/meta-ai-model-hacked-a-company-during-misconfigured-cyber-test/ also interesting: The AI race: Dark AI is in the…
-
Ransom Cartel Leader Sentenced to 16 Years in U.S.
A U.S. court sentenced Ransom Cartel founder Maksim Silnikau to 16 years for running a ransomware-as-a-service operation. Maksim Silnikau (aka >>J.P. Morgan,<>lansky,<>xxx,<<) built a ransomware business the way a franchise owner builds a chain: he never had to touch most of the crime scenes himself. This week, a federal judge in Virginia […] First seen…
-
Hacker pleads guilty to stealing data from more than 165 Snowflake customers
Connor Moucka pled guilty to hacking and stealing data from more than 165 Snowflake customers, which net him and his accomplices more than $2.5 million in ransom payments. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/06/hacker-pleads-guilty-to-stealing-data-from-more-than-165-snowflake-customers/ also interesting: 8 Cyber Predictions for 2025: A CSO’s Perspective NC Pathology Practice Notifying 236,000 of Data Theft Hack…
-
Toolkit Hidden Inside Oracle Database Evades Endpoint Tools
Attackers used SQL injection to compile a post-exploitation toolkit inside an Oracle database First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/khunt-toolkit-oracle-database-sql/ also interesting: Top 7 zero-day exploitation trends of 2024 Cybersecurity Snapshot: AI Will Take Center Stage in Cyber in 2026, Google Says, as MITRE Revamps ATTCK Framework LeakyLooker: Hacking Google Cloud’s Data via Dangerous…
-
ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories
Apparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF can finish the job.This week runs on cheap leverage: exposed servers, recycled bugs, poisoned agent instructions, remote-access tools dressed as support software, and trusted defaults doing attackers a favor.Nothing here…
-
The 12 Best Protective DNS (PDNS) Services, Compared and Priced (2026)
Protective DNS is the rare control where the cheap options are genuinely good so this comparison leads with value. The verdict: DNSFilter is the best published-price PDNS for most organizations, Cloudflare Gateway owns the free-to-enterprise arc (and now runs the UK’s national PDNS with Accenture), N-able and ScoutDNS serve MSPs at fair rates, CIRA gives…
-
The Best Firewall Management Tools, Compared and Priced (2026)
The firewall policy management market had its earthquake: Skybox Security shut down overnight in February 2025, selling its technology to Tufin and leaving customers to migrate a reminder that in this category, vendor viability is a feature. The value verdict: Tufin (now absorbing Skybox’s base) and AlgoSec lead enterprise policy governance, FireMon owns real-time visibility…
-
Republic of Georgia alleges foreign disinfo campaign sought to scare off Russian tourists
Georgia’s State Security Service is investigating whether foreign entities were behind the spread of fabricated stories claiming that Georgians were mistreating Russian tourists. First seen on therecord.media Jump to article: therecord.media/georgia-alleges-foreign-disinformation-scare-russian-tourists also interesting: Project DDoSia Russian Hackers Planning a Massive DDoS Attack Act fast to snuff out employee curiosity over ‘free’ AI apps Russia’s sabotage…
-
Gegen den gesunden Menschenverstand: Pubs und Theater verbieten Metas Datenbrillen
Tags: unclassifiedUm heimliche Aufnahmen von Gästen und Personal zu verhindern, verbieten immer mehr Einrichtungen in Großbritannien Datenbrillen. First seen on golem.de Jump to article: www.golem.de/news/gegen-den-gesunden-menschenverstand-pubs-und-theater-verbieten-metas-datenbrillen-2608-211686.html also interesting: Almost unfixable Sinkclose bug affects hundreds of millions of AMD chips Privatsphäre: Airbnb verbannt Sicherheitskameras ganz aus vermieteten Apartments Achieving Excellence through ISMS Implementation Bürger unter Generalverdacht: DAV kritisiert…
-
MCTTP 2026 – So holen Sie das Maximale aus Defender-Telemetriedaten heraus
Tags: unclassifiedFirst seen on security-insider.de Jump to article: www.security-insider.de/defender-for-endpoint-telemetrie-regeln-filter-limits-blindspots-mcttp-2026-a-5685be7dd4a38ea8c77e1ec9a993e86c/ also interesting: (ISC)2 Announces Young Professionals Program SAA statt CIA: Worauf es bei der Erkennung von Insiderangriffen ankommt Anzeigetafeln eines Museums in Russland gehackt Jscrambler Raises $5.2 Million for Code, Webpage Protection Solution
-
TeamPCP Traced Back to 2020 Cryptojacking Operation
Tags: infrastructureOligo Security has linked TeamPCP to ShadowRay 2.0 and to cryptojacking infrastructure dating back to 2020 First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/teampcp-shadowray-ta-natalstatus/ also interesting: Strengthening Critical Infrastructure Defense: Shifting to an Exposure Management Mindset JFrog und NVIDIA bündeln Ihre Kräfte für eine souveräne KI Cloudflare Confirms API Outage Caused by React useEffect Overload…
-
How AI Exposed a Browser Security Gap that Enterprises Cannot Ignore
AI did not create a new browser security problem. It exposed one that enterprises have long been able to ignore. Skyhigh Security explains why browsers have become a critical control point for governing data movement, AI interactions, and modern work. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/how-ai-exposed-a-browser-security-gap-that-enterprises-cannot-ignore/ also interesting: Your Network Is Showing Time…
-
Apple Photos Privacy Case Advances, With Up to $32.5 Billion Alleged Exposure
Apple’s Photos biometric privacy case will proceed after an appeals court declined to review class certification. Here’s what remains unresolved. The post Apple Photos Privacy Case Advances, With Up to $32.5 Billion Alleged Exposure appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-apple-photos-bipa-class-action-appeal/ also interesting: >>Siri Data Stays Private, Not Used for…
-
Novel-reading apps used users’ phones to generate fake ad traffic
A new mobile ad fraud scheme, dubbed Papyrus, is using a cluster of novel-reading apps to generate hidden browser traffic, according to IAS Threat Lab. Sample novel-reading … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/06/papyrus-mobile-ad-fraud-scheme/ also interesting: ‘Sim farms’, high heels, zombie knives: what scammers buy with the money they steal Colossal breach exposes…
-
Black Hat 2026: Critical Flaws Found in Anthropic, Google, and OpenAI Coding Agents
Researchers disclosed critical flaws in AI coding agents from Anthropic, Google, and OpenAI that could enable credential theft, RCE, and supply chain attacks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/black-hat-2026-critical-flaws-found-in-anthropic-google-and-openai-coding-agents/ also interesting: Top 5 real-world AI security threats revealed in 2025 The 2024 cyberwar playbook: Tricks used by nation-state actors Top 12 ways hackers…
-
Meta AI Agent Exploited Third-Party Flaw During Cybersecurity Test
Meta is investigating after an AI model hacked another company during testing, raising concerns over agent containment and enterprise security safeguards. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/artificial-intelligence/news-meta-ai-agent-hack/ also interesting: Unplug Gemini from email and calendars, says cybersecurity firm When Language Becomes the Attack Surface: Inside the Google Gemini Calendar Exploit U.S. CISA adds…
-
Eco-Stimmungsbild zu NIS-2 deckt Umsetzungshürden auf
NIS-2 ist in der Wirtschaft angekommen, aber die praktische Umsetzung bleibt für viele Unternehmen anspruchsvoll. Das zeigt ein aktuelles Stimmungsbild des Eco Verband der Internetwirtschaft unter 38 Unternehmen aus dem Eco-Umfeld. Die größten Herausforderungen bei der Umsetzung sehen die Befragten bei Dokumentationspflichten, Meldeprozessen mit 24-/72-Stunden-Regelungen sowie Risikoanalyse und Risikomanagement. Das Eco-Stimmungsbild gibt einen Einblick […]…
-
iCloud Private Relay: WebKit legt echte IP trotz Schutz offen
iCloud Private Relay schützt nicht lückenlos: Drei WebKit-Leaks können echte IP-Adressen offenlegen und Apples Privatsphäre-Schutz umgehen. First seen on tarnkappe.info Jump to article: tarnkappe.info/artikel/it-sicherheit/icloud-private-relay-webkit-ip-leak-332158.html also interesting: Your passwords are everywhere: What the massive 16 billion login leak means for you macOS Sploitlight flaw leaks Apple Intelligence data Top cybersecurity M&A deals for 2025 iPhone 18…
-
Neue Shai-Hulud-Welle: npm-Wurm greift verstärkt Pakete, GitHub und CI-Systeme an
Tags: githubShai-Hulud kompromittiert über 400 npm-Pakete, stiehlt Zugangsdaten und infiziert GitHub-Repositorys sowie Entwicklungs- und CI/CD-Umgebungen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/neue-shai-hulud-welle-npm-wurm-greift-verstaerkt-pakete-github-und-ci-systeme-an/a46043/ also interesting: Specterops erweitert sein Attack-Path-Management für Identitäten auf Okta, Github und Mac Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched TeamPCP breached GitHub’s internal codebase via poisoned VS Code extension GitHub…
-
Meta Joins OpenAI and Anthropic in Reporting AI Exploit Incident
One of Meta’s AI models exploited a third-party security flaw during an evaluation, the latest in a series of similar incidents involving advanced AI systems First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/meta-ai-exploit-incident/ also interesting: Simple Prompt Injection Lets Hackers Bypass OpenAI Guardrails Framework Cybersecurity Snapshot: Top Advice for Detecting and Preventing AI Attacks, and…
-
Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities
Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network.Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, including 2,844 in the United States, but Forescout could not confirm any were compromised. That figure counts exposed First…
-
Fake Xeno Roblox Executor Delivers Powercat Java Stealer Through Discord
The fake “undetected” Xeno Roblox executor currently circulating on gaming forums and Discord is a weaponized loader for the Powercat Java stealer, a multi”‘stage RAT and infostealer that targets Discord, Roblox, Minecraft, crypto wallets and payment tokens while enabling full remote control of infected Windows systems. Threat actors are promoting trojanized Xeno executors through Roblox”‘focused…
-
Critical Paperclip AI Agent Flaws Allow Unauthenticated Remote Code Execution
Critical vulnerabilities in the open-source Paperclip AI-agent orchestration platform could allow attackers to execute commands remotely on exposed servers or on a developer’s local machine. These flaws arise from broken authorization boundaries across agent imports and API routes, as well as trust assumptions for localhost. Paperclip is designed to coordinate autonomous agents across >>companies,<< with…
-
Photos: Black Hat USA 2026
Photo gallery from the Business Hall at Black Hat USA 2026. Interesting booths, demo stages, crowded aisles, and the moments in between. Featured vendors: Stellar Cyber, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/06/black-hat-usa-2026-photos/ also interesting: CISOs’ security priorities reveal an augmented cyber agenda CISOs must prove the business value of cyber, the right…
-
Canadian Pleads Guilty to Snowflake Customer Data Extortion
Extortionist Connor Moucka, 26, Helped Breach Over 150 Customers’ Accounts. Canadian national Connor Riley Moucka, 26, pleaded guilty in Seattle federal court holding to ransom data he helped steal from over 150 customers of cloud-based data warehousing platform Snowflake, leading to victims paying millions in cryptocurrency ransoms and incident response costs. First seen on govinfosecurity.com…
-
Black Hat USA: TP-Link Flaws Put Omada Controllers and Camera Feeds at Risk
Forescout disclosed 15 TP-Link flaws at Black Hat USA 2026 that could expose Omada credentials and VPN keys, allow internal access and affect VIGI camera feeds. First seen on hackread.com Jump to article: hackread.com/black-hat-usa-tp-link-flaws-omada-credentials-camera-risk/ also interesting: A new ransomware regime is now targeting critical systems with weaker networks When Your Own Eyes Turn Against You:…
-
Ein VLAN ist kein Air-Gap Kritische Infrastruktur braucht echte Trennung
Tags: infrastructureEnde Juli wurden mehr als 30 kommunale Wassersysteme im US-Bundesstaat Minnesota innerhalb von wenigen Tagen Opfer eines koordinierten Cyberangriffs. In der Stadt Braham ging eine Wasseraufbereitungsanlage offline, in der Stadt Plymouth wurde die Mobilfunkkommunikation zu zwei Wassertürmen und Abwasser-Hebestationen unterbrochen. In der Stadt Maple Plain wurde sogar der lokale Notstand ausgerufen. Erste Berichte wiesen auf…
-
Belarusian cybercriminal behind Ransom Cartel gets 16-year prison sentence
A Belarusian national active in the cybercriminal world for decades was sentenced to 16 years in U.S. prison for running the Ransom Cartel ransomware operation. First seen on therecord.media Jump to article: therecord.media/belarus-hacker-ransomware-sentenced also interesting: UnitedHealth confirms it paid ransomware gang to stop data leak Cybercriminals Court Traitorous Insiders via Ransom Notes Rogues gallery: 15…
-
AI code security with Claude Mythos Preview: Inside Tenable’s 500+ hours of testing for Project Glasswing
Tags: access, ai, api, application-security, compliance, control, cyber, cybersecurity, data, exploit, flaw, reverse-engineering, risk, software, threat, tool, update, vulnerabilityWe spent 500+ hours and 40 billion tokens testing Anthropic’s Claude Mythos Preview for Project Glasswing. The takeaway: frontier AI won’t run your code security program, but used well, it can make one even stronger. Key takeaways Frontier AI dramatically scales security testing. In one month, Tenable dedicated 11 security experts and more than 40…

