access ai android api apple attack authentication backdoor breach business ceo china cisa cisco ciso cloud compliance control credentials crypto cve cyber cyberattack cybercrime cybersecurity data data-breach defense detection email exploit finance flaw framework fraud google governance government group hacker hacking healthcare identity infrastructure injection intelligence Internet jobs law leak linux malicious malware microsoft monitoring network open-source password phishing privacy ransomware remote-code-execution resilience risk russia scam service software strategy supply-chain technology theft threat tool unclassified update usa vulnerability windows zero-day
-
How to report an AI Act violation in the EU
The EU’s fight to regulate AI models entered a new chapter on 2 August 2026, when the European Commission’s AI Office and national authorities began enforcing the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/10/eu-ai-act-enforcement-how-to-report-violation/ also interesting: Invisible C2″Š”, “Šthanks to AI-powered techniques Cybersecurity Snapshot: Cyber Pros Emerge as Bold AI Adopters, While AI…
-
Black Hat: AI isn’t the problem. We are
Tags: aiFirst seen on scworld.com Jump to article: www.scworld.com/news/black-hat-ai-isnt-the-problem-we-are also interesting: The Challenges of AI Security Begin With Defining It AppOmni Unleashes World’s First SaaS Security Model Context Protocol (MCP) Server For Agentic AI Architectures ADN Microsoft CSP Security Week: KI gegen Cyberkriminalität A CISO’s AI Playbook
-
Cybersecurity Newsletter Weekly Top 50 Biggest Cybersecurity Stories $70M Bitcoin Heist,Google Passkey Theft, Copilot CEO Fraud,Chrome 151 Claude Exploits More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 50 most important stories from August 37, 2026. It was a brutal week for trust in the tools we rely on: a Coldcard firmware flaw drained $70 million in Bitcoin, malware learned to steal Google’s synced passkeys, and […]…
-
The Best Intrusion Detection Prevention (IDS/IPS) Tools, Compared and Priced (2026)
This market runs from $0 to seven figures, and the free options power half the paid ones, so price comparisons here reward honesty. The verdict up front: Snort and Suricata are the best-value detection engines on earth (free, production-grade, industry-embedded), Zeek is the evidence standard, and among commercial platforms Fortinet delivers the strongest inline-prevention […]…
-
6 Strategies for Maintaining Cyber Resilience During Peak Vacation Periods
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/6-strategies-cyber-resilience-maintain-vacation also interesting: It’s Time to Reassess Your Cybersecurity Priorities Cybersecurity Snapshot: SANS Recommends Six Controls To Secure AI Systems, While NCSC Warns About Outdated API Security Methods Securing the Future Together: Why Thales and HPE are the Partners You Can Trust 4 issues holding back CISOs’ security…
-
Bedrohlicher Trend: Meta-KI-Hack aktuelles Beispiel für potenziell verhängnisvolle Entwicklung
Tags: aiFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/bedrohung-trend-meta-ki-hack-beispiel-potenzial-verhaengnis also interesting: MSSP Market News: Resecurity Releases AI Fraud Prevention Platform Ex-GitHub Engineers Raise $20M to Enhance Pen-Testing with AI-Powered XBOW How to spot and avoid AI-generated scams Phishing is old, but AI just gave it new life
-
20 Flaws in Fertility Tracker Risked Data Loss, Fake Results
Mira Ultra 4 Fixes Vulnerabilities After University Team Hacked Bluetooth, Firmware. Multiple vulnerabilities identified in a popular at-home fertility tracking device could have allowed attackers to impersonate the device, manipulate hormone readings, access sensitive health information and reverse engineer production firmware, said the researchers who made the discovery. First seen on govinfosecurity.com Jump to article:…
-
U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Data
IEH was breached by a phishing attack that exposed its Microsoft 365 inbox, including emails and potentially export-controlled military data. IEH Corporation is a U.S. defense and aerospace manufacturer based in Brooklyn, New York. The company specializes in high-reliability electrical connectors, particularly hyperboloid connectors used in demanding military and aerospace environments. Its connectors are used…
-
OpenAI Pauses Development on Powerful Astra Model Over Autonomous Cyberattack Risks
OpenAI has halted select internal development on its unreleased flagship model, Astra, after safety evaluations revealed the system had achieved unprecedented autonomous cyberattack capabilities. The move comes as the artificial intelligence (AI) industry grapples with a wave of containment failures, where increasingly autonomous models have repeatedly breached sandbox environments and accessed live targets on the..…
-
The AI safety test is becoming a safety risk
AI agents are escaping cybersecurity testing environments and reaching real-world systems, raising questions about whether safety infrastructure, industry standards and regulation can keep pace with increasingly powerful models. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/09/the-ai-safety-test-is-becoming-a-safety-risk/ also interesting: 25 on 2025: APAC security thought leaders share their predictions and aspirations Privacy Roundup: Week 4 of…
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 109
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums DarkSword’s Panel Sprawl: How One Body Hash Unravels a Six-Panel, Two-Codebase Operator Cluster Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba…
-
This ‘adversarial’ pattern can prevent surveillance cameras from detecting you
A security researcher has designed an algorithm that can create computer-generated patterns capable of hiding people, faces, and vehicles from detection by surveillance cameras. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/09/this-adversarial-pattern-can-prevent-surveillance-cameras-from-detecting-you/ also interesting: APT37 Targets Windows with Rust Backdoor and Python Loader APT37 Targets Windows with Rust Backdoor and Python Loader 2025 Year of…
-
SANS Urges IT Security Teams to Close Open Doors to AI Agents
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/ai-agents-sans-it-security-teams-close-open-doors also interesting: Cybersecurity Snapshot: SANS Recommends Six Controls To Secure AI Systems, While NCSC Warns About Outdated API Security Methods Cybersecurity Snapshot: Top Advice for Detecting and Preventing AI Attacks, and for Securing AI Systems What does aligning security to the business really mean? Strategie-Briefing des SANS…
-
Security Affairs newsletter Round 589 by Pierluigi Paganini INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions Metabase Zero-Day Exploited in the Wild,…
-
Offene Türen für KI-Agenten schließen das SANS Institute gibt IT-Sicherheitsteams Empfehlungen
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/ki-agenten-sans-institute-it-sicherheitsteams-empfehlungen also interesting: 4 critical leadership priorities for CISOs in the AI era SANS Institute unterstützt mit AI-Blueprints die Einführung von KI Wie KI die Cybersicherheit neu gestaltet 8 guiding principles for reskilling the SOC for agentic AI
-
Urlaubszeit Sommerzeit Vorfallzeit: Sechs Ratschläge für Zeiten mit geringer Personalstärke
Management Summary Urlaubszeit ist Risikobetrieb: Reduzierte Personalstärke, höhere Abhängigkeit von IT-Systemen und wachsende Angriffsflächen machen die Sommermonate zu einer Phase mit erhöhtem Kontrollbedarf. KI verändert das Schwachstellenmanagement: Frontier-KI-Modelle beschleunigen die Entdeckung und Veröffentlichung von Verwundbarkeiten; Patch-, CERT- und Threat-Feed-Prozesse müssen deshalb auch in Ferienzeiten aktiv bleiben. Klare Rollen verhindern Wissensmonopole: Ein offiziell definierter Reduced Staff……
-
Reiseziel, Restaurant, Route: Wo KI zum Reisebegleiter wird
Tags: aiEin Viertel lässt sich Urlaubsziele bereits von KI vorschlagen, für weitere 41 Prozent kommt es infrage. Mehrheit ist offen für KI-Tipps zu Sightseeing, Ausflügen und Events. Ein Viertel bearbeitet Urlaubsfotos mit KI. Von der ersten Urlaubsidee über die Planung bis zum Aufenthalt vor Ort: Viele Reisende wollen sich von Künstlicher Intelligenz auch bei ihrem……
-
Odysseus-Film: Homer dichtet Malware
Hacker nutzen Fake-Angebote für Christopher Nolans Odysseus-Film, um Malware mit LummaStealer auszuspielen. Laut der renommierten Althistorikerin Mary Beard hat Christopher Nolan in seiner aktuellen Odysseus-Verfilmung von 2026 Erotik und Witz zugunsten von Gewalt weggekürzt. Hacker transportieren ihrerseits aktuell illegal die LummaStealer-Malware zum Informationsdiebstahl als Angebot vermeintlicher Downloads des Films. Die Experten der Bitdefender Labs… First…
-
Alarmflut im Leitstand vermeiden
Tags: complianceIntelligente Alarmierung schafft Klarheit und schützt kritische Prozesse. Management Summary Alarmflut wird zum Betriebsrisiko: In modernen Leitständen überlagern zahlreiche Meldungen häufig die wirklich kritischen Ereignisse besonders in Pharma und Chemie kann das Prozesssicherheit, Qualität und Compliance gefährden. Klassische Grenzwerte reichen nicht mehr aus: Starre Schwellenwertsysteme erkennen komplexe Wechselwirkungen, schleichende Trends und kontextabhängige Abweichungen… First seen…
-
Berliner Staatsanwaltschaft: 350 Anklagen gegen Encrochat- und Sky-ECC-Nutzer
Tags: cyberattackDie Berliner Staatsanwaltschaft zieht Zwischenbilanz zu Kryptohandys. Der Angriff auf die Systeme durch die Staatsapparate sind weiter umstritten. First seen on golem.de Jump to article: www.golem.de/news/berliner-staatsanwaltschaft-350-anklagen-gegen-encrochat-und-sky-ecc-nutzer-2608-211741.html also interesting: US-Dienstleistungsunternehmen von Cyberangriff betroffen? US-Dienstleistungsunternehmen für das Gesundheitswesen von Cyberangriff betroffen Cyberangriff auf einen Internet-Anbieter in Neukaledonien Cyberangriff auf einen Schulbezirk in Ohio, USA
-
Keepit AI Truth Cloud: Verifizierte Backup-Daten sollen Enterprise-KI absichern
Keepit stellt AI Truth Cloud vor: Unveränderliche Backup-Daten, MCP-Integration und AI Safe Room sollen eine vertrauenswürdige Basis für Enterprise-KI schaffen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/keepit-ai-truth-cloud-verifizierte-backup-daten-sollen-enterprise-ki-absichern/a46059/ also interesting: CISOs and CIOs confront growing data protection challenges in the era of AI and cloud Disaster Recovery und Business Continuity effektiv planen Would Your Business…
-
Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools
CSS attacks on major webmail services can steal credentials, hijack sessions and manipulate AI tools connected to users’ inboxes. PortSwigger researcher Gareth Heyes demonstrated something that should make every webmail team a little nervous: plain CSS, the styling language that’s supposed to just make text look nice, can be weaponized to steal passwords, hijack sessions, and…
-
Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Mapping the malware blast radius a single alert won’t show you In this … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/09/week-in-review-cisco-fixes-imc-bug-patch-tuesday-forecast-black-hat-usa-2026/ also interesting: 5 key takeaways from Black Hat USA 2025 Cisco Firewall and VPN Zero Day Attacks: CVE-2025-20333…
-
Roblox-Cheater werden selbst zu Betrogenen
Cyberkriminelle nutzen die Suche vieler Gamer nach Cheats und Hilfsprogrammen gezielt aus. Nach Erkenntnissen der Bitdefender Labs verbreiten Angreifer manipulierte Roblox-Tools, die Schadsoftware installieren und den vollständigen Zugriff auf infizierte Computer ermöglichen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/malware-roblox-cheater-betrug also interesting: Unraveling Raspberry Robin’s Layers: Analyzing Obfuscation Techniques and Core Mechanisms New family of…
-
6 Ratschläge zur Sicherung der Resilienz auch in Zeiten erhöhter urlaubsbedingter Abwesenheit
Tags: resilienceFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/6-ratschlaege-sicherung-resilienz-urlaub-abwesenheit also interesting: Die Geräte-Identität, die -Wartung und der Umgang mit Zertifikaten – Auswirkungen des Cyber Resilience Act und der IEC 62443 auf die (IT-)Produkte Watch Now: Shield Your Data, Secure Your Future: A Multi-Layered Approach to Operational Resilience Designing for Cyber Resilience, Not Just Defense 7 Lessons…
-
Existenzielle IT-Sicherheit treibt Deutschlands Krankenhäuser zur digitalen Aufrüstung
Tags: germanyFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/it-sicherheit-deutschland-krankenhaeuser-digital-aufruestung also interesting: Var Group Y-Report 2024 – Cyberbedrohungslage in Deutschland spitzt sich zu Cyberangriff auf Versicherungsmakler BüchnerBarella Link11 Highlights Growing Cybersecurity Risks and Introduces Integrated WAAP Platform German authorities identify REvil and GandCrab ransomware bosses
-
ExfilSquad Targets New Victims, Shares Data via Torrents
Tags: dataFirst seen on resecurity.com Jump to article: www.resecurity.com/blog/article/exfilsquad-targets-new-victims-shares-data-via-torrents also interesting: Fog Ransomware Attacking Windows Servers Administrators To Steal RDP Logins Threat Actors Favor Rclone, WinSCP and cURL as Data Exfiltration Tools Cybercriminals pwn 850k+ Americans healthcare data Identity Risk Intelligence vs Threat Intelligence: What’s the Difference?
-
Continuous Control Monitoring vs Annual Testing – Kovrr
Articles related to cyber risk quantification, cyber risk management, and cyber resilience. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/continuous-control-monitoring-vs-annual-testing-kovrr/ also interesting: 7 top cybersecurity projects for 2025 LLMs hype versus reality: What CISOs should focus on The healthcare industry is at a cybersecurity crossroads Top 10 Cybersecurity Predictions for 2026
-
EU AI Act Compliance Roadmap: What to Document – Kovrr
Articles related to cyber risk quantification, cyber risk management, and cyber resilience. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/eu-ai-act-compliance-roadmap-what-to-document-kovrr/ also interesting: 12 most innovative launches at RSA 2025 From Risk to ROI: How Security Maturity Drives Business Value When Chatbots Go Rogue: Securing Conversational AI in Cyber Defense The Changing Threat Landscape for Retailers:…
-
Secure SDLC principles explained for SaaS founders
Key takeaways Secure SDLC helps SaaS founders reduce breach risk, rework, and customer trust damage by building security into normal delivery. The most effective controls are simple and repeatable across planning, design, build, test, release, and maintenance. Small teams can make real progress with clear ownership, peer review, automated checks, and a basic release checklist….…
-
Hackers breach TrueConf to trojanize client installers with backdoors
The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-breach-trueconf-to-trojanize-client-installers-with-backdoors/ also interesting: Top 12 ways hackers broke into your systems in 2024 The most notorious and damaging ransomware of all time Privacy Roundup:…
-
Google’s top hacker hunter explains why hacking groups get codenames
Google recently changed how it refers and assigns names to hacking groups. TechCrunch spoke with one of the world’s foremost experts on tracking hackers to understand why companies give hackers codenames. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/08/googles-top-hacker-hunter-explains-why-hacking-groups-get-codenames/ also interesting: The most notorious and damaging ransomware of all time Scattered Spider Targeting American Insurance…
-
Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions
China opened a cybersecurity review of Palo Alto Networks, citing national security concerns but giving no details about the reasons behind the probe. China’s Cyberspace Administration (CAC) announced that it’s launching a cybersecurity review of products Palo Alto Networks sells in the country. The announcement itself runs to a few sentences of formal Chinese, citing…
-
Astra: OpenAI will neues KI-Modell vorerst nicht veröffentlichen
Wie gefährlich darf eine KI werden, bevor sie zur Waffe wird? OpenAI kann diese Frage bei seinem Modell Astra derzeit nicht mehr sicher beantworten. First seen on golem.de Jump to article: www.golem.de/news/astra-openai-will-neues-ki-modell-vorerst-nicht-veroeffentlichen-2608-211738.html also interesting: Attackers Can Manipulate AI Memory to Spread Lies Fraudsters integrate ChatGPT into global scam campaigns OpenAI Hugging Face Hack Shows Autonomous…
-
Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data
Attackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims. Metabase just confirmed something no analytics vendor wants to write: attackers found and used an unpatched, maximum-severity flaw against Metabase Cloud before anyone on the defense side knew it existed. The company’s own…
-
U.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalog
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, injection, kev, remote-code-execution, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2026-8037 (CVSS score of 9.6), to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability is an OS Command Injection Remote Code Execution issue…
-
Flock’s Plans for Rideshare Dashcams and Coaching Police, Revealed
Plus: A judge rules cell tower dumps unconstitutional, water utility hacks spread to a dozen states, a phishing email opens a missile-parts supplier’s inbox, and a ransomware boss gets 16 years. First seen on wired.com Jump to article: www.wired.com/story/flocks-plans-for-rideshare-dashcams-and-coaching-police-revealed/ also interesting: Ransomware attacks: The evolving extortion threat to US financial institutions 5 practical steps to…
-
„Ein Problem, das grundsätzlich unlösbar ist”: Warum KI-Modelle vielleicht nie sicher sein werden
Tags: aiFirst seen on t3n.de Jump to article: t3n.de/news/problem-unloesbar-ki-modelle-sicher-1755811/ also interesting: Cloud, AI Talent Gaps Plague Cybersecurity Teams Einsatz von KI in IT- und Security-Teams – So ergänzen sich Mensch und Maschine in der Cybersicherheit LinkedIn Halts AI Data Processing in UK Amid Privacy Concerns Raised by ICO Slack patches Slack AI issue that could have…
-
Für 1.999 Euro: Samsung will mit Fold-Design Apple zuvorkommen
Tags: appleFirst seen on t3n.de Jump to article: t3n.de/news/samsung-galaxy-z-fold-8-apple-foldable-iphone-1999-euro-1754055/ also interesting: USB-C bei iPhone und Mac absichern: MDM-Admins dürfen Sicherheit reduzieren Apple drags UK government to court over ‘backdoor’ order US spy chief says UK has dropped its Apple backdoor demand Apple Bug Bounty Payouts Can Now Top $5m
-
Für 1.999 Euro: Samsung will mit Fold-Design Apple zuvorkommen
Tags: appleFirst seen on t3n.de Jump to article: t3n.de/news/samsung-galaxy-z-fold-8-apple-foldable-iphone-1999-euro-1754055/ also interesting: Ways iOS Sideloading Can Be More Secure Apple Joins Voluntary U.S. Government Commitment to AI Safety Apple patches 0-day exploited in “extremely sophisticated attack” UK court lifts secrecy veil, confirms Apple is suing British government over ‘backdoor’ request
-
Data Poisoning: Warum vergiftete Daten eine wachsende Gefahr für die IT-Sicherheit sind
Tags: dataFirst seen on t3n.de Jump to article: t3n.de/news/data-poisoning-warum-vergiftete-daten-eine-wachsende-gefahr-fuer-die-it-sicherheit-sind-1756214/ also interesting: Cloud Access Security Broker ein Kaufratgeber Understanding RDAP: The Future of Domain Registration Data Access Apache Parquet Critical RCE via Deserialization (CVE-2025-30065) Trump Wants AI in Classrooms. Where Are the Safeguards?
-
Neuer Job als Projektleiter Digital Transformation gesucht? Schau dir unsere Top Jobs an
Tags: jobsFirst seen on t3n.de Jump to article: t3n.de/news/unsere-jobs-der-woche-1175973/ also interesting: 17 hottest IT security certs for higher pay today Tool touted as ‘first AI software engineer’ is bad at its job, testers claim Cyber incident that closed British Museum was inside job The most notorious and damaging ransomware of all time
-
Nach OpenAI und Anthropic: Auch chinesisches KI-Modell aus Testumgebung ausgebrochen
First seen on t3n.de Jump to article: t3n.de/news/chinesisches-ki-modell-kimi-k3-aus-testumgebung-ausgebrochen-1757100/ also interesting: PyPI Attack: ChatGPT, Claude Impersonators Deliver JarkaStealer via Python Libraries AkiraBot Targets 420,000 Sites with OpenAI-Generated Spam, Bypassing CAPTCHA Protections ChatGPT-03 Exploited to Override Critical Shutdown Protocols Top 5 real-world AI security threats revealed in 2025
-
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
New research shows content inside an email can escape its message boundary and interfere with the webmail interface.Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email.PortSwigger researcher Gareth…
-
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
Attacker-controlled instructions can make Atlassian’s Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed.PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It…
-
Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All
Two security researchers bought cheap domains”, including noreply.net and deleteduser.com”, and set up email listening services. Hundreds of companies are sending them corporate secrets. First seen on wired.com Jump to article: www.wired.com/story/sensitive-info-goes-into-no-reply-emails-constantly-this-guy-sees-it-all/ also interesting: 10 most critical LLM vulnerabilities Polyglot files used to spread new backdoor 11 ways cybercriminals are making phishing more potent than…
-
Account-Farming für Claude & Co.: Wie billige KI-Tokens zum Security-Risiko werden
Graumärkte verkaufen Zugänge zu Frontier-KI bis zu 90 Prozent günstiger. Okta zeigt die Risiken durch Account-Farming, Proxies und statische API-Keys. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/account-farming-fuer-claude-co-wie-billige-ki-tokens-zum-security-risiko-werden/a46052/ also interesting: SOAR buyer’s guide: 11 security orchestration, automation, and response products, and how to choose Salesforce’s glaring Dreamforce omission: Vital security lessons from Salesloft Drift AI…
-
Bugtraq Is Back: The Original Full Disclosure Mailing List Is Live Again
Sophia Antipolis, France, August 7th, 2026, CyberNewswire At DEF CON 34 in Las Vegas, security researcher Jonathan Brossard, known in the community as endrazine, announced the rebirth of the original Bugtraq mailing list. Established in 1993, Bugtraq is the original mailing list where cybersecurity vulnerabilities, mitigations, and cutting-edge techniques have been discussed at scale. With…
-
WordPress XSS2Shell Flaw Enables Attackers to Achieve Remote Code Execution
WordPress has patched a high-severity vulnerability, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that begins as an unauthenticated cross-site scripting bug on the login screen and can be chained into full remote code execution. Researchers at pwn.ai discovered the flaw, which carries a CVSS score of 8.9 and affects every actively maintained WordPress branch, a codebase…
-
Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients
Hackers stole personal, medical, and insurance data of 3.8 million people from Unlimited Technology Systems’ data center. Unlimited Technology Systems disclosed a data breach affecting more than 3.8 million people after hackers accessed one of its commercial data centers between October 5 and 10, 2025. Unlimited Technology Systems is a U.S.-based healthcare technology company headquartered…

