Tag: attack
-
Black Hat 2026: OpenAI reveals agents planned ‘collective attacks’ via secret ‘message board’
First seen on scworld.com Jump to article: www.scworld.com/news/black-hat-2026-openai-reveals-agents-planned-collective-attacks-via-secret-message-board
-
QuickFox VPN targeted in long-standing supply chain attack delivering FDMTP backdoor
First seen on scworld.com Jump to article: www.scworld.com/brief/quickfox-vpn-targeted-in-long-standing-supply-chain-attack-delivering-fdmtp-backdoor
-
AI Attacks Are Evolving: TryHackMe Demo Explores Prompt Injection
TryHackMe demo: Explore how prompt injection is reshaping AI security risks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/ai-attacks-are-evolving-tryhackme-demo-explores-prompt-injection/
-
No Perfect Fix for AI Browser Prompt Injection Flaws
AI browsers from top vendors remain vulnerable to prompt injection attacks despite multiple security guardrails, according to new research. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/no-perfect-fix-ai-browser-prompt-injection-flaws
-
Ransom Cartel ransomware creator sentenced to 16 years in prison
Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ransom-cartel-ransomware-creator-sentenced-to-16-years-in-prison/
-
Flooding Dropper Hits npm With 850 Malicious Packages
Tags: attack, automation, cloud, container, control, credentials, cvss, data-breach, detection, dns, endpoint, github, guide, infrastructure, linux, macOS, malicious, malware, monitoring, software, threat, windows<div cla TL;DR Sonatype Research Labs is tracking an active malicious package campaign, dubbed ‘Flooding Dropper,’ spreading on npm, currently impacting 846 software components. The attacker appears to be automating parts of the npm account and package creation process, combining terms such as bigops and bnpl with other words and recurring version patterns, such as releases…
-
Canadian pleads guilty to Snowflake cloud data-theft attacks
A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/canadian-pleads-guilty-to-snowflake-cloud-data-theft-attacks/
-
Intel 471 Adds MCP Connector and Native AI Analyst to Verity471
Intel 471 has added two AI capabilities to its Verity471 cyber intelligence platform: MCP471, a connector for Model Context Protocol workflows, and Agent471, a native AI analyst. The capabilities are being demonstrated at Black Hat USA 2026 from Aug. 4 to 6. Intel 471 said the additions are designed to bring pre-attack intelligence and threat-hunting..…
-
Anthropic’s AI used fake identities, malware in rogue attack on GitHub project
Anthropic and OpenAI models’ unprompted actions forced halt to UK cyber tests. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/08/anthropics-ai-used-fake-identities-malware-in-rogue-attack-on-github-project/
-
Oracle SQL Injection Attack Enables Remote Code Execution
A Huntress investigation reveals how attackers used SQL injection to achieve RCE and steal credentials. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/oracle-sql-injection-attack-enables-remote-code-execution/
-
OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries
Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January 2025. First seen on hackread.com Jump to article: hackread.com/octlurk-silklurk-backdoors-target-6-countries/
-
Mini Shai-Hulud npm Attack: More Than 2,200 Components Impacted
Tags: access, ai, attack, breach, cloud, container, control, credentials, data, data-breach, github, guide, infection, intelligence, kubernetes, malicious, malware, microsoft, open-source, risk, sbom, service, software, threat, update<div cla TL;DR A new wave of the Shai-Hulud malicious package campaign emerged on npm, with 2,225 software component versions impacted. The malware executes through a malicious preinstall hook, steals npm, GitHub, cloud, Kubernetes, Vault, CI/CD, and other credentials, then uses stolen publishing access to compromise additional packages. Organizations that installed an affected version should…
-
XM Cyber Releases Open-Source Tools for Hunting macOS and Oracle Cloud Exposures
XM Cyber has announced new open-source exposure-hunting tools for macOS endpoints and Oracle Cloud Infrastructure. The release, issued from Black Hat USA and DEF CON, says the tools are intended to help security teams uncover and validate complex attack paths. The macOS tool examines weaknesses that can allow an attacker to move from an initial..…
-
OpenAI’s GPT-5.6 Tests Show Prompt-Injection Gains and Agent Risks
OpenAI’s latest GPT-5.6 safety results show low failure rates for direct prompt injection but higher success rates when attacks arrive through tools and external content. The post OpenAI’s GPT-5.6 Tests Show Prompt-Injection Gains and Agent Risks appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-gpt-5-6-prompt-injection/
-
CrowdStrike Warns AI Adoption Is Creating ‘Underdefended’ Attack Surfaces
CrowdStrike warns that AI adoption, rapid vulnerability exploitation, cloud attacks, and malicious npm packages are creating new enterprise security risks. The post CrowdStrike Warns AI Adoption Is Creating ‘Underdefended’ Attack Surfaces appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-crowdstrike-ai-underdefended-attack-surfaces/
-
Flaws in Google APK for Python Unlock AgentAgent Attack
Google has fixed the issues, which exploited a trust boundary between two AI agents with different privilege levels to trigger automation that could compromise the supply chain. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/flaws-google-apk-python-agent-to-agent-attack
-
COLDCARD security audit phishing attack installs remote access tool
A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/coldcard-security-audit-phishing-attack-installs-remote-access-tool/
-
“I’m Allowed”: Hackers Use Simple Claims to Bypass AI Guardrails
Cisco Talos found hackers using simple authorization claims to bypass AI guardrails, build DDoS attack tools, steal credentials and access live camera services. First seen on hackread.com Jump to article: hackread.com/im-allowed-hackers-use-claims-bypass-ai-guardrails/
-
Elastic Expands Attack Discovery to Push Security Teams Toward ‘Alert Zero’
Elastic (NYSE: ESTC) announced major advances to its agentic security operations platform ahead of Black Hat USA 2026, centered on getting security teams closer to what the company calls >>Alert Zero,<< the point where an alert queue has been worked down to the attacks that actually matter. The centerpiece is an expanded version of Attack..…
-
Terra Security Adds Prevention Rules to Its Offensive Security Platform
Terra Security has launched Prevention, a capability that turns confirmed exploit findings into targeted Web Application Firewall or firewall rules while a permanent fix is still in progress. The feature is part of Terra Platform. When Terra confirms that a finding is exploitable, its AI agents test whether existing compensating controls stop that attack path……
-
Menlo Security Extends Platform Reach to AI Agents
Menlo Security today at the Black Hat USA conference extended its cloud platform to secure artificial intelligence (AI) agents at runtime by sanitizing the web pages and files they read to neutralize prompt injection attacks and block data exfiltration. Company CEO Bill Robbins said the Menlo Agent Runtime Security (MARS) platform created to isolate browsers..…
-
Open-source software’s archenemy TeamPCP goes back further than anyone thought
Oligo Security uncovered evidence of a long operational history, including multiple previous attacks it traced to the same attacker infrastructure and tools. First seen on cyberscoop.com Jump to article: cyberscoop.com/teampcp-long-active-history-2020-oligo-security/
-
Hackers Smuggle Post-Exploitation Toolkit Into Oracle Database Via Classic SQL Injection Flaw
A SQL injection vulnerability that many organisations might consider a decades-old, well-understood threat has been used as the entry point for a far more sophisticated attack, after threat actors were caught planting a custom-built, database-resident toolkit inside an Oracle database. Security firm Huntress said it was alerted to suspicious activity on an endpoint hosting an…
-
How to Implement Continuous Agentic Pentesting for the Web
Continuous agentic pentesting is the practice of using autonomous AI agents to attack, validate, and report on your web applications on an ongoing basis, every… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/how-to-implement-continuous-agentic-pentesting-for-the-web/
-
Countering AI-Driven Phishing in the Age of Agentic AI
Phishing remains an evergreen method of getting a “foot in the door,” and AI is making these attacks faster, more scalable, and increasingly convincing. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/countering-ai-driven-phishing-in-the-age-of-agentic-ai/
-
Zimperium Launches Deep Insights for Automated Mobile Forensics
Zimperium has announced Deep Insights, a mobile security product that combines real-time Mobile Threat Defense with automated mobile forensics. Deep Insights automates forensic analysis and reconstructs the sequence of events around a mobile incident. Zimperium said it correlates configuration changes, application activity, permission shifts and suspicious network traffic to build a step-by-step attack timeline. The..…
-
Django Flaws Let Attackers Trigger RCE, SSRF, DoS, and XSS Attacks
The Django project has released security updates, specifically Django 6.0.8 and Django 5.2.17, to address four vulnerabilities that could lead to server-side request forgery (SSRF), arbitrary file writes with potential for remote code execution (RCE), denial-of-service (DoS), and stored cross-site scripting (XSS) attacks. An advisory posted by Natalia Bidart on August 4, 2026, urges all…
-
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
Cybersecurity researchers have disclosed what has been described as a “long-standing supply chain attack” on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users.According to Fortinet FortiGuard Labs, the supply chain attack has been ongoing since at least August 2025 and involves a trojanized version of the application to…

