Tag: cyber
-
Anthropic Launches Claude Security Plugin to Scan Codebases for Vulnerabilities Before Commit
Anthropic has launched the Claude Security plugin for Claude Code in beta, enhancing its AI-assisted development platform with security scanning capabilities designed to identify vulnerabilities earlier in the software development lifecycle. The company stated that developers can scan code changes before committing them or initiate comprehensive security reviews across an entire codebase directly from the…
-
Critical Adobe Acrobat Chrome Extension Flaw “HermeticReader” Lets Hackers Hijack WhatsApp Chats of 300M+ Users
Guardio Labs has disclosed a critical vulnerability chain in the Adobe Acrobat Chrome extension that could allow a malicious website to hijack and exfiltrate rendered WhatsApp Web data from affected users. This vulnerability is tracked as CVE-2026-48294 and has impacted Adobe Acrobat extension version 26.5.2. The extension is installed across approximately 329 million browsers. Adobe…
-
National Guard’s Cyber Shield exercise focuses on power sector defense
First seen on scworld.com Jump to article: www.scworld.com/brief/national-guards-cyber-shield-exercise-focuses-on-power-sector-defense
-
How AI-Driven Robotics Expands Industrial Cyber Risk
CEO: Connected Factories and Hospitals Expose Legacy OT Systems to Modern Threats. Claroty CEO Yaniv Vardi says physical AI will accelerate robotics and industrial automation while making cyber-physical security a strategic priority as connected operational technology exposes critical infrastructure to attacks with real-world consequences. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/how-ai-driven-robotics-expands-industrial-cyber-risk-a-32303
-
5 Things To Know On OpenAI Hugging Face Autonomous Hack
OpenAI acknowledged that two of its frontier models were responsible for an “unprecedented cyber incident” after the models autonomously compromised AI model platform Hugging Face. First seen on crn.com Jump to article: www.crn.com/news/security/2026/5-things-to-know-on-openai-hugging-face-autonomous-hack
-
AI Models Caught Cheating in Cyber Evaluations
OpenAI, Anthropic Models Broke Test Rules, Left Few Reasoning Clues. Five frontier models from OpenAI and Anthropic cheated during cybersecurity evaluations monitored by the U.K. AI Security Institute, using online answers and out-of-scope attacks. The models rarely admitted breaking the rules and their reasoning traces contained little evidence of the misconduct. First seen on govinfosecurity.com…
-
OpenAI Models Escaped Test Environment and Breached Hugging Face
OpenAI models escaped from a controlled cyber test, exploited zero-day flaws and breached Hugging Face while searching its production database for test answers. First seen on hackread.com Jump to article: hackread.com/openai-models-breached-hugging-face/
-
Malicious NuGet Typosquat Targets Digitain Betting Platform and Rigs Game Results
JFrog Security Research has disclosed a precision supply-chain attack in which a typosquatted NuGet package, Newtonsoftt.Json.Net, impersonated the ubiquitous Newtonsoft.Json library while secretly rigging game outcomes at online betting operator Digitain. Unlike typical info-stealers that harvest credentials indiscriminately, this trojan functions as a fully operational JSON library for every host except its single intended target.…
-
Bridewell Launches Dedicated Threat Intelligence Practice BCON Collective
Bridewell has launched BCON Collective, a dedicated Threat Research and Cyber Threat Intelligence (CTI) practice designed to help organisations better understand, prioritise and respond to today’s rapidly changing cyber threat landscape. The new practice brings together Bridewell’s existing intelligence-led services, original threat research and specialist analysts under a single identity, reflecting growing customer demand for…
-
Our models breached Hugging Face during a cyber capability test
The recent Hugging Face breach was the work of several OpenAI models, the AI research company claimed in a blog post. The breach Late last week, the company behind Hugging … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/22/hugging-face-breach-openai-testing/
-
AppViewX Arms Enterprise CLM Teams for Post-Quantum Migration and AI Adoption in Latest Product Release
New York, United States, July 22nd, 2026, CyberNewswire The platform’s new release speeds the adoption of hybrid PQC certificates and AI-driven certificate lifecycle management AppViewX, the leading machine and agent identity security company built for the AI and quantum enterprise, today announced support for hybrid composite post-quantum cryptography (PQC) certificates and the AppViewX Model Context…
-
AppViewX Arms Enterprise CLM Teams for Post-Quantum Migration and AI Adoption in Latest Product Release
New York, United States, July 22nd, 2026, CyberNewswire The platform’s new release speeds the adoption of hybrid PQC certificates and AI-driven certificate lifecycle management AppViewX, the leading machine and agent identity security company built for the AI and quantum enterprise, today announced support for hybrid composite post-quantum cryptography (PQC) certificates and the AppViewX Model Context…
-
Singapore to hold CII boards accountable as AI reshapes OT threat landscape
The Cyber Security Agency’s first update to its critical infrastructure code of practice since 2022 will make boards directly answerable for cyber resilience First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646154/Singapore-to-hold-CII-boards-accountable-as-AI-reshapes-OT-threat-landscape
-
Apple Fixes Hide My Email Vulnerability That Exposed Users’ Real Email Addresses
Apple has addressed a year-old vulnerability in its >>Hide My Email<< privacy feature, which could expose users' real email addresses. This incident has already led to a class action lawsuit and increased scrutiny of Apple's privacy claims. Hide My Email, part of the paid iCloud+ subscription, allows users to generate random alias addresses that forward…
-
Middle East faces new cyber reality: attackers logging in, not breaking in
Geopolitical tensions, stolen credentials and increasingly rapid attacker movement are reshaping the Middle East’s cyber threat landscape, putting pressure on organisations to look beyond traditional, alert-driven security models First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646049/Middle-East-faces-new-cyber-reality-attackers-logging-in-not-breaking-in
-
CISA Warns WordPress Core SQL Injection Vulnerability Is Actively Exploited in Attacks
Tags: attack, cisa, cve, cyber, cybersecurity, exploit, infrastructure, injection, kev, sql, vulnerability, wordpressThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has classified a critical SQL injection vulnerability in WordPress Core, tracked as CVE-2026-60137, as one of its Known Exploited Vulnerabilities (KEV) due to its active exploitation in real-world attacks. This vulnerability affects the core functionality of WordPress when themes or plugins fail to properly validate untrusted input…
-
Zimbra 10.1.20 Fixes Critical SNMP Command Injection and Multiple XSS Flaws
Zimbra has released version 10.1.20 of its Collaboration Suite (ZCS) to address multiple high-severity security vulnerabilities. This release includes a critical command injection flaw in the SNMP monitoring component and several cross-site scripting (XSS) issues affecting the Classic Web Client. The update, published on July 20, 2026, provides a permanent fix for a previously disclosed…
-
FBI Warns Scammers Use AI Deepfakes and Fake IC3 Websites to Target Fraud Victims
The Federal Bureau of Investigation (FBI) has issued a new Public Service Announcement (Alert Number I-072026-PSA) regarding an evolving fraud campaign. Cybercriminals are increasingly using AI-generated deepfakes and spoofed Internet Crime Complaint Center (IC3) websites to target and re-victimize individuals who have already fallen prey to scams. Released on July 20, 2026, the alert highlights…
-
Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands
ASUS has announced a significant security vulnerability in its router firmware that could enable remote attackers to execute arbitrary commands through a man-in-the-middle (MITM) attack. This raises substantial concerns for both enterprise and home network security. The flaw, identified as CVE-2026-13385, impacts multiple branches of ASUS router firmware, including the widely used versions 3.0.0.4_386, 3.0.0.4_388,…
-
Hackers Clone Microsoft Login Portals to Capture Credentials and Session Tokens in Real Time
An active adversary-in-the-middle (AiTM) phishing campaign that clones Microsoft authentication pages to intercept credentials, Multi-Factor Authentication (MFA) codes, and session tokens in real time. Rather than relying on simple password harvesting, this technique hijacks authenticated user sessions directly. Detailed by Infoblox Threat Intel researchers Darby Wise and Nick Sundvall, the widespread campaign has targeted universities,…
-
Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns
Global ransomware attacks climbed 3% in the second quarter of 2026, rising from 2,165 incidents in Q1 to 2,229, according to NCC Group’s latest Quarterly Cyber Threat Intelligence Report. While the increase in volume was modest, the security firm warned that supply chain attacks are growing rapidly in both scale and sophistication, and that the…
-
Ransomware, Spies and Hacktivists Converge on UK and Ireland, New Threat Report Warns
A new threat intelligence report has painted a stark picture of the cyber risks facing the UK and Ireland, describing an environment in which ransomware gangs, nation-state spies and politically motivated hacktivists are increasingly working the same terrain, often against the same victims. The >>Cyber Threat Landscape: UK & Ireland<< report, published by threat intelligence…
-
North Korean Hackers Use Fake Job Interviews to Deploy PylangGhost and GolangGhost RATs
North Korea’s Famous Chollima threat group, also tracked as Wagemole, is actively running a sophisticated cyberespionage campaign dubbed ClickFake Interview. The operation targets cryptocurrency and Web3 professionals, tricking candidates into executing terminal commands that infect their devices with platform-specific Remote Access Trojans (RATs): PylangGhost on Windows and GolangGhost on macOS. Detailed analysis by the SOCRadar…
-
Google’s Gemini 3.5 Flash Cyber becomes a vulnerability hunter
Google’s Gemini 3.5 Flash Cyber model finds, validates, and patches vulnerabilities before they can be exploited while helping mitigate broader misuse. It is part of a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/22/google-gemini-3-5-flash-cyber-model/
-
SolarWinds Serv-U Update Fixes 15 Critical Vulnerabilities Enabling Remote Code Execution as Root
SolarWinds has released Serv-U 2026.3, which includes fixes for a cluster of 9.1 CVSS critical vulnerabilities that allow remote code execution (RCE) and privilege escalation up to root on Unix-like systems. This update significantly strengthens the managed file transfer (MFT) and FTP server platform against potential takeovers. While Windows instances are rated as having a…
-
Threat Actor Turns Claude Opus Into Automated AI-Powered Penetration Testing Platform
A Russian-speaking threat actor known as “Trim” has reportedly transformed Anthropic’s Claude Opus into the central component of an automated, AI-powered penetration testing platform. This development highlights the rapid repurposing of advanced AI models for offensive security operations. According to research by Cato CTRL, Trim progressed from sharing jailbreak instructions on a Russian cybercrime forum…
-
Google Unveils Gemini 3.5 Flash Cyber to Find and Fix Software Vulnerabilities Faster
Google has introduced Gemini 3.5 Flash Cyber, a lightweight AI model designed to improve cybersecurity by helping defenders identify, validate, and patch software vulnerabilities more efficiently. Built on Gemini 3.5 Flash and optimized for security tasks, Flash Cyber aims to deliver a cost-effective alternative to larger AI models while supporting large-scale vulnerability analysis. First seen on thecyberexpress.com Jump to…
-
Police Dismantle Kratos Phishing-as-a-Service Platform and Take Down Over 200 Servers
Tags: credentials, crime, cyber, cybercrime, germany, infrastructure, Internet, office, phishing, serviceAuthorities from Germany, the United States, and Indonesia have dismantled the central infrastructure of Kratos, a major phishing-as-a-service (PhaaS) platform that enabled cybercriminals worldwide to conduct large-scale credential-harvesting campaigns. The operation, announced by Germany’s Federal Criminal Police Office (BKA) and the Frankfurt am Main Public Prosecutor’s Office’s Central Office for Combating Internet Crime (ZIT), resulted…
-
AccuKnox Wins Best AI Startup Award for Enterprise Agentic AI Security at BSides Bangalore
Bangalore, India, July 22nd, 2026, CyberNewswire AccuKnox announced it has won the number one Startup Award at Security BSides Bangalore 2026, marking the second consecutive year the company has topped the category after also winning in 2025. The back-to-back recognition affirms AccuKnox’s standing among the region’s leading cybersecurity startups. AI Security Adoption For AccuKnox, this award…

