Tag: cyber
-
Iran-Linked Hackers Shut Down UK Power Plant for Four Days in Cyberattack
A cyberattack linked to Iranian threat actors forced a British power plant offline for four consecutive days in July, reportedly marking the first successful cyber incident to disrupt a UK energy-generation facility completely. This incident, first reported by The Telegraph, affected a small-scale electricity generator rather than a major power station. The UK government emphasized…
-
Anthropic Brings Claude Mythos 5 to Cyber Defenders for Vulnerability Scanning and Patching
Anthropic has enhanced its AI-driven cyber defense offerings by integrating Claude Mythos 5 into Claude Security. This new feature enables enterprise customers to scan their own codebases for security vulnerabilities and receive suggested remediation patches. This rollout, announced on August 21, 2026, introduces the company’s most advanced cyber model into a structured workflow that delivers…
-
Cybersecurity Newsletter Bulletin Top 50 Biggest Cybersecurity Stories of the Week Shell Azure Mega-Breaches, Salt Typhoon Evicted, Entra ID RCE, Chinese vCenter ESXi Ransomware More
Tags: breach, china, cisa, credentials, cyber, cybersecurity, exploit, flaw, mobile, ransomware, rce, remote-code-execution, theft, vcenterWelcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 50 most important stories from August 1721, 2026. Breaches and exploited flaws dominated: Cl0p claimed 89GB from Shell, a mass Azure credential-theft campaign hit McDonald’s and Vodafone, and T-Mobile physically cut a cable to evict Salt Typhoon. CISA […]…
-
Army seeks AI agents for cyber defense amid evolving threats
First seen on scworld.com Jump to article: www.scworld.com/brief/army-seeks-ai-agents-for-cyber-defense-amid-evolving-threats
-
(g+) Artificial Intelligence: AI hasn’t gone rogue. It’s worse than that
Recent cyber attacks reflect what the technology was trained to do but safeguards are falling short First seen on golem.de Jump to article: www.golem.de/news/artificial-intelligence-ai-hasn-t-gone-rogue-it-s-worse-than-that-2608-212188.html
-
(g+) Artificial Intelligence: AI hasn’t gone rogue. It’s worse than that
Recent cyber attacks reflect what the technology was trained to do but safeguards are falling short First seen on golem.de Jump to article: www.golem.de/news/artificial-intelligence-ai-hasn-t-gone-rogue-it-s-worse-than-that-2608-212188.html
-
6 NIST Software Criteria for Financial Institutions
Tags: compliance, cyber, cybersecurity, dora, finance, framework, nist, regulation, software, threat<div cla Financial institutions face overlapping requirements from SEC cyber disclosure rules, NYDFS cybersecurity regulations, and sector-specific mandates like DORA in Europe. When your compliance team juggles multiple frameworks while your security operations center monitors threats in real time, the gap between technical findings and boardroom reporting grows wider by the day. First seen on…
-
Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments
Plus: Apple sends out an “unprecedented” number of spyware warnings, Ukraine hits a Russian ecommerce giant with cyber and drone attacks, and more. First seen on wired.com Jump to article: www.wired.com/story/security-news-this-week-your-expired-visa-card-could-be-zombiefied-to-make-contactless-payments/
-
Chinese Hacker Uses DeepSeek and Hermes Agent to Launch Autonomous Cyberattacks
A Chinese-speaking threat actor has been observed using DeepSeek through the Hermes Agent framework to automate reconnaissance, vulnerability research, exploit acquisition, and attack attempts against internet-facing infrastructure. According to Unit 42, the actor tracked under the aliases knaithe and KnYuan built an AI-assisted offensive environment that combined DeepSeek’s reasoning capabilities with Hermes Agent’s terminal access,…
-
Zero-Click Grok Attack Lets Hackers Steal Chat History Using Encrypted Prompt Injection
A newly disclosed prompt-injection technique could turn a routine request to summarize a webpage in xAI’s Grok web chat into a silent data-exfiltration attack, potentially exposing a user’s name, approximate location, subscription tier, and active conversation history. Security researchers at Adversa AI have dubbed the technique >>Cryptographic Context Injection.<< The attack targets Grok's ability to…
-
768 Leaked AWS Keys Still Active With Full Admin Access to Corporate Accounts
Tags: access, cloud, corporate, credentials, cyber, data, data-breach, iam, infrastructure, risk, theftA large-scale investigation has uncovered 768 publicly exposed AWS access keys that remain active and grant full administrative privileges to corporate cloud environments, posing a serious risk of account takeover, data theft, infrastructure abuse, and cloud billing fraud. The credentials include 526 root access keys and 242 IAM user keys attached to AWS’s AdministratorAccess managed…
-
Cyber Talk-11 Palo Alto Networks: A Security Company That Never Stops Rebuilding Itself
On August 19, 2026, Palo Alto Networks announced an industry initiative called the Frontier AI Critical Defense Program, bringing together partners including Anthropic, OpenAI, IBM, Microsoft, Siemens, Red Hat, Idaho National Laboratory, and organizations across technology, energy, healthcare, and industrial control. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/cyber-talk-11-palo-alto-networks-a-security-company-that-never-stops-rebuilding-itself/
-
NCSC tells organisations to have AI kill switches at the ready
In the wake of a series of cyber incidents involving AI agents, the NCSC has published interim guidance for operators of agentic systems, advising organisations retain the ability to pull the plug on AI systems entirely. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649464/NCSC-tells-organisations-to-have-AI-kill-switches-at-the-ready
-
The Cyber Express Weekly Roundup: Tax Data Breach, AI Security Risks, and Critical GitLab Flaw
Tags: ai, breach, cyber, cybersecurity, data, data-breach, exploit, flaw, gitlab, government, risk, software, threat, vulnerabilityThis weekly roundup highlights a broad range of cybersecurity threats affecting government agencies, businesses, enterprise AI systems, and software platforms. From a major French tax authority breach to a critical GitLab vulnerability, recent incidents demonstrate how attackers continue to exploit sensitive data, digital systems, and emerging technologies. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/weekly-roundup-tax-breach-ai-gitlab-flaw/
-
The Cyber Express Weekly Roundup: Tax Data Breach, AI Security Risks, and Critical GitLab Flaw
Tags: ai, breach, cyber, cybersecurity, data, data-breach, exploit, flaw, gitlab, government, risk, software, threat, vulnerabilityThis weekly roundup highlights a broad range of cybersecurity threats affecting government agencies, businesses, enterprise AI systems, and software platforms. From a major French tax authority breach to a critical GitLab vulnerability, recent incidents demonstrate how attackers continue to exploit sensitive data, digital systems, and emerging technologies. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/weekly-roundup-tax-breach-ai-gitlab-flaw/
-
US Bank Investigates Alleged Data Breach After LockBit Ransomware Extortion Claim
US Bank is currently investigating claims made by the LockBit ransomware group, which alleges that it breached the bank and stole sensitive data. The group has set a deadline of September 3 for the bank to meet an undisclosed extortion demand. As of now, the details of the alleged attack have not been independently verified,…
-
Deepfake Ads Funnel Investors Into WhatsApp Groups Controlled by Fake Financial Analysts
Investment fraud is increasingly exploiting the one action banks struggle most to block: a payment the customer actively wants to make. Deepfake advertisements, impersonated financial experts, and coordinated WhatsApp groups are now being used to steer retail investors into manipulated stock trades and fake investment platforms. In 2025, investment scams became the largest fraud-loss category…
-
Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics
Tags: access, authentication, conference, cyber, defense, espionage, google, group, intelligence, phishing, russia, tactics, threat, toolGoogle tracks three Russia-linked espionage clusters using phishing and legitimate authentication tools to target researchers, diplomats and defense staff. Google’s Threat Intelligence Group tracked three separate suspected Russia-linked cyber espionage clusters. All three focus on the same thing: abusing authentication features that are supposed to protect accounts to access them instead. Threat actors target researchers,…
-
More Incidents of AIs Going Rogue in Cybersecurity Challenges
The AI Security Institute has a new report of AI systems engaging in “unsanctioned behavior””, what I have been calling “genie behavior”, while being tested on their cybersecurity capabilities. The incident stemmed from a single evaluation where agents were given a task of solving a cyber security challenge. We ran this challenge 122 times across…
-
UAT-10147 Compromises Web Servers to Deploy BadIIS for SEO Fraud and Data Theft
Tags: china, cyber, cybercrime, data, data-breach, finance, fraud, government, group, linux, malware, technology, theft, vulnerability, windowsA Chinese-speaking cybercrime group, tracked as UAT-10147, targeting vulnerable Windows and Linux web servers worldwide to deploy BadIIS malware, steal data, and manipulate search engine results for financial gain. Talos observed victims in Brazil, Bolivia, China, Canada, and Vietnam, spanning government, education, media, technology, and gaming organizations. An operational security lapse exposed an attacker download…
-
Critical N-Able PassPortal Extension Flaw Gives Attackers Full Password Vault Access
Tags: access, authentication, control, cve, cvss, cyber, cybersecurity, flaw, malicious, password, vulnerabilityCybersecurity researchers have revealed a critical vulnerability in N-able’s PassPortal browser extension that could have allowed a malicious website or embedded iframe to obtain authentication materials and take control of a user’s password vault. This vulnerability, tracked as CVE-2026-15580, affects PassPortal version 3.49.5 and has a CVSS v4.0 base score of 9.4. It was patched…
-
OpenAI Frontier Models Get Zero Data Retention With Private Safety Processing
OpenAI has reaffirmed its commitment to Zero Data Retention (ZDR) for eligible API customers using frontier models while introducing the new Private Safety Processing. This safety architecture is designed to detect multi-session misuse without exposing the underlying prompts or responses to OpenAI personnel. Announced on August 19, 2026, this initiative addresses a critical challenge in…
-
Hackers Hide Agent Tesla Malware Behind Emojis to Steal Browser and Email Passwords
A business email compromise campaign is using emoji-filled JScript to conceal an Agent Tesla v4 infostealer designed to steal browser, email, and messaging credentials. The operation pairs a convincing bank-payment lure with a fileless execution chain that keeps the final malware payload out of sight of traditional disk-based scanning. The messages masquerade as internal forwarded…
-
Quarkslab Says Anti-Reversing Software Should Return Plausible Wrong Answers Instead of Crashing
Quarkslab has argued that LLM-assisted reverse engineering does not make obfuscation obsolete, but it changes the defender’s threat model. Its latest experiment found that autonomous coding agents routinely avoid difficult deobfuscation, pivot to dynamic analysis, and often stop once they obtain an answer that appears credible even if it is wrong. The research firm tested…
-
Head Mare APT Exploits TrueConf Server RCE Flaws to Deliver PhantomCore Malware
Tags: access, apt, attack, conference, cyber, exploit, flaw, group, kaspersky, malware, rce, remote-code-execution, russia, supply-chainThe Head Mare APT group has been linked to a supply chain compromise involving unpatched TrueConf Server instances, which enabled the delivery of PhantomCore malware to video conference participants. Kaspersky researchers identified this activity while investigating attacks against Russian organizations. Attackers hosted legitimate-looking TrueConf client installers on compromised servers that silently deployed the remote-access malware…
-
Head Mare APT Exploits TrueConf Server RCE Flaws to Deliver PhantomCore Malware
Tags: access, apt, attack, conference, cyber, exploit, flaw, group, kaspersky, malware, rce, remote-code-execution, russia, supply-chainThe Head Mare APT group has been linked to a supply chain compromise involving unpatched TrueConf Server instances, which enabled the delivery of PhantomCore malware to video conference participants. Kaspersky researchers identified this activity while investigating attacks against Russian organizations. Attackers hosted legitimate-looking TrueConf client installers on compromised servers that silently deployed the remote-access malware…
-
Google Chrome 151 Update Fixes 7 Security Flaws Enabling Remote Code Execution and Sandbox Escape
Google has released Chrome version 151 to the Stable channel for desktop platforms, addressing seven security vulnerabilities. Among these vulnerabilities is a critical use-after-free flaw, along with several high-severity issues affecting various components of the browser, including V8, DOM, Workers, networking, and Linux toolkit theming. The update is being rolled out as version 151.0.7922.173/.174 for…
-
Critical Spring Security LDAP Flaw Lets Remote Attackers Read and Modify Directory Data
A critical vulnerability has been identified in the embedded UnboundID LDAP server within Spring Security. This flaw could allow remote attackers to authenticate using a well-known administrative bind DN, granting them the ability to read or modify data stored in an application’s in-memory LDAP directory. This issue, tracked as CVE-2026-59270, was disclosed on August 20,…
-
Russia-Linked Hackers Exploit Legitimate Login Flows to Bypass 2FA and Steal Account Access
Tags: 2fa, access, authentication, credentials, cyber, defense, espionage, exploit, government, hacker, login, password, russiaThree suspected Russian cyber espionage clusters abusing legitimate authentication mechanisms to hijack accounts belonging to academics, diplomats, defense personnel, government staff, and think-tank researchers across Europe and the United States. Rather than relying solely on credential-harvesting pages, the operators manipulate users into completing genuine app-password, OAuth, device-code, and device-linking workflows that can hand attackers authenticated…

