Tag: cybersecurity
-
OpenAI Pauses Astra Model Over Critical Cybersecurity Risk Concerns
OpenAI paused work involving Astra after tests showed cybersecurity abilities that could approach its Critical risk threshold under the company’s framework. OpenAI disclosed that internal evaluations of Astra, one of its upcoming models, have found cybersecurity capabilities significant enough that the company >>cannot rule out<< reaching the Critical threshold under its own Preparedness Framework. In…
-
Critical Progress LoadMaster flaw now actively exploited in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-warns-of-critical-progress-loadmaster-flaw-exploited-in-attacks/
-
A GitHub Misconfiguration Let Kimi K3 Cheat a Cybersecurity Benchmark
Kimi K3 bypassed a UK cybersecurity test by accessing GitHub, cloning the benchmark and reading its solutions instead of solving the challenge Sometimes the smartest move isn’t solving the puzzle, it’s noticing nobody locked the door to the answer key. That’s essentially what happened when Moonshot’s Kimi K3 model was put through a cybersecurity evaluation…
-
OpenAI locks down Astra over potential critical cyber capabilities
OpenAI’s internal evaluation of its upcoming model, Astra, found significant advances in agentic coding and cybersecurity, leading the company to conclude that it cannot … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/10/openai-astra-critical-cyber-capabilities/
-
Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro (“solidity-pro”) that has been observed delivering a browser wallet and credential stealer.The names of the extensions are below – helper-beeps.solidity-pro web3devtoolsx.solidity-proAlthough neither of the extensions is now available on Open VSX, the GitHub repository First seen on thehackernews.com Jump…
-
Claude-Powered AI Agent Exploits API Authorization Flaw to Hack Gym Booking System
An Australian AI agent powered by Anthropic’s Claude reportedly exploited an authorization flaw in a gym booking platform, allowing it to book classes outside of permitted time frames and cancel another user’s waitlist reservation without explicit permission. This incident underscores how increasingly autonomous AI agents can turn routine online tasks into cybersecurity issues when granted…
-
Cybersecurity Newsletter Weekly Top 50 Biggest Cybersecurity Stories $70M Bitcoin Heist,Google Passkey Theft, Copilot CEO Fraud,Chrome 151 Claude Exploits More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 50 most important stories from August 37, 2026. It was a brutal week for trust in the tools we rely on: a Coldcard firmware flaw drained $70 million in Bitcoin, malware learned to steal Google’s synced passkeys, and […]…
-
The AI safety test is becoming a safety risk
AI agents are escaping cybersecurity testing environments and reaching real-world systems, raising questions about whether safety infrastructure, industry standards and regulation can keep pace with increasingly powerful models. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/09/the-ai-safety-test-is-becoming-a-safety-risk/
-
Security Affairs newsletter Round 589 by Pierluigi Paganini INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions Metabase Zero-Day Exploited in the Wild,…
-
Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions
China opened a cybersecurity review of Palo Alto Networks, citing national security concerns but giving no details about the reasons behind the probe. China’s Cyberspace Administration (CAC) announced that it’s launching a cybersecurity review of products Palo Alto Networks sells in the country. The announcement itself runs to a few sentences of formal Chinese, citing…
-
U.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalog
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, injection, kev, remote-code-execution, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2026-8037 (CVSS score of 9.6), to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability is an OS Command Injection Remote Code Execution issue…
-
Bugtraq Is Back: The Original Full Disclosure Mailing List Is Live Again
Sophia Antipolis, France, August 7th, 2026, CyberNewswire At DEF CON 34 in Las Vegas, security researcher Jonathan Brossard, known in the community as endrazine, announced the rebirth of the original Bugtraq mailing list. Established in 1993, Bugtraq is the original mailing list where cybersecurity vulnerabilities, mitigations, and cutting-edge techniques have been discussed at scale. With…
-
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress”¯Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary First seen on…
-
Zutrittskontrolle als Governance- und Cybersecurity-Priorität
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/zutrittskontrolle-governance-cybersecurity-prioritaet
-
China Opens Cybersecurity Review of Palo Alto Networks Products
China has opened a cybersecurity review of Palo Alto Networks products, raising potential risks for critical infrastructure customers and foreign vendors. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-china-palo-alto-networks-cybersecurity-review/
-
Experts say healthcare faces cybersecurity crisis: ‘These are patient safety issues’
Regulatory failures, funding constraints and industry consolidation have created serious hacking risks. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/healthcare-cybersecurity-crisis-def-con/827378/
-
Water utilities group partners with DEF CON offshoot for Water Watch Center
The National Rural Water Association and a group of cybersecurity experts have formed a program to help cash-strapped utilities face the increase in threats to their systems. First seen on therecord.media Jump to article: therecord.media/water-watch-center-utilities-def-con-franklin-nrwa
-
Kimi K3 Bypasses Cyber Test With Answer From GitHub
Test Flaw Allowed Moonshot AI’s Model to Reach the Internet. Moonshot AI’s open-weight model Kimi K3 jumped its sandbox during a test of its cybersecurity abilities to locate an already worked-out solution on GitHub – behavior perfectly normal for coders but that raises red flags for artificial intelligence models. First seen on govinfosecurity.com Jump to…
-
Cybersecurity, Then & Now: A Visual Look at 20 Years of Change
Tags: cybersecuritySince 2006, Dark Reading has been at the forefront of covering cybersecurity. The more things change, the more they stay the same. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/cybersecurity-then-now
-
AI Agents, Supply Chain Attacks, and Critical Flaws Define the Week in August 2026
Weekly summary of Cybersecurity Insider newsletters for August 2026, including Def Con and Black Hat conference coverage First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/weekly-roundup/ai-agents-supply-chain-attacks-and-critical-flaws-define-the-week-in-august-2026/
-
Chinese AI model Kimi escaped its cybersecurity testing environment, researchers say
In the Kimi test, the sandbox designed to contain the experiment was not properly configured. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/07/chinese-ai-model-kimi-escaped-its-cybersecurity-testing-environment-researchers-say/
-
Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026
Tags: ai, automation, conference, control, credentials, cve, cyber, cybersecurity, data, data-breach, defense, detection, exploit, flaw, group, iam, intelligence, ISO-27001, mitigation, network, nvidia, offense, open-source, RedTeam, risk, skills, soc, technology, threat, tool, usa, vulnerabilityAgentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event. Key takeaways Building defensive cybersecurity tooling no longer requires a developer. Agentic tooling drove…
-
The Cyber Express Weekly Roundup: Ransomware Surge, Government Data Breaches, Logistics Disruptions, and Third-Party Security Risks
This weekly roundup highlights the growing cybersecurity risks affecting businesses, government agencies, and critical service providers. From the continued dominance of ransomware operations to government database breaches and third-party supply chain incidents, recent events demonstrate how attackers are increasingly targeting trusted systems and external service providers to maximize disruption and data exposure. First seen on thecyberexpress.com Jump…
-
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
Cybersecurity researchers have called attention to an active “widespread email-driven phishing campaign” that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email.”The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic, First seen on thehackernews.com…
-
Deemed Export, Deemed Impossible: The Government Discovers That AI Has No Border
Anthropic’s reported AI model shutdown highlights how U.S. export controls could collide with frontier AI, cybersecurity, identity management and global cloud access. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/deemed-export-deemed-impossible-the-government-discovers-that-ai-has-no-border/
-
Frontier AI Has a Cybersecurity Expertise Problem
First OpenAI’s model went rogue and broke out of testing containment to hack real systems, then Anthropic, and now Meta AI. Do you see a trend? Here is what it means: Although these frontier AI companies employ some of the world’s brightest engineers, architects, and developers, technical excellence is not the same as deep cybersecurity…
-
Updoc Data Breach Exposes Patient Contact Information Following Third-Party Security Incident
The Updoc data breach has raised fresh concerns about cybersecurity in Australia’s healthcare sector after the telehealth provider confirmed that an unauthorized third party may have accessed customer contact information through an external system. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/updoc-data-breach/
-
Intruder’s Chris Wallis on AI pentesting and the future of cybersecurity
First seen on scworld.com Jump to article: www.scworld.com/resource/intruders-chris-wallis-on-ai-pentesting-and-the-future-of-cybersecurity
-
Optiv’s John Hurley on simplifying cybersecurity
Tags: cybersecurityFirst seen on scworld.com Jump to article: www.scworld.com/resource/optivs-john-hurley-on-simplifying-cybersecurity

