Tag: threat
-
ThreatLabz 2026 Report: Frontier AI and Enterprise Readiness
Tags: access, ai, attack, authentication, breach, cisa, ciso, control, credentials, cyberattack, data, data-breach, endpoint, exploit, flaw, governance, identity, Internet, kev, login, malicious, privacy, radius, resilience, strategy, switch, threat, update, vpn, vulnerability, zero-trustThe BreachIt was 9:14 AM when the CISO’s VPN connection momentarily dropped, something that normally wouldn’t cause any concern. What he couldn’t see was that attackers had already exploited a pre-authentication flaw in the VPN appliance itself, gaining access before any login ever occurred. From there, they extracted stored credentials, forged an identity as his…
-
Real emails, hijacked payments: Two H1 2026 attack chains
Gen’s H1 2026 Threat Report examines two separate attack chains. One used compromised business inboxes and browser manipulation in a banking-malware campaign, while the other used clipboard hijacking to redirect cryptocurrency payments. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/real-emails-hijacked-payments-two-h1-2026-attack-chains/
-
Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026
Tags: ai, automation, conference, control, credentials, cve, cyber, cybersecurity, data, data-breach, defense, detection, exploit, flaw, group, iam, intelligence, ISO-27001, mitigation, network, nvidia, offense, open-source, RedTeam, risk, skills, soc, technology, threat, tool, usa, vulnerabilityAgentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event. Key takeaways Building defensive cybersecurity tooling no longer requires a developer. Agentic tooling drove…
-
Beyond Cyber: How CTI Teams Are Solving Converged Threat Use Cases
In this post we explain how cyber threat intelligence teams are being expected to take on physical risk, how tradecraft overlaps, and how Flashpoint bridges the gap. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/beyond-cyber-how-cti-teams-are-solving-converged-threat-use-cases/
-
What Is Cyber Security Risk Assessment? A Complete Guide (2026)
A cyber security risk assessment is a structured process for identifying, analyzing, and prioritizing the risks to an organization’s information systems, data, and operations. It works by pairing each threat and vulnerability with the likelihood it will be exploited and the business impact if it is”, so leaders can decide which risks to fix, transfer,…
-
TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
Tags: attack, cybercrime, group, infrastructure, Internet, malware, software, supply-chain, threat, trainingA new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training their sights on the software supply chain.”The connection is supported by overlapping domains, malware deployment paths, staging techniques, backend…
-
Google’s John Hultquist on outpacing the adversary with AI threat defense
First seen on scworld.com Jump to article: www.scworld.com/resource/googles-john-hultquist-on-outpacing-the-adversary-with-ai-threat-defense
-
Prompt injection remains top LLM threat, OWASP report finds
First seen on scworld.com Jump to article: www.scworld.com/brief/prompt-injection-remains-top-llm-threat-owasp-report-finds
-
The Coordination Gap: How Attackers Are Outpacing Law Enforcement
The fight against cybercrime continues because threat actors have adapted their strategies to avoid deterrents, but law enforcement still operates in silos. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/coordination-gap-attackers-outpacing-law-enforcement
-
Cyber Risk Now Needs a Business Translator
Dataminr’s Balaji Yelamanchili on Risk Prioritization, AI and Cyber Resilience. Security teams face more signals than they can act on, and boards now demand answers in business terms, not technical ones. Balaji Yelamanchili of Dataminr explains how combining threat intelligence with risk quantification helps organizations prioritize what actually matters. First seen on govinfosecurity.com Jump to…
-
Novel-reading apps used users’ phones to generate fake ad traffic
A new mobile ad fraud scheme, dubbed Papyrus, is using a cluster of novel-reading apps to generate hidden browser traffic, according to IAS Threat Lab. Sample novel-reading … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/06/papyrus-mobile-ad-fraud-scheme/
-
AI code security with Claude Mythos Preview: Inside Tenable’s 500+ hours of testing for Project Glasswing
Tags: access, ai, api, application-security, compliance, control, cyber, cybersecurity, data, exploit, flaw, reverse-engineering, risk, software, threat, tool, update, vulnerabilityWe spent 500+ hours and 40 billion tokens testing Anthropic’s Claude Mythos Preview for Project Glasswing. The takeaway: frontier AI won’t run your code security program, but used well, it can make one even stronger. Key takeaways Frontier AI dramatically scales security testing. In one month, Tenable dedicated 11 security experts and more than 40…
-
Fake Xeno Roblox Executor Delivers Powercat Java Stealer Through Discord
The fake “undetected” Xeno Roblox executor currently circulating on gaming forums and Discord is a weaponized loader for the Powercat Java stealer, a multi”‘stage RAT and infostealer that targets Discord, Roblox, Minecraft, crypto wallets and payment tokens while enabling full remote control of infected Windows systems. Threat actors are promoting trojanized Xeno executors through Roblox”‘focused…
-
Mac Malware Found Draining Crypto Wallets After Fake CAPTCHA Trick
Researchers at Huntress have uncovered a strain of macOS malware that can gradually siphon funds out of victims’ cryptocurrency wallets, after tracing an infection back to a fake CAPTCHA scam known as ClickFix. The incident came to light during a retrospective threat hunt in June 2026, when a Huntress analyst discovered remnants of a Mac-specific…
-
Defending Water OT with AZT PROTECT – ARIA Cybersecurity
<div cla The threat landscape for municipal water systems has never been more perilous, and the regulatory spotlight has never been brighter. A flurry of attacks has taken over the news: in some cases, ransomware-based attacks cripple water production and in other cases controls on individual unprotected PLCs are being suddenly accessed by bad actors…
-
KHunt Toolkit Turns Oracle SQL Injection Into SYSTEM-Level RCE and Credential Theft
Tags: credentials, cyber, data, infrastructure, injection, oracle, rce, remote-code-execution, sql, theft, threatKHunt shows how a “routine” SQL injection against an Oracle”‘backed web app can be weaponized into SYSTEM”‘level remote code execution and credential theft by compiling a full post”‘exploitation toolkit directly inside the database engine. This incident materially shifts the Oracle threat model: the database itself becomes attacker infrastructure, not just a data store. Subsequent triage…
-
Kill switch fears now rival ransomware as a top security risk for European businesses, Proton study finds
For years, the security team’s job has been to defend against cyberattacks. New research from Proton suggests that job now needs to extend to a very different kind of threat: the risk that a foreign government orders a US technology provider to cut a business off entirely. A study of 1,500 business decision-makers across the…
-
NVIDIA Group Proposes SAFE Initiative for Agentic Threat Intel Sharing
The Open Secure AI Alliance has announced plans for the Shared AI Findings Exchange (SAFE) First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/safe-initiative-agentic-threat/
-
Why Post-Quantum Security Is Climbing the Enterprise Agenda
Tags: ai, attack, computer, computing, conference, container, crypto, cryptography, cybersecurity, data, google, government, hacker, Hardware, ibm, infrastructure, intelligence, risk, technology, threat, toolWhy Post-Quantum Security Is Climbing the Enterprise Agenda andrew.gertz@t“¦ Thu, 08/06/2026 – 04:56 Learn why post-quantum security is becoming an enterprise priority, how AI and quantum computing are reshaping cryptography, and how Thales Luna 8 helps organizations prepare. Data Security Key Management Encryption Key Management Bree Fowler – Journalist More About This Author > At…
-
Hackers Abuse Cloud Startup Credits to Resell Claude and Gemini AI Access
Threat actors are exploiting free cloud trials and startup credit programs to build gray-market AI proxy services. These services resell discounted access to advanced AI models, including Anthropic Claude and Google Gemini, according to Okta Threat Intelligence. These services rely on fraudulent or synthetic account registrations to accumulate promotional credits offered by cloud providers. The…
-
VulnCheck Warns That Chinese Zbtlink Routers Include a Backdoor
VulnCheck researcher say at least 100,000 Chinese-made Zbtlink routers around the world may include an intentionally implanted backdoor dubbed “Endlessdoors” that could give threat actors access to devices on the network. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/vulncheck-warns-that-chinese-zbtlink-routers-include-a-backdoor/
-
Flooding Dropper Hits npm With 850 Malicious Packages
Tags: attack, automation, cloud, container, control, credentials, cvss, data-breach, detection, dns, endpoint, github, guide, infrastructure, linux, macOS, malicious, malware, monitoring, software, threat, windows<div cla TL;DR Sonatype Research Labs is tracking an active malicious package campaign, dubbed ‘Flooding Dropper,’ spreading on npm, currently impacting 846 software components. The attacker appears to be automating parts of the npm account and package creation process, combining terms such as bigops and bnpl with other words and recurring version patterns, such as releases…
-
Phoenix Security Launches Exploit Hunt to Validate Vulnerabilities With AI-Generated Exploits
Phoenix Security has launched Exploit Hunt, an AI red-team capability that works from a live threat model and reports a vulnerability only after generating and validating a runnable proof-of-concept exploit. Announced Aug. 5 and timed to Black Hat USA 2026, Exploit Hunt is available now in Phoenix Purple. It can run continuously, on every pull..…
-
Intel 471 Adds MCP Connector and Native AI Analyst to Verity471
Intel 471 has added two AI capabilities to its Verity471 cyber intelligence platform: MCP471, a connector for Model Context Protocol workflows, and Agent471, a native AI analyst. The capabilities are being demonstrated at Black Hat USA 2026 from Aug. 4 to 6. Intel 471 said the additions are designed to bring pre-attack intelligence and threat-hunting..…
-
CSS: The Hidden Threat Lurking in Your Inbox
CSS was once just about design. Now researchers warn it’s powerful enough to exfiltrate data from webmail, and some vendors aren’t prepared. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/css-hidden-threat-lurking-inbox
-
Mini Shai-Hulud npm Attack: More Than 2,200 Components Impacted
Tags: access, ai, attack, breach, cloud, container, control, credentials, data, data-breach, github, guide, infection, intelligence, kubernetes, malicious, malware, microsoft, open-source, risk, sbom, service, software, threat, update<div cla TL;DR A new wave of the Shai-Hulud malicious package campaign emerged on npm, with 2,225 software component versions impacted. The malware executes through a malicious preinstall hook, steals npm, GitHub, cloud, Kubernetes, Vault, CI/CD, and other credentials, then uses stolen publishing access to compromise additional packages. Organizations that installed an affected version should…
-
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks.The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software…
-
5 Best AI Detection Response Platforms for 2026
Compare AI detection response platforms for 2026, including Dash, Lakera, Operant AI, HiddenLayer and Prisma AIRS, for runtime threat protection and response. First seen on hackread.com Jump to article: hackread.com/best-ai-detection-response-platforms-2026/
-
Salt Security Launches Industry-First AWS WAF Managed Ruleset for AI Agents and API Protection
Salt Security has unveiled what it says is the industry’s first AWS WAF managed ruleset designed specifically to protect both APIs and AI agents, extending native AWS Web Application Firewall (WAF) capabilities to address emerging threats driven by agentic AI. Announced at Black Hat USA 2026, the new Salt Managed Rules for AWS WAF are…
-
Commvault Adds Google Threat Intelligence to Threat Scan Recovery Workflows
Commvault is adding Google Threat Intelligence data and scanning capabilities to Threat Scan workflows, a move aimed at helping organizations identify compromised recovery points and choose clean data after a cyberattack. Announced during Black Hat USA 2026, the integration combines Commvault Threat Scan with intelligence from Google’s Mandiant, VirusTotal and Google threat teams. Customers will..…

