Site Directory
Services
Newsletter
- OpenAI releases Astra GPT 6, it's not AGI, it's just very useful
- Dwarkesh and Agentic "civilizations"
- The simmering backlash on AI Data Centers
- Two AI realities - The painful path to a glorious future
- 5 trending AI terms you need to know in August 2026
- The meteoric rise and fall of Leopold, a cautionary tale in AI investing
- Anyone can build your product now over a weekend. So where is the moat?
- Kimi K3: Is this China's Sputnik moment for AI?
- Your next Website visitor is not a Human
- Fable 5 returns, but has it been lobotomized?
- AI in a Cage : The end of the "AI for Everyone" Era
- Why I Skipped the SpaceX HyPeO
- The night the Feds pulled the plug: What the Fable 5 shutdown really means for the future of AI
- WWDC 2026: Apple arrives very late to the AI party - limping, on a crutch
- Why is Gen Z booing AI?
- Yes, Google is winning the AI race
- Data Centers in Space and Ocean
- Daybreak vs. Mythos: The AI Cybersecurity arms race
Daily briefings
- Paperclip Authorization Flaw Shows How AI Agents Can Be Turned into Admin-Level Attack Paths
- Paperclip and Ruflo flaws highlight systemic AI agent abuse pathways
- Paperclip Authorization Flaw Highlights Direct AI Agent Abuse Path
- AI Agent Abuse Briefing: Authorization and Sandbox Boundaries Remain a Primary Weak Point
- AI agent abuse remains the highest-risk pattern in today’s briefing
- Paperclip Control-Plane Flaw Shows How Fast Agent Abuse Can Escalate to Code Execution
- Paperclip and Ruflo flaws highlight fragile AI agent control planes
- Paperclip agent-control flaw exposes path from signup to privileged AI execution
- Paperclip authorization flaw turns self-signup into privileged AI agent execution path
- Paperclip Control-Plane Flaw Highlights Rising AI Agent Abuse Risk
- Paperclip Authorization Bypass Highlights Growing AI Agent Abuse Risk
- Paperclip Authorization Flaw Highlights Growing AI Agent Abuse Risk
- AI agent abuse risks center on authorization bypass, sandbox escape, and unsafe tool execution
- Paperclip authorization flaw highlights fragile AI agent control planes
- AI agent abuse remains the top operational risk in today’s briefing
- Paperclip and Ruflo flaws highlight escalating AI agent-control risks
- Paperclip authorization flaw highlights systemic AI agent control-plane risks
- Paperclip control-plane flaw turns self-signup into privileged AI agent execution risk
- AI agent abuse remains the highest-risk pattern in today’s briefing
- Paperclip authorization flaws expose critical AI agent abuse path from signup to code execution
- Paperclip and Ruflo flaws underscore systemic AI agent abuse and orchestration risks
- Paperclip Authorization Bypass Highlights Fragile AI Agent Control Planes
- Paperclip authorization flaw highlights AI agent abuse risks in control planes
- AI agent abuse remains the highest-priority risk across recent agent-control and MCP flaws
- Paperclip and Ruflo flaws highlight systemic AI agent abuse risks in control planes and MCP orchestration
- AI agent abuse remains the top control-plane risk in today’s briefing
- Paperclip and Ruflo flaws highlight escalating AI agent abuse risk
- Paperclip authorization flaws show how weak agent control planes enable rapid privilege escalation
- AI agent control flaws and MCP exposure drive today’s highest-risk alerts
- Paperclip and Ruflo flaws highlight systemic AI agent control-plane exposure
- Paperclip and Ruflo flaws highlight escalating AI agent abuse risk
- Paperclip Authorization Flaw Highlights High-Impact AI Agent Abuse Risk
- Paperclip flaws show how agent control-plane gaps can escalate to code execution
- Paperclip control-plane flaws show how agent abuse can turn low-privilege access into code execution
- Paperclip control-plane flaws show how agent abuse can become RCE
- Paperclip flaw shows how AI control-plane abuse can become full takeover
- Paperclip control-plane flaws enable agent takeover and command execution
- Paperclip flaws show how agent control-plane abuse can lead to full takeover
- Paperclip auth bypass shows how agent control-plane flaws become code execution
- Paperclip flaws show how agent control-plane abuse can turn sign-up into RCE
- Cursor ‘DuneSlide’ Flaws Turn Indirect Prompt Injection Into OS-Level RCE
- Zero-Click and Tooling Prompt-Injection Paths Highlight Need to Rebuild AI Trust Boundaries
- Prompt injection remains a leading path to AI sandbox escape
- Cursor DuneSlide flaws turn indirect prompt injection into full developer workstation compromise
- Cursor ‘DuneSlide’ flaws turn zero-click prompt injection into full RCE on developer machines
- Cursor DuneSlide flaws turn hidden prompt injection into full OS-level RCE on developer machines
- Cursor DuneSlide flaws turn indirect prompt injection into zero‑click OS‑level RCE
- Prompt Injection Turns Cursor IDE Sandbox Escapes into Full Host RCE
- Cursor DuneSlide flaws turn indirect prompt injection into zero‑click OS‑level RCE
- Cursor ‘DuneSlide’ flaws show prompt injection can become zero‑click RCE on developer workstations
- Prompt injection is driving new AI IDE sandbox-escape risks
- Cursor AI IDE prompt-injection flaws turn benign prompts into full workstation compromise
- Cursor DuneSlide flaws show prompt injection can directly trigger OS-level RCE in AI IDEs
- Cursor DuneSlide flaws turn a single prompt into full developer workstation compromise
- Cursor AI IDE flaws turn prompt injection into zero‑click OS‑level RCE on developer machines
- Cursor ‘DuneSlide’ flaws show how a single injected prompt can break IDE sandboxes for full RCE
- Cursor AI IDE Prompt Injection Flaws Enable Sandbox Escape and OS-Level RCE
- Zero‑Click Prompt Injection in Cursor IDE Enables Sandbox Escape and Host RCE
- Cursor AI IDE zero‑click prompt injection flaws enable sandbox escape and OS‑level RCE
- Cursor AI IDE zero‑click prompt injection flaws expose developers to OS‑level RCE
- Zero-Click Prompt Injection in Cursor IDE Enables Sandbox Escape and OS-Level RCE
- Zero‑Click Prompt Injection in Cursor IDE Turns Benign Content Into OS‑Level RCE
- AI Security Advisory: Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands
- AI Security Advisory: Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands
- AI Security Advisory: Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands
- AI Security Advisory: Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands
- AI Security Advisory: Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands
- AI Security Advisory: Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands
- Prompt Injection in AI Coding Editors Escapes Sandboxes and Enables OS-Level RCE
- Cursor ‘DuneSlide’ Bugs Show How a Single Prompt Can Escape the IDE and Hit the OS
- Cursor DuneSlide Bugs Show How a Single Prompt Can Escape IDE Sandboxes and Hit the OS
- Cursor AI IDE Prompt Injection Flaws Enable Sandbox Escape and OS-Level RCE
- Cursor prompt injection flaws highlight agent sandbox escape risk
- Cursor AI IDE prompt injection flaws enable sandbox escape and OS-level code execution
- Cursor ‘DuneSlide’ Flaws Turn Single Prompt Into Full OS Compromise Vector
- Cursor Sandbox Flaws Turn Prompt Injection Into Full Host Command Execution
- FortiBleed Credential Cache Drives High-Impact Data Leakage Risk for AI Environments
- FortiBleed Credential Heist Drives High AI Data Leakage Risk Behind Fortinet Edges
- FortiBleed-driven credential leaks heighten downstream data exposure risk
- FortiBleed Turns Fortinet Perimeters into High-Risk Data Exfiltration Paths
- FortiBleed Campaign Turns Fortinet Perimeters into High-Risk Data Exfiltration Paths
- FortiBleed Perimeter Breach Translates Directly into AI Data Leakage Risk
- FortiBleed Exposes Fortinet Credentials, Elevating AI Data Leakage Risk Behind Compromised Perimeters
- FortiBleed raises data leakage risk through compromised perimeter access
- FortiBleed credential leak raises immediate perimeter-to-internal data exposure risk
- FortiBleed Credential Theft Turns Fortinet Perimeters into High‑Risk Data Exfiltration Paths for AI Systems
- FortiBleed: Stolen Fortinet Credentials Create Direct Path to AI Data Exposure
- FortiBleed Exposes Fortinet Credentials, Puts Downstream AI Data at Risk of Silent Exfiltration
- Cisco Secure Workload CVSS 10.0 API Flaw Creates High-Impact SaaS AI Control Plane Risk
- Cisco Secure Workload CVSS 10.0 API Flaw Exposes SaaS-Attached AI Agents to Cross‑Tenant Data Access
- Cisco Secure Workload CVSS 10.0 API Flaw Exposes High-Privilege SaaS AI Integrations
- Cisco Secure Workload API flaw raises SaaS AI access-control risk
- Cisco Secure Workload CVSS 10.0 API Flaw Exposes High-Privilege SaaS AI Integrations
- Cisco Secure Workload CVSS 10.0 API flaw exposes SaaS AI control plane risk
- Cisco Secure Workload CVSS 10.0 API Flaw Exposes High‑Privilege SaaS AI Control Plane Risk
- Cisco Secure Workload CVSS 10.0 API Flaw Exposes SaaS Tenant Data and AI Automation Paths
- Cisco Secure Workload CVSS 10.0 API Flaw Exposes High-Privilege SaaS Control Plane to Unauthenticated Abuse
- Cisco Secure Workload CVSS 10.0 API Flaw Exposes High‑Privilege SaaS AI Control Plane
- Cisco Secure Workload CVSS 10.0 API Flaw Exposes SaaS AI Control Plane to Cross‑Tenant Abuse
- SaaS AI risk centers on API privilege abuse and supply-chain compromise
- Cisco Secure Workload CVSS 10.0 API Flaw Exposes High-Privilege SaaS Attack Path for AI Agents
- Critical Cisco Secure Workload API Flaw Exposes Cross-Tenant SaaS Data and Controls
- Cisco Secure Workload CVSS 10.0 API Flaw Exposes SaaS AI Control Plane Risk
- Critical SaaS API flaw exposes Secure Workload as an AI control-plane risk
- Cisco Secure Workload API flaw raises SaaS control-plane risk
- Cisco Secure Workload CVSS 10.0 API Flaw Exposes High‑Privilege SaaS Control Plane Risk
- Cisco Secure Workload CVSS 10.0 API flaw creates high‑impact SaaS AI control plane risk
- Cisco Secure Workload CVSS 10.0 API Flaw Exposes High-Privilege SaaS Control Plane Risk
- SaaS AI risk: Cisco Secure Workload API flaw exposes tenant-level data and config paths
Morning briefs
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
- AI Morning Brief: Models, Builders, Security, And Signals
Threat reports
- AI Security Report 2026
- AI Security Issues SMBs Need To Solve Before Rolling Out AI Tools
- AI Cybersecurity Tips to Protect Your Small Business | CO
- Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints
- Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack
- Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation
- LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server
- Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
- China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
- Telus Warns Customers of Account Breaches
- Three JFrog Artifactory Flaws Exploited for Backdoor Deployment
- ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks
- Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
- Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development
- New Warnings About the Risks of AI to Humanity Revive a Long-Running Debate
- Personal, Financial Info Exposed in Revolut Data Breach
- The Race to Control AI and Protect What Makes Us Human
- Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution
- CISOs Race to Control AI Agents Without Destroying Their Value
- New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
- 3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
- Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports
- Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
- WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution
- ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits
- AI Changed the Exposure Problem. Validation Needs to Change With It.
- Context7 MCP documentation server prompt-injection flaw
- Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up
- Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
- Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says
- OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
- BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
- CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
- When the Whole Company Adopts AI: What It Does to Your SOC
- Surfshark Systems Targeted by Hackers
- Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion
- PaperCut Flaws Exploited in AI-Powered Attacks
- Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors
- China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
- PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws
- Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
- Phishing Research Challenges Conventional Security Awareness Testing
- GitLab Vulnerability Exploited One Day After Disclosure
- In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review
- Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack
- Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison
- Check Point Patches Critical VPN Vulnerabilities
- Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance
- GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
- Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
- Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
- Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
- Your Critical Vulnerabilities Might Not Be Your Biggest Risk
- New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender
- Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks
- Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key
- Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6
- Mandiant Founder Kevin Mandia Joins Amazon Board
- Cybersecurity M&A Roundup: 33 Deals Announced in August 2026
- Anthropic Researcher Resigns With Warning About the Dangers of AI Development
- Hacker Conversations: Vinnie Liu, Performer Turned Ringmaster
- Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews
- Webinar Today: Keep Pace With AI – A New Operating Model for Endpoint Remediation
- Critical NetScaler Vulnerability Exploited in Attacks
- ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories
- Google Play Early Access Abused to Push Thousands of Deceptive Android Apps
- Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
- PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
- Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
- CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
- This Key Will Self-Destruct: An Open Standard for Revocable API Keys
- New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser
- Chrome 153 Patches Seventh Zero-Day of 2026
- Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
- New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
- F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
- Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed
- SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution
- Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
- N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
- HelmGuard Raises $7.3 Million for Agentic GRC and Security
- AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns
- Android’s September 2026 Updates Patch 180 Vulnerabilities
- Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories
- Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension
- US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities
- Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy
- ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws
- U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto
- Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
- Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
- Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE
- DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval
- Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets
- U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok
- Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
- BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
- Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing
- Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days
- Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day
- The Hidden Instructions That Can Hijack AI Agents
- Hackers Return $263 Million Stolen From Liquid Network
- Cylake Raises $245 Million Ahead of Cybersecurity Platform Beta
- SAP Patches Critical Extended Passport Processing Vulnerability
- Party’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin Theft
- Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
- Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC
- ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account
- Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
- WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls
- What It Took to Reach 1 Billion Build Manifests
- FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
- Testing race conditions with memory access tracing and stack-based delay injection
- AI Shadow Leaks & News Feed
- N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
- JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
- Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits
- North Korean Hackers Deploy New Linux Espionage Toolkit
- OpenAI Agents Hijack Another Victim Website
- Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
- Modified ScreenConnect Clients Used in Worm-Like Campaign
- PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
- Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
- ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
- Your Cloud Security Checklist Doesn't Work the Way You Think It Does
- Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
- Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
- Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel
- Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
- Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
- Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
- Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
- Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
- Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
- Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
- GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests
- In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation
- HPE Patches Critical RCE Vulnerabilities in AOS-CX
- OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders
- Sangoma Switchvox Vulnerabilities Exploited in the Wild
- 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover
- Catch Raises $5 Million for AI Executive Assistant With Guardrails
- VMware Workstation and Fusion Updates Patch Critical Vulnerability
- Google Patches 6th Chrome Zero-Day of 2026
- Nvidia Is Buying AI Platform Hugging Face for $13 Billion
- Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
- PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
- New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
- Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone
- Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
- CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
- Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal
- Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents
- HiddenLayer Raises $100 Million for AI Runtime Security
- AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million
- 153 Million Driver License Images Offered on Dark Web
- Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability
- Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities
- ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories
- Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
- BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
- Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
- US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
- Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
- Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means
- Chrome and Firefox Updates Patch Dozens of Vulnerabilities
- 23-Year-Old Sality P2P Botnet Disrupted
- SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
- GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
- Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands
- Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
- Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials
- Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads
- OpenLeash Adds a Human Check to Risky AI Agent Actions
- UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure
- Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products
- Exploit Published for Fresh Cleo Harmony Vulnerability
- Anthropic Details Response to Security Incidents, Unveils Enterprise Safeguards
- Malicious Virtualizor Update Served via BGP Hijacking
- OpenAI’s Astra Crosses ‘Critical’ Cyber Threshold After Finding Zero-Days
- Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs
- Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
- Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
- Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
- BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
- Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control
- How to Secure Enterprise AI: From Adoption to Incident Readiness
- Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
- Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild
- 9.5 Million Impacted by Aesto Health Data Breach
- WatchGuard Patches Critical Vulnerabilities
- PaperCut Exploitation Escalates to Active Intrusions
- Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis
- Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity
- Palo Alto Networks Acquires AI Agent Platform Console
- Sevii Targets AI-Speed Attacks With Preemptive Autonomous Defense
- Coast Guard Establishes Office of Maritime Cybersecurity Policy
- Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars
- Hackers Start Exploiting Critical Langflow Vulnerability
- Five Venezuelans Plead Guilty in US Court to ATM Jackpotting
- Ransomware Gang Claims Nutex Health Data Breach
- Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
- Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
- 13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
- Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
- Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones
- Attackers Steal METR API Key and Consume AI Credits Worth About $600,000
- Judge Says Pentagon’s Measures Against Anthropic Were ‘Illegal and Baseless’
- Berlin Won’t Pay Extortion Group Claiming Data Theft
- More Details Emerge on Exploited PaperCut Vulnerabilities
- DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims
- Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit
- ServiceNow Patches 3 Critical Code Injection Vulnerabilities
- McKesson Confirms Data Breach as Attacker Deadline Looms
- What the Hugging Face Incident Teaches Security Leaders About AI Agent Access
- Anthropic Warns Claude Users of Infostealer Malware Infections
- Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs
- North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
- ⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
- ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
- Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
- Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance
- China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
- TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
- Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network
- Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
- Hasbro Data Breach Exposed Employee Personal Information
- Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
- PaperCut Releases Emergency Patch for Exploited Zero-Day
- PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions
- APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
- OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face
- In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions
- ATF Confirms Cyber Incident After Ransomware Group Claims Attack
- OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems
- Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge
- Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says
- Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
- Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers
- ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
- 19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
- Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth
- Key Reasons Why Identity Fabric Matters in 2026
- Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
- China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
- Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
- US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks
- Pro-Russian Hackers Claim Responsibility for Major Cyberattack on Norway’s Public Digital Services
- Recent Citrix NetScaler Vulnerability Exploited in the Wild
- New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access
- CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
- Trump Order Aims to Block Foreign Backdoors in US Power Grid Gear
- Australia Arrests 2 Alleged TeamPCP Hackers
- OpenAI Agents Coordinated via Makeshift Message Board Ahead of Hugging Face Hack
- Okta Shares Surge on Strong Earnings, Growing Demand for AI Identity Security
- CISO Conversations: Chris Wheeler – Trust Is the Job, From the Navy to the C-Suite
- Cyberattack Causes Global Disruption at Boston Scientific
- The Future of AI-Driven Security Depends on Complete Data
- Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
- ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
- Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers
- Learn How to Build Security Operations Ready for AI-Powered Attacks
- Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
- What the Data Says About AI in Security Operations in 2026
- Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools
- GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
- OpenAI explains how its AI agents attacked Hugging Face via Artifactory SSRF zero‑day
- Chrome 152 Patches Over 300 Vulnerabilities
- Sensitive Information Exposed in Nutex Health Data Breach
- CISA Warns of Exploited Gitea Vulnerability
- INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown
- Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode
- Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
- Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
- AI Speeds Up Malware Development, Not Its Success Rate: Analysis
- Adobe and Nvidia Patch Dozens of Vulnerabilities
- CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks
- The MFA Identity Trap: When Authentication Creates a False Sense of Security
- FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
- Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
- NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions
- CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing
- Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code
- Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine
- Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests
- OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation
- Silent Patches Don’t Stop Attackers—They Blind Defenders
- Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff
- CISA Warns of Exploited Oracle WebLogic Vulnerability
- Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
- Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
- Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation
- Alice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails
- WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities
- WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update
- Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference
- First Malware Built Specifically for Car Head Units Fuels Botnet
- U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
- A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
- WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android
- Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode
- Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows
- 24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
- E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands
- Frontier AI: Vulnerability Management's Systemic Revolution
- Rethinking Application Security for the AI Era
- Iran-Linked Hackers Shut Down UK Power Plant for Four Days
- TikTok Reaches $400 Million Settlement With US Justice Department Over Children’s Privacy
- Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund
- UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
- ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited
- Hired for One Job, Judged on Another: The CISO’s Real Problem
- Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts
- 91 Vulnerabilities Patched in Spring Application Framework
- Venezuelan Gets Record Federal Prison Term for ATM Jackpotting
- Personal Information Exposed in Apollo Global Data Breach
- Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt
- Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
- ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
- WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
- Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
- Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
- The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk
- Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight
- 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
- TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit
- AI package supply‑chain breach exposes terabytes of user credentials
- Rust Supply Chain Attack Linked to North Korean Hackers
- Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind
- Microsoft Rolls Out 22 Fresh Security Patches
- CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities
- GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
- Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution
- Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
- Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
- AI Security Incident Database – DuneSlide and Other Agent Exploits
- Former NSA Director Paul Nakasone Launches National Security Advisory Firm
- In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug
- Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini
- New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets
- Critical Isolated-vm Vulnerability Leads to RCE on Host
- Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
- Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
- Wazuh and AI For Enhanced SOC Workflows
- Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0
- Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler
- Critical GitLab Flaw Exploited Shortly After Disclosure
- Hackers Using AI to Target Siemens PLCs in Critical US Sectors
- Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
- Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second
- Hackers Target Zimbra Servers in Active Exploitation Campaign
- Surveillance – Everything You Wanted to Know, But Were Afraid to Ask
- Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia
- Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities
- MLflow Vulnerability Exploited for Cloud Credential Theft
- Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities
- ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More
- AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
- New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data
- Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE
- Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
- Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
- Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments
- Why "Shady AI" is Security's Next Big Governance Problem
- CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification
- Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
- NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
- ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
- 40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
- 943 Patches Rolled Out With Oracle’s August 2026 Security Update
- Chrome, Firefox Updates Patch Dozens of Vulnerabilities
- CareCloud Data Breach Impact Grows to 3.7 Million Individuals
- Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure
- Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
- Virtual Event Today: CodeSecCon – Secure Your Code and Applications
- Prevalent AI Raises $22 Million to Expand Data Fabric Platform
- US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them
- Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign
- CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities
- OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior
- SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs
- Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P
- Phishing 3.0: The Fight Moves to Agent Versus Agent
- StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
- Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
- Heights Finance Data Breach Impacts at Least 1.2 Million Individuals
- GitLab Patches Critical Code Injection Vulnerability
- Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates
- SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers
- CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
- Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
- Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection
- Webinar Today: Rethinking Cyber Defense for AI-Speed Attacks
- CISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW
- AI-Driven Vulnerability Surge Breaks the Traditional Patching Model
- Xpander Raises $7.5 Million for AI Management and Governance
- Fortinet Acquires AI Security Company Virtue AI
- 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw
- Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
- Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
- Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
- AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files
- TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks
- One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
- 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
- 40,000 Impacted by SafePal Data Breach
- Recent macOS Screen Sharing Vulnerability Exploited in Attacks
- Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure
- Fortune 500 Companies Hit in Azure Data Theft Campaign
- 680,000 Impacted by French Tax Authority Data Breach
- Irregular Details How a Naming Error Let AI Models Attack a Real Company
- Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware
- Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
- Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
- ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
- How MCP Servers Can Expose Enterprise Secrets
- Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access
- Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies
- Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
- SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch
- Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner
- Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware
- Over 1,000 Charities Hit by Beacon CRM Data Breach
- 14,000 Trezor Customers Impacted by Data Breach at ShipMonk
- Hackers Exploiting Unpatched GeoServer Zero-Day
- AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions
- In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities
- Trivy, Not LiteLLM Behind the 2,500 Org Compromise
- Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal
- 1.6 Million Likely Impacted by RingCentral Data Breach
- IAM Compliance Requirements and Best Practices
- Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
- Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers
- CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps
- Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware
- Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups
- China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud
- GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE
- White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs
- Critical VMware vCenter Vulnerability in Attackers’ Crosshairs
- Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’
- Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
- Cybersecurity M&A Roundup: 21 Deals Announced in July 2026
- Adobe Commerce Bug Targeted Immediately After Disclosure
- WordPress 7.0.4 Patches Remote Code Execution Vulnerability
- Venture Firm Team8 Secures Additional $365 Million
- Fortinet Patches Authentication Flaws in FortiWeb and FortiManager
- ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories
- New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure
- AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS
- WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud
- North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring
- Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack
- Fresh Windows Zero-Day Exploited in North Korean Cyberattacks
- Ivanti EPM Update Patches Remotely Exploitable Flaws
- ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact
- SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform
- Cisco Patches Firewall Zero-Day Exploited for DoS Attacks
- Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
- Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
- SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
- ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access
- Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
- Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
- Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
- Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client
- Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
- 'Ghostjacking' Attack Uses Poisoned Logs to Turn AI Agents Bad
- SharePoint Vulnerability Exploited Shortly After PoC Release
- Mindgard Raises $30 Million to Protect AI Systems
- WhatsApp Unveils New Scam Alert Feature
- Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset
- Ceva Logistics Operations Disrupted by Cyberattack
- Chipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combined
- Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
- 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One
- OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning
- Enterprise Defenses Recovered at the Edge and Collapsed Inside
- Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
- Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption
- OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber
- Mozilla Issues New Firefox GPG Key Following Exposure
- Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
- BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
- August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day
- Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws
- Zoom Patches Zero-Click Code Execution Vulnerability
- The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It
- Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
- DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
- OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development
- A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
- Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo
- Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers
- Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
- Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
- Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks
- AI Incidents Database
- LiteLLM Supply Chain Attack: 2500+ Companies Exposed
- CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability
- Corporate Data Stolen in Levi Strauss Cyberattack
- Critical Flaws Discovered in Belgian eID Software Used by 2 Million People
- Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
- OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause
- Reco to brief Black Hat on AI agent security risks
- Exclusive: AI cybersecurity startup RunSybil raises $40 million
- OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns
- Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds
- Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC
- ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad
- New Jersey, Alabama Join States Targeted in Water Cyberattacks
- Metabase Patches Vulnerability Exploited as Zero-Day
- Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility
- Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development
- China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
- ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
- Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
- New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
- TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
- Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
- New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
- Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
- N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
- Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
- Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
- Trojanized AI skills gain 1.7M installs in agent-targeted attack
- Chinese AI model Kimi escaped its cybersecurity testing environment, researchers say
- Shadow AI Risk: How SaaS Apps Are Quietly Enabling Massive Breaches
- SMBs and AI: Governance and Security Split Leaders from the 'Stuck ...
- Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data
- Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix
- Black Hat USA 2026 – Summary of Vendor Announcements (Part 4)
- Microsoft, Apple Release Fresh Security Updates
- 3.8 Million Impacted by Unlimited Technology Systems Data Breach
- Critical Vulnerabilities Patched With Chrome 151 Update
- New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
- Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
- Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
- TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
- In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street
- Vishing Extortion Group UNC6671 Rebrands After Making Millions
- ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
- UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
- New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
- Growing Up The Hard Way
- 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
- Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
- AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
- Meta AI Hacked External Systems During Cybersecurity Testing
- Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison
- Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities
- Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability
- Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access
- AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model
- Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
- Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service
- CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
- Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People
- Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
- OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes
- Snowflake Hacker Pleads Guilty in US Court
- Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts
- Podcast: Compliance Won’t Save You: The Future of Cyber Risk with Edna Conway
- Critical Paperclip Flaw Allowed Admin Access, Code Execution
- New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
- Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.9 CVSS Score Bugs
- New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs
- ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories
- Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities
- CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps
- Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses
- AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory
- CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities
- Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
- Water Sector Cyberattacks Reportedly Hit at Least 12 States
- Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself
- CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
- QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
- How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones
- Black Hat USA 2026 – Summary of Vendor Announcements (Part 3)
- The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict
- New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts
- 311,000 Impacted by Brown Health Medical Group-MA Data Breach
- Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data
- Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt
- Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
- Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
- Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain
- New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
- Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk
- Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup
- Leaked n8n API Tokens Exposed Live Instances to Credential Theft
- Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
- OpenAI, Anthropic AI agents implicated in new security breaches
- Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks
- 150,000 Impacted by Madera Community Hospital Data Breach
- Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers
- New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems
- CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
- 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
- Black Hat USA 2026 – Summary of Vendor Announcements (Part 2)
- Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer
- Oligo Raises $60 Million for Runtime Security
- CISO Conversations: Russ Kirby – Passion Is the Antidote to Burnout
- Weaponized Email AI Assistants Could Help Attackers Hijack Accounts
- Zenity Raises $125 Million in Series C Funding
- TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover
- Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
- Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
- Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
- When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted
- Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent
- New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
- DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
- AI agents fake identities and target real people in new security incident
- Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking
- US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States
- Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable
- N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
- Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
- Black Hat USA 2026 – Summary of Vendor Announcements (Part 1)
- Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion
- Cyberattack Hits Liechtenstein’s Register of People Behind Companies and Foundations
- River Bank Says Hackers Deleted Data Stolen in Ransomware Attack
- Horizon3 Raises $250 Million to Fund Continuing Growth
- N‑able Patches Vulnerability Exploited to Hack N-central Servers
- Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
- INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
- ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
- FOMO in the SOC: Where AI Platforms like Claude Actually Fit
- Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
- PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web
- Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
- Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
- Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
- Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
- Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments
- Ruby on Rails Patches Critical Vulnerability
- Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
- Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations
- Critical Flaw Led to Azure Cosmos DB Pwnage
- CareCloud Data Breach Impacts Over 350,000
- Critical Code Execution Vulnerability Patched in TeamCity
- In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research
- Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers
- Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace
- EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels
- HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
- Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
- Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
- Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
- 6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
- Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
- Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations
- What we know about the rogue AI-agent security breaches
- Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms
- 1 in 5 Data Center Assets Are Within Easy Reach of Attackers
- US and Allies Update SBOM Guidance
- Chrome 151 Patches 370 Vulnerabilities
- Cisco Secure FMC Zero-Day Exploited in the Wild
- Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
- FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks
- Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
- Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
- CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs
- Bank of America to Acquire Cybersecurity Firm MDSec
- Okta to Acquire Identity Threat Detection Firm Permiso
- Timeless Compliance: Why Better Questions Beat Bigger Frameworks
- DataBahn Raises $40 Million for Agentic Data Pipeline Management
- Cantina Emerges From Stealth With $8 Million in Funding
- DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
- ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
- Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
- Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
- The Network Has Become the Control Plane for AI Security
- Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
- SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT
- Spur Raises $200 Million for IP Intelligence Platform
- JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack
- Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks
- ShinyHunters Claims Ernst & Young Hack
- Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
- OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
- New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
- Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
- Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
- Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack
- US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security
- Mate Security Raises $35 Million for Agentic SOC
- ThreatLocker Raises $190 Million in Series F Funding
- Critical VM Escape Vulnerability Patched in VMware ESXi
- US, Australia Release OT Isolation Guidance for Critical Infrastructure
- Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
- Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
- Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
- Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
- Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments
- Mythos Asks the Right Question. It Doesn't Answer It.
- Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
- 73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack
- Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity
- Rogue OpenAI agent that hacked startup tried to attack other firms
- Google Adopts New Threat Actor Naming System
- Unpatched Fastjson Vulnerability Exploited in Attacks
- Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day
- Origin Energy Data Breach Affects 900,000 Australians
- For Some, So-Called ‘Skynet Day’ Came too Close to Sci-Fi After a Rogue Agent Hacked Into a Startup
- Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
- Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
- Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Cost
- Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
- Cyera Acquiring Oasis Security in $1 Billion Deal
- Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe
- OT Security Startup Frenos Raises $1.52 Million
- Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model
- Hacker Conversations: Tal Kollander’s Journey From Black Hat to Hack Blocker
- Act Security Emerges from Stealth to Fight the Patch Problem
- Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
- 24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
- JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
- Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
- Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
- DentaQuest Data Breach Potentially Impacts Over 23 Million People
- MCBS Data Breach Affects 1.2 Million Individuals
- TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
- GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption
- New GitHub, PyPI Policies Boost Supply Chain Security
- PTC Windchill Vulnerability Exploited in Ransomware Campaign
- MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection
- Nvidia and Tech Giants Launch AI Security Alliance
- Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack
- NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework
- Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
- Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
- ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
- n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
- Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
- Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
- Rethinking security for the age of AI
- Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
- Small businesses faster at fixing cyber flaws as AI risk grows
- Rockwell Patches Code Execution Flaws in Arena Simulation Software
- Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
- Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
- CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
- Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
- DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
- Data Breach Confirmed After Australian Energy Giant Origin Is Hacked
- NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
- Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
- Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
- Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
- In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws
- AegisAI Raises $36 Million for AI-Powered Email Security
- Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday
- BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
- Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
- ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
- Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
- Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do
- Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
- Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
- Assaf Keren Appointed New CISO of Meta
- New Check Point Zero-Day Vulnerability Exploited in the Wild
- US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices
- Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
- Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
- GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
- OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider
- Is Patching Dead? Vulnerability Management in the Post-Mythos Era
- Chick-fil-A Accounts Get Fried in Credential Stuffing Attack
- Abstract Raises $25 Million to Expand Composable Security Operations Platform
- Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models
- Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses
- ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
- Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
- Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
- China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
- How Synthetic Identity Fraud is Coming for Machine Identities
- Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
- Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts
- AI security threats UK SMBs July 2026
- Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation
- Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates
- Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife
- OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face
- Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
- Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library
- Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
- OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark
- Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs
- Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts
- Palo Alto Networks to Acquire Observability Platform Provider Embrace
- Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft
- When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover
- StrongestLayer Raises $4.1 Million in Seed Funding Extension
- Vibe-Coded Apps Riddled With Exploitable Security Flaws
- Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks
- Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
- Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
- Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
- The Fastest Path to AI Adoption Runs Through Security
- Why Modern SOCs Need Multi-Layered Detections
- How an OpenAI benchmark test turned into a real-world cyberattack
- OpenAI says its AI went rogue and launched 'unprecedented' cyber ...
- OpenAI says its AI agent went rogue and hacked a startup during security testing
- Clover Health Investments Discloses Data Breach
- Exploitation of ServiceNow Vulnerability Seen Days After Disclosure
- Zimbra Update Patches Critical Vulnerabilities
- WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
- New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
- Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
- Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains
- Cisco Launches Low-Cost AI Models for Source Code Security
- Empirical Security Raises $25 Million in Series A Funding
- SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity
- New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication
- CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG
- AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code
- Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities
- Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
- Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
- Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities
- Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs
- N-day is Becoming N-Hour. Patching Faster Won't Save You.
- New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit
- The AI Wire | AI Security Incident News Feed
- Hugging Face Dataset Hack Exposes AI Supply Chain Weakness
- Hugging Face Hacked in Autonomous AI Attack
- Chrome 150 Update Patches Severe Memory Safety Bugs
- WP2Shell WordPress Vulnerabilities Exploited in the Wild
- New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
- Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
- World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
- SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
- Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
- Prompt Injection Breaks Today's AI Agents, Study Warns
- Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software
- SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
- OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability
- New Index Tracks Material Breaches — And Refuses to Add Up the Losses
- Ernst & Young Data Breach Affects Personal, Financial Information
- Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool
- FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
- HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
- ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
- Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
- Mythos Didn't Break Your Security Program. Your Exposure Window Could.
- Hugging Face warns an autonomous AI agent hacked its network
- Hugging Face warns an autonomous AI agent hacked its production infrastructure
- Hugging Face's Autonomous AI Agent Breach
- UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
- SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
- New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
- OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
- Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
- Prompt injection is exploiting enterprise AI's biggest design flaws by targeting agents, RAG pipelines and model routers
- Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei
- Risk Ledger Raises $32 Million in Series B Funding
- Fresh SharePoint Vulnerability Exploited Soon After Disclosure
- Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
- In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint
- Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive
- Beacon Security Raises $13 Million for Security Data Platform
- Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday
- New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
- GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
- Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
- E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants
- The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace?
- Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man
- ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
- New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage
- F5 Patches Multiple NGINX, BIG-IP Vulnerabilities
- China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans
- Old UEFI Shims Expose Systems to Secure Boot Bypass
- Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day
- Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities
- OpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 Sol
- Zoom Patches Critical Windows Flaw That Could Enable Account Takeover
- TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development
- Legacy Systems, Real-World Impacts: The Reality of OT Security
- Two Scattered Spider Hackers Sentenced to Jail in UK
- AI Data Centers Are Being Built Faster Than They Can Be Secured
- ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing
- Oak Emerges From Stealth Mode With $60 Million in Funding
- Splunk, Zoom Patch Critical Vulnerabilities
- Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack
- ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories
- n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer
- New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands
- New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password
- 20+ Hijacked Government Websites Became an Attack Channel
- New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands
- Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor
- AI Can Find Bugs, But Human Knowledge Still Proves Them
- Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide
- MITRE ATLAS AML.T0053 LLM Plugin Compromise
- Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption
- ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell
- Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates
- SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits
- Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
- Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
- Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
- Unpatched Cursor Vulnerability Exposes Users to Code Execution
- CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities
- Windows Bind Link Attacks Can Hide Malware From EDR Tools
- Virtual Event Today: Cloud & Data Security Summit
- US Charges Russian Individuals and Firms for Running Cybercrime Services
- OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
- Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws
- SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.
- Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
- New Webinar: Closing the Approval Gap in AI-Era Ad Tech
- Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution
- Tenet Security hijacked Claude Code in 85% of tests via a fake Sentry error — no stolen credentials, no alerts
- 7,000 Langflow Servers Under Active Attack; LangGraph and LangChain Share Exploited Vulnerabilities
- Prompt Injection Risks 2026: OWASP & Check Point Reports
- Valarian Raises $50 Million for Sovereign Infrastructure Control Layer
- Multiple Jscrambler Packages Impacted by Supply Chain Attack
- Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules
- Grok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It Reads
- U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support
- 148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
- Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity
- Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days
- Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims
- Adobe Patches Critical ColdFusion Vulnerabilities
- 7 Severe Vulnerabilities Patched in VMware Avi Load Balancer
- Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar
- SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud
- SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data
- Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads
- LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts
- RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
- 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
- Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks
- How Pentera Turns AI Security Workflows into Validation Engines
- OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
- Organizations Warned of Exploited Joomla Extension Vulnerabilities
- Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns
- Centers Laboratory Data Breach Affects 540,000 Individuals
- Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365
- iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
- Hacker Conversations: Jesse McGraw (GhostExodus), From Blackhat Hacker to Redemption
- Cybersecurity M&A Roundup: 37 Deals Announced in June 2026
- RabbitMQ Vulnerability Threatens Enterprise Systems
- Zimbra Patches Critical Code Execution Vulnerability
- EU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying Campaign
- CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks
- Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found
- ⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
- New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email
- Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
- Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling
- Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots
- Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory
- Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
- Ghost Accounts Abuse GitHub API in Mass Recon Campaign
- Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
- Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns
- GigaWiper Combines Multiple Malware for System-Level Sabotage
- ‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism
- Network of 200 GitHub Repositories Used for Malware Infection
- Attackers Exploit 'Ill Bloom' Vulnerability to Drain $3.1 Million From Cryptocurrency Wallets
- Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks
- Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
- In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops
- Third US Security Expert Sentenced to Prison for Helping Ransomware Gang
- China, India-Linked Hackers Both Targeted Same Pakistani Police Force
- Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers
- URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat
- Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
- Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot
- Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched
- Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws
- New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic
- Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers
- From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale
- Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
- Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking
- Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access
- Malware attacks on SMBs disguised as AI services surged by five times in 2026, Kaspersky reports
- The AI Supply Chain Has a Supply Chain Problem
- AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique
- Chrome 150 Update Patches 27 Vulnerabilities
- 8Layers Raises $2.9 Million for Identity Security Platform
- Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices
- Meta's New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images
- Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It
- GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
- Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
- QIZ Security Raises $17 Million for Cryptographic Governance Platform
- UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge
- Palo Alto Networks Patches 13 Vulnerabilities
- 12 Million Impacted by Data Breach at Japanese Telco KDDI
- 15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google
- Microsoft Patches Defender ‘RoguePlanet’ Vulnerability
- Mount Royal University Confirms Data Stolen in Ransomware Attack
- New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware
- npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk
- ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories
- AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up
- Summer of Clearinghouses
- GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses
- Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges
- GitLost: GitHub AI Agent Leaks Private Data via Prompt Injection
- China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware
- 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
- CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
- Accenture Confirms Data Breach After Hacker Claims Source Code Theft
- China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors
- Webinar Today: Why Email Security Keeps Failing
- Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations
- CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws
- Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection
- AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers
- New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware
- Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS
- New Ghost Phishing Wave Is Breaking Traditional Email Security
- SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
- GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures
- The Verification Step Is the New ATO Battleground in 2026
- GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code
- Is AI Making Cyberattacks Worse for Small Businesses?
- Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
- CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
- BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA
- Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
- County Government Reportedly Paid $1 Million to Cyber Extortion Group
- Critical Gitea Flaw Under Active Exploitation, Researchers Warn
- CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws
- Critical Adobe ColdFusion Vulnerability Exploited in Attacks
- Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks
- CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Thinker
- Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems
- Keyfactor Scores $1 Billion+ Investment for AI, Post-Quantum Security
- RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service
- Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots
- DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
- Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data
- Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker
- Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants
- What Changes When Your Software Supply Chain Includes AI Writing Your Code?
- New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions
- New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS
- Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages
- SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing
- Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks
- The Shift Toward Business-Aligned Risk Management
- Armored Likho APT Targeting Government, Electric Power Entities
- North Korean Hackers Target Open Source Developers in Supply Chain Attacks
- Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability
- Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments
- 16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems
- Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure
- ⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More
- How to Evaluate an AI SOC Platform in 2026: 6 Capabilities That Separate Leaders from Bolt-On AI solutions
- Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
- Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices
- New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android
- New Avalon Malware Framework Packs CrownX Ransomware Capabilities
- U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case
- North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
- Medtronic Data Breach Impacts 3.8 Million People
- Alleged Scattered Spider Hacker Extradited to US
- Google, FBI Disrupt NetNut Residential Proxy Network Powered by Millions of Devices
- Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution
- PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords
- Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices
- Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
- In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM Jackpotting
- Agentic AI Used to Conduct Ransomware Attack via Langflow
- North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
- Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer
- European Parliament Member Investigating Spyware Was Hacked With Pegasus
- 史上初のAIエージェント型ランサムウェア「JadePuffer」感染事例の報告
- AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
- FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations
- New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos
- SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
- Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters
- 19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges
- New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure
- How to Conduct a Successful Audit of AI-Driven Software Development
- FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks
- Trump Administration Lifts Restrictions on Anthropic’s Claude Models After Cybersecurity Alarm
- Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability
- ‘BioShocking’ Attack Tricks AI Browsers Into Stealing Credentials
- ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories
- ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API
- Identity Lifecycle Management Wasn't Built for AI Agents
- Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors
- Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari
- Dawnguard Raises $6.3 Million for Security Architecture Automation Platform
- Massive Password Spray Campaign Targeting Azure CLI
- Google Patches 382 Chrome Vulnerabilities
- Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware
- Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls
- Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts
- Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery
- Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service
- Microsoft Adds New Teams Controls to Block Unauthorized AI Bots From Meetings
- Adobe Patches Critical ColdFusion, Campaign Classic Vulnerabilities
- Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attack
- SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT
- VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer
- Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures
- Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic
- Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands
- Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts
- AI-Generated Browser Ransomware Abuses Chromium API on Windows, Linux, macOS, Android
- 2026 Cybersecurity Assessment: The Gap Between Awareness and Resilience
- Microsoft Accelerates Post-Quantum Cryptography Shift to 2029
- SMBs Grapple with AI-powered Malware Fears Despite ...
- Tokyo SMB Cybersecurity News Clip: Runaway OpenAI Models Attack Hugging Face in Evaluation Escape Incident
- The AI Token Costs That Can Break Cybersecurity
- Nissan Employee Data Breached in Oracle PeopleSoft Hack
- Critical SimpleHelp Vulnerability Exploited for Malware Delivery
- Quantifind Raises $200 Million for AI-Native Risk Intelligence
- New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking
- New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials
- Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth
- Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs
- Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild
- Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input
- BlueHammer Vulnerability Exploited in Ransomware Attacks
- Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks
- Aflac Japan Data Breach Impacts 4.38 Million
- Hacker Conversations: Chris Thompson, Former Head of IBM X-Force Red, Co-Founder of RemoteThreat
- Supreme Court Rules Constitutional Privacy Protections Apply to Cellphone Users’ Location History
- Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data
- RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS
- Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints
- Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses
- GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks
- 282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study
- What the Numbers Say About FIFA 2026 Cyber Risk
- Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer
- AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks
- Microsoft Copilot Studio Zero-Click Email Injection Tracked as CVE-2026-21520
- SearchLeak and LiteLLM CVE Chain Break Email and Key Trust Boundaries in GenAI Stacks
- AI Agent Security Practices 2026: Prompt Injection, MCP Risks, Data Leaks
- Securing AI agents: When AI tools move from reading to acting
- US Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks Evolve
- OpenAI Unveils GPT-5.6 Sol as Its Most Advanced Cybersecurity AI
- Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts
- Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw
- Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer
- WhatsApp Rolling Out Username Feature to Bolster Phone Number Privacy
- Researchers Demo New Claude Code Attack Using Harmless-Looking Repositories to Hijack Developer Machines
- Straiker Raises $64 Million for AI Security Platform
- Insurance Regulators Group NAIC Hit in Oracle PeopleSoft Hack
- ‘DirtyClone’ Linux Kernel Vulnerability Leads to Root Access
- WhatsApp is Finally Getting Usernames to Help Keep Phone Numbers Private
- Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks
- ⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More
- 236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers
- Why Post-Quantum Cryptography Starts With Credentials
- Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
- FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys
- Chinese Framework Powers 200,000 Scam Sites
- Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials
- OpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber Safeguards
- $3 Million Reportedly Stolen in Polymarket Hack
- Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets
- First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild
- New Enterprise-Ready MCP Specification Brings New Security Challenges
- Philip Martin Joins Uber as Chief Information Security Officer
- Russia Used Cellebrite on Jailed Activist's iPhone Months After Sales Cutoff
- Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks
- Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories
- More Klue Breach Victims Identified as Hackers Get Hacked
- In Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk Layoffs
- Nebulock Raises $25 Million for AI-Native Contextual Security
- Linux Foundation Unveils New Open Source Security Project Akrites
- New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
- Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign
- New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries
- Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs
- CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
- New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets
- Guardian Agents: The Next Layer of Identity Governance
- Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack
- Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant
- 25-Year-Old Vulnerability Patched in Curl
- NIST Opens Updated IoT Security Guidance to Public Review
- Chrome 149 Update Resolves 18 Severe Vulnerabilities
- Cisco SD-WAN Zero-Day Exploited Months Before Patching
- New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns
- Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access
- Runlayer Raises $30 Million in Series A Funding
- Cal Water Says No OT Systems Breached in Iranian Handala Cyberattack
- Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning
- GitLab Patches Code Execution, Information Disclosure Vulnerabilities
- Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability
- ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories
- Surviving the Mythos Era: Richard Bejtlich on the Case for NDR
- New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis
- Webinar Today: Modern Exposure Validation in the AI Era
- Hackers Exploiting Cisco Unified CM Vulnerability
- Anthropic’s Mythos Model Found Vulnerabilities in Classified US Government Systems, Official Says
- DoJ Seizes Huione Cloud Account Tied to Cyber Scam Money Laundering
- Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root
- When Information Becomes the Attack Surface – Understanding AI Agent Traps
- Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware
- Exclusive: Meet AIVEX, a New Triage Model Built to Reduce Supply Chain Threat and Risk
- macOS Weaknesses Chained to Silently Disable Endpoint Security Agents
- Third DraftKings Hacker Sentenced to 18 Months in Prison
- Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs
- CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited
- Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered
- Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
- Dawn of the Apex Agentic Adversary
- Canadian Electricity Provider London Hydro Discloses Data Breach
- Trump Signs Executive Order Accelerating Post-Quantum Cryptography Migration
- Xsolis Data Breach Affects 1.4 Million Individuals
- Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT
- WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool
- OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws
- Dragos Unveils AI for OT Security
- Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps
- Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks
- CISO Conversations: Carl Froggett – Combining CISO and CIO at Deep Instinct
- Algerian Man Extradited to US for Running Cybercrime Marketplaces
- FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances
- OpenAI Refocuses Cybersecurity Efforts on Patching Over Discovery
- FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation
- Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents
- Trump Order Sets 2030 Deadline for Federal Post-Quantum Crypto Migration
- GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns
- Agentic AI: The Weapon That No Longer Needs a Warrior
- Fortinet Responds to FortiBleed Campaign
- More Cybersecurity Firms Disclose Impact From Klue Hack
- Texas Parks & Wildlife Data Breach Affects 3 Million Individuals
- Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices
- AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network
- INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific
- Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data
- Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data
- North Korean Hackers Blamed for Mastra NPM Supply Chain Attack
- What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks
- New Exploit Bypasses Apple’s Boot Defenses, Affects Millions of iPhones
- ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack
- Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants
- 29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests
- New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer
- Google Sets Sept. 30 Deadline for Android Developer Verification in Four Countries
- Stop Your Legacy Infrastructure from Hijacking Your AI Agents
- ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More
- AI Is Changing Cyber Risk. Here's How SMBs Can Respond.
- French President Urges US to Share Cutting-Edge AI and Democracies to Cooperate on Regulation
- Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain
- The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes
- Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
- HSCC Issues New Guidance on AI Cyber Risk and Governance for Healthcare Organizations
- Cybersecurity Firms Impacted by Klue Supply Chain Attack
- Cisco to Acquire WideField Security to Boost Splunk’s Agentic SOC
- 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown
- Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure
- Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data
- Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone
- In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum
- CryptoBandits Malware Doubles as a Backdoor, Abuses Tor
- FortiBleed: 86,000 Fortinet Device Credentials Compromised
- AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution
- Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites
- CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices
- From Assistive to Agentic: The AI Shift That's Redefining Threat Management
- Forget Data Leakage: Shadow AI's Real Threat Is Access Control
- F5 Patches Critical, High-Severity NGINX Vulnerabilities
- SailPoint to Acquire Entro in Reported $200 Million Deal
- Kodak Admits Data Breach After ShinyHunters Hack Claims
- Majority of Internet-Accessible REDCap Servers Outdated
- Accenture to Acquire Majority Stake in Dragos, All of runZero, NetRise in $4.1 Billion OT Cybersecurity Push
- No Exploits Required
- Dream Raises $260 Million at $3 Billion Valuation
- Atlassian, Splunk Patch Critical Vulnerabilities
- Rokarolla Banking Trojan Targets 200 Applications
- F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution
- Orphaned AI Agents: How to Find Hidden Access Risks Inside Your Network
- ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories
- Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2
- INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023
- The Scripts on Your Checkout Page Are Now a PCI DSS Problem
- DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic
- Only 11% of SMBs Are Utilizing AI-Powered Defenses Amid Growing AI Threats
- Stolen AI Compute as Attack Infrastructure (LLMjacking)
- Microsoft Working on Patch for ‘RoguePlanet’ Zero-Day
- Oracle’s Second Monthly Security Updates Deliver 245 Patches
- Chrome and Firefox Updated to Patch Critical, High-Severity Vulnerabilities
- Joomla, LiteSpeed Vulnerabilities Exploited in Attacks
- 3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs
- Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats
- 144 Mastra npm Packages Compromised via Hijacked Contributor Account
- CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution
- Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting
- Webinar Today: How Modern Breaches Bypass MFA and Evade Detection
- 1Password Acquires Apono in Reported $250M-$300M Deal
- Tenet Security Emerges From Stealth With $6 Million Seed Funding
- Rockwell Automation Patches Vulnerabilities in ICS Controllers and Software
- Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack
- Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments
- Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development
- Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline
- Adversarial Exposure Validation Turns Security Visibility into Confident Prioritization
- The Top 10 Attack Surface Exposures in 2026
- Tech Coalition ‘Athena’ Targets OSS Vulnerabilities Ahead of Disclosure
- Cisco Patches Another SD-WAN Zero-Day Exploited in Attacks
- Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware
- Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw
- CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation
- Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails
- North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels
- iRhythm Confirms Data Stolen in Hack
- Hacker Conversations: Isira Adithya, the Evolution of an Ethical Hacker
- Magnitude Emerges From Stealth Mode With $10 Million in Funding
- AI and Cybersecurity – Everything You Wanted to Know, But Were Afraid to Ask
- Endpoint Security Startup Ent Emerges From Stealth With $100 Million Seed Round
- ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures
- New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds
- Survey: 94% of Incidents Involve Anonymized Infrastructure. Teams Are Still Reactive
- Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week
- China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth
- FBI, Google Dismantle ‘Outsider Enterprise’ Phishing Service
- Maine Disables Data Breach Portal Due to Fake Submissions
- Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts
- Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw
- Ransomware Attack Shuts Down Mills of Australia’s Second-Largest Sugar Producer
- Chinese Hackers Target Medical, Military, and AI Research in North America
- NewCore Emerges From Stealth Mode With $66 Million in Funding
- Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges
- Ozempic Maker Novo Nordisk Says Hackers Breached IT Systems
- French Government Messaging Platform Breached by Mysterious ‘Misere’ Hacker
- ShinyHunters Claims Council of Europe Hack
- LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers
- One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
- ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More
- The Onboarding Password Mistake That Creates Unnecessary Risk
- 152 Chrome Wallpaper Extensions with 105K Installs Linked to Adware and Fake Traffic
- Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites
- Anthropic Says It Has Taken Its Latest AI Models Offline to Comply With New Export Controls
- U.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign Nationals
- Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit
- Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing
- NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks
- Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication
- Ivanti Sentry Exploitation Attempts Hitting Honeypots
- Chrome 149 Update Patches 28 Vulnerabilities
- Anthropic Disputes Fable 5 AI Jailbreak
- Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters
- LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution
- INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator
- Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities
- In Other News: Google Security Layoffs, AudiA6 Takedown, $400 Million Coupang Fine
- Industry Reactions to Claude Fable 5: Feedback Friday
- Iranian Cyber Group Handala Claims Cal Water Hack
- China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade
- Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code
- Rethinking MDR as Attackers and Defenders Embrace AI
- ESET調査:中小企業のAI活用で設定不備やプロンプト注入による情報流出リスクが増加
- ‘GreatXML’ Zero-Day Exploit Bypasses BitLocker
- University of Nottingham Confirms Breach After Hackers Leak Data
- Microsoft Patches Exploited Exchange Server Vulnerability
- GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks
- Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks
- Alert Fatigue Is Becoming a Security Threat of Its Own
- CISA Directs Federal Agencies to Prioritize Security Patches Based on Risk
- OnyxC2 Stealer Offers Cybercriminals Enterprise-Grade Theft for $250 a Month
- Hackers Exploit Langflow Vulnerability for Remote Code Execution
- Siemens Says Desigo CC Files Flagged as Malware by Security Engines
- New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets
- New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files
- The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm
- Cybersecurity Stars Awards 2026: Winners Announced Across 95 Categories
- ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories
- AI Broke Vulnerability Management. That's Why CISOs Are Moving Budget to BAS.
- OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack
- Guardz Report: 9 Out Of 10 SMBs Have Compromised Users as AI-Driven Attacks Reshape the MSP Threat Landscape
- Prompt injection still drives most agentic AI security failures
- ServiceNow Patches Vulnerability Exploited Against Some Customers
- Critical Vulnerabilities Patched in Fortinet, Ivanti Products
- ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact
- No Patch Planned for Exploited Arista EOS Vulnerability
- Anthropic Releases Claude Fable 5, Its Most Powerful AI Yet, With Cyber Safeguards
- ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances
- Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows
- Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS
- Infostealers Turn Millions of Devices Into Credential Theft Machines
- Cyera Raises $600 Million at $12 Billion Valuation
- Aryon Security Raises $29 Million in Series A Funding
- Critical HVAC and UPS Vulnerabilities Could Let Hackers Disrupt Data Centers
- CISO Forum Webinar Today: 2026 Mid-Year Review
- New Windows Zero-Day Exploit ‘RoguePlanet’ Released
- After AI Reaches Production: 12 Ways Security Teams Can Take Control
- China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance
- Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities
- Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE
- CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation
- Your Automated Pentest Looks Clean. See What It Missed in This Expert Webinar
- Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs
- Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks
- Google Patches 5th Chrome Zero-Day Exploited in 2026
- LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE
- One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public
- Microsoft Patches 200 Vulnerabilities
- Adobe Patches 123 Vulnerabilities
- Anthropic Launches Claude Fable 5: Mythos-Class AI With Cybersecurity Guardrails
- OpenSSL Patches High-Severity Vulnerability Found With AI
- Claude Mythos Turns N-Days Into N-Hours With Rapid Exploit Creation
- New Platform Uses Cryptographic Invisibility to Protect AI-Built Applications
- Meta to Use Off-Site Business Data for Feed and AI Personalization
- Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code
- Microsoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe Continues
- WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine
- Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models
- Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now
- The Hidden Security Risk in Modern Networks: The Work Between Tools
- New FROST Attack Lets Websites Track What Sites and Apps You Open via SSD Timing
- Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer
- AI Cybersecurity Risks in Healthcare
- OpenAI Rolling Out ChatGPT Account Security Controls
- SolarWinds Serv-U Vulnerability Exploited in the Wild
- Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse
- UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign
- VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks
- A Security Raises $37 Million for Autonomous Offensive Security Platform
- Everybody Is Vibe Coding But Nobody Told the Security Team
- WhatsApp Catches Spyware Firm NSO Defying No-Hacking Court Order
- Cybersecurity M&A Roundup: 26 Deals Announced in May 2026
- Everest Forms Vulnerability Exploited to Hack WordPress Sites
- 174,000 Impacted by Lansing Community College Data Breach
- Silent Ransom Group Uses DNS Fast Flux in Attacks
- Meta Blocks NSO Group's New WhatsApp Phishing Attack, Files Contempt Order
- Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups
- AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overload
- ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More
- The Hardest Fork
- VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances
- AI attacks are more likely to target the model than the user, prompt injection and data leakage risks grow
- OpenAI Cookbook: Best Practices for Building Safe AI Agents
- Emphere Raises $2.1 Million for AI-Powered Vulnerability Remediation
- AI Agent Prompt Injection: The New CI/CD Supply Chain Threat
- Free Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AI
- CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog
- AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs
- Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available
- Opal Security Raises $23 Million for AI-Native Identity Governance
- New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration
- Five Eyes: Chinese Spies Target Government, Military Staff With Fake Job Opportunities
- Nightclub Giant RCI Says Data Breach Affects 40,000 Individuals
- Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026
- Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites
- FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins
- PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network
- OWASP Incubator Project Helps Developers Find and Fix Vulnerable Dependencies in Seconds
- In Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISA
- Hackers Leak DentaQuest Information Impacting 2.6 Million
- Chrome 149 Patches 429 Vulnerabilities
- Industry Reactions to New Trump AI Cybersecurity Executive Order: Feedback Friday
- IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks
- Android Spyware Asin Targets Arabic Users via Fake News, PDF and War Map Apps
- New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework
- Only 10% of SOCs Say They’re Getting Excellent Value From AI. Here’s What the Second Wave Has to Deliver
- Cisco Warns of Available PoC for Critical Unified CM Vulnerability
- VS Code Vulnerability Allows One-Click GitHub Token Theft
- Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS
- Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months
- CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog
- DoJ Disrupts Southeast Asia Crypto Fraud Networks, Freezes $3.8 Million in Assets
- WhatsApp, Slack Notifications Could Hijack Google Gemini on Android
- Offroad Emerges From Stealth With $7 Million to Tackle Enterprise Identity Risk
- Webinar Today: Third-Party Risk in Practice – Where Programs Break Down and How to Respond
- Willow Raises $7 Million for Securing Autonomous AI Agents
- Gemini Voice Assistant Hijacked via Messaging Notifications
- Mirasvit Vulnerability Exploited to Execute Code on Magento Servers
- Chinese Cybercrime Group in Spotlight for Record Campaign Pace
- Over 1.4 Million Accounts Disrupted in Cybercrime Crackdown
- Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public
- Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories
- Agentic AI Is Transforming Defense, But Only Secure IT Infrastructure Will Maximize It
- ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories
- China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa
- FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads
- Microsoft Tries to Calm Legal Threat Fears After Zero-Day Disclosure Backlash
- New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare
- Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content
- Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited
- Coralogix Raises $200M at $1.6B Valuation to Scale AI Observability Platform
- Kirki, Burst Statistics WordPress Plugin Flaws in Attackers’ Crosshairs
- Security of 100 AI Agents Tested and Ranked – What You Need to Know
- Hackers Target Global Stock Exchange in Espionage Operation
- IMA Diligence Services Data Breach Impacts 525,000 People
- Organizations Warned of Exploited Linux Kernel Vulnerability
- ‘HTTP/2 Bomb’ Exploit Knocks Web Servers Offline in Seconds
- Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT
- Beyond the Zero-Day: See Your Network Like an Attacker | Webinar with HD Moore
- Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag
- Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)
- One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens
- Shrinking the IAM Attack Surface through Identity Visibility and Intelligence Platforms (IVIP)
- Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes
- A complicated relationship between SMBs and AI tools
- Supply Chain Attack Hits 32 Red Hat NPM Packages
- Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads
- Oracle’s First Monthly Patches Resolve 77 Vulnerabilities
- Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT
- Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded
- Trump Signs Executive Order That Invites Vetting of Top AI Models for National Security Risks
- Two New Reports Offer Competing Explanations for Cybersecurity’s Growing Crisis
- Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk
- Android Update Patches Exploited Zero-Day, 123 Other Vulnerabilities
- Anthropic Expanding Mythos Access to 150 New Organizations
- The Zero-Knowledge Threat Actor and the End of Responsible Disclosure
- Critical Vulnerability in HP VoIP Phones Enables Enterprise Network Breaches
- Oracle WebLogic Vulnerability Exploited in the Wild
- Meta AI Hands Over High-Profile Instagram Accounts to Hackers
- Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine
- Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation
- AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It.
- How Leading Organizations Are Turning EDR Into Operational Resilience
- LLM Agents as Active Post-Exploitation Tools
- Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts
- WP Maps Pro Vulnerability Exploited to Take Over WordPress Sites
- Dutch Police Dismantle Massive 17-Million-Device Botnet
- Critical Windows Netlogon Vulnerability in Attackers’ Crosshairs
- Dragos Acquires xIoT Security Firm Phosphorus
- As the Pentagon Pushes for Battlefield AI, Some Military Leaders Urge Caution
- 19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access
- Recent Palo Alto Networks Vulnerability Exploited for Weeks
- Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm
- ⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More
- China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan
- The Security Growth Platform: Why MSPs Are Moving Beyond vCISO Tools
- OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack
- CISO Daily Briefing – Marimo LLM Agent Post-Exploitation Incident
- Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices
- Russian Spies Are Aggressively Seeking Western Technology as Sanctions Bite, Officials Say
- Exploit Code Published for Critical Flowise RCE Vulnerability
- PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation
- Top AI Security Vulnerabilities to Watch out for in 2026
- Inside the shadows: The new SaaS security risks of Shadow AI in 2026
- Top 5 AI Security Threats in SaaS
- Cybersecurity climbs the SMB agenda, as AI pressure exposes resilience gaps
- AI in cybersecurity: SaaS security risks you can't afford to ignore
- AI-Induced Cybersecurity Risks in Healthcare: A Narrative Review of ...
- AI and SaaS Will Make 2026 a Turning Point for Healthcare Security
- AI Adoption, SaaS Disruption & Cybersecurity Risks
- Indirect Prompt Injection via Corporate Emails Exploits Executive AI Agents
- In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain Attacks
- Charter Communications Data Breach Could Impact Nearly 5 Million
- MokN Raises $15 Million for Phish-Back Platform
- Gogs Zero-Day Exposes Servers to Remote Code Execution
- California Sues 23andMe, Alleging It Failed to Protect User Data in 2023 Breach
- Chrome 148 Update Patches 151 Vulnerabilities
- ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface
- Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit
- New Russia-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks
- What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks
- Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets
- Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels
- Sysdig catches first live LLM attack on AWS database
- Popular open-source RAG package found hosting malicious packages in supply chain leak
- Russia-Linked ‘GreyVibe’ Attackers Use AI to Supercharge Cyberattacks
- Geordie Raises $30 Million for AI Security and Governance Platform
- Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code
- Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer
- Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal
- ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More
- New AI Usage Report: Enterprise AI Risk Is Heavily Concentrated Among a Small Group of AI "Power users"
- JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware
- Regulatory Crackdown on Startup AI Data Ingestion Laws Passes Senate
- Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users
- Malicious npm Package Stole Files From Claude AI User Directory via GitHub
- 5 Steps to Managing Shadow AI Tools Without Slowing Down Employees
- GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure
- 3 SOC Steps that Shut Down Incident Risks Early
- Gitea Vulnerability Exposes Private Container Images without Authentication
- AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites
- Cyber Security Moves Up the SMB Agenda as AI Adoption Exposes Operational Gaps
- Indirect Prompt Injection Goes Live: Why Guardrails Won't ...
- MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries
- [THN Webinar] New AI DDoS Attacks Are Smarter. Learn How to Fight Back
- Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions
- MFA Prompt Bombing: Why Your Second Factor Isn't Saving You
- CERT-In Recommends 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks
- Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning
- KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike
- ⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos
- Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks
- The Alert Firehose Finally Meets Its Match
- Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms
- TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO
- Japanese SMB Cybersecurity News Clip: EU AI Act High-Risk System Guidelines and SME Resources
- npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks
- Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware
- Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software
- Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer
- LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root
- Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV
- First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups
- Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware
- Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows
- Making Vulnerable Drivers Exploitable Without Hardware - The BYOVD Perspective
- Kimwolf DDoS Botnet Operator Arrested in Canada Over DDoS-for-Hire Attacks
- CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV
- Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access
- Cybersecurity Rises on SMB Agendas Amid AI Expansion
- AI Has Changed the Cybersecurity Threat Landscape for SMBs, Warns Eclipse Networks
- Anthropic Discloses Prompt Injection Risks: Browser Agent Hijacked in 31.5% of Tests
- Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor
- ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories
- Microsoft Warns of Two Actively Exploited Defender Vulnerabilities
- When Identity is the Attack Path
- 9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros
- Top 14 AI Security Risks in 2026
- Bedrock’s ArgusAI Offers Transparency into Data Access by AI Models and Agents
- Threat landscape for SMBs in 2026: fake AI tools, phishing ...
- AI Has Changed the Cybersecurity Threat Landscape for SMBs, Warns Eclipse Networks
- Useful but Risky: A Complicated Relationship Between SMBs and AI Tools
- Is AI Making Cyberattacks Worse for Small Businesses?
- AI Security for SMBs: Emerging Threats from Slopsquatting and Adaptive Malware
- Documented AI Agent Incidents
- Sysdig Researchers Document JADEPUFFER: First End-to-End Ransomware Attack Executed by an AI Agent
- SMBs and AI: Governance and Security Split Leaders from Laggards
- A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens
- Healthcare AI Platform Xsolis Reports Data Breach Affecting 1.4 Million Individuals
- 2026 SMB Threat Report: Fake AI Tools Drive Attacks
- SMBs Hit a Cybersecurity Breaking Point as 91% Fear AI-Powered Threats
- SMBs Falling Behind in AI-Powered Cyber Defenses, CrowdStrike Study
- AI-Optimized npm Malware Targeting LLM Agents
- Why AI Security in Healthcare and Finance Can't Wait
- AI Agents Are the New Exposure Point for MSPs and SMBs
- As AI Evolves, Necessary Coordination on Security Expands
- AI Security Platform Race Highlights Third-Party AI Risk
- Fintech Shows Resilience As SaaS Plummets Amid AI Turmoil
- Incorporating AI into Your Cybersecurity Strategy for Small to Mid-Sized Businesses
- Health-ISAC Analyzes How Anthropic’s Claude Mythos Could Affect Healthcare Cybersecurity
- OWASP GenAI Exploit Round-up Report Q1 2026
- 94.4% of AI Agents Remain Vulnerable to Prompt Injection in 2026 Audit
- Major AI vendors publish 2026 prompt injection disclosures with inconsistent metrics
- Cybersecurity Briefing: AI-Driven Threats and Data Exposure for Small Businesses
- Prompt Injection is Becoming a Major Security Threat
- NewCore Launches with $66M to Secure Enterprise AI Agents via Authentication and Governance
- AI: The Cybersecurity Crisis That Vendors Love
- AI agent and LLM misuse drives new attack and governance risks
- State of Health AI 2026
- AI-Powered Supply Chain Attacks: What SMBs Need to Know
- AI, Data Theft & The 57% Rise in SMB Cyber Crime | Microsoft Security Explained
- AI is reviving tech sectors that VCs had all but forgotten
- SMBs in the Age of AI: Navigating Cyber Complexity and Risk
- Prompt Steel: Russia-linked threat group uses LLM-powered tool to automate data theft
- AI Security Issues SMBs Need to Solve Before Rolling Out Tools Like ChatGPT
- How Microsoft Is Building Trusted & Secure AI for Healthcare
- CVE-2025-32711 EchoLeak and Large-Scale AI Agent Exploits Presented at Black Hat USA 2025
- Sage-Commissioned IDC Study: SMBs Adopt AI Faster Than They Secure It
- On the Effectiveness of Mutational Grammar Fuzzing
- CNCERT Warning: OpenClaw AI Agents Exposed to Indirect Prompt Injection and Data Leak Risk
- AI-Driven Cyber Attacks: What SMBs Must Do to Defend in 2026
- The Rise of AI in IT Operations: What SMBs Need to Prepare For
- Twin cybersecurity incidents leave AI industry shaken
- Netskope–Imprivata integration aims to protect patient data across cloud, web, AI, and private apps
- AI Cybersecurity Threats for SMBs 2026
- A Deep Dive into the GetProcessHandleFromHwnd API
- Cyber Security Climbs the SMB Agenda as AI Pressure Exposes Resilience Gaps
- Cybersecurity for Small Businesses: Affordable AI-Powered Protection
- AI Agents Vulnerable to Prompt Injection Attacks
- Don't miss the 19 FinTech deals of the week - Nearly $500m raised by the sector
- Bypassing Administrator Protection by Abusing UI Access
- Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529
- AI & Cyber Readiness for SMBs: What You Need to Know
- How AI Can Protect Healthcare SMBs from Cyber Threats
- Bypassing Windows Administrator Protection
- 8 AI Cybersecurity Companies for 2026
- Prompt Injection Attack Explained: AI Cybersecurity Threat
- Small and Medium Business Cyberattacks and the AI Security Gap
- A 0-click exploit chain for the Pixel 9 Part 3: Where do we go from here?
- A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave
- A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby
- SaaS Security Industry News and Updates
- Unveiling AI Agent Vulnerabilities Part III: Data Exfiltration
- 2025 State Small Business Survey: Surge in AI ...
- Welcome to the new Project Zero Blog
- Cyber Readiness for SMBs: Getting the Basics Right in the Age of AI
- Prompt injection: types, real-world CVEs, and enterprise defenses
- AI Agent Security: Prompt Injection, Data Leakage, and the OWASP LLM Top 10
- Artificial Intelligence for Small Business: Cyber Security Guidance
- Bridging the SaaS Security Gap in Healthcare Organizations
- ForcedLeak and the Future of AI Agent Security
- AI Agents Can Leak Company Data Through Simple Web Pages
- EchoLeak: A Real-World Zero-Click Prompt Injection Vulnerability in Microsoft 365 Copilot
- Indirect Prompt Injection & Data Leakage: AI Hacking Explained
- Model Namespace Reuse: An AI Supply-Chain Attack Exploiting Major Cloud Platforms
- Prompt Injection: An Analysis of Recent LLM Security Incidents
- Zenity Labs Finds Leading AI Agents Highly Vulnerable to Hijacking Attacks
- MediTrust Health Breach Exposes 2.1 Million Patient Records via Third‑Party AI-Linked Scheduling API
- MediTrust Health breach exposes 2.1 million patient records via third-party scheduling API
- From Prompt Injections to Protocol Exploits: Threats in LLM ...
- OpenAI Security Incident Involving Compromised Employee Accounts and Limited Code Exposure
- Top 10 Security Concerns for AI-Powered Startups
- Indirect Prompt Injection Attacks: Hidden AI Risks
- SMB survival requires cybersecurity transformation with AI
- Simple Prompt Injection Attacks Can Leak Personal Data
- Securing AI Agents: How to Prevent Hidden Prompt Injection Attacks
- Ten New AI Security Vendors
- Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild
- Data, Health, Security And Defense Startups Among The New Unicorns In April 2025
- Anthropic Publishes Red-Teaming Findings on Tool-Using AI Agents and Supply Chain Abuse
- What Is a Prompt Injection Attack?
- Why 94% of AI Agents Are Vulnerable to Prompt Injection — And What To Do About It
- NCSC and ENISA Publish Joint Guidance on Securing AI Supply Chains for European SMEs and SaaS Providers
- Prompt Injection Is the #1 OWASP Risk for LLM Applications
- The Trust Factor in AI Adoption for SMBs | AI Security Guide (Podcast)
- Security Risks in Shadow AI Use Inside Hospitals
- Microsoft Warns of Nation-State Prompt Injection Campaigns Targeting AI Assistants and Copilots
- 'Best SaaS Product for Cybersecurity' Award Criteria
- US HHS Cybersecurity Center Warns of AI-Enabled Data Leakage and Prompt Injection in Healthcare
- LLM01:2025 Prompt Injection – OWASP GenAI Security Project
- Prompt Injection and Data Exfiltration Risks in Google Drive via Gemini AI Integrations
- HiddenLayer Identifies New Attack Technique for Stealing LLM Fine-Tuning Data from SaaS Integrations
- Prompt Injection Attacks: The Most Common AI Exploit in 2025
- NIST Technical Blog on Strengthening AI Agent Hijacking Evaluations
- Lasso Security Uncovers Critical Vulnerabilities in Hugging Face Repositories Exposing Sensitive AI Assets
- From Prompt Injections to Protocol Exploits: Threats in LLM-Powered Systems
- Prompt Injection
- New Pax8 Research Reveals Small Businesses Are Adopting AI Faster Than They’re Building Strategies to Manage It
- Nation-State Exploitation of Credentials in AI-Driven Healthcare and Cloud Environments
- Google Cloud: Mitigating Prompt Injection Attacks in Generative AI Applications
- Healthcare investors focus on AI privacy and security startups as generative AI adoption accelerates in medicine
- Security for AI: GenAI Risks and the Emerging Startup Landscape
- UK NCSC warns that generative AI will “almost certainly” increase cyber threats to all organizations
- OpenAI confirms denial-of-service attack that disrupted ChatGPT and API availability
- OWASP publishes updated Top 10 for Large Language Model Applications outlining prompt injection and data leakage risks
- Black Hat demo highlights indirect prompt injection attacks against ChatGPT-style systems
- Mithril Security demonstrates model supply-chain attack by poisoning open-source GPT-J-6B on Hugging Face
- NIST releases AI Risk Management Framework to guide secure and trustworthy AI deployments
- Prompt Injection – The critical vulnerability lurking beneath the AI hype
