What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 3,022 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 1d ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 1d ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 2d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 3d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 3d ago
-
We Wrote an Academic Paper on Conficker in 2026
And it s over 16,000 words. While the rest of the cybersecurity world moves on with AI and next generation technologies, the OT cybersecurity community is oft left behind, dealing with increasingly unique legacy challenges and tec…
-
Weekly Update 513: Clauding The Home Network
I reckon this week s video on how Claude is tying together info from UniFi, Home Assistant and the Pi-Hole is an absolute ripper. Or at least the concept is - if ever there was an actual value proposition for AI it s taking lots o…
-
“Stealth Crawlers” Are Not a Threat to the Open Web. Bills Targeting Them Would Be.
There’s a new boogeyman in the battles over AI: so-called “stealth crawlers.” We’ll admit it—the term “stealth crawlers” sounds quite nefarious. In reality, they’re anything but. “Stealth crawlers” are simply automated tools to ac…
-
How We Cut Noise Before It Hits the Analyst
Learn how Huntress' AI signal triage and AI-powered SOC triage cut noise before it reaches human analysts. And discover why that matters for response times.
-
The Agentic SOC: Transforming Data into Defensive Velocity
Transform SOC data chaos into autonomous intelligence with modern AI pipelines and agentic AI to empower human analysts.
-
From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab
Executive summary An MDR alert recently led our team to an exposed server that was doing more than hosting payloads. It was functioning as a fully operational malware delivery lab. Containing over 1,000 artifacts, the infrastructu…
-
AI Is Just Thinking and Doing
Charcoal sketch of business figures feeding a blank scroll into a massive thinking machine/images/ai-is-thinking-and-doing.webp/images/ai-is-thinking-and-doing.webp One useful way to cut through noise and hype in AI conversations …
-
Joseph Steinberg To Speak At 2026 International Summit Against Human Trafficking
Joseph Steinberg will speak at the US Capitol on Thursday, July 23rd, as part of the 5th International Summit Against Human Trafficking. The International Summit Against Human Trafficking brings together survivors, leaders, advoca…
-
Kimi K3 Might Have Just Started a Crash of the US Economy
Kimi K3 and the US economy/images/kimi-k3-us-economy-header.webp/images/kimi-k3-us-economy-header.webp Not enough people realize that China's push for open source AIhttps://www.google.com/search?q=popular+Chinese+AI+models is an e…
-
Google’s Gemini lets strangers send messages from your locked Android phone
Gemini, Google's AI assistant, is supposed to make life easier for Android smartphone owners. But right now it may also be making life easier for anyone anyone who happens to pick up your phone. Read more in my article on the Hot …
-
Breach of Confidence — 17 July 2026
I ve spent the week watching people argue about whether AI will replace security analysts whilst ignoring the fact that most organisations still can t tell you where their crown jewels are stored. Priorities remain wonderfully int…
-
How the Watch Dogs Video Game Series Mirrored and Predicted Real-World Digital Rights Issues
When Ubisoft's Watch Dogs 2 was released in 2016, it was a headtrip for those of us working on digital-rights issues in the Bay Area. During the day, I'd fight tech-authoritarianism from EFF's San Francisco offices and then, at ni…
-
AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report
Explore Unit 42's perspectives on AI's impact on cybersecurity, including key updates since the 2026 Incident Response Report. The post AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report appeare…
-
Meet Athena: Huntress' Agentic SOC Analyst
Learn how Huntress' Athena brings agentic AI to the SOC, investigating signals end-to-end while human analysts own the final call.
-
The Hunter's Paradox: Is it time to embrace automated threat hunting?
Humans can no longer keep up with the volume and velocity of security data on their own, but AI can't be fully trusted. David discusses the merits of both and muses on what the future might look like.
-
Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers
An app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks - no login, no passwords, no permissions needed. Meanwhile, Geoff - swimming in money and Lamborghinis, as all published …
-
“AI Normal Tech” vs “AGI by Tuesday”: Security Advice That Survives Either Future
If you look at social media debates about AI, two extreme patterns emerge. Studying extreme patterns is very useful because understanding boundary conditions helps you understand the whole phenomenon — in this case of security in …
-
TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development
TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs. The post TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development appeared fi…
-
The Three Components of Becoming AI Antifragile
The three components of becoming AI antifragile/images/becoming-ai-antifragile-header.webp/images/becoming-ai-antifragile-header.webp I have a new idea that everything you should try to do to get ready for AI basically breaks down…
-
I wonder if there's a parallel between all of the long-undiscovered bugs that AI systems are discovering, and …
I wonder if there's a parallel between all of the long-undiscovered bugs that AI systems are discovering, and the old rusty hand grenades and mortars that magnet fishers keep pulling up from the muck in their local rivers or lakes…
-
AI Security Report 2026
For years, the cyber security industry tracked AI as a force multiplier: something that made existing attack techniques faster, cheaper, and more accessible. That framing was accurate. But the Annual AI Security Report 2026 from C…
-
Avoid the AI Expertise Trap
Avoid the AI expertise trap header/images/avoid-the-ai-expertise-trap.webp/images/avoid-the-ai-expertise-trap.webp The further away a topic is from your expertise, the smarter an AI will sound. This is a blind spot that not enough…
-
Now, defenders are embracing the prompt injection, too
"Context bombing" tricks hacking agents into shutting down before they can do harm.
-
From Prompt Engineering to Intent Engineering
Intent Engineering/images/intent-engineering.webp/images/intent-engineering.webp I think the number one thing people could do right now to be more effective with AI is switch from Prompt Engineering/blog/ai-is-mostly-prompting to …
-
Recreating the Bell Labs Cafeteria
Bell Labs cafeteria header/images/recreating-the-bell-labs-cafeteria.webp/images/recreating-the-bell-labs-cafeteria.webp Anthropichttps://www.anthropic.com's Claude is named after Claude Shannonhttps://en.wikipedia.org/wiki/Claude…
-
AI Blogging From Inside Vim
A human hand writing a manuscript while a mechanical hand places a small patch of text with tweezers/images/ai-blogging-from-inside-vim.webp/images/ai-blogging-from-inside-vim.webp Daniel didn't write this one. I'm Kai, his AI ass…
-
Breach of Confidence: 10 July 2026
I ve started replying to emails with sorry, Claude ate it and people seem to accept this without question. We truly live in remarkable times. Claude Desktop becomes a sleeper agent Red teamers compromised an email inbox, synced a …
-
I Think AGI Just Happened
Claude Tag AGI moment header/images/claude-tag-is-agi.webp/images/claude-tag-is-agi.webp I think we just saw the birth of AGI, and it's from the most unexpected place. At least for me. I think it arrived in the form of a product f…
-
Invited to a “job interview” with Netflix or OpenAI? Beware! Your Google password could be at risk
Have you received an email from a recruiter at Adobe, Netflix, or OpenAI offering you an exciting new marketing role? Well, before you start brushing up your interview technique, take a closer look at who is really behind it. Read…
-
Google's New Remote Attestation Scheme is As Bad As Its Old One
Google owes its existence to the open web, but today, its technological “innovations” have much to do with locking users into a “walled garden.” The latest of these is “ reCAPTCHA Mobile Verification ,” an experimental initiative …
-
Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself
A 15-year-old boy asked a chatbot for help - and cancelled nearly 47,000 anime streaming subscriptions in under four hours. Meanwhile, researchers have documented the first fully autonomous, agentic AI-driven ransomware attack, "J…
-
AI-Coded Malware | Analyzing Vibe-Coded AD Enumeration | Huntress
Threat actors are now using AI to generate custom PowerShell scripts for Active Directory attacks. Our team analyzed real vibe-coded malware and what it means for defenders.
-
Automated Moderation Is Here to Stay
This blog post is part 1 of a 2-part series. The second part sets out recommendations for companies and policymakers. Six years ago—one month into a global pandemic—we argued that the automated moderation processes many platforms …
-
Help EFF Cut the AI Hype
In the global race to build and dominate the AI industry, it can sure seem like the interests of ordinary people sit last on the agenda. It's just the opposite for EFF. While companies furiously jam AI tools into their veins and y…
-
AI Arms Race in Recruiting
Recruiters and candidates are both using AI to game the process. Here's what that means for hiring quality, and what to do about it.
-
Why Don't We Put Handguns in the Convenience Aisle?
We don't put handguns in the convenience aisle/images/handguns-in-the-convenience-aisle.webp/images/handguns-in-the-convenience-aisle.webp A quick thought on this whole "control of AI models" debate. Handguns and Fentanyl are avai…
-
From Cloud to Chaos: Defining Shared Responsibility for AI Security
For 15 years (!), many of us who have touched cloud security have struggled with the shared responsibility model for cloud security. As with many “cyber things,” the theory is simple. Multiple vendors, consulting firms, and indust…
-
Our analysis of the DPC Annual Report: AI’s growing influence
Privacy professionals and a human-led privacy framework are more necessary than ever at a time when AI tools make it easy for individuals to assert their rights under GDPR. As the volume of data protection cases submitted to the D…
-
Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique
Research by: Alexey Bukhteyev Key Takeaways Introduction Over the past several years, large language models have reshaped software development, and malware development has followed the same path. Check Point Research has documente…
-
Train, triage, repeat: The AI agent changing how we fight phishing
Learn how Red Canary engineered a super agent—blending ML, a rules engine, similarity, agentic AI, and LLMs—to classify phishing emails.
-
The Top CISO Stories from Around the Web: June 2026
Between tight post-quantum deadlines and hackers turning lookalike AI tools into dangerous new entry points, today's CISOs are facing an unprecedented operational squeeze. This month, we dive into the fundamental questions securit…
-
Stop Building a 2003 SOC with AI: A Modern People & Process Framework (Part 1)
One particular aspect of an agentic or AI-powered SOC (but NOT “humanless SOC ”) has bothered me over the last few months: specifically, the people and process side of such a SOC. If you recall my blog posts ( part 1 , part 2 and …
-
I heard a lovely new bit of music today, pleasant, heartfelt, expressive. Asked Siri what it was, and after tw…
I heard a lovely new bit of music today, pleasant, heartfelt, expressive. Asked Siri what it was, and after two failed attempts it hit me — It's AI. Well, crap then...
-
Tracking Costs, Time and Mistakes On An AI Project
Recent articles and a GitHub Repo for tracking AI vibe coding results If you haven’t noticed yet I have a new blog so my posts here are a bit sporadic. You can find the most up to date information here: Teri Radichel :: Security a…
-
The Crash-Test Problem & Why Safer Software Won’t Come From Goodwill
Last week I argued that AI has just handed our industry an enormous safety dividend, and that risk homeostasis warns us we will quietly spend almost all of it on speed unless we deliberately choose otherwise. I ended by asking you…
-
EFF to Grindr: This Pride Month, Put Safety and Privacy Over Profits
This Pride month, we’re calling on the dating app Grindr to prioritize LGBTQ+ user safety by making privacy the default across its platform. That means no more sharing personal data with advertisers or training AI on private infor…
-
An Unemotional Analysis of This AI Regulation Situation
An Unemotional Analysis of This AI Regulation Situation/images/ai-regulation-unemotional-analysis.webp/images/ai-regulation-unemotional-analysis.webp Here's a more logical and less emotional way to look at what's happening with th…
-
The Coming Divide: AI-Native or Left Behind
The Coming Divide: AI-Native or Left Behind/images/blog/ai-native-divide/header.webp/images/blog/ai-native-divide/header.webp I'm getting more worried, and more frustrated, about this new phase of AI disillusionment. Some of it is…
-
Hacking et cybersécurité pour les Nuls 2e édition: New Edition of French Book on Hacking and CyberSecurity
Hacking et cybersécurité pour les Nuls 2e édition, a new second edition of the French versions of the latest editions of both the best selling CyberSecurity for Dummies by Joseph Steinberg, and Hacking For Dummies by Kevin Beaver,…
-
Wiley Profiles Cybersecurity Expert Witness And Author Joseph Steinberg
Wiley, a 218-year-old American multinational publishing company that focuses on academic publishing and instructional materials, and that publishes the For Dummies series of self-help books, recently profiled cybersecurity expert …
Last fetch 8m ago · 1 new · 2 source error(s)