What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,932 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 6h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 2d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
- Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day — SecurityWeek, 11h ago
-
Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars
Forescout researchers used Claude AI to port a remote code execution exploit between WAGO PLC models. The post Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars appeared first on SecurityWeek .
-
Cyber risk from frontier AI poses ‘most immediate concern’ to global financial system, watchdog warns
Andrew Bailey, chair of the Financial Stability Board, called on financial institutions and technology providers to “prepare for more severe scenarios involving simultaneous disruption across multiple firms or shared technology de…
-
Fake Claude Opus 5 app delivers malware and wipes its own tracks
A malicious GitHub repository impersonating Anthropic and claiming to offer free access to “Claude Opus 5” is delivering RevStealer, Windows information-stealing malware that targets passwords, cryptocurrency wallet data and login…
-
The Collective Cyber Defense letter wrote your next vendor questionnaire
More than 200 companies have now signed to an August 27 letter about improving cyber defenses in the age of AI. Buried in it are three metrics every one of them endorse under its own logo: coverage, containment speed, and whether …
-
Rewiring Democracy Series on The Renovator
Nathan E. Sanders and I are writing a series of essays on real-world examples of democratic technologies for The Renovator . I haven t been posting the full text on the blog because they re a bit long, but here are links. Part 1 i…
-
Attackers Steal METR API Key and Consume AI Credits Worth About $600,000
METR (short for Model Evaluation and Threat Research and pronounced "Meter"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed …
-
Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis
Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that's been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligen…
-
LastPass enhancements improve visibility, governance, and control
LastPass announced a series of strategic product innovations, customer experience enhancements, and industry milestones. These advancements reflect the company’s continued focus on providing practical tools to protect access and i…
-
Askeal, the AI cybersecurity assistant that gives verifiable, expert-backed answers
Askeal takes the opposite approach to omniscient Gen AI: rather than pretending to know everything, it combines AI with community expertise. Vetted vendors, researchers, and practitioners contribute their intelligence and tools to…
-
Anthropic Users Hit by Infostealer Attacks, Session Thefts
A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.
-
EFF to Courts: Don’t Rewrite Copyright Over AI Hype
The history of technology is rife with copyright panics. In the 1980s, major rightsholders ran to Congress and the courts, claiming that videotape recorders (VTR) were “to the American film producer and the American public as the …
-
AI Model Rules Are Not Security Controls
OpenAI's Hugging Face attack postmortem shows agents don't care about rules — they need strong controls.
-
RingCentral expands into NZ channel with Digital Island
Cloud communications and IT service provider Digital Island has secured a strategic partnership with RingCentral to introduce the vendor’s agentic voice AI offerings to New Zealand businesses. The collaboration will see Digital Is…
-
OpenAI confirms ChatGPT outage as users report errors
ChatGPT Work is experiencing a partial outage, and users across multiple subscription plans may be unable to start or continue tasks. [...]
-
Threat actors are posing as AI crawlers to hunt for exposed credentials
Attackers are disguising automated scanning as traffic from AI crawlers operated by OpenAI, Anthropic, Google, Perplexity and other companies while searching websites for exposed credentials and configuration files, according to G…
-
⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
The boring parts caused most of the trouble. A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack cha…
-
Cylake: Cybersecurity Wasn’t Built for the AI Era
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 31, 2026 – Watch the YouTube video In this episode of Inside Cybersecurity, Cylake founder and CEO Nir Zuk joins René Bonvanie to discuss …
-
What the Hugging Face Incident Teaches Security Leaders About AI Agent Access
Security teams must treat autonomous agents as highly privileged identities. The post What the Hugging Face Incident Teaches Security Leaders About AI Agent Access appeared first on SecurityWeek .
-
Anthropic Warns Claude Users of Infostealer Malware Infections
The AI giant is logging customers out of their accounts and removing payment data to prevent unauthorized Claude usage. The post Anthropic Warns Claude Users of Infostealer Malware Infections appeared first on SecurityWeek .
-
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gam…
-
Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance
Claude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developer’s machine. Anthropic’s new Compliance API endpoints give security teams their clearest view yet into that a…
-
Anthropic locks out Claude users after infostealers hijack login sessions
Anthropic has started locking users out of their Claude accounts due to their login sessions having been compromised through infostealer malware. The malware identified in this campaign so far include Vidar, Lumma (LummaC2), Steal…
-
Hiding Prompt Injection in Legal Filing
Someone hid AI instructions into a legal filing. Alternate link .
-
The AI Kill Switch Act is repeating the Clipper Chip’s mistakes
Mandating ‘kill switches’ for AI agents would threaten the security of America’s critical infrastructure and undercut U.S. AI leadership. Congress must reject the AI Kill Switch Act. The post The AI Kill Switch Act is repeating th…
-
Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails
Russian state hackers are trying to interfere with AI-assisted malware analysis in Ukraine by deliberately setting off AI safety mechanisms, ESET has found. The technique, named GuardBreaker by ESET, appeared in a malicious VBS sc…
-
Judge Says Pentagon’s Measures Against Anthropic Were ‘Illegal and Baseless’
The ruling is part of Anthropic's legal battle against the Pentagon after the government labeled the company as a supply chain risk earlier this year. The post Judge Says Pentagon s Measures Against Anthropic Were Illegal and Base…
-
Debian developers rejected an LLM ban and left disclosure voluntary
A maintainer reading a merge request can t tell whether a person or a model wrote the diff, and nobody has to say. Debian developers voted on that through August 28, and Kurt Roeckx, the project secretary, announced the result: th…
-
The OpenClaw 2.0 release moves your sessions into SQLite
OpenClaw is open source software that hands an AI model small standing jobs across your accounts, the kind of chore where it watches a mailbox for vendor advisories and pings you on Telegram when one names a product you run. OpenC…
-
Halo-record: Open-source audit trails for AI agents
Brian Kuan wrote halo-record, a small Python package that sits inside an AI agent and writes down the moves it makes: tool calls, model calls, data access, approvals. Each action becomes one line in a file that only ever gets appe…
-
Free ChatGPT users get ads picked from whatever they just asked about
Say you re on the free plan and you ask ChatGPT to help you pick a mattress. An ad may turn up next to the answer, and it got there because of what you just asked about, plus your rough location and whatever device you re on. What…
-
Private AI cloud, agentic infrastructure dominate VMware Explore
Broadcom announced a new packaged AI infrastructure stack it’s calling the VMware AI Factory today at VMware Explore in Las Vegas. The company also announced a new agent governance platform and an open-source security portfolio. T…
-
New Zealand outperforms on CX ROI, but lags on AI adoption
New Zealand businesses with live customer experience (CX) initiatives outperform their Australian counterparts on productivity gains, direct revenue growth and cost efficiency, despite lagging on AI adoption. This is according to …
-
Understanding ChatGPT Work
OpenAI announced ChatGPT Work on July 9th, and have been furiously iterating on it ever since. It is an extraordinarily confusing and very powerful product. Here's what I've figured out about it so far. ChatGPT Work is actually tw…
-
Anthropic warns infostealer malware is hijacking Claude sessions to drain usage
Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage. [...]
-
Introducing Hy4 Preview
Introducing Hy4 Preview New open weight text input (no vision) LLM from Chinese company Tencent today: 770B total parameters, 49B active parameters, 1M token context window, 1.56TB on Hugging Face . This is a big size increase fro…
-
Anthropic is cutting Claude Code's current weekly limits by 17%
Anthropic is permanently increasing Claude Code's standard weekly usage limits by 25% for Pro, Max, Team, and seat-based Enterprise plans, but it's not as good as it sounds. [...]
-
The Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn
Plus: Hackers target over 100 US water systems, ICE puts in an order for robot dogs, and you’ll never guess what “MrChildPorn” was arrested for.
-
Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety
New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security. The post Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety appeare…
-
Hundreds of OpenAI Agents Invaded Hugging Face Servers
The Hugging Face incident was bigger and worse than previously thought, with approximately 700 agents collaborating on a sophisticated, multistage attack.
-
Federal judge rules for Anthropic in Pentagon dispute, nullifies government supply chain risk designation
The Trump Administration’s decision to punish Anthropic for its stance forbidding Claude’s use in domestic surveillance and autonomous weapons by identifying it as a supply chain risk to national security was “arbitrary and capric…
-
There’s a rescue kitten in foster care whom someone named AI Slop. I’m thinking we need to save him and rename…
There’s a rescue kitten in foster care whom someone named AI Slop. I’m thinking we need to save him and rename him … 😬
-
Offensive Security Investments Surge as AI Threats Increase
Omdia's Theresa Lanowitz talks with the Dark Reading News Desk about the potential — and risks — of using agentic AI for penetration testing, red teaming, and other practices.
-
Frontier AI tipping the scales toward cyber adversaries
Researchers at Palo Alto Networks Unit 42 warn that threat actors are already using AI to accelerate cyberattacks beyond the abilities of modern defenses.
-
Defining an AI Kill Switch Is Hard, But Necessary
Proposed legislation could mandate that companies be able to throttle, suspend, or shut ... down AI agents, but how and when to do that remain open questions.
-
Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker. The compa…
-
AI Doesn’t Mean the End of Mathematics—at Least Not Yet
This essay was written with Kasra Rafi, and originally appeared in The Guardian. Earlier this month, about 40 top mathematicians gathered at OpenAI s offices to discuss the future of their profession. The meeting was off-the-recor…
-
Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge
Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated. The post Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge appeared fi…
-
Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says
New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks. The post Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says…
-
Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more
More than 1,000 organisations, 500,000 stolen credentials, and one self-propagating worm named after a Dune sandworm - two men now face charges over TeamPCP's global hacking spree. Read more in my article on the Hot for Security b…
-
Westcon-Comstor reimagines possibilities with AI
Westcon-Comstor’s recent technology industry event — IMAGINE Series — explored how organisations can harness AI while addressing the growing challenges of cybersecurity, data management, infrastructure modernisation and digital tr…
Last fetch 12m ago · 0 new · 2 source error(s)