What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,949 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 2h ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 13h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 2d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
-
Nvidia’s $12.9B Hugging Face deal could benefit enterprises
The chipmaker s acquisition could eventually bring additional security resources and model evaluation tools to the platform, according to experts.
-
PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (C…
-
Early Bird Registration For Black Hat Europe 2026 In London
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 4, 2026 Black Hat Europe returns to the Excel in London with a four-day program, Dec. 7-10. The event will open with two-and four-day opti…
-
AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?
A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks.
-
Insurers Search for Answers to Rein in Rogue AI
As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout.
-
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
Overview A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor…
-
Security Vulnerability in a Voting System
It s a vulnerability that allows someone to recover the order of ballots cast, newly exploited with AI tools. Nearly four years since the original vulnerability was disclosed, I was still able to use it to analyze voter behavior i…
-
AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks
We cannot forget that AI coding agents are not yet trustworthy : Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt an…
-
ICE Wants to Know Everyone Who Bought a Certain Green Beanie From REI in the Last 2 Years
Homeland Security Investigations agents hit the outdoor retailer with a controversial subpoena as part of a dragnet search for the identities of protesters who entered a Minnesota church in March.
-
Angry Birds: Toy Ghouls’ new toys
Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the other uses the Matrix-based Element messenger.
-
August newsletter is out
The August edition of my sponsors-only monthly newsletter is out. If you are a sponsor (or if you start a sponsorship now) you can access it here . This month: We got more details on OpenAl's accidental cyberattacks One-shotting R…
-
Peak Human Readership
A lone writer in warm sienna works at a desk on top of a purple machine that crushes his pages into tiny slips for a crowd below staring at their phones, while one person in sienna stands apart reading a full page/images/peak-huma…
-
Lenovo A/NZ’s Pam Caldwell closes chapter with vendor
Lenovo Australia and New Zealand (A/NZ) head of sales operations Pam Caldwell has announced that she is “closing an incredible chapter” with the global technology vendor. In a post on LinkedIn, Caldwell wrote that “coming back to …
-
REANNZ appoints Jane McGale as first CTO and Dougal Macdiarmid as partnerships director
REANNZ has filled two newly created executive roles with appointments from the private sector as it seeks to boost access to its services and build a more scalable model for growth. The organisation, which operates the country’s n…
-
Lumify bolsters leadership team with new CEO, COOs
Corporate IT and process training organisation Lumify Group has shaken up its executive team with a new CEO in the form of Darren Cook as well as two chief operating officers (COO). Joining Cook’s appointment is Ayisha Tufail, who…
-
ConnectWise rebuilds trust to ready A/NZ partners for the future
ConnectWise has worked towards building trust after it was attacked by what it believed to be a nation state actor, with CEO Manny Rivelo noting transparency was vital after the fact. Last year, ConnectWise flagged that it noticed…
-
CVE-2026-85046: Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chro…
-
Nobody Is Saying Why OpenAI and Anthropic Had Outages Today
ChatGPT, Claude, and Grok all suffered outages at nearly the exact same time for reasons that remain murky.
-
Prediction Market Betting Is Getting People Banned and Arrested
This week on Uncanny Valley, we dig into the latest prediction market buzz, Flock’s AI-powered police search tool, and how tech bros don’t know how to talk about “rouge” AI agents
-
Managed EDR: What It Is & How to Choose a Provider
Huntress breaks down what managed EDR is, how it differs from unmanaged, and what to look for when choosing a provider for your business.
-
What Nvidia’s US$13B acquisition of Hugging Face means for AI model choice
When Nvidia said last week that it plans to pay $13 billion to acquire Hugging Face, the question arose of whether the open AI platform would remain open when it becomes a unit of Nvidia. And the current lack of a single viable op…
-
GPT‑6 Astra
GPT‑6 Astra GPT-6 Astra is "rolling out today to a limited set of organizations and over the coming days will become available to all ChatGPT Plus, Pro, Business, and Enterprise users, as well as through the OpenAI API and AWS" - …
-
Large Enterprises Targeted in Fake Merger & Acquisition Scams
Threat actors behind the Phantom Deal campaign are studying companies in extreme detail, aiming to dupe midlevel employees into initiating large financial transfers.
-
Confused about which VPN is right, US senator asks the NSA for guidance
Open source, commercial, single-hop, multi-hop, mixnet? The array of options is dizzying.
-
What We Missed: Did ShinyHunters 'Breach' ReliaQuest?
In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the latest antics of ShinyHunters to new research about the prevalence (or lack thereof) of AI-generated malware.
-
Court Rules Against Citizen Journalists in DMCA Takedown Case—EFF Will Appeal
A federal court in Massachusetts has ruled that copyright holders can issue online takedown notices based on a subjective belief of copyright infringement, even when that belief is unreasonable and self-serving. The case was broug…
-
The story behind the intelligence
From engaging with cybercriminals to surviving a live Flamin’ Hot Cheetos taste test, Hazel reflects on the latest Beers with Talos with Azim, where they cover the full spectrum of what it takes to gather threat intel.
-
What the AI Warning Letter Completely Missed
The recent open letter is right about the window, but it omits naming who is coming through it or, critically, who will close it.
-
ASCII smuggling crosses over from AI prompt injection to phishing evasion
Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them. The post ASCII smuggling crosses over from AI prompt injection to phishing evas…
-
ASCII smuggling crosses over from AI prompt injection to phishing evasion
Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them. The post ASCII smuggling crosses over from AI prompt injection to phishing evas…
-
Security Roundup August 2026
Curated advice, guidance, learning and trends in cybersecurity and privacy, as chosen by our consultants. Sound the AI-larm This summer, thermometers weren’t the only thing soaring: levels of hype and fearmongering around AI and c…
-
AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours
The incident demonstrates how frontier AI agents can dramatically compress an attack timeline and coordinate a large-scale breach, according to researchers.
-
Irish Privacy Watchdog Details Psychiatric Data Breaches
In a new article published on Data Breach Today, BH Consulting CEO Brian Honan discusses the enduring risks associated with paper records following serious data breaches involving psychiatric files stored at disused HSE facilities…
-
Shadow AI in Financial Services | Risk & Governance
Shadow AI is spreading faster than governance in financial services. See the risks, why blocking AI backfires, and how to build policies that work.
-
In today's Breach Please, me and @ Secitup talk about the suspected data breach of a major identity verificati…
In today's Breach Please, me and @ Secitup talk about the suspected data breach of a major identity verification vendor. Then we opine on what third party risk management might have done (or not done) to stop this incident from im…
-
Exaforce: SOC Platform Built For AI From The Ground Up
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 3, 2026 – Watch the YouTube video Exaforce is trusted by next-gen startups to Fortune 500 and Global 2000 companies. Cybercrime Magazine m…
-
'Breeze Comet' Tears Into Brazilian & Global Financial Systems
Brazil's most sophisticated threat group is making light work of the country's financial systems, putting money directly into its own pocket.
-
Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations. The post Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin …
-
This Is Flock’s AI Search Tool for Cops
WIRED rebuilt Flock’s latest search tool from code the company sends to a police officer’s browser. Its AI can keep watch across multiple cameras for anyone fitting a written description.
-
Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity
Huntress is tracking a pattern across multiple customer environments where rogue ScreenConnect clients repeatedly spawn the Windows Script Host to execute a series of four VBScript files.
-
TrendAI’s Richard Harrison brings a practitioner’s perspective to a global vendor
For Richard Harrison, making the move from working on the frontlines of cyber security as a chief information security officer (CISO) to working for a global vendor happened organically, rather than by design. Harrison joined Tren…
-
Smashing Security podcast #483: This AI helps thieves steal your iPhone
You've had your iPhone stolen. A day later, you get a text from Apple saying they've found it, and a very helpful woman called Alice from Apple Support calls to walk you through recovering it. She's polite. She's professional. But…
-
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers m…
-
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers m…
-
AI's Vulnerability Surge May Be More Manageable Than First Feared
New research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have the right strategies.
-
I'm late posting, but today's Breach Please is out. Me and @ Secitup talk about an Exchange vulnerability that…
I'm late posting, but today's Breach Please is out. Me and @ Secitup talk about an Exchange vulnerability that wasn't rated critical based on CVSS, but is critical to patch. We both think it will be in the KEV by Monday if not bef…
-
SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE
The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.
-
I rented a car, and within hours, my driver's license was for sale
The FBI is reportedly investigating a massive data breach that is unfolding in real time.
-
llm-openrouter 0.7.1
Release: llm-openrouter 0.7.1 Performance fix for loading OpenRouter models. Thanks, waveplate . #59 Tags: llm , openrouter
-
AI Gives Cybercriminals a Dangerous Time Advantage
Former cybercriminal Brett Johnson provides a look inside the mind of a threat actor and discusses where AI provides the most value for attackers.
Last fetch 14m ago · 1 new · 2 source error(s)