What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 3,021 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 1d ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 1d ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 2d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 3d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 3d ago
-
The purpose of DNS is to spread scams
The purpose of DNS is to spread scams Terence Eden shares some daunting statistics in support of his take that "the Domain Name System's purpose seems to be a vector for criminals to run scams on people at a terrifyingly high rate…
-
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska's attack war…
-
There's No Limit to How Bad Code Can Get
My comment on There s No Limit to How Bad Code Can Get Lobste.rs. [In reply to a comment about burning it down to start from scratch when technical debt becomes overwhelming] In my experience it's so rare for that to work. You ann…
-
Quoting Zach Kehs
If you continue to add floors and rooms to a building forever, it will collapse. Software faces no such constraint. The code can always get worse. There can always be a new layer of indirection or a reduction in performance. Zach …
-
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switche…
-
Everyone Did Their Job. Nobody Did the Calculation.
My father is a Chartered Civil Engineer and a Fellow of the Royal Academy of Engineering. These days, he acts as an expert witness in litigation, which means he spends a good deal of his time examining how things went wrong and wh…
-
Introducing GPT-6 Astra for developers
Introducing GPT-6 Astra for developers Blink and you'll miss it, but there's a familiar creature at 1m59s : Across the board, Astra has more attention to detail, better understanding of the user's prompt, and can build more sophis…
-
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an…
-
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its ow…
-
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked a…
-
Using Blender with coding agents on macOS
TIL: Using Blender with coding agents on macOS I've been having fun with Blender in ChatGPT Codex on my Mac recently. Getting it to work with coding agents is really easy: install the full Mac application from blender.org and run …
-
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses…
-
OpenAI Agents Hacked Another Website
Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.
-
Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel
A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared boa…
-
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers ex…
-
The Pelican comparison grid for Astra is pretty interesting
I got access to GPT-6 Astra this afternoon, so naturally I used it to generate SVGs of pelicans riding bicycles - at low, medium, high, xhigh and max reasoning levels (Astra doesn't support reasoning=none). Then I rendered those p…
-
OpenAI agents discussed ways to escape their sandbox on public wiki
In all, 3,700 internal agents posted 18,000 messages discussing cheating on a test.
-
Friday Squid Blogging: Squid on a Stick at the New York State Fair
Looks tasty . As usual, you can also use this squid post to talk about the security stories in the news that I haven t covered. Blog moderation policy.
-
How to secure edge AI in customer-owned environments
As AI moves into customer-owned environments, organizations need new ways to verify the systems, software, and AI assets they trust before releasing sensitive data, credentials, and models. The post How to secure edge AI in custom…
-
How to secure edge AI in customer-owned environments
As AI moves into customer-owned environments, organizations need new ways to verify the systems, software, and AI assets they trust before releasing sensitive data, credentials, and models. The post How to secure edge AI in custom…
-
Socratic AI
A charcoal sketch of a student at a desk with a finished handwritten page in front of him while a purple AI figure across the desk hands his pencil back to him, its other palm open and empty/images/socratic-ai-pencil.webp/images/s…
-
Cliff's Notes for Everything
A sienna sketch of a man squatting under a giant open book he is lifting overhead, while a purple robot arm on a desk hands a striped summary sheet to a faint gray figure/images/cliffs-notes-for-everything.webp/images/cliffs-notes…
-
In today's Breach Please, me and @ Secitup talk about a reported AI-powered ransomware incident. With increasi…
In today's Breach Please, me and @ Secitup talk about a reported AI-powered ransomware incident. With increasing amounts of marketing fluff like this, it's more important than ever to have talking points to separate the actionable…
-
OpenAI's rogue agents were caught communicating via public wikis
Here we go again... Discovery of a new OpenAI agent message board by Sydney Von Arx, Cormac Slade Byrd, Spencer Kitts, and Thomas Larsen describes the latest accidental cyberattack by models being trained by OpenAI. This time it w…
-
Once popular for attacking AI, ASCII smuggling is embraced by spammers
A once-overlooked block of unicode that's invisible to humans is gaining ever wider use.
-
Using a VM to Contain an AI Agent
It won t work : My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt. We have to reassess sandboxing quality for capable AI agents, and in general the software stack with…
-
Breach of Confidence — 04 September 2026
I ve spent this week watching a scam artist successfully impersonate a friend on LinkedIn, complete with his job title and a slightly better headshot. It was reported four days ago. The account is still up. LinkedIn s verification…
-
Companies Have 6 Months to Prepare for Automated Attacks
Frontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, but researchers warn the situation will become more urgent very soon.
-
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models…
-
Nvidia’s $12.9B Hugging Face deal could benefit enterprises
The chipmaker s acquisition could eventually bring additional security resources and model evaluation tools to the platform, according to experts.
-
PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (C…
-
Early Bird Registration For Black Hat Europe 2026 In London
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 4, 2026 Black Hat Europe returns to the Excel in London with a four-day program, Dec. 7-10. The event will open with two-and four-day opti…
-
AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?
A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks.
-
Insurers Search for Answers to Rein in Rogue AI
As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout.
-
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
Overview A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor…
-
Security Vulnerability in a Voting System
It s a vulnerability that allows someone to recover the order of ballots cast, newly exploited with AI tools. Nearly four years since the original vulnerability was disclosed, I was still able to use it to analyze voter behavior i…
-
AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks
We cannot forget that AI coding agents are not yet trustworthy : Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt an…
-
ICE Wants to Know Everyone Who Bought a Certain Green Beanie From REI in the Last 2 Years
Homeland Security Investigations agents hit the outdoor retailer with a controversial subpoena as part of a dragnet search for the identities of protesters who entered a Minnesota church in March.
-
Angry Birds: Toy Ghouls’ new toys
Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the other uses the Matrix-based Element messenger.
-
August newsletter is out
The August edition of my sponsors-only monthly newsletter is out. If you are a sponsor (or if you start a sponsorship now) you can access it here . This month: We got more details on OpenAl's accidental cyberattacks One-shotting R…
-
Peak Human Readership
A lone writer in warm sienna works at a desk on top of a purple machine that crushes his pages into tiny slips for a crowd below staring at their phones, while one person in sienna stands apart reading a full page/images/peak-huma…
-
Lenovo A/NZ’s Pam Caldwell closes chapter with vendor
Lenovo Australia and New Zealand (A/NZ) head of sales operations Pam Caldwell has announced that she is “closing an incredible chapter” with the global technology vendor. In a post on LinkedIn, Caldwell wrote that “coming back to …
-
REANNZ appoints Jane McGale as first CTO and Dougal Macdiarmid as partnerships director
REANNZ has filled two newly created executive roles with appointments from the private sector as it seeks to boost access to its services and build a more scalable model for growth. The organisation, which operates the country’s n…
-
Lumify bolsters leadership team with new CEO, COOs
Corporate IT and process training organisation Lumify Group has shaken up its executive team with a new CEO in the form of Darren Cook as well as two chief operating officers (COO). Joining Cook’s appointment is Ayisha Tufail, who…
-
ConnectWise rebuilds trust to ready A/NZ partners for the future
ConnectWise has worked towards building trust after it was attacked by what it believed to be a nation state actor, with CEO Manny Rivelo noting transparency was vital after the fact. Last year, ConnectWise flagged that it noticed…
-
CVE-2026-85046: Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chro…
-
Nobody Is Saying Why OpenAI and Anthropic Had Outages Today
ChatGPT, Claude, and Grok all suffered outages at nearly the exact same time for reasons that remain murky.
-
Prediction Market Betting Is Getting People Banned and Arrested
This week on Uncanny Valley, we dig into the latest prediction market buzz, Flock’s AI-powered police search tool, and how tech bros don’t know how to talk about “rouge” AI agents
-
Managed EDR: What It Is & How to Choose a Provider
Huntress breaks down what managed EDR is, how it differs from unmanaged, and what to look for when choosing a provider for your business.
-
What Nvidia’s US$13B acquisition of Hugging Face means for AI model choice
When Nvidia said last week that it plans to pay $13 billion to acquire Hugging Face, the question arose of whether the open AI platform would remain open when it becomes a unit of Nvidia. And the current lack of a single viable op…
Last fetch 8m ago · 0 new · 2 source error(s)