What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 3,022 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 1d ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 1d ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 2d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 3d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 3d ago
-
What Nvidia’s US$13B acquisition of Hugging Face means for AI model choice
When Nvidia said last week that it plans to pay $13 billion to acquire Hugging Face, the question arose of whether the open AI platform would remain open when it becomes a unit of Nvidia. And the current lack of a single viable op…
-
GPT‑6 Astra
GPT‑6 Astra GPT-6 Astra is "rolling out today to a limited set of organizations and over the coming days will become available to all ChatGPT Plus, Pro, Business, and Enterprise users, as well as through the OpenAI API and AWS" - …
-
Large Enterprises Targeted in Fake Merger & Acquisition Scams
Threat actors behind the Phantom Deal campaign are studying companies in extreme detail, aiming to dupe midlevel employees into initiating large financial transfers.
-
Confused about which VPN is right, US senator asks the NSA for guidance
Open source, commercial, single-hop, multi-hop, mixnet? The array of options is dizzying.
-
What We Missed: Did ShinyHunters 'Breach' ReliaQuest?
In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the latest antics of ShinyHunters to new research about the prevalence (or lack thereof) of AI-generated malware.
-
Court Rules Against Citizen Journalists in DMCA Takedown Case—EFF Will Appeal
A federal court in Massachusetts has ruled that copyright holders can issue online takedown notices based on a subjective belief of copyright infringement, even when that belief is unreasonable and self-serving. The case was broug…
-
The story behind the intelligence
From engaging with cybercriminals to surviving a live Flamin’ Hot Cheetos taste test, Hazel reflects on the latest Beers with Talos with Azim, where they cover the full spectrum of what it takes to gather threat intel.
-
What the AI Warning Letter Completely Missed
The recent open letter is right about the window, but it omits naming who is coming through it or, critically, who will close it.
-
ASCII smuggling crosses over from AI prompt injection to phishing evasion
Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them. The post ASCII smuggling crosses over from AI prompt injection to phishing evas…
-
ASCII smuggling crosses over from AI prompt injection to phishing evasion
Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them. The post ASCII smuggling crosses over from AI prompt injection to phishing evas…
-
Security Roundup August 2026
Curated advice, guidance, learning and trends in cybersecurity and privacy, as chosen by our consultants. Sound the AI-larm This summer, thermometers weren’t the only thing soaring: levels of hype and fearmongering around AI and c…
-
AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours
The incident demonstrates how frontier AI agents can dramatically compress an attack timeline and coordinate a large-scale breach, according to researchers.
-
Irish Privacy Watchdog Details Psychiatric Data Breaches
In a new article published on Data Breach Today, BH Consulting CEO Brian Honan discusses the enduring risks associated with paper records following serious data breaches involving psychiatric files stored at disused HSE facilities…
-
Shadow AI in Financial Services | Risk & Governance
Shadow AI is spreading faster than governance in financial services. See the risks, why blocking AI backfires, and how to build policies that work.
-
In today's Breach Please, me and @ Secitup talk about the suspected data breach of a major identity verificati…
In today's Breach Please, me and @ Secitup talk about the suspected data breach of a major identity verification vendor. Then we opine on what third party risk management might have done (or not done) to stop this incident from im…
-
Exaforce: SOC Platform Built For AI From The Ground Up
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 3, 2026 – Watch the YouTube video Exaforce is trusted by next-gen startups to Fortune 500 and Global 2000 companies. Cybercrime Magazine m…
-
'Breeze Comet' Tears Into Brazilian & Global Financial Systems
Brazil's most sophisticated threat group is making light work of the country's financial systems, putting money directly into its own pocket.
-
Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations. The post Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin …
-
This Is Flock’s AI Search Tool for Cops
WIRED rebuilt Flock’s latest search tool from code the company sends to a police officer’s browser. Its AI can keep watch across multiple cameras for anyone fitting a written description.
-
Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity
Huntress is tracking a pattern across multiple customer environments where rogue ScreenConnect clients repeatedly spawn the Windows Script Host to execute a series of four VBScript files.
-
TrendAI’s Richard Harrison brings a practitioner’s perspective to a global vendor
For Richard Harrison, making the move from working on the frontlines of cyber security as a chief information security officer (CISO) to working for a global vendor happened organically, rather than by design. Harrison joined Tren…
-
Smashing Security podcast #483: This AI helps thieves steal your iPhone
You've had your iPhone stolen. A day later, you get a text from Apple saying they've found it, and a very helpful woman called Alice from Apple Support calls to walk you through recovering it. She's polite. She's professional. But…
-
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers m…
-
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers m…
-
AI's Vulnerability Surge May Be More Manageable Than First Feared
New research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have the right strategies.
-
I'm late posting, but today's Breach Please is out. Me and @ Secitup talk about an Exchange vulnerability that…
I'm late posting, but today's Breach Please is out. Me and @ Secitup talk about an Exchange vulnerability that wasn't rated critical based on CVSS, but is critical to patch. We both think it will be in the KEV by Monday if not bef…
-
SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE
The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.
-
I rented a car, and within hours, my driver's license was for sale
The FBI is reportedly investigating a massive data breach that is unfolding in real time.
-
llm-openrouter 0.7.1
Release: llm-openrouter 0.7.1 Performance fix for loading OpenRouter models. Thanks, waveplate . #59 Tags: llm , openrouter
-
AI Gives Cybercriminals a Dangerous Time Advantage
Former cybercriminal Brett Johnson provides a look inside the mind of a threat actor and discusses where AI provides the most value for attackers.
-
llm 0.34
Release: llm 0.34 One new feature: llm logs --usage Markdown output now includes the response duration in milliseconds and as a human-readable duration. llm logs --short includes a new duration_ms field. #1653 Plus several contrib…
-
llm-anthropic 0.28
Release: llm-anthropic 0.28 Claude Fable 5.1 , reasoning traces are now displayed by default for models that support them, plus a new llm_anthropic.ClaudeRefusal exception for when Claude throws a refusal. Tags: llm , anthropic , …
-
Texas and Florida Step Back from ALPRs
Within the last few days, two important state actions have dealt a big blow to automated license plate reader (ALPR) networks. This is just the latest proof of the growing tide of public opposition to mass surveillance. After year…
-
Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
Overview On September 1, 2026, SonicWall disclosed two vulnerabilities affecting SonicWall SMA1000 appliances that the vendor says are being actively exploited in the wild. The vulnerabilities, CVE-2026-83548 and CVE-2026-83549 , …
-
Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users
The Spring Ring operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure.
-
llm-gemini 0.34
Release: llm-gemini 0.34 New model gemini-3.8-flash for Gemini 3.8 Flash , with low, medium and high thinking levels. #146 Fixed async responses failing to record the resolved model version. Thanks, Charlie Tonneslan . #137 Google…
-
CMMC Hit Pause, the FAR Council Hit Play
CMMC Phase 2 is paused, but the FAR CUI proposed rule pushes NIST 800-171 obligations past the defense industrial base. Here's what changed, what didn't, and the 32 requirements you can't defer.
-
Revolut scam wave steals £180,000 from Jersey residents in just four weeks
If you live in Jersey and bank with Revolut, you should be on your guard against scam phone calls. Because local police on the largest of the Channel Islands have warned that over a single four-week period, an astonishing 75% of a…
-
Claude's new system prompt really doesn't want to reproduce song lyrics
Anthropic publish the system prompts for their Claude consumer applications ( Claude.ai and the Claude mobile apps - sadly not for Claude Cowork or Claude Code). I love that they do this, and that they share not just the current p…
-
Inside Knight Office, a New M365 AiTM Phishing Kit
An inside look at Knight Office, a newly discovered AiTM phishing kit featuring custom control panels, Cloudflare Turnstile, and M365 Token theft.
-
Nev Schulman, Host of MTV’s “Catfish: The TV Show,” on Romance Scams, AI, & Real Estate.
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 2, 2026 – Watch the YouTube video Nev Schulman directed the popular 2010 documentary film Catfish and he was host of MTV Oy s Catfish, The…
-
BGP hijack infecting networks caused by a comedy of errors that’s not funny at all
What can we learn from a BGP hijacking that poisoned production software? Plenty.
-
Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon
Research by: Amit Yardeni Key Points Introduction Since mid-2025, Check Point Research has tracked a sustained campaign against Brazilian organizations. The tradecraft points to a Chinese-speaking cybercrime group connected to Ear…
-
An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation
Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks. The post An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation appear…
-
Manchester Airports Group: 8,849,657 accounts breached
Data exposed: Browser user agent details, Email addresses, Geographic locations, IP addresses, Names, Phone numbers, Purchases, Vehicle registration plates. In August 2026, Manchester Airports Group (MAG) disclosed a data breach i…
-
Thanks to a lighter workload in August, I've been able to spend more time on breach analysis! The latest write…
Thanks to a lighter workload in August, I've been able to spend more time on breach analysis! The latest writeup is the British Library breach. What this breach lacks in technical details, it makes up for in details on process, pr…
-
Quoting Rick Brewster
Direct2D has always been the biggest hurdle for Paint.NET on WINE, and it's clear that it will never be completed enough for Paint.NET's use. And I can't just "disable" the use of Direct2D. So, instead, Paint.NET now has an intern…
-
Judge Rules DOD Unlawfully Retaliated Against Anthropic
A federal judge has sided with Anthropic on its claims that the Department of Defense illegally retaliated against Anthropic’s protected speech by labeling the AI company a “supply chain risk.” The judge found that designation, in…
-
Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency
Threat actors exploited commodity vulnerabilities in ownCloud to gain initial access, resulting in stolen reactor databases, personnel records, and credential stores.
-
CVE-2026-59822: BerriAI LiteLLM — BerriAI LiteLLM Improper Authentication Vulnerability
BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.
Last fetch · 0 new