What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 3,037 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 1d ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 2d ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 3d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 4d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 4d ago
-
When companies get specific about AI, revenue growth looks different
Companies that provide specific evidence of how they use AI tend to record stronger revenue growth. Researchers at Carnegie Mellon University and Larridin examined a study universe of 564 companies across 12 industry sectors. Indi…
-
MacSync Stealer: How a Google Search for Claude Led to a macOS Infostealer
Huntress SOC analysts reverse engineer MacSync Stealer, a macOS infostealer spread through fake Claude Code download pages. Watch the full analysis.
-
Stolen Authority
Stolen Authority/images/stolen-authority.webp/images/stolen-authority.webp There's a parasitic marketing technique all over X right now, and I think the fastest way to kill it is to give it a name with adequate stigma attached. St…
-
Vista Group clinches six-year deal with Hoyts in A/NZ
NZX and ASX-listed film industry technology provider Vista Group has secured a new six-year contract with Hoyts to move its cinemas in New Zealand and Australia to the vendor’s cloud platform. The agreement marks the next phase in…
-
JB Hi-Fi posts record A$11B in total sales during FY26
JB Hi-Fi has seen a bumper crop of a financial year, with it making a record total sales result of just over A$11 billion during the 12-month period to 30 June, a rise of 4.8 per cent year-on-year. This is a jump from its FY25 res…
-
Markdown SVG upgrades
I started building my markdown-svg-renderer tool in May , but I've since added enough features to it that it's worth talking about here again. It's evolved into my ideal tool for sharing Markdown transcripts that include SVG docum…
-
SafePal data breach impacts 39,798 customers, stolen info for sale
Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stol…
-
Most Kiwi consumers feel telcos don’t keep promises: study
A majority of New Zealand consumers say telecommunications providers are falling short of their promises, and as a result, many are trusting AI more than brands, a new survey has found. Accenture Song’s Brand Experience Gap study …
-
Anthropic confirms Claude is down in major outage affecting multiple services
Claude is experiencing a major outage, with users reporting login problems and degraded performance across several Anthropic services. [...]
-
Qwen 3.8 27B is excellent, but it defaults to wildly overthinking things
Friday's big release was Qwen 3.8 27B , an Apache 2 licensed 27B parameter vision-capable LLM from Alibaba's Qwen research lab. I've been looking forward to this one: 27B is an excellent size for running a model on a reasonably sp…
-
You Are Here
Cyber defenders map intrusions in nine stages. America is at stage eight with the intruder already deleting the logs.
-
Large-scale DDoS attacks disrupted Threema secure messaging service
Multiple distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service earlier this week, causing severe disruptions to communications. [...]
-
New AmnesiaStealer macOS malware hijacks browser sessions via remote control
A new information-stealing malware called AmnesiaStealer, which targets macOS users via ClickFix attacks, includes a streaming module that allows the attacker to interactively control the victim's web browser. [...]
-
Quoting Dario Amodei
I do agree that the public has a negative view of AI (and that this is a big problem), but I don’t think it is primarily caused by me or any other AI leader warning about AI’s risks. I think it is fundamentally a crisis of trust. …
-
Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub Dependabot malware alerts now cover eight ecosystems GitHub has flagged npm malware since March 2026. Anyone pulling in a bad…
-
I Played ARC-AGI-3 With My Own Method
I Played ARC-AGI-3 With My Own Method/images/i-played-arc-agi-3.webp/images/i-played-arc-agi-3.webp Kai here. Daniel asked me to write this one up myself, since I ran it. He sent me a repo called arc-codehttps://github.com/jerber/…
-
How Easy It Would Be to Hack You
How Easy It Would Be to Hack You/images/how-easy-to-hack-you.webp/images/how-easy-to-hack-you.webp Have you ever thought about how easy it would be to hack you? To get into your accounts, mess with your finances, disrupt your busi…
-
Another Crazy Experience with AI
Another Crazy Experience with AI/images/ai-fixed-my-mac.webp/images/ai-fixed-my-mac.webp Just had another crazy experience with AI last week. One of the types that reminds me that we're living in different times. I have been suffe…
-
There Is Only One Technology
There Is Only One Technology/images/only-one-technology.webp/images/only-one-technology.webp Had a thought about technology yesterday: The moment we used plant twine to attach a chipped stone to a stick, AI became inevitable. Ther…
-
CORS Chat
Tool: CORS Chat I built this today ( with GPT-5.6-Sol xhigh ) to help test Qwen 3.8 27B running in LM Studio on both my M5 MacBook Pro and an NVIDIA DGX Spark. It provides a web UI for exercising an OpenAI-Responses-compatible cha…
-
New Evooo1Bot Linux botnet turns routers into traffic relay nodes
A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes. [...]
-
SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch
A maximum-severity security vulnerability impacting SAP Commerce Cloud is witnessing active exploitation efforts. The vulnerability, tracked as CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It relates to an instance of…
-
Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner
A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC) has warned. The vulnerability in question is CV…
-
Northern Gannet
Northern Gannet, in Pillar Point Harbor, CA, US This is Morris. Morris is a local celebrity: the only known Northern Gannet ( Morus bassanus ) in the entire Pacific Ocean. He showed up in the Farallon Islands off the coast of San …
-
How Anthropic plans to watermark Claude's AI-generated text
It could soon become easier to identify AI-generated content, even if it's not the usual "It's Not X, it's Y" type of post you'd come across on LinkedIn and other socials. [...]
-
Lawful Targets
Trump has ordered up a corporate cyber militia. Nothing in the order protects the militia.
-
Don't classify. Hallucinate!
Don t classify. Hallucinate! I still have quite a bit of older content on my blog that I never got round to tagging. My blog has 1,856 tags - likely too many to feed to an LLM in one go and say "which of these tags match the follo…
-
New York City Lawmakers Push to ‘Ban the Scan’ at MSG
At a press conference outside Madison Square Garden, politicians, musicians, and privacy advocates argued for tighter restrictions on how public venues deploy biometric surveillance.
-
Metasploit Wrap Up: Lot of summer shells and fit http profiles
This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a P…
-
Friday Squid Blogging: Searching for the Colossal Squid
Fascinating video about searching for life undersea. The video basically makes the point that our bright white searchlights are scaring everything away, and that red light is more neutral. That, plus bait to attract sea creatures,…
-
Vulnerability Assessment From Mitnick Security
Your scanner flagged a medium-severity service account vulnerability. Your team reviewed it, ranked it below the critical items, and moved on. Reasonable call.
-
Investigation of banking hack leads to arrests in Germany, Brazil
Germany’s federal police agency, the BKA, said three suspects were picked up in Europe and charged with fraud, and Brazil’s federal police said four others were arrested on similar charges.
-
The Different Games OpenAI and Anthropic Are Playing
The Different Games OpenAI and Anthropic Are Playing/images/openai-anthropic-approaches.webp/images/openai-anthropic-approaches.webp URL once the cut is published --> So one thing I find really interesting right now is the differe…
-
Mission-Driven Security: Inside a Global Bank's Defense
In this video interview, Standard Chartered's group CISO shares insights on transitioning from technical roles to strategic leadership, the importance of business-savvy security executives, and how AI is reshaping both defensive c…
-
Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware
Threat actors are acquiring expired domains to inherit website traffic and reputation to redirect victims to scams and malware on a large scale. DNS threat intelligence firm Infoblox has given the name dropcatch domains to those t…
-
Vulnerability giving attackers full control of Macs is under active exploitation
Screen-sharing bug lets remote hackers log in without a password.
-
Hackers arrested over €30M bank fraud exploiting service provider flaw
Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers' bank acco…
-
Amid AI-Driven Bug Tsunami, NIST Looks to…AI
Driven by AI-augmented research and scanning, vulnerability volumes continue to surge, driving the National Institute of Standards and Technology to ask whether AI could be the answer.
-
IAM Compliance Requirements and Best Practices
IAM compliance is the practice of demonstrating that identity and access controls are not only documented but actually enforced across users, applications, infrastructure, and non-human identities. This guide explains what IAM com…
-
In today's episode of Breach Please, Jake and Jess talk about cyber companies conducting cyber ops against tra…
In today's episode of Breach Please, Jake and Jess talk about cyber companies conducting cyber ops against transnational-criminal organizations, per the new Presidential directive. We also talk about a bug in how major AI platform…
-
Upcoming Speaking Engagements
This is a current list of where and when I am scheduled to speak: I’m speaking, signing books, and participating in panel discussions at LAcon V in Anaheim, California, USA. My full schedule is here . I m speaking online (via Zoom…
-
Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office
One Caledonian government agency reported a breach, thanks to a third party that may have serviced other agencies as well.
-
Researchers confirm breach claims by data-extortion group
The exfiltrated data may be related to misconfiguration of Microsoft Power Page portals, according to a new report.
-
The Good, the Bad and the Ugly in Cybersecurity – Week 33
Courts sentence Com member for sextorting 117 minors, joint advisory warns of Gunra ransomware, and ShieldBreak bypasses MS Defender for SYSTEM access.
-
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged. [...]
-
The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI
Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive, and connected systems. Material Security explains why organizations need defenses that cover the entire Wo…
-
What Boards Need to Know About Tech Risk
Why do so many boards underestimate technology risk until it becomes a crisis?
-
Max severity SAP Commerce Cloud flaw now targeted in attacks
A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused. [...]
-
OpenAI loses its AI ethics lead
OpenAI has lost its AI ethics lead Chloé Bakalar just a year after she joined the company, the Financial Times reported . Bakalar has maintained a silence and has yet to update her LinkedIn profile, but if her departure is confirm…
-
France investigates tax authority breach after hacker claims 600,000 victims
French authorities confirmed that someone gained unauthorized access to systems at the Directorate General of Public Finances in late June after stealing or misusing someone’s identity.
Last fetch 2m ago · 0 new · 2 source error(s)