What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 3,038 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 2d ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 2d ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 3d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 4d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 4d ago
-
This Coin-Sized Device Can Hack a Boeing 737
Security researchers found that in less than 60 seconds, they could open a hatch on a plane’s exterior, plug in a tiny device, and redirect the aircraft’s autopilot or sabotage its flight plan.
-
Lazarus hackers pair fake job offers with Windows zero-day exploit
The North Korea-linked Lazarus group is using fake job offers, trojanized PDF software and a Windows zero-day in attacks aimed primarily at the defense sector, Check Point researchers have found. The activity is part of Operation …
-
OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning
A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal reasoning and secrets from session logs, including API keys and passwords. The weakness…
-
Enterprise Defenses Recovered at the Edge and Collapsed Inside
Enterprise defenses are tuned to catch the attacks that make noise. This year's data shows attackers winning by making none. According to Picus Labs' new Blue Report 2026, which measured more than 338 million real attack simulatio…
-
Ceva Logistics Operations Disrupted by Cyberattack
Affecting European contract logistics operations at eight Ceva warehouses, the incident caused shipment delays for multiple customers. The post Ceva Logistics Operations Disrupted by Cyberattack appeared first on SecurityWeek .
-
Signal adds new security feature to thwart man-in-the-middle attacks
Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven't been intercepted. [...]
-
Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalatio…
-
Chipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combined
Intel has informed customers about several high-severity vulnerabilities that can lead to privilege escalation and even code execution. The post Chipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combined appeared fir…
-
New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges
Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldBreak" after Microsoft released the August 2026 Patch Tuesday security updates. [...]
-
In this episode of Breach Please, we talk about new research showing that AI isn't actually that good at gener…
In this episode of Breach Please, we talk about new research showing that AI isn't actually that good at generating patches, highlighting objective rates of failure (it's not great). Then we discuss in-flight shenanigans and how s…
-
‘The Worst I’ve Ever Seen’: Cargo Thefts Have Turned Violent in Pursuit of AI Hardware
Experts allege that two recent incidents in California show the extreme lengths that criminal organizations are willing to go to to steal servers and other gear meant for data centers.
-
Prompt Injections for Defense
This seems to work : Researchers from Tracebit on Monday said they found that placing prompt injections alongside passwords, cryptographic keys, and other secrets stored on Amazon Web Services was often all that was needed to shut…
-
Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack
LiteLLM was compromised through the Trivy hack and abused to distribute information-stealing malware to its users. The post Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack appeared first on SecurityWeek .
-
Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)
Microsoft s August 2026 Patch Tuesday delivered security fixes for 400+ vulnerabilities, including one that has been exploited in zero-day attacks (CVE-2026-68820) and three that were publicly disclosed prior to the release of the…
-
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directo…
-
ConnectSecure helps MSPs automate Microsoft 365 security remediation
ConnectSecure has announced that Microsoft 365 Auto Remediation and AI-powered Training Assessments are now live on the ConnectSecure platform. The capabilities help managed service providers (MSPs) address supported M365 security…
-
CBTS brings continuous penetration testing to enterprise security
CBTS has launched Penetration Testing as a Service (PTaaS), combining autonomous penetration testing with security expertise to help organizations continuously identify exploitable risks, validate attack paths, and prioritize reme…
-
Fresh Windows Zero-Day Exploited in North Korean Cyberattacks
The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor. The post Fresh Windows Zero-Day Exploited in North Korean Cyberattacks appeared first on SecurityWeek .
-
Crytica’s RDAi detects OT device tampering from within
Crytica Security has developed a patented solution that delivers rapid, deterministic threat detection for operational technology (OT), protecting the embedded systems and connected devices that underpin critical infrastructure, n…
-
Chrome’s anti-abuse protections block 7 billion unwanted Android notifications daily
Google Chrome s latest measures against abusive web push notifications include automatically revoking notification permissions for inactive and suspicious websites, helping reduce scams, phishing attempts, and other deceptive cont…
-
Weekly Update 516: Live From Vietnam
A little wind noise, a little connectivity flakiness, and a little lip-sync issues from YouTube, but look at that view! Back to business, it s the Brinks Home FAQ I found most interesting this week. I mean, how do you write your o…
-
Ivanti EPM Update Patches Remotely Exploitable Flaws
The vulnerabilities could be exploited to leak credentials for external SQL connections or crash an agent service. The post Ivanti EPM Update Patches Remotely Exploitable Flaws appeared first on SecurityWeek .
-
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that inst…
-
ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact
CISA has also published several advisories describing vulnerabilities in ICS and other OT products. The post ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact appeared first on SecurityWeek .
-
Split-second deepfake glitch blows digital certificate fraudster’s cover
Spanish police have arrested a man in Murcia accused of using deepfake software to trick a certificate provider s video identity checks in an attempt to obtain digital signatures he could use for financial fraud. According to the …
-
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution. The vulnerability, assigned the CVE identifier CVE-2026-58231, is rate…
-
SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform
The security defects could allow unauthenticated attackers to execute arbitrary code remotely and read sensitive data. The post SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform appeared first on SecurityWeek…
-
ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access
The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak. The vulnerability, roote…
-
Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild. The high-severity flaw, tracked as CV…
-
Post-quantum migration gets harder when every user holds a key
In this Help Net Security interview, Christopher Smith, CEO of Quantus, discusses what cryptographic inventories turn up in banks and hospitals, including default passwords and admin keys still held by former employees. He explain…
-
PentestGPT: Open-source automated penetration testing agentic framework
PentestGPT is an open-source penetration testing agent that points a large language model at a target and lets it work. In its default mode it runs recon, then exploit, then walkthrough, each stage feeding the next. Switch it to p…
-
Cisco Patches Firewall Zero-Day Exploited for DoS Attacks
CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices. The post Cisco Patches Firewall Zero-Day Exploited for DoS Attacks appeared first on SecurityWeek .
-
Atturra modernises Invercargill City Council’s ageing HR, payroll platforms with TechOne
Atturra has modernised Invercargill City Council’s separated ageing HR and payroll platforms with the go-live of a new TechnologyOne solution. The service provider was tapped in early 2024 to upgrade the Council’s systems as part …
-
338 million attack simulations reveal the state of enterprise defense
First, a bit of good news: Enterprise defenses are recovering. However, it’s a narrow recovery, with a twist. Today, organizations are better at stopping loud attacks but have barely moved the needle at all against the quiet ones.…
-
Ready-made $500 kit puts a crypto scam within anyone’s reach
A seller on a cybercrime forum is offering a ready-made scam kit for $500, complete with an admin panel that tracks victims, checks their crypto wallets for value, and inflates fake balances to squeeze out more money, Malwarebytes…
-
AI deployments are stretching enterprise security to its limits
CISOs and CTOs expect AI deployments to increase their organizations attack surface by an average of 14% over the next year. Nearly all lack visibility into AI deployments, and 90% are concerned about employees using unapproved AI…
-
Nvidia’s US$500B AI investment pool could impact enterprise chip pricing, availability
Nvidia and six financial partners are creating a US$500 billion investment pool to help Nvidia customers including frontier AI labs, AI clouds, and other enterprises buy its chips on credit. The impact of such a cash infusion on e…
-
Inside day one of EDGE 2026: A powerful start as Jay McBain challenges partners to rethink growth
GE 2026 kicked off in spectacular fashion in Cairns, with globally renowned IT industry analyst Jay McBain delivering a keynote that challenged partners to rethink growth, ecosystems and the future of the technology channel. Partn…
-
Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse
Google says Chrome's anti-abuse systems reduced unwanted notifications on Android by more than 7 billion per day during the first quarter of 2026. [...]
-
Kimwolf botnet rebuilt to survive takedowns, researchers say
Months after police seized its servers and arrested an alleged operator, the Kimwolf botnet is running code that disguises attacks as Chrome traffic and fetches its orders from the Ethereum blockchain. The post Kimwolf botnet rebu…
-
DEF CON crowd suspected in fake-hotspot attack on Delta flight
FBI Atlanta confirms it's looking into the incident, no arrests made.
-
There are no lossless transformations of natural-language text
There are no lossless transformations of natural-language text Sophie Alpert shares her "internal policy on acceptable use of AI writing by engineers". It's a short read (supporting its own recommendations) and really good. If you…
-
There are no lossless transformations of natural-language text
There are no lossless transformations of natural-language text Sophie Alpert shares her "internal policy on acceptable use of AI writing by engineers". It's a short read (supporting its own recommendations) and really good. If you…
-
Urgent action needed to boost strained digital skills pipeline: Tech NZ
Coordinated national action is needed to address New Zealand’s digital skills challenge, which has become a structural issue, as demand for AI, cyber security, and cloud skills puts pressure on the local talent pipeline. This is a…
-
Federal judge issues second order blocking Trump mail-in voting directive
The U.S. Supreme Court temporarily reversed an earlier decision through the shadow docket. The post Federal judge issues second order blocking Trump mail-in voting directive appeared first on CyberScoop .
-
Rebranded AI legal tech firm Nylon to raise $20m for UK, US expansion
Auckland legal tech company Nylon has embarked on a rebrand and is seeking to raise $20 million in a new seed round to expand in the UK and US. Founded in 2023, Nylon was previously known as Law Cyborg and uses AI to answer detail…
-
Stealing Reasoning Traces from Proprietary LLM APIs
Stealing Reasoning Traces from Proprietary LLM APIs A vanity domain name ( stolen-thoughts.com ) for a neat paper : Anthropic, OpenAI, and Google return encrypted chain-of-thought blocks to clients that can be replayed across sess…
-
Stealing Reasoning Traces from Proprietary LLM APIs
Stealing Reasoning Traces from Proprietary LLM APIs A vanity domain name ( stolen-thoughts.com ) for a neat paper : Anthropic, OpenAI, and Google return encrypted chain-of-thought blocks to clients that can be replayed across sess…
-
Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as "critical."
-
DeadLock ransomware uses blockchain to resist infrastructure takedown
The DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims and data-leak activity. [...]
Last fetch just now · 0 new · 2 source error(s)