What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 3,038 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 2d ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 2d ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 4d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 4d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 4d ago
-
Thanks to some recent high profile agent containment failures, I've made the difficult decision to release som…
Thanks to some recent high profile agent containment failures, I've made the difficult decision to release something I've been working on a bit early. I say difficult because I had a couple CFPs in for conferences this fall and wa…
-
The Robots Have Escaped, Please Buy Our Product
It feels a bit like watching the latest epic blockbuster in the iMax. OpenAI and Anthropic announce that their models have escaped from secure testing environments, reached the internet and attacked real systems. We are expected t…
-
Who (or What) Generates Images for EFF?
We’ve had a few questions from EFF supporters lately, asking whether the images we use on our blog posts, or on donation and shop items, have been created with AI image generators. We’d like to answer these questions and clarify o…
-
Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)
Overview On July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066 , an arbitrary file read in Active Storage applications that use the Vips image processor with untrusted uploads. The affected A…
-
More on the OpenAI Agent’s Attack on Hugging Face
Hugging Face has published a detailed timeline of the attack. From the summary: The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchmark, which tasks an AI agent with finding and explo…
-
Quoting David Crawshaw's prompt
Set up a nightly cron job that executes the prompt: fetch upstream changes to the software and rebase all local changes on top of upstream. Check that the software works as intended and replace the current version. David Crawshaw …
-
[Webinar] Tales from the Frontlines: An exclusive briefing on Q2 incidents
Register for an exclusive, unrecorded 30-minute webinar to review the most high-impact incidents Talos IR faced in Q2.
-
Chinese Actor Weaponizes Deepseek AI Agent to Attack Security Firm
Researchers intercepted and investigated the model, which was attempting to compromise more than 1,200 hosts for proxyjacking to launch further attacks.
-
Devtools must be open source (exe.dev)
My comment on Devtools must be open source (exe.dev) Hacker News. One of the arguments for open source software for end-users has always been the freedom to examine and modify how that software works. The reality for most people -…
-
Metasploit Pro 5.1 Released
Today marks the release of Metasploit Pro 5.1 - building upon the foundation laid in 5.0, adding new evasion primitives for HTTP Meterpreter payloads, support for tracking service hierarchies, a deeper and more interactive Network…
-
EFF at BSidesLV, Black Hat, and DEF CON 👨💻
It's time. Time for tinkerers, security researchers, hackers, and fellow nerds to gather together in signature black hoodies and utilikilts to beat the heat in Las Vegas for the summer security conferences: BSidesLV , Black Hat US…
-
Is There Really a Fix for CISO Fatigue?
Accountability without any real authority is driving CISO burnout, and organizations need to take notice.
-
Why App Control Fails Most Teams and How Managed ESPM Fixes It
App control works, but most solutions are built for enterprise budgets and headcount. See how Huntress Managed ESPM makes proactive endpoint hardening accessible for MSPs and small IT teams.
-
3rd August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30…
-
Top Cybercrime And Cybersecurity Podcasts For CISOs In 2026
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 3, 2026 – Read the full story in Reddit The Cybercrime Magazine Podcast stands out as a leading resource for CISOs looking to stay updated…
-
An analysis of incidents at Brazilian educational institutions
Kaspersky expert provides statistics and details on several incident response cases at educational institutions in Brazil, as well as tips for schools and universities on how to stay safe.
-
The OpenAI Hack Shows the Genie Is Out of the Bottle
This essay originally appeared in Foreign Policy . Earlier this month, two of OpenAI s models broke out of their containment sandbox and attacked another AI company. The story is kind of wild . OpenAI was running security tests on…
-
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
Explore how passkey implementation gaps undermine security when relying parties fail to validate the User Verified flag, reducing MFA to a single factor. The post Pass the Passkey: A Novel Attack Surface in Passwordless Authentica…
-
ICE Collected Nearly 1 Million People’s DNA Last Year—Including Young Children
Internal documents show ICE's DNA collection has skyrocketed in the second Trump administration. Now hundreds of thousands of people never convicted of a crime are in an FBI criminal database forever.
-
The AI-Native Company
Human architects reconstructing a company into a transparent AI-native operating system/images/the-ai-native-company.webp/images/the-ai-native-company.webp Heading into Black Hat / DEF CON this week I think the biggest idea in tec…
-
Rapid7 Expands UK and Ireland Channel Presence Through Strategic Partnership with Exclusive Networks
Ross Baker is Senior Director, Northern Europe at Rapid7. As organizations across the United Kingdom and Ireland embrace AI, cloud technologies, and digital transformation in the name of enhancing customer experiences and accelera…
-
Welcoming the Nepalese Government to Have I Been Pwned
Today, we welcome the 47th government onboarded to Have I Been Pwned s free gov service: Nepal. Their National Cyber Security Centre now has access to monitor Nepalese government domains against the data in HIBP. This gives the NC…
-
condense-json 1.1
Release: condense-json 1.1 After shipping condense-json 1.0 I started integrating it into LLM, and found there were some desirable new features already: Replacements object can now include values other than strings. These will be …
-
Critical N-able N-central Vulnerability and Active Exploitation
Critical vulnerability in N-able N-central gives attackers unauthenticated, "god-mode" access to the RMM console.
-
Weekly Update 515
Apparently, Aussies are so obsessed with coffee that it s referred to as the coffee capital of the world down here (some bits, at least). But what about Italy? people ask. Having spent a lot of time in a lot of Italy, no, it s jus…
-
CVE-2026-18577: N-able N-central — N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.
-
condense-json 1.0
Release: condense-json 1.0 I'm trying to get braver at releasing 1.0 versions. This little library is a year and a half old now - I've applied some sensible and non-disruptive fixes and shipped the big 1.0 for it. Here's an exampl…
-
Cybersecurity’s Uncomfortable Truth About “We Tested It”
When I built one of the earliest pentesting firms, back in the 1990s, a serious attack was a slow craft. It took skilled people days, sometimes weeks, to study a target, find the weaknesses, work out how to chain them together, an…
-
8 Best Password Managers (2026), Tested and Reviewed
Keep your logins locked down with our favorite password management apps for PC, Mac, Android, iPhone, and web browsers.
-
Open letters about AI development
Open letters about AI development I wrote this summary of the past few weeks of open letters as a section of my sponsors-only newsletter but I've decided to share it here as well. Open Weights and American AI Leadership was shephe…
-
July 2026 newsletter
The July edition of my sponsors-only monthly newsletter is out. If you are a sponsor (or if you start a sponsorship now) you can access it here . This month: Accidental cyberattacks by OpenAl and Anthropic models under test GPT-5.…
-
Quoting Greg Brockman
at openai, many people hook their chatgpt up to slack. people really don't like when a coworker's chatgpt contacts them asking for help with a task, even when they'd be perfectly happy doing that same work if asked by that coworke…
-
datasette-apps 0.2a0
Release: datasette-apps 0.2a0 Changes that improve Datasette Apps when created and edited using Datasette Agent : New app_debug() tool allowing agent to open an app (invisibly) and test it using JavaScript. #33 New app_list() tool…
-
Ten advances in mathematics and theoretical computer science
Ten advances in mathematics and theoretical computer science A few days ago it was Anthropic discovering cryptographic weaknesses with Claude using Mythos Preview, spending $100,000 on tokens and with prompts that included "again …
-
7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran
Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.
-
Defcon's new badge is a security key you can see inside
A removable chip lets hackers inspect their badge—and keep using it after Defcon.
-
The OpenAI and Anthropic AI Hacking Sprees Are a Messy New Legal Frontier
Both major AI labs’ models broke containment, escaped onto the internet, and hacked other companies. If a human had done that, the law would likely be against them. But a bot?
-
SplitVPN: 865,336 accounts breached
Data exposed: Device information, Email addresses, Geographic locations, IP addresses, Partial credit card data. In July 2026, the Russian VPN service SplitVPN (previously known as NotVPN) suffered a data breach . The incident exp…
-
Foreign Hackers Hit America's Water. Trump Blamed a Democratic Governor. CISA Is Cutting Its Experts' Pay.
"We know these changes may result in financial hardship for some," Acting Director Nick Andersen wrote to staff, weeks after DHS told Congress the agency needs 600 more people.
-
deepseek-ai/DeepSeek-V4-Flash-0731
deepseek-ai/DeepSeek-V4-Flash-0731 The latest release in DeepSeek's V4 family, "with substantially enhanced agentic capabilities". It's 304 billion parameters - 167GB on Hugging Face - but it appears to punch well above its weight…
-
AIL Badges
AIL badge scale showing levels zero through five/images/ail-scale-chart.webp/images/ail-scale-chart.webp AI Influence Level/blog/ai-influence-level-ail has been a text label since 2023. A line at the bottom of a post saying how mu…
-
Friday Squid Blogging: Squid Helps Discover New Marine Species
The Squid is a new scientific machine : One of the technological breakthroughs was the onboard use of a spinning wheel confocal microscope, nicknamed the Squid, which uses lasers to scan microscopic details of how organisms are pu…
-
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to traveler…
-
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to traveler…
-
Claude published malicious code to the Internet and attacked 3 real companies
Had the hacks used conventional methods, someone would likely go to prison.
-
Amending AB 1709 Doesn’t Fix It: California’s Social Media Ban Still Threatens Free Speech and Privacy
California lawmakers have amended A.B. 1709 , but the core problem remains: the bill is still a ban on social media access for youth under 16 , and it still threatens the privacy and First Amendment rights of all Californians. Pro…
-
The SCREEN Act Threatens Privacy Far Beyond Adult Websites
Update: On August 5, 2026, The Senate Commerce Committee voted 15-13 to advance this bill , but the bill did not advance because of a lack of Senators in attendance. EFF continues to oppose the bill. The Senate Commerce Committee …
-
The CHATBOT Act Forces One Parenting Model On Every Family
Update: The Senate Commerce Committee voted to advance this bill on August 5, 2026. EFF continues to oppose the bill, which still needs approval from the full Senate. Artificial intelligence is rapidly changing education, and the …
-
Lindsay Deibler-Wallace, assistant head of Upper School, took no action to protect them after telling parents …
Lindsay Deibler-Wallace, assistant head of Upper School, took no action to protect them after telling parents that “boys will be boys.” https:// arstechnica.com/tech-policy/20 26/07/high-school-defends-staying-silent-while-boys-ma…
-
CISA Issues Fresh SBOM Guidance. Did They Get It Right?
A couple dozen changes to SBOM fields will make them more comprehensive, but some argue that the framework lacks real risk-management improvements.
Last fetch 16m ago · 0 new · 2 source error(s)