What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 3,038 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 2d ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 2d ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 4d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 4d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 4d ago
-
Anthropic’s Opus 5 Is Better at Resisting Prompt Injection
The chart is interesting. On the IPI benchmark, Opus 5 improved over Opus 4.8, reducing the probability of an attacker succeeding within 15 attempts from 5.5% to 2.0%, and from 0.5% to 0.2% on 1 attempt. It also improved on Sonnet…
-
Suppose you're briefing your stakeholders on a rogue AI agent hacking your infrastructure. Do you call it a th…
Suppose you're briefing your stakeholders on a rogue AI agent hacking your infrastructure. Do you call it a threat actor? Me and @ Secitup discuss this and SO MUCH more as we dissect the (excellent) Hugging Face post mortem. https…
-
EFF Guide to Recording Law Enforcement
This post is available as a printable one page handout in English and Spanish . Recordings of law enforcement, whether by bystanders or by those directly encountering officers, can be powerful tools of government accountability an…
-
AI scammers outperform humans when it comes to building trust
The AI chatbot was more effective at creating “exploitable trust” than the humans.
-
The Morning After We Pull a Root of Trust, Nobody Owns It
The most valuable move any security team can make is building a certificate and key inventory.
-
Interpol Leverages Global System to Curtail Fraud Payments
When a fraudulent transaction occurs, law enforcement agencies must work quickly to halt payments before cybercriminals cash out.
-
DROP Platform Lets Californians Reduce Digital Footprint
Hundreds of thousands of California residents have already registered for the Delete Request and Opt-out Platform (DROP), which launches Aug. 1. Other states could follow if the process goes smoothly.
-
Digging Into Anthropic’s Cyber Verification Program
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 31, 2026 – Listen to the podcast The exploit lands before the fix even ships, says John Vecchi, CMO at Mitiga, a leader in zero-impact bre…
-
The Good, the Bad and the Ugly in Cybersecurity – Week 31
Police flag 4,000 URLs to disrupt The Com, theft victims sue Apple over a $1.8M wallet scam, and OpenAI and Anthropic models reach real systems in cyber tests.
-
USA Fencing Lunges Into the Hidden Identity Challenge in Amateur Sports
The organization behind Team USA's Olympic/Paralympic fencing teams has automated identity verification to handle growing membership, cutting manual review time while ensuring athletes compete in the correct categories.
-
Device Code Phishing Keeps Evolving. Here’s What to Watch For
Huntress is tracking an evolving wave of device code phishing that abuses trusted Microsoft 365 sign-in flows. Learn the signals defenders should watch for and how to respond.
-
Rapid7 at Black Hat USA 2026: See preemptive security in action
Black Hat USA returns to Mandalay Bay in Las Vegas this August, bringing together security practitioners, researchers, and leaders from around the world. Rapid7 will be there in the Business Hall, with new capabilities, live demon…
-
The $5 million threat: AI Is supercharging phishing attacks
According to the newly-published study, phishing and social engineering are becoming more expensive to recover from, trickier to detect, and increasingly augmented by artificial intelligence. Read more in my article on the Fortra …
-
Breach of Confidence — 31 July 2026
I ve been thinking about the number of security products that promise to solve problems nobody actually has. Then I remembered that most actual problems don t have vendors. The government just made up a new crime A bloke at the US…
-
Network Anomaly Detection in KATA
An analysis of how Network Anomaly Detection (NAD) rules work within Kaspersky Anti Targeted Attack, using Kerberoasting and DNS tunneling attacks as examples.
-
The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version
Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic. The post The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version appe…
-
The New Defcon Badges Pack a Unique Open Source Chip That Doubles as a Security Key
Created by legendary hardware hacker Andrew “bunnie” Huang, the badges for this year’s famed security conference aim to push the boundaries of security and transparency.
-
Weekly Cyber Update: 31 July 2026
Russian hackers target hotel and conference centre Wi-Fi; Cl0p is back with another extortion campaign; OpenAI and Anthropic models go rogue; and the Health-ISAC warns of intensifying Shiny Hunters campaigns. The Cyber Threat Inte…
-
Anthropic Says Claude Hacked Into 3 Organizations During Cybersecurity Tests
In a review triggered by OpenAI’s Hugging Face incident, Anthropic discovered three of its AI models had breached real-world organizations during third-party evaluations.
-
I'm not going to mince words: the major AI labs are negligent in protecting the public from their agents. We n…
I'm not going to mince words: the major AI labs are negligent in protecting the public from their agents. We need government regulation now or at the very least a private cause of action with guaranteed punitive damages for agents…
-
What the Singularity Actually Means
What the Singularity Actually Means/images/what-the-singularity-actually-means.webp/images/what-the-singularity-actually-means.webp The singularity might be my favorite idea in all of AI, and it has a real, specific meaning that I…
-
A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran
A memo obtained by WIRED, issued by the water utilities information sharing group WaterISAC, links dozens of cyberattacks against Minnesota water utilities to Tehran.
-
Minnesota Water Utility Attacks Expose Sector's Cyber-Risks
A likely Iran-backed actor targeted more than 30 community water systems in Minnesota in a sobering reminder of rising threats to US critical infrastructure.
-
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Exploits can give persistent server access that survives credential rotation and disk re-imaging.
-
AI Harnesses Burst With Potential Exploit Opps
A myriad of software makes up the typical AI harness, and trust issues between the components can create concerning attack vectors.
-
You were onto something with “It’s the Climb,” Miley
Amy hikes Virginia’s most difficult trail and muses on the persistent challenges of cybersecurity. The two aren't dissimilar.
-
Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting
The two Chrome updates in June patched more bugs than the 23 updates before them. Now, Google is ramping up its patching schedule thanks to AI-assisted vulnerability discovery.
-
Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to s…
-
KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
Overview On July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066 , a critical vulnerability affecting Active Storage image processing when used in conjunction with the libvips image processing …
-
What’s new in Microsoft Security: July 2026
This month’s updates help security and IT teams secure their AI environments, use AI to defend, and strengthen the foundations that AI-powered operations depend on. The post What’s new in Microsoft Security: July 2026 appeared…
-
What’s new in Microsoft Security: July 2026
This month’s updates help security and IT teams secure their AI environments, use AI to defend, and strengthen the foundations that AI-powered operations depend on. The post What’s new in Microsoft Security: July 2026 appeared…
-
Claude Mythos — Hype vs. Reality: What Security Teams Need to Know
In this edition of Reporters' Notebook, our journalists discuss the ins and outs of Anthropic's Claude Mythos rollout. How seriously should we take its risks? How big of a deal is it?
-
Rapid7 named a Leader in the IDC MarketScape: Worldwide MDR Service for Midmarket 2026 Vendor Assessment
IDC has named Rapid7 a Leader in the 2026 Worldwide Managed Detection and Response Service for Midmarket 2026 Vendor Assessment ( Doc #US52992326, July 2026 ). We believe this recognition and research highlights where MDR is headi…
-
Huntress hits an inflection point
CEO Kyle Hanslovan outlines how Huntress is evolving its research-led strategy, adopting AI with human oversight, and expanding its partner network to protect businesses against rapid, automated cyberattacks.
-
Incident Response Plans: What to Include & Why They Matter
An incident response plan is your organization's playbook for surviving a cyberattack. Learn what to include and how Huntress helps you stay ready
-
Metasploit Framework 6.5 Released
Today we’re proud to announce that Metasploit Framework version 6.5 has been released. Over the past two years, with the help of countless contributors, we’ve added 422 new modules along with a whole slew of new features. Malleabl…
-
$250M ARR Was Never the Goal. It Came From Staying True to Our Mission.
Hitting $250M ARR is a milestone, but it wasn't the goal. CEO Kyle Hanslovan reflects on Huntress' mission to protect the 99% and why staying true to it remains his top priority."
-
Adform compromised to serve crypto stealer via supply chain attack
Adform are an advertising company used by around 14k companies, owning around a 30% share of the demand-side category. They operate by offering a Javascript embed for websites, via this URL: hxxps://s2.adform.net/banners/scripts/s…
-
Hacker Summer Camp: What First-Timers Actually Need to Know | Huntress
Heading to Vegas for Hacker Summer Camp? Here are some insider tips for first-timers on navigating DEF CON, Black Hat, and BSides like a pro.
-
OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia
Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan networks, dump credentials, and keylogging.
-
Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)
Overview On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affectin…
-
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
Unit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read more. The post Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberatta…
-
Black Hat special: Rewind and revisit
Amy looks back at the incredible journeys that brought past guests to the world of threat intelligence.
-
Welcome to JFK, Please Lower Your Expectations
JFK airport looks like it was designed by a steering committee of tired men who only took the job because it paid well and gave them a crew to discuss their golf scores with. The entire setup before you get through security is old…
-
North Korea’s elite hackers turned on their own government – and got caught
For years, North Korea's state-trained hackers have been one of the world's most prolific robbers of banks - stealing huge sums of money from foreign financial instituions, draining cryptocurrency exchanges of billions, and funnel…
-
Toy Ghouls’ new toy: the GenieLocker ransomware
Kaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks by Toy Ghouls, a financially motivated extortion group.
-
SE Asian Cybercriminal Syndicates Become a Global Power
The organized crime groups have moved from goods to services and continue to traffic people from at least 80 countries, costing nations in the region at least $88 billion in 2025 alone.
-
The Answer to the Harness Question
The Answer to the Harness Question/images/the-answer-to-the-harness-question.webp/images/the-answer-to-the-harness-question.webp Martin Casado posted something about AI harnesses that captures where a lot of smart people are stuck…
-
'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China
A premium-grade malware-as-a-service offering takes flight with multiple threat groups, building infostealers that drain victims' bank accounts.
-
Cybersecurity, Then & Now: A Visual Look at 20 Years of Change
Since 2006, Dark Reading has been at the forefront of covering cybersecurity. The more things change, the more they stay the same.
Last fetch 12m ago · 0 new · 2 source error(s)