What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 3,039 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 2d ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 2d ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 4d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 4d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 4d ago
-
Cybersecurity, Then & Now: A Visual Look at 20 Years of Change
Since 2006, Dark Reading has been at the forefront of covering cybersecurity. The more things change, the more they stay the same.
-
Smashing Security podcast #478: This job interview could destroy your company
You've been headhunted for a great job in cryptocurrency. All you have to do is complete a short online assessment - with your webcam on, of course, so they can verify who you really are. Which is ironic, because the person recrui…
-
Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission
HAWK withstood years of testing that had yet to uncover a fatal weakness found through Mythos.
-
Still Got My Nokia Somewhere Up There
I still have my Nokia 3210 somewhere. Not in a drawer I can easily reach but boxed up in the garage with the party decorations and a broken food processor I ve been meaning to fix since 2019. I know it s there because I packed it …
-
OpenAI's Rogue Model Claims More Victims Beyond Hugging Face
OpenAI's goal-seeking agent compromised a Modal customer environment and others during its sandbox escape.
-
Red Agents vs. Blue Agents: How to Make AI Better at Defense
The agentic AI playing field was heavily tilted toward offense, so researchers began using red team agents to help teach their blue counterparts.
-
Who's Liable When AI Agents Escape? Hugging Face Breach Raises Hard Questions
Dark Reading walks through the many twists and turns in the bizarre story of how OpenAI's agent AI system broke out of its sandbox and decided to target Hugging Face, and what CISOs should be aware of.
-
Hugging Face Hack: Lessons for Cyber Defenders
Dark Reading Confidential Episode 20: Expert Rich Mogull reflects on lessons cyber teams should pull from the OpenAI agent's attack on Hugging Face.
-
CyberSecurity Expert Joseph Steinberg Discusses The Dangerous Failure to Address Hardware Vulnerabilities
In a video shot for Sepio Cyber, on whose advisory board he serves, Cybersecurity Expert Joseph Steinberg warns the public about a critical vulnerability facing modern organizations: unmanaged hardware. Steinberg explains that whi…
-
When AppSec Scanners Become a Supply Chain Attack Vector
New research shows how security scanners embedded in the software supply chain can be attacked to serve as a foothold for downstream attacks.
-
🏃 Fitness Tracker Privacy Fails | EFFector 38.14
Watches, bands, and rings—if you want to digitally monitor your fitness, more companies than ever are selling devices to do it. And more Americans than ever now own at least one wearable health device. But what are the companies t…
-
CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity
Overview On July 27, 2026, JetBrains published a security advisory for CVE-2026-63077 , a critical unauthenticated vulnerability affecting all versions of TeamCity On-Premises. The issue is classified as deserialization of untrust…
-
Better security starts with better questions
Learn how better questions, trusted AI, and human judgment help security leaders make confident decisions and build resilient systems. The post Better security starts with better questions appeared first on Microsoft Security Bl…
-
Anthropic is finding bugs faster than Microsoft can fix them
Microsoft is on a mad dash behind the scenes to patch exploits before hackers find them.
-
Patch-Resistant 'RufRoot' Flaw Can Unleash Malicious AI Agent Swarms
The vulnerability in the AI hosting platform Ruflo allows an unauthenticated attacker to take over the system and corrupt memory, so bad behavior can persist after patching.
-
Reverse Engineering the Six Stages of MacSync Stealer and RAT
We reverse-engineered MacSync, a six-stage macOS stealer and RAT, recovered from attacker infrastructure after the victim’s host was taken offline.
-
Introducing Huntress Webhooks. Get Real-Time Security Alerts.
Huntress Webhooks push incidents and escalations straight to Slack, your PSA, or SIEM in real time with no polling. See how you can set them up in minutes.
-
How AI is Rewriting the Zero-Day Playbook for Preemptive Security
The scenario is all too familiar for any cybersecurity professional: It’s late in the day, and a critical zero-day vulnerability is disclosed. When this happens, CISOs from every industry immediately turn to their Security Operati…
-
Bent: How A Homeless Teen Became One Of The Cybercrime Industry’s Most Prolific Counterfeiters
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 29, 2026 – Listen to the podcast Bent is the story of John J. Boseak’s phenomenal life of crime. Inked from head to toe, with an addiction…
-
CVE-2026-20316: Cisco Secure Firewall Management Center (FMC) — Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device u…
-
The Incompetence Defense
On the provenance and uses of Singh's Law
-
San Francisco: Don’t Fall for Industry Defense of Surveillance Pricing
The concept of “surveillance pricing” is just one part of a much larger problem and business model: corporations maximizing their profits by invading our privacy. The all-too-common business model is to systematically harvest, col…
-
We now have a better understanding how OpenAI hacked into Hugging Face
10 days passed from OpenAI models exploiting JFrog Artifactory 0-day to release of a patch.
-
Ghost Credentials Expose Cloud Systems to Hidden Identity Risks
Dormant nonhuman identities can create security blind spots, says security researcher Aleksandr Krasnov, who plans to release an open source tool next week at Black Hat USA 2026 that sniffs out trust paths.
-
Thousands of Data Center Controllers Open to Takeover
A host of Internet-exposed remote hardware management processors are subject to offline password-cracking attacks — and adversaries have taken note.
-
When AI Agents Escape Sandboxes, Old Security Rules Apply
OpenAI's recent AI agent sandbox escape proves traditional security principles matter more than ever: limit access, isolate execution, log everything.
-
Stronger AI Safety Requires Peeking Inside the 'Black Box'
Researchers propose focusing on identification of certain cognitive elements in LLMs that indicate when AI systems may take an unwanted action.
-
This week on Enterprise Security Weekly: O'Shea Bowens explores MCP from a network security lens Jeremiah Gros…
This week on Enterprise Security Weekly: O'Shea Bowens explores MCP from a network security lens Jeremiah Grossman drops a serious truth bomb - the evidence doesn't support all the fervor around AI vulnerability discovery In the n…
-
Rapid7 Analysis: Check Point SmartConsole Authentication Bypass (CVE-2026-16232)
Overview On July 22, 2026, Check Point published a security advisory for CVE-2026-16232 , an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server …
-
'Certighost' Flaw Haunts Microsoft Active Directory Certificates
Microsoft patched a high-severity vulnerability earlier this month that allows a threat actor to escalate privileges and compromise an AD environment.
-
Why Are Gay Bars Building Databases of Their Patrons?
Recent reports have raised alarm about the use of PatronScan, an ID-checking and face-scanning system, at multiple LGBTQ+ bars in San Francisco’s Castro neighborhood. Much of the attention has focused on reports that the system ph…
-
The Floppy Disc Generation’s Data Problem
I keep a box of cables in the garage. Not even sure why anymore. VGA cables, SCSI terminators, a couple of those old parallel printer cables thick as garden hoses. I pulled it down last weekend because my daughter needed an HDMI c…
-
Rapid7 Cyber GRC is now available: Turn security action into compliance proof
Compliance has become one of the biggest operational drains on modern security teams. CISOs are being asked to manage a growing sprawl of frameworks, prove control effectiveness more often, respond to more customer assurance reque…
-
The Next Evolution of MDR: Preemptive Defense and Agentic Investigation
For years, security operations followed a familiar sequence: detect suspicious activity, investigate what happened, and respond before it caused significant harm. That model developed in a threat landscape where defenders had cons…
-
Credential Stuffing Campaign Hits SonicWall | Huntress SOC Tracking
The Huntress SOC is tracking an active credential stuffing campaign targeting SonicWall devices, compromising dozens of organizations since July 25.
-
Today's episode of Breach Please is live. Jake and Jess talk about how the story (again) about AI chats being …
Today's episode of Breach Please is live. Jake and Jess talk about how the story (again) about AI chats being indexed by search engines isn't really an AI story. We also talk briefly about a repo zero day. https:// youtu.be/pgLoqM…
-
Meta Is Facing $1.4T In State Lawsuits Over Social Media Addiction
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 28, 2026 – Listen to the podcast Meta is facing penalties of up to a massive $1.4 trillion from four U.S. states that sued the company ove…
-
Former Citigroup CISO Blauner on What Makes A Great Security Leader
The cybersecurity pioneer discusses the evolution of the CISO role, AI's impact on careers, and why operational resilience is the profession's next frontier.
-
Security Roundup July 2026
Curated advice, guidance, learning and trends in cybersecurity and privacy, as chosen by our consultants. NIS2 not yet law in Ireland, but nonetheless in force The European Commission is taking four member states to court for fail…
-
IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains
Talos IR's Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn how to sharpen your defenses.
-
Mirage Kitten targets Middle East and Africa region with new malware
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
-
Rapid7 and Exclusive Networks expand partnership to modernize security operations and accelerate customer success
Claudia Zoon is Senior Manager, Channel Sales at Rapid7. Across Belgium, the Netherlands, and Luxembourg, organizations are accelerating digital transformation through AI, cloud adoption, and increasingly connected business operat…
-
AI Autopsy: JadePuffer Claims a First for AI-Driven Ransomware
JadePuffer signals a new era of machine-speed cyberattacks, where AI agents can execute ransomware campaigns with minimal human input JadePuffer, described as the first fully autonomous AI-driven ransomware operation, could usher …
-
Houston City College: 831,642 accounts breached
Data exposed: Academic records, Citizenship statuses, Dates of birth, Email addresses, Genders, Names, Phone numbers, Physical addresses. In June 2026, Houston City College was the target of a ShinyHunters "pay or leak" extortion …
-
AI Agent Drives Espionage Attack on Thai Ministry of Finance
Attackers used Hermes, an autonomous open source tool, in unrestricted YOLO mode to conduct espionage against Thailand's Ministry of Finance.
-
Microsoft unveils AI security tools it says outperform competing platforms
Microsoft says tools cost less than competing ones and outperform them, too.
-
Agentic Browsers Rewind Web Security by 20 Years
PleaseFix class of flaws makes it easy to socially engineer agentic browsers and highlights weaknesses in how they handle cross-origin requests.
-
'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure
This category of vulnerabilities allows an attacker to easily acquire administrative level permissions and bypass cloud providers' access controls.
-
FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown
An FBI agent explains how the mulitnational law-enforcement Operation Cronos was successful in disrupting the largest ransomware group of its time.
-
Missed EFF's Livestream with Adam Savage and iFixit? Listen Here!
EFF’s first EFFecting Change livestream was all the way back in July of 2024. Maybe you've caught each stream, or maybe you’ve only caught a few. Or maybe you’re like me and prefer to listen to conversations like these on your dai…
Last fetch just now · 0 new · 2 source error(s)