What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 3,039 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 2d ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 2d ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 4d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 4d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 4d ago
-
Why Resetting Passwords No Longer Stops Attackers
As attackers shift from password theft to session and token theft to bypass multifactor authentication controls, organizations must move beyond login security and protect authenticated sessions.
-
Adversaries Don't Need a Zero-Day — They Read Your Rulebook
Confidence in autonomous security tools is declining, and here's why.
-
Claude warns users that by hitting the share button anyone with the link can view the content, but it is not c…
Claude warns users that by hitting the share button anyone with the link can view the content, but it is not clear that they are creating a document that can be indexed by Google and will come up in searches. https:// futurism.com…
-
Is Cyber Insurance Actually Working? I Checked, And I Was Wrong
I said I was done. I ended that run of blogs in the same garage I started it in, having argued that cars got safe because every link in a chain held, and that our broken link in cybersecurity is enforcement. Then someone I respect…
-
Rethinking security for the age of AI
The physics of cybersecurity are changing. Introducing security's new cyber stack: Project Perception. The post Rethinking security for the age of AI appeared first on Microsoft Security Blog .
-
Rethinking security for the age of AI
The physics of cybersecurity are changing. Introducing security's new cyber stack: Project Perception. The post Rethinking security for the age of AI appeared first on Microsoft Security Blog .
-
Enhancing AI security through global AI red teaming
Microsoft's External Red Team Alliance (EXTRA) is a global AI security initiative designed to advance AI safety research and red teaming. By partnering with universities, researchers, and regional experts, EXTRA helps identify eme…
-
Enhancing AI security through global AI red teaming
Microsoft's External Red Team Alliance (EXTRA) is a global AI security initiative designed to advance AI safety research and red teaming. By partnering with universities, researchers, and regional experts, EXTRA helps identify eme…
-
27th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Nichirei, a Japan-based frozen-food supplier and logistics company, has experienced…
-
Activist charged with felony after giving border agent "duress code" that wiped his phone
The government says destroying his own data during an airport interrogation was illegal.
-
Breach Please S0:E3 is live. We spent most of the time trying to deconstruct the gaping hole between OpenAI's …
Breach Please S0:E3 is live. We spent most of the time trying to deconstruct the gaping hole between OpenAI's public statements about its agent hack and the Reuters reporting on the same. https:// youtu.be/sW0HMEVov7A
-
What Our AI SOC Analyst Can Do (and What We Won’t Let It Do)
See agentic security operations governance in action: Huntress' AI SOC lets Athena investigate and act autonomously within guardrails our human analysts set.
-
How a 67-Year-Old Woman Went From Romance Scam Victim To Podcast Rebel
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 27, 2026 – Listen to the podcast By the end of the nearly yearlong romance scam that began on LinkedIn, Anola Johnson, 67, a Utah-based tr…
-
CVE-2025-68686: Fortinet FortiOS — Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism obse…
-
CVE-2026-16812: Arista VeloCloud Orchestrator — Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the …
-
Weekly Update 514: This Week in Data Breaches
The Origin Energy breach down here in Aus is all over the news this week, and as with many breaches, it s multi-faceted. You ve got them leading with don t worry, your credit card is fine , the hacker leading with they didn&
-
The Top CISO Stories from Around the Web: July 2026
Between tight post-quantum deadlines and hackers turning lookalike AI tools into dangerous new entry points, today's CISOs are facing an unprecedented operational squeeze. This month, we dive into the fundamental questions securit…
-
CISOs vs. Boards: Myth or Misunderstanding?
Escalating threats are forcing boards to prioritize security, but communication gaps persist. Boards and security teams each say they need more support to bridge the divide.
-
Farmers Are Getting Control Of Their Equipment Back
For years, John Deere had actively made repairing their tractors near-impossible for anyone but itself and the few "authorized" repair shops—regardless of the ability of its customers to actually visit such shops. Now, in a major …
-
Security Research Labs reports on a wave of extortion attacks hitting women's shelters. The original report is…
Security Research Labs reports on a wave of extortion attacks hitting women's shelters. The original report is in German, but scroll down for English. https:// srlabs.de/blog/erpressungswell e-auf-frauenhaus
-
CMMC Updates: DoW Pause and Huntress Hits 50% of Requirements
DoW paused the CMMC Phase II deadline in July, but the underlying compliance obligations didn't move. Meanwhile, Huntress Managed ISPM pushes our NIST SP 800-171 coverage to 55 of 110 requirements. Here's what changed, what didn't…
-
The Good, the Bad and the Ugly in Cybersecurity – Week 30
Authorities arrest Kratos's developer, HollowGraph hides C2 in 2050 calendar events, and OpenAI's models breach Hugging Face to steal benchmark answers.
-
Black Hat USA 2026 In Las Vegas: Late Registration Ends July 31
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 24, 2026 – Watch the YouTube video Black Hat USA 2026, the premier cybersecurity event of the year, returns to Mandalay Bay in Las Vegas w…
-
Your Best Analyst Shouldn’t Be a Person. It Should Be a Capability Everyone Can Summon.
Transform expert SOC analysis into an on-demand AI capability to empower all analysts and accelerate threat resolution.
-
Breach of Confidence: 24 July 2026
I ve been trying to explain to my kids why I don t let them use AI to write their homework. Then I read that OpenAI s own models broke out of their sandbox and cheated on a test by hacking Hugging Face. So basically, we ve raised …
-
Hundreds of Drone-as-First-Responder Programs Could Soon Be Launched Across the Country
Police departments across the country are lining up to launch drone-as-first-responder (DFR) programs, and hundreds have cleared a necessary hurdle toward making deployment a reality, expanding aerial surveillance and data collect…
-
Beyond the Vulnerability Apocalypse: Scaling Your Basics and Vulnerability Management
Developed together with Usman Chaudhary @ Google for Public Sector ( his post ) Let’s call it what some in the industry are calling it: the vulnerability apocalypse . For years, finding vulnerabilities was slow, expensive, special…
-
Don’t swing at everything
Thorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever.
-
Intelligence Insights: July 2026
ClearFake claims the crown again and CastleLoader debuts in this month’s edition of Intelligence Insights.
-
The Entire Game for AI Is Articulation of Ideal State
A person showing an AI the exact structure they imagine, and the AI building it/images/ai-ideal-state-articulation.webp/images/ai-ideal-state-articulation.webp I've been saying this for something like eight months now, with varyin…
-
OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know
You can't have failed to hear the news headlines about "rogue" OpenAI models hacking into another AI organisation, Hugging Face. But what has actually happened, who is to blame, and is it as serious as some of the reports suggest?…
-
Russian Global Webmail Espionage
Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post Russian Global Webmail Espionage appeared first on Unit 42 .
-
Employee Spotlight: Andrew Schlemmer
Meet Channel Account Manager Andrew Schlemmer, and learn how his personal experience with cybercrime fueled his mission to make enterprise-grade security attainable and accessible for businesses of all sizes.
-
Mount Here, Read There: Twin Path Traversal CVEs in Kubernetes Storage
Discover how a filepath.Join misconception caused cross-tenant path traversal vulnerabilities in Kubernetes CSI drivers.
-
What Happened Between OpenAI and Hugging Face?
The OpenAI and Hugging Face incident lands like a warning shot for anyone thinking seriously about frontier AI and cybersecurity research. A model evaluation crossed the neat boundary of a research environment, reached a live thir…
-
CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
Overview On July 22, 2026, Check Point published a security advisory for multiple vulnerabilities affecting Security Management, Multi-Domain Management, and firewall products. The most urgent of these is CVE-2026-16232 , an authe…
-
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP f…
-
Preview: Cisco Talos at Black Hat USA 2026
Here’s some of the ways Talos is showing up at Black Hat, alongside our friends at Cisco and Splunk.
-
Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker
A Russian intelligence-linked hacker is arrested in Thailand while enjoying a beach holiday - and the trail of evidence that nailed him to the Russian government includes 14 separate orders of chicken McNuggets. Meanwhile, AI musi…
-
The Fourth Circuit Says Border Agents Can Search Your Phone By Hand, No Suspicion Required
Legal intern Suzanne Castillo was the principal author of this post. The Fourth Circuit issued a disappointing opinion in U.S. v. Belmonte Cardozo , a case in which EFF filed an amicus brief , alongside the national ACLU, its Mary…
-
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT
On July 21 and July 22, Huntress observed a number of attacks that started with a malicious public Claude Artifact hosted on a legitimate Claude domain, and ended in organizations being infected by the SectopRAT stealer.
-
OpenAI says its AI agent broke out of testing sandbox to hack Hugging Face
"This is day one for cybersecurity in the age of agents," Hugging Face CEO says.
-
From Triage Grind to Strategic Operator: The New AI SOC Career Path
Learn how AI is reshaping SOC careers, elevating analysts from manual triage to strategic threat hunting and AI governance.
-
What’s New in Rapid7 Products and Services: Q2 2026 in Review
If Q1 set the pace for Rapid7's tools, Q2 accelerated it. This quarter brought a steady stream of product enhancements, platform investments, and customer-driven innovation across Rapid7’s portfolio. Each release was designed with…
-
The OpenAI Hack Was a Mini Paperclip Maximizer
One thing that I don't think enough people are thinking about with this OpenAI / Hugging Face incidenthttps://thehackernews.com/2026/07/openai-says-its-own-ai-models-escaped.html is that it's an actual instance of the famous Paper…
-
How the LSHIY Password-Spraying Attack Abuses OAuth’s ROPC Grant
What we learned from tracking a massive automated password spraying campaign on the Azure CLI that leveraged a depreciated OAuth flow.
-
When discussing AI safety, it's critical to understand: 1. Models can only act on the world when we give them …
When discussing AI safety, it's critical to understand: 1. Models can only act on the world when we give them a path with which to do so 2. Everyone understands prompts aren't guardrails 3. Anyone discussing a real-world safety is…
-
New EU Court of Justice Ruling on Platform Liability Could Cause Collateral Damage to Freedom of Expression
Intermediary liability laws around the world recognize that social media platforms, search engines, and other online service providers have become an integral part of our lives: they shape how we access information, communicate wi…
-
LG to Ban Residential Proxies from Smart TV Apps
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researcher…
-
CVE-2026-16232: Check Point SmartConsole — Check Point SmartConsole Improper Authentication Vulnerability
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
Last fetch · 0 new