What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 3,040 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 2d ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 3d ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 4d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 4d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 5d ago
-
EFF and ARTICLE 19 Submission to the European Commission on the DSA Trusted Flagger Guidelines
EFF and ARTICLE 19 have submitted joint comments to the European Commission on draft guidelines for the Digital Services Act’s trusted flagger mechanism. Having long advocated for a DSA that protects freedom of expression while pr…
-
Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers
An app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks - no login, no passwords, no permissions needed. Meanwhile, Geoff - swimming in money and Lamborghinis, as all published …
-
The Impostor Got Verified. The Founder Couldn't.
On LinkedIn, a scammer impersonating a company can get verified more easily than the company can verify its own staff. The lock works; Microsoft owns the key.
-
CVE-2026-58644: Microsoft SharePoint — Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
-
CVE-2026-25089: Fortinet FortiSandbox — Fortinet FortiSandbox OS Command Injection Vulnerability
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.
-
CVE-2026-39808: Fortinet FortiSandbox — Fortinet FortiSandbox OS Command Injection Vulnerability
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
-
“AI Normal Tech” vs “AGI by Tuesday”: Security Advice That Survives Either Future
If you look at social media debates about AI, two extreme patterns emerge. Studying extreme patterns is very useful because understanding boundary conditions helps you understand the whole phenomenon — in this case of security in …
-
The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)
Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) appeared …
-
North Korea Is Hiring
The recruiter was real, the company was real, and the code they asked him to run was a hacked poker game that helps fund a nuclear program.
-
California Steps Back From Dangerous Expansion of its Age-Gating Law
The California legislature has stepped back from a plan that would have expanded its age-gating law, removing language that could have compounded serious threats to users’ speech, privacy and security just to browse the internet. …
-
Windows 0-day drops the same day Microsoft releases record number of patches
HiveLegacy is a "powerful primitive" that's likely capable of other nefarious actions.
-
Most Smart Watches, Rings, and Bands Lack Basic Transparency Reports and Key Privacy Features
Oura Rings, Garmin GPS fitness watches, Apple Watches, Whoop bands—every year, more and more tech devices are promising to monitor our health and fitness, guide us toward healthier living, and provide useful health metrics to take…
-
🚫 Don't Let Congress Age-Gate the Internet | EFFector 38.13
The effort to age gate the internet is back in Washington—and now it has a new name. Recently passed by the House of Representatives, the KIDS Act is a sprawling package of proposals to control what we can see and say online. Supp…
-
New Onyxia Cyber CISO Survey Report Exposes Wide Gaps in Cyber Resilience Standards Across Critical Infrastructure, Healthcare, Financial Services, Retail, and Technology
Today, we are unveiling our third CISO research report, “Industry Divides: Uncovering the CISO’s Resilience Priorities Across Sectors.” Based on a survey of 300 CISOs across financial services, healthcare, critical infrastructure,…
-
Wishin’ for Switchin’? The Huntress Buyout Program Has You Covered
Stuck riding out a contract with a vendor you no longer want to use? The Huntress Buyout Program covers your remaining term so you can switch today, not later.
-
Every Ransomware Attack Has a Backstory
Ransomware is the final act, not the first move. Learn how attackers use access brokers and trusted tools to infiltrate your environment—and how to stop them early.
-
TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development
TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs. The post TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development appeared fi…
-
AI Autopsy: JadePuffer Claims a First for AI-Driven Ransomware
The first autonomous ransomware campaign has arrived. Here s why every CISO should be paying attention. Phil Muncaster examines JadePuffer, the first documented end-to-end autonomous ransomware campaign, and considers what it mean…
-
Fluke: 821,100 accounts breached
Data exposed: Email addresses, Employers, Job titles, Names, Physical addresses, Support tickets. In July 2026, electronic test and measurement equipment company Fluke was targeted in a ShinyHunters "pay or leak" extortion campaig…
-
Goose Creek: 6,574,121 accounts breached
Data exposed: Email addresses, Names, Phone numbers, Physical addresses, Purchases. In June 2026, a party claiming to have access to data from Goose Creek Candle Company sent emails to a number of the company's customers , claimin…
-
Weekly Update 512: IoT Lockout Fail
Build a smart home , they said. It ll make life so much better , they said. Well, life wasn t very bloody good at 23:00 the other night after travelling 33 hours from Paris only to find the IoT doorlock batteries dead and the
-
CVE-2026-46817: Oracle E-Business Suite — Oracle E-Business Suite Improper Privilege Management Vulnerability
Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can resul…
-
CVE-2023-4346: KNX Association KNX Protocol Connection Authorization Option 1 — KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability
KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled an…
-
Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
Old and forgotten "shims" Microsoft failed to revoke have made Secure Boot bypasses simple.
-
European Court: Apple Can Not Shirk Off its Interoperability Requirements
One of the best bulwarks against monopoly is interoperability—that is making a new product or service work with an existing product or service. Interoperability allows users, and not the manufacturers of their devices or largest p…
-
Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products, including 57 that Microsoft marked as "critical."
-
The Three Components of Becoming AI Antifragile
The three components of becoming AI antifragile/images/becoming-ai-antifragile-header.webp/images/becoming-ai-antifragile-header.webp I have a new idea that everything you should try to do to get ready for AI basically breaks down…
-
Don’t Repeat NY’s 3D Printing Blunder
This year the state of New York had the dubious honor of being the first to pass a controversial provision to mandate all 3D printers come with surveillance and censorship. That means not only is there a ticking clock to protect e…
-
Microsoft Patches a Record 570 Security Flaws
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing P…
-
I wonder if there's a parallel between all of the long-undiscovered bugs that AI systems are discovering, and …
I wonder if there's a parallel between all of the long-undiscovered bugs that AI systems are discovering, and the old rusty hand grenades and mortars that magnet fishers keep pulling up from the muck in their local rivers or lakes…
-
5 Modern Threats You Need to Watch
Ransomware, BEC, and social engineering attacks increasingly start with a simple login, not malware. See the five threat patterns IT and security teams need to watch for, and how to catch them early.
-
What Happens When Someone Mentions Your Name?
A few years ago, my friend Jim Shields wrote a book called Three Guys Walk Into a Bar. The basic premise is that there are three kinds of people. There is a guy. You need a wall painted, so you find a guy. Any reasonably competent…
-
[Video] Where protection starts: Cisco Talos Intelligence Integrations
Every day, defenders make high-consequence decisions with incomplete information. Learn how Cisco Talos Intelligence Integrations help reduce uncertainty by turning the latest threat intelligence into proactive protections across …
-
Should cyber insurance be part of your business backup plan?
Insurance is all about managing risk. Unlike policies that are legally required for driving a car or taking out a mortgage, cyber insurance is optional. But for small businesses in particular, is cyber cover worth getting? If they…
-
The serpent’s tongue: Luring the Python out of its den
This blog examines the full lifecycle of a Python package, from hosting on repositories such as PyPI or custom web servers, through source and wheel distribution formats, to the final installation into virtual or system-wide Pytho…
-
The ransomware negotiator who was working for the other side
When a company falls victim to a ransomware attack, it is not uncommon for it to turn to experts for help. Specialist ransomware negotiation firms handle communications with criminal gangs on a victim's behalf. What victims don't …
-
AI Security Report 2026
For years, the cyber security industry tracked AI as a force multiplier: something that made existing attack techniques faster, cheaper, and more accessible. That framing was accurate. But the Annual AI Security Report 2026 from C…
-
CVE-2026-56155: Microsoft Active Directory Federation Services — Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.
-
CVE-2026-56164: Microsoft SharePoint Server — Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
-
CVE-2026-15409: SonicWall SMA1000 Appliances — SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.
-
CVE-2026-15410: SonicWall SMA1000 Appliances — SonicWall SMA1000 Appliances Code Injection Vulnerability
SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
-
The US government warns that Russia state hackers are coming after your router
With residential proxies all the rage, CISA urges router users to be vigilant.
-
Sony Nerfs Videogame Ownership
Legal intern Suzanne Castillo co-authored of this post. Playstation’s decision to kill physical game discs is the latest attack on our diminishing rights to access and engage with culture digitally. Rent-seeking corporations and n…
-
Avoid the AI Expertise Trap
Avoid the AI expertise trap header/images/avoid-the-ai-expertise-trap.webp/images/avoid-the-ai-expertise-trap.webp The further away a topic is from your expertise, the smarter an AI will sound. This is a blind spot that not enough…
-
Now, defenders are embracing the prompt injection, too
"Context bombing" tricks hacking agents into shutting down before they can do harm.
-
Lessons Learned from CISA’s Recent GitHub Leak
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository…
-
Effective Patch Management Strategies: 7 Best Practices | Huntress
Stop letting bad actors exploit old bugs. Build a practical patch management strategy to keep them out and learn to stay secure without all the fluff.
-
A Bridge Not Too Far!
On our Irkutsk–Yakutsk–Magadan–Yakutsk winter road-trip we finally rolled into civilization and were fast approaching Yakutsk Airport, from where we d soon have the good fortune to be heading home. But before the triumphant finale…
-
13th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 13th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES U.S. auto insurer AssuranceAmerica has disclosed a data breach affecting approximat…
-
Threat Actors Achieve Persistence After SQL Injection
See how a threat actor used SQL injection and BadIIS to gain persistence, disable Windows Defender, and quietly install a cryptominer.
Last fetch 11m ago · 1 new · 2 source error(s)