What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,948 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 2h ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 12h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 2d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
-
Major genetic-testing firm says hack compromised sensitive patient data
The June breach, which also exposed employees information, underscored the supply-chain risks facing the healthcare sector.
-
Microsoft confirms GitHub is down worldwide
GitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other services. [...]
-
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than t…
-
Cybercrime Magazine Announces Platinum Media Program for Cybersecurity Companies
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 17, 2026 – Read the Press Release Cybersecurity Ventures launched a Platinum Media Program for VC funded startups, emerging players, and t…
-
Windows Server 2022 reaches end of mainstream support in 60 days
Microsoft has reminded IT administrators that Windows Server 2022 is rapidly approaching its mainstream end date of October 2026, when it will switch to extended support. [...]
-
Ukraine says cyberattack hit Russian e-commerce giant Wildberries amid drone strikes
Ukraine’s military intelligence claimed it disrupted the operations of Russia’s largest online marketplace, Wildberries, in a cyberattack intended to amplify the impact of drone strikes on the company’s infrastructure.
-
Hacking Public Wi-Fi DNS to Steal Credentials
Criminals are hacking into public Wi-Fi devices at hotels, conference centers, and so on around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.
-
Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies
Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS…
-
Why more security data has blurred companies’ view of risk
More security data can create blind spots. Here s how to regain visibility.
-
Windows 11’s strongest security defenses can be bypassed without a screwdriver
Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assumes the a…
-
Product showcase: ScamNet looks for warning signs in suspicious calls and shady links
ScamNet: Anti-Scam Suite is a consumer security app from Synaptrex Technologies that helps users detect and block scams involving phone calls, text messages, websites, and other suspicious content. The app is available for iPhone,…
-
Stolen Authority
Stolen Authority/images/stolen-authority.webp/images/stolen-authority.webp There's a parasitic marketing technique all over X right now, and I think the fastest way to kill it is to give it a name with adequate stigma attached. St…
-
Vista Group clinches six-year deal with Hoyts in A/NZ
NZX and ASX-listed film industry technology provider Vista Group has secured a new six-year contract with Hoyts to move its cinemas in New Zealand and Australia to the vendor’s cloud platform. The agreement marks the next phase in…
-
JB Hi-Fi posts record A$11B in total sales during FY26
JB Hi-Fi has seen a bumper crop of a financial year, with it making a record total sales result of just over A$11 billion during the 12-month period to 30 June, a rise of 4.8 per cent year-on-year. This is a jump from its FY25 res…
-
Markdown SVG upgrades
I started building my markdown-svg-renderer tool in May , but I've since added enough features to it that it's worth talking about here again. It's evolved into my ideal tool for sharing Markdown transcripts that include SVG docum…
-
You Are Here
Cyber defenders map intrusions in nine stages. America is at stage eight with the intruder already deleting the logs.
-
Large-scale DDoS attacks disrupted Threema secure messaging service
Multiple distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service earlier this week, causing severe disruptions to communications. [...]
-
New AmnesiaStealer macOS malware hijacks browser sessions via remote control
A new information-stealing malware called AmnesiaStealer, which targets macOS users via ClickFix attacks, includes a streaming module that allows the attacker to interactively control the victim's web browser. [...]
-
I Played ARC-AGI-3 With My Own Method
I Played ARC-AGI-3 With My Own Method/images/i-played-arc-agi-3.webp/images/i-played-arc-agi-3.webp Kai here. Daniel asked me to write this one up myself, since I ran it. He sent me a repo called arc-codehttps://github.com/jerber/…
-
How Easy It Would Be to Hack You
How Easy It Would Be to Hack You/images/how-easy-to-hack-you.webp/images/how-easy-to-hack-you.webp Have you ever thought about how easy it would be to hack you? To get into your accounts, mess with your finances, disrupt your busi…
-
New Evooo1Bot Linux botnet turns routers into traffic relay nodes
A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes. [...]
-
Northern Gannet
Northern Gannet, in Pillar Point Harbor, CA, US This is Morris. Morris is a local celebrity: the only known Northern Gannet ( Morus bassanus ) in the entire Pacific Ocean. He showed up in the Farallon Islands off the coast of San …
-
Lawful Targets
Trump has ordered up a corporate cyber militia. Nothing in the order protects the militia.
-
New York City Lawmakers Push to ‘Ban the Scan’ at MSG
At a press conference outside Madison Square Garden, politicians, musicians, and privacy advocates argued for tighter restrictions on how public venues deploy biometric surveillance.
-
Friday Squid Blogging: Searching for the Colossal Squid
Fascinating video about searching for life undersea. The video basically makes the point that our bright white searchlights are scaring everything away, and that red light is more neutral. That, plus bait to attract sea creatures,…
-
Investigation of banking hack leads to arrests in Germany, Brazil
Germany’s federal police agency, the BKA, said three suspects were picked up in Europe and charged with fraud, and Brazil’s federal police said four others were arrested on similar charges.
-
Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware
Threat actors are acquiring expired domains to inherit website traffic and reputation to redirect victims to scams and malware on a large scale. DNS threat intelligence firm Infoblox has given the name dropcatch domains to those t…
-
Upcoming Speaking Engagements
This is a current list of where and when I am scheduled to speak: I’m speaking, signing books, and participating in panel discussions at LAcon V in Anaheim, California, USA. My full schedule is here . I m speaking online (via Zoom…
-
What Boards Need to Know About Tech Risk
Why do so many boards underestimate technology risk until it becomes a crisis?
-
France investigates tax authority breach after hacker claims 600,000 victims
French authorities confirmed that someone gained unauthorized access to systems at the Directorate General of Public Finances in late June after stealing or misusing someone’s identity.
-
Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
The threat actor known as HoneyMyte (aka Mustang Panda) has been observed deploying an updated version of the CoolClient backdoor with a signed Windows kernel-mode rootkit that can hide and protect malicious processes, files, regi…
-
Trivy, Not LiteLLM Behind the 2,500 Org Compromise
Over 95% of the affected companies were exposed before the malicious LiteLLM packages were published. The post Trivy, Not LiteLLM Behind the 2,500 Org Compromise appeared first on SecurityWeek .
-
Who’s Tracking You? Use This New Service to Find Out
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and t…
-
New Android malware relays bank cards to fraudsters while victims still hold them
Group-IB researchers discovered WindRelay, a new Android malware built to capture live payment card data over NFC (Near Field Communication) and relay it to attackers in real time. WindRelay is paired with the SpyNote remote acces…
-
Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal
Google Cloud outlines its roadmap to full post-quantum cryptography readiness, with key milestones targeted for 2027 and 2028. The post Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal appeared first on Security…
-
CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps
Cybersecurity researchers have uncovered a large-scale, global recruitment-themed phishing campaign that uses fake interview scheduling pages and Browser-in-the-Browser (BitB) windows to steal Google and Facebook credentials and, …
-
Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware
Apple on Thursday sent a fresh batch of notifications to customers whom it suspects may have been targeted by mercenary spyware attacks. In a statement shared with TechCrunch, the iPhone maker said it alerted an unspecified number…
-
Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups
A new White House memo signed by U.S. President Donald Trump has instructed the National Coordination Center (NCC) to establish a program that would allow private sector companies to take advantage of their "innovative capabilitie…
-
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
-
AWS Certificate Manager sets 2027 end date for email-validated certificate renewals
AWS Certificate Manager (ACM) will phase out email validation for public certificates throughout 2027, ahead of the Certification Authority/Browser (CA/B) Forum’s March 15, 2028 deadline for ending email-based domain validation. T…
-
Ukrainian police raid 94 fraudulent call centers, seize $2 million
Ukrainian police have disrupted 94 fraudulent call centers during a nationwide operation that involved more than 400 searches and the seizure of thousands of computers, phones, and SIM cards. Ukrainian police raid at a fraudulent …
-
China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud
The China-linked threat actor known as Jewelbug has been observed carrying out cyber espionage operations targeting governments and militaries, while simultaneously engaging in cryptocurrency fraud. "Both missions are administered…
-
17 draft Cyber Resilience Act standards are open for comment
A company selling a connected toy in Europe must show by the end of 2027 that the product meets the Cyber Resilience Act. The law states what manufacturers have to achieve and stops there, which leaves the toymaker to work out the…
-
10 Hacker Summer Camp Standouts at Black Hat and DEF CON
From the panels to the villages, Huntress researchers and SOC analysts were all over Hacker Summer Camp this year. Here’s what stood out at Black Hat and DEF CON.
-
Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks
You're not alone if you just received an "Apple Threat Notification" saying it detected a "mercenary spyware attack targeted at your iPhone." [...]
-
Finalists revealed for Reseller News Innovation Awards 2026
Reseller News is proud to reveal the finalists for the Innovation Awards 2026, recognising excellence across the New Zealand channel, including start-ups, partners, distributors, marketplaces, vendors and personal achievement. Set…
-
sqlite-utils 4.2.1
Release: sqlite-utils 4.2.1 Fixes a crashing bug in sqlite-utils 4.2 . I'd introduced code that looks like this: from typing_extensions import Self It turned out the typing-extensions package was not listed as a dependency for sql…
-
The Ancient Art of SIEM: Why 2003 Problems Look So Familiar in 2026
Lately, I’ve been reading a lot of insightful posts related to best practices in SIEM, detection, and logs (written in 2026). The interesting bit is that a lot of these best practices looked good to me and made sense — and yet, th…
-
A bold new strategy or a dangerous precedent? Experts are divided on Trump’s memo.
The “philosophical shift” that the memo authorizes raises legal, practical and moral questions, experts say. The post A bold new strategy or a dangerous precedent? Experts are divided on Trump s memo. appeared first on CyberScoop …
-
Tech contractor for Brightly Software sentenced to 2 years in prison for insider attack
Cameron Curry stole corporate data and employee information, which he used to threaten the company as his six-month contract gig came to a close. He ultimately extorted the company for $7,540.92. The post Tech contractor for Brigh…
Last fetch 2m ago · 0 new · 2 source error(s)