What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,950 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 4h ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 14h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 2d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
-
Previously unseen entry vector used to breach Polish energy plant
The December 29 cyberattack on a Polish combined heat and power (CHP) plant was the first observed case of attackers gaining access to an OT network through a private APN, according to CERT Polska. The private APN is a dedicated m…
-
Cybersecurity jobs available right now: August 11, 2026
CTI Detection Engineer Department of Parliamentary Services Australia Hybrid View job details As a CTI Detection Engineer, you will lead the detection lifecycle by identifying detection gaps, developing and validating detection lo…
-
One NZ reshuffles leadership team ahead of CEO change
One New Zealand is revamping its executive team as Nick Judd prepares to become chief executive officer on 31 August, taking over from Jason Paris. The changes will see current chief technology officer Kieran Byrne become chief fi…
-
Mercury adds 50,000 mobile connections through bundled services
Mercury has reached 50,000 connections for its mobile service, powering the electricity company’s ambitions to become a leading multi-product home services provider. According to Mercury, the growth in its mobile offering supports…
-
The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications
Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution. The post The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Oper…
-
Multistate Water System Attacks Widen, Iran Suspected
Attacks targeting water systems just keep flowing across a dozen states, against ill-secured, Internet-exposed PLCs.
-
BdThemes plugins supply-chain hack creates rogue WordPress admins
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create rogue admin accounts. [...]
-
Meta’s Ray-Bans are being banned from pubs, restaurants, and theatres
A growing number of UK venues have decided to act against privacy-busting smart glasses. Read more in my article on the Hot for Security blog.
-
The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists
It's time to turn from CVSS-backed patching to choke-point patching focused on breaking chains to critical assets.
-
Meta Must Stop Silencing Reproductive Health Information
Access to accurate information about reproductive and maternal health can be critical. But on Meta's platforms, simply talking about prescription medication, abortion care, or one's own medical experiences can be enough to trigger…
-
Outdated Cybercrime Laws Put Security Researchers at Risk
A public policy expert mapped global cybercrime laws to develop a five-point framework for protecting ethical hackers and good-faith security research.
-
Sherlock Holmes was the “OG” Social Engineer
The crime solver wore disguises, spied on targets, and built intelligence networks long before modern-day tactics emerged. He has lessons for today’s ethical- and nonethical-hat hackers.
-
Poland uncovers second heat plant cyberattack that went hidden for months
The incident occurred on the same day as coordinated cyberattacks struck more than 30 other renewable energy installations and a larger heat plant, as Poland publicly disclosed in January.
-
Senate Democrats introduce bill to distribute $300 million annually to shore up water system cybersecurity
Two Democratic senators introduced legislation that would allocate $300 million each year to fund cybersecurity improvements for the water and wastewater sector.
-
Russian military hackers pose as recruiters to target Ukrainian IT workers
Ukraine’s computer emergency response team, CERT-UA, said Saturday that the campaign has been running since at least May and is linked to Sandworm, the notorious hacking unit associated with Russia’s GRU military intelligence agen…
-
UK man tied to The Com sentenced for abusing 117 victims
Justin Swaddle, who was a minor when he committed the crimes, coerced children across multiple countries into self-harm and sexual abuse using threats tied to their personal information, authorities said. The post UK man tied to T…
-
Civil-society initiative will pay cybersecurity vendors to protect rural water systems
The group is seeking philanthropic grants, but its founder said the federal government ultimately needs to step in.
-
A researcher bought noreply.net. Companies started sending him secrets.
Companies treat some email domains as digital trash cans, despite the risks.
-
10th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 10th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES North Carolina Ports, the US authority operating the ports of Wilmington, Morehea…
-
British ‘Com’ member who abused more than 100 girls worldwide jailed for two years
Justin Swaddle, of Leeds in northern England, targeted 117 female victims aged 13 to 17, according to the National Crime Agency.
-
Microsoft Entra ID is removing an extra MFA hurdle for Windows Hello and macOS PSSO users
Microsoft is changing how Entra ID handles MFA for people who sign in with Windows Hello for Business (WHfB) or macOS Platform Single Sign-On (PSSO). The rollout reaches worldwide and GCC tenants starting early October 2026, with …
-
Five Years, 88,000 Backdoors, and a Pair of Handcuffs: Inside the Global Manhunt That Ended in an Arrest
Go inside Huntress and the FBI’s five-year pursuit of Silk Typhoon, from 88,000 Exchange backdoors to an arrest and a wider fight against cybercrime.
-
Member of The Com sent to prison for blackmail, sextortion
A member of "The Com," a loose-knit online cybercrime collective that targets children and teenagers, has been sentenced to two years in prison for blackmail and sextortion offenses against nearly 120 victims worldwide. [...]
-
Top 5 B2B Cybersecurity YouTube Channels In 2026
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 10, 2026 – Cybercrime Magazine YouTube channel Out of the pure play cybersecurity b2b focused media outlets and event producers with YouTu…
-
New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead…
-
LexisNexis shuts down services after suspicious activity on servers
LexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor. [...]
-
New Jersey, Alabama Join States Targeted in Water Cyberattacks
Hackers linked to Iran targeted industrial control systems (ICS) at water facilities in at least a dozen US states. The post New Jersey, Alabama Join States Targeted in Water Cyberattacks appeared first on SecurityWeek .
-
Python Now Has a Post-Quantum Encryption Library
This is good : Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency , we implemented support for ML-KEM, the NIST-standard key-establishment primitive, …
-
Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility
CERT.PL said this appears to be the first instance of a private APN being used as an attack vector. The post Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility appeared first on SecurityWeek .
-
IT threat evolution in Q2 2026. Non-mobile statistics
The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as internet of things (IoT) devices, during Q2 2026.
-
IT threat evolution in Q2 2026. Mobile statistics
This report contains mobile threat statistics for Q2 2026, along with noteworthy discoveries and quarterly trends: the Anatsa banker and a transition to droppers.
-
Corporate Data Stolen in Levi Strauss Cyberattack
Using social engineering, a threat actor accessed the computers of three employees and exfiltrated data from them. The post Corporate Data Stolen in Levi Strauss Cyberattack appeared first on SecurityWeek .
-
Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been observed delivering a browser wallet and credential stealer. The names of the ex…
-
GitHub Dependabot malware alerts now cover eight ecosystems
GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no such warning, because GitHub s malware detection only ever watched one ecosys…
-
Product showcase: Enpass Password Manager breaks away from the proprietary cloud model
Enpass is a password manager that stores passwords, passkeys, payment cards, identities, secure notes, software licenses, and other sensitive information in encrypted vaults. Vaults remain on the device or in a cloud storage servi…
-
Contact Energy and CDC aim to build data centre on site of former Stratford gas power plant
Contact Energy and data centre operator CDC are exploring the option of building a 250 MW data centre together on the site of a defunct gas power plant in the Taranaki town of Stratford. In a statement released to the NZX, the ene…
-
Canon Business Services A/NZ grabs Matt Clarkin as sales GM
Canon Business Services (CBS) Australia and New Zealand (A/NZ) has hired Matt Clarkin as general manager of sales and marketing. Coming after a six-month stint at Avanade, Clarkin joins the company with over 26 years of experience…
-
Over 400M GB used on Spark subsidised broadband offer in first decade
Since its launch in 2016, Spark’s subsidised prepaid broadband programme, Skinny Jump, has provided access to around 418 million gigabytes of data and now connects one in five New Zealand households without home internet, the telc…
-
Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All
Two security researchers bought cheap domains—including noreply.net and deleteduser.com—and set up email listening services. Hundreds of companies are sending them corporate secrets.
-
Quoting John Gruber
Me, I try to get into the mindset of playing live music, not recording a studio album. Except when I’m writing a piece where I really want it to be an album. Those aren’t rare , per se, but they’re occasional . If I tried to make …
-
Quoting John Gruber
Me, I try to get into the mindset of playing live music, not recording a studio album. Except when I’m writing a piece where I really want it to be an album. Those aren’t rare , per se, but they’re occasional . If I tried to make …
-
Friday Squid Blogging: Arctic Bobtail Squid Video
Nice video of the Arctic bobtail squid. As usual, you can also use this squid post to talk about the security stories in the news that I haven t covered. Blog moderation policy.
-
Water utilities group partners with DEF CON offshoot for Water Watch Center
The National Rural Water Association and a group of cybersecurity experts have formed a program to help cash-strapped utilities face the increase in threats to their systems.
-
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection ch…
-
US cyber ambassador nominee Cassady confirmed in Senate
NTIA official Adam Cassady becomes the second person confirmed to be the State Department's ambassador-at-large for cyber policy.
-
Experts say healthcare faces cybersecurity crisis: ‘These are patient safety issues’
Regulatory failures, funding constraints and industry consolidation have created serious hacking risks.
-
New Mexico judge orders Meta to pay $567 million in kids online safety case
The money will be used to create a fund to mitigate social media harms, including by carving out $420 million for treatment for New Mexico youth who have been hurt on the platforms.
-
Breach of Confidence: 07 August 2026
I ve spent the week explaining to people that stateless protocols are not a commentary on government, and I m not sure I ve convinced anyone. One Protocol To Rule Them All MCP 2.0 has gone stateless. One request instead of two, no…
-
Levi Strauss & Co. says hackers stole corporate data in cyberattack
Levi Strauss & Co. (Levi's) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines. [...]
-
Polish data centre plans to send its waste heat to the neighbours
As Europe swelters in a heatwave, residents probably don’t want to hear about ways to make their homes even hotter, but that’s what Polish property developer Citylink is talking about, with plans to dump waste heat from a new data…
Last fetch 11m ago · 0 new · 2 source error(s)