What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,952 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 4h ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 15h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 2d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
-
Polish data centre plans to send its waste heat to the neighbours
As Europe swelters in a heatwave, residents probably don’t want to hear about ways to make their homes even hotter, but that’s what Polish property developer Citylink is talking about, with plans to dump waste heat from a new data…
-
Coast Guard says it is monitoring cyberattack that disrupted North Carolina’s ports
The cyberattack hit gate systems at all three North Carolina ports, as officials continue investigating the breach and its effects on operations. The post Coast Guard says it is monitoring cyberattack that disrupted North Carolina…
-
Real emails, hijacked payments: Two H1 2026 attack chains
Gen's H1 2026 Threat Report examines two separate attack chains. One used compromised business inboxes and browser manipulation in a banking-malware campaign, while the other used clipboard hijacking to redirect cryptocurrency pay…
-
North Carolina Ports confirms cyberattack disrupting operations
The North Carolina Ports Authority has confirmed that a cyberattack disrupted IT systems and slowed operations at Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. [...]
-
Cybercrime Magazine’s Best Convos At Black Hat USA 2026
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 7, 2026 – Watch at Cybercrime.TV The premier Cybersecurity event of the year, Black Hat USA 2026 in Las Vegas, ended yesterday and the Cyb…
-
The Good, the Bad and the Ugly in Cybersecurity – Week 32
Snowflake hacker's guilty plea covers a 100M-record breach, Mythos 5 spends 34 hours trying to backdoor real code, and ChainDrop's worm spreads via npm.
-
Growing Up The Hard Way
Open Source had a great childhood. For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and never once thought about who was watching. It ran the kind of lemonade stand that took IOU…
-
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw has existed since 2008. The fix…
-
New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exh…
-
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key …
-
ICE Is Buying Access to Credit Card Records
Through data brokers, ICE is buying the information you provided to open a credit card.
-
Black Hat USA 2026 – Summary of Vendor Announcements (Part 4)
Companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas. The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 4) appeared first on SecurityWeek .
-
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Entra ID researcher Dirk-jan Mollema demonstrated that malware already running in a signed-in Windows session can silently use the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID. The attacker can the…
-
TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
A new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training…
-
US fuel gauge exposure fell by more than half in three months
Every month for the better part of a year, about 4,800 US internet addresses answered a query in the protocol that fuel tank gauges speak. In June the number was 2,354. The count fell across April, May, and June, all three months …
-
The next smart move for SMB partners
For small and mid-sized businesses (SMBs), technology investment has entered a new phase. The conversation has moved beyond buying hardware, moving to the cloud or adopting the latest software platform. Today, SMBs are demanding m…
-
Government calls in Chorus debt to fund roads, classrooms
The New Zealand government has finalised plans to sell debt it holds in Chorus, valued at $702 million, to help fund other infrastructure projects, including roads and classrooms. In a joint statement, Minister of Finance Nicola W…
-
The Honest Curator
He fabricates nothing. The lie is in the hanging, and no fact-check can reach it.
-
A/NZ market helps shape Coro’s next phase of channel growth
Cyber security vendor Coro is using lessons learned from its first year in Australia and New Zealand (A/NZ) to help drive its global channel strategy, with the company claiming stronger-than-expected growth as managed service prov…
-
datasette-auth-tokens 0.4a13
Release: datasette-auth-tokens 0.4a13 Upgraded for compatibility with `sqlite-utils 4. Tags: datasette
-
datasette-auth-tokens 0.4a13
Release: datasette-auth-tokens 0.4a13 Upgraded for compatibility with `sqlite-utils 4. Tags: datasette
-
ChainDrop: Inside a Self-Propagating npm Worm
Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42 .
-
The Coordination Gap: How Attackers Are Outpacing Law Enforcement
The fight against cybercrime continues because threat actors have adapted their strategies to avoid deterrents, but law enforcement still operates in silos.
-
Capitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scams
A Senate Foreign Relations Committee hearing explored how 13 federal agencies and myriad foreign governments are wrestling with the problem. The post Capitol Hill wants to know if executive branch, foreign allies coordinated enoug…
-
What Is Zero Trust Security? A Guide for Businesses
Zero trust security assumes no user or device is trusted by default. See how Huntress enforces the model with Managed EDR and ITDR for lean IT teams.
-
Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online
A scan of internet-connected industrial equipment found 4,400 exposed PLCs, including 22 in cities recently targeted by water system attacks. The post Despite federal warnings, thousands of U.S. industrial controllers used in wate…
-
From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture
Two former chief security officers of the Democratic National Committee explain that a strong security-first mindset requires executive support — and a dose of absurdity.
-
datasette 1.0a38
Release: datasette 1.0a38 This release fixes a SQL injection security issue that affects Datasette instances that serve a mixture of public and private tables in the same database, with access configured using the Datasette permis…
-
datasette 1.0a38
Release: datasette 1.0a38 This release fixes a SQL injection security issue that affects Datasette instances that serve a mixture of public and private tables in the same database, with access configured using the Datasette permis…
-
datasette 0.65.3
Release: datasette 0.65.3 Back-ported the SQL Injection security fix from 1.0a38 . Tags: datasette
-
datasette 0.65.3
Release: datasette 0.65.3 Back-ported the SQL Injection security fix from 1.0a38 . Tags: datasette
-
Ransom Cartel creator sentenced to 16 years in prison
Maksim Silnikau participated in cybercrime since at least 2005. He ran Ransom Cartel from 2021 until his arrest in 2023. The post Ransom Cartel creator sentenced to 16 years in prison appeared first on CyberScoop .
-
Simon Willison on Technical Blogging
Simon Willison on Technical Blogging I was interviewed by Cynthia Dunlop for her "Write that blog!" series back in January, but I just realized I never linked to the interview from my own blog! It includes my answers to the follow…
-
Simon Willison on Technical Blogging
Simon Willison on Technical Blogging I was interviewed by Cynthia Dunlop for her "Write that blog!" series back in January, but I just realized I never linked to the interview from my own blog! It includes my answers to the follow…
-
Hackers grow more willing to destroy, not just disrupt, OT systems
Experts said the alarming trend has further stressed infrastructure providers that are already struggling with strong passwords, comprehensive logging and other basics.
-
Canadian Man Pleads Guilty in Snowflake Extortions
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud dat…
-
New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs
An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using it, re-poisoning the predictor after the defense has run. MIT CSAIL researcher…
-
Snowflake Hacker Pleads Guilty in US Court
Connor Riley Moucka was extradited to the United States in July 2025 after he was arrested in Canada. The post Snowflake Hacker Pleads Guilty in US Court appeared first on SecurityWeek .
-
Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam
A ClickFix scam tricked a Mac user into running a Terminal command that installed Go-based malware able to steal Keychain passwords and drain crypto wallets.
-
Extreme Heat Warning: Summer 2026 Cybersecurity Venture Capital Investments
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 6, 2026 – Cybersecurity VC Deal Flow Tracker During Black Hat USA 2026 at the Mandalay Bay Convention Center in Las Vegas this week, outdo…
-
Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities
Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network. Its August 3 scan counted 4,40…
-
CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps
Coinspect has identified CryptoJS.lib.WordArray.random() as the weak random number generator behind the Ill Bloom wallet drains. Introduced in the JavaScript cryptography library 12 years ago, the function supplied weak entropy th…
-
Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses
Cybersecurity researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address. Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to ensure user…
-
Adversarial Clothing Designed to Fool Facial Recognition Systems
There are many companies manufacturing adversarial clothing designed to confuse facial recognition systems. It s a cool idea, but I worry that it s mostly security theater: Our patterns play with that chaos, confuse algorithms and…
-
The water sector just got it’s wake-up call. Again.
The attack on water systems across seven states was preventable. Utilities had the playbook. They didn't use it. The post The water sector just got it s wake-up call. Again. appeared first on CyberScoop .
-
AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model
Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent's tools with no check that a model turn had authorized them. In several of the attack pa…
-
Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
Cybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models from Zbtlink. According to a new report from VulnCheck, the implant appears in all 21 firmware images …
-
Fresh form factor presents plentiful opportunities for HP partners
HP’s latest bid to reinvent the desktop presents opportunities for partners to start fresh conversation with customers about the future of PCs in their business. This is according to HP’s head of personal systems for Australia and…
-
Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency
Graham gets a phone call from the police. Well, someone who sounds convincingly like the police. There's just one small problem: what they really want is the 24-word seed key to Graham's cryptocurrency wallet. Meanwhile, if you've…
-
Thousands of servers can be backdoored by exploiting buggy motherboard controllers
Baseboard management controllers from the world's biggest manufacturers are a security mess.
Last fetch 8m ago · 0 new · 2 source error(s)