What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,952 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 5h ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 16h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 2d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
-
Canadian pleads guilty to Snowflake cloud data-theft attacks
A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. [...]
-
Snowflake hacker pleads guilty, faces up to 32 years in prison
Connor Moucka obtained almost $500,000 for playing a key role in one of the most widespread and damaging cyberattack sprees on record. The post Snowflake hacker pleads guilty, faces up to 32 years in prison appeared first on Cyber…
-
CSS: The Hidden Threat Lurking in Your Inbox
CSS was once just about design. Now researchers warn it's powerful enough to exfiltrate data from webmail — and some vendors aren't prepared.
-
Tom Cotton prods Treasury for tax code tweaks to modernize OT
The Senate Intel Committee chair wrote to Treasury Secretary Scott Bessent about changes to spur investment in aging technology to better guard against cyberattacks. The post Tom Cotton prods Treasury for tax code tweaks to modern…
-
15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning
Researchers are calling attention to the risks inherent in automated network device provisioning, using a world-leading device manufacturer as a case study.
-
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watchi…
-
DHS Is Hiring Bounty Hunters to Find and Photograph Deported People’s Homes Abroad
Homeland Security told immigrants that leaving the US would wipe out fines it claims they owe. Now it wants private investigators to find them in their home countries and collect.
-
Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)
Learn why KuppingerCole named Microsoft a Leader in its Leadership Compass: Cloud Native Application Protection Platforms report. The post Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Applica…
-
Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)
Learn why KuppingerCole named Microsoft a Leader in its Leadership Compass: Cloud Native Application Protection Platforms report. The post Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Applica…
-
Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum …
-
History of Hacking: The ILOVEYOU Computer Worm
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 4, 2026 – Watch the YouTube short ILOVEYOU , sometimes referred to as the Love Bug or Loveletter, was a computer worm that infected tens o…
-
Open-source software’s archenemy TeamPCP goes back further than anyone thought
Oligo Security uncovered evidence of a long operational history, including multiple previous attacks it traced to the same attacker infrastructure and tools. The post Open-source software’s archenemy TeamPCP goes back further than…
-
Five Stars, Five Draft Deferments
On the president's new clothes
-
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed. The "evil …
-
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
Cybersecurity researchers have disclosed what has been described as a "long-standing supply chain attack" on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users. According to…
-
Why Aren’t Things Worse?
Dense branching mass compressed through a mechanical iris bottleneck/images/why-arent-things-worse-header.webp/images/why-arent-things-worse-header.webp One of the things I’ve been thinking about for years, but more acutely now be…
-
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates. This analysis details the attack chain, affected environments, and prac…
-
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates. This analysis details the attack chain, affected environments, and prac…
-
Mobile Ad Software Encourages Location Data Sharing, EFF Report Finds
Developers Must Beware of Ad Libraries that Betray Users’ Privacy SAN FRANCISCO – Some software development kits (SDKs) provided by advertising companies to help developers monetize their apps are automatically feeding users’ loca…
-
Developers: Beware of Ad Libraries that Betray Your Users’ Location Privacy
Across mobile platforms, advertising companies provide developers with software development kits (SDKs) that make it easy to monetize their apps. But those same SDKs can automatically feed users’ location data into ad systems that…
-
PipeNetwork/minimax-h3-mlx
PipeNetwork/minimax-h3-mlx MiniMax released MiniMax-H3 two days ago - they describe it as a "a general-purpose, omni-modal generative system", which in practice means it accepts text, images, audio and video and can use them to ge…
-
PipeNetwork/minimax-h3-mlx
PipeNetwork/minimax-h3-mlx MiniMax released MiniMax-H3 two days ago - they describe it as a "a general-purpose, omni-modal generative system", which in practice means it accepts text, images, audio and video and can use them to ge…
-
Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook
The attacks use diverse social engineering lures and rotating payloads to deliver ScreenConnect for persistent remote access to compromised networks.
-
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device A…
-
Landmark Deal Would Officially Add Laser Weapons to US Army Arsenal
Facing a growing drone threat, the Pentagon is poised to sign a first-of-its-kind contract for “Enduring High Energy Lasers”—and make directed energy weapons an official part of the Army’s kit.
-
Technology's Power in the Hands of the People
In the scorching heat of every Las Vegas summer, EFF joins thousands of hackers, makers, policy analysts, and activists for the world's largest computer security gathering. If you're there during this summer security week, be sure…
-
Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to…
-
Bank of America Phishing Email Delivers ScreenConnect Malware
A fake Bank of America phishing email kicks off a multi-stage malware infection chain. See how one convincing bank scam unravels.
-
Almost Half of Malware Samples Communicate Direct to IP
Nearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these threats. The post Almost Half of Malware Samples Communicate Direct to IP appeared first on Un…
-
How legitimate cloud platforms enable phishers to bypass MFA
We cover a cloud-based AitM attack scenario leveraging service workers and Ultraviolet, and provide detailed phishing hosting statistics across platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS.
-
Device Code Phishing Up 1,500% in 2026; Vishing Doubles
Newer social engineering techniques help attackers ignore entrenched security controls and limit the evidence they leave behind.
-
EFF Joins 18 Civil Rights Organizations Calling on Governor Hochul to Reject the Stealth Crawler Prohibition Act
EFF joined a group of 18 civil society organizations to send a letter encouraging New York Governor Kathy Hochul to veto Senate Bill 9934A, the New York Stealth Crawler Prohibition Act . The letter states: While framed as a measur…
-
[Webinar] Tales from the Frontlines: An exclusive briefing on Q2 incidents
Register for an exclusive, unrecorded 30-minute webinar to review the most high-impact incidents Talos IR faced in Q2.
-
Devtools must be open source (exe.dev)
My comment on Devtools must be open source (exe.dev) Hacker News. One of the arguments for open source software for end-users has always been the freedom to examine and modify how that software works. The reality for most people -…
-
Metasploit Pro 5.1 Released
Today marks the release of Metasploit Pro 5.1 - building upon the foundation laid in 5.0, adding new evasion primitives for HTTP Meterpreter payloads, support for tracking service hierarchies, a deeper and more interactive Network…
-
EFF at BSidesLV, Black Hat, and DEF CON 👨💻
It's time. Time for tinkerers, security researchers, hackers, and fellow nerds to gather together in signature black hoodies and utilikilts to beat the heat in Las Vegas for the summer security conferences: BSidesLV , Black Hat US…
-
Is There Really a Fix for CISO Fatigue?
Accountability without any real authority is driving CISO burnout, and organizations need to take notice.
-
Why App Control Fails Most Teams and How Managed ESPM Fixes It
App control works, but most solutions are built for enterprise budgets and headcount. See how Huntress Managed ESPM makes proactive endpoint hardening accessible for MSPs and small IT teams.
-
3rd August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30…
-
Top Cybercrime And Cybersecurity Podcasts For CISOs In 2026
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 3, 2026 – Read the full story in Reddit The Cybercrime Magazine Podcast stands out as a leading resource for CISOs looking to stay updated…
-
An analysis of incidents at Brazilian educational institutions
Kaspersky expert provides statistics and details on several incident response cases at educational institutions in Brazil, as well as tips for schools and universities on how to stay safe.
-
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
Explore how passkey implementation gaps undermine security when relying parties fail to validate the User Verified flag, reducing MFA to a single factor. The post Pass the Passkey: A Novel Attack Surface in Passwordless Authentica…
-
ICE Collected Nearly 1 Million People’s DNA Last Year—Including Young Children
Internal documents show ICE's DNA collection has skyrocketed in the second Trump administration. Now hundreds of thousands of people never convicted of a crime are in an FBI criminal database forever.
-
Welcoming the Nepalese Government to Have I Been Pwned
Today, we welcome the 47th government onboarded to Have I Been Pwned s free gov service: Nepal. Their National Cyber Security Centre now has access to monitor Nepalese government domains against the data in HIBP. This gives the NC…
-
Weekly Update 515
Apparently, Aussies are so obsessed with coffee that it s referred to as the coffee capital of the world down here (some bits, at least). But what about Italy? people ask. Having spent a lot of time in a lot of Italy, no, it s jus…
-
condense-json 1.0
Release: condense-json 1.0 I'm trying to get braver at releasing 1.0 versions. This little library is a year and a half old now - I've applied some sensible and non-disruptive fixes and shipped the big 1.0 for it. Here's an exampl…
-
Cybersecurity’s Uncomfortable Truth About “We Tested It”
When I built one of the earliest pentesting firms, back in the 1990s, a serious attack was a slow craft. It took skilled people days, sometimes weeks, to study a target, find the weaknesses, work out how to chain them together, an…
-
8 Best Password Managers (2026), Tested and Reviewed
Keep your logins locked down with our favorite password management apps for PC, Mac, Android, iPhone, and web browsers.
-
datasette-apps 0.2a0
Release: datasette-apps 0.2a0 Changes that improve Datasette Apps when created and edited using Datasette Agent : New app_debug() tool allowing agent to open an app (invisibly) and test it using JavaScript. #33 New app_list() tool…
-
Defcon's new badge is a security key you can see inside
A removable chip lets hackers inspect their badge—and keep using it after Defcon.
Last fetch 7m ago · 0 new · 2 source error(s)