What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,952 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 6h ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 16h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 2d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
-
Friday Squid Blogging: Squid Helps Discover New Marine Species
The Squid is a new scientific machine : One of the technological breakthroughs was the onboard use of a spinning wheel confocal microscope, nicknamed the Squid, which uses lasers to scan microscopic details of how organisms are pu…
-
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to traveler…
-
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to traveler…
-
Amending AB 1709 Doesn’t Fix It: California’s Social Media Ban Still Threatens Free Speech and Privacy
California lawmakers have amended A.B. 1709 , but the core problem remains: the bill is still a ban on social media access for youth under 16 , and it still threatens the privacy and First Amendment rights of all Californians. Pro…
-
The SCREEN Act Threatens Privacy Far Beyond Adult Websites
Update: On August 5, 2026, The Senate Commerce Committee voted 15-13 to advance this bill , but the bill did not advance because of a lack of Senators in attendance. EFF continues to oppose the bill. The Senate Commerce Committee …
-
EFF Guide to Recording Law Enforcement
This post is available as a printable one page handout in English and Spanish . Recordings of law enforcement, whether by bystanders or by those directly encountering officers, can be powerful tools of government accountability an…
-
The Morning After We Pull a Root of Trust, Nobody Owns It
The most valuable move any security team can make is building a certificate and key inventory.
-
Interpol Leverages Global System to Curtail Fraud Payments
When a fraudulent transaction occurs, law enforcement agencies must work quickly to halt payments before cybercriminals cash out.
-
DROP Platform Lets Californians Reduce Digital Footprint
Hundreds of thousands of California residents have already registered for the Delete Request and Opt-out Platform (DROP), which launches Aug. 1. Other states could follow if the process goes smoothly.
-
USA Fencing Lunges Into the Hidden Identity Challenge in Amateur Sports
The organization behind Team USA's Olympic/Paralympic fencing teams has automated identity verification to handle growing membership, cutting manual review time while ensuring athletes compete in the correct categories.
-
Device Code Phishing Keeps Evolving. Here’s What to Watch For
Huntress is tracking an evolving wave of device code phishing that abuses trusted Microsoft 365 sign-in flows. Learn the signals defenders should watch for and how to respond.
-
Breach of Confidence — 31 July 2026
I ve been thinking about the number of security products that promise to solve problems nobody actually has. Then I remembered that most actual problems don t have vendors. The government just made up a new crime A bloke at the US…
-
Network Anomaly Detection in KATA
An analysis of how Network Anomaly Detection (NAD) rules work within Kaspersky Anti Targeted Attack, using Kerberoasting and DNS tunneling attacks as examples.
-
The New Defcon Badges Pack a Unique Open Source Chip That Doubles as a Security Key
Created by legendary hardware hacker Andrew “bunnie” Huang, the badges for this year’s famed security conference aim to push the boundaries of security and transparency.
-
A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran
A memo obtained by WIRED, issued by the water utilities information sharing group WaterISAC, links dozens of cyberattacks against Minnesota water utilities to Tehran.
-
Minnesota Water Utility Attacks Expose Sector's Cyber-Risks
A likely Iran-backed actor targeted more than 30 community water systems in Minnesota in a sobering reminder of rising threats to US critical infrastructure.
-
You were onto something with “It’s the Climb,” Miley
Amy hikes Virginia’s most difficult trail and muses on the persistent challenges of cybersecurity. The two aren't dissimilar.
-
Incident Response Plans: What to Include & Why They Matter
An incident response plan is your organization's playbook for surviving a cyberattack. Learn what to include and how Huntress helps you stay ready
-
Metasploit Framework 6.5 Released
Today we’re proud to announce that Metasploit Framework version 6.5 has been released. Over the past two years, with the help of countless contributors, we’ve added 422 new modules along with a whole slew of new features. Malleabl…
-
$250M ARR Was Never the Goal. It Came From Staying True to Our Mission.
Hitting $250M ARR is a milestone, but it wasn't the goal. CEO Kyle Hanslovan reflects on Huntress' mission to protect the 99% and why staying true to it remains his top priority."
-
Hacker Summer Camp: What First-Timers Actually Need to Know | Huntress
Heading to Vegas for Hacker Summer Camp? Here are some insider tips for first-timers on navigating DEF CON, Black Hat, and BSides like a pro.
-
OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia
Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan networks, dump credentials, and keylogging.
-
Black Hat special: Rewind and revisit
Amy looks back at the incredible journeys that brought past guests to the world of threat intelligence.
-
Welcome to JFK, Please Lower Your Expectations
JFK airport looks like it was designed by a steering committee of tired men who only took the job because it paid well and gave them a crew to discuss their golf scores with. The entire setup before you get through security is old…
-
North Korea’s elite hackers turned on their own government – and got caught
For years, North Korea's state-trained hackers have been one of the world's most prolific robbers of banks - stealing huge sums of money from foreign financial instituions, draining cryptocurrency exchanges of billions, and funnel…
-
SE Asian Cybercriminal Syndicates Become a Global Power
The organized crime groups have moved from goods to services and continue to traffic people from at least 80 countries, costing nations in the region at least $88 billion in 2025 alone.
-
'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China
A premium-grade malware-as-a-service offering takes flight with multiple threat groups, building infostealers that drain victims' bank accounts.
-
Cybersecurity, Then & Now: A Visual Look at 20 Years of Change
Since 2006, Dark Reading has been at the forefront of covering cybersecurity. The more things change, the more they stay the same.
-
Smashing Security podcast #478: This job interview could destroy your company
You've been headhunted for a great job in cryptocurrency. All you have to do is complete a short online assessment - with your webcam on, of course, so they can verify who you really are. Which is ironic, because the person recrui…
-
Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission
HAWK withstood years of testing that had yet to uncover a fatal weakness found through Mythos.
-
Still Got My Nokia Somewhere Up There
I still have my Nokia 3210 somewhere. Not in a drawer I can easily reach but boxed up in the garage with the party decorations and a broken food processor I ve been meaning to fix since 2019. I know it s there because I packed it …
-
When AppSec Scanners Become a Supply Chain Attack Vector
New research shows how security scanners embedded in the software supply chain can be attacked to serve as a foothold for downstream attacks.
-
🏃 Fitness Tracker Privacy Fails | EFFector 38.14
Watches, bands, and rings—if you want to digitally monitor your fitness, more companies than ever are selling devices to do it. And more Americans than ever now own at least one wearable health device. But what are the companies t…
-
Reverse Engineering the Six Stages of MacSync Stealer and RAT
We reverse-engineered MacSync, a six-stage macOS stealer and RAT, recovered from attacker infrastructure after the victim’s host was taken offline.
-
Introducing Huntress Webhooks. Get Real-Time Security Alerts.
Huntress Webhooks push incidents and escalations straight to Slack, your PSA, or SIEM in real time with no polling. See how you can set them up in minutes.
-
Bent: How A Homeless Teen Became One Of The Cybercrime Industry’s Most Prolific Counterfeiters
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 29, 2026 – Listen to the podcast Bent is the story of John J. Boseak’s phenomenal life of crime. Inked from head to toe, with an addiction…
-
The Incompetence Defense
On the provenance and uses of Singh's Law
-
San Francisco: Don’t Fall for Industry Defense of Surveillance Pricing
The concept of “surveillance pricing” is just one part of a much larger problem and business model: corporations maximizing their profits by invading our privacy. The all-too-common business model is to systematically harvest, col…
-
Ghost Credentials Expose Cloud Systems to Hidden Identity Risks
Dormant nonhuman identities can create security blind spots, says security researcher Aleksandr Krasnov, who plans to release an open source tool next week at Black Hat USA 2026 that sniffs out trust paths.
-
Thousands of Data Center Controllers Open to Takeover
A host of Internet-exposed remote hardware management processors are subject to offline password-cracking attacks — and adversaries have taken note.
-
Why Are Gay Bars Building Databases of Their Patrons?
Recent reports have raised alarm about the use of PatronScan, an ID-checking and face-scanning system, at multiple LGBTQ+ bars in San Francisco’s Castro neighborhood. Much of the attention has focused on reports that the system ph…
-
The Floppy Disc Generation’s Data Problem
I keep a box of cables in the garage. Not even sure why anymore. VGA cables, SCSI terminators, a couple of those old parallel printer cables thick as garden hoses. I pulled it down last weekend because my daughter needed an HDMI c…
-
Meta Is Facing $1.4T In State Lawsuits Over Social Media Addiction
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 28, 2026 – Listen to the podcast Meta is facing penalties of up to a massive $1.4 trillion from four U.S. states that sued the company ove…
-
IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains
Talos IR's Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn how to sharpen your defenses.
-
Mirage Kitten targets Middle East and Africa region with new malware
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
-
Missed EFF's Livestream with Adam Savage and iFixit? Listen Here!
EFF’s first EFFecting Change livestream was all the way back in July of 2024. Maybe you've caught each stream, or maybe you’ve only caught a few. Or maybe you’re like me and prefer to listen to conversations like these on your dai…
-
Why Resetting Passwords No Longer Stops Attackers
As attackers shift from password theft to session and token theft to bypass multifactor authentication controls, organizations must move beyond login security and protect authenticated sessions.
-
Is Cyber Insurance Actually Working? I Checked, And I Was Wrong
I said I was done. I ended that run of blogs in the same garage I started it in, having argued that cars got safe because every link in a chain held, and that our broken link in cybersecurity is enforcement. Then someone I respect…
-
Activist charged with felony after giving border agent "duress code" that wiped his phone
The government says destroying his own data during an airport interrogation was illegal.
-
How a 67-Year-Old Woman Went From Romance Scam Victim To Podcast Rebel
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 27, 2026 – Listen to the podcast By the end of the nearly yearlong romance scam that began on LinkedIn, Anola Johnson, 67, a Utah-based tr…
Last fetch 14m ago · 0 new · 2 source error(s)