What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,956 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 7h ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 17h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 2d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
-
How a 67-Year-Old Woman Went From Romance Scam Victim To Podcast Rebel
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 27, 2026 – Listen to the podcast By the end of the nearly yearlong romance scam that began on LinkedIn, Anola Johnson, 67, a Utah-based tr…
-
CISOs vs. Boards: Myth or Misunderstanding?
Escalating threats are forcing boards to prioritize security, but communication gaps persist. Boards and security teams each say they need more support to bridge the divide.
-
Farmers Are Getting Control Of Their Equipment Back
For years, John Deere had actively made repairing their tractors near-impossible for anyone but itself and the few "authorized" repair shops—regardless of the ability of its customers to actually visit such shops. Now, in a major …
-
Black Hat USA 2026 In Las Vegas: Late Registration Ends July 31
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 24, 2026 – Watch the YouTube video Black Hat USA 2026, the premier cybersecurity event of the year, returns to Mandalay Bay in Las Vegas w…
-
Hundreds of Drone-as-First-Responder Programs Could Soon Be Launched Across the Country
Police departments across the country are lining up to launch drone-as-first-responder (DFR) programs, and hundreds have cleared a necessary hurdle toward making deployment a reality, expanding aerial surveillance and data collect…
-
Don’t swing at everything
Thorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever.
-
Intelligence Insights: July 2026
ClearFake claims the crown again and CastleLoader debuts in this month’s edition of Intelligence Insights.
-
Russian Global Webmail Espionage
Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post Russian Global Webmail Espionage appeared first on Unit 42 .
-
Employee Spotlight: Andrew Schlemmer
Meet Channel Account Manager Andrew Schlemmer, and learn how his personal experience with cybercrime fueled his mission to make enterprise-grade security attainable and accessible for businesses of all sizes.
-
Preview: Cisco Talos at Black Hat USA 2026
Here’s some of the ways Talos is showing up at Black Hat, alongside our friends at Cisco and Splunk.
-
The Fourth Circuit Says Border Agents Can Search Your Phone By Hand, No Suspicion Required
Legal intern Suzanne Castillo was the principal author of this post. The Fourth Circuit issued a disappointing opinion in U.S. v. Belmonte Cardozo , a case in which EFF filed an amicus brief , alongside the national ACLU, its Mary…
-
What’s New in Rapid7 Products and Services: Q2 2026 in Review
If Q1 set the pace for Rapid7's tools, Q2 accelerated it. This quarter brought a steady stream of product enhancements, platform investments, and customer-driven innovation across Rapid7’s portfolio. Each release was designed with…
-
How the LSHIY Password-Spraying Attack Abuses OAuth’s ROPC Grant
What we learned from tracking a massive automated password spraying campaign on the Azure CLI that leveraged a depreciated OAuth flow.
-
New EU Court of Justice Ruling on Platform Liability Could Cause Collateral Damage to Freedom of Expression
Intermediary liability laws around the world recognize that social media platforms, search engines, and other online service providers have become an integral part of our lives: they shape how we access information, communicate wi…
-
LG to Ban Residential Proxies from Smart TV Apps
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researcher…
-
What Are Initial Access Brokers?
Discover what initial access brokers (IABs) are, how they compromise networks to sell their access to other attackers, and how to protect your business.
-
Apps targeted at US troops contain Chinese and Russian code
More than one-eighth of apps analyzed contained foreign code.
-
Ukraine warns fake CAPTCHAs are being used to make you hack yourself
Ukraine's computer emergency response team, CERT-UA, has warned that the Kremlin-backed Sandworm hacking group is leveraging fake CAPTCHA checks on compromised websites that persuade users to run malicious code. Read more in my ar…
-
New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery
Kaspersky GReAT experts describe a new Project CAV3RN C2 module. It uses Outlook calendar for communication via Microsoft Graph and has a backup connection via DNS AAAA responses.
-
Protect Your Privacy with California's DROP Tool
Are you a California resident? Then we've got exciting news for you: there's a tool just for you that lets you take a single, relatively easy step to protect your privacy. It's called a DROP request. (That's Delete Request and Opt…
-
An Explosion of Surveillance Towers is Coming to U.S. Borders, Costing Over $1 Billion
A new report from the Government Accounting Office reveals that the Department of Homeland Security (DHS) plans to nearly triple the number of surveillance towers along U.S. borders, from the current 830 to 2,300 by 2034. DHS expe…
-
A stitch in time saves… 29!
Privyet, droogs! Yes – we ve been stitching time and saving the world a full 29 years already! And last Friday we celebrated those 29 years in typically unrestrained, loud, colorful, and rock rollicking style. Also typical: the ve…
-
The Broken Link In Cybersecurity Nobody Wants To Fix – Is It What You Think?
There s a problem in cybersecurity I haven t been able to let go of these past few weeks. I ve been returning to it and looking at it from different angles. To begin, I asked whether we re solving the wrong problem in cybersecurit…
-
Victory! Flock Ends Rollout of Audio “Distress Detection” of Human Voices
Reversing course, Flock Safety—the surveillance technology vendor most known for its extensive network of automated license plate readers — has announced that it will end a pilot for its acoustic gunshot detection devices to ident…
-
Your Vision. Your Legacy. Your Future.
This month, we celebrate 36 years of EFF and a mission that is bigger than any one of us. Thanks to EFF, communities around the world are demanding that technology protects their freedom, advances justice, and opens doors to oppor…
-
Microsoft VSS: Still Essential, But Not the Whole Story
Microsoft VSS remains a cornerstone of Windows data protection, but its architectural limits matter. Learn when to rely on it and when to go beyond it.
-
Now, even Russia's most elite hackers are using Clickfix to infect devices
The social-engineering technique has primarily been a tool of financially motivated criminals.
-
Begun, the Patch Wars have
Long foretold, the Great Patching has begun and it’s a doozy. Buckle in as Joe takes you through the story.
-
Custom HTML for Custom Phishing: Make the Fake Feel Real
Build personalized, realistic phishing scenarios with Huntress Custom HTML for Custom Phishing, tailored to your organization's unique risks and vendors.
-
HelloNet campaign: new malicious modules launched through the ViPNet update system
We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).
-
44 years of Blade Runner.
In the summer of 1982 – 44 years ago – arguably one of the greatest works in the history of Hollywood-kind premiered: Blade Runner. But in Chinese numerology, 44 is a bad number ( four sounds a lot like death in Mandarin), so, sho…
-
GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration
Two-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia.
-
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.
-
EFF and ARTICLE 19 Submission to the European Commission on the DSA Trusted Flagger Guidelines
EFF and ARTICLE 19 have submitted joint comments to the European Commission on draft guidelines for the Digital Services Act’s trusted flagger mechanism. Having long advocated for a DSA that protects freedom of expression while pr…
-
The Impostor Got Verified. The Founder Couldn't.
On LinkedIn, a scammer impersonating a company can get verified more easily than the company can verify its own staff. The lock works; Microsoft owns the key.
-
The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)
Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) appeared …
-
California Steps Back From Dangerous Expansion of its Age-Gating Law
The California legislature has stepped back from a plan that would have expanded its age-gating law, removing language that could have compounded serious threats to users’ speech, privacy and security just to browse the internet. …
-
Windows 0-day drops the same day Microsoft releases record number of patches
HiveLegacy is a "powerful primitive" that's likely capable of other nefarious actions.
-
Most Smart Watches, Rings, and Bands Lack Basic Transparency Reports and Key Privacy Features
Oura Rings, Garmin GPS fitness watches, Apple Watches, Whoop bands—every year, more and more tech devices are promising to monitor our health and fitness, guide us toward healthier living, and provide useful health metrics to take…
-
🚫 Don't Let Congress Age-Gate the Internet | EFFector 38.13
The effort to age gate the internet is back in Washington—and now it has a new name. Recently passed by the House of Representatives, the KIDS Act is a sprawling package of proposals to control what we can see and say online. Supp…
-
New Onyxia Cyber CISO Survey Report Exposes Wide Gaps in Cyber Resilience Standards Across Critical Infrastructure, Healthcare, Financial Services, Retail, and Technology
Today, we are unveiling our third CISO research report, “Industry Divides: Uncovering the CISO’s Resilience Priorities Across Sectors.” Based on a survey of 300 CISOs across financial services, healthcare, critical infrastructure,…
-
Wishin’ for Switchin’? The Huntress Buyout Program Has You Covered
Stuck riding out a contract with a vendor you no longer want to use? The Huntress Buyout Program covers your remaining term so you can switch today, not later.
-
Weekly Update 512: IoT Lockout Fail
Build a smart home , they said. It ll make life so much better , they said. Well, life wasn t very bloody good at 23:00 the other night after travelling 33 hours from Paris only to find the IoT doorlock batteries dead and the
-
Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
Old and forgotten "shims" Microsoft failed to revoke have made Secure Boot bypasses simple.
-
European Court: Apple Can Not Shirk Off its Interoperability Requirements
One of the best bulwarks against monopoly is interoperability—that is making a new product or service work with an existing product or service. Interoperability allows users, and not the manufacturers of their devices or largest p…
-
Don’t Repeat NY’s 3D Printing Blunder
This year the state of New York had the dubious honor of being the first to pass a controversial provision to mandate all 3D printers come with surveillance and censorship. That means not only is there a ticking clock to protect e…
-
What Happens When Someone Mentions Your Name?
A few years ago, my friend Jim Shields wrote a book called Three Guys Walk Into a Bar. The basic premise is that there are three kinds of people. There is a guy. You need a wall painted, so you find a guy. Any reasonably competent…
-
[Video] Where protection starts: Cisco Talos Intelligence Integrations
Every day, defenders make high-consequence decisions with incomplete information. Learn how Cisco Talos Intelligence Integrations help reduce uncertainty by turning the latest threat intelligence into proactive protections across …
-
Should cyber insurance be part of your business backup plan?
Insurance is all about managing risk. Unlike policies that are legally required for driving a car or taking out a mortgage, cyber insurance is optional. But for small businesses in particular, is cyber cover worth getting? If they…
-
The serpent’s tongue: Luring the Python out of its den
This blog examines the full lifecycle of a Python package, from hosting on repositories such as PyPI or custom web servers, through source and wheel distribution formats, to the final installation into virtual or system-wide Pytho…
Last fetch 14m ago · 5 new · 2 source error(s)