>
./threat_intel_feed
Curated cybersecurity news from global sources.
BleepingComputer
Aug 2, 2026
Google Chrome may soon block New Tab hijacker extensions by default
Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/google/google-chrome-may-soon-block-new-tab-hijacker-extensions-by-default/)
The Hacker News
Aug 1, 2026
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses.
Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and reported it to authorities.
Anyone who visited a site carrying the affected script on July 27 and copied a Bitcoin,
[Read full article on The Hacker News](https://thehackernews.com/2026/08/hackers-poison-adform-script-to-swap.html)
The Hacker News
Aug 1, 2026
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report.
Researchers track the operation as CaptiveCrunch and attribute it to Storm-2945. It assesses Storm-2945 to be an operational sub-cluster of Midnight Blizzard, also known as
[Read full article on The Hacker News](https://thehackernews.com/2026/08/hijacked-hotel-wi-fi-pushes-fake.html)
BleepingComputer
Jul 31, 2026
Amgen says cloud data breach exposed patient health, proprietary info
Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/amgen-says-cloud-data-breach-exposed-patient-health-proprietary-info/)
BleepingComputer
Jul 31, 2026
Arch Linux disables AUR package adoption to stop malware flood
The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/arch-linux-disables-aur-package-adoption-to-stop-malware-flood/)
BleepingComputer
Jul 31, 2026
Online ad firm Adform’s script compromised to steal cryptocurrency
Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones controlled by an attacker. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/online-ad-firm-adforms-script-compromised-to-steal-cryptocurrency/)
CyberScoop
Jul 31, 2026
Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world
The president went against his intelligence agencies’ conclusions about Iran being the likely suspect in the campaign.
The post Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/trump-blames-minnesota-water-cyberattacks-iran/)
The Hacker News
Jul 31, 2026
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025.
These targeted organizations operate across several sectors, such as healthcare, research, government offices,
[Read full article on The Hacker News](https://thehackernews.com/2026/08/suspected-chinese-speaking-hackers.html)
BleepingComputer
Jul 31, 2026
Hacker uses DeepSeek AI to autonomously attack vulnerable servers
A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/hacker-uses-deepseek-ai-to-autonomously-attack-vulnerable-servers/)
BleepingComputer
Jul 31, 2026
CISA warns of cyberattacks disrupting U.S. water utilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/cisa-warns-of-cyberattacks-disrupting-us-water-utilities/)
The Hacker News
Jul 31, 2026
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators.
Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019.
The same apps have a second job. When a box
[Read full article on The Hacker News](https://thehackernews.com/2026/07/cheap-android-tv-boxes-pose-as-phones.html)
The Hacker News
Jul 31, 2026
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved from a niche red-team technique to an industrial-scale threat in under six months.
Designed for input-constrained devices like smart TVs, printers, and so on, the device authorization login flow has been adopted by a wide range of apps and use-cases that it wasn't originally
[Read full article on The Hacker News](https://thehackernews.com/2026/07/6-reasons-why-device-code-phishing-is.html)
CyberScoop
Jul 31, 2026
What the Hugging Face breach reveals about defense in the age of agentic AI
We almost never get both sides of an intrusion. This time we did. Last month, Hugging Face disclosed a breach into part of its production infrastructure, saying an autonomous AI agent system ran the attack from start to finish. Five days later, OpenAI revealed that its own models, including GPT-5.6 Sol along with an unreleased […]
The post What the Hugging Face breach reveals about defense in the age of agentic AI appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/hugging-face-breach-agentic-ai-security-op-ed/)
CyberScoop
Jul 31, 2026
Anthropic says its AI accidentally hacked three companies during safety tests
Following OpenAI’s own incident, Anthropic reviewed its own evaluations and found three cases of Claude hacking external companies.
The post Anthropic says its AI accidentally hacked three companies during safety tests appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/anthropic-claude-ai-hacks-real-companies/)
BleepingComputer
Jul 31, 2026
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests
One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. [...]
[Read full article on BleepingComputer](https://www.bleepingcomputer.com/news/security/anthropics-claude-breached-3-orgs-uploaded-pypi-malware-during-tests/)
CyberScoop
Jul 30, 2026
Okta’s deal for Permiso aims to close gaps in identity threat detection
Ely Kahn, Okta's chief product officer, told CyberScoop the deal enriches the company's current threat detection tools and gives it deeper visibility into AI agent activity across enterprise systems.
The post Okta’s deal for Permiso aims to close gaps in identity threat detection appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/okta-acquires-permiso-security-ai-identity-threat-detection/)
CyberScoop
Jul 30, 2026
CISA issues recommendations to federal agencies on open-source software security
One expert said they were pleased by the guidance, which touches on open-weight AI models, patching and more.
The post CISA issues recommendations to federal agencies on open-source software security appeared first on CyberScoop.
[Read full article on CyberScoop](https://cyberscoop.com/cisa-open-source-software-security-guidance/)
PortSwigger Research
Feb 5, 2026
Top 10 web hacking techniques of 2025
Welcome to the Top 10 Web Hacking Techniques of 2025, the 19th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year
[Read full article on PortSwigger Research](https://portswigger.net/research/top-10-web-hacking-techniques-of-2025)
PortSwigger Research
Jan 6, 2026
Top 10 web hacking techniques of 2025: call for nominations
Update: nominations are now closed, and voting is live! Cast your vote here Over the last year, security researchers have shared a huge amount of work with the community through blog posts, presentati
[Read full article on PortSwigger Research](https://portswigger.net/research/top-10-web-hacking-techniques-of-2025-nominations-open)
PortSwigger Research
Dec 10, 2025
The Fragile Lock: Novel Bypasses For SAML Authentication
TLDR This post shows how to achieve a full authentication bypass in the Ruby and PHP SAML ecosystem by exploiting several parser-level inconsistencies: including attribute pollution, namespace confusi
[Read full article on PortSwigger Research](https://portswigger.net/research/the-fragile-lock)
PortSwigger Research
Nov 11, 2025
Introducing HTTP Anomaly Rank
HTTP Anomaly Rank If you've ever used Burp Intruder or Turbo Intruder, you'll be familiar with the ritual of manually digging through thousands of responses by repeatedly sorting the table via length,
[Read full article on PortSwigger Research](https://portswigger.net/research/introducing-http-anomaly-rank)
PortSwigger Research
Sep 17, 2025
WebSocket Turbo Intruder: Unearthing the WebSocket Goldmine
Many testers and tools give up the moment a protocol upgrade to WebSocket occurs, or only perform shallow analysis. This is a huge blind spot, leaving many bugs like Broken Access Controls, Race condi
[Read full article on PortSwigger Research](https://portswigger.net/research/websocket-turbo-intruder-unearthing-the-websocket-goldmine)